<?xml version='1.0' encoding='UTF-8'?>
<nvd xmlns="http://nvd.nist.gov/feeds/cve/1.2" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xsi:schemaLocation="http://nvd.nist.gov/feeds/cve/1.2 http://nvd.nist.gov/schema/nvdcve.xsd" pub_date="2012-02-13" nvd_xml_version="1.2">
  <entry type="CVE" severity="High" seq="2004-0001" published="2004-02-17" name="CVE-2004-0001" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Unknown vulnerability in the eflags checking in the 32-bit ptrace emulation for the Linux kernel on AMD64 systems allows local users to gain privileges.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" admin="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/337238" source="CERT-VN" adv="1">VU#337238</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-017.html" source="REDHAT" patch="1" adv="1">RHSA-2004:017</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/14888" source="XF" adv="1">linux-ptrace-gain-privilege(14888)</ref>
      <ref url="http://www.securityfocus.com/bid/9429" source="BID" adv="1">9429</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200402-06.xml" source="GENTOO">GLSA-200402-06</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:868" source="OVAL" sig="1">oval:org.mitre.oval:def:868</ref>
    </refs>
    <vuln_soft>
      <prod vendor="linux" name="linux_kernel">
        <vers num="2.6.20.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0002" published="2004-03-03" name="CVE-2004-0002" modified="2008-09-10" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">The TCP MSS (maximum segment size) functionality in netinet allows remote attackers to cause a denial of service (resource exhaustion) via (1) a low MTU, which causes a large number of small packets to be produced, or (2) via a large number of packets with a small TCP payload, which cause a large number of calls to the resource-intensive sowakeup function.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://lists.freebsd.org/pipermail/cvs-src/2004-January/016271.html" source="CONFIRM" patch="1" adv="1">http://lists.freebsd.org/pipermail/cvs-src/2004-January/016271.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="freebsd" name="freebsd">
        <vers num="3.0" edition="releng" />
        <vers num="3.1" />
        <vers num="3.2" />
        <vers num="3.3" />
        <vers num="3.4" />
        <vers num="3.5" edition="stable" />
        <vers num="3.5.1" edition="release" />
        <vers num="3.5.1" edition="stable" />
        <vers num="4.0" edition="alpha" />
        <vers num="4.0" edition="releng" />
        <vers num="4.1" />
        <vers num="4.1.1" edition="release" />
        <vers num="4.1.1" edition="stable" />
        <vers num="4.2" edition="stable" />
        <vers num="4.3" edition="release" />
        <vers num="4.3" edition="release_p38" />
        <vers num="4.3" edition="releng" />
        <vers num="4.3" edition="stable" />
        <vers num="4.4" edition="release_p42" />
        <vers num="4.4" edition="releng" />
        <vers num="4.4" edition="stable" />
        <vers num="4.5" edition="release" />
        <vers num="4.5" edition="release_p32" />
        <vers num="4.5" edition="releng" />
        <vers num="4.5" edition="stable" />
        <vers num="4.6" edition="release" />
        <vers num="4.6" edition="release_p20" />
        <vers num="4.6" edition="releng" />
        <vers num="4.6" edition="stable" />
        <vers num="4.6.2" />
        <vers num="4.7" edition="release" />
        <vers num="4.7" edition="release_p17" />
        <vers num="4.7" edition="releng" />
        <vers num="4.7" edition="stable" />
        <vers num="4.8" edition="pre-release" />
        <vers num="4.8" edition="release_p6" />
        <vers num="4.8" edition="releng" />
        <vers num="4.9" edition="pre-release" />
        <vers num="5.0" edition="alpha" />
        <vers num="5.0" edition="release_p14" />
        <vers num="5.0" edition="releng" />
        <vers num="5.1" edition="release_p5" />
        <vers num="5.1" edition="releng" />
        <vers num="5.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0003" published="2004-03-03" name="CVE-2004-0003" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Unknown vulnerability in Linux kernel before 2.4.22 allows local users to gain privileges, related to "R128 DRI limits checking."</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-044.html" source="REDHAT" patch="1" adv="1">RHSA-2004:044</ref>
      <ref url="http://www.linuxcompatible.org/print25630.html" source="CONFIRM" patch="1" adv="1">http://www.linuxcompatible.org/print25630.html</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-065.html" source="REDHAT">RHSA-2004:065</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2004_05_linux_kernel.html" source="SUSE">SuSE-SA:2004:005</ref>
      <ref url="http://www.debian.org/security/2004/dsa-495" source="DEBIAN">DSA-495</ref>
      <ref url="http://www.debian.org/security/2004/dsa-491" source="DEBIAN">DSA-491</ref>
      <ref url="http://www.debian.org/security/2004/dsa-489" source="DEBIAN">DSA-489</ref>
      <ref url="http://www.debian.org/security/2004/dsa-482" source="DEBIAN">DSA-482</ref>
      <ref url="http://www.debian.org/security/2004/dsa-481" source="DEBIAN">DSA-481</ref>
      <ref url="http://www.debian.org/security/2004/dsa-480" source="DEBIAN">DSA-480</ref>
      <ref url="http://www.debian.org/security/2004/dsa-479" source="DEBIAN">DSA-479</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9204" source="OVAL">oval:org.mitre.oval:def:9204</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15029" source="XF">linux-r128-gain-priviliges(15029)</ref>
      <ref url="http://www.turbolinux.com/security/2004/TLSA-2004-14.txt" source="TURBO">TLSA-2004-14</ref>
      <ref url="http://www.securityfocus.com/bid/9570" source="BID">9570</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-166.html" source="REDHAT">RHSA-2004:166</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-106.html" source="REDHAT">RHSA-2004:106</ref>
      <ref url="http://www.mandrakesecure.net/en/advisories/advisory.php?name=MDKSA-2004:029" source="MANDRAKE">MDKSA-2004:029</ref>
      <ref url="http://www.ciac.org/ciac/bulletins/o-145.shtml" source="CIAC">O-145</ref>
      <ref url="http://www.ciac.org/ciac/bulletins/o-127.shtml" source="CIAC">O-127</ref>
      <ref url="http://www.ciac.org/ciac/bulletins/o-126.shtml" source="CIAC">O-126</ref>
      <ref url="http://www.ciac.org/ciac/bulletins/o-121.shtml" source="CIAC">O-121</ref>
      <ref url="http://www.ciac.org/ciac/bulletins/o-082.shtml" source="CIAC">O-082</ref>
      <ref url="http://secunia.com/advisories/12075" source="SECUNIA">12075</ref>
      <ref url="http://secunia.com/advisories/11891" source="SECUNIA">11891</ref>
      <ref url="http://secunia.com/advisories/11464" source="SECUNIA">11464</ref>
      <ref url="http://secunia.com/advisories/11376" source="SECUNIA">11376</ref>
      <ref url="http://secunia.com/advisories/11370" source="SECUNIA">11370</ref>
      <ref url="http://secunia.com/advisories/11369" source="SECUNIA">11369</ref>
      <ref url="http://secunia.com/advisories/11362" source="SECUNIA">11362</ref>
      <ref url="http://secunia.com/advisories/11361" source="SECUNIA">11361</ref>
      <ref url="http://secunia.com/advisories/11202" source="SECUNIA">11202</ref>
      <ref url="http://secunia.com/advisories/10912" source="SECUNIA">10912</ref>
      <ref url="http://secunia.com/advisories/10911" source="SECUNIA">10911</ref>
      <ref url="http://secunia.com/advisories/10782" source="SECUNIA">10782</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:834" source="OVAL" sig="1">oval:org.mitre.oval:def:834</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1017" source="OVAL" sig="1">oval:org.mitre.oval:def:1017</ref>
    </refs>
    <vuln_soft>
      <prod vendor="linux" name="linux_kernel">
        <vers prev="1" num="2.4.22" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0004" published="2004-02-17" name="CVE-2004-0004" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">The libCheckSignature function in crypto-utils.lib for OpenCA 0.9.1.6 and earlier only compares the serial of the signer's certificate and the one in the database, which can cause OpenCA to incorrectly accept a signature if the certificate's chain is trusted by OpenCA's chain directory, allowing remote attackers to spoof requests from other users.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <other />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/336446" source="CERT-VN">VU#336446</ref>
      <ref url="http://www.securityfocus.com/bid/9435" source="BID" patch="1" adv="1">9435</ref>
      <ref url="http://www.openca.org/news/CAN-2004-0004.txt" source="CONFIRM" patch="1" adv="1">http://www.openca.org/news/CAN-2004-0004.txt</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/14847" source="XF">openca-improper-signature-verification(14847)</ref>
      <ref url="http://www.osvdb.org/3615" source="OSVDB">3615</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107427313700554&amp;w=2" source="BUGTRAQ">20040116 [OpenCA Advisory] Vulnerability in signature verification</ref>
    </refs>
    <vuln_soft>
      <prod vendor="openca" name="openca">
        <vers prev="1" num="0.9.1.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0005" published="2004-03-03" name="CVE-2004-0005" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple buffer overflows in Gaim 0.75 allow remote attackers to cause a denial of service and possibly execute arbitrary code via (1) octal encoding in yahoo_decode that causes a null byte to be written beyond the buffer, (2) octal encoding in yahoo_decode that causes a pointer to reference memory beyond the terminating null byte, (3) a quoted printable string to the gaim_quotedp_decode MIME decoder that causes a null byte to be written beyond the buffer, and (4) quoted printable encoding in gaim_quotedp_decode that causes a pointer to reference memory beyond the terminating null byte.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/655974" source="CERT-VN">VU#655974</ref>
      <ref url="http://www.kb.cert.org/vuls/id/404470" source="CERT-VN">VU#404470</ref>
      <ref url="http://www.kb.cert.org/vuls/id/226974" source="CERT-VN">VU#226974</ref>
      <ref url="http://www.kb.cert.org/vuls/id/190366" source="CERT-VN">VU#190366</ref>
      <ref url="http://www.debian.org/security/2004/dsa-434" source="DEBIAN" patch="1" adv="1">DSA-434</ref>
      <ref url="http://security.e-matters.de/advisories/012004.html" source="MISC" patch="1" adv="1">http://security.e-matters.de/advisories/012004.html</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107513690306318&amp;w=2" source="BUGTRAQ" adv="1">20040126 Advisory 01/2004: 12 x Gaim remote overflows</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/14944" source="XF">gaim-mime-decoder-oob(14944)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/14942" source="XF">gaim-mime-decoder-bo(14942)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/14938" source="XF">gaim-sscanf-oob(14938)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/14935" source="XF">gaim-yahoodecode-offbyone-bo(14935)</ref>
      <ref url="http://www.slackware.com/security/viewer.php?l=slackware-security&amp;y=2004&amp;m=slackware-security.361158" source="SLACKWARE">SSA:2004-026</ref>
      <ref url="http://www.securitytracker.com/id?1008850" source="SECTRACK">1008850</ref>
      <ref url="http://www.osvdb.org/3736" source="OSVDB">3736</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2004_04_gaim.html" source="SUSE">SuSE-SA:2004:004</ref>
      <ref url="http://www.linuxsecurity.com/content/view/105690/104/" source="GENTOO">GLSA-200401-04</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000813" source="CONECTIVA">CLA-2004:813</ref>
      <ref url="http://archives.neohapsis.com/archives/fulldisclosure/2004-01/0994.html" source="FULLDISC">20040126 Advisory 01/2004: 12 x Gaim remote overflows</ref>
    </refs>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0006" published="2004-03-03" name="CVE-2004-0006" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple buffer overflows in Gaim 0.75 and earlier, and Ultramagnetic before 0.81, allow remote attackers to cause a denial of service and possibly execute arbitrary code via (1) cookies in a Yahoo web connection, (2) a long name parameter in the Yahoo login web page, (3) a long value parameter in the Yahoo login page, (4) a YMSG packet, (5) the URL parser, and (6) HTTP proxy connect.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/871838" source="CERT-VN">VU#871838</ref>
      <ref url="http://www.kb.cert.org/vuls/id/527142" source="CERT-VN">VU#527142</ref>
      <ref url="http://www.kb.cert.org/vuls/id/503030" source="CERT-VN">VU#503030</ref>
      <ref url="http://www.kb.cert.org/vuls/id/444158" source="CERT-VN">VU#444158</ref>
      <ref url="http://www.kb.cert.org/vuls/id/371382" source="CERT-VN">VU#371382</ref>
      <ref url="http://www.kb.cert.org/vuls/id/297198" source="CERT-VN">VU#297198</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-032.html" source="REDHAT" patch="1" adv="1">RHSA-2004:032</ref>
      <ref url="http://ultramagnetic.sourceforge.net/advisories/001.html" source="CONFIRM" patch="1" adv="1">http://ultramagnetic.sourceforge.net/advisories/001.html</ref>
      <ref url="http://security.e-matters.de/advisories/012004.html" source="MISC" patch="1" adv="1">http://security.e-matters.de/advisories/012004.html</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-045.html" source="REDHAT">RHSA-2004:045</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-033.html" source="REDHAT">RHSA-2004:033</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2004_04_gaim.html" source="SUSE">SuSE-SA:2004:004</ref>
      <ref url="http://www.debian.org/security/2004/dsa-434" source="DEBIAN">DSA-434</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200401-04.xml" source="GENTOO" adv="1">GLSA-200401-04</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10222" source="OVAL">oval:org.mitre.oval:def:10222</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107513690306318&amp;w=2" source="BUGTRAQ" adv="1">20040126 Advisory 01/2004: 12 x Gaim remote overflows</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/20040201-01-U.asc" source="SGI">20040201-01-U</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/14947" source="XF">gaim-http-proxy-bo(14947)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/14945" source="XF">gaim-urlparser-bo(14945)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/14943" source="XF">gaim-yahoopacketread-keyname-bo(14943)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/14941" source="XF">gaim-login-value-bo(14941)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/14940" source="XF">gaim-login-name-bo(14940)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/14939" source="XF">gaim-yahoowebpending-cookie-bo(14939)</ref>
      <ref url="http://www.slackware.com/security/viewer.php?l=slackware-security&amp;y=2004&amp;m=slackware-security.361158" source="SLACKWARE">SSA:2004-026</ref>
      <ref url="http://www.securitytracker.com/id?1008850" source="SECTRACK">1008850</ref>
      <ref url="http://www.securityfocus.com/bid/9489" source="BID">9489</ref>
      <ref url="http://www.osvdb.org/3732" source="OSVDB">3732</ref>
      <ref url="http://www.osvdb.org/3731" source="OSVDB">3731</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2004:006" source="MANDRAKE">MDKSA-2004:006</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107522432613022&amp;w=2" source="BUGTRAQ">20040127 Ultramagnetic Advisory #001:  Multiple vulnerabilities in Gaim code</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000813" source="CONECTIVA">CLA-2004:813</ref>
      <ref url="http://archives.neohapsis.com/archives/fulldisclosure/2004-01/0994.html" source="FULLDISC">20040126 Advisory 01/2004: 12 x Gaim remote overflows</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/20040202-01-U.asc" source="SGI">20040202-01-U</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:818" source="OVAL" sig="1">oval:org.mitre.oval:def:818</ref>
    </refs>
    <vuln_soft>
      <prod vendor="rob_flynn" name="gaim">
        <vers prev="1" num="0.75" />
      </prod>
      <prod vendor="ultramagnetic" name="ultramagnetic">
        <vers prev="1" num="0.81" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0007" published="2004-03-03" name="CVE-2004-0007" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in the Extract Info Field Function for (1) MSN and (2) YMSG protocol handlers in Gaim 0.74 and earlier, and Ultramagnetic before 0.81, allows remote attackers to cause a denial of service and possibly execute arbitrary code.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/197142" source="CERT-VN">VU#197142</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-033.html" source="REDHAT" patch="1" adv="1">RHSA-2004:033</ref>
      <ref url="http://www.debian.org/security/2004/dsa-434" source="DEBIAN" patch="1" adv="1">DSA-434</ref>
      <ref url="http://ultramagnetic.sourceforge.net/advisories/001.html" source="CONFIRM" patch="1" adv="1">http://ultramagnetic.sourceforge.net/advisories/001.html</ref>
      <ref url="http://security.e-matters.de/advisories/012004.html" source="MISC" patch="1" adv="1">http://security.e-matters.de/advisories/012004.html</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107522432613022&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20040127 Ultramagnetic Advisory #001:  Multiple vulnerabilities in Gaim code</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-032.html" source="REDHAT">RHSA-2004:032</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200401-04.xml" source="GENTOO">GLSA-200401-04</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9906" source="OVAL">oval:org.mitre.oval:def:9906</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/14946" source="XF">gaim-extractinfo-bo(14946)</ref>
      <ref url="http://www.slackware.com/security/viewer.php?l=slackware-security&amp;y=2004&amp;m=slackware-security.361158" source="SLACKWARE">SSA:2004-026</ref>
      <ref url="http://www.securitytracker.com/id?1008850" source="SECTRACK">1008850</ref>
      <ref url="http://www.securityfocus.com/bid/9489" source="BID">9489</ref>
      <ref url="http://www.securityfocus.com/advisories/6281" source="SUSE">SuSE-SA:2004:004</ref>
      <ref url="http://www.osvdb.org/3733" source="OSVDB">3733</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2004:006" source="MANDRAKE">MDKSA-2004:006</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107513690306318&amp;w=2" source="BUGTRAQ">20040126 Advisory 01/2004: 12 x Gaim remote overflows</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000813" source="CONECTIVA">CLA-2004:813</ref>
      <ref url="http://archives.neohapsis.com/archives/fulldisclosure/2004-01/0994.html" source="FULLDISC">20040126 Advisory 01/2004: 12 x Gaim remote overflows</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:819" source="OVAL" sig="1">oval:org.mitre.oval:def:819</ref>
    </refs>
    <vuln_soft>
      <prod vendor="rob_flynn" name="gaim">
        <vers prev="1" num="0.74" />
      </prod>
      <prod vendor="ultramagnetic" name="ultramagnetic">
        <vers prev="1" num="0.81" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0008" published="2004-03-03" name="CVE-2004-0008" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Integer overflow in Gaim 0.74 and earlier, and Ultramagnetic before 0.81, allows remote attackers to cause a denial of service and possibly execute arbitrary code via a directIM packet that triggers a heap-based buffer overflow.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/779614" source="CERT-VN" adv="1">VU#779614</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-032.html" source="REDHAT" patch="1" adv="1">RHSA-2004:032</ref>
      <ref url="http://ultramagnetic.sourceforge.net/advisories/001.html" source="CONFIRM" patch="1" adv="1">http://ultramagnetic.sourceforge.net/advisories/001.html</ref>
      <ref url="http://security.e-matters.de/advisories/012004.html" source="MISC" patch="1" adv="1">http://security.e-matters.de/advisories/012004.html</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107522432613022&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20040127 Ultramagnetic Advisory #001:  Multiple vulnerabilities in Gaim code</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-045.html" source="REDHAT">RHSA-2004:045</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-033.html" source="REDHAT">RHSA-2004:033</ref>
      <ref url="http://www.debian.org/security/2004/dsa-434" source="DEBIAN">DSA-434</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200401-04.xml" source="GENTOO">GLSA-200401-04</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9469" source="OVAL">oval:org.mitre.oval:def:9469</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/20040201-01-U.asc" source="SGI">20040201-01-U</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/14937" source="XF">gaim-directim-bo(14937)</ref>
      <ref url="http://www.securitytracker.com/id?1008850" source="SECTRACK">1008850</ref>
      <ref url="http://www.osvdb.org/3734" source="OSVDB">3734</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2004:006" source="MANDRAKE">MDKSA-2004:006</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107522338611564&amp;w=2" source="BUGTRAQ">20040127 [slackware-security]  GAIM security update (SSA:2004-026-01)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107513690306318&amp;w=2" source="BUGTRAQ">20040126 Advisory 01/2004: 12 x Gaim remote overflows</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000813" source="CONECTIVA">CLA-2004:813</ref>
      <ref url="http://archives.neohapsis.com/archives/fulldisclosure/2004-01/0994.html" source="FULLDISC">20040126 Advisory 01/2004: 12 x Gaim remote overflows</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/20040202-01-U.asc" source="SGI">20040202-01-U</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:820" source="OVAL" sig="1">oval:org.mitre.oval:def:820</ref>
    </refs>
    <vuln_soft>
      <prod vendor="rob_flynn" name="gaim">
        <vers prev="1" num="0.74" />
      </prod>
      <prod vendor="ultramagnetic" name="ultramagnetic">
        <vers prev="1" num="0.81" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0009" published="2004-03-03" name="CVE-2004-0009" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Apache-SSL 1.3.28+1.52 and earlier, with SSLVerifyClient set to 1 or 3 and SSLFakeBasicAuth enabled, allows remote attackers to forge a client certificate by using basic authentication with the "one-line DN" of the target user.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107619127531765&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20040206 Apache-SSL security advisory - apache_1.3.28+ssl_1.52 and prior</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15065" source="XF" adv="1">apachessl-default-password(15065)</ref>
      <ref url="http://www.securityfocus.com/bid/9590" source="BID" adv="1">9590</ref>
      <ref url="http://www.apache-ssl.org/advisory-20040206.txt" source="CONFIRM">http://www.apache-ssl.org/advisory-20040206.txt</ref>
      <ref url="http://www.osvdb.org/3877" source="OSVDB">3877</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2004-February/016870.html" source="FULLDISC">20040206 [apache-ssl] Apache-SSL security advisory - apache_1.3.28+ssl_1.52 and prior</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apache-ssl" name="apache-ssl">
        <vers prev="1" num="1.3.28_1.52" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0010" published="2004-03-03" name="CVE-2004-0010" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Stack-based buffer overflow in the ncp_lookup function for ncpfs in Linux kernel 2.4.x allows local users to gain privileges.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/9691" source="BID" patch="1" adv="1">9691</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-069.html" source="REDHAT" patch="1" adv="1">RHSA-2004:069</ref>
      <ref url="http://www.debian.org/security/2004/dsa-479" source="DEBIAN" patch="1" adv="1">DSA-479</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15250" source="XF" adv="1">linux-ncplookup-gain-privileges(15250)</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-188.html" source="REDHAT">RHSA-2004:188</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-065.html" source="REDHAT">RHSA-2004:065</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2004_05_linux_kernel.html" source="SUSE">SuSE-SA:2004:005</ref>
      <ref url="http://www.debian.org/security/2004/dsa-495" source="DEBIAN">DSA-495</ref>
      <ref url="http://www.debian.org/security/2004/dsa-491" source="DEBIAN">DSA-491</ref>
      <ref url="http://www.debian.org/security/2004/dsa-489" source="DEBIAN">DSA-489</ref>
      <ref url="http://www.debian.org/security/2004/dsa-482" source="DEBIAN">DSA-482</ref>
      <ref url="http://www.debian.org/security/2004/dsa-481" source="DEBIAN">DSA-481</ref>
      <ref url="http://www.debian.org/security/2004/dsa-480" source="DEBIAN">DSA-480</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11388" source="OVAL">oval:org.mitre.oval:def:11388</ref>
      <ref url="http://www.securityfocus.com/advisories/6759" source="TURBO">TLSA-2004-05</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2004:015" source="MANDRAKE">MDKSA-2004:015</ref>
      <ref url="http://www.ciac.org/ciac/bulletins/o-082.shtml" source="CIAC">O-082</ref>
      <ref url="http://fedoranews.org/updates/FEDORA-2004-079.shtml" source="FEDORA">FEDORA-2004-079</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000820" source="CONECTIVA">CLA-2004:820</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:835" source="OVAL" sig="1">oval:org.mitre.oval:def:835</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1035" source="OVAL" sig="1">oval:org.mitre.oval:def:1035</ref>
    </refs>
    <vuln_soft>
      <prod vendor="linux" name="linux_kernel">
        <vers num="2.4.0" edition="test1" />
        <vers num="2.4.0" edition="test10" />
        <vers num="2.4.0" edition="test11" />
        <vers num="2.4.0" edition="test12" />
        <vers num="2.4.0" edition="test2" />
        <vers num="2.4.0" edition="test3" />
        <vers num="2.4.0" edition="test4" />
        <vers num="2.4.0" edition="test5" />
        <vers num="2.4.0" edition="test6" />
        <vers num="2.4.0" edition="test7" />
        <vers num="2.4.0" edition="test8" />
        <vers num="2.4.0" edition="test9" />
        <vers num="2.4.1" />
        <vers num="2.4.10" />
        <vers num="2.4.11" />
        <vers num="2.4.12" />
        <vers num="2.4.13" />
        <vers num="2.4.14" />
        <vers num="2.4.15" />
        <vers num="2.4.16" />
        <vers num="2.4.17" />
        <vers num="2.4.18" edition="" />
        <vers num="2.4.18" edition=":x86" />
        <vers num="2.4.18" edition="pre1" />
        <vers num="2.4.18" edition="pre2" />
        <vers num="2.4.18" edition="pre3" />
        <vers num="2.4.18" edition="pre4" />
        <vers num="2.4.18" edition="pre5" />
        <vers num="2.4.18" edition="pre6" />
        <vers num="2.4.18" edition="pre7" />
        <vers num="2.4.18" edition="pre8" />
        <vers num="2.4.19" edition="pre1" />
        <vers num="2.4.19" edition="pre2" />
        <vers num="2.4.19" edition="pre3" />
        <vers num="2.4.19" edition="pre4" />
        <vers num="2.4.19" edition="pre5" />
        <vers num="2.4.19" edition="pre6" />
        <vers num="2.4.2" />
        <vers num="2.4.20" />
        <vers num="2.4.21" edition="pre1" />
        <vers num="2.4.21" edition="pre4" />
        <vers num="2.4.21" edition="pre7" />
        <vers num="2.4.22" />
        <vers num="2.4.23" edition="pre9" />
        <vers num="2.4.24" />
        <vers num="2.4.3" />
        <vers num="2.4.4" />
        <vers num="2.4.5" />
        <vers num="2.4.6" />
        <vers num="2.4.7" />
        <vers num="2.4.8" />
        <vers num="2.4.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0011" published="2004-01-20" name="CVE-2004-0011" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in fsp before 2.81.b18 allows remote users to execute arbitrary code.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/9377" source="BID" patch="1" adv="1">9377</ref>
      <ref url="http://www.debian.org/security/2004/dsa-416" source="DEBIAN" patch="1" adv="1">DSA-416</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/14155" source="XF" adv="1">fsp-boundry-error-bo(14155)</ref>
      <ref url="http://www.ciac.org/ciac/bulletins/o-048.shtml" source="CIAC">O-048</ref>
    </refs>
    <vuln_soft>
      <prod vendor="debian" name="fsp">
        <vers prev="1" num="2.81.b18" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0013" published="2004-02-03" name="CVE-2004-0013" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">jabber 1.4.2, 1.4.2a, and possibly earlier versions, does not properly handle SSL connections, which allows remote attackers to cause a denial of service (crash).</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <other />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2004:005" source="MANDRAKE" patch="1" adv="1">MDKSA-2004:005</ref>
      <ref url="http://www.debian.org/security/2004/dsa-414" source="DEBIAN" patch="1" adv="1">DSA-414</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/14158" source="XF" adv="1">jabber-ssl-connections-dos(14158)</ref>
      <ref url="http://www.securityfocus.com/bid/9376" source="BID" adv="1">9376</ref>
      <ref url="http://www.osvdb.org/3345" source="OSVDB">3345</ref>
      <ref url="http://secunia.com/advisories/10559" source="SECUNIA">10559</ref>
    </refs>
    <vuln_soft>
      <prod vendor="jabber_software_foundation" name="jabber_server">
        <vers num="1.4.2a" />
        <vers num="1.4.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0014" published="2004-01-20" name="CVE-2004-0014" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple buffer overflows in the nd WebDAV interface 0.8.2 and earlier allows remote web servers to execute arbitrary code via certain long strings.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/9365" source="BID" patch="1" adv="1">9365</ref>
      <ref url="http://www.debian.org/security/2004/dsa-412" source="DEBIAN" patch="1" adv="1">DSA-412</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/14141" source="XF" adv="1">nd-long-string-bo(14141)</ref>
      <ref url="http://www.securitytracker.com/id?1008616" source="SECTRACK">1008616</ref>
      <ref url="http://secunia.com/advisories/10550" source="SECUNIA">10550</ref>
      <ref url="http://secunia.com/advisories/10549" source="SECUNIA">10549</ref>
    </refs>
    <vuln_soft>
      <prod vendor="nd" name="nd">
        <vers prev="1" num="0.8.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0015" published="2004-02-03" name="CVE-2004-0015" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">vbox3 0.1.8 and earlier does not properly drop privileges before executing a user-provided TCL script, which allows local users to gain privileges.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.debian.org/security/2004/dsa-418" source="DEBIAN" patch="1" adv="1">DSA-418</ref>
      <ref url="http://www.securityfocus.com/bid/9381" source="BID" adv="1">9381</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/14170" source="XF">vbox3-gain-privileges(14170)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="vbox3" name="vbox3">
        <vers prev="1" num="0.1.8" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0016" published="2004-02-03" name="CVE-2004-0016" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">The calendar module for phpgroupware 0.9.14 does not enforce the "save extension" feature for holiday files, which allows remote attackers to create and execute PHP files.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.debian.org/security/2004/dsa-419" source="DEBIAN" patch="1" adv="1">DSA-419</ref>
      <ref url="http://www.securityfocus.com/bid/9387" source="BID" adv="1">9387</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/13489" source="XF">phpgroupware-calendar-file-include(13489)</ref>
      <ref url="http://www.osvdb.org/6860" source="OSVDB">6860</ref>
    </refs>
    <vuln_soft>
      <prod vendor="phpgroupware" name="phpgroupware">
        <vers num="0.9.14" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0017" published="2004-02-03" name="CVE-2004-0017" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple SQL injection vulnerabilities in the (1) calendar and (2) infolog modules for phpgroupware 0.9.14 allow remote attackers to perform unauthorized database operations.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.debian.org/security/2004/dsa-419" source="DEBIAN" patch="1" adv="1">DSA-419</ref>
      <ref url="http://www.securityfocus.com/bid/9386" source="BID" adv="1">9386</ref>
      <ref url="http://www.securitytracker.com/id?1008662" source="SECTRACK">1008662</ref>
      <ref url="http://secunia.com/advisories/10591" source="SECUNIA">10591</ref>
    </refs>
    <vuln_soft>
      <prod vendor="phpgroupware" name="phpgroupware">
        <vers num="0.9.14" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0028" published="2004-02-03" name="CVE-2004-0028" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">jitterbug 1.6.2 does not properly sanitize inputs, which allows remote authenticated users to execute arbitrary commands.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.debian.org/security/2004/dsa-420" source="DEBIAN" patch="1" adv="1">DSA-420</ref>
      <ref url="http://www.securityfocus.com/bid/9397" source="BID" adv="1">9397</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/14207" source="XF">jitterbug-execute-code(14207)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="samba" name="jitterbug">
        <vers num="1.6.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0029" published="2004-01-20" name="CVE-2004-0029" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Lotus Notes Domino 6.0.2 on Linux installs the notes.ini configuration file with world-writable permissions, which allows local users to modify the Notes configuration and gain privileges.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <config />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/14153" source="XF" adv="1">lotus-notes-insecure-permissions(14153)</ref>
      <ref url="http://www.securityfocus.com/bid/9366" source="BID" adv="1">9366</ref>
      <ref url="http://www.securitytracker.com/id?1008623" source="SECTRACK">1008623</ref>
      <ref url="http://www.osvdb.org/3424" source="OSVDB">3424</ref>
      <ref url="http://www.excluded.org/advisories/advisory05.txt" source="MISC">http://www.excluded.org/advisories/advisory05.txt</ref>
      <ref url="http://secunia.com/advisories/10566" source="SECUNIA">10566</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107340897710308&amp;w=2" source="BUGTRAQ">20040106 Lotus Notes Domino 6.0.2 (linux) faulty default permissions</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="lotus_domino">
        <vers num="6.0.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0030" published="2004-01-20" name="CVE-2004-0030" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">PHP remote file inclusion vulnerability in (1) functions.php, (2) authentication_index.php, and (3) config_gedcom.php for PHPGEDVIEW 2.61 allows remote attackers to execute arbitrary PHP code by modifying the PGV_BASE_DIRECTORY parameter to reference a URL on a remote web server that contains the code.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/14159" source="XF" adv="1">phpgedview-pgvbasedirectory-file-include(14159)</ref>
      <ref url="http://www.securityfocus.com/bid/9368" source="BID">9368</ref>
      <ref url="http://www.osvdb.org/3343" source="OSVDB">3343</ref>
      <ref url="http://secunia.com/advisories/10565" source="SECUNIA" adv="1">10565</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107340840209453&amp;w=2" source="BUGTRAQ">20040106 Vuln in PHPGEDVIEW 2.61 Multi-Problem</ref>
      <ref url="http://www.securitytracker.com/id?1008632" source="SECTRACK">1008632</ref>
    </refs>
    <vuln_soft>
      <prod vendor="phpgedview" name="phpgedview">
        <vers num="2.61" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0031" published="2004-01-20" name="CVE-2004-0031" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">PHPGEDVIEW 2.61 allows remote attackers to reinstall the software and change the administrator password via a direct HTTP request to editconfig.php.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107340840209453&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20040106 Vuln in PHPGEDVIEW 2.61 Multi-Problem</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/14161" source="XF" adv="1">phpgedview-modify-admin-password(14161)</ref>
      <ref url="http://www.osvdb.org/3403" source="OSVDB">3403</ref>
      <ref url="http://secunia.com/advisories/10565" source="SECUNIA">10565</ref>
    </refs>
    <vuln_soft>
      <prod vendor="phpgedview" name="phpgedview">
        <vers num="2.61" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0032" published="2004-01-20" name="CVE-2004-0032" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in search.php in PHPGEDVIEW 2.61 allows remote attackers to inject arbitrary HTML and web script via the firstname parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107340840209453&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20040106 Vuln in PHPGEDVIEW 2.61 Multi-Problem</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/14160" source="XF" adv="1">phpgedview-search-xss(14160)</ref>
      <ref url="http://www.securityfocus.com/bid/9369" source="BID">9369</ref>
      <ref url="http://www.osvdb.org/3402" source="OSVDB">3402</ref>
      <ref url="http://secunia.com/advisories/10565" source="SECUNIA">10565</ref>
    </refs>
    <vuln_soft>
      <prod vendor="phpgedview" name="phpgedview">
        <vers num="2.61" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0033" published="2004-01-20" name="CVE-2004-0033" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">admin.php in PHPGEDVIEW 2.61 allows remote attackers to obtain sensitive information via an action parameter with a phpinfo command.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107340840209453&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20040106 Vuln in PHPGEDVIEW 2.61 Multi-Problem</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/14162" source="XF" adv="1">phpgedview-admin-info-disclosure(14162)</ref>
      <ref url="http://www.securityfocus.com/bid/9371" source="BID">9371</ref>
      <ref url="http://www.osvdb.org/3404" source="OSVDB">3404</ref>
      <ref url="http://secunia.com/advisories/10565" source="SECUNIA">10565</ref>
    </refs>
    <vuln_soft>
      <prod vendor="phpgedview" name="phpgedview">
        <vers num="2.61" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0034" published="2004-01-20" name="CVE-2004-0034" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in Phorum 3.4.5 and earlier allow remote attackers to inject arbitrary HTML or web script via (1) the phorum_check_xss function in common.php, (2) the EditError variable in profile.php, and (3) the Error variable in login.php.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/14145" source="XF" adv="1">phorum-common-xss(14145)</ref>
      <ref url="http://www.securityfocus.com/bid/9361" source="BID" adv="1">9361</ref>
      <ref url="http://secunia.com/advisories/10567" source="SECUNIA">10567</ref>
      <ref url="http://phorum.org/" source="CONFIRM" adv="1">http://phorum.org/</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107340481804110&amp;w=2" source="BUGTRAQ" adv="1">20040105 Multiple Vulnerabilities in Phorum 3.4.5</ref>
      <ref url="http://www.securitytracker.com/id?1008633" source="SECTRACK">1008633</ref>
      <ref url="http://www.osvdb.org/3510" source="OSVDB">3510</ref>
      <ref url="http://www.osvdb.org/3506" source="OSVDB">3506</ref>
      <ref url="http://www.osvdb.org/3434" source="OSVDB">3434</ref>
    </refs>
    <vuln_soft>
      <prod vendor="phorum" name="phorum">
        <vers prev="1" num="3.4.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0035" published="2004-01-20" name="CVE-2004-0035" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in register.php for Phorum 3.4.5 and earlier allows remote attackers to execute arbitrary SQL commands via the hide_email parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/14146" source="XF" adv="1">phorum-register-sql-injection(14146)</ref>
      <ref url="http://www.securityfocus.com/bid/9363" source="BID" adv="1">9363</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107340481804110&amp;w=2" source="BUGTRAQ" adv="1">20040105 Multiple Vulnerabilities in Phorum 3.4.5</ref>
      <ref url="http://www.osvdb.org/3508" source="OSVDB">3508</ref>
      <ref url="http://secunia.com/advisories/10567" source="SECUNIA">10567</ref>
    </refs>
    <vuln_soft>
      <prod vendor="phorum" name="phorum">
        <vers prev="1" num="3.4.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0036" published="2004-01-20" name="CVE-2004-0036" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">SQL injection vulnerability in calendar.php for vBulletin Forum 2.3.x before 2.3.4 allows remote attackers to steal sensitive information via the eventid parameter.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107340358202123&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20040105 vBulletin Forum 2.3.xx calendar.php SQL Injection</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/14144" source="XF" adv="1">vbulletin-calendar-sql-injection(14144)</ref>
      <ref url="http://www.vbulletin.com/forum/showthread.php?postid=588825" source="CONFIRM">http://www.vbulletin.com/forum/showthread.php?postid=588825</ref>
      <ref url="http://www.securityfocus.com/bid/9360" source="BID">9360</ref>
      <ref url="http://www.osvdb.org/3344" source="OSVDB">3344</ref>
    </refs>
    <vuln_soft>
      <prod vendor="jelsoft" name="vbulletin">
        <vers num="2.3.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0037" published="2004-01-20" name="CVE-2004-0037" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">FirstClass Desktop Client 7.1 allows remote attackers to execute arbitrary commands via hyperlinks in FirstClass RTF messages.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/14151" source="XF" adv="1">firstclassclient-execute-code(14151)</ref>
      <ref url="http://www.securityfocus.com/bid/9370" source="BID" adv="1">9370</ref>
      <ref url="http://www.osvdb.org/3442" source="OSVDB">3442</ref>
      <ref url="http://secunia.com/advisories/10556" source="SECUNIA">10556</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107340950611167&amp;w=2" source="BUGTRAQ" adv="1">20040105 FirstClass Client 7.1: Command Execution via Email Web Link</ref>
      <ref url="http://www.securitytracker.com/id?1008609" source="SECTRACK">1008609</ref>
    </refs>
    <vuln_soft>
      <prod vendor="opentext" name="opentext_firstclass_desktop_client">
        <vers num="7.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0038" published="2004-06-14" name="CVE-2004-0038" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">McAfee ePolicy Orchestrator (ePO) 2.5.1 Patch 13 and 3.0 SP2a Patch 3 allows remote attackers to execute arbitrary commands via certain HTTP POST requests to the spipe/file handler on ePO TCP port 81.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/14166" source="XF" patch="1" adv="1">epolicy-execute-commands(14166)</ref>
      <ref url="http://xforce.iss.net/xforce/alerts/id/173" source="ISS" patch="1" adv="1">20040510 McAfee ePolicy Orchestrator Remote Compromise Vulnerability</ref>
      <ref url="http://www.securityfocus.com/bid/10200" source="BID" patch="1" adv="1">10200</ref>
      <ref url="http://www.osvdb.org/5626" source="MISC" patch="1" adv="1">http://www.osvdb.org/5626</ref>
      <ref url="http://download.nai.com/products/patches/ePO/v2.x/Patch14.txt" source="CONFIRM" adv="1">http://download.nai.com/products/patches/ePO/v2.x/Patch14.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mcafee" name="epolicy_orchestrator">
        <vers num="2.5" edition="sp1" />
        <vers num="2.5.1" />
        <vers num="3.0" edition="sp2a" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0039" published="2004-03-03" name="CVE-2004-0039" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Multiple format string vulnerabilities in HTTP Application Intelligence (AI) component in Check Point Firewall-1 NG-AI R55 and R54, and Check Point Firewall-1 HTTP Security Server included with NG FP1, FP2, and FP3 allows remote attackers to execute arbitrary code via HTTP requests that cause format string specifiers to be used in an error message, as demonstrated using the scheme of a URI.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/790771" source="CERT-VN" patch="1" adv="1">VU#790771</ref>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA04-036A.html" source="CERT">TA04-036A</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/14149" source="XF" patch="1" adv="1">fw1-format-string(14149)</ref>
      <ref url="http://www.securityfocus.com/bid/9581" source="BID" patch="1" adv="1">9581</ref>
      <ref url="http://xforce.iss.net/xforce/alerts/id/162" source="ISS">20040204 Checkpoint Firewall-1 HTTP Parsing Format String Vulnerabilities</ref>
      <ref url="http://www.ciac.org/ciac/bulletins/o-072.shtml" source="CIAC">O-072</ref>
      <ref url="http://www.checkpoint.com/techsupport/alerts/security_server.html" source="CONFIRM">http://www.checkpoint.com/techsupport/alerts/security_server.html</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107604682227031&amp;w=2" source="BUGTRAQ">20040205 Two checkpoint fw-1/vpn-1 vulns</ref>
    </refs>
    <vuln_soft>
      <prod vendor="checkpoint" name="firewall-1">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0040" published="2004-03-03" name="CVE-2004-0040" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Stack-based buffer overflow in Check Point VPN-1 Server 4.1 through 4.1 SP6 and Check Point SecuRemote/SecureClient 4.1 through 4.1 build 4200 allows remote attackers to execute arbitrary code via an ISAKMP packet with a large Certificate Request packet.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/873334" source="CERT-VN" patch="1" adv="1">VU#873334</ref>
      <ref url="http://www.securityfocus.com/bid/9582" source="BID" patch="1" adv="1">9582</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/14150" source="XF" adv="1">vpn1-ike-bo(14150)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107604682227031&amp;w=2" source="BUGTRAQ" adv="1">20040205 Two checkpoint fw-1/vpn-1 vulns</ref>
      <ref url="http://xforce.iss.net/xforce/alerts/id/163" source="ISS">20040204 Checkpoint VPN-1/SecureClient ISAKMP Buffer Overflow</ref>
      <ref url="http://www.osvdb.org/4432" source="OSVDB">4432</ref>
      <ref url="http://www.osvdb.org/3821" source="OSVDB">3821</ref>
      <ref url="http://www.ciac.org/ciac/bulletins/o-073.shtml" source="CIAC">O-073</ref>
    </refs>
    <vuln_soft>
      <prod vendor="checkpoint" name="firewall-1">
        <vers num="4.1" edition="sp1" />
        <vers num="4.1" edition="sp2" />
        <vers num="4.1" edition="sp3" />
        <vers num="4.1" edition="sp4" />
        <vers num="4.1" edition="sp5" />
        <vers num="4.1" edition="sp5a" />
        <vers num="next_generation_fp0" />
        <vers num="next_generation_fp1" />
      </prod>
      <prod vendor="checkpoint" name="vpn-1">
        <vers num="4.1" edition="sp5a" />
        <vers num="next_generation_fp0" />
        <vers num="next_generation_fp1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0041" published="2004-02-03" name="CVE-2004-0041" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">The mod_auth_shadow module 1.4 and earlier does not properly enforce the expiration of a user account and password, which could allow remote authenticated users to bypass intended access restrictions.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.debian.org/security/2004/dsa-421" source="DEBIAN" patch="1" adv="1">DSA-421</ref>
      <ref url="http://www.securitytracker.com/id?1008675" source="SECTRACK">1008675</ref>
      <ref url="http://www.securityfocus.com/bid/9404" source="BID" adv="1">9404</ref>
      <ref url="http://www.osvdb.org/3454" source="OSVDB">3454</ref>
      <ref url="http://secunia.com/advisories/10612" source="SECUNIA" adv="1">10612</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mod_auth_shadow" name="mod_auth_shadow">
        <vers num="1.0" />
        <vers num="1.1" />
        <vers num="1.2" />
        <vers num="1.3" />
        <vers num="1.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0042" published="2004-02-03" name="CVE-2004-0042" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">vsftpd 1.1.3 generates different error messages depending on whether or not a valid username exists, which allows remote attackers to identify valid usernames.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://securitytracker.com/id?1008628" source="SECTRACK">1008628</ref>
    </refs>
    <vuln_soft>
      <prod vendor="beasts" name="vsftpd">
        <vers num="1.1.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0043" published="2004-02-03" name="CVE-2004-0043" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in Yahoo Instant Messenger 5.6.0.1351 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long filename in the download feature.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/9383" source="BID">9383</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2004-January/015334.html" source="FULLDISC">20040108 Yahoo Instant Messenger Long Filename Downloading Buffer Overflow</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/14171" source="XF">yahoo-messenger-filename-bo(14171)</ref>
      <ref url="http://www.securitytracker.com/id?1008651" source="SECTRACK">1008651</ref>
      <ref url="http://www.osvdb.org/3437" source="OSVDB">3437</ref>
      <ref url="http://secunia.com/advisories/10573" source="SECUNIA">10573</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107357996802255&amp;w=2" source="BUGTRAQ">20040108 Yahoo Instant Messenger Long Filename Downloading Buffer Overflow</ref>
    </refs>
    <vuln_soft>
      <prod vendor="yahoo" name="messenger">
        <vers prev="1" num="5.6.0.1351" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0044" published="2004-02-03" name="CVE-2004-0044" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Cisco Personal Assistant 1.4(1) and 1.4(2) disables password authentication when "Allow Only Cisco CallManager Users" is enabled and the Corporate Directory settings refer to the directory service being used by Cisco CallManager, which allows remote attackers to gain access with a valid username.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <config />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.cisco.com/warp/public/707/cisco-sa-20040108-pa.shtml" source="CISCO" patch="1" adv="1">20040108 Cisco Personal Assistant User Password Bypass Vulnerability</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/14172" source="XF">ciscopersonalassistant-config-file-access(14172)</ref>
      <ref url="http://www.securityfocus.com/bid/9384" source="BID">9384</ref>
      <ref url="http://www.osvdb.org/3430" source="OSVDB">3430</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="personal_assistant">
        <vers num="1.4(1)" />
        <vers num="1.4(2)" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0045" published="2004-02-03" name="CVE-2004-0045" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in the ARTpost function in art.c in the control message handling code for INN 2.4.0 may allow remote attackers to execute arbitrary code.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/759020" source="CERT-VN">VU#759020</ref>
      <ref url="http://www.securityfocus.com/bid/9382" source="BID" patch="1" adv="1">9382</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2004-01/0064.html" source="BUGTRAQ" patch="1" adv="1">20040108 [OpenPKG-SA-2004.001] OpenPKG Security Advisory (inn)</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2004-01/0063.html" source="BUGTRAQ" patch="1" adv="1">20040107 [SECURITY] INN: Buffer overflow in control message handling</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/14190" source="XF">inn-artpost-control-message-bo(14190)</ref>
      <ref url="http://www.slackware.org/security/viewer.php?l=slackware-security&amp;y=2004&amp;m=slackware-security.365791" source="SLACKWARE">SSA:2004-014-02</ref>
      <ref url="http://secunia.com/advisories/10578" source="SECUNIA">10578</ref>
    </refs>
    <vuln_soft>
      <prod vendor="isc" name="inn">
        <vers num="2.4.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0046" published="2004-02-03" name="CVE-2004-0046" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in SnapStream PVS LITE allows remote attackers to inject arbitrary web script or HTML via a GET request containing a terminating '"' (double quote) character.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/14164" source="XF">snapstream-quotation-xss(14164)</ref>
      <ref url="http://www.securityfocus.com/bid/9375" source="BID" adv="1">9375</ref>
      <ref url="http://www.osvdb.org/3440" source="OSVDB">3440</ref>
      <ref url="http://securitytracker.com/id?1008646" source="SECTRACK">1008646</ref>
      <ref url="http://secunia.com/advisories/10575" source="SECUNIA">10575</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107350313917867&amp;w=2" source="BUGTRAQ" adv="1">20040106 SnapStream PVS LITE Cross Site Scripting Vulnerabillity</ref>
    </refs>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0047" published="2004-03-03" name="CVE-2004-0047" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Multiple programs in trr19 1.0 do not properly drop privileges before executing a system command, which could allow local users to gain privileges.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.debian.org/security/2004/dsa-430" source="DEBIAN" patch="1" adv="1">DSA-430</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/14975" source="XF">trr19-gain-privileges(14975)</ref>
      <ref url="http://www.securityfocus.com/bid/9520" source="BID" adv="1">9520</ref>
      <ref url="http://secunia.com/advisories/10744/" source="SECUNIA">10744</ref>
      <ref url="http://www.securitytracker.com/id?1008875" source="SECTRACK">1008875</ref>
      <ref url="http://www.osvdb.org/3747" source="OSVDB">3747</ref>
      <ref url="http://secunia.com/advisories/10745" source="SECUNIA">10745</ref>
    </refs>
    <vuln_soft>
      <prod vendor="yamamoto_hirotaka" name="trr19">
        <vers num="1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0049" published="2004-02-17" name="CVE-2004-0049" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:S/C:N/I:N/A:C)" CVSS_score="6.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="8.0" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Helix Universal Server/Proxy 9 and Mobile Server 10 allow remote attackers to cause a denial of service via certain HTTP POST messages to the Administration System port.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://service.real.com/help/faq/security/040112_dos/" source="CONFIRM" patch="1" adv="1">http://service.real.com/help/faq/security/040112_dos/</ref>
      <ref url="http://www.securityfocus.com/bid/9421" source="BID" adv="1">9421</ref>
      <ref url="http://service.real.com/help/faq/security/security022604.html" source="CONFIRM">http://service.real.com/help/faq/security/security022604.html</ref>
      <ref url="http://www.securityfocus.com/archive/1/357834" source="BUGTRAQ">20040318 ptl-2004-02: RealNetworks Helix Server 9 Administration Server Buffer Overflow</ref>
      <ref url="http://seclists.org/lists/vulnwatch/2004/Jan-Mar/0057.html" source="VULNWATCH">20040318 ptl-2004-02: RealNetworks Helix Server 9 Administration Server Buffer Overflow</ref>
    </refs>
    <vuln_soft>
      <prod vendor="realnetworks" name="helix_universal_mobile_server">
        <vers prev="1" num="10.1.1.120" />
      </prod>
      <prod vendor="realnetworks" name="helix_universal_server">
        <vers prev="1" num="9.0.2.881" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0050" published="2004-06-14" name="CVE-2004-0050" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Verity Ultraseek before 5.2.2 allows remote attackers to obtain the full pathname of the document root via an MS-DOS device name in the web search option, such as (1) NUL, (2) CON, (3) AUX, (4) COM1, (5) COM2, and others.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/16066" source="XF" patch="1" adv="1">ultraseek-error-path-disclosure(16066)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108377388114888&amp;w=2" source="BUGTRAQ" adv="1">20040505 Corsaire Security Advisory - Verity Ultraseek path disclosure issue</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2004-May/020952.html" source="FULLDISC">20040505 Corsaire Security Advisory - Verity Ultraseek path disclosure issue</ref>
      <ref url="http://archives.neohapsis.com/archives/vulnwatch/2004-q2/0024.html" source="VULNWATCH" adv="1">20040505 Corsaire Security Advisory - Verity Ultraseek path disclosure issue</ref>
    </refs>
    <vuln_soft>
      <prod vendor="verity" name="ultraseek">
        <vers prev="1" num="5.2.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0051" published="2004-10-20" name="CVE-2004-0051" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple content security gateway and antivirus products allow remote attackers to bypass content restrictions via MIME messages that use non-standard but frequently supported Content-Transfer-Encoding values such as (1) uuencode, (2) mac-binhex40, and (3) yenc, which may be interpreted differently by mail clients.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/17337" source="XF">mime-contenttransfer-filter-bypass(17337)</ref>
      <ref url="http://www.uniras.gov.uk/vuls/2004/380375/mime.htm" source="MISC" adv="1">http://www.uniras.gov.uk/vuls/2004/380375/mime.htm</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109517788100063&amp;w=2" source="BUGTRAQ" adv="1">20040914 Corsaire Security Advisory - Multiple vendor MIME Content-Transfer-Encoding mechanism issue</ref>
    </refs>
    <vuln_soft>
      <prod vendor="clearswift" name="mailsweeper">
        <vers num="4.3.10" />
        <vers num="4.3.11" />
        <vers num="4.3.13" />
        <vers num="4.3.14" />
        <vers num="4.3.15" />
        <vers num="4.3.7" />
        <vers num="4.3.8" />
      </prod>
      <prod vendor="f-secure" name="internet_gatekeeper">
        <vers num="6.3" />
        <vers num="6.31" />
        <vers num="6.32" />
        <vers num="6.4" />
      </prod>
      <prod vendor="paul_l_daniels" name="ripmime">
        <vers num="1.2.0" />
        <vers num="1.2.1" />
        <vers num="1.2.2" />
        <vers num="1.2.3" />
        <vers num="1.2.4" />
        <vers num="1.2.5" />
        <vers num="1.2.6" />
        <vers num="1.2.7" />
        <vers num="1.3.2.0" />
        <vers num="1.3.2.2" />
        <vers num="1.3.2.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0052" published="2004-10-20" name="CVE-2004-0052" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple content security gateway and antivirus products allow remote attackers to bypass content restrictions via MIME messages that use non-standard separator characters, or use standard separators incorrectly, within MIME headers, fields, parameters, or values, which may be interpreted differently by mail clients.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/17334" source="XF">mime-separator-filtering-bypass(17334)</ref>
      <ref url="http://www.uniras.gov.uk/vuls/2004/380375/mime.htm" source="MISC" adv="1">http://www.uniras.gov.uk/vuls/2004/380375/mime.htm</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109517669115891&amp;w=2" source="BUGTRAQ" adv="1">20040914 Corsaire Security Advisory - Multiple vendor MIME separator issue</ref>
    </refs>
    <vuln_soft>
      <prod vendor="clearswift" name="mailsweeper">
        <vers num="4.3.10" />
        <vers num="4.3.11" />
        <vers num="4.3.13" />
        <vers num="4.3.14" />
        <vers num="4.3.15" />
        <vers num="4.3.7" />
        <vers num="4.3.8" />
      </prod>
      <prod vendor="f-secure" name="internet_gatekeeper">
        <vers num="6.3" />
        <vers num="6.31" />
        <vers num="6.32" />
        <vers num="6.4" />
      </prod>
      <prod vendor="paul_l_daniels" name="ripmime">
        <vers num="1.2.0" />
        <vers num="1.2.1" />
        <vers num="1.2.2" />
        <vers num="1.2.3" />
        <vers num="1.2.4" />
        <vers num="1.2.5" />
        <vers num="1.2.6" />
        <vers num="1.2.7" />
        <vers num="1.3.2.0" />
        <vers num="1.3.2.2" />
        <vers num="1.3.2.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0053" published="2004-10-20" name="CVE-2004-0053" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple content security gateway and antivirus products allow remote attackers to bypass content restrictions via MIME messages that use fields that use RFC2047 encoding, which may be interpreted differently by mail clients.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/17331" source="XF">mime-rfc2047-filtering-bypass(17331)</ref>
      <ref url="http://www.uniras.gov.uk/vuls/2004/380375/mime.htm" source="MISC" adv="1">http://www.uniras.gov.uk/vuls/2004/380375/mime.htm</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109520704408739&amp;w=2" source="BUGTRAQ" adv="1">20040914 Corsaire Security Advisory - Multiple vendor MIME RFC2047 encoding issue</ref>
    </refs>
    <vuln_soft>
      <prod vendor="clearswift" name="mailsweeper">
        <vers num="4.3.10" />
        <vers num="4.3.11" />
        <vers num="4.3.13" />
        <vers num="4.3.14" />
        <vers num="4.3.15" />
        <vers num="4.3.7" />
        <vers num="4.3.8" />
      </prod>
      <prod vendor="f-secure" name="internet_gatekeeper">
        <vers num="6.3" />
        <vers num="6.31" />
        <vers num="6.32" />
        <vers num="6.4" />
      </prod>
      <prod vendor="paul_l_daniels" name="ripmime">
        <vers num="1.2.0" />
        <vers num="1.2.1" />
        <vers num="1.2.2" />
        <vers num="1.2.3" />
        <vers num="1.2.4" />
        <vers num="1.2.5" />
        <vers num="1.2.6" />
        <vers num="1.2.7" />
        <vers num="1.3.2.0" />
        <vers num="1.3.2.2" />
        <vers num="1.3.2.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0054" published="2004-02-17" name="CVE-2004-0054" modified="2009-03-04" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple vulnerabilities in the H.323 protocol implementation for Cisco IOS 11.3T through 12.2T allow remote attackers to cause a denial of service and possibly execute arbitrary code, as demonstrated by the NISCC/OUSPG PROTOS test suite for the H.225 protocol.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/749342" source="CERT-VN" patch="1" adv="1">VU#749342</ref>
      <ref url="http://www.cert.org/advisories/CA-2004-01.html" source="CERT" patch="1" adv="1">CA-2004-01</ref>
      <ref url="http://www.cisco.com/warp/public/707/cisco-sa-20040113-h323.shtml" source="CISCO" patch="1" adv="1">20040113 Vulnerabilities in H.323 Message Processing</ref>
      <ref url="http://www.uniras.gov.uk/vuls/2004/006489/h323.htm" source="MISC">http://www.uniras.gov.uk/vuls/2004/006489/h323.htm</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:4884" source="OVAL">oval:org.mitre.oval:def:4884</ref>
      <ref url="http://www.securitytracker.com/id?1008685" source="SECTRACK">1008685</ref>
      <ref url="http://www.securityfocus.com/bid/9406" source="BID">9406</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="ios">
        <vers num="11.3t" />
        <vers num="12.0" />
        <vers num="12.0s" />
        <vers num="12.0t" />
        <vers num="12.1" />
        <vers num="12.1e" />
        <vers num="12.1t" />
        <vers num="12.2" />
        <vers num="12.2s" />
        <vers num="12.2t" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0055" published="2004-02-17" name="CVE-2004-0055" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The print_attr_string function in print-radius.c for tcpdump 3.8.1 and earlier allows remote attackers to cause a denial of service (segmentation fault) via a RADIUS attribute with a large length value.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/955526" source="CERT-VN" adv="1">VU#955526</ref>
      <ref url="http://www.securityfocus.com/bid/7090" source="BID" patch="1" adv="1">7090</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-008.html" source="REDHAT" patch="1" adv="1">RHSA-2004:008</ref>
      <ref url="http://www.redhat.com/archives/fedora-announce-list/2004-March/msg00015.html" source="MLIST">[fedora-announce-list] 20040311 Re: [SECURITY] Fedora Core 1 Update: tcpdump-3.7.2-8.fc1.1</ref>
      <ref url="http://www.redhat.com/archives/fedora-announce-list/2004-March/msg00009.html" source="FEDORA">FEDORA-2004-092</ref>
      <ref url="http://www.redhat.com/archives/fedora-announce-list/2004-March/msg00006.html" source="FEDORA">FEDORA-2004-090</ref>
      <ref url="http://www.debian.org/security/2004/dsa-425" source="DEBIAN">DSA-425</ref>
      <ref url="http://secunia.com/advisories/12179/" source="SECUNIA">12179</ref>
      <ref url="http://secunia.com/advisories/11032/" source="SECUNIA">11032</ref>
      <ref url="http://secunia.com/advisories/11022" source="SECUNIA">11022</ref>
      <ref url="http://secunia.com/advisories/10718" source="SECUNIA">10718</ref>
      <ref url="http://secunia.com/advisories/10652" source="SECUNIA">10652</ref>
      <ref url="http://secunia.com/advisories/10644" source="SECUNIA">10644</ref>
      <ref url="http://secunia.com/advisories/10639" source="SECUNIA">10639</ref>
      <ref url="http://secunia.com/advisories/10636" source="SECUNIA">10636</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9989" source="OVAL">oval:org.mitre.oval:def:9989</ref>
      <ref url="http://lwn.net/Alerts/66445/" source="TRUSTIX">2004-0004</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2004/Feb/msg00000.html" source="APPLE">APPLE-SA-2004-02-23</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/20040103-01-U.asc" source="SGI">20040103-01-U</ref>
      <ref url="ftp://ftp.sco.com/pub/updates/UnixWare/SCOSA-2004.9/SCOSA-2004.9.txt" source="SCO">SCOSA-2004.9</ref>
      <ref url="ftp://ftp.sco.com/pub/security/OpenLinux/CSSA-2004-008.0.txt" source="CALDERA">CSSA-2004-008.0</ref>
      <ref url="http://www.securitytracker.com/id?1008735" source="SECTRACK">1008735</ref>
      <ref url="http://www.redhat.com/archives/fedora-legacy-list/2004-January/msg00726.html" source="FEDORA">FLSA:1222</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2004:008" source="MANDRAKE">MDKSA-2004:008</ref>
      <ref url="http://marc.theaimsgroup.com/?l=tcpdump-workers&amp;m=107325073018070&amp;w=2" source="MLIST">[tcpdump-workers] multiple vulnerabilities in tcpdump 3.8.1</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107577418225627&amp;w=2" source="BUGTRAQ">20040131 [FLSA-2004:1222] Updated tcpdump resolves security vulnerabilites (resend with correct paths)</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000832" source="CONECTIVA">CLSA-2003:832</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/20040202-01-U.asc" source="SGI">20040202-01-U</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:853" source="OVAL" sig="1">oval:org.mitre.oval:def:853</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:850" source="OVAL" sig="1">oval:org.mitre.oval:def:850</ref>
    </refs>
    <vuln_soft>
      <prod vendor="lbl" name="tcpdump">
        <vers num="3.5.2" />
        <vers num="3.6.2" />
        <vers num="3.7" />
        <vers num="3.7.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0056" published="2004-02-17" name="CVE-2004-0056" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple vulnerabilities in the H.323 protocol implementation for Nortel Networks Business Communications Manager (BCM), Succession 1000 IP Trunk and IP Peer Networking, and 802.11 Wireless IP Gateway allow remote attackers to cause a denial of service and possibly execute arbitrary code, as demonstrated by the NISCC/OUSPG PROTOS test suite for the H.225 protocol.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/749342" source="CERT-VN" patch="1" adv="1">VU#749342</ref>
      <ref url="http://www.cert.org/advisories/CA-2004-01.html" source="CERT" patch="1" adv="1">CA-2004-01</ref>
      <ref url="http://www.uniras.gov.uk/vuls/2004/006489/h323.htm" source="MISC">http://www.uniras.gov.uk/vuls/2004/006489/h323.htm</ref>
      <ref url="http://www.securitytracker.com/id?1008687" source="SECTRACK">1008687</ref>
      <ref url="http://www.securityfocus.com/bid/9406" source="BID">9406</ref>
    </refs>
    <vuln_soft>
      <prod vendor="nortel" name="business_communications_manager">
        <vers num="" />
      </prod>
      <prod vendor="nortel" name="802.11_wireless_ip_gateway">
        <vers num="" />
      </prod>
      <prod vendor="nortel" name="succession_communication_server_1000">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0057" published="2004-02-17" name="CVE-2004-0057" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The rawprint function in the ISAKMP decoding routines (print-isakmp.c) for tcpdump 3.8.1 and earlier allows remote attackers to cause a denial of service (segmentation fault) via malformed ISAKMP packets that cause invalid "len" or "loc" values to be used in a loop, a different vulnerability than CVE-2003-0989.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/174086" source="CERT-VN">VU#174086</ref>
      <ref url="http://www.securityfocus.com/bid/9423" source="BID" patch="1" adv="1">9423</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-007.html" source="REDHAT" patch="1" adv="1">RHSA-2004:007</ref>
      <ref url="http://www.debian.org/security/2004/dsa-425" source="DEBIAN" patch="1" adv="1">DSA-425</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/14837" source="XF">tcpdump-rawprint-isakmp-dos(14837)</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/350238/30/21640/threaded" source="BUGTRAQ">20040119 [ESA-20040119-002] 'tcpdump' multiple vulnerabilities.</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-008.html" source="REDHAT">RHSA-2004:008</ref>
      <ref url="http://www.redhat.com/archives/fedora-announce-list/2004-March/msg00015.html" source="MLIST">[fedora-announce-list] 20040311 Re: [SECURITY] Fedora Core 1 Update: tcpdump-3.7.2-8.fc1.1</ref>
      <ref url="http://www.redhat.com/archives/fedora-announce-list/2004-March/msg00009.html" source="FEDORA">FEDORA-2004-092</ref>
      <ref url="http://www.redhat.com/archives/fedora-announce-list/2004-March/msg00006.html" source="FEDORA">FEDORA-2004-090</ref>
      <ref url="http://secunia.com/advisories/12179/" source="SECUNIA">12179</ref>
      <ref url="http://secunia.com/advisories/11032/" source="SECUNIA">11032</ref>
      <ref url="http://secunia.com/advisories/11022" source="SECUNIA">11022</ref>
      <ref url="http://secunia.com/advisories/10718" source="SECUNIA">10718</ref>
      <ref url="http://secunia.com/advisories/10668" source="SECUNIA">10668</ref>
      <ref url="http://secunia.com/advisories/10652" source="SECUNIA">10652</ref>
      <ref url="http://secunia.com/advisories/10644" source="SECUNIA">10644</ref>
      <ref url="http://secunia.com/advisories/10639" source="SECUNIA">10639</ref>
      <ref url="http://secunia.com/advisories/10636" source="SECUNIA">10636</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11197" source="OVAL">oval:org.mitre.oval:def:11197</ref>
      <ref url="http://marc.theaimsgroup.com/?l=tcpdump-workers&amp;m=107325073018070&amp;w=2" source="MLIST" adv="1">[tcpdump-workers] multiple vulnerabilities in tcpdump 3.8.1</ref>
      <ref url="http://lwn.net/Alerts/66805/" source="ENGARDE">ESA-20040119-002</ref>
      <ref url="http://lwn.net/Alerts/66445/" source="TRUSTIX">2004-0004</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2004/Feb/msg00000.html" source="APPLE">APPLE-SA-2004-02-23</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/20040103-01-U.asc" source="SGI">20040103-01-U</ref>
      <ref url="ftp://ftp.sco.com/pub/updates/UnixWare/SCOSA-2004.9/SCOSA-2004.9.txt" source="SCO">SCOSA-2004.9</ref>
      <ref url="ftp://ftp.sco.com/pub/security/OpenLinux/CSSA-2004-008.0.txt" source="CALDERA">CSSA-2004-008.0</ref>
      <ref url="http://www.securitytracker.com/id?1008716" source="SECTRACK">1008716</ref>
      <ref url="http://www.redhat.com/archives/fedora-legacy-list/2004-January/msg00726.html" source="FEDORA">FLSA:1222</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2004:008" source="MANDRAKE">MDKSA-2004:008</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107577418225627&amp;w=2" source="BUGTRAQ">20040131 [FLSA-2004:1222] Updated tcpdump resolves security vulnerabilites (resend with correct paths)</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/20040202-01-U.asc" source="SGI">20040202-01-U</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:854" source="OVAL" sig="1">oval:org.mitre.oval:def:854</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:851" source="OVAL" sig="1">oval:org.mitre.oval:def:851</ref>
    </refs>
    <vuln_soft>
      <prod vendor="lbl" name="tcpdump">
        <vers prev="1" num="3.8.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2004-0058" published="2004-02-17" name="CVE-2004-0058" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">Antivir / Linux 2.0.9-9, and possibly earlier versions, allows local users to overwrite arbitrary files via a symlink attack on the .pid_antivir_$$ temporary file.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/14214" source="XF">antivir-tmpfile-insecure(14214)</ref>
      <ref url="http://www.securitytracker.com/id?1008702" source="SECTRACK">1008702</ref>
      <ref url="http://www.osvdb.org/3496" source="OSVDB">3496</ref>
      <ref url="http://secunia.com/advisories/10620" source="SECUNIA">10620</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107402026023763&amp;w=2" source="BUGTRAQ">20040113 symlink vul for Antivir / Linux Version 2.0.9-9 (maybe lower)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="linux" name="linux_kernel">
        <vers prev="1" num="2.0.9.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0059" published="2004-02-17" name="CVE-2004-0059" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in upload capability of WWW File Share Pro 2.42 and earlier allows remote attackers to overwrite arbitrary files via .. (dot dot) sequences in the filename parameter of a Content-Disposition: header.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securitytracker.com/id?1008779" source="SECTRACK">1008779</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107411794303201&amp;w=2" source="BUGTRAQ">20040114 Multiple vulnerabilities in WWW Fileshare Pro &lt;= 2.42</ref>
    </refs>
    <vuln_soft>
      <prod vendor="lionmax_software" name="www_file_share_pro">
        <vers prev="1" num="2.42" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0060" published="2004-02-17" name="CVE-2004-0060" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">WWW File Share Pro 2.42 and earlier allows remote attackers to cause a denial of service (crash) via a large POST request.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securitytracker.com/id?1008779" source="SECTRACK">1008779</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107411794303201&amp;w=2" source="BUGTRAQ">20040114 Multiple vulnerabilities in WWW Fileshare Pro &lt;= 2.42</ref>
    </refs>
    <vuln_soft>
      <prod vendor="lionmax_software" name="www_file_share_pro">
        <vers prev="1" num="2.42" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0061" published="2004-02-17" name="CVE-2004-0061" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">WWW File Share Pro 2.42 and earlier allows remote attackers to bypass directory access restrictions via (1) a URL with a trailing . (dot), or (2) a URI with a leading slash or backslash character.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securitytracker.com/id?1008779" source="SECTRACK">1008779</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107411794303201&amp;w=2" source="BUGTRAQ">20040114 Multiple vulnerabilities in WWW Fileshare Pro &lt;= 2.42</ref>
    </refs>
    <vuln_soft>
      <prod vendor="lionmax_software" name="www_file_share_pro">
        <vers prev="1" num="2.42" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0062" published="2004-02-17" name="CVE-2004-0062" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Integer overflow in the rnd arithmetic rounding function for various versions of FishCart before 3.1 allows remote attackers to "cause negative totals" via an order with a large quantity.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input bound="1" />
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107411850203994&amp;w=2" source="BUGTRAQ" adv="1">20040114 FishCart Integer Overflow / Rounding Error</ref>
      <ref url="http://www.securitytracker.com/id?1008731" source="SECTRACK">1008731</ref>
    </refs>
    <vuln_soft>
      <prod vendor="fishnet" name="fishcart">
        <vers prev="1" num="3.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0063" published="2004-02-17" name="CVE-2004-0063" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">The SPP_VerifyPVV function in nCipher payShield SPP library 1.3.12, 1.5.18 and 1.6.18 returns a Status_OK value even if the HSM returns a different status code, which could cause applications to make incorrect security-critical decisions, e.g. by accepting an invalid PIN number.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.ncipher.com/support/advisories/advisory8_payshield.html" source="CONFIRM" adv="1">http://www.ncipher.com/support/advisories/advisory8_payshield.html</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/14832" source="XF">payshield-incorrect-request-verification(14832)</ref>
      <ref url="http://www.securityfocus.com/bid/9422" source="BID">9422</ref>
      <ref url="http://www.osvdb.org/3537" source="OSVDB">3537</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107411819503569&amp;w=2" source="BUGTRAQ">20040114 nCipher Advisory #8: payShield library may verify bad requests</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ncipher" name="payshield_spp_library">
        <vers num="1.3.12" />
        <vers num="1.5.18" />
        <vers num="1.6.18" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2004-0064" published="2004-02-17" name="CVE-2004-0064" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">The SuSEconfig.gnome-filesystem script for YaST in SuSE 9.0 allows local users to overwrite arbitrary files via a symlink attack on files within the tmp.SuSEconfig.gnome-filesystem.$RANDOM temporary directory.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <other />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/9411" source="BID" adv="1">9411</ref>
      <ref url="http://www.securitytracker.com/id?1008703" source="SECTRACK">1008703</ref>
      <ref url="http://www.osvdb.org/3460" source="OSVDB">3460</ref>
      <ref url="http://secunia.com/advisories/10623" source="SECUNIA">10623</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107402658600437&amp;w=2" source="BUGTRAQ">20040113 SuSE linux 9.0 YaST config Skribt [exploit]</ref>
    </refs>
    <vuln_soft>
      <prod vendor="suse" name="suse_linux">
        <vers num="9.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0065" published="2004-02-17" name="CVE-2004-0065" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple SQL injection vulnerabilities in phpGedView before 2.65 allow remote attackers to execute arbitrary SQL via (1) timeline.php and (2) placelist.php.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107394912715478&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20040112 More phpGedView Vulnerabilities</ref>
      <ref url="http://www.securityfocus.com/bid/11925" source="BID">11925</ref>
      <ref url="http://www.securityfocus.com/bid/11910" source="BID">11910</ref>
    </refs>
    <vuln_soft>
      <prod vendor="phpgedview" name="phpgedview">
        <vers prev="1" num="2.65" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0066" published="2004-02-17" name="CVE-2004-0066" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">phpGedView before 2.65 allows remote attackers to obtain the absolute path of the web server via malformed parameters to (1) indilist.php, (2) famlist.php, (3) placelist.php, (4) imageview.php, (5) timeline.php, (6) clippings.php, (7) login.php, and (8) gdbi.php.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107394912715478&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20040112 More phpGedView Vulnerabilities</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/14215" source="XF">phpgedview-path-disclosure(14215)</ref>
      <ref url="http://www.osvdb.org/3464" source="OSVDB">3464</ref>
    </refs>
    <vuln_soft>
      <prod vendor="phpgedview" name="phpgedview">
        <vers prev="1" num="2.65" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0067" published="2004-02-17" name="CVE-2004-0067" modified="2011-09-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in phpGedView before 2.65 allow remote attackers to inject arbitrary HTML or web script via (1) descendancy.php, (2) index.php, (3) individual.php, (4) login.php, (5) relationship.php, (6) source.php, (7) imageview.php, (8) calendar.php, (9) gedrecord.php, (10) login.php, and (11) gdbi_interface.php.  NOTE: some aspects of vector 10 were later reported to affect 4.1.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107394912715478&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20040112 More phpGedView Vulnerabilities</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/36285" source="XF">phpgedview-login-xss(36285)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/14212" source="XF">phpgedview-multiple-xss(14212)</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/2995" source="VUPEN" adv="1">ADV-2007-2995</ref>
      <ref url="http://www.securityfocus.com/bid/11907" source="BID">11907</ref>
      <ref url="http://www.securityfocus.com/bid/11906" source="BID">11906</ref>
      <ref url="http://www.securityfocus.com/bid/11905" source="BID">11905</ref>
      <ref url="http://www.securityfocus.com/bid/11904" source="BID">11904</ref>
      <ref url="http://www.securityfocus.com/bid/11903" source="BID">11903</ref>
      <ref url="http://www.securityfocus.com/bid/11894" source="BID">11894</ref>
      <ref url="http://www.securityfocus.com/bid/11891" source="BID">11891</ref>
      <ref url="http://www.securityfocus.com/bid/11890" source="BID">11890</ref>
      <ref url="http://www.securityfocus.com/bid/11888" source="BID">11888</ref>
      <ref url="http://www.securityfocus.com/bid/11882" source="BID">11882</ref>
      <ref url="http://www.securityfocus.com/bid/11880" source="BID">11880</ref>
      <ref url="http://www.securityfocus.com/bid/11868" source="BID">11868</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/477881/100/0/threaded" source="BUGTRAQ">20070827 PhpGedView login page multiple XSS</ref>
      <ref url="http://www.osvdb.org/3479" source="OSVDB">3479</ref>
      <ref url="http://www.osvdb.org/3478" source="OSVDB">3478</ref>
      <ref url="http://www.osvdb.org/3477" source="OSVDB">3477</ref>
      <ref url="http://www.osvdb.org/3476" source="OSVDB">3476</ref>
      <ref url="http://www.osvdb.org/3475" source="OSVDB">3475</ref>
      <ref url="http://www.osvdb.org/3474" source="OSVDB">3474</ref>
      <ref url="http://www.osvdb.org/3473" source="OSVDB">3473</ref>
      <ref url="http://securitytracker.com/id?1018613" source="SECTRACK">1018613</ref>
      <ref url="http://secunia.com/advisories/26628" source="SECUNIA" adv="1">26628</ref>
    </refs>
    <vuln_soft>
      <prod vendor="phpgedview" name="phpgedview">
        <vers prev="1" num="2.65" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0068" published="2004-02-17" name="CVE-2004-0068" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">PHP remote file inclusion vulnerability in config.php for PhpDig 1.6.5 and earlier allows remote attackers to execute arbitrary PHP code by modifying the $relative_script_path parameter to reference a URL on a remote web server that contains the code.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/9424" source="BID" patch="1" adv="1">9424</ref>
      <ref url="http://www.phpdig.net/showthread.php?s=58bcc71c822830ec3bbdaae6d56846e0&amp;threadid=393" source="CONFIRM" patch="1">http://www.phpdig.net/showthread.php?s=58bcc71c822830ec3bbdaae6d56846e0&amp;threadid=393</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107412194008671&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20040114 PhpDig 1.6.x: remote command execution</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/14826" source="XF">phpdig-config-file-include(14826)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="phpdig.net" name="phpdig">
        <vers prev="1" num="1.6.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0069" published="2004-02-17" name="CVE-2004-0069" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Format string vulnerability in HD Soft Windows FTP Server 1.6 and earlier allows remote attackers to execute arbitrary code via format string specifiers in the username, which is processed by the wscanf function.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/9385" source="BID" adv="1">9385</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107401398014761&amp;w=2" source="BUGTRAQ">20040113 exploit for HD Soft Windows FTP Server 1.6</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107367110805273&amp;w=2" source="BUGTRAQ" adv="1">20040108 Windows FTP Server Format String Vulnerability</ref>
      <ref url="http://www.securitytracker.com/id?1008658" source="SECTRACK">1008658</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hd_soft" name="windows_ftp_server">
        <vers prev="1" num="1.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0070" published="2004-02-17" name="CVE-2004-0070" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">PHP remote file inclusion vulnerability in module.php for ezContents allows remote attackers to execute arbitrary PHP code by modifying the link parameter to reference a URL on a remote web server that contains the code.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/14199" source="XF">ezcontents-php-file-include(14199)</ref>
      <ref url="http://www.securityfocus.com/bid/9396" source="BID" adv="1">9396</ref>
      <ref url="http://www.osvdb.org/6878" source="OSVDB">6878</ref>
      <ref url="http://www.ezcontents.org/forum/viewtopic.php?t=361" source="CONFIRM">http://www.ezcontents.org/forum/viewtopic.php?t=361</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107392588915627&amp;w=2" source="BUGTRAQ">20040110 Remote Code Execution in ezContents</ref>
    </refs>
    <vuln_soft>
      <prod vendor="visualshapers" name="ezcontents">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0071" published="2004-02-17" name="CVE-2004-0071" modified="2005-10-20" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in buildManPage in class.manpagelookup.php for PHP Man Page Lookup 1.2.0 allows remote attackers to read arbitrary files via the command parameter ($cmd variable) to index.php.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/14203" source="XF">manpagelookup-directory-traversal(14203)</ref>
      <ref url="http://www.securityfocus.com/bid/9395" source="BID">9395</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107392764118403&amp;w=2" source="BUGTRAQ" adv="1">20040110 PHP Manpage lookup directory transversal / file disclosing</ref>
      <ref url="http://www.securitytracker.com/id?1008689" source="SECTRACK">1008689</ref>
    </refs>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0072" published="2004-02-17" name="CVE-2004-0072" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in Accipiter Direct Server 6.0 allows remote attackers to read arbitrary files via encoded \.. (backslash .., "%5c%2e%2e") sequences in an HTTP request.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/9389" source="BID" patch="1" adv="1">9389</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/14198" source="XF" adv="1">accipterdirectserver-directory-traversal(14198)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107392576215418&amp;w=2" source="BUGTRAQ" adv="1">20040109 Directory Traversal in Accipiter Direct Server 6.0</ref>
      <ref url="http://archives.neohapsis.com/archives/fulldisclosure/2004-01/0274.html" source="FULLDISC">20040109 Directory Traversal in Accipiter Direct Server 6.0</ref>
      <ref url="http://www.osvdb.org/3433" source="OSVDB">3433</ref>
      <ref url="http://secunia.com/advisories/10600" source="SECUNIA">10600</ref>
    </refs>
    <vuln_soft>
      <prod vendor="accipiter" name="accipiter_direct_server">
        <vers num="6.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0073" published="2004-02-17" name="CVE-2004-0073" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">PHP remote file inclusion vulnerability in (1) config.php and (2) config_page.php for EasyDynamicPages 2.0 allows remote attackers to execute arbitrary PHP code by modifying the edp_relative_path parameter to reference a URL on a remote web server that contains a malicious serverdata.php script.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/9338" source="BID" patch="1" adv="1">9338</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/14136" source="XF">easydynamicpages-php-file-include(14136)</ref>
      <ref url="http://www.osvdb.org/3408" source="OSVDB">3408</ref>
      <ref url="http://www.osvdb.org/3318" source="OSVDB">3318</ref>
      <ref url="http://securitytracker.com/id?1008584" source="SECTRACK">1008584</ref>
      <ref url="http://secunia.com/advisories/10535" source="SECUNIA">10535</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107307457327707&amp;w=2" source="BUGTRAQ">20040102 include() vuln in EasyDynamicPages v.2.0</ref>
    </refs>
    <vuln_soft>
      <prod vendor="stoitsov" name="easydynamicpages">
        <vers num="2.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0074" published="2004-02-17" name="CVE-2004-0074" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Multiple buffer overflows in xsok 1.02 allows local users to gain privileges via (1) a long LANG environment variable, or (2) a long -xsokdir command line argument, a different vulnerability than CVE-2003-0949.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/9341" source="BID" patch="1" adv="1">9341</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/14910" source="XF">xsok-lang-bo(14910)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/14906" source="XF" adv="1">xsok-long-xsokdir-bo(14906)</ref>
      <ref url="http://www.securityfocus.com/bid/9352" source="BID" adv="1">9352</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107332542918529&amp;w=2" source="BUGTRAQ">20040103 xsok local games exploit (2)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107307407027259&amp;w=2" source="BUGTRAQ">20040102 xsok local games exploit</ref>
    </refs>
    <vuln_soft>
      <prod vendor="michael_bischoff" name="xsok">
        <vers num="1.02" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2004-0075" published="2004-03-15" name="CVE-2004-0075" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">The Vicam USB driver in Linux before 2.4.25 does not use the copy_from_user function when copying data from userspace to kernel space, which crosses security boundaries and allows local users to cause a denial of service.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/9690" source="BID" patch="1" adv="1">9690</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-065.html" source="REDHAT" patch="1" adv="1">RHSA-2004:065</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15246" source="XF" adv="1">linux-vicam-dos(15246)</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-293.html" source="REDHAT">RHSA-2005:293</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2004_05_linux_kernel.html" source="SUSE">SuSE-SA:2004:005</ref>
      <ref url="http://www.ciac.org/ciac/bulletins/o-082.shtml" source="CIAC">O-082</ref>
      <ref url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2004:015" source="MANDRAKE">MDKSA-2004:015</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000846" source="CONECTIVA">CLA-2004:846</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:836" source="OVAL" sig="1">oval:org.mitre.oval:def:836</ref>
    </refs>
    <vuln_soft>
      <prod vendor="linux" name="linux_kernel">
        <vers num="2.4.0" edition="test1" />
        <vers num="2.4.0" edition="test10" />
        <vers num="2.4.0" edition="test11" />
        <vers num="2.4.0" edition="test12" />
        <vers num="2.4.0" edition="test2" />
        <vers num="2.4.0" edition="test3" />
        <vers num="2.4.0" edition="test4" />
        <vers num="2.4.0" edition="test5" />
        <vers num="2.4.0" edition="test6" />
        <vers num="2.4.0" edition="test7" />
        <vers num="2.4.0" edition="test8" />
        <vers num="2.4.0" edition="test9" />
        <vers num="2.4.1" />
        <vers num="2.4.10" />
        <vers num="2.4.11" />
        <vers num="2.4.12" />
        <vers num="2.4.13" />
        <vers num="2.4.14" />
        <vers num="2.4.15" />
        <vers num="2.4.16" />
        <vers num="2.4.17" />
        <vers num="2.4.18" edition="" />
        <vers num="2.4.18" edition=":x86" />
        <vers num="2.4.18" edition="pre1" />
        <vers num="2.4.18" edition="pre2" />
        <vers num="2.4.18" edition="pre3" />
        <vers num="2.4.18" edition="pre4" />
        <vers num="2.4.18" edition="pre5" />
        <vers num="2.4.18" edition="pre6" />
        <vers num="2.4.18" edition="pre7" />
        <vers num="2.4.18" edition="pre8" />
        <vers num="2.4.19" edition="pre1" />
        <vers num="2.4.19" edition="pre2" />
        <vers num="2.4.19" edition="pre3" />
        <vers num="2.4.19" edition="pre4" />
        <vers num="2.4.19" edition="pre5" />
        <vers num="2.4.19" edition="pre6" />
        <vers num="2.4.2" />
        <vers num="2.4.20" />
        <vers num="2.4.21" edition="pre1" />
        <vers num="2.4.21" edition="pre4" />
        <vers num="2.4.21" edition="pre7" />
        <vers num="2.4.22" />
        <vers num="2.4.23" edition="pre9" />
        <vers num="2.4.23_ow2" />
        <vers num="2.4.24" />
        <vers num="2.4.24_ow1" />
        <vers num="2.4.3" />
        <vers num="2.4.4" />
        <vers num="2.4.5" />
        <vers num="2.4.6" />
        <vers num="2.4.7" />
        <vers num="2.4.8" />
        <vers num="2.4.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" seq="2004-0076" reject="1" published="2004-08-18" name="CVE-2004-0076" modified="2008-09-10">
    <desc>
      <descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: none.  Reason: This candidate was removed from consideration by its Candidate Numbering Authority.  Notes: none.</descript>
    </desc>
    <refs />
  </entry>
  <entry type="CVE" severity="High" seq="2004-0077" published="2004-03-03" name="CVE-2004-0077" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">The do_mremap function for the mremap system call in Linux 2.2 to 2.2.25, 2.4 to 2.4.24, and 2.6 to 2.6.2, does not properly check the return value from the do_munmap function when the maximum number of VMA descriptors is exceeded, which allows local users to gain root privileges, a different vulnerability than CAN-2003-0985.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/981222" source="CERT-VN">VU#981222</ref>
      <ref url="http://www.securityfocus.com/bid/9686" source="BID" patch="1" adv="1">9686</ref>
      <ref url="http://www.debian.org/security/2004/dsa-439" source="DEBIAN" patch="1" adv="1">DSA-439</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200403-02.xml" source="GENTOO" patch="1" adv="1">GLSA-200403-02</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15244" source="XF" adv="1">linux-mremap-gain-privileges(15244)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107711762014175&amp;w=2" source="BUGTRAQ" adv="1">20040218 Second critical mremap() bug found in all Linux kernels</ref>
      <ref url="http://isec.pl/vulnerabilities/isec-0014-mremap-unmap.txt" source="MISC">http://isec.pl/vulnerabilities/isec-0014-mremap-unmap.txt</ref>
      <ref url="http://www.slackware.com/security/viewer.php?l=slackware-security&amp;y=2004&amp;m=slackware-security.404734" source="SLACKWARE">SSA:2004-049</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-106.html" source="REDHAT">RHSA-2004:106</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-069.html" source="REDHAT">RHSA-2004:069</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-066.html" source="REDHAT">RHSA-2004:066</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-065.html" source="REDHAT">RHSA-2004:065</ref>
      <ref url="http://www.osvdb.org/3986" source="OSVDB">3986</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2004_05_linux_kernel.html" source="SUSE">SuSE-SA:2004:005</ref>
      <ref url="http://www.debian.org/security/2004/dsa-514" source="DEBIAN">DSA-514</ref>
      <ref url="http://www.debian.org/security/2004/dsa-475" source="DEBIAN">DSA-475</ref>
      <ref url="http://www.debian.org/security/2004/dsa-470" source="DEBIAN">DSA-470</ref>
      <ref url="http://www.debian.org/security/2004/dsa-466" source="DEBIAN">DSA-466</ref>
      <ref url="http://www.debian.org/security/2004/dsa-456" source="DEBIAN">DSA-456</ref>
      <ref url="http://www.debian.org/security/2004/dsa-454" source="DEBIAN">DSA-454</ref>
      <ref url="http://www.debian.org/security/2004/dsa-453" source="DEBIAN">DSA-453</ref>
      <ref url="http://www.debian.org/security/2004/dsa-450" source="DEBIAN">DSA-450</ref>
      <ref url="http://www.debian.org/security/2004/dsa-444" source="DEBIAN">DSA-444</ref>
      <ref url="http://www.debian.org/security/2004/dsa-442" source="DEBIAN">DSA-442</ref>
      <ref url="http://www.debian.org/security/2004/dsa-441" source="DEBIAN">DSA-441</ref>
      <ref url="http://www.debian.org/security/2004/dsa-440" source="DEBIAN">DSA-440</ref>
      <ref url="http://www.debian.org/security/2004/dsa-438" source="DEBIAN">DSA-438</ref>
      <ref url="http://www.ciac.org/ciac/bulletins/o-082.shtml" source="CIAC">O-082</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107755871932680&amp;w=2" source="TRUSTIX">2004-0008</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107712137732553&amp;w=2" source="TRUSTIX">2004-0007</ref>
      <ref url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2004:015" source="MANDRAKE">MDKSA-2004:015</ref>
      <ref url="http://fedoranews.org/updates/FEDORA-2004-079.shtml" source="FEDORA">FEDORA-2004-079</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000820" source="CONECTIVA">CLA-2004:820</ref>
      <ref url="http://archives.neohapsis.com/archives/vulnwatch/2004-q1/0040.html" source="VULNWATCH">20040218 Second critical mremap() bug found in all Linux kernels</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:837" source="OVAL" sig="1">oval:org.mitre.oval:def:837</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:825" source="OVAL" sig="1">oval:org.mitre.oval:def:825</ref>
    </refs>
    <vuln_soft>
      <prod vendor="redhat" name="bigmem_kernel">
        <vers num="2.4.20-8" edition="" />
        <vers num="2.4.20-8" edition=":i686" />
      </prod>
      <prod vendor="redhat" name="kernel">
        <vers num="2.4.20-8" edition="" />
        <vers num="2.4.20-8" edition=":athlon" />
        <vers num="2.4.20-8" edition=":athlon_smp" />
        <vers num="2.4.20-8" edition=":i686_smp" />
        <vers num="2.4.20-8" edition=":i686" />
        <vers num="2.4.20-8" edition=":i386" />
      </prod>
      <prod vendor="redhat" name="kernel_doc">
        <vers num="2.4.20-8" edition="" />
        <vers num="2.4.20-8" edition=":i386" />
      </prod>
      <prod vendor="redhat" name="kernel_source">
        <vers num="2.4.20-8" edition="" />
        <vers num="2.4.20-8" edition=":i386_src" />
      </prod>
      <prod vendor="linux" name="linux_kernel">
        <vers num="2.2.0" />
        <vers num="2.2.1" />
        <vers num="2.2.10" />
        <vers num="2.2.11" />
        <vers num="2.2.12" />
        <vers num="2.2.13" />
        <vers num="2.2.14" />
        <vers num="2.2.15" edition="pre16" />
        <vers num="2.2.15_pre20" />
        <vers num="2.2.16" edition="pre6" />
        <vers num="2.2.17" />
        <vers num="2.2.18" />
        <vers num="2.2.19" />
        <vers num="2.2.2" />
        <vers num="2.2.20" />
        <vers num="2.2.21" />
        <vers num="2.2.22" />
        <vers num="2.2.23" />
        <vers num="2.2.24" />
        <vers num="2.2.3" />
        <vers num="2.2.4" />
        <vers num="2.2.5" />
        <vers num="2.2.6" />
        <vers num="2.2.7" />
        <vers num="2.2.8" />
        <vers num="2.2.9" />
        <vers num="2.4.0" edition="test1" />
        <vers num="2.4.0" edition="test10" />
        <vers num="2.4.0" edition="test11" />
        <vers num="2.4.0" edition="test12" />
        <vers num="2.4.0" edition="test2" />
        <vers num="2.4.0" edition="test3" />
        <vers num="2.4.0" edition="test4" />
        <vers num="2.4.0" edition="test5" />
        <vers num="2.4.0" edition="test6" />
        <vers num="2.4.0" edition="test7" />
        <vers num="2.4.0" edition="test8" />
        <vers num="2.4.0" edition="test9" />
        <vers num="2.4.1" />
        <vers num="2.4.10" />
        <vers num="2.4.11" />
        <vers num="2.4.12" />
        <vers num="2.4.13" />
        <vers num="2.4.14" />
        <vers num="2.4.15" />
        <vers num="2.4.16" />
        <vers num="2.4.17" />
        <vers num="2.4.18" edition="" />
        <vers num="2.4.18" edition=":x86" />
        <vers num="2.4.18" edition="pre1" />
        <vers num="2.4.18" edition="pre2" />
        <vers num="2.4.18" edition="pre3" />
        <vers num="2.4.18" edition="pre4" />
        <vers num="2.4.18" edition="pre5" />
        <vers num="2.4.18" edition="pre6" />
        <vers num="2.4.18" edition="pre7" />
        <vers num="2.4.18" edition="pre8" />
        <vers num="2.4.19" edition="pre1" />
        <vers num="2.4.19" edition="pre2" />
        <vers num="2.4.19" edition="pre3" />
        <vers num="2.4.19" edition="pre4" />
        <vers num="2.4.19" edition="pre5" />
        <vers num="2.4.19" edition="pre6" />
        <vers num="2.4.2" />
        <vers num="2.4.20" />
        <vers num="2.4.21" edition="pre1" />
        <vers num="2.4.21" edition="pre4" />
        <vers num="2.4.21" edition="pre7" />
        <vers num="2.4.22" />
        <vers num="2.4.23" edition="pre9" />
        <vers num="2.4.24" />
        <vers num="2.4.3" />
        <vers num="2.4.4" />
        <vers num="2.4.5" />
        <vers num="2.4.6" />
        <vers num="2.4.7" />
        <vers num="2.4.8" />
        <vers num="2.4.9" />
        <vers num="2.6.0" edition="test1" />
        <vers num="2.6.0" edition="test10" />
        <vers num="2.6.0" edition="test11" />
        <vers num="2.6.0" edition="test2" />
        <vers num="2.6.0" edition="test3" />
        <vers num="2.6.0" edition="test4" />
        <vers num="2.6.0" edition="test5" />
        <vers num="2.6.0" edition="test6" />
        <vers num="2.6.0" edition="test7" />
        <vers num="2.6.0" edition="test8" />
        <vers num="2.6.0" edition="test9" />
        <vers num="2.6.1" edition="rc1" />
        <vers num="2.6.1" edition="rc2" />
        <vers num="2.6.2" />
        <vers num="2.6_test9_cvs" />
      </prod>
      <prod vendor="netwosix" name="netwosix_linux">
        <vers num="1.0" />
      </prod>
      <prod vendor="trustix" name="secure_linux">
        <vers num="1.5" />
        <vers num="2.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0078" published="2004-03-03" name="CVE-2004-0078" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in the index menu code (menu_pad_string of menu.c) for Mutt 1.4.1 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via certain mail messages.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/9641" source="BID" patch="1" adv="1">9641</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-051.html" source="REDHAT" patch="1" adv="1">RHSA-2004:051</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-050.html" source="REDHAT" patch="1" adv="1">RHSA-2004:050</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15134" source="XF" adv="1">mutt-index-menu-bo(15134)</ref>
      <ref url="http://bugs.debian.org/126336" source="CONFIRM">http://bugs.debian.org/126336</ref>
      <ref url="http://www.slackware.com/security/viewer.php?l=slackware-security&amp;y=2004&amp;m=slackware-security.405053" source="SLACKWARE">SSA:2004-043</ref>
      <ref url="http://www.osvdb.org/3918" source="OSVDB">3918</ref>
      <ref url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2004:010" source="MANDRAKE">MDKSA-2004:010</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107884956930903&amp;w=2" source="BUGTRAQ">20040309 [OpenPKG-SA-2004.005] OpenPKG Security Advisory (mutt)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107696262905039&amp;w=2" source="BUGTRAQ">20040215 LNSA-#2004-0001: mutt remote crash</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107651677817933&amp;w=2" source="BUGTRAQ">20040211 Mutt-1.4.2 fixes buffer overflow.</ref>
      <ref url="ftp://ftp.caldera.com/pub/security/OpenLinux/CSSA-2004-013.0.txt" source="CALDERA">CSSA-2004-013.0</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:838" source="OVAL" sig="1">oval:org.mitre.oval:def:838</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:811" source="OVAL" sig="1">oval:org.mitre.oval:def:811</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mutt" name="mutt">
        <vers num="1.2.1" />
        <vers num="1.2.5" />
        <vers num="1.2.5.1" />
        <vers num="1.2.5.12" />
        <vers num="1.2.5.12_ol" />
        <vers num="1.2.5.4" />
        <vers num="1.2.5.5" />
        <vers num="1.3.12" />
        <vers num="1.3.12.1" />
        <vers num="1.3.16" />
        <vers num="1.3.17" />
        <vers num="1.3.22" />
        <vers num="1.3.24" />
        <vers num="1.3.25" />
        <vers num="1.3.27" />
        <vers num="1.3.28" />
        <vers num="1.4.0" />
        <vers num="1.4.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0079" published="2004-11-23" name="CVE-2004-0079" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The do_change_cipher_spec function in OpenSSL 0.9.6c to 0.9.6k, and 0.9.7a to 0.9.7c, allows remote attackers to cause a denial of service (crash) via a crafted SSL/TLS handshake that triggers a null dereference.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA04-078A.html" source="CERT" adv="1">TA04-078A</ref>
      <ref url="http://www.kb.cert.org/vuls/id/288574" source="CERT-VN">VU#288574</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15505" source="XF" adv="1">openssl-dochangecipherspec-dos(15505)</ref>
      <ref url="http://www.uniras.gov.uk/vuls/2004/224012/index.htm" source="MISC">http://www.uniras.gov.uk/vuls/2004/224012/index.htm</ref>
      <ref url="http://www.trustix.org/errata/2004/0012" source="TRUSTIX">2004-0012</ref>
      <ref url="http://www.slackware.org/security/viewer.php?l=slackware-security&amp;y=2004&amp;m=slackware-security.455961" source="SLACKWARE">SSA:2004-077</ref>
      <ref url="http://www.securityfocus.com/bid/9899" source="BID" adv="1">9899</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-830.html" source="REDHAT">RHSA-2005:830</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-829.html" source="REDHAT">RHSA-2005:829</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-139.html" source="REDHAT">RHSA-2004:139</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-121.html" source="REDHAT">RHSA-2004:121</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-120.html" source="REDHAT">RHSA-2004:120</ref>
      <ref url="http://www.redhat.com/archives/fedora-announce-list/2005-October/msg00087.html" source="FEDORA">FEDORA-2005-1042</ref>
      <ref url="http://www.openssl.org/news/secadv_20040317.txt" source="CONFIRM">http://www.openssl.org/news/secadv_20040317.txt</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2004_07_openssl.html" source="SUSE">SuSE-SA:2004:007</ref>
      <ref url="http://www.linuxsecurity.com/advisories/engarde_advisory-4135.html" source="ENGARDE">ESA-20040317-003</ref>
      <ref url="http://www.debian.org/security/2004/dsa-465" source="DEBIAN">DSA-465</ref>
      <ref url="http://www.cisco.com/warp/public/707/cisco-sa-20040317-openssl.shtml" source="CISCO">20040317 Cisco OpenSSL Implementation Vulnerability</ref>
      <ref url="http://www.ciac.org/ciac/bulletins/o-101.shtml" source="CIAC">O-101</ref>
      <ref url="http://support.lexmark.com/index?page=content&amp;id=TE88&amp;locale=EN&amp;userlocale=EN_US" source="CONFIRM">http://support.lexmark.com/index?page=content&amp;id=TE88&amp;locale=EN&amp;userlocale=EN_US</ref>
      <ref url="http://support.avaya.com/elmodocs2/security/ASA-2005-239.htm" source="CONFIRM">http://support.avaya.com/elmodocs2/security/ASA-2005-239.htm</ref>
      <ref url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doc=fsalert/57524" source="SUNALERT">57524</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200403-03.xml" source="GENTOO">GLSA-200403-03</ref>
      <ref url="http://secunia.com/advisories/18247" source="SECUNIA">18247</ref>
      <ref url="http://secunia.com/advisories/17401" source="SECUNIA">17401</ref>
      <ref url="http://secunia.com/advisories/17398" source="SECUNIA">17398</ref>
      <ref url="http://secunia.com/advisories/17381" source="SECUNIA">17381</ref>
      <ref url="http://secunia.com/advisories/11139" source="SECUNIA">11139</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9779" source="OVAL">oval:org.mitre.oval:def:9779</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5770" source="OVAL">oval:org.mitre.oval:def:5770</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108403806509920&amp;w=2" source="HP">SSRT4717</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107953412903636&amp;w=2" source="BUGTRAQ">20040317 New OpenSSL releases fix denial of service attacks [17 March 2004]</ref>
      <ref url="http://lists.apple.com/mhonarc/security-announce/msg00045.html" source="CONFIRM">http://lists.apple.com/mhonarc/security-announce/msg00045.html</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2005/Aug/msg00000.html" source="APPLE">APPLE-SA-2005-08-15</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2005//Aug/msg00001.html" source="APPLE">APPLE-SA-2005-08-17</ref>
      <ref url="http://fedoranews.org/updates/FEDORA-2004-095.shtml" source="FEDORA">FEDORA-2004-095</ref>
      <ref url="http://docs.info.apple.com/article.html?artnum=61798" source="CONFIRM">http://docs.info.apple.com/article.html?artnum=61798</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000834" source="CONECTIVA">CLA-2004:834</ref>
      <ref url="ftp://ftp.sco.com/pub/updates/OpenServer/SCOSA-2004.10/SCOSA-2004.10.txt" source="SCO">SCOSA-2004.10</ref>
      <ref url="ftp://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2004-005.txt.asc" source="NETBSD">NetBSD-SA2004-005</ref>
      <ref url="ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-04:05.openssl.asc" source="FREEBSD">FreeBSD-SA-04:05</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2004:023" source="MANDRAKE">MDKSA-2004:023</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:975" source="OVAL" sig="1">oval:org.mitre.oval:def:975</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:870" source="OVAL" sig="1">oval:org.mitre.oval:def:870</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2621" source="OVAL" sig="1">oval:org.mitre.oval:def:2621</ref>
    </refs>
    <vuln_soft>
      <prod vendor="4d" name="webstar">
        <vers num="4.0" />
        <vers num="5.2" />
        <vers num="5.2.1" />
        <vers num="5.2.2" />
        <vers num="5.2.3" />
        <vers num="5.2.4" />
        <vers num="5.3" />
        <vers num="5.3.1" />
      </prod>
      <prod vendor="avaya" name="intuity_audix">
        <vers num="" edition=":lx" />
        <vers num="5.1.46" />
        <vers num="s3210" />
        <vers num="s3400" />
      </prod>
      <prod vendor="avaya" name="vsu">
        <vers num="10000_r2.0.1" />
        <vers num="100_r2.0.1" />
        <vers num="2000_r2.0.1" />
        <vers num="5" />
        <vers num="500" />
        <vers num="5000_r2.0.1" />
        <vers num="5x" />
        <vers num="7500_r2.0.1" />
      </prod>
      <prod vendor="checkpoint" name="firewall-1">
        <vers num="" edition=":vsx-ng-ai" />
        <vers num="2.0" edition="" />
        <vers num="2.0" edition=":gx" />
        <vers num="next_generation_fp0" />
        <vers num="next_generation_fp1" />
        <vers num="next_generation_fp2" />
      </prod>
      <prod vendor="checkpoint" name="provider-1">
        <vers num="4.1" edition="sp1" />
        <vers num="4.1" edition="sp2" />
        <vers num="4.1" edition="sp3" />
        <vers num="4.1" edition="sp4" />
      </prod>
      <prod vendor="checkpoint" name="vpn-1">
        <vers num="next_generation_fp0" />
        <vers num="next_generation_fp1" />
        <vers num="next_generation_fp2" />
        <vers num="vsx_ng_with_application_intelligence" />
      </prod>
      <prod vendor="cisco" name="access_registrar">
        <vers num="" />
      </prod>
      <prod vendor="cisco" name="application_and_content_networking_software">
        <vers num="" />
      </prod>
      <prod vendor="cisco" name="ciscoworks_common_management_foundation">
        <vers num="2.1" />
      </prod>
      <prod vendor="cisco" name="ciscoworks_common_services">
        <vers num="2.2" />
      </prod>
      <prod vendor="cisco" name="css11000_content_services_switch">
        <vers num="" />
      </prod>
      <prod vendor="cisco" name="css_secure_content_accelerator">
        <vers num="1.0" />
        <vers num="2.0" />
      </prod>
      <prod vendor="cisco" name="okena_stormwatch">
        <vers num="3.2" />
      </prod>
      <prod vendor="cisco" name="pix_firewall">
        <vers num="6.2.2_.111" />
      </prod>
      <prod vendor="cisco" name="threat_response">
        <vers num="" />
      </prod>
      <prod vendor="cisco" name="webns">
        <vers num="6.10" />
        <vers num="6.10_b4" />
        <vers num="7.10" />
        <vers num="7.10_.0.06s" />
        <vers num="7.1_0.1.02" />
        <vers num="7.1_0.2.06" />
        <vers num="7.2_0.0.03" />
      </prod>
      <prod vendor="hp" name="wbem">
        <vers num="a.01.05.08" />
        <vers num="a.02.00.00" />
        <vers num="a.02.00.01" />
      </prod>
      <prod vendor="lite" name="speed_technologies_litespeed_web_server">
        <vers num="1.0.1" />
        <vers num="1.0.2" />
        <vers num="1.0.3" />
        <vers num="1.1" />
        <vers num="1.1.1" />
        <vers num="1.2.1" />
        <vers num="1.2.2" />
        <vers num="1.2_rc1" />
        <vers num="1.2_rc2" />
        <vers num="1.3" />
        <vers num="1.3.1" />
        <vers num="1.3_rc1" />
        <vers num="1.3_rc2" />
        <vers num="1.3_rc3" />
      </prod>
      <prod vendor="neoteris" name="instant_virtual_extranet">
        <vers num="3.0" />
        <vers num="3.1" />
        <vers num="3.2" />
        <vers num="3.3" />
        <vers num="3.3.1" />
      </prod>
      <prod vendor="novell" name="edirectory">
        <vers num="8.0" />
        <vers num="8.5" />
        <vers num="8.5.12a" />
        <vers num="8.5.27" />
        <vers num="8.6.2" />
        <vers num="8.7" />
        <vers num="8.7.1" edition="sp1" />
      </prod>
      <prod vendor="novell" name="imanager">
        <vers num="1.5" />
        <vers num="2.0" />
      </prod>
      <prod vendor="openssl" name="openssl">
        <vers num="0.9.6c" />
        <vers num="0.9.6d" />
        <vers num="0.9.6e" />
        <vers num="0.9.6f" />
        <vers num="0.9.6g" />
        <vers num="0.9.6h" />
        <vers num="0.9.6i" />
        <vers num="0.9.6j" />
        <vers num="0.9.6k" />
        <vers num="0.9.7" edition="beta1" />
        <vers num="0.9.7" edition="beta2" />
        <vers num="0.9.7" edition="beta3" />
        <vers num="0.9.7a" />
        <vers num="0.9.7b" />
        <vers num="0.9.7c" />
      </prod>
      <prod vendor="redhat" name="openssl">
        <vers num="0.9.6-15" edition="" />
        <vers num="0.9.6-15" edition=":i386" />
        <vers num="0.9.6b-3" edition="" />
        <vers num="0.9.6b-3" edition=":i386" />
        <vers num="0.9.7a-2" edition="" />
        <vers num="0.9.7a-2" edition=":i386_dev" />
        <vers num="0.9.7a-2" edition=":i386" />
        <vers num="0.9.7a-2" edition=":i386_perl" />
      </prod>
      <prod vendor="rsa" name="bsafe_ssl-j_sdk">
        <vers num="3.0" />
        <vers num="3.0.1" />
        <vers num="3.1" />
      </prod>
      <prod vendor="sgi" name="propack">
        <vers num="2.3" />
        <vers num="2.4" />
        <vers num="3.0" />
      </prod>
      <prod vendor="stonesoft" name="servercluster">
        <vers num="2.5" />
        <vers num="2.5.2" />
      </prod>
      <prod vendor="stonesoft" name="stonebeat_fullcluster">
        <vers num="1_2.0" />
        <vers num="1_3.0" />
        <vers num="2.0" />
        <vers num="2.5" />
        <vers num="3.0" />
      </prod>
      <prod vendor="stonesoft" name="stonebeat_securitycluster">
        <vers num="2.0" />
        <vers num="2.5" />
      </prod>
      <prod vendor="stonesoft" name="stonebeat_webcluster">
        <vers num="2.0" />
        <vers num="2.5" />
      </prod>
      <prod vendor="stonesoft" name="stonegate">
        <vers num="1.5.17" />
        <vers num="1.5.18" />
        <vers num="1.6.2" />
        <vers num="1.6.3" />
        <vers num="1.7" />
        <vers num="1.7.1" />
        <vers num="1.7.2" />
        <vers num="2.0.1" />
        <vers num="2.0.4" />
        <vers num="2.0.5" />
        <vers num="2.0.6" />
        <vers num="2.0.7" />
        <vers num="2.0.8" />
        <vers num="2.0.9" />
        <vers num="2.1" />
        <vers num="2.2" />
        <vers num="2.2.1" />
        <vers num="2.2.4" />
      </prod>
      <prod vendor="stonesoft" name="stonegate_vpn_client">
        <vers num="1.7" />
        <vers num="1.7.2" />
        <vers num="2.0" />
        <vers num="2.0.7" />
        <vers num="2.0.8" />
        <vers num="2.0.9" />
      </prod>
      <prod vendor="tarantella" name="tarantella_enterprise">
        <vers num="3.20" />
        <vers num="3.30" />
        <vers num="3.40" />
      </prod>
      <prod vendor="vmware" name="gsx_server">
        <vers num="2.0" />
        <vers num="2.0.1_build_2129" />
        <vers num="2.5.1" />
        <vers num="2.5.1_build_5336" />
        <vers num="3.0_build_7592" />
      </prod>
      <prod vendor="avaya" name="converged_communications_server">
        <vers num="2.0" />
      </prod>
      <prod vendor="avaya" name="s8300">
        <vers num="r2.0.0" />
        <vers num="r2.0.1" />
      </prod>
      <prod vendor="avaya" name="s8500">
        <vers num="r2.0.0" />
        <vers num="r2.0.1" />
      </prod>
      <prod vendor="avaya" name="s8700">
        <vers num="r2.0.0" />
        <vers num="r2.0.1" />
      </prod>
      <prod vendor="avaya" name="sg200">
        <vers num="4.31.29" />
        <vers num="4.4" />
      </prod>
      <prod vendor="avaya" name="sg203">
        <vers num="4.31.29" />
        <vers num="4.4" />
      </prod>
      <prod vendor="avaya" name="sg208">
        <vers num="4.4" />
      </prod>
      <prod vendor="avaya" name="sg5">
        <vers num="4.2" />
        <vers num="4.3" />
        <vers num="4.4" />
      </prod>
      <prod vendor="bluecoat" name="proxysg">
        <vers num="" />
      </prod>
      <prod vendor="cisco" name="call_manager">
        <vers num="" />
      </prod>
      <prod vendor="cisco" name="content_services_switch_11500">
        <vers num="" />
      </prod>
      <prod vendor="cisco" name="firewall_services_module">
        <vers num="1.1.2" />
        <vers num="1.1.3" />
        <vers num="1.1_(3.005)" />
        <vers num="2.1_(0.208)" />
      </prod>
      <prod vendor="cisco" name="gss_4480_global_site_selector">
        <vers num="" />
      </prod>
      <prod vendor="cisco" name="gss_4490_global_site_selector">
        <vers num="" />
      </prod>
      <prod vendor="cisco" name="mds_9000">
        <vers num="" />
      </prod>
      <prod vendor="cisco" name="secure_content_accelerator">
        <vers num="10000" />
      </prod>
      <prod vendor="hp" name="aaa_server">
        <vers num="" />
      </prod>
      <prod vendor="hp" name="apache-based_web_server">
        <vers num="2.0.43.00" />
        <vers num="2.0.43.04" />
      </prod>
      <prod vendor="securecomputing" name="sidewinder">
        <vers num="5.2" />
        <vers num="5.2.0.01" />
        <vers num="5.2.0.02" />
        <vers num="5.2.0.03" />
        <vers num="5.2.0.04" />
        <vers num="5.2.1" />
        <vers num="5.2.1.02" />
      </prod>
      <prod vendor="sun" name="crypto_accelerator_4000">
        <vers num="1.0" />
      </prod>
      <prod vendor="symantec" name="clientless_vpn_gateway_4400">
        <vers num="5.0" />
      </prod>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.3.3" />
      </prod>
      <prod vendor="apple" name="mac_os_x_server">
        <vers num="10.3.3" />
      </prod>
      <prod vendor="bluecoat" name="cacheos_ca_sa">
        <vers num="4.1.10" />
        <vers num="4.1.12" />
      </prod>
      <prod vendor="cisco" name="ios">
        <vers num="12.1(11)e" />
        <vers num="12.1(11b)e" />
        <vers num="12.1(11b)e12" />
        <vers num="12.1(11b)e14" />
        <vers num="12.1(13)e9" />
        <vers num="12.1(19)e1" />
        <vers num="12.2(14)sy" />
        <vers num="12.2(14)sy1" />
        <vers num="12.2sy" />
        <vers num="12.2za" />
      </prod>
      <prod vendor="cisco" name="pix_firewall">
        <vers num="6.0" />
        <vers num="6.0(1)" />
        <vers num="6.0(2)" />
        <vers num="6.0(3)" />
        <vers num="6.0(4)" />
        <vers num="6.0(4.101)" />
        <vers num="6.1" />
        <vers num="6.1(1)" />
        <vers num="6.1(2)" />
        <vers num="6.1(3)" />
        <vers num="6.1(4)" />
        <vers num="6.1(5)" />
        <vers num="6.2" />
        <vers num="6.2(1)" />
        <vers num="6.2(2)" />
        <vers num="6.2(3)" />
        <vers num="6.2(3.100)" />
        <vers num="6.3" />
        <vers num="6.3(1)" />
        <vers num="6.3(2)" />
        <vers num="6.3(3.102)" />
        <vers num="6.3(3.109)" />
      </prod>
      <prod vendor="freebsd" name="freebsd">
        <vers num="4.8" edition="releng" />
        <vers num="4.9" />
        <vers num="5.1" edition="release" />
        <vers num="5.1" edition="releng" />
        <vers num="5.2" />
        <vers num="5.2.1" edition="release" />
      </prod>
      <prod vendor="hp" name="hp-ux">
        <vers num="11.00" />
        <vers num="11.11" />
        <vers num="11.23" />
        <vers num="8.05" />
      </prod>
      <prod vendor="openbsd" name="openbsd">
        <vers num="3.3" />
        <vers num="3.4" />
      </prod>
      <prod vendor="redhat" name="enterprise_linux">
        <vers num="3.0" edition="" />
        <vers num="3.0" edition=":workstation_server" />
        <vers num="3.0" edition=":advanced_server" />
        <vers num="3.0" edition=":enterprise_server" />
      </prod>
      <prod vendor="redhat" name="enterprise_linux_desktop">
        <vers num="3.0" />
      </prod>
      <prod vendor="redhat" name="linux">
        <vers num="7.2" />
        <vers num="7.3" />
        <vers num="8.0" />
      </prod>
      <prod vendor="sco" name="openserver">
        <vers num="5.0.6" />
        <vers num="5.0.7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0080" published="2004-03-03" name="CVE-2004-0080" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The login program in util-linux 2.11 and earlier uses a pointer after it has been freed and reallocated, which could cause login to leak sensitive data.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/801526" source="CERT-VN">VU#801526</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-056.html" source="REDHAT" patch="1" adv="1">RHSA-2004:056</ref>
      <ref url="http://www.securityfocus.com/bid/9558" source="BID" adv="1">9558</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15016" source="XF">utillinux-information-leak(15016)</ref>
      <ref url="http://www.osvdb.org/3796" source="OSVDB">3796</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200404-06.xml" source="GENTOO">GLSA-200404-06</ref>
      <ref url="http://secunia.com/advisories/10773" source="SECUNIA">10773</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108144719532385&amp;w=2" source="BUGTRAQ">20040408 LNSA-#2004-0010: login may leak sensitive data</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108077689801698&amp;w=2" source="BUGTRAQ">20040331 OpenLinux: util-linux could leak sensitive data</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/20040406-01-U" source="SGI">20040406-01-U</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/20040201-01-U.asc" source="SGI">20040201-01-U</ref>
    </refs>
    <vuln_soft>
      <prod vendor="andries_brouwer" name="util-linux">
        <vers prev="1" num="2.11" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0081" published="2004-11-23" name="CVE-2004-0081" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">OpenSSL 0.9.6 before 0.9.6d does not properly handle unknown message types, which allows remote attackers to cause a denial of service (infinite loop), as demonstrated using the Codenomicon TLS Test Tool.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA04-078A.html" source="CERT">TA04-078A</ref>
      <ref url="http://www.kb.cert.org/vuls/id/465542" source="CERT-VN" adv="1">VU#465542</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15509" source="XF" adv="1">openssl-tls-dos(15509)</ref>
      <ref url="http://www.uniras.gov.uk/vuls/2004/224012/index.htm" source="MISC">http://www.uniras.gov.uk/vuls/2004/224012/index.htm</ref>
      <ref url="http://www.trustix.org/errata/2004/0012" source="TRUSTIX">2004-0012</ref>
      <ref url="http://www.securityfocus.com/bid/9899" source="BID" adv="1">9899</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-139.html" source="REDHAT">RHSA-2004:139</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-121.html" source="REDHAT">RHSA-2004:121</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-120.html" source="REDHAT">RHSA-2004:120</ref>
      <ref url="http://www.linuxsecurity.com/advisories/engarde_advisory-4135.html" source="ENGARDE">ESA-20040317-003</ref>
      <ref url="http://www.debian.org/security/2004/dsa-465" source="DEBIAN">DSA-465</ref>
      <ref url="http://www.cisco.com/warp/public/707/cisco-sa-20040317-openssl.shtml" source="CISCO">20040317 Cisco OpenSSL Implementation Vulnerability</ref>
      <ref url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doc=fsalert/57524" source="SUNALERT">57524</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200403-03.xml" source="GENTOO">GLSA-200403-03</ref>
      <ref url="http://secunia.com/advisories/11139" source="SECUNIA">11139</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2004-119.html" source="REDHAT">RHSA-2004:119</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11755" source="OVAL">oval:org.mitre.oval:def:11755</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108403850228012&amp;w=2" source="BUGTRAQ">20040508 [FLSA-2004:1395] Updated OpenSSL resolves security vulnerability</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107955049331965&amp;w=2" source="BUGTRAQ">20040317 Re: New OpenSSL releases fix denial of service attacks [17  March 2004]</ref>
      <ref url="http://fedoranews.org/updates/FEDORA-2004-095.shtml" source="FEDORA">FEDORA-2004-095</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000834" source="CONECTIVA">CLA-2004:834</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/20040304-01-U.asc" source="SGI">20040304-01-U</ref>
      <ref url="ftp://ftp.sco.com/pub/updates/OpenServer/SCOSA-2004.10/SCOSA-2004.10.txt" source="SCO">SCOSA-2004.10</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:902" source="OVAL" sig="1">oval:org.mitre.oval:def:902</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:871" source="OVAL" sig="1">oval:org.mitre.oval:def:871</ref>
    </refs>
    <vuln_soft>
      <prod vendor="4d" name="webstar">
        <vers num="4.0" />
        <vers num="5.2" />
        <vers num="5.2.1" />
        <vers num="5.2.2" />
        <vers num="5.2.3" />
        <vers num="5.2.4" />
        <vers num="5.3" />
        <vers num="5.3.1" />
      </prod>
      <prod vendor="avaya" name="intuity_audix">
        <vers num="" edition=":lx" />
        <vers num="5.1.46" />
        <vers num="s3210" />
        <vers num="s3400" />
      </prod>
      <prod vendor="avaya" name="vsu">
        <vers num="10000_r2.0.1" />
        <vers num="100_r2.0.1" />
        <vers num="2000_r2.0.1" />
        <vers num="5" />
        <vers num="500" />
        <vers num="5000_r2.0.1" />
        <vers num="5x" />
        <vers num="7500_r2.0.1" />
      </prod>
      <prod vendor="checkpoint" name="firewall-1">
        <vers num="" edition=":vsx-ng-ai" />
        <vers num="2.0" edition="" />
        <vers num="2.0" edition=":gx" />
        <vers num="next_generation_fp0" />
        <vers num="next_generation_fp1" />
        <vers num="next_generation_fp2" />
      </prod>
      <prod vendor="checkpoint" name="provider-1">
        <vers num="4.1" edition="sp1" />
        <vers num="4.1" edition="sp2" />
        <vers num="4.1" edition="sp3" />
        <vers num="4.1" edition="sp4" />
      </prod>
      <prod vendor="checkpoint" name="vpn-1">
        <vers num="next_generation" />
        <vers num="next_generation_fp0" />
        <vers num="next_generation_fp1" />
        <vers num="vsx_ng_with_application_intelligence" />
      </prod>
      <prod vendor="cisco" name="access_registrar">
        <vers num="" />
      </prod>
      <prod vendor="cisco" name="application_and_content_networking_software">
        <vers num="" />
      </prod>
      <prod vendor="cisco" name="ciscoworks_common_management_foundation">
        <vers num="2.1" />
      </prod>
      <prod vendor="cisco" name="ciscoworks_common_services">
        <vers num="2.2" />
      </prod>
      <prod vendor="cisco" name="css11000_content_services_switch">
        <vers num="" />
      </prod>
      <prod vendor="cisco" name="css_secure_content_accelerator">
        <vers num="1.0" />
        <vers num="2.0" />
      </prod>
      <prod vendor="cisco" name="okena_stormwatch">
        <vers num="3.2" />
      </prod>
      <prod vendor="cisco" name="pix_firewall">
        <vers num="6.2.2_.111" />
      </prod>
      <prod vendor="cisco" name="threat_response">
        <vers num="" />
      </prod>
      <prod vendor="cisco" name="webns">
        <vers num="6.10" />
        <vers num="6.10_b4" />
        <vers num="7.10" />
        <vers num="7.10_.0.06s" />
        <vers num="7.1_0.1.02" />
        <vers num="7.1_0.2.06" />
        <vers num="7.2_0.0.03" />
      </prod>
      <prod vendor="hp" name="wbem">
        <vers num="a.01.05.08" />
        <vers num="a.02.00.00" />
        <vers num="a.02.00.01" />
      </prod>
      <prod vendor="lite" name="speed_technologies_litespeed_web_server">
        <vers num="1.0.1" />
        <vers num="1.0.2" />
        <vers num="1.0.3" />
        <vers num="1.1" />
        <vers num="1.1.1" />
        <vers num="1.2.1" />
        <vers num="1.2.2" />
        <vers num="1.2_rc1" />
        <vers num="1.2_rc2" />
        <vers num="1.3" />
        <vers num="1.3.1" />
        <vers num="1.3_rc1" />
        <vers num="1.3_rc2" />
        <vers num="1.3_rc3" />
      </prod>
      <prod vendor="neoteris" name="instant_virtual_extranet">
        <vers num="3.0" />
        <vers num="3.1" />
        <vers num="3.2" />
        <vers num="3.3" />
        <vers num="3.3.1" />
      </prod>
      <prod vendor="novell" name="edirectory">
        <vers num="8.0" />
        <vers num="8.5" />
        <vers num="8.5.12a" />
        <vers num="8.5.27" />
        <vers num="8.6.2" />
        <vers num="8.7" />
        <vers num="8.7.1" edition="sp1" />
      </prod>
      <prod vendor="novell" name="imanager">
        <vers num="1.5" />
        <vers num="2.0" />
      </prod>
      <prod vendor="openssl" name="openssl">
        <vers num="0.9.6c" />
        <vers num="0.9.6d" />
        <vers num="0.9.6e" />
        <vers num="0.9.6f" />
        <vers num="0.9.6g" />
        <vers num="0.9.6h" />
        <vers num="0.9.6i" />
        <vers num="0.9.6j" />
        <vers num="0.9.6k" />
        <vers num="0.9.7" edition="beta1" />
        <vers num="0.9.7" edition="beta2" />
        <vers num="0.9.7" edition="beta3" />
        <vers num="0.9.7a" />
        <vers num="0.9.7b" />
        <vers num="0.9.7c" />
      </prod>
      <prod vendor="redhat" name="openssl">
        <vers num="0.9.6-15" edition="" />
        <vers num="0.9.6-15" edition=":i386" />
        <vers num="0.9.6b-3" edition="" />
        <vers num="0.9.6b-3" edition=":i386" />
        <vers num="0.9.7a-2" edition="" />
        <vers num="0.9.7a-2" edition=":i386_dev" />
        <vers num="0.9.7a-2" edition=":i386" />
        <vers num="0.9.7a-2" edition=":i386_perl" />
      </prod>
      <prod vendor="rsa" name="bsafe_ssl-j_sdk">
        <vers num="3.0" />
        <vers num="3.0.1" />
        <vers num="3.1" />
      </prod>
      <prod vendor="sgi" name="propack">
        <vers num="2.3" />
        <vers num="2.4" />
        <vers num="3.0" />
      </prod>
      <prod vendor="stonesoft" name="servercluster">
        <vers num="2.5" />
        <vers num="2.5.2" />
      </prod>
      <prod vendor="stonesoft" name="stonebeat_fullcluster">
        <vers num="1_2.0" />
        <vers num="1_3.0" />
        <vers num="2.0" />
        <vers num="2.5" />
        <vers num="3.0" />
      </prod>
      <prod vendor="stonesoft" name="stonebeat_securitycluster">
        <vers num="2.0" />
        <vers num="2.5" />
      </prod>
      <prod vendor="stonesoft" name="stonebeat_webcluster">
        <vers num="2.0" />
        <vers num="2.5" />
      </prod>
      <prod vendor="stonesoft" name="stonegate">
        <vers num="1.5.17" />
        <vers num="1.5.18" />
        <vers num="1.6.2" />
        <vers num="1.6.3" />
        <vers num="1.7" />
        <vers num="1.7.1" />
        <vers num="1.7.2" />
        <vers num="2.0.1" />
        <vers num="2.0.4" />
        <vers num="2.0.5" />
        <vers num="2.0.6" />
        <vers num="2.0.7" />
        <vers num="2.0.8" />
        <vers num="2.0.9" />
        <vers num="2.1" />
        <vers num="2.2" />
        <vers num="2.2.1" />
        <vers num="2.2.4" />
      </prod>
      <prod vendor="stonesoft" name="stonegate_vpn_client">
        <vers num="1.7" />
        <vers num="1.7.2" />
        <vers num="2.0" />
        <vers num="2.0.7" />
        <vers num="2.0.8" />
        <vers num="2.0.9" />
      </prod>
      <prod vendor="tarantella" name="tarantella_enterprise">
        <vers num="3.20" />
        <vers num="3.30" />
        <vers num="3.40" />
      </prod>
      <prod vendor="vmware" name="gsx_server">
        <vers num="2.0" />
        <vers num="2.0.1_build_2129" />
        <vers num="2.5.1" />
        <vers num="2.5.1_build_5336" />
        <vers num="3.0_build_7592" />
      </prod>
      <prod vendor="avaya" name="converged_communications_server">
        <vers num="2.0" />
      </prod>
      <prod vendor="avaya" name="s8300">
        <vers num="r2.0.0" />
        <vers num="r2.0.1" />
      </prod>
      <prod vendor="avaya" name="s8500">
        <vers num="r2.0.0" />
        <vers num="r2.0.1" />
      </prod>
      <prod vendor="avaya" name="s8700">
        <vers num="r2.0.0" />
        <vers num="r2.0.1" />
      </prod>
      <prod vendor="avaya" name="sg200">
        <vers num="4.31.29" />
        <vers num="4.4" />
      </prod>
      <prod vendor="avaya" name="sg203">
        <vers num="4.31.29" />
        <vers num="4.4" />
      </prod>
      <prod vendor="avaya" name="sg208">
        <vers num="4.4" />
      </prod>
      <prod vendor="avaya" name="sg5">
        <vers num="4.2" />
        <vers num="4.3" />
        <vers num="4.4" />
      </prod>
      <prod vendor="bluecoat" name="proxysg">
        <vers num="" />
      </prod>
      <prod vendor="cisco" name="call_manager">
        <vers num="" />
      </prod>
      <prod vendor="cisco" name="content_services_switch_11500">
        <vers num="" />
      </prod>
      <prod vendor="cisco" name="firewall_services_module">
        <vers num="1.1.2" />
        <vers num="1.1.3" />
        <vers num="1.1_(3.005)" />
        <vers num="2.1_(0.208)" />
      </prod>
      <prod vendor="cisco" name="gss_4480_global_site_selector">
        <vers num="" />
      </prod>
      <prod vendor="cisco" name="gss_4490_global_site_selector">
        <vers num="" />
      </prod>
      <prod vendor="cisco" name="mds_9000">
        <vers num="" />
      </prod>
      <prod vendor="cisco" name="secure_content_accelerator">
        <vers num="10000" />
      </prod>
      <prod vendor="hp" name="aaa_server">
        <vers num="" />
      </prod>
      <prod vendor="hp" name="apache-based_web_server">
        <vers num="2.0.43.00" />
        <vers num="2.0.43.04" />
      </prod>
      <prod vendor="securecomputing" name="sidewinder">
        <vers num="5.2" />
        <vers num="5.2.0.01" />
        <vers num="5.2.0.02" />
        <vers num="5.2.0.03" />
        <vers num="5.2.0.04" />
        <vers num="5.2.1" />
        <vers num="5.2.1.02" />
      </prod>
      <prod vendor="sun" name="crypto_accelerator_4000">
        <vers num="1.0" />
      </prod>
      <prod vendor="symantec" name="clientless_vpn_gateway_4400">
        <vers num="5.0" />
      </prod>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.3.3" />
      </prod>
      <prod vendor="apple" name="mac_os_x_server">
        <vers num="10.3.3" />
      </prod>
      <prod vendor="bluecoat" name="cacheos_ca_sa">
        <vers num="4.1.10" />
        <vers num="4.1.12" />
      </prod>
      <prod vendor="cisco" name="ios">
        <vers num="12.1(11)e" />
        <vers num="12.1(11b)e" />
        <vers num="12.1(11b)e12" />
        <vers num="12.1(11b)e14" />
        <vers num="12.1(13)e9" />
        <vers num="12.1(19)e1" />
        <vers num="12.2(14)sy" />
        <vers num="12.2(14)sy1" />
        <vers num="12.2sy" />
        <vers num="12.2za" />
      </prod>
      <prod vendor="cisco" name="pix_firewall">
        <vers num="6.0" />
        <vers num="6.0(1)" />
        <vers num="6.0(2)" />
        <vers num="6.0(3)" />
        <vers num="6.0(4)" />
        <vers num="6.0(4.101)" />
        <vers num="6.1" />
        <vers num="6.1(1)" />
        <vers num="6.1(2)" />
        <vers num="6.1(3)" />
        <vers num="6.1(4)" />
        <vers num="6.1(5)" />
        <vers num="6.2" />
        <vers num="6.2(1)" />
        <vers num="6.2(2)" />
        <vers num="6.2(3)" />
        <vers num="6.2(3.100)" />
        <vers num="6.3" />
        <vers num="6.3(1)" />
        <vers num="6.3(2)" />
        <vers num="6.3(3.102)" />
        <vers num="6.3(3.109)" />
      </prod>
      <prod vendor="freebsd" name="freebsd">
        <vers num="4.8" edition="releng" />
        <vers num="4.9" />
        <vers num="5.1" edition="release" />
        <vers num="5.1" edition="releng" />
        <vers num="5.2" />
        <vers num="5.2.1" edition="release" />
      </prod>
      <prod vendor="hp" name="hp-ux">
        <vers num="11.00" />
        <vers num="11.11" />
        <vers num="11.23" />
        <vers num="8.05" />
      </prod>
      <prod vendor="openbsd" name="openbsd">
        <vers num="3.3" />
        <vers num="3.4" />
      </prod>
      <prod vendor="redhat" name="enterprise_linux">
        <vers num="3.0" edition="" />
        <vers num="3.0" edition=":workstation_server" />
        <vers num="3.0" edition=":advanced_server" />
        <vers num="3.0" edition=":enterprise_server" />
      </prod>
      <prod vendor="redhat" name="enterprise_linux_desktop">
        <vers num="3.0" />
      </prod>
      <prod vendor="redhat" name="linux">
        <vers num="7.2" />
        <vers num="7.3" />
        <vers num="8.0" />
      </prod>
      <prod vendor="sco" name="openserver">
        <vers num="5.0.6" />
        <vers num="5.0.7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0082" published="2004-03-03" name="CVE-2004-0082" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">The mksmbpasswd shell script (mksmbpasswd.sh) in Samba 3.0.0 and 3.0.1, when creating an account but marking it as disabled, may overwrite the user password with an uninitialized buffer, which could enable the account with a more easily guessable password.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/9637" source="BID" patch="1" adv="1">9637</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-064.html" source="REDHAT" patch="1" adv="1">RHSA-2004:064</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15132" source="XF" adv="1">samba-mksmbpasswd-gain-access(15132)</ref>
      <ref url="http://www.vuxml.org/freebsd/3388eff9-5d6e-11d8-80e3-0020ed76ef5a.html" source="CONFIRM">http://www.vuxml.org/freebsd/3388eff9-5d6e-11d8-80e3-0020ed76ef5a.html</ref>
      <ref url="http://us1.samba.org/samba/ftp/WHATSNEW-3.0.2a.txt" source="CONFIRM">http://us1.samba.org/samba/ftp/WHATSNEW-3.0.2a.txt</ref>
      <ref url="http://www.osvdb.org/3919" source="OSVDB">3919</ref>
      <ref url="http://www.ciac.org/ciac/bulletins/o-078.shtml" source="CIAC">O-078</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:827" source="OVAL" sig="1">oval:org.mitre.oval:def:827</ref>
    </refs>
    <vuln_soft>
      <prod vendor="samba" name="samba">
        <vers num="3.0" />
        <vers num="3.0.0" />
        <vers num="3.0.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0083" published="2004-03-03" name="CVE-2004-0083" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Buffer overflow in ReadFontAlias from dirfile.c of XFree86 4.1.0 through 4.3.0 allows local users and remote attackers to execute arbitrary code via a font alias file (font.alias) with a long token, a different vulnerability than CVE-2004-0084 and CVE-2004-0106.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/820006" source="CERT-VN">VU#820006</ref>
      <ref url="http://www.securityfocus.com/bid/9636" source="BID" patch="1" adv="1">9636</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107644835523678&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20040210 iDEFENSESecurityAdvisory02.10.04: XFree86FontInformationFileBufferOverflow</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15130" source="XF" adv="1">xfree86-fontalias-bo(15130)</ref>
      <ref url="http://www.xfree86.org/cvs/changes" source="CONFIRM" adv="1">http://www.xfree86.org/cvs/changes</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-061.html" source="REDHAT">RHSA-2004:061</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-060.html" source="REDHAT">RHSA-2004:060</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-059.html" source="REDHAT">RHSA-2004:059</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2004_06_xf86.html" source="SUSE">SuSE-SA:2004:006</ref>
      <ref url="http://www.idefense.com/application/poi/display?id=72" source="MISC">http://www.idefense.com/application/poi/display?id=72</ref>
      <ref url="http://www.debian.org/security/2004/dsa-443" source="DEBIAN">DSA-443</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200402-02.xml" source="GENTOO" adv="1">GLSA-200402-02</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9612" source="OVAL">oval:org.mitre.oval:def:9612</ref>
      <ref url="http://www.slackware.com/security/viewer.php?l=slackware-security&amp;y=2004&amp;m=slackware-security.405053" source="SLACKWARE">SSA:2004-043</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2004:012" source="MANDRAKE">MDKSA-2004:012</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-57768-1" source="SUNALERT">57768</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110979666528890&amp;w=2" source="FEDORA">FLSA:2314</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107653324115914&amp;w=2" source="BUGTRAQ">20040211 XFree86 vulnerability exploit</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000821" source="CONECTIVA">CLA-2004:821</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:830" source="OVAL" sig="1">oval:org.mitre.oval:def:830</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:806" source="OVAL" sig="1">oval:org.mitre.oval:def:806</ref>
    </refs>
    <vuln_soft>
      <prod vendor="xfree86_project" name="x11r6">
        <vers num="4.1.0" />
        <vers num="4.1.11" />
        <vers num="4.1.12" />
        <vers num="4.2.0" />
        <vers num="4.2.1" edition="" />
        <vers num="4.2.1" edition=":errata" />
        <vers num="4.3.0" />
      </prod>
      <prod vendor="openbsd" name="openbsd">
        <vers num="3.3" />
        <vers num="3.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0084" published="2004-03-03" name="CVE-2004-0084" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Buffer overflow in the ReadFontAlias function in XFree86 4.1.0 to 4.3.0, when using the CopyISOLatin1Lowered function, allows local or remote authenticated users to execute arbitrary code via a malformed entry in the font alias (font.alias) file, a different vulnerability than CVE-2004-0083 and CVE-2004-0106.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/667502" source="CERT-VN">VU#667502</ref>
      <ref url="http://www.securityfocus.com/bid/9652" source="BID" patch="1" adv="1">9652</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-061.html" source="REDHAT" patch="1" adv="1">RHSA-2004:061</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-060.html" source="REDHAT" patch="1" adv="1">RHSA-2004:060</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15200" source="XF" adv="1">xfree86-copyisolatin1lLowered-bo(15200)</ref>
      <ref url="http://www.slackware.com/security/viewer.php?l=slackware-security&amp;y=2004&amp;m=slackware-security.405053" source="SLACKWARE">SSA:2004-043</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-059.html" source="REDHAT">RHSA-2004:059</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2004_06_xf86.html" source="SUSE">SuSE-SA:2004:006</ref>
      <ref url="http://www.idefense.com/application/poi/display?id=73" source="MISC">http://www.idefense.com/application/poi/display?id=73</ref>
      <ref url="http://www.debian.org/security/2004/dsa-443" source="DEBIAN">DSA-443</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10405" source="OVAL">oval:org.mitre.oval:def:10405</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110979666528890&amp;w=2" source="FEDORA">FLSA:2314</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000821" source="CONECTIVA">CLA-2004:821</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2004:012" source="MANDRAKE">MDKSA-2004:012</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-57768-1" source="SUNALERT">57768</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107662833512775&amp;w=2" source="BUGTRAQ">20040212 iDEFENSE Security Advisory 02.11.04: XFree86 Font Information File Buffer Overflow II</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:831" source="OVAL" sig="1">oval:org.mitre.oval:def:831</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:807" source="OVAL" sig="1">oval:org.mitre.oval:def:807</ref>
    </refs>
    <vuln_soft>
      <prod vendor="xfree86_project" name="x11r6">
        <vers num="4.1.0" />
        <vers num="4.1.11" />
        <vers num="4.1.12" />
        <vers num="4.2.0" />
        <vers num="4.2.1" edition="" />
        <vers num="4.2.1" edition=":errata" />
        <vers num="4.3.0" />
      </prod>
      <prod vendor="openbsd" name="openbsd">
        <vers num="3.3" />
        <vers num="3.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0085" published="2004-03-03" name="CVE-2004-0085" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Unknown vulnerability in the Mail application for Mac OS X 10.1.5 and 10.2.8 with unknown impact, a different vulnerability than CVE-2004-0086.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <other />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/14992" source="XF" patch="1" adv="1">macosx-mail-undisclosed(14992)</ref>
      <ref url="http://www.securityfocus.com/bid/9504" source="BID" patch="1" adv="1">9504</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2004/Jan/msg00000.html" source="APPLE">APPLE-SA-2004-01-26</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.1.5" />
        <vers num="10.2.8" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0086" published="2004-03-03" name="CVE-2004-0086" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Unknown vulnerability in the Mail application for Mac OS X 10.3.2 has unknown impact and attack vectors, a different vulnerability than CVE-2004-0085.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <other />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/9504" source="BID">9504</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2004/Jan/msg00000.html" source="APPLE">APPLE-SA-2004-01-26</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.3.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2004-0087" published="2004-03-03" name="CVE-2004-0087" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">The System Configuration subsystem in Mac OS 10.2.8 and 10.3.2 allows local users to modify network settings, a different vulnerability than CVE-2004-0088.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <config />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/14997" source="XF">macosx-configd-file-manipulation(14997)</ref>
      <ref url="http://www.securityfocus.com/bid/9504" source="BID">9504</ref>
      <ref url="http://www.osvdb.org/6819" source="OSVDB">6819</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2004/Jan/msg00000.html" source="APPLE">APPLE-SA-2004-01-26</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.2.8" />
        <vers num="10.3.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2004-0088" published="2004-03-03" name="CVE-2004-0088" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">The System Configuration subsystem in Mac OS 10.2.8 allows local users to modify network settings, a different vulnerability than CVE-2004-0087.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <config />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/9504" source="BID">9504</ref>
      <ref url="http://www.osvdb.org/6820" source="OSVDB">6820</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2004/Jan/msg00000.html" source="APPLE">APPLE-SA-2004-01-26</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.2.8" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0089" published="2004-03-03" name="CVE-2004-0089" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Buffer overflow in TruBlueEnvironment in Mac OS X 10.3.x and 10.2.x allows local users to gain privileges via a long environment variable.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/902374" source="CERT-VN">VU#902374</ref>
      <ref url="http://www.securityfocus.com/bid/9509" source="BID" adv="1">9509</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/14968" source="XF">macosx-trublue-environmentvariable-bo(14968)</ref>
      <ref url="http://www.osvdb.org/6821" source="OSVDB">6821</ref>
      <ref url="http://www.atstake.com/research/advisories/2004/a012704-1.txt" source="ATSTAKE">A012704-1</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2004/Jan/msg00000.html" source="APPLE">APPLE-SA-2004-01-26</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.2.8" />
        <vers num="10.3.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0090" published="2004-12-31" name="CVE-2004-0090" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Unknown vulnerability in Windows File Sharing for Mac OS X 10.1.5 through 10.3.2 does not "shutdown properly," which has unknown impact and attack vectors.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/9504" source="BID" patch="1">9504</ref>
      <ref url="http://secunia.com/advisories/10723/" source="SECUNIA" patch="1" adv="1">10723</ref>
      <ref url="http://www.auscert.org.au/render.html?it=3791&amp;cid=1" source="AUSCERT" adv="1">ESB-2004.0072</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2004/Jan/msg00000.html" source="APPLE" adv="1">APPLE-SA-2004-01-26</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.1.5" />
        <vers num="10.2" />
        <vers num="10.2.1" />
        <vers num="10.2.2" />
        <vers num="10.2.3" />
        <vers num="10.2.4" />
        <vers num="10.2.5" />
        <vers num="10.2.6" />
        <vers num="10.2.7" />
        <vers num="10.2.8" />
        <vers num="10.3" />
        <vers num="10.3.1" />
        <vers num="10.3.2" />
      </prod>
      <prod vendor="apple" name="mac_os_x_server">
        <vers num="10.1.5" />
        <vers num="10.2" />
        <vers num="10.2.1" />
        <vers num="10.2.2" />
        <vers num="10.2.3" />
        <vers num="10.2.4" />
        <vers num="10.2.5" />
        <vers num="10.2.6" />
        <vers num="10.2.7" />
        <vers num="10.2.8" />
        <vers num="10.3" />
        <vers num="10.3.1" />
        <vers num="10.3.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0091" published="2004-02-17" name="CVE-2004-0091" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">** DISPUTED **  NOTE: this issue has been disputed by the vendor.  Cross-site scripting (XSS) vulnerability in register.php for unknown versions of vBulletin allows remote attackers to inject arbitrary HTML or web script via the reg_site (or possibly regsite) parameter.  NOTE: the vendor has disputed this issue, saying "There is no hidden field called 'reg_site', nor any $reg_site variable anywhere in the vBulletin 2 or vBulletin 3 source code or templates, nor has it ever existed.  We can only assume that this vulnerability was found in a site running code modified from that supplied by Jelsoft."</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://securitytracker.com/id?1008780" source="SECTRACK">1008780</ref>
      <ref url="http://marc.theaimsgroup.com/?l=vuln-dev&amp;m=107488880317647&amp;w=2" source="VULN-DEV" adv="1">20040123 RE: vBulletin Security Vulnerability</ref>
      <ref url="http://marc.theaimsgroup.com/?l=vuln-dev&amp;m=107478592401619&amp;w=2" source="VULN-DEV" adv="1">20040120 Re: vBulletin Security Vulnerability</ref>
      <ref url="http://marc.theaimsgroup.com/?l=vuln-dev&amp;m=107462499927040&amp;w=2" source="VULN-DEV" adv="1">20040120 vBulletin Security Vulnerability</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107462349324945&amp;w=2" source="BUGTRAQ" adv="1">20040120 vBulletin Security Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="jelsoft" name="vbulletin">
        <vers num="3.0_beta_2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0092" published="2004-03-03" name="CVE-2004-0092" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Unknown vulnerability in Safari web browser in Mac OS X 10.2.8 and 10.3.2, with unknown impact.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <other />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/9504" source="BID">9504</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2004/Jan/msg00000.html" source="APPLE">APPLE-SA-2004-01-26</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.2.8" />
        <vers num="10.3.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0093" published="2004-03-15" name="CVE-2004-0093" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">XFree86 4.1.0 allows remote attackers to cause a denial of service and possibly execute arbitrary code via an out-of-bounds array index when using the GLX extension and Direct Rendering Infrastructure (DRI).</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.debian.org/security/2004/dsa-443" source="DEBIAN" patch="1" adv="1">DSA-443</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15272" source="XF" adv="1">xfree86-glx-array-dos(15272)</ref>
      <ref url="http://www.securityfocus.com/bid/9701" source="BID" adv="1">9701</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-152.html" source="REDHAT">RHSA-2004:152</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000824" source="CONECTIVA">CLSA-2004:824</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/20040406-01-U" source="SGI">20040406-01-U</ref>
    </refs>
    <vuln_soft>
      <prod vendor="xfree86_project" name="x11r6">
        <vers num="4.1.0" />
        <vers num="4.1.11" />
        <vers num="4.1.12" />
        <vers num="4.2.0" />
        <vers num="4.2.1" edition="" />
        <vers num="4.2.1" edition=":errata" />
        <vers num="4.3.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0094" published="2004-03-15" name="CVE-2004-0094" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Integer signedness errors in XFree86 4.1.0 allow remote attackers to cause a denial of service and possibly execute arbitrary code when using the GLX extension and Direct Rendering Infrastructure (DRI).</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.debian.org/security/2004/dsa-443" source="DEBIAN" patch="1" adv="1">DSA-443</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15273" source="XF" adv="1">xfree86-glx-integer-dos(15273)</ref>
      <ref url="http://www.securityfocus.com/bid/9701" source="BID">9701</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-152.html" source="REDHAT">RHSA-2004:152</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000824" source="CONECTIVA">CLSA-2004:824</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/20040406-01-U" source="SGI">20040406-01-U</ref>
    </refs>
    <vuln_soft>
      <prod vendor="xfree86_project" name="x11r6">
        <vers num="4.1.0" />
        <vers num="4.1.11" />
        <vers num="4.1.12" />
        <vers num="4.2.0" />
        <vers num="4.2.1" edition="" />
        <vers num="4.2.1" edition=":errata" />
        <vers num="4.3.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0095" published="2004-02-17" name="CVE-2004-0095" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">McAfee ePolicy Orchestrator agent allows remote attackers to cause a denial of service (memory consumption and crash) and possibly execute arbitrary code via an HTTP POST request with an invalid Content-Length value, possibly triggering a buffer overflow.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/9476" source="BID" adv="1">9476</ref>
      <ref url="http://download.nai.com/products/patches/ePO/v3.1.0/EPO3013.zip" source="CONFIRM">http://download.nai.com/products/patches/ePO/v3.1.0/EPO3013.zip</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/14989" source="XF">epolicy-contentlength-post-dos(14989)</ref>
      <ref url="http://www.osvdb.org/3744" source="OSVDB">3744</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mcafee" name="epolicy_orchestrator">
        <vers num="3.6.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0096" published="2004-03-03" name="CVE-2004-0096" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Unknown vulnerability in mod_python 2.7.9 allows remote attackers to cause a denial of service (httpd crash) via a certain query string, a variant of CAN-2003-0973.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <other />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.modpython.org/pipermail/mod_python/2004-January/014879.html" source="MLIST" patch="1" adv="1">[mod_python] 20040122 [ANNOUNCE] Mod_python 2.7.10</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-063.html" source="REDHAT">RHSA-2004:063</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-058.html" source="REDHAT">RHSA-2004:058</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200401-03.xml" source="GENTOO">GLSA-200401-03</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apache" name="mod_python">
        <vers num="2.7.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0097" published="2004-03-03" name="CVE-2004-0097" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Multiple vulnerabilities in PWLib before 1.6.0 allow remote attackers to cause a denial of service and possibly execute arbitrary code, as demonstrated by the NISCC/OUSPG PROTOS test suite for the H.225 protocol.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" admin="1" />
    </loss_types>
    <vuln_types>
      <other />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/749342" source="CERT-VN" patch="1" adv="1">VU#749342</ref>
      <ref url="http://www.cert.org/advisories/CA-2004-01.html" source="CERT" patch="1" adv="1">CA-2004-01</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-047.html" source="REDHAT" patch="1" adv="1">RHSA-2004:047</ref>
      <ref url="http://www.debian.org/security/2004/dsa-448" source="DEBIAN" patch="1" adv="1">DSA-448</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15202" source="XF" adv="1">pwlib-message-dos(15202)</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10056" source="OVAL">oval:org.mitre.oval:def:10056</ref>
      <ref url="http://www.securityfocus.com/bid/9406" source="BID">9406</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:826" source="OVAL" sig="1">oval:org.mitre.oval:def:826</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:803" source="OVAL" sig="1">oval:org.mitre.oval:def:803</ref>
    </refs>
    <vuln_soft>
      <prod vendor="openh323_project" name="pwlib">
        <vers prev="1" num="1.6.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0099" published="2004-03-03" name="CVE-2004-0099" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">mksnap_ffs in FreeBSD 5.1 and 5.2 only sets the snapshot flag when creating a snapshot for a file system, which causes default values for other flags to be used, possibly disabling security-critical settings and allowing a local user to bypass intended access restrictions.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/9533" source="BID" patch="1" adv="1">9533</ref>
      <ref url="ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-04:01.mksnap_ffs.asc" source="FREEBSD" patch="1" adv="1">FreeBSD-SA-04:01</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15005" source="XF">freebsd-mksnapffs-bypass-security(15005)</ref>
      <ref url="http://www.osvdb.org/3790" source="OSVDB">3790</ref>
    </refs>
    <vuln_soft>
      <prod vendor="freebsd" name="freebsd">
        <vers num="5.1" edition="release" />
        <vers num="5.2.1" edition="release" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0103" published="2004-03-03" name="CVE-2004-0103" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">crawl before 4.0.0 beta23 does not properly "apply a size check" when copying a certain environment variable, which may allow local users to gain privileges, possibly as a result of a buffer overflow.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.debian.org/security/2004/dsa-432" source="DEBIAN" patch="1" adv="1">DSA-432</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15032" source="XF">crawl-long-environment-bo(15032)</ref>
      <ref url="http://www.securityfocus.com/bid/9566" source="BID">9566</ref>
      <ref url="http://secunia.com/advisories/10788/" source="SECUNIA">10788</ref>
    </refs>
    <vuln_soft>
      <prod vendor="linley_henzell" name="crawl">
        <vers prev="1" num="4.0.0_b23" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0104" published="2004-03-03" name="CVE-2004-0104" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple format string vulnerabilities in Metamail 2.7 and earlier allow remote attackers to execute arbitrary code.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/518518" source="CERT-VN">VU#518518</ref>
      <ref url="http://www.securityfocus.com/bid/9692" source="BID" patch="1" adv="1">9692</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-073.html" source="REDHAT" patch="1" adv="1">RHSA-2004:073</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15259" source="XF" adv="1">metamail-printheader-format-string(15259)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15245" source="XF">metamail-contenttype-format-string(15245)</ref>
      <ref url="http://www.debian.org/security/2004/dsa-449" source="DEBIAN">DSA-449</ref>
      <ref url="http://secunia.com/advisories/10908" source="SECUNIA">10908</ref>
      <ref url="http://archives.neohapsis.com/archives/vulnwatch/2004-q1/0041.html" source="VULNWATCH">20040218 metamail format string bugs and buffer overflows</ref>
      <ref url="http://www.slackware.com/security/viewer.php?l=slackware-security&amp;y=2004&amp;m=slackware-security.404734" source="SLACKWARE">SSA:2004-049</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2004:014" source="MANDRAKE">MDKSA-2004:014</ref>
      <ref url="http://www.ciac.org/ciac/bulletins/o-083.shtml" source="CIAC">O-083</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107713476911429&amp;w=2" source="BUGTRAQ">20040218 metamail format string bugs and buffer overflows</ref>
    </refs>
    <vuln_soft>
      <prod vendor="metamail_corporation" name="metamail">
        <vers prev="1" num="2.7" />
      </prod>
      <prod vendor="sgi" name="propack">
        <vers num="2.3" />
        <vers num="2.4" />
      </prod>
      <prod vendor="redhat" name="enterprise_linux">
        <vers num="2.1" edition="" />
        <vers num="2.1" edition=":workstation" />
        <vers num="2.1" edition=":advanced_server" />
        <vers num="2.1" edition=":enterprise_server" />
      </prod>
      <prod vendor="redhat" name="linux_advanced_workstation">
        <vers num="2.1" edition="" />
        <vers num="2.1" edition=":itanium_processor" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0105" published="2004-03-03" name="CVE-2004-0105" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple buffer overflows in Metamail 2.7 and earlier allow remote attackers to execute arbitrary code.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/513062" source="CERT-VN">VU#513062</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-073.html" source="REDHAT" patch="1" adv="1">RHSA-2004:073</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15258" source="XF" adv="1">metamail-splitmail-subject-bo(15258)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15247" source="XF">metamail-printheader-nonascii-bo(15247)</ref>
      <ref url="http://www.debian.org/security/2004/dsa-449" source="DEBIAN">DSA-449</ref>
      <ref url="http://secunia.com/advisories/10908" source="SECUNIA">10908</ref>
      <ref url="http://archives.neohapsis.com/archives/vulnwatch/2004-q1/0041.html" source="VULNWATCH">20040218 metamail format string bugs and buffer overflows</ref>
      <ref url="http://www.slackware.com/security/viewer.php?l=slackware-security&amp;y=2004&amp;m=slackware-security.404734" source="SLACKWARE">SSA:2004-049</ref>
      <ref url="http://www.securityfocus.com/bid/9692" source="BID">9692</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2004:014" source="MANDRAKE">MDKSA-2004:014</ref>
      <ref url="http://www.ciac.org/ciac/bulletins/o-083.shtml" source="CIAC">O-083</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107713476911429&amp;w=2" source="BUGTRAQ">20040218 metamail format string bugs and buffer overflows</ref>
    </refs>
    <vuln_soft>
      <prod vendor="metamail_corporation" name="metamail">
        <vers prev="1" num="2.7" />
      </prod>
      <prod vendor="sgi" name="propack">
        <vers num="2.3" />
        <vers num="2.4" />
      </prod>
      <prod vendor="redhat" name="enterprise_linux">
        <vers num="2.1" edition="" />
        <vers num="2.1" edition=":workstation" />
        <vers num="2.1" edition=":advanced_server" />
        <vers num="2.1" edition=":enterprise_server" />
      </prod>
      <prod vendor="redhat" name="linux_advanced_workstation">
        <vers num="2.1" edition="" />
        <vers num="2.1" edition=":itanium_processor" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0106" published="2004-03-03" name="CVE-2004-0106" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Multiple unknown vulnerabilities in XFree86 4.1.0 to 4.3.0, related to improper handling of font files, a different set of vulnerabilities than CVE-2004-0083 and CVE-2004-0084.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <other />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.slackware.com/security/viewer.php?l=slackware-security&amp;y=2004&amp;m=slackware-security.405053" source="SLACKWARE" patch="1" adv="1">SSA:2004-043</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-061.html" source="REDHAT" patch="1" adv="1">RHSA-2004:061</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-060.html" source="REDHAT" patch="1" adv="1">RHSA-2004:060</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15206" source="XF" adv="1">xfree86-multiple-font-improper-handling(15206)</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-059.html" source="REDHAT">RHSA-2004:059</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2004_06_xf86.html" source="SUSE">SuSE-SA:2004:006</ref>
      <ref url="http://www.debian.org/security/2004/dsa-443" source="DEBIAN">DSA-443</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11111" source="OVAL">oval:org.mitre.oval:def:11111</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2004:012" source="MANDRAKE">MDKSA-2004:012</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110979666528890&amp;w=2" source="FEDORA">FLSA:2314</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000821" source="CONECTIVA">CLA-2004:821</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:832" source="OVAL" sig="1">oval:org.mitre.oval:def:832</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:809" source="OVAL" sig="1">oval:org.mitre.oval:def:809</ref>
    </refs>
    <vuln_soft>
      <prod vendor="xfree86_project" name="x11r6">
        <vers num="4.1.0" />
        <vers num="4.1.11" />
        <vers num="4.1.12" />
        <vers num="4.2.0" />
        <vers num="4.2.1" edition="" />
        <vers num="4.2.1" edition=":errata" />
        <vers num="4.3.0" />
      </prod>
      <prod vendor="openbsd" name="openbsd">
        <vers num="3.3" />
        <vers num="3.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0107" published="2004-04-15" name="CVE-2004-0107" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">The (1) post and (2) trigger scripts in sysstat 4.0.7 and earlier allow local users to overwrite arbitrary files via symlink attacks on temporary files, a different vulnerability than CVE-2004-0108.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/9838" source="BID" patch="1" adv="1">9838</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-053.html" source="REDHAT" patch="1" adv="1">RHSA-2004:053</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/20040302-01-U.asc" source="SGI" patch="1">20040302-01-U</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15428" source="XF">sysstat-post-trigger-symlink(15428)</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-093.html" source="REDHAT">RHSA-2004:093</ref>
      <ref url="http://www.osvdb.org/6884" source="OSVDB">6884</ref>
      <ref url="http://www.ciac.org/ciac/bulletins/o-097.shtml" source="CIAC">O-097</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10737" source="OVAL">oval:org.mitre.oval:def:10737</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:862" source="OVAL" sig="1">oval:org.mitre.oval:def:862</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:849" source="OVAL" sig="1">oval:org.mitre.oval:def:849</ref>
    </refs>
    <vuln_soft>
      <prod vendor="redhat" name="sysstat">
        <vers num="4.0.7-3" edition="" />
        <vers num="4.0.7-3" edition=":i386" />
      </prod>
      <prod vendor="sgi" name="propack">
        <vers num="2.3" />
        <vers num="2.4" />
      </prod>
      <prod vendor="sysstat" name="sysstat">
        <vers num="4.0.7" />
        <vers num="4.1.1" />
        <vers num="4.1.2" />
        <vers num="4.1.3" />
        <vers num="4.1.4" />
        <vers num="4.1.5" />
        <vers num="4.1.6" />
        <vers num="4.1.7" />
        <vers num="5.0.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0108" published="2004-04-15" name="CVE-2004-0108" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">The isag utility, which processes sysstat data, allows local users to overwrite arbitrary files via a symlink attack on temporary files, a different vulnerability than CAN-2004-0107.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/9844" source="BID" patch="1" adv="1">9844</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-053.html" source="REDHAT" patch="1" adv="1">RHSA-2004:053</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/20040302-01-U.asc" source="SGI" patch="1">20040302-01-U</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15437" source="XF">sysstat-isag-symlink(15437)</ref>
      <ref url="http://www.debian.org/security/2004/dsa-460" source="DEBIAN">DSA-460</ref>
    </refs>
    <vuln_soft>
      <prod vendor="redhat" name="sysstat">
        <vers num="4.0.7-3" edition="" />
        <vers num="4.0.7-3" edition=":i386" />
      </prod>
      <prod vendor="sgi" name="propack">
        <vers num="2.3" />
        <vers num="2.4" />
      </prod>
      <prod vendor="sysstat" name="sysstat">
        <vers num="4.0.7" />
        <vers num="4.1.1" />
        <vers num="4.1.2" />
        <vers num="4.1.3" />
        <vers num="4.1.4" />
        <vers num="4.1.5" />
        <vers num="4.1.6" />
        <vers num="4.1.7" />
        <vers num="5.0.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0109" published="2004-06-01" name="CVE-2004-0109" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Buffer overflow in the ISO9660 file system component for Linux kernel 2.4.x, 2.5.x and 2.6.x, allows local users with physical access to overflow kernel memory and execute arbitrary code via a malformed CD containing a long symbolic link entry.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.linuxsecurity.com/advisories/engarde_advisory-4285.html" source="ENGARDE" patch="1" adv="1">ESA-20040428-004</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2004-166.html" source="REDHAT" patch="1" adv="1">RHSA-2004:166</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108213675028441&amp;w=2" source="TRUSTIX" patch="1" adv="1">2004-0020</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/20040405-01-U.asc" source="SGI" patch="1" adv="1">20040405-01-U</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15866" source="XF">linux-iso9660-bo(15866)</ref>
      <ref url="http://www.turbolinux.com/security/2004/TLSA-2004-14.txt" source="TURBO">TLSA-2004-14</ref>
      <ref url="http://www.securityfocus.com/bid/10141" source="BID">10141</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-183.html" source="REDHAT">RHSA-2004:183</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-106.html" source="REDHAT">RHSA-2004:106</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-105.html" source="REDHAT">RHSA-2004:105</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2004_09_kernel.html" source="SUSE">SuSE-SA:2004:009</ref>
      <ref url="http://www.idefense.com/application/poi/display?id=101&amp;type=vulnerabilities" source="MISC" adv="1">http://www.idefense.com/application/poi/display?id=101&amp;type=vulnerabilities</ref>
      <ref url="http://www.debian.org/security/2004/dsa-495" source="DEBIAN">DSA-495</ref>
      <ref url="http://www.debian.org/security/2004/dsa-491" source="DEBIAN">DSA-491</ref>
      <ref url="http://www.debian.org/security/2004/dsa-489" source="DEBIAN">DSA-489</ref>
      <ref url="http://www.debian.org/security/2004/dsa-482" source="DEBIAN">DSA-482</ref>
      <ref url="http://www.debian.org/security/2004/dsa-481" source="DEBIAN">DSA-481</ref>
      <ref url="http://www.debian.org/security/2004/dsa-480" source="DEBIAN">DSA-480</ref>
      <ref url="http://www.debian.org/security/2004/dsa-479" source="DEBIAN">DSA-479</ref>
      <ref url="http://www.ciac.org/ciac/bulletins/o-127.shtml" source="CIAC">O-127</ref>
      <ref url="http://www.ciac.org/ciac/bulletins/o-121.shtml" source="CIAC">O-121</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200407-02.xml" source="GENTOO">GLSA-200407-02</ref>
      <ref url="http://secunia.com/advisories/12003" source="SECUNIA">12003</ref>
      <ref url="http://secunia.com/advisories/11986" source="SECUNIA">11986</ref>
      <ref url="http://secunia.com/advisories/11891" source="SECUNIA">11891</ref>
      <ref url="http://secunia.com/advisories/11861" source="SECUNIA">11861</ref>
      <ref url="http://secunia.com/advisories/11626" source="SECUNIA">11626</ref>
      <ref url="http://secunia.com/advisories/11518" source="SECUNIA">11518</ref>
      <ref url="http://secunia.com/advisories/11494" source="SECUNIA">11494</ref>
      <ref url="http://secunia.com/advisories/11486" source="SECUNIA">11486</ref>
      <ref url="http://secunia.com/advisories/11470" source="SECUNIA">11470</ref>
      <ref url="http://secunia.com/advisories/11469" source="SECUNIA">11469</ref>
      <ref url="http://secunia.com/advisories/11464" source="SECUNIA">11464</ref>
      <ref url="http://secunia.com/advisories/11373" source="SECUNIA">11373</ref>
      <ref url="http://secunia.com/advisories/11362" source="SECUNIA">11362</ref>
      <ref url="http://secunia.com/advisories/11361" source="SECUNIA">11361</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10733" source="OVAL">oval:org.mitre.oval:def:10733</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000846" source="CONECTIVA">CLA-2004:846</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/20040504-01-U.asc" source="SGI">20040504-01-U</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2004:029" source="MANDRAKE">MDKSA-2004:029</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:940" source="OVAL" sig="1">oval:org.mitre.oval:def:940</ref>
    </refs>
    <vuln_soft>
      <prod vendor="linux" name="linux_kernel">
        <vers num="2.4.0" />
        <vers num="2.5.0" />
        <vers num="2.6.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0110" published="2004-03-15" name="CVE-2004-0110" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in the (1) nanohttp or (2) nanoftp modules in XMLSoft Libxml 2 (Libxml2) 2.6.0 through 2.6.5 allow remote attackers to execute arbitrary code via a long URL.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/493966" source="CERT-VN">VU#493966</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15301" source="XF" patch="1" adv="1">libxml2-nanohttp-bo(15301)</ref>
      <ref url="http://www.securityfocus.com/bid/9718" source="BID" patch="1" adv="1">9718</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2004-090.html" source="REDHAT" patch="1" adv="1">RHSA-2004:090</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107851606605420&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20040305 [OpenPKG-SA-2004.003] OpenPKG Security Advisory (libxml)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15302" source="XF">libxml2-nanoftp-bo(15302)</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-091.html" source="REDHAT">RHSA-2004:091</ref>
      <ref url="http://www.debian.org/security/2004/dsa-455" source="DEBIAN">DSA-455</ref>
      <ref url="http://www.ciac.org/ciac/bulletins/o-086.shtml" source="CIAC">O-086</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200403-01.xml" source="GENTOO">GLSA-200403-01</ref>
      <ref url="http://secunia.com/advisories/10958/" source="SECUNIA">10958</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11626" source="OVAL">oval:org.mitre.oval:def:11626</ref>
      <ref url="http://www.xmlsoft.org/news.html" source="CONFIRM">http://www.xmlsoft.org/news.html</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-650.html" source="REDHAT">RHSA-2004:650</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2005_01_sr.html" source="SUSE">SUSE-SR:2005:001</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107860178228804&amp;w=2" source="BUGTRAQ">20040306 TSLSA-2004-0010 - libxml2</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:875" source="OVAL" sig="1">oval:org.mitre.oval:def:875</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:833" source="OVAL" sig="1">oval:org.mitre.oval:def:833</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sgi" name="propack">
        <vers num="2.3" />
        <vers num="2.4" />
      </prod>
      <prod vendor="xmlsoft" name="libxml">
        <vers num="1.8.17" />
      </prod>
      <prod vendor="xmlsoft" name="libxml2">
        <vers num="2.4.19" />
        <vers num="2.4.23" />
        <vers num="2.5.10" />
        <vers num="2.5.11" />
        <vers num="2.5.4" />
        <vers num="2.6.0" />
        <vers num="2.6.1" />
        <vers num="2.6.2" />
        <vers num="2.6.3" />
        <vers num="2.6.4" />
        <vers num="2.6.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0111" published="2004-04-15" name="CVE-2004-0111" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">gdk-pixbuf before 0.20 allows attackers to cause a denial of service (crash) via a malformed bitmap (BMP) file.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <other />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/9842" source="BID" patch="1" adv="1">9842</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-103.html" source="REDHAT" patch="1" adv="1">RHSA-2004:103</ref>
      <ref url="https://bugzilla.fedora.us/show_bug.cgi?id=2005" source="FEDORA">FLSA:2005</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15426" source="XF">gdk-pixbuf-bitmap-dos(15426)</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-102.html" source="REDHAT">RHSA-2004:102</ref>
      <ref url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2004:020" source="MANDRAKE">MDKSA-2004:020</ref>
      <ref url="http://www.debian.org/security/2004/dsa-464" source="DEBIAN">DSA-464</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:846" source="OVAL" sig="1">oval:org.mitre.oval:def:846</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:845" source="OVAL" sig="1">oval:org.mitre.oval:def:845</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gnome" name="gdkpixbuf">
        <vers num="0.18" />
        <vers num="0.20" />
      </prod>
      <prod vendor="redhat" name="gdk_pixbuf">
        <vers num="0.18.0-7" edition="" />
        <vers num="0.18.0-7" edition=":i386_dev" />
        <vers num="0.18.0-7" edition=":i386" />
        <vers num="0.18.0-7" edition=":i386_gnome" />
      </prod>
      <prod vendor="sgi" name="propack">
        <vers num="2.3" />
        <vers num="2.4" />
      </prod>
      <prod vendor="redhat" name="enterprise_linux">
        <vers num="2.1" edition="" />
        <vers num="2.1" edition=":workstation" />
        <vers num="2.1" edition=":advanced_server" />
        <vers num="2.1" edition=":enterprise_server" />
        <vers num="3.0" edition="" />
        <vers num="3.0" edition=":workstation" />
        <vers num="3.0" edition=":advanced_servers" />
        <vers num="3.0" edition=":enterprise_server" />
      </prod>
      <prod vendor="redhat" name="linux_advanced_workstation">
        <vers num="2.1" edition="" />
        <vers num="2.1" edition=":itanium_processor" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0112" published="2004-11-23" name="CVE-2004-0112" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The SSL/TLS handshaking code in OpenSSL 0.9.7a, 0.9.7b, and 0.9.7c, when using Kerberos ciphersuites, does not properly check the length of Kerberos tickets during a handshake, which allows remote attackers to cause a denial of service (crash) via a crafted SSL/TLS handshake that causes an out-of-bounds read.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA04-078A.html" source="CERT" adv="1">TA04-078A</ref>
      <ref url="http://www.kb.cert.org/vuls/id/484726" source="CERT-VN">VU#484726</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15508" source="XF" adv="1">openssl-kerberos-ciphersuites-dos(15508)</ref>
      <ref url="http://www.uniras.gov.uk/vuls/2004/224012/index.htm" source="MISC">http://www.uniras.gov.uk/vuls/2004/224012/index.htm</ref>
      <ref url="http://www.trustix.org/errata/2004/0012" source="TRUSTIX">2004-0012</ref>
      <ref url="http://www.slackware.org/security/viewer.php?l=slackware-security&amp;y=2004&amp;m=slackware-security.455961" source="SLACKWARE">SSA:2004-077</ref>
      <ref url="http://www.securityfocus.com/bid/9899" source="BID" adv="1">9899</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-121.html" source="REDHAT">RHSA-2004:121</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-120.html" source="REDHAT">RHSA-2004:120</ref>
      <ref url="http://www.openssl.org/news/secadv_20040317.txt" source="CONFIRM">http://www.openssl.org/news/secadv_20040317.txt</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2004_07_openssl.html" source="SUSE">SuSE-SA:2004:007</ref>
      <ref url="http://www.cisco.com/warp/public/707/cisco-sa-20040317-openssl.shtml" source="CISCO">20040317 Cisco OpenSSL Implementation Vulnerability</ref>
      <ref url="http://www.ciac.org/ciac/bulletins/o-101.shtml" source="CIAC">O-101</ref>
      <ref url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doc=fsalert/57524" source="SUNALERT">57524</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200403-03.xml" source="GENTOO">GLSA-200403-03</ref>
      <ref url="http://secunia.com/advisories/11139" source="SECUNIA">11139</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9580" source="OVAL">oval:org.mitre.oval:def:9580</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108403806509920&amp;w=2" source="HP">SSRT4717</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107953412903636&amp;w=2" source="BUGTRAQ">20040317 New OpenSSL releases fix denial of service attacks [17 March 2004]</ref>
      <ref url="http://lists.apple.com/mhonarc/security-announce/msg00045.html" source="CONFIRM">http://lists.apple.com/mhonarc/security-announce/msg00045.html</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2005/Aug/msg00000.html" source="APPLE">APPLE-SA-2005-08-15</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2005//Aug/msg00001.html" source="APPLE">APPLE-SA-2005-08-17</ref>
      <ref url="http://docs.info.apple.com/article.html?artnum=61798" source="CONFIRM">http://docs.info.apple.com/article.html?artnum=61798</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000834" source="CONECTIVA">CLA-2004:834</ref>
      <ref url="ftp://ftp.sco.com/pub/updates/OpenServer/SCOSA-2004.10/SCOSA-2004.10.txt" source="SCO">SCOSA-2004.10</ref>
      <ref url="ftp://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2004-005.txt.asc" source="NETBSD">NetBSD-SA2004-005</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2004:023" source="MANDRAKE">MDKSA-2004:023</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:928" source="OVAL" sig="1">oval:org.mitre.oval:def:928</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1049" source="OVAL" sig="1">oval:org.mitre.oval:def:1049</ref>
    </refs>
    <vuln_soft>
      <prod vendor="4d" name="webstar">
        <vers num="4.0" />
        <vers num="5.2" />
        <vers num="5.2.1" />
        <vers num="5.2.2" />
        <vers num="5.2.3" />
        <vers num="5.2.4" />
        <vers num="5.3" />
        <vers num="5.3.1" />
      </prod>
      <prod vendor="avaya" name="intuity_audix">
        <vers num="" edition=":lx" />
        <vers num="5.1.46" />
        <vers num="s3210" />
        <vers num="s3400" />
      </prod>
      <prod vendor="avaya" name="vsu">
        <vers num="10000_r2.0.1" />
        <vers num="100_r2.0.1" />
        <vers num="2000_r2.0.1" />
        <vers num="5" />
        <vers num="500" />
        <vers num="5000_r2.0.1" />
        <vers num="5x" />
        <vers num="7500_r2.0.1" />
      </prod>
      <prod vendor="checkpoint" name="firewall-1">
        <vers num="" edition=":vsx-ng-ai" />
        <vers num="2.0" edition="" />
        <vers num="2.0" edition=":gx" />
        <vers num="next_generation_fp0" />
        <vers num="next_generation_fp1" />
        <vers num="next_generation_fp2" />
      </prod>
      <prod vendor="checkpoint" name="provider-1">
        <vers num="4.1" edition="sp1" />
        <vers num="4.1" edition="sp2" />
        <vers num="4.1" edition="sp3" />
        <vers num="4.1" edition="sp4" />
      </prod>
      <prod vendor="checkpoint" name="vpn-1">
        <vers num="next_generation_fp0" />
        <vers num="next_generation_fp1" />
        <vers num="next_generation_fp2" />
        <vers num="vsx_ng_with_application_intelligence" />
      </prod>
      <prod vendor="cisco" name="access_registrar">
        <vers num="" />
      </prod>
      <prod vendor="cisco" name="application_and_content_networking_software">
        <vers num="" />
      </prod>
      <prod vendor="cisco" name="ciscoworks_common_management_foundation">
        <vers num="2.1" />
      </prod>
      <prod vendor="cisco" name="ciscoworks_common_services">
        <vers num="2.2" />
      </prod>
      <prod vendor="cisco" name="css11000_content_services_switch">
        <vers num="" />
      </prod>
      <prod vendor="cisco" name="css_secure_content_accelerator">
        <vers num="1.0" />
        <vers num="2.0" />
      </prod>
      <prod vendor="cisco" name="okena_stormwatch">
        <vers num="3.2" />
      </prod>
      <prod vendor="cisco" name="pix_firewall">
        <vers num="6.2.2_.111" />
      </prod>
      <prod vendor="cisco" name="threat_response">
        <vers num="" />
      </prod>
      <prod vendor="cisco" name="webns">
        <vers num="6.10" />
        <vers num="6.10_b4" />
        <vers num="7.10" />
        <vers num="7.10_.0.06s" />
        <vers num="7.1_0.1.02" />
        <vers num="7.1_0.2.06" />
        <vers num="7.2_0.0.03" />
      </prod>
      <prod vendor="hp" name="wbem">
        <vers num="a.01.05.08" />
        <vers num="a.02.00.00" />
        <vers num="a.02.00.01" />
      </prod>
      <prod vendor="lite" name="speed_technologies_litespeed_web_server">
        <vers num="1.0.1" />
        <vers num="1.0.2" />
        <vers num="1.0.3" />
        <vers num="1.1" />
        <vers num="1.1.1" />
        <vers num="1.2.1" />
        <vers num="1.2.2" />
        <vers num="1.2_rc1" />
        <vers num="1.2_rc2" />
        <vers num="1.3" />
        <vers num="1.3.1" />
        <vers num="1.3_rc1" />
        <vers num="1.3_rc2" />
        <vers num="1.3_rc3" />
      </prod>
      <prod vendor="neoteris" name="instant_virtual_extranet">
        <vers num="3.0" />
        <vers num="3.1" />
        <vers num="3.2" />
        <vers num="3.3" />
        <vers num="3.3.1" />
      </prod>
      <prod vendor="novell" name="edirectory">
        <vers num="8.0" />
        <vers num="8.5" />
        <vers num="8.5.12a" />
        <vers num="8.5.27" />
        <vers num="8.6.2" />
        <vers num="8.7" />
        <vers num="8.7.1" edition="sp1" />
      </prod>
      <prod vendor="novell" name="imanager">
        <vers num="1.5" />
        <vers num="2.0" />
      </prod>
      <prod vendor="openssl" name="openssl">
        <vers num="0.9.6c" />
        <vers num="0.9.6d" />
        <vers num="0.9.6e" />
        <vers num="0.9.6f" />
        <vers num="0.9.6g" />
        <vers num="0.9.6h" />
        <vers num="0.9.6i" />
        <vers num="0.9.6j" />
        <vers num="0.9.6k" />
        <vers num="0.9.7" edition="beta1" />
        <vers num="0.9.7" edition="beta2" />
        <vers num="0.9.7" edition="beta3" />
        <vers num="0.9.7a" />
        <vers num="0.9.7b" />
        <vers num="0.9.7c" />
      </prod>
      <prod vendor="redhat" name="openssl">
        <vers num="0.9.6-15" edition="" />
        <vers num="0.9.6-15" edition=":i386" />
        <vers num="0.9.6b-3" edition="" />
        <vers num="0.9.6b-3" edition=":i386" />
        <vers num="0.9.7a-2" edition="" />
        <vers num="0.9.7a-2" edition=":i386_dev" />
        <vers num="0.9.7a-2" edition=":i386" />
        <vers num="0.9.7a-2" edition=":i386_perl" />
      </prod>
      <prod vendor="rsa" name="bsafe_ssl-j_sdk">
        <vers num="3.0" />
        <vers num="3.0.1" />
        <vers num="3.1" />
      </prod>
      <prod vendor="sgi" name="propack">
        <vers num="2.3" />
        <vers num="2.4" />
        <vers num="3.0" />
      </prod>
      <prod vendor="stonesoft" name="servercluster">
        <vers num="2.5" />
        <vers num="2.5.2" />
      </prod>
      <prod vendor="stonesoft" name="stonebeat_fullcluster">
        <vers num="1_2.0" />
        <vers num="1_3.0" />
        <vers num="2.0" />
        <vers num="2.5" />
        <vers num="3.0" />
      </prod>
      <prod vendor="stonesoft" name="stonebeat_securitycluster">
        <vers num="2.0" />
        <vers num="2.5" />
      </prod>
      <prod vendor="stonesoft" name="stonebeat_webcluster">
        <vers num="2.0" />
        <vers num="2.5" />
      </prod>
      <prod vendor="stonesoft" name="stonegate">
        <vers num="1.5.17" />
        <vers num="1.5.18" />
        <vers num="1.6.2" />
        <vers num="1.6.3" />
        <vers num="1.7" />
        <vers num="1.7.1" />
        <vers num="1.7.2" />
        <vers num="2.0.1" />
        <vers num="2.0.4" />
        <vers num="2.0.5" />
        <vers num="2.0.6" />
        <vers num="2.0.7" />
        <vers num="2.0.8" />
        <vers num="2.0.9" />
        <vers num="2.1" />
        <vers num="2.2" />
        <vers num="2.2.1" />
        <vers num="2.2.4" />
      </prod>
      <prod vendor="tarantella" name="tarantella_enterprise">
        <vers num="3.20" />
        <vers num="3.30" />
        <vers num="3.40" />
      </prod>
      <prod vendor="vmware" name="gsx_server">
        <vers num="2.0" />
        <vers num="2.0.1_build_2129" />
        <vers num="2.5.1" />
        <vers num="2.5.1_build_5336" />
        <vers num="3.0_build_7592" />
      </prod>
      <prod vendor="avaya" name="converged_communications_server">
        <vers num="2.0" />
      </prod>
      <prod vendor="avaya" name="s8300">
        <vers num="r2.0.0" />
        <vers num="r2.0.1" />
      </prod>
      <prod vendor="avaya" name="s8500">
        <vers num="r2.0.0" />
        <vers num="r2.0.1" />
      </prod>
      <prod vendor="avaya" name="s8700">
        <vers num="r2.0.0" />
        <vers num="r2.0.1" />
      </prod>
      <prod vendor="avaya" name="sg200">
        <vers num="4.31.29" />
        <vers num="4.4" />
      </prod>
      <prod vendor="avaya" name="sg203">
        <vers num="4.31.29" />
        <vers num="4.4" />
      </prod>
      <prod vendor="avaya" name="sg208">
        <vers num="4.4" />
      </prod>
      <prod vendor="avaya" name="sg5">
        <vers num="4.2" />
        <vers num="4.3" />
        <vers num="4.4" />
      </prod>
      <prod vendor="bluecoat" name="proxysg">
        <vers num="" />
      </prod>
      <prod vendor="cisco" name="call_manager">
        <vers num="" />
      </prod>
      <prod vendor="cisco" name="content_services_switch_11500">
        <vers num="" />
      </prod>
      <prod vendor="cisco" name="firewall_services_module">
        <vers num="1.1.2" />
        <vers num="1.1.3" />
        <vers num="1.1_(3.005)" />
        <vers num="2.1_(0.208)" />
      </prod>
      <prod vendor="cisco" name="gss_4480_global_site_selector">
        <vers num="" />
      </prod>
      <prod vendor="cisco" name="gss_4490_global_site_selector">
        <vers num="" />
      </prod>
      <prod vendor="cisco" name="mds_9000">
        <vers num="" />
      </prod>
      <prod vendor="cisco" name="secure_content_accelerator">
        <vers num="10000" />
      </prod>
      <prod vendor="hp" name="aaa_server">
        <vers num="" />
      </prod>
      <prod vendor="hp" name="apache-based_web_server">
        <vers num="2.0.43.00" />
        <vers num="2.0.43.04" />
      </prod>
      <prod vendor="securecomputing" name="sidewinder">
        <vers num="5.2" />
        <vers num="5.2.0.01" />
        <vers num="5.2.0.02" />
        <vers num="5.2.0.03" />
        <vers num="5.2.0.04" />
        <vers num="5.2.1" />
        <vers num="5.2.1.02" />
      </prod>
      <prod vendor="sun" name="crypto_accelerator_4000">
        <vers num="1.0" />
      </prod>
      <prod vendor="symantec" name="clientless_vpn_gateway_4400">
        <vers num="5.0" />
      </prod>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.3.3" />
      </prod>
      <prod vendor="apple" name="mac_os_x_server">
        <vers num="10.3.3" />
      </prod>
      <prod vendor="bluecoat" name="cacheos_ca_sa">
        <vers num="4.1.10" />
        <vers num="4.1.12" />
      </prod>
      <prod vendor="cisco" name="ios">
        <vers num="12.1(11)e" />
        <vers num="12.1(11b)e" />
        <vers num="12.1(11b)e12" />
        <vers num="12.1(11b)e14" />
        <vers num="12.1(13)e9" />
        <vers num="12.1(19)e1" />
        <vers num="12.2(14)sy" />
        <vers num="12.2(14)sy1" />
        <vers num="12.2sy" />
        <vers num="12.2za" />
      </prod>
      <prod vendor="cisco" name="pix_firewall">
        <vers num="6.0" />
        <vers num="6.0(1)" />
        <vers num="6.0(2)" />
        <vers num="6.0(3)" />
        <vers num="6.0(4)" />
        <vers num="6.0(4.101)" />
        <vers num="6.1" />
        <vers num="6.1(1)" />
        <vers num="6.1(2)" />
        <vers num="6.1(3)" />
        <vers num="6.1(4)" />
        <vers num="6.1(5)" />
        <vers num="6.2" />
        <vers num="6.2(1)" />
        <vers num="6.2(2)" />
        <vers num="6.2(3)" />
        <vers num="6.2(3.100)" />
        <vers num="6.3" />
        <vers num="6.3(1)" />
        <vers num="6.3(2)" />
        <vers num="6.3(3.102)" />
        <vers num="6.3(3.109)" />
      </prod>
      <prod vendor="freebsd" name="freebsd">
        <vers num="4.8" edition="releng" />
        <vers num="4.9" />
        <vers num="5.1" edition="release" />
        <vers num="5.1" edition="releng" />
        <vers num="5.2" />
        <vers num="5.2.1" edition="release" />
      </prod>
      <prod vendor="hp" name="hp-ux">
        <vers num="11.00" />
        <vers num="11.11" />
        <vers num="11.23" />
        <vers num="8.05" />
      </prod>
      <prod vendor="openbsd" name="openbsd">
        <vers num="3.3" />
        <vers num="3.4" />
      </prod>
      <prod vendor="redhat" name="enterprise_linux">
        <vers num="3.0" edition="" />
        <vers num="3.0" edition=":workstation_server" />
        <vers num="3.0" edition=":advanced_server" />
        <vers num="3.0" edition=":enterprise_server" />
      </prod>
      <prod vendor="redhat" name="enterprise_linux_desktop">
        <vers num="3.0" />
      </prod>
      <prod vendor="redhat" name="linux">
        <vers num="7.2" />
        <vers num="7.3" />
        <vers num="8.0" />
      </prod>
      <prod vendor="sco" name="openserver">
        <vers num="5.0.6" />
        <vers num="5.0.7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0113" published="2004-03-29" name="CVE-2004-0113" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Memory leak in ssl_engine_io.c for mod_ssl in Apache 2 before 2.0.49 allows remote attackers to cause a denial of service (memory consumption) via plain HTTP requests to the SSL port of an SSL-enabled server.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/9826" source="BID" patch="1" adv="1">9826</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15419" source="XF" adv="1">apache-modssl-plain-dos(15419)</ref>
      <ref url="http://www.apacheweek.com/features/security-20" source="CONFIRM" adv="1">http://www.apacheweek.com/features/security-20</ref>
      <ref url="http://marc.theaimsgroup.com/?l=apache-cvs&amp;m=107869699329638" source="MLIST" adv="1">[apache-cvs] 20040307 cvs commit: httpd-2.0/modules/ssl ssl_engine_io.c</ref>
      <ref url="http://www.trustix.org/errata/2004/0017" source="TRUSTIX">2004-0017</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-182.html" source="REDHAT">RHSA-2004:182</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-084.html" source="REDHAT">RHSA-2004:084</ref>
      <ref url="http://www.osvdb.org/4182" source="OSVDB">4182</ref>
      <ref url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2004:043" source="MANDRAKE">MDKSA-2004:043</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200403-04.xml" source="GENTOO">GLSA-200403-04</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108731648532365&amp;w=2" source="HP">SSRT4717</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108369640424244&amp;w=2" source="APPLE">APPLE-SA-2004-05-03</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108034113406858&amp;w=2" source="BUGTRAQ">20040325 LNSA-#2004-0006: bug workaround for Apache 2.0.48</ref>
      <ref url="http://issues.apache.org/bugzilla/show_bug.cgi?id=27106" source="MISC">http://issues.apache.org/bugzilla/show_bug.cgi?id=27106</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000839" source="CONECTIVA">CLSA-2004:839</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:876" source="OVAL" sig="1">oval:org.mitre.oval:def:876</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apache" name="http_server">
        <vers num="2.0.35" />
        <vers num="2.0.36" />
        <vers num="2.0.37" />
        <vers num="2.0.38" />
        <vers num="2.0.39" />
        <vers num="2.0.40" />
        <vers num="2.0.41" />
        <vers num="2.0.42" />
        <vers num="2.0.43" />
        <vers num="2.0.44" />
        <vers num="2.0.45" />
        <vers num="2.0.46" />
        <vers num="2.0.47" />
        <vers num="2.0.48" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0114" published="2004-03-03" name="CVE-2004-0114" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">The shmat system call in the System V Shared Memory interface for FreeBSD 5.2 and earlier, NetBSD 1.3 and earlier, and OpenBSD 2.6 and earlier, does not properly decrement a shared memory segment's reference count when the vm_map_find function fails, which could allow local users to gain read or write access to a portion of kernel memory and gain privileges.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/15061" source="XF" patch="1" adv="1">bsd-shmat-gain-privileges(15061)</ref>
      <ref url="http://www.securityfocus.com/bid/9586" source="BID" patch="1" adv="1">9586</ref>
      <ref url="ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-04:02.shmat.asc" source="FREEBSD" patch="1" adv="1">FreeBSD-SA-04:02</ref>
      <ref url="http://www.pine.nl/press/pine-cert-20040201.txt" source="MISC">http://www.pine.nl/press/pine-cert-20040201.txt</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107608375207601&amp;w=2" source="BUGTRAQ" adv="1">20040205 [PINE-CERT-20040201] reference count overflow in shmat()</ref>
      <ref url="http://www.osvdb.org/3836" source="OSVDB">3836</ref>
      <ref url="http://www.openbsd.org/errata33.html#sysvshm" source="CONFIRM">http://www.openbsd.org/errata33.html#sysvshm</ref>
      <ref url="ftp://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2004-004.txt.asc" source="NETBSD">NetBSD-SA2004-004</ref>
    </refs>
    <vuln_soft>
      <prod vendor="freebsd" name="freebsd">
        <vers prev="1" num="5.2" />
      </prod>
      <prod vendor="netbsd" name="netbsd">
        <vers prev="1" num="1.3" />
      </prod>
      <prod vendor="openbsd" name="openbsd">
        <vers prev="1" num="2.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0115" published="2004-03-03" name="CVE-2004-0115" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">VirtualPC_Services in Microsoft Virtual PC for Mac 6.0 through 6.1 allows local attackers to truncate and overwrite arbitrary files, and execute arbitrary code, via a symlink attack on the VPCServices_Log temporary file.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/9632" source="BID" patch="1" adv="1">9632</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms04-005.asp" source="MS" patch="1" adv="1">MS04-005</ref>
      <ref url="http://www.atstake.com/research/advisories/2004/a021004-1.txt" source="ATSTAKE" adv="1">A021004-1</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15113" source="XF">virtual-pc-gain-privileges(15113)</ref>
      <ref url="http://www.osvdb.org/3893" source="OSVDB">3893</ref>
      <ref url="http://www.ciac.org/ciac/bulletins/o-076.shtml" source="CIAC">O-076</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="virtual_pc">
        <vers num="6.0" edition="" />
        <vers num="6.0" edition=":mac" />
        <vers num="6.1" edition="" />
        <vers num="6.1" edition=":mac" />
        <vers num="6.2" edition="" />
        <vers num="6.2" edition=":mac" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0116" published="2004-06-01" name="CVE-2004-0116" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">An Activation function in the RPCSS Service involved with DCOM activation for Microsoft Windows 2000, XP, and 2003 allows remote attackers to cause a denial of service (memory consumption) via an activation request with a large length field.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/417052" source="CERT-VN" patch="1" adv="1">VU#417052</ref>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA04-104A.html" source="CERT" adv="1">TA04-104A</ref>
      <ref url="http://www.eeye.com/html/Research/Advisories/AD20040413A.html" source="EEYE" patch="1" adv="1">AD20040413A</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms04-012.asp" source="MS">MS04-012</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15708" source="XF">win-rpcss-rpcmessage-dos(15708)</ref>
      <ref url="http://www.securityfocus.com/bid/10127" source="BID">10127</ref>
      <ref url="http://www.ciac.org/ciac/bulletins/o-115.shtml" source="CIAC">O-115</ref>
      <ref url="http://securitytracker.com/alerts/2004/Apr/1009758.html" source="SECTRACK">1009758</ref>
      <ref url="http://secunia.com/advisories/11065/" source="SECUNIA">11065</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:958" source="OVAL" sig="1">oval:org.mitre.oval:def:958</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:957" source="OVAL" sig="1">oval:org.mitre.oval:def:957</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:955" source="OVAL" sig="1">oval:org.mitre.oval:def:955</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_2000">
        <vers num="" />
      </prod>
      <prod vendor="microsoft" name="windows_2003_server">
        <vers num="r2" />
      </prod>
      <prod vendor="microsoft" name="windows_xp">
        <vers num="" edition="gold" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0117" published="2004-06-01" name="CVE-2004-0117" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Unknown vulnerability in the H.323 protocol implementation in Windows 98, Windows 2000, Windows XP, and Windows Server 2003 allows remote attackers to execute arbitrary code.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/353956" source="CERT-VN" patch="1" adv="1">VU#353956</ref>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA04-104A.html" source="CERT" adv="1">TA04-104A</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms04-011.asp" source="MS">MS04-011</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15710" source="XF">win-h323-bo(15710)</ref>
      <ref url="http://www.ciac.org/ciac/bulletins/o-114.shtml" source="CIAC">O-114</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:964" source="OVAL" sig="1">oval:org.mitre.oval:def:964</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:946" source="OVAL" sig="1">oval:org.mitre.oval:def:946</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:907" source="OVAL" sig="1">oval:org.mitre.oval:def:907</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="netmeeting">
        <vers prev="1" num="3" />
      </prod>
      <prod vendor="microsoft" name="windows_2000">
        <vers num="" />
      </prod>
      <prod vendor="microsoft" name="windows_2003_server">
        <vers num="r2" />
      </prod>
      <prod vendor="microsoft" name="windows_98">
        <vers num="" edition="gold" />
      </prod>
      <prod vendor="microsoft" name="windows_me">
        <vers num="" />
      </prod>
      <prod vendor="microsoft" name="windows_xp">
        <vers num="" edition="gold" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0118" published="2004-06-01" name="CVE-2004-0118" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">The component for the Virtual DOS Machine (VDM) subsystem in Windows NT 4.0 and Windows 2000 does not properly validate system structures, which allows local users to access protected kernel memory and execute arbitrary code.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" other="1" admin="1" />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/783748" source="CERT-VN" patch="1" adv="1">VU#783748</ref>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA04-104A.html" source="CERT" adv="1">TA04-104A</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms04-011.asp" source="MS" patch="1" adv="1">MS04-011</ref>
      <ref url="http://www.eeye.com/html/Research/Advisories/AD20040413E.html" source="EEYE" patch="1" adv="1">AD20040413E</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2004-April/020070.html" source="FULLDISC">20040413 EEYE: Windows VDM TIB Local Privilege Escalation</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15714" source="XF">win-vdm-gain-privileges(15714)</ref>
      <ref url="http://www.securityfocus.com/bid/10117" source="BID">10117</ref>
      <ref url="http://www.ciac.org/ciac/bulletins/o-114.shtml" source="CIAC">O-114</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1718" source="OVAL" sig="1">oval:org.mitre.oval:def:1718</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1512" source="OVAL" sig="1">oval:org.mitre.oval:def:1512</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_2000">
        <vers num="" />
      </prod>
      <prod vendor="microsoft" name="windows_nt">
        <vers num="4.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0119" published="2004-06-01" name="CVE-2004-0119" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">The Negotiate Security Software Provider (SSP) interface in Windows 2000, Windows XP, and Windows Server 2003, allows remote attackers to cause a denial of service (crash from null dereference) or execute arbitrary code via a crafted SPNEGO NegTokenInit request during authentication protocol selection.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/638548" source="CERT-VN" patch="1" adv="1">VU#638548</ref>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA04-104A.html" source="CERT" adv="1">TA04-104A</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms04-011.asp" source="MS">MS04-011</ref>
      <ref url="http://archives.neohapsis.com/archives/vulnwatch/2004-q1/0081.html" source="VULNWATCH">20040414 NSFOCUS SA2004-01 : DoS Vulnerability in Microsoft Windows SPNEGO Protocol Decoding</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15715" source="XF">win-spp-bo(15715)</ref>
      <ref url="http://www.securityfocus.com/bid/10113" source="BID">10113</ref>
      <ref url="http://www.ciac.org/ciac/bulletins/o-114.shtml" source="CIAC">O-114</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1997" source="OVAL" sig="1">oval:org.mitre.oval:def:1997</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1962" source="OVAL" sig="1">oval:org.mitre.oval:def:1962</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1808" source="OVAL" sig="1">oval:org.mitre.oval:def:1808</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="internet_information_server">
        <vers num="" />
      </prod>
      <prod vendor="microsoft" name="windows_2000">
        <vers num="" />
      </prod>
      <prod vendor="microsoft" name="windows_2003_server">
        <vers num="r2" />
      </prod>
      <prod vendor="microsoft" name="windows_xp">
        <vers num="" edition="gold" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0120" published="2004-06-01" name="CVE-2004-0120" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The Microsoft Secure Sockets Layer (SSL) library, as used in Windows 2000, Windows XP, and Windows Server 2003, allows remote attackers to cause a denial of service via malformed SSL messages.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/150236" source="CERT-VN" patch="1" adv="1">VU#150236</ref>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA04-104A.html" source="CERT" adv="1">TA04-104A</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms04-011.asp" source="MS">MS04-011</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15712" source="XF">ssl-message-dos(15712)</ref>
      <ref url="http://www.securityfocus.com/bid/10115" source="BID">10115</ref>
      <ref url="http://www.ciac.org/ciac/bulletins/o-114.shtml" source="CIAC">O-114</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:892" source="OVAL" sig="1">oval:org.mitre.oval:def:892</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:886" source="OVAL" sig="1">oval:org.mitre.oval:def:886</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:885" source="OVAL" sig="1">oval:org.mitre.oval:def:885</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_2000">
        <vers num="" />
      </prod>
      <prod vendor="microsoft" name="windows_2003_server">
        <vers num="r2" />
      </prod>
      <prod vendor="microsoft" name="windows_xp">
        <vers num="" edition="gold" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0121" published="2004-04-15" name="CVE-2004-0121" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Argument injection vulnerability in Microsoft Outlook 2002 does not sufficiently filter parameters of mailto: URLs when using them as arguments when calling OUTLOOK.EXE, which allows remote attackers to use script code in the Local Machine zone and execute arbitrary programs.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA04-070A.html" source="CERT">TA04-070A</ref>
      <ref url="http://www.kb.cert.org/vuls/id/305206" source="CERT-VN">VU#305206</ref>
      <ref url="http://www.securityfocus.com/bid/9827" source="BID" patch="1" adv="1">9827</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms04-009.asp" source="MS" patch="1" adv="1">MS04-009</ref>
      <ref url="http://www.idefense.com/application/poi/display?id=79&amp;type=vulnerabilities" source="IDEFENSE" patch="1" adv="1">20040309 Microsoft Outlook "mailto:" Parameter Passing Vulnerability</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15429" source="XF">outlook-ms04009-patch(15429)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15414" source="XF">outlook-mailtourl-execute-code(15414)</ref>
      <ref url="http://www.ciac.org/ciac/bulletins/o-096.shtml" source="CIAC">O-096</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107893704602842&amp;w=2" source="BUGTRAQ">20040310 Outlook mailto: URL argument injection vulnerability</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:843" source="OVAL" sig="1">oval:org.mitre.oval:def:843</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="office">
        <vers num="xp" edition="sp1" />
        <vers num="xp" edition="sp2" />
      </prod>
      <prod vendor="microsoft" name="outlook">
        <vers num="2002" edition="sp1" />
        <vers num="2002" edition="sp2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0122" published="2004-04-15" name="CVE-2004-0122" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Microsoft MSN Messenger 6.0 and 6.1 does not properly handle certain requests, which allows remote attackers to read arbitrary files.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/688094" source="CERT-VN">VU#688094</ref>
      <ref url="http://www.securityfocus.com/bid/9828" source="BID" patch="1" adv="1">9828</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms04-010.asp" source="MS" patch="1" adv="1">MS04-010</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15427" source="XF">msn-ms04010-patch(15427)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15415" source="XF">msn-request-view-files(15415)</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:844" source="OVAL" sig="1">oval:org.mitre.oval:def:844</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="msn_messenger">
        <vers num="6.0" />
        <vers num="6.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0123" published="2004-06-01" name="CVE-2004-0123" modified="2008-09-10" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Double free vulnerability in the ASN.1 library as used in Windows NT 4.0, Windows 2000, Windows XP, and Windows Server 2003, allows remote attackers to cause a denial of service and possibly execute arbitrary code.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/255924" source="CERT-VN" patch="1" adv="1">VU#255924</ref>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA04-104A.html" source="CERT" adv="1">TA04-104A</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15713" source="XF">win-asn1-double-free(15713)</ref>
      <ref url="http://www.securityfocus.com/bid/10118" source="BID">10118</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms04-011.asp" source="MS">MS04-011</ref>
      <ref url="http://www.ciac.org/ciac/bulletins/o-114.shtml" source="CIAC">O-114</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:924" source="OVAL" sig="1">oval:org.mitre.oval:def:924</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1076" source="OVAL" sig="1">oval:org.mitre.oval:def:1076</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1007" source="OVAL" sig="1">oval:org.mitre.oval:def:1007</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_2000">
        <vers num="" />
      </prod>
      <prod vendor="microsoft" name="windows_2003_server">
        <vers num="r2" />
      </prod>
      <prod vendor="microsoft" name="windows_98">
        <vers num="" edition="gold" />
      </prod>
      <prod vendor="microsoft" name="windows_98se">
        <vers num="" />
      </prod>
      <prod vendor="microsoft" name="windows_me">
        <vers num="" />
      </prod>
      <prod vendor="microsoft" name="windows_nt">
        <vers num="4.0" />
      </prod>
      <prod vendor="microsoft" name="windows_xp">
        <vers num="" edition="gold" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2004-0124" published="2004-06-01" name="CVE-2004-0124" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:N/A:N)" CVSS_score="2.6" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="4.9" CVSS_base_score="2.6">
    <desc>
      <descript source="cve">The DCOM RPC interface for Microsoft Windows NT 4.0, 2000, XP, and Server 2003 allows remote attackers to cause network communications via an "alter context" call that contains additional data, aka the "Object Identity Vulnerability."</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
      <race />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/212892" source="CERT-VN" patch="1" adv="1">VU#212892</ref>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA04-104A.html" source="CERT" adv="1">TA04-104A</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15711" source="XF">win-objectidentifier-open-port(15711)</ref>
      <ref url="http://www.securityfocus.com/bid/10121" source="BID">10121</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms04-012.asp" source="MS">MS04-012</ref>
      <ref url="http://www.ciac.org/ciac/bulletins/o-115.shtml" source="CIAC">O-115</ref>
      <ref url="http://secunia.com/advisories/11065/" source="SECUNIA">11065</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1072" source="OVAL" sig="1">oval:org.mitre.oval:def:1072</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1066" source="OVAL" sig="1">oval:org.mitre.oval:def:1066</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1062" source="OVAL" sig="1">oval:org.mitre.oval:def:1062</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1041" source="OVAL" sig="1">oval:org.mitre.oval:def:1041</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_2000">
        <vers num="" />
      </prod>
      <prod vendor="microsoft" name="windows_2003_server">
        <vers num="r2" />
      </prod>
      <prod vendor="microsoft" name="windows_nt">
        <vers num="4.0" edition="" />
        <vers num="4.0" edition=":terminal_server" />
        <vers num="4.0" edition=":workstation" />
        <vers num="4.0" edition=":server" />
      </prod>
      <prod vendor="microsoft" name="windows_xp">
        <vers num="" edition="gold" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0125" published="2004-08-06" name="CVE-2004-0125" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">The jail system call in FreeBSD 4.x before 4.10-RELEASE does not verify that an attempt to manipulate routing tables originated from a non-jailed process, which could allow local users to modify the routing table.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/10485" source="BID" patch="1" adv="1">10485</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/16342" source="XF" adv="1">freebsd-jailed-table-modify(16342)</ref>
      <ref url="ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-04:12.jailroute.asc" source="FREEBSD">FreeBSD-SA-04:12</ref>
    </refs>
    <vuln_soft>
      <prod vendor="freebsd" name="freebsd">
        <vers num="4.0" edition="alpha" />
        <vers num="4.0" edition="releng" />
        <vers num="4.1" />
        <vers num="4.1.1" edition="release" />
        <vers num="4.1.1" edition="stable" />
        <vers num="4.10" />
        <vers num="4.2" edition="stable" />
        <vers num="4.3" edition="release" />
        <vers num="4.3" edition="release_p38" />
        <vers num="4.3" edition="releng" />
        <vers num="4.3" edition="stable" />
        <vers num="4.4" edition="release_p42" />
        <vers num="4.4" edition="releng" />
        <vers num="4.4" edition="stable" />
        <vers num="4.5" edition="release" />
        <vers num="4.5" edition="release_p32" />
        <vers num="4.5" edition="releng" />
        <vers num="4.5" edition="stable" />
        <vers num="4.6" edition="release" />
        <vers num="4.6" edition="release_p20" />
        <vers num="4.6" edition="releng" />
        <vers num="4.6" edition="stable" />
        <vers num="4.6.2" />
        <vers num="4.7" edition="release" />
        <vers num="4.7" edition="release_p17" />
        <vers num="4.7" edition="releng" />
        <vers num="4.7" edition="stable" />
        <vers num="4.8" edition="pre-release" />
        <vers num="4.8" edition="release_p6" />
        <vers num="4.8" edition="releng" />
        <vers num="4.9" edition="pre-release" />
        <vers num="4.9" edition="releng" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0126" published="2004-03-29" name="CVE-2004-0126" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">The jail_attach system call in FreeBSD 5.1 and 5.2 changes the directory of a calling process even if the process doesn't have permission to change directory, which allows local users to gain read/write privileges to files and directories within another jail.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/9762" source="BID" patch="1" adv="1">9762</ref>
      <ref url="ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-04:03.jail.asc" source="FREEBSD" patch="1" adv="1">FreeBSD-SA-04:03</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15344" source="XF" adv="1">freebsd-jailattach-gain-privileges(15344)</ref>
      <ref url="http://www.osvdb.org/4101" source="OSVDB">4101</ref>
    </refs>
    <vuln_soft>
      <prod vendor="freebsd" name="freebsd">
        <vers num="5.1" edition="release" />
        <vers num="5.2" />
        <vers num="5.2.1" edition="release" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0127" published="2004-03-03" name="CVE-2004-0127" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Directory traversal vulnerability in editconfig_gedcom.php for phpGedView 2.65.1 and earlier allows remote attackers to read arbitrary files or execute arbitrary PHP programs on the server via .. (dot dot) sequences in the gedcom_config parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/9529" source="BID" patch="1" adv="1">9529</ref>
      <ref url="http://www.securityfocus.com/archive/1/352355" source="BUGTRAQ" patch="1" adv="1">20040129 PHP Code Injection Vulnerabilities in phpGedView 2.65.1 and prior</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15129" source="XF">phpgedview-editconfig-directory-traversal(15129)</ref>
      <ref url="http://www.securitytracker.com/id?1008892" source="SECTRACK">1008892</ref>
      <ref url="http://www.osvdb.org/displayvuln.php?osvdb_id=3768" source="OSVDB">3768</ref>
      <ref url="http://secunia.com/advisories/10753/" source="SECUNIA">10753</ref>
    </refs>
    <vuln_soft>
      <prod vendor="phpgedview" name="phpgedview">
        <vers num="2.52.3" />
        <vers num="2.60" />
        <vers num="2.61" />
        <vers num="2.61.1" />
        <vers num="2.65" />
        <vers num="2.65.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0128" published="2004-03-03" name="CVE-2004-0128" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">PHP remote file inclusion vulnerability in the GEDCOM configuration script for phpGedView 2.65.1 and earlier allows remote attackers to execute arbitrary PHP code by modifying the PGV_BASE_DIRECTORY parameter to reference a URL on a remote web server that contains a malicious theme.php script.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/9531" source="BID" patch="1" adv="1">9531</ref>
      <ref url="http://www.securityfocus.com/archive/1/352355" source="BUGTRAQ" patch="1" adv="1">20040129 PHP Code Injection Vulnerabilities in phpGedView 2.65.1 and prior</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/14987" source="XF">phpgedview-gedfilconf-file-include(14987)</ref>
      <ref url="http://www.osvdb.org/3769" source="OSVDB">3769</ref>
      <ref url="http://sourceforge.net/project/shownotes.php?release_id=141517" source="CONFIRM" adv="1">http://sourceforge.net/project/shownotes.php?release_id=141517</ref>
      <ref url="http://secunia.com/advisories/10753/" source="SECUNIA">10753</ref>
    </refs>
    <vuln_soft>
      <prod vendor="phpgedview" name="phpgedview">
        <vers num="2.52.3" />
        <vers num="2.60" />
        <vers num="2.61" />
        <vers num="2.61.1" />
        <vers num="2.65" />
        <vers num="2.65.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0129" published="2004-03-03" name="CVE-2004-0129" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in export.php in phpMyAdmin 2.5.5 and earlier allows remote attackers to read arbitrary files via .. (dot dot) sequences in the what parameter.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/9564" source="BID" patch="1" adv="1">9564</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107582619125932&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20040203 Arbitrary File Disclosure Vulnerability in phpMyAdmin 2.5.5-pl1 and prior</ref>
      <ref url="http://www.phpmyadmin.net/home_page/relnotes.php?rel=0" source="CONFIRM">http://www.phpmyadmin.net/home_page/relnotes.php?rel=0</ref>
      <ref url="http://sourceforge.net/forum/forum.php?forum_id=350228" source="CONFIRM">http://sourceforge.net/forum/forum.php?forum_id=350228</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200402-05.xml" source="GENTOO" adv="1">GLSA-200402-05</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15021" source="XF">phpmyadmin-dotdot-directory-traversal(15021)</ref>
      <ref url="http://www.osvdb.org/3800" source="OSVDB">3800</ref>
      <ref url="http://secunia.com/advisories/10769" source="SECUNIA">10769</ref>
    </refs>
    <vuln_soft>
      <prod vendor="phpmyadmin" name="phpmyadmin">
        <vers num="2.0" />
        <vers num="2.0.1" />
        <vers num="2.0.2" />
        <vers num="2.0.3" />
        <vers num="2.0.4" />
        <vers num="2.0.5" />
        <vers num="2.1" />
        <vers num="2.1.1" />
        <vers num="2.1.2" />
        <vers num="2.2.2" />
        <vers num="2.2.3" />
        <vers num="2.2.4" />
        <vers num="2.2.5" />
        <vers num="2.2.6" />
        <vers num="2.2_pre1" />
        <vers num="2.2_rc1" />
        <vers num="2.2_rc2" />
        <vers num="2.2_rc3" />
        <vers num="2.3.1" />
        <vers num="2.3.2" />
        <vers num="2.4.0" />
        <vers num="2.5.0" />
        <vers num="2.5.1" />
        <vers num="2.5.2" />
        <vers num="2.5.4" />
        <vers num="2.5.5" />
        <vers num="2.5.5_pl1" />
        <vers num="2.5.5_rc1" />
        <vers num="2.5.5_rc2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0130" published="2004-03-03" name="CVE-2004-0130" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">login.php in phpGedView 2.65 and earlier allows remote attackers to obtain sensitive information via an HTTP request to login.php that does not contain the required username or password parameters, which causes the information to be leaked in an error message.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securiteam.com/unixfocus/5NP0M1PBPQ.html" source="MISC" adv="1">http://www.securiteam.com/unixfocus/5NP0M1PBPQ.html</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15128" source="XF">phpgedview-loginphp-path-disclosure(15128)</ref>
      <ref url="http://www.osvdb.org/6886" source="OSVDB">6886</ref>
      <ref url="http://www.netvigilance.com/advisory0001" source="MISC">http://www.netvigilance.com/advisory0001</ref>
      <ref url="http://securitytracker.com/alerts/2004/Jan/1008844.html" source="SECTRACK">1008844</ref>
    </refs>
    <vuln_soft>
      <prod vendor="phpgedview" name="phpgedview">
        <vers prev="1" num="2.65" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0131" published="2004-03-03" name="CVE-2004-0131" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The rad_print_request function in logger.c for GNU Radius daemon (radiusd) before 1.2 allows remote atackers to cause a denial of service (crash) via a UDP packet with an Acct-Status-Type attribute without a value and no Acct-Session-Id attribute, which causes a null dereference.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/277396" source="CERT-VN" adv="1">VU#277396</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15046" source="XF" patch="1" adv="1">radius-radprintrequest-dos(15046)</ref>
      <ref url="http://www.securityfocus.com/bid/9578" source="BID" patch="1" adv="1">9578</ref>
      <ref url="http://ftp.gnu.org/gnu/radius/radius-1.2.tar.gz" source="CONFIRM">http://ftp.gnu.org/gnu/radius/radius-1.2.tar.gz</ref>
      <ref url="http://www.osvdb.org/3824" source="OSVDB">3824</ref>
      <ref url="http://www.idefense.com/application/poi/display?id=71&amp;type=vulnerabilities&amp;flashstatus=true" source="IDEFENSE">20040204 GNU Radius Remote Denial of Service Vulnerability</ref>
      <ref url="http://secunia.com/advisories/10799" source="SECUNIA">10799</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gnu" name="radius">
        <vers num="1.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0132" published="2004-03-03" name="CVE-2004-0132" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple PHP remote file inclusion vulnerabilities in ezContents 2.0.2 and earlier allow remote attackers to execute arbitrary PHP code from a remote web server, as demonstrated using (1) the GLOBALS[rootdp] parameter to db.php, or (2) the GLOBALS[language_home] parameter to archivednews.php, and a malicious version of lang_admin.php.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107651585921958&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20040210 PHP Code Injection Vulnerabilities in ezContents 2.0.2 and prior</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15135" source="XF" adv="1">ezcontents-multiple-file-include(15135)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="visualshapers" name="ezcontents">
        <vers num="1.40" />
        <vers num="1.41" />
        <vers num="1.42" />
        <vers num="1.43" />
        <vers num="1.44" />
        <vers num="1.45" />
        <vers num="1.45b" />
        <vers num="2.0.1" />
        <vers num="2.0.2" />
        <vers num="2.0_rc1" />
        <vers num="2.0_rc2" />
        <vers num="2.0_rc3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2004-0133" published="2004-06-01" name="CVE-2004-0133" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">The XFS file system code in Linux 2.4.x has an information leak in which in-memory data is written to the device for the XFS file system, which allows local users to obtain sensitive information by reading the raw device.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <config />
      <other />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.linuxsecurity.com/advisories/engarde_advisory-4285.html" source="ENGARDE" patch="1" adv="1">ESA-20040428-004</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108213675028441&amp;w=2" source="TRUSTIX" patch="1" adv="1">2004-0020</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/20040405-01-U.asc" source="SGI" patch="1" adv="1">20040405-01-U</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200407-02.xml" source="GENTOO">GLSA-200407-02</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15901" source="XF">linux-xfs-info-disclosure(15901)</ref>
      <ref url="http://www.securityfocus.com/bid/10151" source="BID">10151</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2004:029" source="MANDRAKE">MDKSA-2004:029</ref>
      <ref url="http://secunia.com/advisories/11362" source="SECUNIA">11362</ref>
    </refs>
    <vuln_soft>
      <prod vendor="linux" name="linux_kernel">
        <vers num="2.4.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0134" published="2004-08-18" name="CVE-2004-0134" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">cpr (libcpr) in SGI IRIX before 6.5.25 allows local users to gain privileges by loading a user provided library while restarting the checkpointed process.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" admin="1" />
    </loss_types>
    <vuln_types>
      <input />
      <exception />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/16259" source="XF" adv="1">irix-cpr-gain-privileges(16259)</ref>
      <ref url="http://www.securityfocus.com/bid/10418" source="BID" adv="1">10418</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/20040507-01-P.asc" source="SGI">20040507-01-P</ref>
    </refs>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0135" published="2004-08-06" name="CVE-2004-0135" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">The syssgi SGI_IOPROBE system call in IRIX 6.5.20 through 6.5.24 allows local users to gain privileges by reading and writing to kernel memory.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" admin="1" />
    </loss_types>
    <vuln_types>
      <access />
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/16413" source="XF" adv="1">irix-sgiioprobe-gain-privileges(16413)</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/20040601-01-P.asc" source="SGI">20040601-01-P</ref>
      <ref url="http://www.osvdb.org/7122" source="OSVDB">7122</ref>
      <ref url="http://secunia.com/advisories/11872" source="SECUNIA">11872</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sgi" name="irix">
        <vers num="3.2" />
        <vers num="3.3" />
        <vers num="3.3.1" />
        <vers num="3.3.2" />
        <vers num="3.3.3" />
        <vers num="4.0" />
        <vers num="4.0.1" />
        <vers num="4.0.1t" />
        <vers num="4.0.2" />
        <vers num="4.0.3" />
        <vers num="4.0.4" />
        <vers num="4.0.4b" />
        <vers num="4.0.4t" />
        <vers num="4.0.5" />
        <vers num="4.0.5_iop" />
        <vers num="4.0.5_ipr" />
        <vers num="4.0.5a" />
        <vers num="4.0.5b" />
        <vers num="4.0.5e" />
        <vers num="4.0.5f" />
        <vers num="4.0.5g" />
        <vers num="4.0.5h" />
        <vers num="5.0" />
        <vers num="5.0.1" />
        <vers num="5.1" />
        <vers num="5.1.1" />
        <vers num="5.2" />
        <vers num="5.3" edition="" />
        <vers num="5.3" edition=":xfs" />
        <vers num="6.0" />
        <vers num="6.0.1" edition="" />
        <vers num="6.0.1" edition=":xfs" />
        <vers num="6.1" />
        <vers num="6.2" />
        <vers num="6.3" />
        <vers num="6.4" />
        <vers num="6.5" />
        <vers num="6.5.1" />
        <vers num="6.5.10" />
        <vers num="6.5.10f" />
        <vers num="6.5.10m" />
        <vers num="6.5.11" />
        <vers num="6.5.11f" />
        <vers num="6.5.11m" />
        <vers num="6.5.12" />
        <vers num="6.5.12f" />
        <vers num="6.5.12m" />
        <vers num="6.5.13" />
        <vers num="6.5.13f" />
        <vers num="6.5.13m" />
        <vers num="6.5.14" />
        <vers num="6.5.14f" />
        <vers num="6.5.14m" />
        <vers num="6.5.15" />
        <vers num="6.5.15f" />
        <vers num="6.5.15m" />
        <vers num="6.5.16" />
        <vers num="6.5.16f" />
        <vers num="6.5.16m" />
        <vers num="6.5.17" />
        <vers num="6.5.17f" />
        <vers num="6.5.17m" />
        <vers num="6.5.18" />
        <vers num="6.5.18f" />
        <vers num="6.5.18m" />
        <vers num="6.5.19" />
        <vers num="6.5.19f" />
        <vers num="6.5.19m" />
        <vers num="6.5.2" />
        <vers num="6.5.20" />
        <vers num="6.5.20f" />
        <vers num="6.5.20m" />
        <vers num="6.5.21" />
        <vers num="6.5.21f" />
        <vers num="6.5.21m" />
        <vers num="6.5.22" />
        <vers num="6.5.22m" />
        <vers num="6.5.23" />
        <vers num="6.5.24" />
        <vers num="6.5.2f" />
        <vers num="6.5.2m" />
        <vers num="6.5.3" />
        <vers num="6.5.3f" />
        <vers num="6.5.3m" />
        <vers num="6.5.4" />
        <vers num="6.5.4f" />
        <vers num="6.5.4m" />
        <vers num="6.5.5" />
        <vers num="6.5.5f" />
        <vers num="6.5.5m" />
        <vers num="6.5.6" />
        <vers num="6.5.6f" />
        <vers num="6.5.6m" />
        <vers num="6.5.7" />
        <vers num="6.5.7f" />
        <vers num="6.5.7m" />
        <vers num="6.5.8" />
        <vers num="6.5.8f" />
        <vers num="6.5.8m" />
        <vers num="6.5.9" />
        <vers num="6.5.9f" />
        <vers num="6.5.9m" />
        <vers num="6.5_20" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2004-0136" published="2004-08-06" name="CVE-2004-0136" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">The mapelf32exec function call in IRIX 6.5.20 through 6.5.24 allows local users to cause a denial of service (system crash) via a "corrupted binary."</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
      <other />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/16416" source="XF" adv="1">irix-mapelf32exec-dos(16416)</ref>
      <ref url="http://www.securityfocus.com/bid/10547" source="BID" adv="1">10547</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/20040601-01-P.asc" source="SGI">20040601-01-P</ref>
      <ref url="http://www.osvdb.org/7123" source="OSVDB">7123</ref>
      <ref url="http://secunia.com/advisories/11872" source="SECUNIA">11872</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sgi" name="irix">
        <vers num="6.5.20f" />
        <vers num="6.5.20m" />
        <vers num="6.5.21f" />
        <vers num="6.5.21m" />
        <vers num="6.5.22" />
        <vers num="6.5.23" />
        <vers num="6.5.24" />
        <vers num="6.5.25" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2004-0137" published="2004-08-06" name="CVE-2004-0137" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">Unknown vulnerability in init for IRIX 6.5.20 through 6.5.24 allows local users to cause a denial of service (system panic) as a result of "page invalidation issues."</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
      <other />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/16417" source="XF" adv="1">irix-page-dos(16417)</ref>
      <ref url="http://www.securityfocus.com/bid/10549" source="BID" adv="1">10549</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/20040601-01-P.asc" source="SGI">20040601-01-P</ref>
      <ref url="http://www.osvdb.org/7124" source="OSVDB">7124</ref>
      <ref url="http://secunia.com/advisories/11872" source="SECUNIA">11872</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sgi" name="irix">
        <vers num="6.5.20f" />
        <vers num="6.5.20m" />
        <vers num="6.5.21f" />
        <vers num="6.5.21m" />
        <vers num="6.5.22" />
        <vers num="6.5.23" />
        <vers num="6.5.24" />
        <vers num="6.5.25" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0138" published="2004-12-31" name="CVE-2004-0138" modified="2010-08-21" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="4.9" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="3.9" CVSS_base_score="4.9">
    <desc>
      <descript source="cve">The ELF loader in Linux kernel 2.4 before 2.4.25 allows local users to cause a denial of service (crash) via a crafted ELF file with an interpreter with an invalid arch (architecture), which triggers a BUG() when an invalid VMA is unmapped.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.debian.org/security/2006/dsa-1082" source="DEBIAN" patch="1" adv="1">DSA-1082</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1070" source="DEBIAN" patch="1" adv="1">DSA-1070</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1069" source="DEBIAN" patch="1" adv="1">DSA-1069</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1067" source="DEBIAN" patch="1" adv="1">DSA-1067</ref>
      <ref url="http://secunia.com/advisories/20202" source="SECUNIA" patch="1" adv="1">20202</ref>
      <ref url="http://secunia.com/advisories/20163" source="SECUNIA" patch="1" adv="1">20163</ref>
      <ref url="http://secunia.com/advisories/20162" source="SECUNIA" patch="1" adv="1">20162</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10123" source="OVAL">oval:org.mitre.oval:def:10123</ref>
      <ref url="http://linux.bkbits.net:8080/linux-2.4/cset@4021346f79nBb-4X_usRikR3Iyb4Vg" source="CONFIRM">http://linux.bkbits.net:8080/linux-2.4/cset@4021346f79nBb-4X_usRikR3Iyb4Vg</ref>
      <ref url="http://kernel.debian.net/debian/pool/main/kernel-source-2.4.17/kernel-source-2.4.17_2.4.17-1woody4_ia64.changes" source="CONFIRM">http://kernel.debian.net/debian/pool/main/kernel-source-2.4.17/kernel-source-2.4.17_2.4.17-1woody4_ia64.changes</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/43124" source="XF">linux-kernel-elfloader-dos(43124)</ref>
      <ref url="http://www.securityfocus.com/bid/18174" source="BID">18174</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-549.html" source="REDHAT">RHSA-2004:549</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-504.html" source="REDHAT">RHSA-2004:504</ref>
      <ref url="http://secunia.com/advisories/20338" source="SECUNIA">20338</ref>
      <ref url="http://kernel.org/pub/linux/kernel/v2.4/ChangeLog-2.4.25" source="CONFIRM">http://kernel.org/pub/linux/kernel/v2.4/ChangeLog-2.4.25</ref>
    </refs>
    <vuln_soft>
      <prod vendor="linux" name="linux_kernel">
        <vers num="2.4.0" />
        <vers num="2.4.1" />
        <vers num="2.4.10" />
        <vers num="2.4.11" />
        <vers num="2.4.12" />
        <vers num="2.4.13" />
        <vers num="2.4.14" />
        <vers num="2.4.15" />
        <vers num="2.4.16" />
        <vers num="2.4.17" />
        <vers num="2.4.18" />
        <vers num="2.4.19" />
        <vers num="2.4.2" />
        <vers num="2.4.20" />
        <vers num="2.4.21" />
        <vers num="2.4.22" />
        <vers num="2.4.23" />
        <vers num="2.4.24" />
        <vers num="2.4.3" />
        <vers num="2.4.4" />
        <vers num="2.4.5" />
        <vers num="2.4.6" />
        <vers num="2.4.7" />
        <vers num="2.4.8" />
        <vers num="2.4.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0139" published="2005-01-10" name="CVE-2004-0139" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Unknown vulnerability in the bsd.a kernel networking for SGI IRIX 6.5.22 through 6.5.25, and possibly earlier versions, in which "t_unbind changes t_bind's behavior," has unknown impact and attack vectors.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <other />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/11276" source="BID" patch="1" adv="1">11276</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/17547" source="XF" adv="1">irix-bsda-kernel(17547)</ref>
      <ref url="http://secunia.com/advisories/12682" source="SECUNIA">12682</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/20040905-01-P.asc" source="SGI">20040905-01-P</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sgi" name="irix">
        <vers num="6.5.22" />
        <vers num="6.5.23" />
        <vers num="6.5.24" />
        <vers num="6.5.25" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0143" published="2004-03-03" name="CVE-2004-0143" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Multiple vulnerabilities in Nokia 6310(i) Mobile phones allow remote attackers to cause a denial of service (reset) via malformed Bluetooth OBject EXchange (OBEX) messages, probably triggering buffer overflows.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/15107" source="XF" patch="1" adv="1">nokia-obex-dos(15107)</ref>
      <ref url="http://www.securityfocus.com/bid/9603" source="BID" patch="1" adv="1">9603</ref>
      <ref url="http://www.pentest.co.uk/documents/ptl-2004-01.html" source="MISC" patch="1" adv="1">http://www.pentest.co.uk/documents/ptl-2004-01.html</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107634788029065&amp;w=2" source="BUGTRAQ" adv="1">20040209 ptl-2004-01: Multiple vulnerabilities in Nokia phones</ref>
      <ref url="http://archives.neohapsis.com/archives/vulnwatch/2004-q1/0034.html" source="VULNWATCH">20040209 ptl-2004-01: Multiple vulnerabilities in Nokia phones</ref>
    </refs>
    <vuln_soft>
      <prod vendor="nokia" name="6310i">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0148" published="2004-04-15" name="CVE-2004-0148" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">wu-ftpd 2.6.2 and earlier, with the restricted-gid option enabled, allows local users to bypass access restrictions by changing the permissions to prevent access to their home directory, which causes wu-ftpd to use the root directory instead.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/9832" source="BID" patch="1" adv="1">9832</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-096.html" source="REDHAT" patch="1" adv="1">RHSA-2004:096</ref>
      <ref url="http://www.debian.org/security/2004/dsa-457" source="DEBIAN" patch="1" adv="1">DSA-457</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15423" source="XF">wuftpd-restrictedgid-gain-access(15423)</ref>
      <ref url="http://www.frsirt.com/english/advisories/2006/1867" source="FRSIRT">ADV-2006-1867</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-102356-1" source="SUNALERT">102356</ref>
      <ref url="http://secunia.com/advisories/20168" source="SECUNIA">20168</ref>
      <ref url="http://secunia.com/advisories/11055" source="SECUNIA">11055</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108999466902690&amp;w=2" source="HP">SSRT4704</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:648" source="OVAL" sig="1">oval:org.mitre.oval:def:648</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1637" source="OVAL" sig="1">oval:org.mitre.oval:def:1637</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1636" source="OVAL" sig="1">oval:org.mitre.oval:def:1636</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1147" source="OVAL" sig="1">oval:org.mitre.oval:def:1147</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sgi" name="propack">
        <vers num="2.3" />
        <vers num="2.4" />
      </prod>
      <prod vendor="washington_university" name="wu-ftpd">
        <vers num="2.4.1" />
        <vers num="2.4.2_beta18" edition="" />
        <vers num="2.4.2_beta18" edition=":academ" />
        <vers num="2.4.2_beta18_vr10" />
        <vers num="2.4.2_beta18_vr11" />
        <vers num="2.4.2_beta18_vr12" />
        <vers num="2.4.2_beta18_vr13" />
        <vers num="2.4.2_beta18_vr14" />
        <vers num="2.4.2_beta18_vr15" />
        <vers num="2.4.2_beta18_vr4" />
        <vers num="2.4.2_beta18_vr5" />
        <vers num="2.4.2_beta18_vr6" />
        <vers num="2.4.2_beta18_vr7" />
        <vers num="2.4.2_beta18_vr8" />
        <vers num="2.4.2_beta18_vr9" />
        <vers num="2.4.2_beta2" edition="" />
        <vers num="2.4.2_beta2" edition=":academ" />
        <vers num="2.4.2_vr16" />
        <vers num="2.4.2_vr17" />
        <vers num="2.5.0" />
        <vers num="2.6.0" />
        <vers num="2.6.1" />
        <vers num="2.6.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0149" published="2004-05-04" name="CVE-2004-0149" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Multiple buffer overflows in xboing before 2.4 allow local users to gain privileges.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" bound="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.debian.org/security/2004/dsa-451" source="DEBIAN" patch="1">DSA-451</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15347" source="XF" adv="1">xboing-bo(15347)</ref>
      <ref url="http://www.securityfocus.com/bid/9764" source="BID" adv="1">9764</ref>
    </refs>
    <vuln_soft>
      <prod vendor="xboing" name="xboing">
        <vers num="2.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0150" published="2004-04-15" name="CVE-2004-0150" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in the getaddrinfo function in Python 2.2 before 2.2.2, when IPv6 support is disabled, allows remote attackers to execute arbitrary code via an IPv6 address that is obtained using DNS.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/9836" source="BID" patch="1" adv="1">9836</ref>
      <ref url="http://www.debian.org/security/2004/dsa-458" source="DEBIAN" patch="1" adv="1">DSA-458</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15409" source="XF">python-getaddrinfo-bo(15409)</ref>
      <ref url="http://www.osvdb.org/4172" source="OSVDB">4172</ref>
      <ref url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2004:019" source="MANDRAKE">MDKSA-2004:019</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200409-03.xml" source="GENTOO">GLSA-200409-03</ref>
    </refs>
    <vuln_soft>
      <prod vendor="python_software_foundation" name="python">
        <vers num="2.2" />
        <vers num="2.2.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0151" published="2004-04-15" name="CVE-2004-0151" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Unknown vulnerability in xitalk 1.1.11 and earlier allows local users to execute arbitrary commands.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/15456" source="XF" patch="1" adv="1">xitalk-gain-privileges(15456)</ref>
      <ref url="http://www.securityfocus.com/bid/9851" source="BID" patch="1" adv="1">9851</ref>
      <ref url="http://www.debian.org/security/2004/dsa-462" source="DEBIAN" patch="1" adv="1">DSA-462</ref>
      <ref url="http://shellcode.org/Advisories/XITALK.txt" source="MISC">http://shellcode.org/Advisories/XITALK.txt</ref>
      <ref url="http://secunia.com/advisories/11114/" source="SECUNIA">11114</ref>
    </refs>
    <vuln_soft>
      <prod vendor="xintercepttalk" name="xitalk">
        <vers num="1.1.11" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0152" published="2004-04-15" name="CVE-2004-0152" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple stack-based buffer overflows in (1) the encode_mime function, (2) the encode_uuencode function, (3) or the decode_uuencode function for emil 2.1.0 and earlier allow remote attackers to execute arbitrary code via e-mail messages containing attachments with filenames.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.debian.org/security/2004/dsa-468" source="DEBIAN" patch="1" adv="1">DSA-468</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15601" source="XF" adv="1">emil-email-bo(15601)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108024939827236&amp;w=2" source="BUGTRAQ" adv="1">20040325 Re: [SECURITY] [DSA 468-1] New emil packages fix multiple vulnerabilities</ref>
    </refs>
    <vuln_soft>
      <prod vendor="emil" name="emil">
        <vers num="2.0.4" />
        <vers num="2.0.5" />
        <vers num="2.1.0_beta9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0153" published="2004-04-15" name="CVE-2004-0153" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple format string vulnerabilities in emil 2.1.0 and earlier may allow remote attackers to execute arbitrary code by triggering certain error messages.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.debian.org/security/2004/dsa-468" source="DEBIAN" patch="1" adv="1">DSA-468</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15602" source="XF" adv="1">emil-format-string(15602)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108024939827236&amp;w=2" source="BUGTRAQ" adv="1">20040325 Re: [SECURITY] [DSA 468-1] New emil packages fix multiple vulnerabilities</ref>
    </refs>
    <vuln_soft>
      <prod vendor="emil" name="emil">
        <vers num="2.0.4" />
        <vers num="2.0.5" />
        <vers num="2.1.0_beta9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0154" published="2004-06-14" name="CVE-2004-0154" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">rpc.mountd in nfs-utils after 1.0.3 and before 1.0.6 allows attackers to cause a denial of service (crash) via an NFS mount of a directory from a client whose reverse DNS lookup name is different from the forward lookup name.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
      <env />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/15418" source="XF" patch="1" adv="1">nfs-utils-dns-dos(15418)</ref>
      <ref url="http://www.trustix.org/errata/misc/2004/TSL-2004-0009-nfs-utils.asc.txt" source="TRUSTIX" patch="1" adv="1">2004-0009</ref>
      <ref url="http://www.securityfocus.com/bid/9813" source="BID" patch="1" adv="1">9813</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-072.html" source="REDHAT" patch="1" adv="1">RHSA-2004:072</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9673" source="OVAL">oval:org.mitre.oval:def:9673</ref>
      <ref url="http://bugzilla.redhat.com/bugzilla/long_list.cgi?buglist=114535" source="MISC" adv="1">http://bugzilla.redhat.com/bugzilla/long_list.cgi?buglist=114535</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:861" source="OVAL" sig="1">oval:org.mitre.oval:def:861</ref>
    </refs>
    <vuln_soft>
      <prod vendor="nfs" name="nfs-utils">
        <vers num="1.0" />
        <vers num="1.0.1" />
        <vers num="1.0.3" />
        <vers num="1.0.4" />
        <vers num="1.0.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0155" published="2004-06-01" name="CVE-2004-0155" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">The KAME IKE Daemon Racoon, when authenticating a peer during Phase 1, validates the X.509 certificate but does not verify the RSA signature authentication, which allows remote attackers to establish unauthorized IP connections or conduct man-in-the-middle attacks using a valid, trusted X.509 certificate.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <access />
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/552398" source="CERT-VN">VU#552398</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-165.html" source="REDHAT" patch="1" adv="1">RHSA-2004:165</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108369640424244&amp;w=2" source="APPLE" patch="1">APPLE-SA-2004-05-03</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108136746911000&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20040407 CAN-2004-0155:  The KAME IKE Daemon Racoon does not verify RSA Signatures during Phase 1, allows man-in-the-middle attacks and unauthorized connections</ref>
      <ref url="http://www.securityfocus.com/bid/10072" source="BID">10072</ref>
      <ref url="http://www.mandrakesecure.net/en/advisories/advisory.php?name=MDKSA-2004:069" source="MANDRAKE">MDKSA-2004:069</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200406-17.xml" source="GENTOO">GLSA-200406-17</ref>
      <ref url="http://secunia.com/advisories/11328" source="SECUNIA">11328</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9291" source="OVAL">oval:org.mitre.oval:def:9291</ref>
      <ref url="ftp://ftp.sco.com/pub/updates/UnixWare/SCOSA-2005.10/SCOSA-2005.10.txt" source="SCO">SCOSA-2005.10</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2004:027" source="MANDRAKE">MDKSA-2004:027</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:945" source="OVAL" sig="1">oval:org.mitre.oval:def:945</ref>
    </refs>
    <vuln_soft>
      <prod vendor="kame" name="racoon">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0156" published="2004-06-01" name="CVE-2004-0156" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Format string vulnerabilities in the (1) die or (2) log_event functions for ssmtp before 2.50.6 allow remote mail relays to cause a denial of service and possibly execute arbitrary code.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.debian.org/security/2004/dsa-485" source="DEBIAN" patch="1" adv="1">DSA-485</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200404-18.xml" source="GENTOO" patch="1" adv="1">GLSA-200404-18</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15872" source="XF">ssmtp-die-logevent-format-string(15872)</ref>
      <ref url="http://www.securityfocus.com/bid/10150" source="BID">10150</ref>
      <ref url="http://www.osvdb.org/5361" source="OSVDB">5361</ref>
      <ref url="http://www.osvdb.org/5360" source="OSVDB">5360</ref>
      <ref url="http://securitytracker.com/id?1009788" source="SECTRACK">1009788</ref>
      <ref url="http://secunia.com/advisories/11571" source="SECUNIA">11571</ref>
      <ref url="http://secunia.com/advisories/11485" source="SECUNIA">11485</ref>
      <ref url="http://secunia.com/advisories/11384" source="SECUNIA">11384</ref>
      <ref url="http://secunia.com/advisories/11378" source="SECUNIA">11378</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108403772130855&amp;w=2" source="BUGTRAQ">20040507 [OpenPKG-SA-2004.020] OpenPKG Security Advisory (ssmtp)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ssmtp" name="ssmtp">
        <vers prev="1" num="2.49" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0157" published="2004-06-01" name="CVE-2004-0157" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">x11.c in xonix 1.4 and earlier uses the current working directory to find and execute the rmail program, which allows local users to execute arbitrary code by modifying the path to point to a malicious rmail program.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.debian.org/security/2004/dsa-484" source="DEBIAN" patch="1" adv="1">DSA-484</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15873" source="XF">xonix-privilege-dropping(15873)</ref>
      <ref url="http://www.securityfocus.com/bid/10149" source="BID">10149</ref>
      <ref url="http://www.osvdb.org/5358" source="OSVDB">5358</ref>
      <ref url="http://shellcode.org/Advisories/XONIX.txt" source="MISC">http://shellcode.org/Advisories/XONIX.txt</ref>
      <ref url="http://securitytracker.com/id?1009789" source="SECTRACK">1009789</ref>
      <ref url="http://secunia.com/advisories/11382" source="SECUNIA">11382</ref>
    </refs>
    <vuln_soft>
      <prod vendor="xonix" name="xonix">
        <vers prev="1" num="1.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0158" published="2004-03-29" name="CVE-2004-0158" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Buffer overflow in lbreakout2 allows local users to gain 'games' group privileges via a large HOME environment variable to (1) editor.c, (2) theme.c, (3) manager.c, (4) config.c, (5) game.c, (6) levels.c, or (7) main.c.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/15229" source="XF" patch="1" adv="1">breakout2-home-bo(15229)</ref>
      <ref url="http://www.securityfocus.com/bid/9712" source="BID" patch="1" adv="1">9712</ref>
      <ref url="http://www.debian.org/security/2004/dsa-445" source="DEBIAN" patch="1" adv="1">DSA-445</ref>
      <ref url="http://security.debian.org/pool/updates/main/l/lbreakout2/lbreakout2_2.2.2-1woody1.diff.gz" source="CONFIRM">http://security.debian.org/pool/updates/main/l/lbreakout2/lbreakout2_2.2.2-1woody1.diff.gz</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107755821705356&amp;w=2" source="BUGTRAQ">20040222 lbreakout2 &lt; 2.4beta-2 local exploit</ref>
    </refs>
    <vuln_soft>
      <prod vendor="lgames" name="lbreakout2">
        <vers num="2.0" />
        <vers num="2.0.1" />
        <vers num="2.1" />
        <vers num="2.1.1" />
        <vers num="2.1.2" />
        <vers num="2.2" />
        <vers num="2.2.1" />
        <vers num="2.2.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0159" published="2004-03-15" name="CVE-2004-0159" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Format string vulnerability in hsftp 1.11 allows remote authenticated users to cause a denial of service and possibly execute arbitrary code via file names containing format string characters that are not properly handled when executing an "ls" command.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/9715" source="BID" patch="1" adv="1">9715</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107755803218677&amp;w=2" source="DEBIAN" patch="1" adv="1">DSA-447</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15276" source="XF" adv="1">hsftp-format-string(15276)</ref>
      <ref url="http://www.osvdb.org/4029" source="OSVDB">4029</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2004-February/017737.html" source="FULLDISC">20040223 Re: [SECURITY] [DSA 447-1] New hsftp packages fix format string vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="samhain_labs" name="hsftp">
        <vers num="1.10" />
        <vers num="1.11" />
        <vers num="1.4" />
        <vers num="1.5" />
        <vers num="1.6" />
        <vers num="1.7" />
        <vers num="1.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0160" published="2004-03-29" name="CVE-2004-0160" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Synaesthesia 2.2 and earlier allows local users to execute arbitrary code via a symlink attack on the configuration file.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <env />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/15279" source="XF" patch="1" adv="1">synaesthesia-configuration-symlink-attack(15279)</ref>
      <ref url="http://www.securityfocus.com/bid/9713" source="BID" patch="1" adv="1">9713</ref>
      <ref url="http://www.debian.org/security/2004/dsa-446" source="DEBIAN" patch="1" adv="1">DSA-446</ref>
    </refs>
    <vuln_soft>
      <prod vendor="synaesthesia" name="synaesthesia">
        <vers num="2.1.0" />
        <vers num="2.1.1" />
        <vers num="2.1.2" />
        <vers num="2.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0161" published="2004-10-20" name="CVE-2004-0161" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple content security gateway and antivirus products allow remote attackers to bypass content restrictions via MIME messages that use RFC2231 encoding, which may be interpreted differently by mail clients.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/9274" source="XF">mime-tools-parameter-encoding(9274)</ref>
      <ref url="http://www.uniras.gov.uk/vuls/2004/380375/mime.htm" source="MISC" adv="1">http://www.uniras.gov.uk/vuls/2004/380375/mime.htm</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109524928232568&amp;w=2" source="BUGTRAQ" adv="1">20040914 Corsaire Security Advisory - Multiple vendor MIME RFC2231 encoding issue</ref>
    </refs>
    <vuln_soft>
      <prod vendor="clearswift" name="mailsweeper">
        <vers num="4.3.10" />
        <vers num="4.3.11" />
        <vers num="4.3.13" />
        <vers num="4.3.14" />
        <vers num="4.3.15" />
        <vers num="4.3.7" />
        <vers num="4.3.8" />
      </prod>
      <prod vendor="f-secure" name="internet_gatekeeper">
        <vers num="6.3" />
        <vers num="6.31" />
        <vers num="6.32" />
        <vers num="6.4" />
      </prod>
      <prod vendor="paul_l_daniels" name="ripmime">
        <vers num="1.2.0" />
        <vers num="1.2.1" />
        <vers num="1.2.2" />
        <vers num="1.2.3" />
        <vers num="1.2.4" />
        <vers num="1.2.5" />
        <vers num="1.2.6" />
        <vers num="1.2.7" />
        <vers num="1.3.2.0" />
        <vers num="1.3.2.2" />
        <vers num="1.3.2.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0162" published="2004-10-20" name="CVE-2004-0162" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple content security gateway and antivirus products allow remote attackers to bypass content restrictions via MIME encapsulation that uses RFC822 comment fields, which may be interpreted as other fields by mail clients.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/17332" source="XF">mime-rfc822-filtering-bypass(17332)</ref>
      <ref url="http://www.uniras.gov.uk/vuls/2004/380375/mime.htm" source="MISC" adv="1">http://www.uniras.gov.uk/vuls/2004/380375/mime.htm</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109517563513776&amp;w=2" source="BUGTRAQ" adv="1">20040914 Corsaire Security Advisory - Multiple vendor MIME RFC822 comment issue</ref>
    </refs>
    <vuln_soft>
      <prod vendor="clearswift" name="mailsweeper">
        <vers num="4.3.10" />
        <vers num="4.3.11" />
        <vers num="4.3.13" />
        <vers num="4.3.14" />
        <vers num="4.3.15" />
        <vers num="4.3.7" />
        <vers num="4.3.8" />
      </prod>
      <prod vendor="f-secure" name="internet_gatekeeper">
        <vers num="6.3" />
        <vers num="6.31" />
        <vers num="6.32" />
        <vers num="6.4" />
      </prod>
      <prod vendor="paul_l_daniels" name="ripmime">
        <vers num="1.2.0" />
        <vers num="1.2.1" />
        <vers num="1.2.2" />
        <vers num="1.2.3" />
        <vers num="1.2.4" />
        <vers num="1.2.5" />
        <vers num="1.2.6" />
        <vers num="1.2.7" />
        <vers num="1.3.2.0" />
        <vers num="1.3.2.2" />
        <vers num="1.3.2.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0163" published="2004-09-28" name="CVE-2004-0163" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Sygate Secure Enterprise (SSE) 3.5MR3 and earlier does not change the key used to encrypt data, which allows remote attackers to cause a denial of service (resource exhaustion) by capturing a session and repeatedly replaying the session.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/16945" source="XF" patch="1" adv="1">sse-replay-dos(16945)</ref>
      <ref url="http://www.corsaire.com/advisories/c031120-002.txt" source="MISC" patch="1" adv="1">http://www.corsaire.com/advisories/c031120-002.txt</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109215685731675&amp;w=2" source="BUGTRAQ">20040810 Corsaire Security Advisory - Sygate Secure Enterprise replay issue</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sygate_technologies" name="secure_enterprise">
        <vers prev="1" num="3.5mr3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0164" published="2004-03-03" name="CVE-2004-0164" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">KAME IKE daemon (racoon) does not properly handle hash values, which allows remote attackers to delete certificates via (1) a certain delete message that is not properly handled in isakmp.c or isakmp_inf.c, or (2) a certain INITIAL-CONTACT message that is not properly handled in isakmp_inf.c.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107411758202662&amp;w=2" source="BUGTRAQ" patch="1">20040114 Re: unauthorized deletion of IPsec (and ISAKMP) SAs in racoon</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/14118" source="XF">openbsd-isakmp-initialcontact-delete-sa(14118)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/14117" source="XF" adv="1">openbsd-isakmp-invalidspi-delete-sa(14117)</ref>
      <ref url="http://www.securityfocus.com/bid/9417" source="BID">9417</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9737" source="OVAL">oval:org.mitre.oval:def:9737</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2004/Feb/msg00000.html" source="APPLE">APPLE-SA-2004-02-23</ref>
      <ref url="ftp://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2004-001.txt.asc" source="NETBSD">NetBSD-SA2004-001</ref>
      <ref url="http://www.securityfocus.com/bid/9416" source="BID">9416</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107403331309838&amp;w=2" source="BUGTRAQ">20040113 unauthorized deletion of IPsec (and ISAKMP) SAs in racoon</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:947" source="OVAL" sig="1">oval:org.mitre.oval:def:947</ref>
    </refs>
    <vuln_soft>
      <prod vendor="kame" name="racoon">
        <vers num="all_versions" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0165" published="2004-03-15" name="CVE-2004-0165" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Format string vulnerability in Point-to-Point Protocol (PPP) daemon (pppd) 2.4.0 for Mac OS X 10.3.2 and earlier allows remote attackers to read arbitrary pppd process data, including PAP or CHAP authentication credentials, to gain privileges.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/841742" source="CERT-VN" adv="1">VU#841742</ref>
      <ref url="http://www.securityfocus.com/bid/9730" source="BID" patch="1" adv="1">9730</ref>
      <ref url="http://www.atstake.com/research/advisories/2004/a022304-1.txt" source="ATSTAKE" patch="1" adv="1">A022304-1</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15297" source="XF" adv="1">macos-pppd-format-string(15297)</ref>
      <ref url="http://www.osvdb.org/6822" source="OSVDB">6822</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2004/Feb/msg00000.html" source="APPLE">APPLE-SA-2004-02-23</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.1" />
        <vers num="10.1.1" />
        <vers num="10.1.2" />
        <vers num="10.1.3" />
        <vers num="10.1.4" />
        <vers num="10.1.5" />
        <vers num="10.2" />
        <vers num="10.2.1" />
        <vers num="10.2.2" />
        <vers num="10.2.3" />
        <vers num="10.2.4" />
        <vers num="10.2.5" />
        <vers num="10.2.6" />
        <vers num="10.2.7" />
        <vers num="10.2.8" />
        <vers num="10.3" />
        <vers num="10.3.1" />
        <vers num="10.3.2" />
      </prod>
      <prod vendor="apple" name="mac_os_x_server">
        <vers num="10.1" />
        <vers num="10.1.1" />
        <vers num="10.1.2" />
        <vers num="10.1.3" />
        <vers num="10.1.4" />
        <vers num="10.1.5" />
        <vers num="10.2" />
        <vers num="10.2.1" />
        <vers num="10.2.2" />
        <vers num="10.2.3" />
        <vers num="10.2.4" />
        <vers num="10.2.5" />
        <vers num="10.2.6" />
        <vers num="10.2.7" />
        <vers num="10.2.8" />
        <vers num="10.3" />
        <vers num="10.3.1" />
        <vers num="10.3.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0166" published="2004-03-15" name="CVE-2004-0166" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Unknown vulnerability in Safari web browser for Mac OS X 10.2.8 related to "the display of URLs in the status bar."</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <other />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/194238" source="CERT-VN" patch="1" adv="1">VU#194238</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/14993" source="XF" patch="1" adv="1">macosx-safari-unknown(14993)</ref>
      <ref url="http://secunia.com/advisories/10959" source="SECUNIA">10959</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2004/Feb/msg00000.html" source="APPLE">APPLE-SA-2004-02-23</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.2.8" />
      </prod>
      <prod vendor="apple" name="mac_os_x_server">
        <vers num="10.2.8" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0167" published="2004-03-15" name="CVE-2004-0167" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">DiskArbitration in Mac OS X 10.2.8 and 10.3.2 does not properly initialize writeable removable media.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <other />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/578886" source="CERT-VN">VU#578886</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15300" source="XF" patch="1" adv="1">macos-diskarbitration-unknown(15300)</ref>
      <ref url="http://www.securityfocus.com/bid/9731" source="BID">9731</ref>
      <ref url="http://www.osvdb.org/6824" source="OSVDB">6824</ref>
      <ref url="http://secunia.com/advisories/10959" source="SECUNIA">10959</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2004/Feb/msg00000.html" source="APPLE">APPLE-SA-2004-02-23</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers prev="1" num="10.2.8" />
        <vers prev="1" num="10.3.2" />
      </prod>
      <prod vendor="apple" name="mac_os_x_server">
        <vers prev="1" num="10.2.8" />
        <vers prev="1" num="10.3.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0168" published="2004-03-15" name="CVE-2004-0168" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Unknown vulnerability in CoreFoundation for Mac OS X 10.3.2, related to "notification logging."</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <other />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/15299" source="XF" patch="1" adv="1">macos-corefoundation-unknown(15299)</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2004/Feb/msg00000.html" source="APPLE">APPLE-SA-2004-02-23</ref>
      <ref url="http://secunia.com/advisories/10959/" source="SECUNIA">10959</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers prev="1" num="10.2.8" />
        <vers prev="1" num="10.3.2" />
      </prod>
      <prod vendor="apple" name="mac_os_x_server">
        <vers prev="1" num="10.2.8" />
        <vers prev="1" num="10.3.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0169" published="2004-03-15" name="CVE-2004-0169" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">QuickTime Streaming Server in MacOS X 10.2.8 and 10.3.2 allows remote attackers to cause a denial of service (crash) via DESCRIBE requests with long User-Agent fields, which causes an Assert error to be triggered in the BufferIsFull function.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/460350" source="CERT-VN" adv="1">VU#460350</ref>
      <ref url="http://www.securityfocus.com/bid/9735" source="BID" patch="1" adv="1">9735</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15291" source="XF" adv="1">darwin-describe-request-dos(15291)</ref>
      <ref url="http://www.osvdb.org/6837" source="OSVDB">6837</ref>
      <ref url="http://www.osvdb.org/6826" source="OSVDB">6826</ref>
      <ref url="http://www.idefense.com/application/poi/display?id=75&amp;type=vulnerabilities" source="IDEFENSE">20040223 Darwin Streaming Server Remote Denial of Service Vulnerability</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2004/Feb/msg00000.html" source="APPLE">APPLE-SA-2004-02-23</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="darwin_streaming_server">
        <vers num="4.1.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0171" published="2004-03-15" name="CVE-2004-0171" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">FreeBSD 5.1 and earlier, and Mac OS X before 10.3.4, allows remote attackers to cause a denial of service (resource exhaustion of memory buffers and system crash) via a large number of out-of-sequence TCP packets, which prevents the operating system from creating new connections.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/395670" source="CERT-VN">VU#395670</ref>
      <ref url="http://www.securityfocus.com/bid/9792" source="BID" patch="1" adv="1">9792</ref>
      <ref url="http://www.idefense.com/application/poi/display?id=78&amp;type=vulnerabilities" source="IDEFENSE" patch="1" adv="1">20040302 FreeBSD Memory Buffer Exhaustion Denial of Service Vulnerability</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15369" source="XF" adv="1">freebsd-mbuf-dos(15369)</ref>
      <ref url="http://www.osvdb.org/4124" source="OSVDB">4124</ref>
      <ref url="http://lists.seifried.org/pipermail/security/2004-May/003743.html" source="APPLE">APPLE-SA-2004-05-28</ref>
      <ref url="ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-04:04.tcp.asc" source="FREEBSD">FreeBSD-SA-04:04</ref>
    </refs>
    <vuln_soft>
      <prod vendor="freebsd" name="freebsd">
        <vers num="4.6.2" />
        <vers num="4.7" />
        <vers num="4.8" />
        <vers num="4.9" />
        <vers num="5.0" />
        <vers num="5.1" />
        <vers num="5.2" />
      </prod>
      <prod vendor="openbsd" name="openbsd">
        <vers num="3.3" />
        <vers num="3.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0172" published="2004-03-15" name="CVE-2004-0172" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Heap-based buffer overflow in the search_for_command function of ltrace 0.3.10, if it is installed setuid, could allow local users to execute arbitrary code via a long filename.  NOTE: It is unclear whether there are any packages that install ltrace as a setuid program, so this candidate might be REJECTed.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/13389" source="XF" adv="1">ltrace-searchforcommand-bo(13389)</ref>
      <ref url="http://www.securityfocus.com/bid/8790" source="BID" adv="1">8790</ref>
      <ref url="http://securitytracker.com/id?1007896" source="SECTRACK">1007896</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2003-October/011610.html" source="FULLDISC">20031008 ltrace bug</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2003-October/011600.html" source="FULLDISC">20031008 ltrace bug</ref>
    </refs>
    <vuln_soft>
      <prod vendor="juan_cespedes" name="ltrace">
        <vers num="0.3.10" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0173" published="2004-04-15" name="CVE-2004-0173" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in Apache 1.3.29 and earlier, and Apache 2.0.48 and earlier, when running on Cygwin, allows remote attackers to read arbitrary files via a URL containing "..%5C" (dot dot encoded backslash) sequences.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/15293" source="XF" patch="1" adv="1">apache-cygwin-directory-traversal(15293)</ref>
      <ref url="http://www.securityfocus.com/bid/9733" source="BID" patch="1" adv="1">9733</ref>
      <ref url="http://www.apacheweek.com/issues/04-03-12" source="CONFIRM">http://www.apacheweek.com/issues/04-03-12</ref>
      <ref url="http://secunia.com/advisories/10962" source="SECUNIA">10962</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107765545431387&amp;w=2" source="BUGTRAQ">20040224 STG Security Advisory: [SSA-20040217-06] Apache for cygwin</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2004-February/017740.html" source="FULLDISC">20040224 STG Security Advisory: [SSA-20040217-06] Apache for cygwin directory traversal vulnerability</ref>
      <ref url="http://issues.apache.org/bugzilla/show_bug.cgi?id=26152" source="CONFIRM">http://issues.apache.org/bugzilla/show_bug.cgi?id=26152</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apache" name="http_server">
        <vers num="0.8.11" />
        <vers num="0.8.14" />
        <vers num="1.0" />
        <vers num="1.0.2" />
        <vers num="1.0.3" />
        <vers num="1.0.5" />
        <vers num="1.1" />
        <vers num="1.1.1" />
        <vers num="1.2" />
        <vers num="1.2.5" />
        <vers num="1.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0174" published="2004-05-04" name="CVE-2004-0174" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Apache 1.4.x before 1.3.30, and 2.0.x before 2.0.49, when using multiple listening sockets on certain platforms, allows remote attackers to cause a denial of service (blocked new connections) via a "short-lived connection on a rarely-accessed listening socket."</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/132110" source="CERT-VN">VU#132110</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15540" source="XF" patch="1" adv="1">apache-socket-starvation-dos(15540)</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-405.html" source="REDHAT" patch="1" adv="1">RHSA-2004:405</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108066914830552&amp;w=2" source="TRUSTIX" patch="1" adv="1">2004-0017</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107973894328806&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20040319 [ANNOUNCE] Apache HTTP Server 2.0.49 Released (fwd)</ref>
      <ref url="http://www.trustix.org/errata/2004/0027" source="TRUSTIX">2004-0027</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200405-22.xml" source="GENTOO">GLSA-200405-22</ref>
      <ref url="http://secunia.com/advisories/11170" source="SECUNIA">11170</ref>
      <ref url="http://www.slackware.com/security/viewer.php?l=slackware-security&amp;y=2004&amp;m=slackware-security.529643" source="SLACKWARE">SSA:2004-133</ref>
      <ref url="http://www.securitytracker.com/alerts/2004/Mar/1009495.html" source="SECTRACK">1009495</ref>
      <ref url="http://www.securityfocus.com/bid/9921" source="BID">9921</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2004:046" source="MANDRAKE">MDKSA-2004:046</ref>
      <ref url="http://www.apache.org/dist/httpd/CHANGES_1.3" source="CONFIRM">http://www.apache.org/dist/httpd/CHANGES_1.3</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-57628-1" source="SUNALERT">57628</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-101555-1" source="SUNALERT">101555</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108731648532365&amp;w=2" source="HP">SSRT4717</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108437852004207&amp;w=2" source="BUGTRAQ">20040512 [OpenPKG-SA-2004.021] OpenPKG Security Advisory (apache)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108369640424244&amp;w=2" source="APPLE">APPLE-SA-2004-05-03</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1982" source="OVAL" sig="1">oval:org.mitre.oval:def:1982</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:100110" source="OVAL" sig="1">oval:org.mitre.oval:def:100110</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apache" name="http_server">
        <vers prev="1" num="2.0.49" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0175" published="2004-08-18" name="CVE-2004-0175" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Directory traversal vulnerability in scp for OpenSSH before 3.4p1 allows remote malicious servers to overwrite arbitrary files.  NOTE: this may be a rediscovery of CVE-2000-0992.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/9986" source="BID" patch="1" adv="1">9986</ref>
      <ref url="https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=120147" source="CONFIRM">https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=120147</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/16323" source="XF">openssh-scp-file-overwrite(16323)</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-567.html" source="REDHAT">RHSA-2005:567</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-562.html" source="REDHAT">RHSA-2005:562</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-495.html" source="REDHAT">RHSA-2005:495</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-481.html" source="REDHAT">RHSA-2005:481</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-165.html" source="REDHAT">RHSA-2005:165</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-106.html" source="REDHAT">RHSA-2005:106</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-074.html" source="REDHAT">RHSA-2005:074</ref>
      <ref url="http://www.osvdb.org/9550" source="OSVDB">9550</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2004_09_kernel.html" source="SUSE">SuSE-SA:2004:009</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2008:191" source="MANDRIVA">MDVSA-2008:191</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:100" source="MANDRIVA">MDKSA-2005:100</ref>
      <ref url="http://www.juniper.net/support/security/alerts/adv59739.txt" source="CONFIRM">http://www.juniper.net/support/security/alerts/adv59739.txt</ref>
      <ref url="http://www.ciac.org/ciac/bulletins/o-212.shtml" source="CIAC">O-212</ref>
      <ref url="http://secunia.com/advisories/19243" source="SECUNIA">19243</ref>
      <ref url="http://secunia.com/advisories/17135" source="SECUNIA">17135</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10184" source="OVAL">oval:org.mitre.oval:def:10184</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000831" source="CONECTIVA">CLSA-2004:831</ref>
      <ref url="ftp://ftp.sco.com/pub/updates/OpenServer/SCOSA-2006.11/SCOSA-2006.11.txt" source="SCO">SCOSA-2006.11</ref>
    </refs>
    <vuln_soft>
      <prod vendor="openbsd" name="openssh">
        <vers num="3.0" />
        <vers num="3.0.1" />
        <vers num="3.0.1p1" />
        <vers num="3.0.2" />
        <vers num="3.0.2p1" />
        <vers num="3.0p1" />
        <vers num="3.1" />
        <vers num="3.1p1" />
        <vers num="3.2" />
        <vers num="3.2.2p1" />
        <vers num="3.2.3p1" />
        <vers num="3.3" />
        <vers num="3.3p1" />
        <vers num="3.4" />
        <vers num="3.4p1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0176" published="2004-05-04" name="CVE-2004-0176" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Multiple buffer overflows in Ethereal 0.8.13 to 0.10.2 allow remote attackers to cause a denial of service and possibly execute arbitrary code via the (1) NetFlow, (2) IGAP, (3) EIGRP, (4) PGM, (5) IrDA, (6) BGP, (7) ISUP, or (8) TCAP dissectors.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/931588" source="CERT-VN">VU#931588</ref>
      <ref url="http://www.kb.cert.org/vuls/id/864884" source="CERT-VN">VU#864884</ref>
      <ref url="http://www.kb.cert.org/vuls/id/740188" source="CERT-VN">VU#740188</ref>
      <ref url="http://www.kb.cert.org/vuls/id/659140" source="CERT-VN">VU#659140</ref>
      <ref url="http://www.kb.cert.org/vuls/id/644886" source="CERT-VN">VU#644886</ref>
      <ref url="http://www.kb.cert.org/vuls/id/591820" source="CERT-VN">VU#591820</ref>
      <ref url="http://www.kb.cert.org/vuls/id/433596" source="CERT-VN">VU#433596</ref>
      <ref url="http://www.kb.cert.org/vuls/id/125156" source="CERT-VN">VU#125156</ref>
      <ref url="http://www.kb.cert.org/vuls/id/119876" source="CERT-VN">VU#119876</ref>
      <ref url="http://www.debian.org/security/2004/dsa-511" source="DEBIAN" patch="1" adv="1">DSA-511</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108058005324316&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20040329 LNSA-#2004-0007: Multiple security problems in Ethereal</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15569" source="XF" adv="1">ethereal-multiple-dissectors-bo(15569)</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-137.html" source="REDHAT">RHSA-2004:137</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-136.html" source="REDHAT">RHSA-2004:136</ref>
      <ref url="http://www.ethereal.com/appnotes/enpa-sa-00013.html" source="CONFIRM">http://www.ethereal.com/appnotes/enpa-sa-00013.html</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200403-07.xml" source="GENTOO">GLSA-200403-07</ref>
      <ref url="http://security.e-matters.de/advisories/032004.html" source="MISC">http://security.e-matters.de/advisories/032004.html</ref>
      <ref url="http://secunia.com/advisories/11185" source="SECUNIA">11185</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10187" source="OVAL">oval:org.mitre.oval:def:10187</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108007072215742&amp;w=2" source="BUGTRAQ" adv="1">20040323 Advisory 03/2004: Multiple (13) Ethereal remote overflows</ref>
      <ref url="http://www.osvdb.org/6893" source="OSVDB">6893</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2004:024" source="MANDRAKE">MDKSA-2004:024</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108213710306260&amp;w=2" source="BUGTRAQ">20040416 [OpenPKG-SA-2004.015] OpenPKG Security Advisory (ethereal)</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000835" source="CONECTIVA">CLA-2004:835</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:887" source="OVAL" sig="1">oval:org.mitre.oval:def:887</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:878" source="OVAL" sig="1">oval:org.mitre.oval:def:878</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ethereal_group" name="ethereal">
        <vers num="0.10" />
        <vers num="0.10.1" />
        <vers num="0.10.2" />
        <vers num="0.8.13" />
        <vers num="0.8.14" />
        <vers num="0.8.18" />
        <vers num="0.8.19" />
        <vers num="0.9" />
        <vers num="0.9.1" />
        <vers num="0.9.10" />
        <vers num="0.9.11" />
        <vers num="0.9.12" />
        <vers num="0.9.13" />
        <vers num="0.9.14" />
        <vers num="0.9.15" />
        <vers num="0.9.16" />
        <vers num="0.9.2" />
        <vers num="0.9.3" />
        <vers num="0.9.4" />
        <vers num="0.9.5" />
        <vers num="0.9.6" />
        <vers num="0.9.7" />
        <vers num="0.9.8" />
        <vers num="0.9.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0177" published="2004-06-01" name="CVE-2004-0177" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The ext3 code in Linux 2.4.x before 2.4.26 does not properly initialize journal descriptor blocks, which causes an information leak in which in-memory data is written to the device for the ext3 file system, which allows privileged users to obtain portions of kernel memory by reading the raw device.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.linuxsecurity.com/advisories/engarde_advisory-4285.html" source="ENGARDE" patch="1" adv="1">ESA-20040428-004</ref>
      <ref url="http://www.debian.org/security/2004/dsa-495" source="DEBIAN" patch="1" adv="1">DSA-495</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2004-166.html" source="REDHAT" patch="1" adv="1">RHSA-2004:166</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108213675028441&amp;w=2" source="TRUSTIX" patch="1" adv="1">2004-0020</ref>
      <ref url="https://bugzilla.fedora.us/show_bug.cgi?id=2336" source="FEDORA">FLSA:2336</ref>
      <ref url="http://www.debian.org/security/2004/dsa-491" source="DEBIAN">DSA-491</ref>
      <ref url="http://www.debian.org/security/2004/dsa-489" source="DEBIAN">DSA-489</ref>
      <ref url="http://www.debian.org/security/2004/dsa-482" source="DEBIAN">DSA-482</ref>
      <ref url="http://www.debian.org/security/2004/dsa-481" source="DEBIAN">DSA-481</ref>
      <ref url="http://www.debian.org/security/2004/dsa-480" source="DEBIAN">DSA-480</ref>
      <ref url="http://www.debian.org/security/2004/dsa-479" source="DEBIAN">DSA-479</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200407-02.xml" source="GENTOO">GLSA-200407-02</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10556" source="OVAL">oval:org.mitre.oval:def:10556</ref>
      <ref url="http://linux.bkbits.net:8080/linux-2.4/cset@4056b368s6vpJbGWxDD_LhQNYQrdzQ" source="MISC">http://linux.bkbits.net:8080/linux-2.4/cset@4056b368s6vpJbGWxDD_LhQNYQrdzQ</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15867" source="XF">linux-ext3-info-disclosure(15867)</ref>
      <ref url="http://www.securityfocus.com/bid/10152" source="BID">10152</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-293.html" source="REDHAT">RHSA-2005:293</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-505.html" source="REDHAT">RHSA-2004:505</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-504.html" source="REDHAT">RHSA-2004:504</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2004:029" source="MANDRAKE">MDKSA-2004:029</ref>
      <ref url="http://www.ciac.org/ciac/bulletins/o-127.shtml" source="CIAC">O-127</ref>
      <ref url="http://www.ciac.org/ciac/bulletins/o-126.shtml" source="CIAC">O-126</ref>
      <ref url="http://www.ciac.org/ciac/bulletins/o-121.shtml" source="CIAC">O-121</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000846" source="CONECTIVA">CLA-2004:846</ref>
    </refs>
    <vuln_soft>
      <prod vendor="linux" name="linux_kernel">
        <vers num="2.4.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2004-0178" published="2004-06-01" name="CVE-2004-0178" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">The OSS code for the Sound Blaster (sb16) driver in Linux 2.4.x before 2.4.26, when operating in 16 bit mode, does not properly handle certain sample sizes, which allows local users to cause a denial of service (crash) via a sample with an odd number of bytes.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <design />
      <config />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.debian.org/security/2004/dsa-495" source="DEBIAN" patch="1" adv="1">DSA-495</ref>
      <ref url="http://www.debian.org/security/2004/dsa-491" source="DEBIAN" patch="1" adv="1">DSA-491</ref>
      <ref url="http://www.debian.org/security/2004/dsa-489" source="DEBIAN" patch="1" adv="1">DSA-489</ref>
      <ref url="http://www.debian.org/security/2004/dsa-482" source="DEBIAN" patch="1" adv="1">DSA-482</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-437.html" source="REDHAT">RHSA-2004:437</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-413.html" source="REDHAT">RHSA-2004:413</ref>
      <ref url="http://www.debian.org/security/2004/dsa-481" source="DEBIAN">DSA-481</ref>
      <ref url="http://www.debian.org/security/2004/dsa-480" source="DEBIAN">DSA-480</ref>
      <ref url="http://www.debian.org/security/2004/dsa-479" source="DEBIAN">DSA-479</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200407-02.xml" source="GENTOO">GLSA-200407-02</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9427" source="OVAL">oval:org.mitre.oval:def:9427</ref>
      <ref url="http://linux.bkbits.net:8080/linux-2.4/cset@404ce5967rY2Ryu6Z_uNbYh643wuFA" source="MISC">http://linux.bkbits.net:8080/linux-2.4/cset@404ce5967rY2Ryu6Z_uNbYh643wuFA</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/20040804-01-U.asc" source="SGI">20040804-01-U</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15868" source="XF">linux-sound-blaster-dos(15868)</ref>
      <ref url="http://www.securityfocus.com/bid/9985" source="BID">9985</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2004:029" source="MANDRAKE">MDKSA-2004:029</ref>
      <ref url="http://www.ciac.org/ciac/bulletins/o-193.shtml" source="CIAC">O-193</ref>
      <ref url="http://www.ciac.org/ciac/bulletins/o-127.shtml" source="CIAC">O-127</ref>
      <ref url="http://www.ciac.org/ciac/bulletins/o-121.shtml" source="CIAC">O-121</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000846" source="CONECTIVA">CLA-2004:846</ref>
    </refs>
    <vuln_soft>
      <prod vendor="linux" name="linux_kernel">
        <vers num="2.4.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0179" published="2004-06-01" name="CVE-2004-0179" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_score="5.1" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="4.9" CVSS_base_score="5.1">
    <desc>
      <descript source="cve">Multiple format string vulnerabilities in (1) neon 0.24.4 and earlier, and other products that use neon including (2) Cadaver, (3) Subversion, and (4) OpenOffice, allow remote malicious WebDAV servers to execute arbitrary code.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
      <exception />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="https://bugzilla.fedora.us/show_bug.cgi?id=1552" source="FEDORA" patch="1">FEDORA-2004-1552</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-160.html" source="REDHAT" patch="1">RHSA-2004:160</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-159.html" source="REDHAT" patch="1">RHSA-2004:159</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-158.html" source="REDHAT" patch="1">RHSA-2004:158</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-157.html" source="REDHAT" patch="1" adv="1">RHSA-2004:157</ref>
      <ref url="http://www.debian.org/security/2004/dsa-487" source="DEBIAN" patch="1" adv="1">DSA-487</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200405-04.xml" source="GENTOO" patch="1" adv="1">GLSA-200405-04</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200405-01.xml" source="GENTOO" patch="1" adv="1">GLSA-200405-01</ref>
      <ref url="http://secunia.com/advisories/11363" source="SECUNIA" patch="1" adv="1">11363</ref>
      <ref url="http://lists.suse.com/archive/suse-security-announce/2004-Apr/0003.html" source="SUSE" patch="1" adv="1">SuSE-SA:2004:008</ref>
      <ref url="http://lists.suse.com/archive/suse-security-announce/2004-Apr/0002.html" source="SUSE" patch="1" adv="1">SuSE-SA:2004:009</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/20040404-01-U.asc" source="SGI" patch="1" adv="1">20040404-01-U</ref>
      <ref url="http://www.securityfocus.com/bid/10136" source="BID">10136</ref>
      <ref url="http://www.osvdb.org/5365" source="OSVDB">5365</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2004:032" source="MANDRAKE" adv="1">MDKSA-2004:032</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10913" source="OVAL">oval:org.mitre.oval:def:10913</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108214147022626&amp;w=2" source="BUGTRAQ">20040416 void.at - neon format string bugs</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108213873203477&amp;w=2" source="BUGTRAQ">20040416 [OpenPKG-SA-2004.016] OpenPKG Security Advisory (neon)</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1065" source="OVAL" sig="1">oval:org.mitre.oval:def:1065</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cadaver" name="cadaver_webdav_client">
        <vers num="0.20.0" />
        <vers num="0.20.1" />
        <vers num="0.20.2" />
        <vers num="0.20.3" />
        <vers num="0.20.4" />
        <vers num="0.20.5" />
        <vers num="0.21.0" />
        <vers num="0.22.0" />
        <vers num="0.22.1" />
      </prod>
      <prod vendor="neon" name="neon_client_library">
        <vers num="0.19.3" />
        <vers num="0.23" />
        <vers num="0.23.1" />
        <vers num="0.23.2" />
        <vers num="0.23.3" />
        <vers num="0.23.4" />
        <vers num="0.23.5" />
        <vers num="0.23.6" />
        <vers num="0.23.7" />
        <vers num="0.23.8" />
        <vers num="0.24" />
        <vers num="0.24.1" />
        <vers num="0.24.2" />
        <vers num="0.24.3" />
        <vers num="0.24.4" />
      </prod>
      <prod vendor="openoffice" name="openoffice">
        <vers num="1.1.2" />
      </prod>
      <prod vendor="subversion" name="subversion">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2004-0180" published="2004-06-01" name="CVE-2004-0180" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:P/A:N)" CVSS_score="2.6" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="4.9" CVSS_base_score="2.6">
    <desc>
      <descript source="cve">The client for CVS before 1.11 allows a remote malicious CVS server to create arbitrary files using certain RCS diff files that use absolute pathnames during checkouts or updates, a different vulnerability than CVE-2004-0405.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-154.html" source="REDHAT" patch="1" adv="1">RHSA-2004:154</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-153.html" source="REDHAT" patch="1" adv="1">RHSA-2004:153</ref>
      <ref url="http://www.debian.org/security/2004/dsa-486" source="DEBIAN" patch="1" adv="1">DSA-486</ref>
      <ref url="ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-04:07.cvs.asc" source="FREEBSD" patch="1" adv="1">FreeBSD-SA-04:07</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9462" source="OVAL">oval:org.mitre.oval:def:9462</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/20040404-01-U.asc" source="SGI">20040404-01-U</ref>
      <ref url="ftp://ftp.openbsd.org/pub/OpenBSD/patches/3.5/common/002_cvs.patch" source="CONFIRM">ftp://ftp.openbsd.org/pub/OpenBSD/patches/3.5/common/002_cvs.patch</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15864" source="XF">cvs-rcs-create-files(15864)</ref>
      <ref url="http://www.slackware.com/security/viewer.php?l=slackware-security&amp;y=2004&amp;m=slackware-security.400181" source="SLACKWARE">SSA:2004-108-02</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2004:028" source="MANDRAKE">MDKSA-2004:028</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200404-13.xml" source="GENTOO">GLSA-200404-13</ref>
      <ref url="http://secunia.com/advisories/11548" source="SECUNIA">11548</ref>
      <ref url="http://secunia.com/advisories/11405" source="SECUNIA">11405</ref>
      <ref url="http://secunia.com/advisories/11400" source="SECUNIA">11400</ref>
      <ref url="http://secunia.com/advisories/11391" source="SECUNIA">11391</ref>
      <ref url="http://secunia.com/advisories/11380" source="SECUNIA">11380</ref>
      <ref url="http://secunia.com/advisories/11377" source="SECUNIA">11377</ref>
      <ref url="http://secunia.com/advisories/11375" source="SECUNIA">11375</ref>
      <ref url="http://secunia.com/advisories/11374" source="SECUNIA">11374</ref>
      <ref url="http://secunia.com/advisories/11371" source="SECUNIA">11371</ref>
      <ref url="http://secunia.com/advisories/11368" source="SECUNIA">11368</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108636445031613&amp;w=2" source="FEDORA">FEDORA-2004-1620</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1042" source="OVAL" sig="1">oval:org.mitre.oval:def:1042</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cvs" name="cvs">
        <vers prev="1" num="1.10" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2004-0181" published="2004-06-01" name="CVE-2004-0181" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">The JFS file system code in Linux 2.4.x has an information leak in which in-memory data is written to the device for the JFS file system, which allows local users to obtain sensitive information by reading the raw device.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.linuxsecurity.com/advisories/engarde_advisory-4285.html" source="ENGARDE" patch="1" adv="1">ESA-20040428-004</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108213675028441&amp;w=2" source="TRUSTIX" patch="1" adv="1">2004-0020</ref>
      <ref url="http://www.vupen.com/english/advisories/2005/1878" source="VUPEN">ADV-2005-1878</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200407-02.xml" source="GENTOO">GLSA-200407-02</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10329" source="OVAL">oval:org.mitre.oval:def:10329</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15902" source="XF">linux-jfs-info-disclosure(15902)</ref>
      <ref url="http://www.turbolinux.com/security/2004/TLSA-2004-14.txt" source="TURBO">TLSA-2004-14</ref>
      <ref url="http://www.securityfocus.com/bid/10143" source="BID">10143</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-663.html" source="REDHAT">RHSA-2005:663</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-504.html" source="REDHAT">RHSA-2004:504</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2004:029" source="MANDRAKE">MDKSA-2004:029</ref>
      <ref url="http://secunia.com/advisories/17002" source="SECUNIA">17002</ref>
    </refs>
    <vuln_soft>
      <prod vendor="linux" name="linux_kernel">
        <vers num="2.4.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0182" published="2004-06-01" name="CVE-2004-0182" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Mailman before 2.0.13 allows remote attackers to cause a denial of service (crash) via an email message with an empty subject field.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-156.html" source="REDHAT" patch="1" adv="1">RHSA-2004:156</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/20040404-01-U.asc" source="SGI" patch="1" adv="1">20040404-01-U</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gnu" name="mailman">
        <vers prev="1" num="2.0.12" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0183" published="2004-05-04" name="CVE-2004-0183" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">TCPDUMP 3.8.1 and earlier allows remote attackers to cause a denial of service (crash) via ISAKMP packets containing a Delete payload with a large number of SPI's, which causes an out-of-bounds read, as demonstrated by the Striker ISAKMP Protocol Test Suite.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/240790" source="CERT-VN">VU#240790</ref>
      <ref url="http://www.debian.org/security/2004/dsa-478" source="DEBIAN" patch="1" adv="1">DSA-478</ref>
      <ref url="https://bugzilla.fedora.us/show_bug.cgi?id=1468" source="FEDORA">FEDORA-2004-1468</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15680" source="XF">tcpdump-isakmp-delete-bo(15680)</ref>
      <ref url="http://www.tcpdump.org/tcpdump-changes.txt" source="CONFIRM">http://www.tcpdump.org/tcpdump-changes.txt</ref>
      <ref url="http://www.securityfocus.com/bid/10003" source="BID">10003</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-219.html" source="REDHAT">RHSA-2004:219</ref>
      <ref url="http://www.rapid7.com/advisories/R7-0017.html" source="MISC">http://www.rapid7.com/advisories/R7-0017.html</ref>
      <ref url="http://securitytracker.com/id?1009593" source="SECTRACK">1009593</ref>
      <ref url="http://secunia.com/advisories/11258" source="SECUNIA">11258</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9971" source="OVAL">oval:org.mitre.oval:def:9971</ref>
      <ref url="http://www.trustix.org/errata/2004/0015" source="TRUSTIX">2004-0015</ref>
      <ref url="http://secunia.com/advisories/11320" source="SECUNIA">11320</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108067265931525&amp;w=2" source="BUGTRAQ">20040330 R7-0017: TCPDUMP ISAKMP payload handling denial-of-service vulnerabilities</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:972" source="OVAL" sig="1">oval:org.mitre.oval:def:972</ref>
    </refs>
    <vuln_soft>
      <prod vendor="lbl" name="tcpdump">
        <vers prev="1" num="3.8.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0184" published="2004-05-04" name="CVE-2004-0184" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Integer underflow in the isakmp_id_print for TCPDUMP 3.8.1 and earlier allows remote attackers to cause a denial of service (crash) via an ISAKMP packet with an Identification payload with a length that becomes less than 8 during byte order conversion, which causes an out-of-bounds read, as demonstrated by the Striker ISAKMP Protocol Test Suite.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/492558" source="CERT-VN">VU#492558</ref>
      <ref url="http://www.debian.org/security/2004/dsa-478" source="DEBIAN" patch="1" adv="1">DSA-478</ref>
      <ref url="https://bugzilla.fedora.us/show_bug.cgi?id=1468" source="FEDORA">FEDORA-2004-1468</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15679" source="XF">tcpdump-isakmp-integer-underflow(15679)</ref>
      <ref url="http://www.tcpdump.org/tcpdump-changes.txt" source="CONFIRM">http://www.tcpdump.org/tcpdump-changes.txt</ref>
      <ref url="http://www.securityfocus.com/bid/10004" source="BID">10004</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-219.html" source="REDHAT">RHSA-2004:219</ref>
      <ref url="http://www.rapid7.com/advisories/R7-0017.html" source="MISC" adv="1">http://www.rapid7.com/advisories/R7-0017.html</ref>
      <ref url="http://securitytracker.com/id?1009593" source="SECTRACK">1009593</ref>
      <ref url="http://secunia.com/advisories/11258" source="SECUNIA">11258</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9581" source="OVAL">oval:org.mitre.oval:def:9581</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108067265931525&amp;w=2" source="BUGTRAQ">20040330 R7-0017: TCPDUMP ISAKMP payload handling denial-of-service vulnerabilities</ref>
      <ref url="http://www.trustix.org/errata/2004/0015" source="TRUSTIX">2004-0015</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:976" source="OVAL" sig="1">oval:org.mitre.oval:def:976</ref>
    </refs>
    <vuln_soft>
      <prod vendor="lbl" name="tcpdump">
        <vers prev="1" num="3.8.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0185" published="2004-03-15" name="CVE-2004-0185" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Buffer overflow in the skey_challenge function in ftpd.c for wu-ftp daemon (wu-ftpd) 2.6.2 allows remote attackers to cause a denial of service and possibly execute arbitrary code via a s/key (SKEY) request with a long name.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securiteam.com/unixfocus/6X00Q1P8KC.html" source="MISC" patch="1" adv="1">http://www.securiteam.com/unixfocus/6X00Q1P8KC.html</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-096.html" source="REDHAT" patch="1" adv="1">RHSA-2004:096</ref>
      <ref url="http://www.debian.org/security/2004/dsa-457" source="DEBIAN" patch="1" adv="1">DSA-457</ref>
      <ref url="ftp://ftp.wu-ftpd.org/pub/wu-ftpd/patches/apply_to_2.6.2/skeychallenge.patch" source="CONFIRM" patch="1">ftp://ftp.wu-ftpd.org/pub/wu-ftpd/patches/apply_to_2.6.2/skeychallenge.patch</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/13518" source="XF" adv="1">wuftpd-skey-bo(13518)</ref>
      <ref url="http://unixpunx.org/txt/exploits_archive/packetstorm/0310-advisories/wuftpd-skey.txt" source="MISC">http://unixpunx.org/txt/exploits_archive/packetstorm/0310-advisories/wuftpd-skey.txt</ref>
      <ref url="http://www.securityfocus.com/bid/8893" source="BID">8893</ref>
    </refs>
    <vuln_soft>
      <prod vendor="washington_university" name="wu-ftpd">
        <vers num="2.6.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0186" published="2004-03-15" name="CVE-2004-0186" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">smbmnt in Samba 2.x and 3.x on Linux 2.6, when installed setuid, allows local users to gain root privileges by mounting a Samba share that contains a setuid root program, whose setuid attributes are not cleared when the share is mounted.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/15131" source="XF" patch="1" adv="1">samba-smbmnt-gain-privileges(15131)</ref>
      <ref url="http://www.securityfocus.com/bid/9619" source="BID" patch="1" adv="1">9619</ref>
      <ref url="http://www.debian.org/security/2004/dsa-463" source="DEBIAN" patch="1" adv="1">DSA-463</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107636290906296&amp;w=2" source="BUGTRAQ">20040209 Samba 3.x + kernel 2.6.x local root vulnerability</ref>
      <ref url="http://www.osvdb.org/3916" source="OSVDB">3916</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107657505718743&amp;w=2" source="BUGTRAQ">20040211 Re: Samba 3.x + kernel 2.6.x local root vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="samba" name="samba">
        <vers num="2.0" />
        <vers num="3.0.0" />
      </prod>
      <prod vendor="linux" name="linux_kernel">
        <vers num="2.6.0" edition="test1" />
        <vers num="2.6.0" edition="test10" />
        <vers num="2.6.0" edition="test11" />
        <vers num="2.6.0" edition="test2" />
        <vers num="2.6.0" edition="test3" />
        <vers num="2.6.0" edition="test4" />
        <vers num="2.6.0" edition="test5" />
        <vers num="2.6.0" edition="test6" />
        <vers num="2.6.0" edition="test7" />
        <vers num="2.6.0" edition="test8" />
        <vers num="2.6.0" edition="test9" />
        <vers num="2.6.1" edition="rc1" />
        <vers num="2.6.1" edition="rc2" />
        <vers num="2.6_test9_cvs" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" seq="2004-0187" reject="1" published="2004-03-15" name="CVE-2004-0187" modified="2008-09-10">
    <desc>
      <descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: CVE-2004-0185.  Reason: This candidate is a reservation duplicate of CVE-2004-0185.  Notes: All CVE users should reference CVE-2004-0185 instead of this candidate.  All references and descriptions in this candidate have been removed to prevent accidental usage.</descript>
    </desc>
    <refs />
  </entry>
  <entry type="CVE" severity="High" seq="2004-0188" published="2004-03-15" name="CVE-2004-0188" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Heap-based buffer overflow in Calife 2.8.5 and earlier may allow local users to execute arbitrary code via a long password.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/9756" source="BID" patch="1" adv="1">9756</ref>
      <ref url="http://www.debian.org/security/2004/dsa-461" source="DEBIAN" patch="1" adv="1">DSA-461</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15335" source="XF" adv="1">calife-long-password-bo(15335)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107789737832092&amp;w=2" source="BUGTRAQ" adv="1">20040227 Calife heap corrupt / potential local root exploit</ref>
      <ref url="http://www.securityfocus.com/bid/9776" source="BID">9776</ref>
    </refs>
    <vuln_soft>
      <prod vendor="calife" name="calife">
        <vers num="2.8.4_c" />
        <vers num="2.8.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0189" published="2004-03-15" name="CVE-2004-0189" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">The "%xx" URL decoding function in Squid 2.5STABLE4 and earlier allows remote attackers to bypass url_regex ACLs via a URL with a NULL ("%00") characterm, which causes Squid to use only a portion of the requested URL when comparing it against the access control lists.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.squid-cache.org/Advisories/SQUID-2004_1.txt" source="CONFIRM" patch="1" adv="1">http://www.squid-cache.org/Advisories/SQUID-2004_1.txt</ref>
      <ref url="http://www.securityfocus.com/bid/9778" source="BID" patch="1" adv="1">9778</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15366" source="XF" adv="1">squid-urlregex-acl-bypass(15366)</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-134.html" source="REDHAT">RHSA-2004:134</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-133.html" source="REDHAT">RHSA-2004:133</ref>
      <ref url="http://www.osvdb.org/5916" source="OSVDB">5916</ref>
      <ref url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2004:025" source="MANDRAKE">MDKSA-2004:025</ref>
      <ref url="http://www.debian.org/security/2004/dsa-474" source="DEBIAN">DSA-474</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200403-11.xml" source="GENTOO">GLSA-200403-11</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108084935904110&amp;w=2" source="BUGTRAQ">20040401 [OpenPKG-SA-2004.008] OpenPKG Security  Advisory (squid)</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000838" source="CONECTIVA">CLA-2004:838</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/20040404-01-U.asc" source="SGI">20040404-01-U</ref>
      <ref url="ftp://ftp.sco.com/pub/updates/UnixWare/SCOSA-2005.16/SCOSA-2005.16.txt" source="SCO">SCOSA-2005.16</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:941" source="OVAL" sig="1">oval:org.mitre.oval:def:941</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:877" source="OVAL" sig="1">oval:org.mitre.oval:def:877</ref>
    </refs>
    <vuln_soft>
      <prod vendor="squid" name="squid">
        <vers num="2.0_patch2" />
        <vers num="2.1_patch2" />
        <vers num="2.3_stable5" />
        <vers num="2.4" />
        <vers num="2.4_stable7" />
        <vers num="2.5_stable3" />
        <vers num="2.5_stable4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0190" published="2004-03-15" name="CVE-2004-0190" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Symantec FireWall/VPN Appliance model 200 records a cleartext password for the password administration page, which may be cached on the administrator's local system or in a proxy, which allows attackers to steal the password and gain privileges.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/9784" source="BID" patch="1" adv="1">9784</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15212" source="XF" adv="1">symantec-firewallvpn-password-plaintext(15212)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107694794031839&amp;w=2" source="BUGTRAQ" adv="1">20040216 Symantec FireWall/VPN Appliance model 200 leak of security</ref>
      <ref url="http://www.osvdb.org/4117" source="OSVDB">4117</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2004-February/017414.html" source="FULLDISC">20040216 Symantec FireWall/VPN Appliance model 200 leak of security</ref>
    </refs>
    <vuln_soft>
      <prod vendor="symantec" name="firewall_vpn_appliance_100">
        <vers num="" />
      </prod>
      <prod vendor="symantec" name="firewall_vpn_appliance_200">
        <vers num="" />
      </prod>
      <prod vendor="symantec" name="firewall_vpn_appliance_200r">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0191" published="2004-03-15" name="CVE-2004-0191" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Mozilla before 1.4.2 executes Javascript events in the context of a new page while it is being loaded, allowing it to interact with the previous page (zombie document) and enable cross-domain and cross-site scripting (XSS) attacks, as demonstrated using onmousemove events.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/15322" source="XF" adv="1">mozilla-event-handler-xss(15322)</ref>
      <ref url="http://www.securityfocus.com/bid/9747" source="BID" adv="1">9747</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107774710729469&amp;w=2" source="BUGTRAQ" adv="1">20040225 Sandblad #13: Cross-domain exploit on zombie document with event handlers</ref>
      <ref url="http://bugzilla.mozilla.org/show_bug.cgi?id=227417" source="CONFIRM" adv="1">http://bugzilla.mozilla.org/show_bug.cgi?id=227417</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-112.html" source="REDHAT">RHSA-2004:112</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-110.html" source="REDHAT">RHSA-2004:110</ref>
      <ref url="http://www.osvdb.org/4062" source="OSVDB">4062</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108448379429944&amp;w=2" source="HP">SSRT4722</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:937" source="OVAL" sig="1">oval:org.mitre.oval:def:937</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:874" source="OVAL" sig="1">oval:org.mitre.oval:def:874</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="mozilla">
        <vers num="0.8" />
        <vers num="0.9.2" />
        <vers num="0.9.2.1" />
        <vers num="0.9.3" />
        <vers num="0.9.35" />
        <vers num="0.9.4" />
        <vers num="0.9.4.1" />
        <vers num="0.9.48" />
        <vers num="0.9.5" />
        <vers num="0.9.6" />
        <vers num="0.9.7" />
        <vers num="0.9.8" />
        <vers num="0.9.9" />
        <vers num="1.0" edition="rc1" />
        <vers num="1.0" edition="rc2" />
        <vers num="1.0.1" />
        <vers num="1.0.2" />
        <vers num="1.1" edition="alpha" />
        <vers num="1.1" edition="beta" />
        <vers num="1.2" edition="alpha" />
        <vers num="1.2" edition="beta" />
        <vers num="1.2.1" />
        <vers num="1.3" />
        <vers num="1.3.1" />
        <vers num="1.4" edition="alpha" />
        <vers num="1.4" edition="beta" />
        <vers num="1.4.1" />
        <vers num="1.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0192" published="2004-03-15" name="CVE-2004-0192" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in the Management Service for Symantec Gateway Security 2.0 allows remote attackers to steal cookies and hijack a management session via a /sgmi URL that contains malicious script, which is not quoted in the resulting error page.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/9755" source="BID" patch="1" adv="1">9755</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107790684732458&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20040227 Symantec Gateway Security Management Service Cross Site Scripting</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15330" source="XF" adv="1">symantecgateway-error-xss(15330)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="symantec" name="gateway_security_5400">
        <vers num="2.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0193" published="2004-03-15" name="CVE-2004-0193" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Heap-based buffer overflow in the ISS Protocol Analysis Module (PAM), as used in certain versions of RealSecure Network 7.0 and Server Sensor 7.0, Proventia A, G, and M Series, RealSecure Desktop 7.0 and 3.6, RealSecure Guard 3.6, RealSecure Sentry 3.6, BlackICE PC Protection 3.6, and BlackICE Server Protection 3.6, allows remote attackers to execute arbitrary code via an SMB packet containing an authentication request with a long username.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/150326" source="CERT-VN" patch="1" adv="1">VU#150326</ref>
      <ref url="http://xforce.iss.net/xforce/alerts/id/165" source="ISS" patch="1" adv="1">20040226 Vulnerability in SMB Parsing in ISS Products</ref>
      <ref url="http://www.eeye.com/html/Research/Upcoming/20040213.html" source="MISC" adv="1">http://www.eeye.com/html/Research/Upcoming/20040213.html</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15207" source="XF">pam-smb-protocol-bo(15207)</ref>
      <ref url="http://www.securityfocus.com/bid/9752" source="BID">9752</ref>
      <ref url="http://www.osvdb.org/4072" source="OSVDB">4072</ref>
      <ref url="http://www.eeye.com/html/Research/Advisories/AD20040226.html" source="EEYE">AD20040226</ref>
      <ref url="http://secunia.com/advisories/10988" source="SECUNIA">10988</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107789851117176&amp;w=2" source="BUGTRAQ">20040227 EEYE: RealSecure/BlackICE Server Message Block (SMB) Processing Overflow</ref>
    </refs>
    <vuln_soft>
      <prod vendor="iss" name="blackice_agent_server">
        <vers num="3.6eca" />
      </prod>
      <prod vendor="iss" name="blackice_pc_protection">
        <vers num="3.6cbd" />
      </prod>
      <prod vendor="iss" name="blackice_server_protection">
        <vers num="3.6cbz" />
      </prod>
      <prod vendor="iss" name="realsecure_desktop">
        <vers num="3.6eca" />
        <vers num="3.6ecf" />
        <vers num="7.0ebg" />
        <vers num="7.0epk" />
      </prod>
      <prod vendor="iss" name="realsecure_guard">
        <vers num="3.6ecb" />
      </prod>
      <prod vendor="iss" name="realsecure_network">
        <vers num="7.0" edition="xpu_20.15" />
      </prod>
      <prod vendor="iss" name="realsecure_sentry">
        <vers num="3.6ecf" />
      </prod>
      <prod vendor="iss" name="realsecure_server_sensor">
        <vers num="7.0" edition="xpu20.16" />
      </prod>
      <prod vendor="iss" name="proventia_a_series_xpu">
        <vers num="20.15" />
      </prod>
      <prod vendor="iss" name="proventia_g_series_xpu">
        <vers num="22.3" />
      </prod>
      <prod vendor="iss" name="proventia_m_series_xpu">
        <vers num="1.30" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0194" published="2004-03-29" name="CVE-2004-0194" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Stack-based buffer overflow in the OutputDebugString function for Adobe Acrobat Reader 5.1 allows remote attackers to execute arbitrary code via a PDF document with XML Forms Data Format (XFDF) data.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/9802" source="BID" patch="1" adv="1">9802</ref>
      <ref url="http://www.nextgenss.com/advisories/adobexfdf.txt" source="MISC" patch="1" adv="1">http://www.nextgenss.com/advisories/adobexfdf.txt</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15384" source="XF" adv="1">acrobatreader-xfdf-bo(15384)</ref>
      <ref url="http://www.osvdb.org/4135" source="OSVDB">4135</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107842545022724&amp;w=2" source="BUGTRAQ">20040303 Abobe Reader 5.1 XFDF Buffer Overflow Vulnerability</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2004-March/018227.html" source="FULLDISC">20040303 Adobe Acrobat Reader XML Forms Data Format Buffer Overflow</ref>
    </refs>
    <vuln_soft>
      <prod vendor="adobe" name="acrobat_reader">
        <vers num="5.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0197" published="2004-06-01" name="CVE-2004-0197" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in Microsoft Jet Database Engine 4.0 allows remote attackers to execute arbitrary code via a specially-crafted database query.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/740716" source="CERT-VN">VU#740716</ref>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA04-104A.html" source="CERT">TA04-104A</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15703" source="XF">msjet-query-execute-code(15703)</ref>
      <ref url="http://www.securityfocus.com/bid/10112" source="BID">10112</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms04-014.asp" source="MS">MS04-014</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:968" source="OVAL" sig="1">oval:org.mitre.oval:def:968</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="jet">
        <vers num="4.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0199" published="2004-06-14" name="CVE-2004-0199" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_score="5.1" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="4.9" CVSS_base_score="5.1">
    <desc>
      <descript source="cve">Help and Support Center in Microsoft Windows XP and Windows Server 2003 SP1 does not properly validate HCP URLs, which allows remote attackers to execute arbitrary code, as demonstrated using certain hcp:// URLs that access the DVD Upgrade capability (dvdupgrd.htm).</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/484814" source="CERT-VN" patch="1" adv="1">VU#484814</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/16095" source="XF" patch="1" adv="1">win-hcp-code-execution(16095)</ref>
      <ref url="http://www.securityfocus.com/bid/10321" source="BID" patch="1" adv="1">10321</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/MS04-015.mspx" source="MS" patch="1" adv="1">MS04-015</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108437759930820&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20040512 MS04-015 - Windows Help Center - Dvdupgrade</ref>
      <ref url="http://www.exploitlabs.com/files/advisories/EXPL-A-2004-001-helpctr.txt" source="MISC">http://www.exploitlabs.com/files/advisories/EXPL-A-2004-001-helpctr.txt</ref>
      <ref url="http://marc.theaimsgroup.com/?l=full-disclosure&amp;m=108430407801825&amp;w=2" source="FULLDISC">20040512 MS04-015 - Windows Help Center - Dvdupgrade</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1032" source="OVAL" sig="1">oval:org.mitre.oval:def:1032</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1008" source="OVAL" sig="1">oval:org.mitre.oval:def:1008</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_2003_server">
        <vers num="enterprise" edition="" />
        <vers num="enterprise" edition=":64-bit" />
        <vers num="enterprise_64-bit" />
        <vers num="r2" edition="" />
        <vers num="r2" edition=":64-bit" />
        <vers num="r2" edition=":datacenter_64-bit" />
        <vers num="standard" edition="" />
        <vers num="standard" edition=":64-bit" />
        <vers num="web" />
      </prod>
      <prod vendor="microsoft" name="windows_xp">
        <vers num="" edition=":home" />
        <vers num="" edition=":64-bit" />
        <vers num="" edition="gold" />
        <vers num="" edition="gold:professional" />
        <vers num="" edition="sp1" />
        <vers num="" edition="sp1:64-bit" />
        <vers num="" edition="sp1:home" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0200" published="2004-09-28" name="CVE-2004-0200" modified="2008-09-10" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Buffer overflow in the JPEG (JPG) parsing engine in the Microsoft Graphic Device Interface Plus (GDI+) component, GDIPlus.dll, allows remote attackers to execute arbitrary code via a JPEG image with a small JPEG COM field length that is normalized to a large integer length before a memory copy operation.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA04-260A.html" source="CERT">TA04-260A</ref>
      <ref url="http://www.kb.cert.org/vuls/id/297462" source="CERT-VN">VU#297462</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/16304" source="XF" patch="1" adv="1">win-jpeg-bo(16304)</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms04-028.asp" source="MS" patch="1" adv="1">MS04-028</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109524346729948&amp;w=2" source="BUGTRAQ">20040914 Microsoft GDIPlus.DLL JPEG Parsing Engine Buffer Overflow</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:4307" source="OVAL" sig="1">oval:org.mitre.oval:def:4307</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:4216" source="OVAL" sig="1">oval:org.mitre.oval:def:4216</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:4003" source="OVAL" sig="1">oval:org.mitre.oval:def:4003</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:3881" source="OVAL" sig="1">oval:org.mitre.oval:def:3881</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:3810" source="OVAL" sig="1">oval:org.mitre.oval:def:3810</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:3320" source="OVAL" sig="1">oval:org.mitre.oval:def:3320</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:3082" source="OVAL" sig="1">oval:org.mitre.oval:def:3082</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:3038" source="OVAL" sig="1">oval:org.mitre.oval:def:3038</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2706" source="OVAL" sig="1">oval:org.mitre.oval:def:2706</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1721" source="OVAL" sig="1">oval:org.mitre.oval:def:1721</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1105" source="OVAL" sig="1">oval:org.mitre.oval:def:1105</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name=".net_framework">
        <vers num="1.0" edition="sp2" />
        <vers num="1.0" edition="sp2:sdk" />
      </prod>
      <prod vendor="microsoft" name="digital_image_pro">
        <vers num="7.0" />
        <vers num="9" />
      </prod>
      <prod vendor="microsoft" name="digital_image_suite">
        <vers num="9" />
      </prod>
      <prod vendor="microsoft" name="excel">
        <vers num="2002" />
        <vers num="2003" />
      </prod>
      <prod vendor="microsoft" name="frontpage">
        <vers num="2002" />
        <vers num="2003" />
      </prod>
      <prod vendor="microsoft" name="greetings">
        <vers num="2002" />
      </prod>
      <prod vendor="microsoft" name="infopath">
        <vers num="2003" />
      </prod>
      <prod vendor="microsoft" name="office">
        <vers num="2003" edition="" />
        <vers num="2003" edition=":student_teacher" />
        <vers num="xp" edition="sp3" />
      </prod>
      <prod vendor="microsoft" name="onenote">
        <vers num="2003" />
      </prod>
      <prod vendor="microsoft" name="outlook">
        <vers num="2002" />
        <vers num="2003" />
      </prod>
      <prod vendor="microsoft" name="picture_it">
        <vers num="2002" />
        <vers num="7.0" />
        <vers num="9" />
      </prod>
      <prod vendor="microsoft" name="powerpoint">
        <vers num="2002" />
        <vers num="2003" />
      </prod>
      <prod vendor="microsoft" name="producer">
        <vers num="" edition="gold" />
        <vers num="" edition="gold:office_powerpoints" />
      </prod>
      <prod vendor="microsoft" name="project">
        <vers num="2002" edition="sp1" />
        <vers num="2003" />
      </prod>
      <prod vendor="microsoft" name="publisher">
        <vers num="2002" />
        <vers num="2003" />
      </prod>
      <prod vendor="microsoft" name="visio">
        <vers num="2002" edition="sp2" />
        <vers num="2003" />
      </prod>
      <prod vendor="microsoft" name="visual_basic">
        <vers num="2002" edition="" />
        <vers num="2002" edition=":.net_standard" />
        <vers num="2003" edition="" />
        <vers num="2003" edition=":.net_standard" />
      </prod>
      <prod vendor="microsoft" name="visual_c#">
        <vers num="2002" edition="" />
        <vers num="2002" edition=":.net_standard" />
        <vers num="2003" edition="" />
        <vers num="2003" edition=":.net_standard" />
      </prod>
      <prod vendor="microsoft" name="visual_c++">
        <vers num="2002" edition="" />
        <vers num="2002" edition=":.net_standard" />
        <vers num="2003" edition="" />
        <vers num="2003" edition=":.net_standard" />
      </prod>
      <prod vendor="microsoft" name="visual_j#_.net">
        <vers num="2003" edition="" />
        <vers num="2003" edition=":.net_standard" />
      </prod>
      <prod vendor="microsoft" name="visual_studio_.net">
        <vers num="2002" edition="gold" />
        <vers num="2003" edition="gold" />
      </prod>
      <prod vendor="microsoft" name="word">
        <vers num="2002" />
        <vers num="2003" />
      </prod>
      <prod vendor="microsoft" name="windows_2003_server">
        <vers num="r2" />
      </prod>
      <prod vendor="microsoft" name="windows_xp">
        <vers num="" edition=":64-bit" />
        <vers num="" edition="gold" />
        <vers num="" edition="sp1" />
        <vers num="" edition="sp1:tablet_pc" />
        <vers num="" edition="sp1:64-bit" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0201" published="2004-08-06" name="CVE-2004-0201" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Heap-based buffer overflow in the HtmlHelp program (hh.exe) in HTML Help for Microsoft Windows 98, Me, NT 4.0, 2000, XP, and Server 2003 allows remote attackers to execute arbitrary commands via a .CHM file with a large length field, a different vulnerability than CVE-2003-1041.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA04-196A.html" source="CERT" patch="1" adv="1">TA04-196A</ref>
      <ref url="http://www.kb.cert.org/vuls/id/920060" source="CERT-VN" patch="1" adv="1">VU#920060</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/MS04-023.mspx" source="MS" patch="1" adv="1">MS04-023</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/16586" source="XF" adv="1">win-htmlhelp-execute-code(16586)</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2004-July/023919.html" source="FULLDISC">20040714 HtmlHelp - .CHM File Heap Overflow</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:3179" source="OVAL" sig="1">oval:org.mitre.oval:def:3179</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2155" source="OVAL" sig="1">oval:org.mitre.oval:def:2155</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1530" source="OVAL" sig="1">oval:org.mitre.oval:def:1530</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1503" source="OVAL" sig="1">oval:org.mitre.oval:def:1503</ref>
    </refs>
    <vuln_soft>
      <prod vendor="avaya" name="ip600_media_servers">
        <vers num="" />
      </prod>
      <prod vendor="avaya" name="definity_one_media_server">
        <vers num="" />
      </prod>
      <prod vendor="avaya" name="s8100">
        <vers num="" />
      </prod>
      <prod vendor="avaya" name="modular_messaging_message_storage_server">
        <vers num="s3400" />
      </prod>
      <prod vendor="microsoft" name="windows_2000">
        <vers num="" edition=":professional" />
        <vers num="" edition=":server" />
        <vers num="" edition=":advanced_server" />
        <vers num="" edition=":datacenter_server" />
        <vers num="" edition="sp1" />
        <vers num="" edition="sp1:datacenter_server" />
        <vers num="" edition="sp1:professional" />
        <vers num="" edition="sp1:server" />
        <vers num="" edition="sp1:advanced_server" />
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:advanced_server" />
        <vers num="" edition="sp2:professional" />
        <vers num="" edition="sp2:datacenter_server" />
        <vers num="" edition="sp2:server" />
        <vers num="" edition="sp3" />
        <vers num="" edition="sp3:datacenter_server" />
        <vers num="" edition="sp3:server" />
        <vers num="" edition="sp3:professional" />
        <vers num="" edition="sp3:advanced_server" />
        <vers num="" edition="sp4" />
        <vers num="" edition="sp4:datacenter_server" />
        <vers num="" edition="sp4:server" />
        <vers num="" edition="sp4:professional" />
        <vers num="" edition="sp4:advanced_server" />
      </prod>
      <prod vendor="microsoft" name="windows_2003_server">
        <vers num="enterprise" edition="" />
        <vers num="enterprise" edition=":64-bit" />
        <vers num="enterprise_64-bit" />
        <vers num="r2" edition="" />
        <vers num="r2" edition=":datacenter_64-bit" />
        <vers num="r2" edition=":64-bit" />
        <vers num="standard" edition="" />
        <vers num="standard" edition=":64-bit" />
        <vers num="web" />
      </prod>
      <prod vendor="microsoft" name="windows_98">
        <vers num="" edition="gold" />
      </prod>
      <prod vendor="microsoft" name="windows_98se">
        <vers num="" />
      </prod>
      <prod vendor="microsoft" name="windows_me">
        <vers num="" />
      </prod>
      <prod vendor="microsoft" name="windows_nt">
        <vers num="4.0" edition="" />
        <vers num="4.0" edition=":server" />
        <vers num="4.0" edition=":enterprise_server" />
        <vers num="4.0" edition=":terminal_server" />
        <vers num="4.0" edition=":workstation" />
        <vers num="4.0" edition="sp1" />
        <vers num="4.0" edition="sp1:server" />
        <vers num="4.0" edition="sp1:workstation" />
        <vers num="4.0" edition="sp1:terminal_server" />
        <vers num="4.0" edition="sp1:enterprise_server" />
        <vers num="4.0" edition="sp2" />
        <vers num="4.0" edition="sp2:enterprise_server" />
        <vers num="4.0" edition="sp2:server" />
        <vers num="4.0" edition="sp2:workstation" />
        <vers num="4.0" edition="sp2:terminal_server" />
        <vers num="4.0" edition="sp3" />
        <vers num="4.0" edition="sp3:workstation" />
        <vers num="4.0" edition="sp3:server" />
        <vers num="4.0" edition="sp3:terminal_server" />
        <vers num="4.0" edition="sp3:enterprise_server" />
        <vers num="4.0" edition="sp4" />
        <vers num="4.0" edition="sp4:workstation" />
        <vers num="4.0" edition="sp4:enterprise_server" />
        <vers num="4.0" edition="sp4:terminal_server" />
        <vers num="4.0" edition="sp4:server" />
        <vers num="4.0" edition="sp5" />
        <vers num="4.0" edition="sp5:workstation" />
        <vers num="4.0" edition="sp5:enterprise_server" />
        <vers num="4.0" edition="sp5:server" />
        <vers num="4.0" edition="sp5:terminal_server" />
        <vers num="4.0" edition="sp6" />
        <vers num="4.0" edition="sp6:terminal_server" />
        <vers num="4.0" edition="sp6:server" />
        <vers num="4.0" edition="sp6:enterprise_server" />
        <vers num="4.0" edition="sp6:workstation" />
        <vers num="4.0" edition="sp6a" />
        <vers num="4.0" edition="sp6a:server" />
        <vers num="4.0" edition="sp6a:enterprise_server" />
        <vers num="4.0" edition="sp6a:workstation" />
      </prod>
      <prod vendor="microsoft" name="windows_xp">
        <vers num="" edition=":home" />
        <vers num="" edition=":64-bit" />
        <vers num="" edition="gold" />
        <vers num="" edition="gold:professional" />
        <vers num="" edition="sp1" />
        <vers num="" edition="sp1:home" />
        <vers num="" edition="sp1:64-bit" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0202" published="2004-08-06" name="CVE-2004-0202" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">IDirectPlay4 Application Programming Interface (API) of Microsoft DirectPlay 7.0a thru 9.0b, as used in Windows Server 2003 and earlier allows remote attackers to cause a denial of service (application crash) via a malformed packet.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/10487" source="BID" patch="1" adv="1">10487</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms04-016.asp" source="MS">MS04-016</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/16306" source="XF">ms-directx-directplay-dos(16306)</ref>
      <ref url="http://www.osvdb.org/6742" source="OSVDB">6742</ref>
      <ref url="http://secunia.com/advisories/11802" source="SECUNIA">11802</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2705" source="OVAL" sig="1">oval:org.mitre.oval:def:2705</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2516" source="OVAL" sig="1">oval:org.mitre.oval:def:2516</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2413" source="OVAL" sig="1">oval:org.mitre.oval:def:2413</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2190" source="OVAL" sig="1">oval:org.mitre.oval:def:2190</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1027" source="OVAL" sig="1">oval:org.mitre.oval:def:1027</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="directx">
        <vers num="7.0" />
        <vers num="7.0a" />
        <vers num="7.1" />
        <vers num="8.0" />
        <vers num="8.0a" />
        <vers num="8.1" />
        <vers num="8.1a" />
        <vers num="8.1b" />
        <vers num="8.2" />
        <vers num="9.0a" />
        <vers num="9.0b" />
      </prod>
      <prod vendor="microsoft" name="windows_2000">
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:professional" />
        <vers num="" edition="sp2:datacenter_server" />
        <vers num="" edition="sp2:server" />
        <vers num="" edition="sp3" />
        <vers num="" edition="sp3:datacenter_server" />
        <vers num="" edition="sp3:server" />
        <vers num="" edition="sp3:professional" />
        <vers num="" edition="sp4" />
        <vers num="" edition="sp4:server" />
        <vers num="" edition="sp4:datacenter_server" />
        <vers num="" edition="sp4:professional" />
      </prod>
      <prod vendor="microsoft" name="windows_2003_server">
        <vers num="enterprise" edition="" />
        <vers num="enterprise" edition=":64-bit" />
        <vers num="enterprise_64-bit" />
        <vers num="r2" edition="" />
        <vers num="r2" edition=":64-bit" />
        <vers num="r2" edition=":datacenter_64-bit" />
        <vers num="standard" edition="" />
        <vers num="standard" edition=":64-bit" />
        <vers num="web" />
      </prod>
      <prod vendor="microsoft" name="windows_98">
        <vers num="" edition="gold" />
      </prod>
      <prod vendor="microsoft" name="windows_98se">
        <vers num="" />
      </prod>
      <prod vendor="microsoft" name="windows_me">
        <vers num="" />
      </prod>
      <prod vendor="microsoft" name="windows_xp">
        <vers num="" edition=":home" />
        <vers num="" edition=":64-bit" />
        <vers num="" edition="gold" />
        <vers num="" edition="gold:professional" />
        <vers num="" edition="sp1" />
        <vers num="" edition="sp1:64-bit" />
        <vers num="" edition="sp1:home" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0203" published="2004-11-23" name="CVE-2004-0203" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in Outlook Web Access for Exchange Server 5.5 Service Pack 4 allows remote attackers to insert arbitrary script and spoof content in HTML email or web caches via an HTML redirect query.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/948750" source="CERT-VN">VU#948750</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms04-026.mspx" source="MS" patch="1" adv="1">MS04-026</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/16583" source="XF">exchange-owa-execute-code(16583)</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2016" source="OVAL" sig="1">oval:org.mitre.oval:def:2016</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="exchange_server">
        <vers num="5.5" edition="sp1" />
        <vers num="5.5" edition="sp2" />
        <vers num="5.5" edition="sp3" />
        <vers num="5.5" edition="sp4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0204" published="2004-08-06" name="CVE-2004-0204" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Directory traversal vulnerability in the web viewers for Business Objects Crystal Reports 9 and 10, and Crystal Enterprise 9 or 10, as used in Visual Studio .NET 2003 and Outlook 2003 with Business Contact Manager, Microsoft Business Solutions CRM 1.2, and other products, allows remote attackers to read and delete arbitrary files via ".." sequences in the dynamicimag argument to crystalimagehandler.aspx.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/10260" source="BID" patch="1" adv="1">10260</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/16044" source="XF" adv="1">crystalreports-file-deletion(16044)</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms04-017.asp" source="MS">MS04-017</ref>
      <ref url="http://support.businessobjects.com/fix/hot/critical/bulletins/security_bulletin_june04.asp" source="CONFIRM">http://support.businessobjects.com/fix/hot/critical/bulletins/security_bulletin_june04.asp</ref>
      <ref url="http://www.osvdb.org/6748" source="OSVDB">6748</ref>
      <ref url="http://secunia.com/advisories/11800" source="SECUNIA">11800</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108671836127360&amp;w=2" source="BUGTRAQ">20040608 Vulnerability: Arbitrary File Access &amp; DoS in Crystal Reports</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108360413811017&amp;w=2" source="BUGTRAQ">20040502 Crystal Reports Vulnerabilities</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1157" source="OVAL" sig="1">oval:org.mitre.oval:def:1157</ref>
    </refs>
    <vuln_soft>
      <prod vendor="bea" name="weblogic_server">
        <vers num="8.1" edition="" />
        <vers num="8.1" edition=":win32" />
        <vers num="8.1" edition=":express" />
        <vers num="8.1" edition="sp1" />
        <vers num="8.1" edition="sp1:express" />
        <vers num="8.1" edition="sp1:win32" />
        <vers num="8.1" edition="sp2" />
        <vers num="8.1" edition="sp2:express" />
        <vers num="8.1" edition="sp2:win32" />
      </prod>
      <prod vendor="borland_software" name="j_builder">
        <vers num="" />
      </prod>
      <prod vendor="businessobjects" name="crystal_enterprise">
        <vers num="10" />
        <vers num="9" />
      </prod>
      <prod vendor="businessobjects" name="crystal_enterprise_java_sdk">
        <vers num="8.5" />
      </prod>
      <prod vendor="businessobjects" name="crystal_enterprise_ras">
        <vers num="8.5" edition="" />
        <vers num="8.5" edition=":unix" />
      </prod>
      <prod vendor="businessobjects" name="crystal_reports">
        <vers num="10" />
        <vers num="9" />
      </prod>
      <prod vendor="microsoft" name="business_solutions_crm">
        <vers num="1.2" />
      </prod>
      <prod vendor="microsoft" name="outlook">
        <vers num="2003" edition="" />
        <vers num="2003" edition=":business_contact_manager" />
      </prod>
      <prod vendor="microsoft" name="visual_studio_.net">
        <vers num="2003" edition="gold" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0205" published="2004-08-06" name="CVE-2004-0205" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Buffer overflow in Microsoft Internet Information Server (IIS) 4.0 allows local users to execute arbitrary code via the redirect function.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA04-196A.html" source="CERT" patch="1" adv="1">TA04-196A</ref>
      <ref url="http://www.kb.cert.org/vuls/id/717748" source="CERT-VN" patch="1" adv="1">VU#717748</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/16578" source="XF" adv="1">iis-redirect-bo(16578)</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms04-021.asp" source="MS">MS04-021</ref>
      <ref url="http://www.ciac.org/ciac/bulletins/o-179.shtml" source="CIAC">O-179</ref>
      <ref url="http://www.securityfocus.com/bid/10706" source="BID">10706</ref>
      <ref url="http://www.osvdb.org/7799" source="OSVDB">7799</ref>
      <ref url="http://secunia.com/advisories/12061" source="SECUNIA">12061</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2204" source="OVAL" sig="1">oval:org.mitre.oval:def:2204</ref>
    </refs>
    <vuln_soft>
      <prod vendor="avaya" name="ip600_media_servers">
        <vers num="" />
      </prod>
      <prod vendor="microsoft" name="internet_information_server">
        <vers num="4.0" />
      </prod>
      <prod vendor="avaya" name="definity_one_media_server">
        <vers num="" />
      </prod>
      <prod vendor="avaya" name="s8100">
        <vers num="" />
      </prod>
      <prod vendor="avaya" name="modular_messaging_message_storage_server">
        <vers num="s3400" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0206" published="2004-11-03" name="CVE-2004-0206" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Network Dynamic Data Exchange (NetDDE) services for Microsoft Windows 98, Windows NT 4.0, Windows 2000, Windows XP, and Windows Server 2003 allows attackers to remotely execute arbitrary code or locally gain privileges via a malicious message or application that involves an "unchecked buffer," possibly a buffer overflow.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/640488" source="CERT-VN" patch="1" adv="1">VU#640488</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/17657" source="XF" patch="1" adv="1">win-ms04031-patch(17657)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/16556" source="XF" patch="1" adv="1">win-netdde-bo(16556)</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms04-031.asp" source="MS" patch="1" adv="1">MS04-031</ref>
      <ref url="http://secunia.com/advisories/12803/" source="SECUNIA">12803</ref>
      <ref url="http://www.securityfocus.com/bid/11372" source="BID">11372</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109786703930674&amp;w=2" source="BUGTRAQ">20041013 Microsoft Windows NetDDE Service Buffer Overflow</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6788" source="OVAL" sig="1">oval:org.mitre.oval:def:6788</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5074" source="OVAL" sig="1">oval:org.mitre.oval:def:5074</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:4592" source="OVAL" sig="1">oval:org.mitre.oval:def:4592</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:3242" source="OVAL" sig="1">oval:org.mitre.oval:def:3242</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:3120" source="OVAL" sig="1">oval:org.mitre.oval:def:3120</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2394" source="OVAL" sig="1">oval:org.mitre.oval:def:2394</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1852" source="OVAL" sig="1">oval:org.mitre.oval:def:1852</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_2000">
        <vers num="" />
      </prod>
      <prod vendor="microsoft" name="windows_2003_server">
        <vers num="r2" />
      </prod>
      <prod vendor="microsoft" name="windows_98">
        <vers num="" edition="gold" />
      </prod>
      <prod vendor="microsoft" name="windows_nt">
        <vers num="4.0" />
      </prod>
      <prod vendor="microsoft" name="windows_xp">
        <vers num="" edition="gold" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2004-0207" published="2004-11-03" name="CVE-2004-0207" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">"Shatter" style vulnerability in the Window Management application programming interface (API) for Microsoft Windows 98, Windows NT 4.0, Windows 2000, Windows XP, and Windows Server 2003 allows local users to gain privileges by using certain API functions to change properties of privileged programs using the SetWindowLong and SetWIndowLongPtr API functions.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/218526" source="CERT-VN" patch="1" adv="1">VU#218526</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/17658" source="XF" patch="1" adv="1">win-ms04032-patch(17658)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/16579" source="XF" patch="1" adv="1">win-mngmt-api-gain-privileges(16579)</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms04-032.asp" source="MS" patch="1" adv="1">MS04-032</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109777417922695&amp;w=2" source="BUGTRAQ">20041013 SetWindowLong Shatter Attacks</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_2000">
        <vers num="" />
      </prod>
      <prod vendor="microsoft" name="windows_2003_server">
        <vers num="r2" />
      </prod>
      <prod vendor="microsoft" name="windows_98">
        <vers num="" edition="gold" />
      </prod>
      <prod vendor="microsoft" name="windows_nt">
        <vers num="4.0" />
      </prod>
      <prod vendor="microsoft" name="windows_xp">
        <vers num="" edition="gold" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0208" published="2004-11-03" name="CVE-2004-0208" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">The Virtual DOS Machine (VDM) subsystem of Microsoft Windows NT 4.0, Windows 2000, Windows XP, and Windows Server 2003 allows local users to access kernel memory and gain privileges via a malicious program that modified some system structures in a way that is not properly validated by privileged operating system functions.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/910998" source="CERT-VN" patch="1" adv="1">VU#910998</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/17658" source="XF" patch="1" adv="1">win-ms04032-patch(17658)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/16580" source="XF" patch="1" adv="1">win-vdm-gain-privilege(16580)</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms04-032.asp" source="MS" patch="1" adv="1">MS04-032</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109772135404427&amp;w=2" source="BUGTRAQ">20041013 EEYE: Windows VDM #UD Local Privilege Escalation</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:4762" source="OVAL" sig="1">oval:org.mitre.oval:def:4762</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:4316" source="OVAL" sig="1">oval:org.mitre.oval:def:4316</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:3953" source="OVAL" sig="1">oval:org.mitre.oval:def:3953</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:3161" source="OVAL" sig="1">oval:org.mitre.oval:def:3161</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1751" source="OVAL" sig="1">oval:org.mitre.oval:def:1751</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_2000">
        <vers num="" />
      </prod>
      <prod vendor="microsoft" name="windows_2003_server">
        <vers num="r2" />
      </prod>
      <prod vendor="microsoft" name="windows_nt">
        <vers num="4.0" />
      </prod>
      <prod vendor="microsoft" name="windows_xp">
        <vers num="" edition="gold" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0209" published="2004-11-03" name="CVE-2004-0209" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Unknown vulnerability in the Graphics Rendering Engine processes of Microsoft Windows 2000, Windows XP, and Windows Server 2003 allows remote attackers to execute arbitrary code via (1) Windows Metafile (WMF) or (2) Enhanced Metafile (EMF) image formats that involve "an unchecked buffer."</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/806278" source="CERT-VN">VU#806278</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/16581" source="XF" patch="1" adv="1">win-emf-bo(16581)</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms04-032.asp" source="MS" patch="1" adv="1">MS04-032</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109829067325779&amp;w=2" source="BUGTRAQ">20041019 [EXPL] (MS04-032) Microsoft Windows XP Metafile (.emf) Heap Overflow</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/17658" source="XF">win-ms04032-patch(17658)</ref>
      <ref url="http://www.securityfocus.com/bid/11375" source="BID">11375</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2428" source="OVAL" sig="1">oval:org.mitre.oval:def:2428</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2114" source="OVAL" sig="1">oval:org.mitre.oval:def:2114</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1872" source="OVAL" sig="1">oval:org.mitre.oval:def:1872</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_2000">
        <vers num="" />
      </prod>
      <prod vendor="microsoft" name="windows_2003_server">
        <vers num="r2" />
      </prod>
      <prod vendor="microsoft" name="windows_xp">
        <vers num="" edition="gold" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0210" published="2004-08-06" name="CVE-2004-0210" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">The POSIX component of Microsoft Windows NT and Windows 2000 allows local users to execute arbitrary code via certain parameters, possibly by modifying message length values and causing a buffer overflow.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA04-196A.html" source="CERT" patch="1" adv="1">TA04-196A</ref>
      <ref url="http://www.kb.cert.org/vuls/id/647436" source="CERT-VN" patch="1" adv="1">VU#647436</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/16590" source="XF" adv="1">win-posix-bo(16590)</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms04-020.asp" source="MS">MS04-020</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2847" source="OVAL" sig="1">oval:org.mitre.oval:def:2847</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2166" source="OVAL" sig="1">oval:org.mitre.oval:def:2166</ref>
    </refs>
    <vuln_soft>
      <prod vendor="avaya" name="modular_messaging_message_storage_server">
        <vers num="s3400" />
      </prod>
      <prod vendor="microsoft" name="windows_2000">
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:datacenter_server" />
        <vers num="" edition="sp2:advanced_server" />
        <vers num="" edition="sp2:professional" />
        <vers num="" edition="sp2:server" />
        <vers num="" edition="sp3" />
        <vers num="" edition="sp3:professional" />
        <vers num="" edition="sp3:datacenter_server" />
        <vers num="" edition="sp3:advanced_server" />
        <vers num="" edition="sp3:server" />
        <vers num="" edition="sp4" />
        <vers num="" edition="sp4:datacenter_server" />
        <vers num="" edition="sp4:server" />
        <vers num="" edition="sp4:professional" />
        <vers num="" edition="sp4:advanced_server" />
      </prod>
      <prod vendor="microsoft" name="windows_nt">
        <vers num="4.0" edition="sp6" />
        <vers num="4.0" edition="sp6:terminal_server" />
        <vers num="4.0" edition="sp6:alpha" />
        <vers num="4.0" edition="sp6a" />
        <vers num="4.0" edition="sp6a:enterprise_server" />
        <vers num="4.0" edition="sp6a:workstation" />
        <vers num="4.0" edition="sp6a:server" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2004-0211" published="2004-11-03" name="CVE-2004-0211" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">The kernel for Microsoft Windows Server 2003 does not reset certain values in CPU data structures, which allows local users to cause a denial of service (system crash) via a malicious program.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/119262" source="CERT-VN" patch="1" adv="1">VU#119262</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/17658" source="XF" patch="1" adv="1">win-ms04032-patch(17658)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/16582" source="XF" patch="1" adv="1">win2k3-kernel-cpu-dos(16582)</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms04-032.asp" source="MS" patch="1" adv="1">MS04-032</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:4893" source="OVAL" sig="1">oval:org.mitre.oval:def:4893</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_2003_server">
        <vers num="r2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0212" published="2004-08-06" name="CVE-2004-0212" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Stack-based buffer overflow in the Task Scheduler for Windows 2000 and XP, and Internet Explorer 6 on Windows NT 4.0, allows local or remote attackers to execute arbitrary code via a .job file containing long parameters, as demonstrated using Internet Explorer and accessing a .job file on an anonymous share.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA04-196A.html" source="CERT" patch="1" adv="1">TA04-196A</ref>
      <ref url="http://www.kb.cert.org/vuls/id/228028" source="CERT-VN">VU#228028</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/16591" source="XF" adv="1">win-taskscheduler-bo(16591)</ref>
      <ref url="http://www.ngssoftware.com/advisories/mstaskjob.txt" source="MISC">http://www.ngssoftware.com/advisories/mstaskjob.txt</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms04-022.asp" source="MS">MS04-022</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108981403025596&amp;w=2" source="BUGTRAQ">20040714 Unchecked buffer in mstask.dll</ref>
      <ref url="http://secunia.com/advisories/12060" source="SECUNIA">12060</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108981273009250&amp;w=2" source="BUGTRAQ">20040714 Microsoft Windows Task Scheduler '.job' Stack Overflow</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:3428" source="OVAL" sig="1">oval:org.mitre.oval:def:3428</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1964" source="OVAL" sig="1">oval:org.mitre.oval:def:1964</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1781" source="OVAL" sig="1">oval:org.mitre.oval:def:1781</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1344" source="OVAL" sig="1">oval:org.mitre.oval:def:1344</ref>
    </refs>
    <vuln_soft>
      <prod vendor="avaya" name="ip600_media_servers">
        <vers num="" />
      </prod>
      <prod vendor="microsoft" name="ie">
        <vers num="6.0" edition="sp1" />
      </prod>
      <prod vendor="avaya" name="definity_one_media_server">
        <vers num="" />
      </prod>
      <prod vendor="avaya" name="s8100">
        <vers num="" />
      </prod>
      <prod vendor="avaya" name="modular_messaging_message_storage_server">
        <vers num="s3400" />
      </prod>
      <prod vendor="microsoft" name="windows_2000">
        <vers num="" edition=":advanced_server" />
        <vers num="" edition=":professional" />
        <vers num="" edition=":datacenter_server" />
        <vers num="" edition=":server" />
        <vers num="" edition="sp1" />
        <vers num="" edition="sp1:datacenter_server" />
        <vers num="" edition="sp1:professional" />
        <vers num="" edition="sp1:server" />
        <vers num="" edition="sp1:advanced_server" />
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:advanced_server" />
        <vers num="" edition="sp2:professional" />
        <vers num="" edition="sp2:datacenter_server" />
        <vers num="" edition="sp2:server" />
        <vers num="" edition="sp3" />
        <vers num="" edition="sp3:datacenter_server" />
        <vers num="" edition="sp3:server" />
        <vers num="" edition="sp3:professional" />
        <vers num="" edition="sp3:advanced_server" />
        <vers num="" edition="sp4" />
        <vers num="" edition="sp4:server" />
        <vers num="" edition="sp4:datacenter_server" />
        <vers num="" edition="sp4:professional" />
        <vers num="" edition="sp4:advanced_server" />
      </prod>
      <prod vendor="microsoft" name="windows_nt">
        <vers num="4.0" edition="sp6a" />
        <vers num="4.0" edition="sp6a:enterprise_server" />
        <vers num="4.0" edition="sp6a:workstation" />
        <vers num="4.0" edition="sp6a:server" />
      </prod>
      <prod vendor="microsoft" name="windows_xp">
        <vers num="" edition=":home" />
        <vers num="" edition=":64-bit" />
        <vers num="" edition="gold" />
        <vers num="" edition="gold:professional" />
        <vers num="" edition="sp1" />
        <vers num="" edition="sp1:64-bit" />
        <vers num="" edition="sp1:home" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0213" published="2004-08-06" name="CVE-2004-0213" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Utility Manager in Windows 2000 launches winhlp32.exe while Utility Manager is running with raised privileges, which allows local users to gain system privileges via a "Shatter" style attack that sends a Windows message to cause Utility Manager to launch winhlp32 by directly accessing the context sensitive help and bypassing the GUI, then sending another message to winhlp32 in order to open a user-selected file, a different vulnerability than CVE-2003-0908.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA04-196A.html" source="CERT" patch="1" adv="1">TA04-196A</ref>
      <ref url="http://www.kb.cert.org/vuls/id/868580" source="CERT-VN">VU#868580</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms04-019.asp" source="MS" patch="1" adv="1">MS04-019</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108975382413405&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20040713 Microsoft Window Utility Manager Local Elevation of Privileges</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/16592" source="XF" adv="1">win-utilitymanager-gain-privileges(16592)</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2495" source="OVAL" sig="1">oval:org.mitre.oval:def:2495</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_2000">
        <vers num="" edition=":datacenter_server" />
        <vers num="" edition=":server" />
        <vers num="" edition=":advanced_server" />
        <vers num="" edition=":professional" />
        <vers num="" edition="sp1" />
        <vers num="" edition="sp1:professional" />
        <vers num="" edition="sp1:datacenter_server" />
        <vers num="" edition="sp1:server" />
        <vers num="" edition="sp1:advanced_server" />
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:datacenter_server" />
        <vers num="" edition="sp2:advanced_server" />
        <vers num="" edition="sp2:professional" />
        <vers num="" edition="sp2:server" />
        <vers num="" edition="sp3" />
        <vers num="" edition="sp3:professional" />
        <vers num="" edition="sp3:datacenter_server" />
        <vers num="" edition="sp3:advanced_server" />
        <vers num="" edition="sp3:server" />
        <vers num="" edition="sp4" />
        <vers num="" edition="sp4:datacenter_server" />
        <vers num="" edition="sp4:server" />
        <vers num="" edition="sp4:professional" />
        <vers num="" edition="sp4:advanced_server" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0214" published="2004-11-03" name="CVE-2004-0214" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Buffer overflow in Microsoft Internet Explorer and Explorer on Windows XP SP1, WIndows 2000, Windows 98, and Windows Me may allow remote malicious servers to cause a denial of service (application crash) and possibly execute arbitrary code via long share names, as demonstrated using Samba.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/616200" source="CERT-VN">VU#616200</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/17662" source="XF" patch="1" adv="1">win-ms04037-patch(17662)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15956" source="XF" patch="1" adv="1">win-long-fileshare-bo(15956)</ref>
      <ref url="http://www.securityfocus.com/bid/10213" source="BID">10213</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms04-037.mspx" source="MS">MS04-037</ref>
      <ref url="http://support.microsoft.com/default.aspx?scid=kb;en-us;322857" source="MSKB">322857</ref>
      <ref url="http://securitytracker.com/id?1011647" source="SECTRACK">1011647</ref>
      <ref url="http://secunia.com/advisories/11482/" source="SECUNIA">11482</ref>
      <ref url="http://seclists.org/lists/fulldisclosure/2004/Apr/0933.html" source="FULLDISC" adv="1">20040425 Microsoft's Explorer and Internet Explorer long share name buffer overflow.</ref>
      <ref url="http://seclists.org/lists/bugtraq/2004/Apr/0322.html" source="BUGTRAQ" adv="1">20040425 Microsoft's Explorer and Internet Explorer long share name buffer overflow.</ref>
      <ref url="http://www.securiteam.com/windowsntfocus/5JP0M1PCKI.html" source="MISC">http://www.securiteam.com/windowsntfocus/5JP0M1PCKI.html</ref>
      <ref url="http://www.osvdb.org/5687" source="OSVDB">5687</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5307" source="OVAL" sig="1">oval:org.mitre.oval:def:5307</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:4345" source="OVAL" sig="1">oval:org.mitre.oval:def:4345</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2638" source="OVAL" sig="1">oval:org.mitre.oval:def:2638</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1749" source="OVAL" sig="1">oval:org.mitre.oval:def:1749</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1601" source="OVAL" sig="1">oval:org.mitre.oval:def:1601</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="ie">
        <vers num="6.0.2900" />
      </prod>
      <prod vendor="microsoft" name="windows_2000">
        <vers num="" />
      </prod>
      <prod vendor="microsoft" name="windows_98">
        <vers num="" edition="gold" />
      </prod>
      <prod vendor="microsoft" name="windows_me">
        <vers num="" />
      </prod>
      <prod vendor="microsoft" name="windows_xp">
        <vers num="" edition="sp1" />
        <vers num="" edition="sp1:tablet_pc" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0215" published="2004-08-06" name="CVE-2004-0215" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Microsoft Outlook Express 5.5 and 6 allows attackers to cause a denial of service (application crash) via a malformed e-mail header.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA04-196A.html" source="CERT" patch="1" adv="1">TA04-196A</ref>
      <ref url="http://www.kb.cert.org/vuls/id/869640" source="CERT-VN" patch="1" adv="1">VU#869640</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/16585" source="XF" adv="1">outlook-malformed-email-header-dos(16585)</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms04-018.asp" source="MS">MS04-018</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:3376" source="OVAL" sig="1">oval:org.mitre.oval:def:3376</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2657" source="OVAL" sig="1">oval:org.mitre.oval:def:2657</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2137" source="OVAL" sig="1">oval:org.mitre.oval:def:2137</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1950" source="OVAL" sig="1">oval:org.mitre.oval:def:1950</ref>
    </refs>
    <vuln_soft>
      <prod vendor="avaya" name="ip600_media_servers">
        <vers num="" />
      </prod>
      <prod vendor="microsoft" name="outlook_express">
        <vers num="6.0" />
      </prod>
      <prod vendor="avaya" name="definity_one_media_server">
        <vers num="" />
      </prod>
      <prod vendor="avaya" name="s8100">
        <vers num="" />
      </prod>
      <prod vendor="avaya" name="modular_messaging_message_storage_server">
        <vers num="s3400" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0216" published="2004-11-03" name="CVE-2004-0216" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Integer overflow in the Install Engine (inseng.dll) for Internet Explorer 5.01, 5.5, and 6 allows remote attackers to execute arbitrary code via a malicious website or HTML email with a long .CAB file name, which triggers the integer overflow when calculating a buffer length and leads to a heap-based buffer overflow.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA04-293A.html" source="CERT" patch="1" adv="1">TA04-293A</ref>
      <ref url="http://www.kb.cert.org/vuls/id/637760" source="CERT-VN" patch="1" adv="1">VU#637760</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/17620" source="XF" patch="1" adv="1">ie-installenginectl-setciffile-bo(17620)</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms04-038.asp" source="MS" patch="1" adv="1">MS04-038</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109760693512754&amp;w=2" source="BUGTRAQ" patch="1">20041012 Microsoft Internet Explorer Install Engine Control Buffer Overflow</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/17651" source="XF">ie-ms04038-patch(17651)</ref>
      <ref url="http://www.ngssoftware.com/advisories/msinsengfull.txt" source="MISC">http://www.ngssoftware.com/advisories/msinsengfull.txt</ref>
      <ref url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=110619893620517&amp;w=2" source="NTBUGTRAQ">20050119 Microsoft Internet Explorer Install Engine Control Buffer Overflow (#NISR19012005a)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110616383332055&amp;w=2" source="BUGTRAQ">20050119 Microsoft Internet Explorer Install Engine Control Buffer Overflow (#NISR19012005a)</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:7865" source="OVAL" sig="1">oval:org.mitre.oval:def:7865</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:7717" source="OVAL" sig="1">oval:org.mitre.oval:def:7717</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6600" source="OVAL" sig="1">oval:org.mitre.oval:def:6600</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6100" source="OVAL" sig="1">oval:org.mitre.oval:def:6100</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5329" source="OVAL" sig="1">oval:org.mitre.oval:def:5329</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5316" source="OVAL" sig="1">oval:org.mitre.oval:def:5316</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="ie">
        <vers num="5.01" />
        <vers num="5.5" />
        <vers num="6" edition="windows_server_2003_sp1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2004-0217" published="2004-04-15" name="CVE-2004-0217" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:H/Au:N/C:P/I:P/A:P)" CVSS_score="3.7" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="1.9" CVSS_base_score="3.7">
    <desc>
      <descript source="cve">The LiveUpdate capability (liveupdate.sh) in Symantec AntiVirus Scan Engine 4.0 and 4.3 for Red Hat Linux allows local users to create or append to arbitrary files via a symlink attack on /tmp/LiveUpdate.log.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <race />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/15215" source="XF" patch="1" adv="1">symantec-scanengine-race-condition(15215)</ref>
      <ref url="http://www.securityfocus.com/bid/9662" source="BID" patch="1" adv="1">9662</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107694800908164&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20040216 Possible race condition in Symantec AntiVirus Scan Engine for Red</ref>
    </refs>
    <vuln_soft>
      <prod vendor="symantec" name="antivirus_scan_engine">
        <vers num="4.0" edition="" />
        <vers num="4.0" edition=":red_hat_linux" />
        <vers num="4.3" edition="" />
        <vers num="4.3" edition=":red_hat_linux" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0218" published="2004-05-04" name="CVE-2004-0218" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">isakmpd in OpenBSD 3.4 and earlier allows remote attackers to cause a denial of service (infinite loop) via an ISAKMP packet with a zero-length payload, as demonstrated by the Striker ISAKMP Protocol Test Suite.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/349113" source="CERT-VN">VU#349113</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15518" source="XF" patch="1" adv="1">openbsd-isakmp-zerolength-dos(15518)</ref>
      <ref url="http://www.openbsd.org/errata.html" source="OPENBSD" patch="1">20040317 015: RELIABILITY FIX: March 17, 2004</ref>
      <ref url="http://www.rapid7.com/advisories/R7-0018.html" source="MISC">http://www.rapid7.com/advisories/R7-0018.html</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108008530028019&amp;w=2" source="BUGTRAQ" adv="1">20040323 R7-0018: OpenBSD isakmpd payload handling denial-of-service vulnerabilities</ref>
      <ref url="http://www.securitytracker.com/alerts/2004/Mar/1009468.html" source="SECTRACK">1009468</ref>
      <ref url="http://www.securityfocus.com/bid/10028" source="BID">10028</ref>
      <ref url="http://secunia.com/advisories/11156" source="SECUNIA">11156</ref>
    </refs>
    <vuln_soft>
      <prod vendor="openbsd" name="openbsd">
        <vers prev="1" num="3.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0219" published="2004-05-04" name="CVE-2004-0219" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">isakmpd in OpenBSD 3.4 and earlier allows remote attackers to cause a denial of service (crash) via an ISAKMP packet with a malformed IPSEC SA payload, as demonstrated by the Striker ISAKMP Protocol Test Suite.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/785945" source="CERT-VN">VU#785945</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15628" source="XF" patch="1" adv="1">openbsd-isakmp-ipsec-dos(15628)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108008530028019&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20040323 R7-0018: OpenBSD isakmpd payload handling denial-of-service vulnerabilities</ref>
      <ref url="http://www.rapid7.com/advisories/R7-0018.html" source="MISC">http://www.rapid7.com/advisories/R7-0018.html</ref>
      <ref url="http://www.openbsd.org/errata.html" source="OPENBSD">20040317 015: RELIABILITY FIX: March 17, 2004</ref>
      <ref url="http://www.securitytracker.com/alerts/2004/Mar/1009468.html" source="SECTRACK">1009468</ref>
      <ref url="http://www.securityfocus.com/bid/9907" source="BID">9907</ref>
    </refs>
    <vuln_soft>
      <prod vendor="openbsd" name="openbsd">
        <vers prev="1" num="3.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0220" published="2004-05-04" name="CVE-2004-0220" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">isakmpd in OpenBSD 3.4 and earlier allows remote attackers to cause a denial of service via a an ISAKMP packet with a malformed Cert Request payload, which causes an integer underflow that is used in a malloc operation that is not properly handled, as demonstrated by the Striker ISAKMP Protocol Test Suite.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/223273" source="CERT-VN">VU#223273</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15629" source="XF" patch="1" adv="1">openbsd-isakmp-integer-underflow(15629)</ref>
      <ref url="http://www.openbsd.org/errata.html" source="OPENBSD" patch="1">20040317 015: RELIABILITY FIX: March 17, 2004</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108008530028019&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20040323 R7-0018: OpenBSD isakmpd payload handling denial-of-service vulnerabilities</ref>
      <ref url="http://www.securitytracker.com/alerts/2004/Mar/1009468.html" source="SECTRACK">1009468</ref>
      <ref url="http://www.securityfocus.com/bid/9907" source="BID">9907</ref>
      <ref url="http://www.rapid7.com/advisories/R7-0018.html" source="MISC">http://www.rapid7.com/advisories/R7-0018.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="openbsd" name="openbsd">
        <vers prev="1" num="3.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0221" published="2004-05-04" name="CVE-2004-0221" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">isakmpd in OpenBSD 3.4 and earlier allows remote attackers to cause a denial of service (crash) via an ISAKMP packet with a delete payload containing a large number of SPIs, which triggers an out-of-bounds read error, as demonstrated by the Striker ISAKMP Protocol Test Suite.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/524497" source="CERT-VN">VU#524497</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15630" source="XF" patch="1" adv="1">openbsd-isakmp-delete-dos(15630)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108008530028019&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20040323 R7-0018: OpenBSD isakmpd payload handling denial-of-service vulnerabilities</ref>
      <ref url="http://www.rapid7.com/advisories/R7-0018.html" source="MISC">http://www.rapid7.com/advisories/R7-0018.html</ref>
      <ref url="http://www.openbsd.org/errata.html" source="OPENBSD" adv="1">20040317 015: RELIABILITY FIX: March 17, 2004</ref>
      <ref url="http://www.securitytracker.com/alerts/2004/Mar/1009468.html" source="SECTRACK">1009468</ref>
      <ref url="http://www.securityfocus.com/bid/9907" source="BID">9907</ref>
    </refs>
    <vuln_soft>
      <prod vendor="openbsd" name="openbsd">
        <vers prev="1" num="3.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0222" published="2004-05-04" name="CVE-2004-0222" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Multiple memory leaks in isakmpd in OpenBSD 3.4 and earlier allow remote attackers to cause a denial of service (memory exhaustion) via certain ISAKMP packets, as demonstrated by the Striker ISAKMP Protocol Test Suite.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/996177" source="CERT-VN">VU#996177</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15519" source="XF" patch="1" adv="1">openbsd-isakmp-memory-leak(15519)</ref>
      <ref url="http://www.openbsd.org/errata.html" source="OPENBSD" patch="1">20040317 015: RELIABILITY FIX: March 17, 2004</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108008530028019&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20040323 R7-0018: OpenBSD isakmpd payload handling denial-of-service vulnerabilities</ref>
      <ref url="http://www.rapid7.com/advisories/R7-0018.html" source="MISC">http://www.rapid7.com/advisories/R7-0018.html</ref>
      <ref url="http://www.securitytracker.com/alerts/2004/Mar/1009468.html" source="SECTRACK">1009468</ref>
      <ref url="http://www.securityfocus.com/bid/10032" source="BID">10028</ref>
    </refs>
    <vuln_soft>
      <prod vendor="openbsd" name="openbsd">
        <vers prev="1" num="3.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0224" published="2004-04-15" name="CVE-2004-0224" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple buffer overflows in (1) iso2022jp.c or (2) shiftjis.c for Courier-IMAP before 3.0.0, Courier before 0.45, and SqWebMail before 4.0.0 may allow remote attackers to execute arbitrary code "when Unicode character is out of BMP range."</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/9845" source="BID" patch="1" adv="1">9845</ref>
      <ref url="http://secunia.com/advisories/11087/" source="SECUNIA" patch="1" adv="1">11087</ref>
      <ref url="http://sourceforge.net/project/shownotes.php?release_id=5767" source="CONFIRM" adv="1">http://sourceforge.net/project/shownotes.php?release_id=5767</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15434" source="XF">courier-codeset-converter-bo(15434)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="double_precision_incorporated" name="courier_mta">
        <vers num="0.43" />
        <vers num="0.43.1" />
        <vers num="0.43.2" />
        <vers num="0.44" />
        <vers num="0.44.2" />
      </prod>
      <prod vendor="double_precision_incorporated" name="sqwebmail">
        <vers num="3.5.2" />
        <vers num="3.5.3" />
        <vers num="3.6.1" />
        <vers num="3.6.2" />
        <vers num="3.6_.0" />
      </prod>
      <prod vendor="inter7" name="courier-imap">
        <vers num="1.6" />
        <vers num="1.7" />
        <vers num="2.0.0" />
        <vers num="2.1" />
        <vers num="2.1.1" />
        <vers num="2.1.2" />
        <vers num="2.2.0" />
        <vers num="2.2.1" />
      </prod>
      <prod vendor="gentoo" name="linux">
        <vers num="1.4" edition="rc1" />
        <vers num="1.4" edition="rc2" />
        <vers num="1.4" edition="rc3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0226" published="2004-08-18" name="CVE-2004-0226" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Multiple buffer overflows in Midnight Commander (mc) before 4.6.0 may allow attackers to cause a denial of service or execute arbitrary code.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-172.html" source="REDHAT" patch="1" adv="1">RHSA-2004:172</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/16016" source="XF" adv="1">midnight-commander-local-privileges(16016)</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2004_12_mc.html" source="SUSE">SuSE-SA:2004:012</ref>
      <ref url="http://www.debian.org/security/2004/dsa-497" source="DEBIAN">DSA-497</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200405-21.xml" source="GENTOO">GLSA-200405-21</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2004:039" source="MANDRAKE">MDKSA-2004:039</ref>
    </refs>
    <vuln_soft>
      <prod vendor="midnight_commander" name="midnight_commander">
        <vers num="4.5.40" />
        <vers num="4.5.41" />
        <vers num="4.5.42" />
        <vers num="4.5.43" />
        <vers num="4.5.44" />
        <vers num="4.5.45" />
        <vers num="4.5.46" />
        <vers num="4.5.47" />
        <vers num="4.5.48" />
        <vers num="4.5.49" />
        <vers num="4.5.50" />
        <vers num="4.5.51" />
        <vers num="4.5.52" />
        <vers num="4.5.55" />
        <vers num="4.6" />
      </prod>
      <prod vendor="sgi" name="propack">
        <vers num="2.3" />
        <vers num="2.4" />
      </prod>
      <prod vendor="gentoo" name="linux">
        <vers num="0.5" />
        <vers num="0.7" />
        <vers num="1.1a" />
        <vers num="1.2" />
        <vers num="1.4" edition="rc1" />
        <vers num="1.4" edition="rc2" />
        <vers num="1.4" edition="rc3" />
      </prod>
      <prod vendor="slackware" name="slackware_linux">
        <vers num="9.0" />
        <vers num="9.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0227" published="2004-06-14" name="CVE-2004-0227" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in the zms script in ZoneMinder before 1.19.2 may allow a remote attacker to execute arbitrary code via a long query string.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/16136" source="XF" patch="1" adv="1">zoneminder-zms-bo(16136)</ref>
      <ref url="http://www.securityfocus.com/bid/10340" source="BID" patch="1" adv="1">10340</ref>
      <ref url="http://www.zoneminder.com/index.php?id=20&amp;type=0&amp;backPID=20&amp;tt_news=29" source="CONFIRM" adv="1">http://www.zoneminder.com/index.php?id=20&amp;type=0&amp;backPID=20&amp;tt_news=29</ref>
    </refs>
    <vuln_soft>
      <prod vendor="triornis" name="zoneminder">
        <vers num="1.17.0" />
        <vers num="1.17.1" />
        <vers num="1.17.2" />
        <vers num="1.18.0" />
        <vers num="1.18.1" />
        <vers num="1.19.0" />
        <vers num="1.19.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0228" published="2004-08-18" name="CVE-2004-0228" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Integer signedness error in the cpufreq proc handler (cpufreq_procctl) in Linux kernel 2.6 allows local users to gain privileges.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" admin="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.novell.com/linux/security/advisories/2004_10_kernel.html" source="SUSE">SuSE-SA:2004:010</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200407-02.xml" source="GENTOO" adv="1">GLSA-200407-02</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15951" source="XF">linux-cpufreq-info-disclosure(15951)</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2004:050" source="MANDRAKE">MDKSA-2004:050</ref>
      <ref url="http://secunia.com/advisories/11683" source="SECUNIA">11683</ref>
      <ref url="http://secunia.com/advisories/11491" source="SECUNIA">11491</ref>
      <ref url="http://secunia.com/advisories/11486" source="SECUNIA">11486</ref>
      <ref url="http://secunia.com/advisories/11464" source="SECUNIA">11464</ref>
      <ref url="http://secunia.com/advisories/11429" source="SECUNIA">11429</ref>
      <ref url="http://fedoranews.org/updates/FEDORA-2004-111.shtml" source="FEDORA">FEDORA-2004-111</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000852" source="CONECTIVA">CLA-2004:852</ref>
    </refs>
    <vuln_soft>
      <prod vendor="linux" name="linux_kernel">
        <vers num="2.6.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0229" published="2004-08-18" name="CVE-2004-0229" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">The framebuffer driver in Linux kernel 2.6.x does not properly use the fb_copy_cmap function, with unknown impact.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/15974" source="XF" adv="1">linux-framebuffer(15974)</ref>
      <ref url="http://www.securityfocus.com/bid/10211" source="BID" adv="1">10211</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2004_10_kernel.html" source="SUSE">SuSE-SA:2004:010</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200407-02.xml" source="GENTOO" adv="1">GLSA-200407-02</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2004:037" source="MANDRAKE">MDKSA-2004:037</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000852" source="CONECTIVA">CLA-2004:852</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gentoo" name="linux">
        <vers num="1.4" />
      </prod>
      <prod vendor="linux" name="linux_kernel">
        <vers num="2.4.20" />
        <vers num="2.4.21" edition="pre1" />
        <vers num="2.4.21" edition="pre4" />
        <vers num="2.4.21" edition="pre7" />
        <vers num="2.4.22" />
        <vers num="2.4.23" edition="pre9" />
        <vers num="2.4.23_ow2" />
        <vers num="2.4.24" />
        <vers num="2.4.24_ow1" />
        <vers num="2.4.25" />
        <vers num="2.4.26" />
        <vers num="2.6.0" edition="test1" />
        <vers num="2.6.0" edition="test10" />
        <vers num="2.6.0" edition="test11" />
        <vers num="2.6.0" edition="test2" />
        <vers num="2.6.0" edition="test3" />
        <vers num="2.6.0" edition="test4" />
        <vers num="2.6.0" edition="test5" />
        <vers num="2.6.0" edition="test6" />
        <vers num="2.6.0" edition="test7" />
        <vers num="2.6.0" edition="test8" />
        <vers num="2.6.0" edition="test9" />
        <vers num="2.6.1" edition="rc1" />
        <vers num="2.6.1" edition="rc2" />
        <vers num="2.6.2" />
        <vers num="2.6.3" />
        <vers num="2.6.4" />
        <vers num="2.6.5" />
        <vers num="2.6_test9_cvs" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0230" published="2004-08-18" name="CVE-2004-0230" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">TCP, when using a large Window Size, makes it easier for remote attackers to guess sequence numbers and cause a denial of service (connection loss) to persistent TCP connections by repeatedly injecting a TCP RST packet, especially in protocols that use long-lived connections, such as BGP.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA04-111A.html" source="CERT" adv="1">TA04-111A</ref>
      <ref url="http://www.kb.cert.org/vuls/id/415294" source="CERT-VN">VU#415294</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15886" source="XF" adv="1">tcp-rst-dos(15886)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/3983" source="VUPEN">ADV-2006-3983</ref>
      <ref url="http://www.uniras.gov.uk/vuls/2004/236929/index.htm" source="MISC">http://www.uniras.gov.uk/vuls/2004/236929/index.htm</ref>
      <ref url="http://www.securityfocus.com/bid/10183" source="BID" adv="1">10183</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/449179/100/0/threaded" source="HP">SSRT061264</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms05-019.mspx" source="MS">MS05-019</ref>
      <ref url="http://www.juniper.net/support/alert.html" source="CONFIRM">http://www.juniper.net/support/alert.html</ref>
      <ref url="http://www.cisco.com/warp/public/707/cisco-sa-20040420-tcp-ios.shtml" source="CISCO">20040420 TCP Vulnerabilities in Multiple IOS-Based Cisco Products</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5711" source="OVAL">oval:org.mitre.oval:def:5711</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108302060014745&amp;w=2" source="BUGTRAQ">20040425 Perl code exploting TCP not checking RST ACK.</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/20040403-01-A.asc" source="SGI">20040403-01-A</ref>
      <ref url="ftp://ftp.sco.com/pub/updates/UnixWare/SCOSA-2005.14/SCOSA-2005.14.txt" source="SCO">SCOSA-2005.14</ref>
      <ref url="ftp://ftp.sco.com/pub/updates/OpenServer/SCOSA-2005.9/SCOSA-2005.9.txt" source="SCO">SCOSA-2005.9</ref>
      <ref url="ftp://ftp.sco.com/pub/updates/OpenServer/SCOSA-2005.3/SCOSA-2005.3.txt" source="SCO">SCOSA-2005.3</ref>
      <ref url="ftp://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2004-006.txt.asc" source="NETBSD">NetBSD-SA2004-006</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/449179/100/0/threaded" source="HP">SSRT061264</ref>
      <ref url="http://www.osvdb.org/4030" source="OSVDB">4030</ref>
      <ref url="http://www.microsoft.com/technet/security/Bulletin/MS06-064.mspx" source="MS">MS06-064</ref>
      <ref url="http://secunia.com/advisories/22341" source="SECUNIA">22341</ref>
      <ref url="http://secunia.com/advisories/11458" source="SECUNIA">11458</ref>
      <ref url="http://secunia.com/advisories/11440" source="SECUNIA">11440</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108506952116653&amp;w=2" source="HP">SSRT4696</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:4791" source="OVAL" sig="1">oval:org.mitre.oval:def:4791</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:3508" source="OVAL" sig="1">oval:org.mitre.oval:def:3508</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:270" source="OVAL" sig="1">oval:org.mitre.oval:def:270</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2689" source="OVAL" sig="1">oval:org.mitre.oval:def:2689</ref>
    </refs>
    <vuln_soft>
      <prod vendor="tcp" name="tcp">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2004-0231" published="2004-08-18" name="CVE-2004-0231" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">Multiple vulnerabilities in Midnight Commander (mc) before 4.6.0, with unknown impact, related to "Insecure temporary file and directory creations."</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.debian.org/security/2004/dsa-497" source="DEBIAN" patch="1" adv="1">DSA-497</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/16020" source="XF" adv="1">midnight-commander-insecure-files(16020)</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-172.html" source="REDHAT">RHSA-2004:172</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2004_12_mc.html" source="SUSE">SuSE-SA:2004:012</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200405-21.xml" source="GENTOO" adv="1">GLSA-200405-21</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2004:039" source="MANDRAKE">MDKSA-2004:039</ref>
    </refs>
    <vuln_soft>
      <prod vendor="midnight_commander" name="midnight_commander">
        <vers num="4.5.40" />
        <vers num="4.5.41" />
        <vers num="4.5.42" />
        <vers num="4.5.43" />
        <vers num="4.5.44" />
        <vers num="4.5.45" />
        <vers num="4.5.46" />
        <vers num="4.5.47" />
        <vers num="4.5.48" />
        <vers num="4.5.49" />
        <vers num="4.5.50" />
        <vers num="4.5.51" />
        <vers num="4.5.52" />
        <vers num="4.5.55" />
        <vers num="4.6" />
      </prod>
      <prod vendor="sgi" name="propack">
        <vers num="2.3" />
        <vers num="2.4" />
      </prod>
      <prod vendor="gentoo" name="linux">
        <vers num="0.5" />
        <vers num="0.7" />
        <vers num="1.1a" />
        <vers num="1.2" />
        <vers num="1.4" edition="rc1" />
        <vers num="1.4" edition="rc2" />
        <vers num="1.4" edition="rc3" />
      </prod>
      <prod vendor="slackware" name="slackware_linux">
        <vers num="9.0" />
        <vers num="9.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0232" published="2004-08-18" name="CVE-2004-0232" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Multiple format string vulnerabilities in Midnight Commander (mc) before 4.6.0 may allow attackers to cause a denial of service or execute arbitrary code.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/16021" source="XF" adv="1">midnight-commander-format-string(16021)</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-172.html" source="REDHAT">RHSA-2004:172</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2004_12_mc.html" source="SUSE">SuSE-SA:2004:012</ref>
      <ref url="http://www.debian.org/security/2004/dsa-497" source="DEBIAN">DSA-497</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200405-21.xml" source="GENTOO">GLSA-200405-21</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2004:039" source="MANDRAKE">MDKSA-2004:039</ref>
    </refs>
    <vuln_soft>
      <prod vendor="midnight_commander" name="midnight_commander">
        <vers num="4.5.40" />
        <vers num="4.5.41" />
        <vers num="4.5.42" />
        <vers num="4.5.43" />
        <vers num="4.5.44" />
        <vers num="4.5.45" />
        <vers num="4.5.46" />
        <vers num="4.5.47" />
        <vers num="4.5.48" />
        <vers num="4.5.49" />
        <vers num="4.5.50" />
        <vers num="4.5.51" />
        <vers num="4.5.52" />
        <vers num="4.5.55" />
        <vers num="4.6" />
      </prod>
      <prod vendor="sgi" name="propack">
        <vers num="2.3" />
        <vers num="2.4" />
      </prod>
      <prod vendor="gentoo" name="linux">
        <vers num="0.5" />
        <vers num="0.7" />
        <vers num="1.1a" />
        <vers num="1.2" />
        <vers num="1.4" edition="rc1" />
        <vers num="1.4" edition="rc2" />
        <vers num="1.4" edition="rc3" />
      </prod>
      <prod vendor="slackware" name="slackware_linux">
        <vers num="9.0" />
        <vers num="9.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2004-0233" published="2004-08-18" name="CVE-2004-0233" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">Utempter allows device names that contain .. (dot dot) directory traversal sequences, which allows local users to overwrite arbitrary files via a symlink attack on device names in combination with an application that trusts the utmp or wtmp files.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/10178" source="BID" patch="1" adv="1">10178</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-174.html" source="REDHAT" patch="1" adv="1">RHSA-2004:174</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15904" source="XF" adv="1">utemper-symlink(15904)</ref>
      <ref url="http://www.slackware.com/security/viewer.php?l=slackware-security&amp;y=2004&amp;m=slackware-security.404389" source="SLACKWARE">SSA:2004-110</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-175.html" source="REDHAT">RHSA-2004:175</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-77-1000752.1-1" source="SUNALERT">1000752</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200405-05.xml" source="GENTOO">GLSA-200405-05</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10115" source="OVAL">oval:org.mitre.oval:def:10115</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2004:031" source="MANDRAKE">MDKSA-2004:031</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:979" source="OVAL" sig="1">oval:org.mitre.oval:def:979</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sgi" name="propack">
        <vers num="2.4" />
        <vers num="3.0" />
      </prod>
      <prod vendor="utempter" name="utempter">
        <vers num="0.5.2" />
        <vers num="0.5.3" />
      </prod>
      <prod vendor="slackware" name="slackware_linux">
        <vers num="9.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0234" published="2004-08-18" name="CVE-2004-0234" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Multiple stack-based buffer overflows in the get_header function in header.c for LHA 1.14, as used in products such as Barracuda Spam Firewall, allow remote attackers or local users to execute arbitrary code via long directory or file names in an LHA archive, which triggers the overflow when testing or extracting the archive.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/10243" source="BID" patch="1" adv="1">10243</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108422737918885&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20040510 [Ulf Harnhammar]: LHA Advisory + Patch</ref>
      <ref url="https://bugzilla.fedora.us/show_bug.cgi?id=1833" source="FEDORA">FLSA:1833</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/16012" source="XF" adv="1">lha-multiple-bo(16012)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1220" source="VUPEN" adv="1">ADV-2006-1220</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-179.html" source="REDHAT">RHSA-2004:179</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-178.html" source="REDHAT">RHSA-2004:178</ref>
      <ref url="http://www.redhat.com/archives/fedora-announce-list/2004-May/msg00005.html" source="FEDORA">FEDORA-2004-119</ref>
      <ref url="http://www.osvdb.org/5754" source="OSVDB">5754</ref>
      <ref url="http://www.osvdb.org/5753" source="OSVDB">5753</ref>
      <ref url="http://www.guay-leroux.com/projects/barracuda-advisory-LHA.txt" source="MISC">http://www.guay-leroux.com/projects/barracuda-advisory-LHA.txt</ref>
      <ref url="http://www.debian.org/security/2004/dsa-515" source="DEBIAN">DSA-515</ref>
      <ref url="http://securitytracker.com/id?1015866" source="SECTRACK">1015866</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200405-02.xml" source="GENTOO">GLSA-200405-02</ref>
      <ref url="http://secunia.com/advisories/19514" source="SECUNIA" adv="1">19514</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9881" source="OVAL">oval:org.mitre.oval:def:9881</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2004-May/020778.html" source="FULLDISC">20040502 Lha local stack overflow Proof Of Concept Code</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2004-May/020776.html" source="FULLDISC">20040501 LHa buffer overflows and directory traversal problems</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000840" source="CONECTIVA">CLA-2004:840</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2006-04/0059.html" source="BUGTRAQ">20060403 Barracuda LHA archiver security bug leads to remote compromise</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:977" source="OVAL" sig="1">oval:org.mitre.oval:def:977</ref>
    </refs>
    <vuln_soft>
      <prod vendor="clearswift" name="mailsweeper">
        <vers num="4.0" />
        <vers num="4.1" />
        <vers num="4.2" />
        <vers num="4.3" />
        <vers num="4.3.10" />
        <vers num="4.3.11" />
        <vers num="4.3.13" />
        <vers num="4.3.3" />
        <vers num="4.3.4" />
        <vers num="4.3.5" />
        <vers num="4.3.6" />
        <vers num="4.3.6_sp1" />
        <vers num="4.3.7" />
        <vers num="4.3.8" />
      </prod>
      <prod vendor="f-secure" name="f-secure_anti-virus">
        <vers num="2003" />
        <vers num="2004" />
        <vers num="4.51" edition="" />
        <vers num="4.51" edition=":linux_workstations" />
        <vers num="4.51" edition=":linux_servers" />
        <vers num="4.51" edition=":linux_gateways" />
        <vers num="4.52" edition="" />
        <vers num="4.52" edition=":linux_workstations" />
        <vers num="4.52" edition=":linux_servers" />
        <vers num="4.52" edition=":linux_gateways" />
        <vers num="4.60" edition="" />
        <vers num="4.60" edition=":samba_servers" />
        <vers num="5.41" edition="" />
        <vers num="5.41" edition=":mimesweeper" />
        <vers num="5.41" edition=":workstations" />
        <vers num="5.41" edition=":windows_servers" />
        <vers num="5.42" edition="" />
        <vers num="5.42" edition=":mimesweeper" />
        <vers num="5.42" edition=":windows_servers" />
        <vers num="5.42" edition=":workstations" />
        <vers num="5.5" edition="" />
        <vers num="5.5" edition=":client_security" />
        <vers num="5.52" edition="" />
        <vers num="5.52" edition=":client_security" />
        <vers num="6.21" edition="" />
        <vers num="6.21" edition=":ms_exchange" />
      </prod>
      <prod vendor="f-secure" name="f-secure_for_firewalls">
        <vers num="6.20" />
      </prod>
      <prod vendor="f-secure" name="f-secure_internet_security">
        <vers num="2003" />
        <vers num="2004" />
      </prod>
      <prod vendor="f-secure" name="f-secure_personal_express">
        <vers num="4.5" />
        <vers num="4.6" />
        <vers num="4.7" />
      </prod>
      <prod vendor="f-secure" name="internet_gatekeeper">
        <vers num="6.31" />
        <vers num="6.32" />
      </prod>
      <prod vendor="rarlab" name="winrar">
        <vers num="3.20" />
      </prod>
      <prod vendor="redhat" name="lha">
        <vers num="1.14i-9" edition="" />
        <vers num="1.14i-9" edition=":i386" />
      </prod>
      <prod vendor="sgi" name="propack">
        <vers num="2.4" />
        <vers num="3.0" />
      </prod>
      <prod vendor="stalker" name="cgpmcafee">
        <vers num="3.2" />
      </prod>
      <prod vendor="tsugio_okamoto" name="lha">
        <vers num="1.14" />
        <vers num="1.15" />
        <vers num="1.17" />
      </prod>
      <prod vendor="winzip" name="winzip">
        <vers num="9.0" />
      </prod>
      <prod vendor="redhat" name="fedora_core">
        <vers num="core_1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0235" published="2004-08-18" name="CVE-2004-0235" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)" CVSS_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_base_score="6.4">
    <desc>
      <descript source="cve">Multiple directory traversal vulnerabilities in LHA 1.14 allow remote attackers or local users to create arbitrary files via an LHA archive containing filenames with (1) .. sequences or (2) absolute pathnames with double leading slashes ("//absolute/path").</descript>
    </desc>
    <loss_types>
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/10243" source="BID" patch="1" adv="1">10243</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108422737918885&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20040510 [Ulf Harnhammar]: LHA Advisory + Patch</ref>
      <ref url="https://bugzilla.fedora.us/show_bug.cgi?id=1833" source="FEDORA">FLSA:1833</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/16013" source="XF" adv="1">lha-directory-traversal(16013)</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-179.html" source="REDHAT">RHSA-2004:179</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-178.html" source="REDHAT">RHSA-2004:178</ref>
      <ref url="http://www.redhat.com/archives/fedora-announce-list/2004-May/msg00005.html" source="FEDORA">FEDORA-2004-119</ref>
      <ref url="http://www.debian.org/security/2004/dsa-515" source="DEBIAN">DSA-515</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200405-02.xml" source="GENTOO">GLSA-200405-02</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10409" source="OVAL">oval:org.mitre.oval:def:10409</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2004-May/020776.html" source="FULLDISC">20040501 LHa buffer overflows and directory traversal problems</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000840" source="CONECTIVA">CLA-2004:840</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:978" source="OVAL" sig="1">oval:org.mitre.oval:def:978</ref>
    </refs>
    <vuln_soft>
      <prod vendor="clearswift" name="mailsweeper">
        <vers num="4.0" />
        <vers num="4.1" />
        <vers num="4.2" />
        <vers num="4.3" />
        <vers num="4.3.10" />
        <vers num="4.3.11" />
        <vers num="4.3.13" />
        <vers num="4.3.3" />
        <vers num="4.3.4" />
        <vers num="4.3.5" />
        <vers num="4.3.6" />
        <vers num="4.3.6_sp1" />
        <vers num="4.3.7" />
        <vers num="4.3.8" />
      </prod>
      <prod vendor="f-secure" name="f-secure_anti-virus">
        <vers num="2003" />
        <vers num="2004" />
        <vers num="4.51" edition="" />
        <vers num="4.51" edition=":linux_workstations" />
        <vers num="4.51" edition=":linux_servers" />
        <vers num="4.51" edition=":linux_gateways" />
        <vers num="4.52" edition="" />
        <vers num="4.52" edition=":linux_workstations" />
        <vers num="4.52" edition=":linux_servers" />
        <vers num="4.52" edition=":linux_gateways" />
        <vers num="4.60" edition="" />
        <vers num="4.60" edition=":samba_servers" />
        <vers num="5.41" edition="" />
        <vers num="5.41" edition=":mimesweeper" />
        <vers num="5.41" edition=":workstations" />
        <vers num="5.41" edition=":windows_servers" />
        <vers num="5.42" edition="" />
        <vers num="5.42" edition=":mimesweeper" />
        <vers num="5.42" edition=":windows_servers" />
        <vers num="5.42" edition=":workstations" />
        <vers num="5.5" edition="" />
        <vers num="5.5" edition=":client_security" />
        <vers num="5.52" edition="" />
        <vers num="5.52" edition=":client_security" />
        <vers num="6.21" edition="" />
        <vers num="6.21" edition=":ms_exchange" />
      </prod>
      <prod vendor="f-secure" name="f-secure_for_firewalls">
        <vers num="6.20" />
      </prod>
      <prod vendor="f-secure" name="f-secure_internet_security">
        <vers num="2003" />
        <vers num="2004" />
      </prod>
      <prod vendor="f-secure" name="f-secure_personal_express">
        <vers num="4.5" />
        <vers num="4.6" />
        <vers num="4.7" />
      </prod>
      <prod vendor="f-secure" name="internet_gatekeeper">
        <vers num="6.31" />
        <vers num="6.32" />
      </prod>
      <prod vendor="rarlab" name="winrar">
        <vers num="3.20" />
      </prod>
      <prod vendor="redhat" name="lha">
        <vers num="1.14i-9" edition="" />
        <vers num="1.14i-9" edition=":i386" />
      </prod>
      <prod vendor="sgi" name="propack">
        <vers num="2.4" />
        <vers num="3.0" />
      </prod>
      <prod vendor="stalker" name="cgpmcafee">
        <vers num="3.2" />
      </prod>
      <prod vendor="tsugio_okamoto" name="lha">
        <vers num="1.14" />
        <vers num="1.15" />
        <vers num="1.17" />
      </prod>
      <prod vendor="winzip" name="winzip">
        <vers num="9.0" />
      </prod>
      <prod vendor="redhat" name="fedora_core">
        <vers num="core_1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0236" published="2004-11-23" name="CVE-2004-0236" modified="2009-01-29" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">SQL injection vulnerability in login.asp in thePHOTOtool allows remote attackers to gain unauthorized access via the password field.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" admin="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/15007" source="XF" adv="1">thephototool-login-sql-injection(15007)</ref>
      <ref url="http://www.securityfocus.com/bid/9884" source="BID" adv="1">9884</ref>
      <ref url="http://www.osvdb.org/6727" source="OSVDB">6727</ref>
      <ref url="http://securitytracker.com/alerts/2004/Feb/1008906.html" source="SECTRACK">1008906</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107576894019530&amp;w=2" source="BUGTRAQ" adv="1">20040131 Advisory !</ref>
    </refs>
    <vuln_soft>
      <prod vendor="steelid" name="thephototool">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0237" published="2004-11-23" name="CVE-2004-0237" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in index.php in Aprox PHP Portal allows remote attackers to read arbitrary files via a full pathname in the show parameter.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/15014" source="XF" adv="1">aproxphpportal-index-directory-traversal(15014)</ref>
      <ref url="http://www.securityfocus.com/bid/9540" source="BID" adv="1">9540</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107577555527321&amp;w=2" source="BUGTRAQ" adv="1">20040131 Directory Traversal in Aprox PHP Portal.</ref>
      <ref url="http://www.osvdb.org/10859" source="OSVDB">10859</ref>
      <ref url="http://securitytracker.com/id?1008915" source="SECTRACK">1008915</ref>
    </refs>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0238" published="2004-11-23" name="CVE-2004-0238" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Multiple buffer overflows in Overkill (0verkill) 0.15pre3 might allow local users to execute arbitrary code in the client via a long HOME environment variable in the (1) load_cfg and (2) save_cfg functions; possibly allow remote attackers to execute arbitrary code via long strings to (3) the send_message function; and, in the server, via (4) the parse_command_line function.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/15000" source="XF">overkill-server-parsecommandline-bo(15000)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/14999" source="XF" adv="1">overkill-client-multiple-bo(14999)</ref>
      <ref url="http://www.securityfocus.com/bid/9550" source="BID" adv="1">9550</ref>
      <ref url="http://www.securiteam.com/securitynews/5AP010KC0C.html" source="MISC">http://www.securiteam.com/securitynews/5AP010KC0C.html</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107577335424509&amp;w=2" source="BUGTRAQ" adv="1">20040202 0verkill - little simple vulnerability.</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2004-February/016579.html" source="FULLDISC">20040202 0verkill - little simple vulnerability.</ref>
    </refs>
    <vuln_soft>
      <prod vendor="0verkill" name="0verkill">
        <vers num="0.16" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0239" published="2004-11-23" name="CVE-2004-0239" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">SQL injection vulnerability in showphoto.php in PhotoPost PHP Pro 4.6 and earlier allows remote attackers to gain unauthorized access via the photo variable.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" admin="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/15008" source="XF" adv="1">photopostphp-sql-injection(15008)</ref>
      <ref url="http://www.securityfocus.com/bid/9557" source="BID" adv="1">9557</ref>
      <ref url="http://www.securiteam.com/securitynews/5KP010UC0W.html" source="MISC">http://www.securiteam.com/securitynews/5KP010UC0W.html</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107582512023998&amp;w=2" source="BUGTRAQ">20040202 ZH2004-03SA (security advisory): Photopost PHP Pro 4.6 Sql</ref>
    </refs>
    <vuln_soft>
      <prod vendor="photopost" name="photopost_php_pro">
        <vers num="3.1" />
        <vers num="3.2" />
        <vers num="3.3" />
        <vers num="4.0" />
        <vers num="4.1" />
        <vers num="4.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0240" published="2004-11-23" name="CVE-2004-0240" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in X-Cart 3.4.3 allows remote attackers to view arbitrary files via a .. (dot dot) in the shop_closed_file argument to auth.php.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/15033" source="XF" adv="1">xcart-dotdot-directory-traversal(15033)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107582648326448&amp;w=2" source="BUGTRAQ" adv="1">20040203 X-Cart vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="qualiteam" name="x-cart">
        <vers num="3.2.0" />
        <vers num="3.2.1" />
        <vers num="3.3.0" />
        <vers num="3.3.2" />
        <vers num="3.4.0" />
        <vers num="3.4.11" />
        <vers num="3.4.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0241" published="2004-11-23" name="CVE-2004-0241" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">X-Cart 3.4.3 allows remote attackers to execute arbitrary commands via the perl_binary argument in (1) upgrade.php or (2) general.php.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" admin="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/9560" source="BID" patch="1" adv="1">9560</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15034" source="XF" adv="1">xcart-perlbinary-execute-commands(15034)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107582648326448&amp;w=2" source="BUGTRAQ" adv="1">20040203 X-Cart vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="qualiteam" name="x-cart">
        <vers num="3.2.0" />
        <vers num="3.2.1" />
        <vers num="3.3.0" />
        <vers num="3.3.2" />
        <vers num="3.4.0" />
        <vers num="3.4.11" />
        <vers num="3.4.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0242" published="2004-11-23" name="CVE-2004-0242" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">X-Cart 3.4.3 allows remote attackers to gain sensitive information via a mode parameter with (1) phpinfo command or (2) perlinfo command.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/9563" source="BID" patch="1" adv="1">9563</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15036" source="XF" adv="1">xcart-generalphp-obtain-information(15036)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107582648326448&amp;w=2" source="BUGTRAQ" adv="1">20040203 X-Cart vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="qualiteam" name="x-cart">
        <vers num="3.2.0" />
        <vers num="3.2.1" />
        <vers num="3.3.0" />
        <vers num="3.3.2" />
        <vers num="3.4.0" />
        <vers num="3.4.11" />
        <vers num="3.4.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0243" published="2004-11-23" name="CVE-2004-0243" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">AIX 4.3.3 through AIX 5.1, when direct remote login is disabled, displays a different message if the password is correct, which allows remote attackers to guess the password via brute force methods.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/15172" source="XF">aix-password-enumeration(15172)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107583269206044&amp;w=2" source="BUGTRAQ" adv="1">20040203 Re: sqwebmail web login</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2004-02/0313.html" source="BUGTRAQ">20040206 AIX password enumeration possible</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="aix">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0244" published="2004-11-23" name="CVE-2004-0244" modified="2009-03-04" CVSS_version="2.0" CVSS_vector="(AV:L/AC:M/Au:N/C:N/I:N/A:C)" CVSS_score="4.7" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="3.4" CVSS_base_score="4.7">
    <desc>
      <descript source="cve">Cisco 6000, 6500, and 7600 series systems with Multilayer Switch Feature Card 2 (MSFC2) and a FlexWAN or OSM module allow local users to cause a denial of service (hang or reset) by sending a layer 2 frame packet that encapsulates a layer 3 packet, but has inconsistent length values with that packet.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/810062" source="CERT-VN">VU#810062</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15013" source="XF" adv="1">cisco-malformed-frame-dos(15013)</ref>
      <ref url="http://www.securityfocus.com/bid/9562" source="BID" adv="1">9562</ref>
      <ref url="http://www.cisco.com/warp/public/707/cisco-sa-20040203-cat6k.shtml" source="CISCO" adv="1">20040203 Cisco 6000/6500/7600 Crafted Layer 2 Frame Vulnerability</ref>
      <ref url="http://secunia.com/advisories/10780" source="SECUNIA">10780</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5828" source="OVAL">oval:org.mitre.oval:def:5828</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="ios">
        <vers num="12.1e" />
        <vers num="12.2sy" />
        <vers num="12.2za" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0245" published="2004-11-23" name="CVE-2004-0245" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Web Crossing 4.x and 5.x allows remote attackers to cause a denial of service (crash) by sending a HTTP POST request with a large or negative Content-Length, which causes an integer divide-by-zero.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107586518120516&amp;w=2" source="BUGTRAQ" adv="1">20040203 Web Crossing 4.x/5.x Denial of Service Vulnerability</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15022" source="XF">webcrossing-contentlength-post-dos(15022)</ref>
      <ref url="http://www.securityfocus.com/bid/9576" source="BID">9576</ref>
    </refs>
    <vuln_soft>
      <prod vendor="web_crossing_inc" name="web_crossing">
        <vers num="4.0" />
        <vers num="5.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0246" published="2004-11-23" name="CVE-2004-0246" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Multiple PHP remote file inclusion vulnerabilities in (1) fonctions.lib.php, (2) derniers_commentaires.php, and (3) admin.php in Les Commentaires 2.0 allow remote attackers to execute arbitrary PHP code via the rep parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" admin="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107584083719763&amp;w=2" source="BUGTRAQ" patch="1">20040203 Les Commentaires (PHP) Include file</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15010" source="XF" adv="1">lescommentaires-multiple-file-include(15010)</ref>
      <ref url="http://www.securityfocus.com/bid/9536" source="BID" adv="1">9536</ref>
      <ref url="http://secunia.com/advisories/10768/" source="SECUNIA">10768</ref>
    </refs>
    <vuln_soft>
      <prod vendor="laurent_adda" name="les_commentaires">
        <vers num="2.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0247" published="2004-11-23" name="CVE-2004-0247" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The client and server of Chaser 1.50 and earlier allow remote attackers to cause a denial of service (crash via exception) via a UDP packet with a length field that is greater than the actual data length, which causes Chaser to read unexpected memory.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/15031" source="XF" adv="1">chaser-memory-dos(15031)</ref>
      <ref url="http://www.securityfocus.com/bid/9567" source="BID" adv="1">9567</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107584109420084&amp;w=2" source="BUGTRAQ" adv="1">20040203 Remote crash of Chaser game &lt;= 1.50</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cauldron" name="chaser_client">
        <vers num="1.5" />
      </prod>
      <prod vendor="cauldron" name="chaser_server">
        <vers num="1.4.9" />
        <vers num="1.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0248" published="2004-11-23" name="CVE-2004-0248" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Cross-site scripting vulnerability (XSS) in PHPX 3.2.3 allows remote attackers to execute arbitrary script as other users by injecting arbitrary HTML or script into (1) keywords argument of main.inc.php, (2) body argument of help.inc.php, or (3) the subject field in Personal Messages and Forum.</descript>
    </desc>
    <sols>
      <sol source="nvd">This vulnerability is addressed in the following product release:
PHPX, PHPX, 3.2.4</sol>
    </sols>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/15051" source="XF" patch="1">phpx-main-help-xss(15051)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15050" source="XF" patch="1">phpx-subject-html-injection(15050)</ref>
      <ref url="http://www.securityfocus.com/bid/9569" source="BID" patch="1">9569</ref>
      <ref url="http://secunia.com/advisories/10797/" source="SECUNIA" patch="1" adv="1">10797</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107586932324901&amp;w=2" source="BUGTRAQ" patch="1">20040203 Multiple Vulnerabilities in PHPX</ref>
    </refs>
    <vuln_soft>
      <prod vendor="phpx" name="phpx">
        <vers num="3.2.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0249" published="2004-11-23" name="CVE-2004-0249" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">PHPX 2.0 through 3.2.4 allows remote attackers to gain access to other accounts by modifying the cookie's PXL variable to reference another userID.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" admin="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/9569" source="BID" patch="1" adv="1">9569</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15052" source="XF" adv="1">phpx-cookie-account-hijacking(15052)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107586932324901&amp;w=2" source="BUGTRAQ" adv="1">20040203 Multiple Vulnerabilities in PHPX</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15512" source="XF">phpx-session-hijack(15512)</ref>
      <ref url="http://secunia.com/advisories/10797/" source="SECUNIA">10797</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2004-03/0154.html" source="BUGTRAQ">20040316 PHPX 2.x - 3.2.4</ref>
    </refs>
    <vuln_soft>
      <prod vendor="phpx" name="phpx">
        <vers num="3.2.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0250" published="2004-11-23" name="CVE-2004-0250" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">SQL injection vulnerability in PhotoPost PHP Pro 4.6 and earlier allows remote attackers to gain privileges via (1) the product parameter in showproduct.php or (2) the cat parameter in showcat.php.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" admin="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107593114909696&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20040204 ZH2004-04SA (security advisory): Multiple Sql Injection</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15008" source="XF" adv="1">photopostphp-sql-injection(15008)</ref>
      <ref url="http://www.zone-h.org/en/advisories/read/id=3864/" source="MISC">http://www.zone-h.org/en/advisories/read/id=3864/</ref>
      <ref url="http://www.securityfocus.com/bid/9557" source="BID" adv="1">9557</ref>
    </refs>
    <vuln_soft>
      <prod vendor="photopost" name="photopost_php_pro">
        <vers num="3.1" />
        <vers num="3.2" />
        <vers num="3.3" />
        <vers num="4.0" />
        <vers num="4.1" />
        <vers num="4.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0251" published="2004-11-23" name="CVE-2004-0251" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in rxgoogle.cgi allows remote attackers to execute arbitrary script as other users via the query parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107594183924958&amp;w=2" source="BUGTRAQ" patch="1">20040204 rxgoogle.cgi XSS Vulnerability.</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15043" source="XF">rxgoogle-query-xss(15043)</ref>
      <ref url="http://www.securityfocus.com/bid/9575" source="BID">9575</ref>
    </refs>
    <vuln_soft>
      <prod vendor="rxgoogle.cgi" name="rxgoogle.cgi">
        <vers num="1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0252" published="2004-11-23" name="CVE-2004-0252" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">TYPSoft FTP Server 1.10 allows remote attackers to cause a denial of service (CPU consumption) via an empty USER name.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/15048" source="XF" adv="1">typsoft-empty-username-dos(15048)</ref>
      <ref url="http://www.securityfocus.com/bid/9573" source="BID" adv="1">9573</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107591511716707&amp;w=2" source="BUGTRAQ" adv="1">20040204 TYPSoft FTP Server 1.10 may be crashed</ref>
      <ref url="http://www.securitytracker.com/alerts/2004/Feb/1008943.html" source="SECTRACK">1008943</ref>
    </refs>
    <vuln_soft>
      <prod vendor="typsoft" name="typsoft_ftp_server">
        <vers num="1.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0253" published="2004-11-23" name="CVE-2004-0253" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">IBM Cloudscape 5.1 running jdk 1.4.2_03 allows remote attackers to execute arbitrary programs or cause a denial of service via certain SQL code, possibly due to a SQL injection vulnerability.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" admin="1" />
    </loss_types>
    <vuln_types>
      <input />
      <config />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/15067" source="XF" adv="1">cloudscape-sql-injection(15067)</ref>
      <ref url="http://www.securityfocus.com/bid/9583" source="BID" adv="1">9583</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107604065819233&amp;w=2" source="BUGTRAQ" adv="1">20040205 IBM cloudscape SQL Database (DB2J) vulnerable to remote command</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="cloudscape">
        <vers num="5.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0254" published="2004-11-23" name="CVE-2004-0254" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in Discuz! Board 2.x and 3.x allows remote attackers to execute arbitrary script as other users via an img tag.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/15066" source="XF">discuzboard-image-tag-xss(15066)</ref>
      <ref url="http://www.securityfocus.com/bid/9584" source="BID">9584</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107606726417150&amp;w=2" source="BUGTRAQ">20040205 Possible Cross Site Scripting in Discuz! Board</ref>
    </refs>
    <vuln_soft>
      <prod vendor="crosscom_olicom" name="discuz">
        <vers num="2.0" />
        <vers num="3.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0255" published="2004-11-23" name="CVE-2004-0255" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Xlight 1.52, with log to screen enabled, allows remote attackers to cause a denial of service by requesting a long directory consisting of . (dot) and / (slash) characters, which causes the server to crash when the administrator views the log file, possibly triggering a buffer overflow.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
      <config />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/15064" source="XF" adv="1">xlight-long-string-dos(15064)</ref>
      <ref url="http://www.securityfocus.com/bid/9585" source="BID" adv="1">9585</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107605633904122&amp;w=2" source="BUGTRAQ" adv="1">20040205 Remote crash Xlight ftp server 1.52</ref>
    </refs>
    <vuln_soft>
      <prod vendor="xlight_ftp_server" name="xlight_ftp_server">
        <vers num="1.25" />
        <vers num="1.41" />
        <vers num="1.45" />
        <vers num="1.52" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2004-0256" published="2004-11-23" name="CVE-2004-0256" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">GNU libtool before 1.5.2, during compile time, allows local users to overwrite arbitrary files via a symlink attack on libtool directories in /tmp.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/9530" source="BID" patch="1" adv="1">9530</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15017" source="XF" adv="1">libtool-insecure-temp-directory(15017)</ref>
      <ref url="http://www.securityfocus.com/archive/1/352333" source="BUGTRAQ">20040130 Symlink Vulnerability in GNU libtool &lt;1.5.2</ref>
      <ref url="http://www.osvdb.org/3795" source="OSVDB">3795</ref>
      <ref url="http://www.geocrawler.com/mail/msg.php3?msg_id=3438808&amp;list=405" source="MISC">http://www.geocrawler.com/mail/msg.php3?msg_id=3438808&amp;list=405</ref>
      <ref url="http://secunia.com/advisories/10777" source="SECUNIA">10777</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000811" source="CONECTIVA">CLA-2004:811</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gnu" name="libtool">
        <vers num="1.0" />
        <vers num="1.1" />
        <vers num="1.2" />
        <vers num="1.3" />
        <vers num="1.3.2" />
        <vers num="1.3.3" />
        <vers num="1.3.4" />
        <vers num="1.3.5" />
        <vers num="1.4" />
        <vers num="1.4.1" />
        <vers num="1.4.2" />
        <vers num="1.4.3" />
        <vers num="1.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0257" published="2004-11-23" name="CVE-2004-0257" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">OpenBSD 3.4 and NetBSD 1.6 and 1.6.1 allow remote attackers to cause a denial of service (crash) by sending an IPv6 packet with a small MTU to a listening port and then issuing a TCP connect to that port.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/9577" source="BID" patch="1" adv="1">9577</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15044" source="XF" adv="1">openbsd-ipv6-dos(15044)</ref>
      <ref url="http://www.openbsd.org/cgi-bin/cvsweb/src/sys/netinet6/ip6_output.c" source="CONFIRM">http://www.openbsd.org/cgi-bin/cvsweb/src/sys/netinet6/ip6_output.c</ref>
      <ref url="http://www.guninski.com/obsdmtu.html" source="MISC">http://www.guninski.com/obsdmtu.html</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107604603226564&amp;w=2" source="BUGTRAQ" adv="1">20040205 OpenBSD IPv6 remote kernel crash</ref>
      <ref url="http://www.osvdb.org/3825" source="OSVDB">3825</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2004-February/016704.html" source="FULLDISC">20040204 Remote openbsd crash with ip6, yet still openbsd much better than windows</ref>
      <ref url="ftp://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2004-002.txt.asc" source="NETBSD">NetBSD-SA2004-002</ref>
    </refs>
    <vuln_soft>
      <prod vendor="netbsd" name="netbsd">
        <vers num="1.6" />
        <vers num="1.6.1" />
      </prod>
      <prod vendor="openbsd" name="openbsd">
        <vers num="3.0" />
        <vers num="3.1" />
        <vers num="3.2" />
        <vers num="3.3" />
        <vers num="3.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0258" published="2004-11-23" name="CVE-2004-0258" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:H/Au:N/C:C/I:C/A:C)" CVSS_score="7.6" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="4.9" CVSS_base_score="7.6">
    <desc>
      <descript source="cve">Multiple buffer overflows in RealOne Player, RealOne Player 2.0, RealOne Enterprise Desktop, and RealPlayer Enterprise allow remote attackers to execute arbitrary code via malformed (1) .RP, (2) .RT, (3) .RAM, (4) .RPM or (5) .SMIL files.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/473814" source="CERT-VN" adv="1">VU#473814</ref>
      <ref url="http://www.securityfocus.com/bid/9579" source="BID" patch="1" adv="1">9579</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107608748813559&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20040204 Multiple File Format Vulnerabilities (Overruns) in REALOne &amp; RealPlayer</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15040" source="XF" adv="1">realoneplayer-multiple-file-bo(15040)</ref>
      <ref url="http://www.service.real.com/help/faq/security/040123_player/EN/" source="CONFIRM">http://www.service.real.com/help/faq/security/040123_player/EN/</ref>
      <ref url="http://www.nextgenss.com/advisories/realone.txt" source="MISC">http://www.nextgenss.com/advisories/realone.txt</ref>
      <ref url="http://www.ciac.org/ciac/bulletins/o-075.shtml" source="CIAC">O-075</ref>
      <ref url="http://archives.neohapsis.com/archives/vulnwatch/2004-q1/0027.html" source="VULNWATCH">20040204 [VulnWatch] Multiple File Format Vulnerabilities (Overruns) in REALOne &amp; RealPlayer</ref>
    </refs>
    <vuln_soft>
      <prod vendor="realnetworks" name="realone_desktop_manager">
        <vers num="" />
      </prod>
      <prod vendor="realnetworks" name="realone_enterprise_desktop">
        <vers num="6.0.11.774" />
      </prod>
      <prod vendor="realnetworks" name="realone_player">
        <vers num="1.0" />
        <vers num="2.0" edition="" />
        <vers num="2.0" edition=":win" />
        <vers num="6.0.11.818" />
        <vers num="6.0.11.830" />
        <vers num="6.0.11.841" />
        <vers num="6.0.11.853" />
        <vers num="6.0.11.868" />
      </prod>
      <prod vendor="realnetworks" name="realplayer">
        <vers num="10.0_beta" />
        <vers num="8.0" edition="" />
        <vers num="8.0" edition=":win32" />
        <vers num="8.0" edition=":mac_os" />
        <vers num="8.0" edition=":unix" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0259" published="2004-11-23" name="CVE-2004-0259" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">The check_referer() function in Formmail.php 5.0 and earlier allows remote attackers to bypass access restrictions via an empty or spoofed HTTP Referer, as demonstrated using an application on the same web server that contains a cross-site scripting (XSS) issue.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" admin="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/15079" source="XF" adv="1">jack-formmail-file-upload(15079)</ref>
      <ref url="http://www.securityfocus.com/bid/9591" source="BID" adv="1">9591</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107619109629629&amp;w=2" source="BUGTRAQ" adv="1">20040206 formmail (PHP) Upload file using CSS</ref>
    </refs>
    <vuln_soft>
      <prod vendor="joe_lumbroso_acks" name="formmail.php">
        <vers num="2.0" />
        <vers num="5.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0260" published="2004-11-23" name="CVE-2004-0260" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The AddToMailingList function in CactuSoft CactuShop 5.0 Lite contains a backdoor that allows remote attackers to delete arbitrary files via an email address that starts with |||.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/15063" source="XF" adv="1">cactushoplite-backdoor(15063)</ref>
      <ref url="http://www.securityfocus.com/bid/9589" source="BID" adv="1">9589</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107619501815888&amp;w=2" source="BUGTRAQ" adv="1">20040206 CactuSoft CactuShop 5.0 Lite shopping cart software backdoor</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2004-February/016819.html" source="FULLDISC">20040206 CactuSoft CactuShop 5.0 Lite shopping cart software backdoor</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cactusoft" name="cactushop_lite">
        <vers num="5.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0261" published="2004-11-23" name="CVE-2004-0261" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">oj.cgi in OpenJournal 2.0 through 2.0.5 allows remote attackers to bypass authentication and access the control panel via a 0 in the uid parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" admin="1" />
    </loss_types>
    <vuln_types>
      <access />
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/9598" source="BID" patch="1" adv="1">9598</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15069" source="XF" adv="1">openjournal-uid-admin-access(15069)</ref>
      <ref url="http://www.grohol.com/downloads/oj/latest/changelog.txt" source="CONFIRM">http://www.grohol.com/downloads/oj/latest/changelog.txt</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107619136600713&amp;w=2" source="BUGTRAQ" adv="1">20040206 Open Journal Blog Authenticaion Bypassing Vulnerability</ref>
      <ref url="http://www.osvdb.org/3872" source="OSVDB">3872</ref>
    </refs>
    <vuln_soft>
      <prod vendor="openjournal" name="openjournal">
        <vers num="2.0" />
        <vers num="2.0_1" />
        <vers num="2.0_2" />
        <vers num="2.0_3" />
        <vers num="2.0_4" />
        <vers num="2.0_5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0262" published="2004-11-23" name="CVE-2004-0262" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Stack-based buffer overflow in The Palace 3.5 and earlier client allows remote attackers to execute arbitrary code via a link to a palace:// url followed by a long server address string.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/15074" source="XF" adv="1">palace-server-address-bo(15074)</ref>
      <ref url="http://www.securityfocus.com/bid/9602" source="BID" adv="1">9602</ref>
      <ref url="http://www.elitehaven.net/thepalace.txt" source="MISC">http://www.elitehaven.net/thepalace.txt</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107634556632195&amp;w=2" source="BUGTRAQ" adv="1">20040207 The Palace 3.x (Client) Stack Overflow Vulnerability</ref>
      <ref url="http://archives.neohapsis.com/archives/vulnwatch/2004-q1/0033.html" source="VULNWATCH">20040207 The Palace 3.x (Client) Stack Overflow Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="the_palace" name="the_palace_client">
        <vers num="3.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0263" published="2004-11-23" name="CVE-2004-0263" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">PHP 4.3.4 and earlier in Apache 1.x and 2.x (mod_php) can leak global variables between virtual hosts that are handled by the same Apache child process but have different settings, which could allow remote attackers to obtain sensitive information.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <access />
      <config />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/15072" source="XF" patch="1" adv="1">php-virtualhost-info-disclosure(15072)</ref>
      <ref url="http://www.securityfocus.com/bid/9599" source="BID" adv="1">9599</ref>
      <ref url="http://www.osvdb.org/3878" source="OSVDB">3878</ref>
      <ref url="http://http://security.gentoo.org/glsa/glsa-200402-01.xml" source="GENTOO">GLSA-200402-01</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apache" name="http_server">
        <vers num="1.0" />
        <vers num="1.0.2" />
        <vers num="1.0.3" />
        <vers num="1.0.5" />
        <vers num="1.1" />
        <vers num="1.1.1" />
        <vers num="1.2" />
        <vers num="1.2.5" />
        <vers num="1.3" />
        <vers num="1.3.1" />
        <vers num="1.3.11" />
        <vers num="1.3.12" />
        <vers num="1.3.14" />
        <vers num="1.3.17" />
        <vers num="1.3.18" />
        <vers num="1.3.19" />
        <vers num="1.3.20" />
        <vers num="1.3.22" />
        <vers num="1.3.23" />
        <vers num="1.3.24" />
        <vers num="1.3.25" />
        <vers num="1.3.26" />
        <vers num="1.3.27" />
        <vers num="1.3.28" />
        <vers num="1.3.29" />
        <vers num="1.3.3" />
        <vers num="1.3.4" />
        <vers num="1.3.6" />
        <vers num="1.3.7" edition="" />
        <vers num="1.3.7" edition=":dev" />
        <vers num="1.3.9" />
        <vers num="2.0" />
        <vers num="2.0.28" edition="beta" />
        <vers num="2.0.32" />
        <vers num="2.0.35" />
        <vers num="2.0.36" />
        <vers num="2.0.37" />
        <vers num="2.0.38" />
        <vers num="2.0.39" />
        <vers num="2.0.40" />
        <vers num="2.0.41" />
        <vers num="2.0.42" />
        <vers num="2.0.43" />
        <vers num="2.0.44" />
        <vers num="2.0.45" />
        <vers num="2.0.46" />
        <vers num="2.0.47" />
        <vers num="2.0.48" />
        <vers num="2.0.9" />
      </prod>
      <prod vendor="ibm" name="http_server">
        <vers num="1.3.19" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0264" published="2004-11-23" name="CVE-2004-0264" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">palmhttpd for PalmOS allows remote attackers to cause a denial of service (crash) by establishing two simultaneous HTTP connections, which exceeds the PalmOS accept queue.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input bound="1" />
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/9608" source="BID" patch="1" adv="1">9608</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107634638201570&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20040208 PalmOS httpd accept() queue overflow DoS vulnerability.</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15090" source="XF" adv="1">palmhttpd-accept-bo(15090)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="jim_rees" name="jim_rees_httpd">
        <vers num="palmos" />
      </prod>
      <prod vendor="shaun2k2" name="palmhttpd">
        <vers num="3.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0265" published="2004-11-23" name="CVE-2004-0265" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in modules.php for Php-Nuke 6.x-7.1.0 allows remote attackers to execute arbitrary script as other users via URL-encoded (1) title or (2) fname parameters in the News or Reviews modules.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/15076" source="XF">phpnuke-mulitple-xss(15076)</ref>
      <ref url="http://www.securityfocus.com/bid/9613" source="BID">9613</ref>
      <ref url="http://www.securityfocus.com/bid/9605" source="BID">9605</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107634727520936&amp;w=2" source="BUGTRAQ">20040208 [waraxe-2004-SA#002] - Cross-Site Scripting (XSS) in Php-Nuke 7.1.0</ref>
    </refs>
    <vuln_soft>
      <prod vendor="francisco_burzi" name="php-nuke">
        <vers num="6.0" />
        <vers num="6.5" />
        <vers num="6.5_beta1" />
        <vers num="6.5_final" />
        <vers num="6.5_rc1" />
        <vers num="6.5_rc2" />
        <vers num="6.5_rc3" />
        <vers num="6.6" />
        <vers num="6.7" />
        <vers num="6.9" />
        <vers num="7.0" />
        <vers num="7.0_final" />
        <vers num="7.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0266" published="2004-11-23" name="CVE-2004-0266" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">SQL injection vulnerability in the "public message" capability (public_message) for Php-Nuke 6.x to 7.1.0 allows remote attackers obtain the administrator password via the c_mid parameter.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/15080" source="XF" adv="1">phpnuke-publicmessage-sql-injection(15080)</ref>
      <ref url="http://www.securityfocus.com/bid/9615" source="BID" adv="1">9615</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107635110327066&amp;w=2" source="BUGTRAQ" adv="1">20040208 [waraxe-2004-SA#003] - SQL injection in Php-Nuke 7.1.0</ref>
    </refs>
    <vuln_soft>
      <prod vendor="francisco_burzi" name="php-nuke">
        <vers num="6.0" />
        <vers num="6.5" />
        <vers num="6.5_beta1" />
        <vers num="6.5_final" />
        <vers num="6.5_rc1" />
        <vers num="6.5_rc2" />
        <vers num="6.5_rc3" />
        <vers num="6.6" />
        <vers num="6.7" />
        <vers num="6.9" />
        <vers num="7.0" />
        <vers num="7.0_final" />
        <vers num="7.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2004-0267" published="2004-11-23" name="CVE-2004-0267" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">The (1) inoregupdate, (2) uniftest, or (3) unimove scripts in eTrust InoculateIT for Linux 6.0 allow local users to overwrite arbitrary files via a symlink attack on files in /tmp.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/15102" source="XF" adv="1">etrust-inoculateit-symlink(15102)</ref>
      <ref url="http://www.securityfocus.com/bid/9616" source="BID" adv="1">9616</ref>
      <ref url="http://www.osvdb.org/4856" source="OSVDB">4856</ref>
      <ref url="http://www.osvdb.org/4855" source="OSVDB">4855</ref>
      <ref url="http://www.osvdb.org/4735" source="OSVDB">4735</ref>
      <ref url="http://www.excluded.org/advisories/advisory10.txt" source="MISC">http://www.excluded.org/advisories/advisory10.txt</ref>
      <ref url="http://secunia.com/advisories/10833" source="SECUNIA">10833</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107635584431518&amp;w=2" source="BUGTRAQ" adv="1">20040209 [local problems] eTrust Virus Protection 6.0 InoculateIT for linux</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ca" name="inoculateit">
        <vers num="6.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0268" published="2004-11-23" name="CVE-2004-0268" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Multiple buffer overflows in EvolutionX 3921 and 3935 allow remote attackers to cause a denial of service (hang) via (1) a long cd command to the FTP server, or (2) a long dir command to the telnet server.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/15104" source="XF" adv="1">evolutionx-command-line-dos(15104)</ref>
      <ref url="http://www.securityfocus.com/bid/9631" source="BID" adv="1">9631</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2004-February/016988.html" source="FULLDISC">20040210 XBOX EvolutionX ftp 'cd' command and telnet 'dir' buffer overflow</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107643394724891&amp;w=2" source="BUGTRAQ">20040210 XBOX EvolutionX ftp 'cd' command and telnet 'dir' buffer overflow</ref>
    </refs>
    <vuln_soft>
      <prod vendor="evolutionx" name="evolutionx">
        <vers num="build_3921" />
        <vers num="build_3935" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0269" published="2004-11-23" name="CVE-2004-0269" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)" CVSS_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_base_score="6.4">
    <desc>
      <descript source="cve">SQL injection vulnerability in PHP-Nuke 6.9 and earlier, and possibly 7.x, allows remote attackers to inject arbitrary SQL code and gain sensitive information via (1) the category variable in the Search module or (2) the admin variable in the Web_Links module.</descript>
    </desc>
    <loss_types>
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/9630" source="BID" patch="1" adv="1">9630</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107643348117646&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20040210 [SCAN Associates Sdn Bhd Security Advisory] PHPNuke 6.9 > and below SQL Injection in multiple module</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15115" source="XF" adv="1">phpnuke-modules-sql-injection(15115)</ref>
      <ref url="http://www.scan-associates.net/papers/phpnuke69.txt" source="MISC">http://www.scan-associates.net/papers/phpnuke69.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="francisco_burzi" name="php-nuke">
        <vers num="1.0" />
        <vers num="2.5" />
        <vers num="3.0" />
        <vers num="4.0" />
        <vers num="4.3" />
        <vers num="4.4" />
        <vers num="4.4.1a" />
        <vers num="5.0" />
        <vers num="5.0.1" />
        <vers num="5.1" />
        <vers num="5.2" />
        <vers num="5.2a" />
        <vers num="5.3.1" />
        <vers num="5.4" />
        <vers num="5.5" />
        <vers num="5.6" />
        <vers num="6.0" />
        <vers num="6.5" />
        <vers num="6.5_beta1" />
        <vers num="6.5_final" />
        <vers num="6.5_rc1" />
        <vers num="6.5_rc2" />
        <vers num="6.5_rc3" />
        <vers num="6.6" />
        <vers num="6.7" />
        <vers num="6.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0270" published="2004-11-23" name="CVE-2004-0270" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">libclamav in Clam AntiVirus 0.65 allows remote attackers to cause a denial of service (crash) via a uuencoded e-mail message with an invalid line length (e.g., a lowercase character), which causes an assert error in clamd that terminates the calling program.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/9610" source="BID" patch="1" adv="1">9610</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107634700823822&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20040209 clamav 0.65 remote DOS exploit</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15077" source="XF" adv="1">clam-antivirus-uuencoded-dos(15077)</ref>
      <ref url="http://www.freebsd.org/cgi/query-pr.cgi?pr=62586" source="CONFIRM">http://www.freebsd.org/cgi/query-pr.cgi?pr=62586</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200402-07.xml" source="GENTOO" adv="1">GLSA-200402-07</ref>
      <ref url="http://www.osvdb.org/3894" source="OSVDB">3894</ref>
    </refs>
    <vuln_soft>
      <prod vendor="clam_anti-virus" name="clamav">
        <vers num="0.65" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0271" published="2004-11-23" name="CVE-2004-0271" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Multiple cross-site scripting vulnerabilities (XSS) in MaxWebPortal allow remote attackers to execute arbitrary web script as other users via (1) the sub_name parameter of dl_showall.asp, (2) the SendTo parameter in Personal Messages, (3) the HTTP_REFERER for down.asp, or (4) the image name of an Avatar in the register form.</descript>
    </desc>
    <sols>
      <sol source="nvd">This vulnerability is addressed in the following product release:
MaxWebPortal, MaxWebPortal, 1.32</sol>
    </sols>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/15122" source="XF" patch="1">maxwebportal-register-xss(15122)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15120" source="XF" patch="1">maxwebportal-multiple-xss(15120)</ref>
      <ref url="http://www.securityfocus.com/bid/9625" source="BID" patch="1">9625</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107643014606515&amp;w=2" source="BUGTRAQ" patch="1">20040210 XSS, Sql Injection and Avatar ScriptCode Injection in MaxWebPortal</ref>
    </refs>
    <vuln_soft>
      <prod vendor="maxwebportal" name="maxwebportal">
        <vers num="1.30" />
        <vers num="1.31" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0272" published="2004-11-23" name="CVE-2004-0272" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in MaxWebPortal allows remote attackers to inject arbitrary SQL code and gain sensitive information via the SendTo parameter in Personal Messages.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/15121" source="XF" adv="1">maxwebportal-personalmesssages-sql-injection(15121)</ref>
      <ref url="http://www.securityfocus.com/bid/9625" source="BID" adv="1">9625</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107643014606515&amp;w=2" source="BUGTRAQ" adv="1">20040210 XSS, Sql Injection and Avatar ScriptCode Injection in MaxWebPortal</ref>
    </refs>
    <vuln_soft>
      <prod vendor="maxwebportal" name="maxwebportal">
        <vers num="1.30" />
        <vers num="1.31" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0273" published="2004-11-23" name="CVE-2004-0273" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Directory traversal vulnerability in RealOne Player, RealOne Player 2.0, and RealOne Enterprise Desktop allows remote attackers to upload arbitrary files via an RMP file that contains .. (dot dot) sequences in a .rjs skin file.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/514734" source="CERT-VN">VU#514734</ref>
      <ref url="http://www.securityfocus.com/bid/9580" source="BID" patch="1" adv="1">9580</ref>
      <ref url="http://service.real.com/help/faq/security/040123_player/EN/" source="CONFIRM" patch="1" adv="1">http://service.real.com/help/faq/security/040123_player/EN/</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107642978524321&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20040210 Directory traversal in RealPlayer allows code execution</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15123" source="XF">realoneplayer-rmp-directory-traversal(15123)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="realnetworks" name="realone_desktop_manager">
        <vers num="" />
      </prod>
      <prod vendor="realnetworks" name="realone_enterprise_desktop">
        <vers num="6.0.11.774" />
      </prod>
      <prod vendor="realnetworks" name="realone_player">
        <vers num="1.0" />
        <vers num="2.0" edition="" />
        <vers num="2.0" edition=":win" />
        <vers num="6.0.11.818" />
        <vers num="6.0.11.830" />
        <vers num="6.0.11.841" />
        <vers num="6.0.11.853" />
        <vers num="6.0.11.868" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0274" published="2004-11-23" name="CVE-2004-0274" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Share.mod in Eggheads Eggdrop IRC bot 1.6.10 through 1.6.15 can mistakenly assign STAT_OFFERED status to a bot that is not a sharebot, which allows remote attackers to use STAT_OFFERED to promote a bot to a sharebot and conduct unauthorized activities.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107643315623958&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20040210 Re: Eggrop bug</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107634593827102&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20040208 Eggrop bug</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15084" source="XF" adv="1">eggdrop-sharemod-gain-access(15084)</ref>
      <ref url="http://www.securityfocus.com/bid/9606" source="BID" adv="1">9606</ref>
      <ref url="http://mogan.nonsoloirc.com/egg_advisory.txt" source="MISC">http://mogan.nonsoloirc.com/egg_advisory.txt</ref>
      <ref url="http://www.osvdb.org/3928" source="OSVDB">3928</ref>
      <ref url="http://www.eggheads.org/news/2004/04/10/26" source="CONFIRM">http://www.eggheads.org/news/2004/04/10/26</ref>
    </refs>
    <vuln_soft>
      <prod vendor="eggheads" name="eggdrop_irc_bot">
        <vers num="1.6.10" />
        <vers num="1.6.11" />
        <vers num="1.6.12" />
        <vers num="1.6.13" />
        <vers num="1.6.14" />
        <vers num="1.6.15" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0275" published="2004-11-23" name="CVE-2004-0275" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">SQL injection vulnerability in calendar_download.php in BosDates 3.2 and earlier allows remote attackers to obtain sensitive information and gain access via the calendar parameter.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/15133" source="XF" adv="1">bosdates-calendar-sql-injection(15133)</ref>
      <ref url="http://www.zone-h.org/en/advisories/read/id=3925/" source="MISC">http://www.zone-h.org/en/advisories/read/id=3925/</ref>
      <ref url="http://www.securityfocus.com/bid/9639" source="BID" adv="1">9639</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107651618613575&amp;w=2" source="BUGTRAQ" adv="1">20040211 ZH2004-05SA (security advisory): Sql Injection Vulnerability in BosDates</ref>
    </refs>
    <vuln_soft>
      <prod vendor="bosdev" name="bosdates">
        <vers num="3.0" />
        <vers num="3.1" />
        <vers num="3.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0276" published="2004-11-23" name="CVE-2004-0276" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The get_real_string function in Monkey HTTP Daemon (monkeyd) 0.8.1 and earlier allows remote attackers to cause a denial of service (crash) via an HTTP request with a sequence of "%" characters and a missing Host field.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/9642" source="BID" patch="1" adv="1">9642</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15187" source="XF" adv="1">monkey-getrealstring-dos(15187)</ref>
      <ref url="http://monkeyd.sourceforge.net/" source="CONFIRM">http://monkeyd.sourceforge.net/</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107652610506968&amp;w=2" source="BUGTRAQ" adv="1">20040211 Denial of Service in Monkey httpd &lt;= 0.8.1</ref>
      <ref url="http://aluigi.altervista.org/poc/monkeydos.zip" source="MISC">http://aluigi.altervista.org/poc/monkeydos.zip</ref>
      <ref url="http://www.osvdb.org/3921" source="OSVDB">3921</ref>
    </refs>
    <vuln_soft>
      <prod vendor="monkey" name="monkey_http_daemon">
        <vers num="0.1.4" />
        <vers num="0.4" />
        <vers num="0.4.1" />
        <vers num="0.4.2" />
        <vers num="0.5" />
        <vers num="0.5.1" />
        <vers num="0.6" />
        <vers num="0.6.1" />
        <vers num="0.6.2" />
        <vers num="0.6.3" />
        <vers num="0.7.0" />
        <vers num="0.7.1" />
        <vers num="0.7.2" />
        <vers num="0.8" />
        <vers num="0.8.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0277" published="2004-11-23" name="CVE-2004-0277" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Format string vulnerability in Dream FTP 1.02 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via format string specifiers in the username.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" admin="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/15070" source="XF" adv="1">dreamftp-username-format-string(15070)</ref>
      <ref url="http://www.securityfocus.com/bid/9600" source="BID" adv="1">9600</ref>
      <ref url="http://www.security-protocols.com/modules.php?name=News&amp;file=article&amp;sid=1722" source="MISC">http://www.security-protocols.com/modules.php?name=News&amp;file=article&amp;sid=1722</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107656166402882&amp;w=2" source="BUGTRAQ">20040211 Re: [Full-Disclosure] DreamFTP Server 1.02 Buffer Overflow</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2004-February/016871.html" source="FULLDISC">20040207 DreamFTP Server 1.02 Buffer Overflow</ref>
    </refs>
    <vuln_soft>
      <prod vendor="bolintech" name="dream_ftp_server">
        <vers num="1.02" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0278" published="2004-11-23" name="CVE-2004-0278" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Ratbag game engine, as used in products such as Dirt Track Racing, Leadfoot, and World of Outlaws Spring Cars, allows remote attackers to cause a denial of service (CPU consumption) via a TCP packet that specifies the length of data to read and then sends a second TCP packet that contains less data than specified, which causes Ratbag to repeatedly check the socket for more data.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/15188" source="XF" adv="1">ratbag-data-length-dos(15188)</ref>
      <ref url="http://www.securityfocus.com/bid/9644" source="BID" adv="1">9644</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107655269820530&amp;w=2" source="BUGTRAQ" adv="1">20040211 Denial of Service in Ratbag's game engine</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ratbag" name="dirt_track_racing">
        <vers num="1.0.3" />
        <vers num="2.0" />
      </prod>
      <prod vendor="ratbag" name="dirt_track_racing_australia">
        <vers num="" />
      </prod>
      <prod vendor="ratbag" name="dirt_track_racing_sprint_cars">
        <vers num="" />
      </prod>
      <prod vendor="ratbag" name="leadfoot">
        <vers num="" />
      </prod>
      <prod vendor="ratbag" name="world_of_outlaws_sprint_cars">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0279" published="2004-11-23" name="CVE-2004-0279" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">AIM Sniff (aimSniff.pl) 0.9b allows local users to overwrite arbitrary files via a symlink attack on /tmp/AS.log.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" admin="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/9653" source="BID" patch="1" adv="1">9653</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107662243303439&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20040212 aimSniff.pl file "deletion" (local)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15199" source="XF" adv="1">aim-sniff-symlink(15199)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="aim_sniff" name="aim_sniff">
        <vers num="0.6" />
        <vers num="0.7" />
        <vers num="0.8" />
        <vers num="0.9" />
        <vers num="0.9b" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0280" published="2004-11-23" name="CVE-2004-0280" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Caucho Technology Resin 2.1.12 allows remote attackers to view JSP source via an HTTP request to a .jsp file that ends in a "%20" (encoded space character), e.g. index.jsp%20.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/15085" source="XF" adv="1">resin-source-disclosure(15085)</ref>
      <ref url="http://www.securityfocus.com/bid/9614" source="BID" adv="1">9614</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107635084830547&amp;w=2" source="BUGTRAQ">20040205 Apache Http Server Reveals Script Source Code to Remote Users And Any Users Can Access Resin Forbidden Directory ("/WEB-INF/")</ref>
    </refs>
    <vuln_soft>
      <prod vendor="caucho_technology" name="resin">
        <vers num="2.1.12" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0281" published="2004-11-23" name="CVE-2004-0281" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Caucho Technology Resin 2.1.12 allows remote attackers to gain sensitive information and view the contents of the /WEB-INF/ directory via an HTTP request for "WEB-INF..", which is equivalent to "WEB-INF" in Windows.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/15087" source="XF" adv="1">resin-dotdot-directory-traversal(15087)</ref>
      <ref url="http://www.securityfocus.com/bid/9617" source="BID" adv="1">9617</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107635084830547&amp;w=2" source="BUGTRAQ">20040205 Apache Http Server Reveals Script Source Code to Remote Users And Any Users Can Access Resin Forbidden Directory ("/WEB-INF/")</ref>
    </refs>
    <vuln_soft>
      <prod vendor="caucho_technology" name="resin">
        <vers num="2.1.12" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0282" published="2004-11-23" name="CVE-2004-0282" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Crob FTP daemon 3.5.2 allows remote attackers to cause a denial of service (crash) by repeatedly connecting to and disconnecting from the server.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/15201" source="XF" adv="1">crob-multiple-connections-dos(15201)</ref>
      <ref url="http://www.securityfocus.com/bid/9651" source="BID" adv="1">9651</ref>
      <ref url="http://www.osvdb.org/6621" source="OSVDB">6621</ref>
      <ref url="http://secunia.com/advisories/10882" source="SECUNIA">10882</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107665920909374&amp;w=2" source="BUGTRAQ" adv="1">20040212 crob ftpd Denial of Service</ref>
    </refs>
    <vuln_soft>
      <prod vendor="crob" name="crob_ftp_server">
        <vers num="3.5.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2004-0283" published="2004-11-23" name="CVE-2004-0283" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">Mailmgr 1.2.3 allows local users to overwrite arbitrary files via a symlink attack on (1) /tmp/mailmgr.unsort, (2) /tmp/mailmgr.tmp, or (3) /tmp/mailmgr.sort.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <config />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/15203" source="XF" adv="1">mailmgr-insecure-temp-directory (15203)</ref>
      <ref url="http://www.securityfocus.com/bid/9654" source="BID" adv="1">9654</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107665013714517&amp;w=2" source="BUGTRAQ" adv="1">20040212 Symlink vulnerabilities in mailmgr</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mailmgr" name="mailmgr">
        <vers num="1.2.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0284" published="2004-11-23" name="CVE-2004-0284" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Microsoft Internet Explorer 6.0, Outlook 2002, and Outlook 2003 allow remote attackers to cause a denial of service (CPU consumption), if "Do not save encrypted pages to disk" is disabled, via a web site or HTML e-mail that contains two null characters (%00) after the host name.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <design />
      <exception />
      <config />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/9629" source="BID" patch="1" adv="1">9629</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107643134712133&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20040210 ASPR #2004-01-20-1: Internet Explorer/Outlook double null character DoS</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15127" source="XF" adv="1">ie-host-null-dos(15127)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="ie">
        <vers num="6.0" edition="sp1" />
      </prod>
      <prod vendor="microsoft" name="outlook">
        <vers num="2002" edition="sp1" />
        <vers num="2002" edition="sp2" />
        <vers num="2003" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0285" published="2004-11-23" name="CVE-2004-0285" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">PHP remote file inclusion vulnerabilities in include/footer.inc.php in (1) AllMyVisitors, (2) AllMyLinks, and (3) AllMyGuests allow remote attackers to execute arbitrary PHP code via a URL in the _AMVconfig[cfg_serverpath] parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/9664" source="BID" patch="1" adv="1">9664</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15228" source="XF">allmyvisitors-file-include(15228)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15227" source="XF" adv="1">allmyguests-php-file-include(15227)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15226" source="XF" adv="1">allmylinks-file-include(15226)</ref>
      <ref url="http://www.osvdb.org/6721" source="OSVDB">6721</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107696291728750&amp;w=2" source="BUGTRAQ" adv="1">20040214 AllMyLinks PHP Code Injection vulnerability</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107696235424865&amp;w=2" source="BUGTRAQ">20040214 AllMyVisitors PHP Code Injection vulnerability</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107696209514155&amp;w=2" source="BUGTRAQ">20040214 AllMyGuests PHP Code Injection vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="voice_of_web" name="allmyguests">
        <vers num="0.1.2" />
        <vers num="0.3" />
        <vers num="0.4" />
        <vers num="0.4.1" />
      </prod>
      <prod vendor="voice_of_web" name="allmylinks">
        <vers num="0.3" />
        <vers num="0.4" />
        <vers num="0.4.1" />
        <vers num="0.4.3" />
        <vers num="0.4.4" />
        <vers num="0.4.9" />
        <vers num="0.5" />
      </prod>
      <prod vendor="voice_of_web" name="allmyvisitors">
        <vers num="0.3" />
        <vers num="0.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0286" published="2004-11-23" name="CVE-2004-0286" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Buffer overflow in RobotFTP 1.0 and 2.0 beta 1 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long username.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/15225" source="XF" adv="1">robot-username-bo(15225)</ref>
      <ref url="http://www.securityfocus.com/bid/9672" source="BID" adv="1">9672</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107696194306878&amp;w=2" source="BUGTRAQ" adv="1">20040215 buffer overflow in Robot FTP Server</ref>
    </refs>
    <vuln_soft>
      <prod vendor="robotftp" name="robotftp_server">
        <vers num="1.0" />
        <vers num="2.0_beta_1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0287" published="2004-11-23" name="CVE-2004-0287" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Xlight FTP server 1.52 allows remote authenticated users to cause a denial of service (crash) via a RETR command with a long argument containing a large number of / (slash) characters, possibly triggering a buffer overflow.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/15220" source="XF" adv="1">xlight-retr-dos(15220)</ref>
      <ref url="http://www.securityfocus.com/bid/9668" source="BID">9668</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107695172917263&amp;w=2" source="BUGTRAQ" adv="1">20040215 Xlight ftp server 1.52 RETR bug</ref>
    </refs>
    <vuln_soft>
      <prod vendor="xlight_ftp_server" name="xlight_ftp_server">
        <vers num="1.52" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0288" published="2004-11-23" name="CVE-2004-0288" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Buffer overflow in the UdmDocToTextBuf function in mnoGoSearch 3.2.13 through 3.2.15 could allow remote attackers to execute arbitrary code by indexing a large document.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/9667" source="BID" patch="1" adv="1">9667</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107695139930726&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20040215 Buffer overflow in mnoGoSearch</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15209" source="XF" adv="1">mnogosearch-udmdoctotextbuf-bo(15209)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mnogosearch" name="mnogosearch">
        <vers num="3.1.19" />
        <vers num="3.1.20" />
        <vers num="3.2.10" />
        <vers num="3.2.13" />
        <vers num="3.2.14" />
        <vers num="3.2.15" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2004-0289" published="2004-11-23" name="CVE-2004-0289" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">Buffer overflow in sdbscan in SignatureDB 0.1.1 allows local users to cause a denial of service (segmentation fault) via a database file that contains a large key parameter.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/15217" source="XF" adv="1">signaturedb-sdbscan-bo(15217)</ref>
      <ref url="http://www.securityfocus.com/bid/9661" source="BID" adv="1">9661</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107695113832648&amp;w=2" source="BUGTRAQ" adv="1">20040215 problems with database files in 'SignatureDB'</ref>
    </refs>
    <vuln_soft>
      <prod vendor="paul_l_daniels" name="signaturedb">
        <vers num="0.1.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0290" published="2004-11-23" name="CVE-2004-0290" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Buffer overflow in Purge Jihad 2.0.1 and earlier allows remote game servers to execute arbitrary code via an information packet that contains large (1) battle type and (2) map name fields.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/15216" source="XF" adv="1">purge-battletype-map-bo(15216)</ref>
      <ref url="http://www.securityfocus.com/bid/9671" source="BID" adv="1">9671</ref>
      <ref url="http://purge.worthplaying.com/phpbb/viewtopic.php?t=1167" source="CONFIRM">http://purge.worthplaying.com/phpbb/viewtopic.php?t=1167</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107695064204362&amp;w=2" source="BUGTRAQ" adv="1">20040216 Broadcast client buffer-overflow in Purge Jihad &lt;= 2.0.1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="freeform_interactive" name="purge">
        <vers num="1.4.7" />
      </prod>
      <prod vendor="freeform_interactive" name="purge_jihad">
        <vers num="2.0.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0291" published="2004-11-23" name="CVE-2004-0291" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">SQL injection vulnerability in post.php for YaBB SE 1.5.4 and 1.5.5 allows remote attackers to obtain hashed passwords via the quote parameter.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/9674" source="BID" patch="1" adv="1">9674</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15224" source="XF" adv="1">yabb-post-sql-injection(15224)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107696318522985&amp;w=2" source="BUGTRAQ">20040216 Another YabbSE SQL Injection</ref>
    </refs>
    <vuln_soft>
      <prod vendor="yabb" name="yabb">
        <vers num="1.5.4" edition="" />
        <vers num="1.5.4" edition=":second_edition" />
        <vers num="1.5.5" edition="" />
        <vers num="1.5.5" edition=":second_edition" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0292" published="2004-11-23" name="CVE-2004-0292" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Buffer overflow in KarjaSoft Sami HTTP Server 1.0.4 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long HTTP GET request.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/15237" source="XF" adv="1">sami-http-get-bo(15237)</ref>
      <ref url="http://www.securityfocus.com/bid/9679" source="BID" adv="1">9679</ref>
      <ref url="http://www.security-protocols.com/modules.php?name=News&amp;file=article&amp;sid=1746" source="MISC">http://www.security-protocols.com/modules.php?name=News&amp;file=article&amp;sid=1746</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107703630913205&amp;w=2" source="BUGTRAQ" adv="1">20040217 KarjaSoft Sami HTTP Server 1.0.4 Buffer Overflow</ref>
    </refs>
    <vuln_soft>
      <prod vendor="karjasoft" name="sami_http_server">
        <vers num="1.0.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0293" published="2004-11-23" name="CVE-2004-0293" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in ShopCartCGI 2.3 allows remote attackers to retrieve arbitrary files via a .. (dot dot) in a HTTP request to (1) gotopage.cgi or (2) genindexpage.cgi.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/14982" source="XF" adv="1">shopcartcgi-dotdot-directory-traversal(14982)</ref>
      <ref url="http://www.zone-h.org/en/advisories/read/id=3962/" source="MISC">http://www.zone-h.org/en/advisories/read/id=3962/</ref>
      <ref url="http://www.securityfocus.com/bid/9670" source="BID" adv="1">9670</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107703602707450&amp;w=2" source="BUGTRAQ" adv="1">20040217 ZH2004-06SA (security advisory): ShopCartCGI v2.3 Remote</ref>
    </refs>
    <vuln_soft>
      <prod vendor="shopcartcgi" name="shopcartcgi">
        <vers num="2.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0294" published="2004-11-23" name="CVE-2004-0294" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">YaBB 1 SP 1.3.1 displays different error messages when a user exists or not, which makes it easier for remote attackers to identify valid users and conduct a brute force password guessing attack.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/15236" source="XF" adv="1">yabb-invalidmessage-obtain-information(15236)</ref>
      <ref url="http://www.securityfocus.com/bid/9677" source="BID" adv="1">9677</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107703591314745&amp;w=2" source="BUGTRAQ">20040217 YABB information leakage on failed login</ref>
    </refs>
    <vuln_soft>
      <prod vendor="yabb" name="yabb">
        <vers num="1_gold_-_sp_1.3.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0295" published="2004-11-23" name="CVE-2004-0295" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">TsFtpSrv.exe in Broker FTP 6.1.0.0 allows remote attackers to cause a denial of service (CPU consumption) via an open idle connection.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/15242" source="XF" adv="1">broker-ftp-tsftpsrv-dos(15242)</ref>
      <ref url="http://www.securityfocus.com/bid/9680" source="BID" adv="1">9680</ref>
      <ref url="http://www.securiteam.com/windowsntfocus/5IP0B0AC1I.html" source="MISC">http://www.securiteam.com/windowsntfocus/5IP0B0AC1I.html</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107705346817241&amp;w=2" source="BUGTRAQ" adv="1">20040217 Broker FTP DoS (Message Server)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="transsoft" name="broker_ftp_server">
        <vers num="6.1_.0.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0296" published="2004-11-23" name="CVE-2004-0296" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">TsFtpSrv.exe in Broker FTP 6.1.0.0 allows remote attackers to cause a TsFtpSrv.exe to exit with an exception by opening and immediately closing a connection.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/15241" source="XF" adv="1">broker-ftp-dos(15241)</ref>
      <ref url="http://www.securityfocus.com/bid/9680" source="BID" adv="1">9680</ref>
      <ref url="http://www.securiteam.com/windowsntfocus/5IP0B0AC1I.html" source="MISC">http://www.securiteam.com/windowsntfocus/5IP0B0AC1I.html</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107705346817241&amp;w=2" source="BUGTRAQ" adv="1">20040217 Broker FTP DoS (Message Server)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="transsoft" name="broker_ftp_server">
        <vers num="6.1_.0.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0297" published="2004-11-23" name="CVE-2004-0297" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Buffer overflow in the Lightweight Directory Access Protocol (LDAP) daemon (iLDAP.exe 3.9.15.10) in Ipswitch IMail Server 8.03 allows remote attackers to cause a denial of service (crash) and execute arbitrary code via an LDAP message with a large tag length.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/972334" source="CERT-VN" adv="1">VU#972334</ref>
      <ref url="http://www.securityfocus.com/bid/9682" source="BID" patch="1" adv="1">9682</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15243" source="XF" adv="1">imail-ldap-tag-bo(15243)</ref>
      <ref url="http://www.ipswitch.com/support/imail/releases/imail_professional/im805HF2.html" source="CONFIRM">http://www.ipswitch.com/support/imail/releases/imail_professional/im805HF2.html</ref>
      <ref url="http://www.osvdb.org/3984" source="OSVDB">3984</ref>
      <ref url="http://www.idefense.com/application/poi/display?id=74" source="IDEFENSE">20040217 Ipswitch IMail LDAP Daemon Remote Buffer Overflow</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ipswitch" name="imail">
        <vers num="8.0.3" />
        <vers num="8.0.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0298" published="2004-11-23" name="CVE-2004-0298" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">CesarFTP 0.99e allows remote attackers to cause a denial of service (CPU consumption) via a long RETR parameter.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/15252" source="XF" adv="1">cesarftp-userpass-dos(15252)</ref>
      <ref url="http://www.securityfocus.com/bid/9666" source="BID" adv="1">9666</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107712057628250&amp;w=2" source="BUGTRAQ" adv="1">20040217 CesarFTP 0.99 : 100% employment of computer resources</ref>
    </refs>
    <vuln_soft>
      <prod vendor="aclogic" name="cesarftp">
        <vers num="0.99e" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2004-0299" published="2004-11-23" name="CVE-2004-0299" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">Buffer overflow in smallftpd 0.99 allows local users to cause a denial of service (crash) via an FTP request with a large number of "/" (slash) characters.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
      <exception />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/15262" source="XF" adv="1">smallftpd-forwardslash-dos(15262)</ref>
      <ref url="http://www.securityfocus.com/bid/9684" source="BID" adv="1">9684</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107714207708375&amp;w=2" source="BUGTRAQ" adv="1">20040217 Smallftpd 1.0.3 DoS</ref>
    </refs>
    <vuln_soft>
      <prod vendor="smallftpd" name="smallftpd">
        <vers num="1.0.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0300" published="2004-11-23" name="CVE-2004-0300" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">SQL injection vulnerability in Online Store Kit 3.0 allows remote attackers to inject arbitrary SQL and gain unauthorized access via (1) the cat parameter in shop.php, (2) the id parameter in more.php, (3) the cat_manufacturer parameter in shop_by_brand.php, or (4) the id parameter in listing.php.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" admin="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/15232" source="XF" adv="1">onlinestorekit-more-sql-injection(15232)</ref>
      <ref url="http://www.zone-h.org/en/advisories/read/id=3972/" source="MISC">http://www.zone-h.org/en/advisories/read/id=3972/</ref>
      <ref url="http://www.systemsecure.org/advisories/ssadvisory16022004.php" source="MISC">http://www.systemsecure.org/advisories/ssadvisory16022004.php</ref>
      <ref url="http://www.securityfocus.com/bid/9687" source="BID" adv="1">9687</ref>
      <ref url="http://www.securityfocus.com/bid/9676" source="BID" adv="1">9676</ref>
      <ref url="http://secunia.com/advisories/10902/" source="SECUNIA">10902</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107712117913185&amp;w=2" source="BUGTRAQ" adv="1">20040218 ZH2004-07SA (security advisory): Multiple Sql injection</ref>
      <ref url="http://www.osvdb.org/3973" source="OSVDB">3973</ref>
      <ref url="http://securitytracker.com/alerts/2004/Feb/1009092.html" source="SECTRACK">1009092</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ecommerce_corporation_online" name="store_kit">
        <vers num="3.0_lite" />
        <vers num="3.0_pro" />
        <vers num="3.0_standard" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0301" published="2004-11-23" name="CVE-2004-0301" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in more.php for Online Store Kit 3.0 allows remote attackers to inject arbitrary HTML via the id parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/15235" source="XF">onlinestorekit-more-xss(15235)</ref>
      <ref url="http://www.systemsecure.org/advisories/ssadvisory16022004.php" source="MISC">http://www.systemsecure.org/advisories/ssadvisory16022004.php</ref>
      <ref url="http://www.securityfocus.com/bid/9676" source="BID">9676</ref>
      <ref url="http://securitytracker.com/alerts/2004/Feb/1009079.html" source="SECTRACK">1009079</ref>
      <ref url="http://secunia.com/advisories/10902/" source="SECUNIA" adv="1">10902</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ecommerce_corporation_online" name="store_kit">
        <vers num="3.0_lite" />
        <vers num="3.0_pro" />
        <vers num="3.0_standard" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0302" published="2004-11-23" name="CVE-2004-0302" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in OWLS 1.0 allows remote attackers to read arbitrary files via a .. (dot dot) in the (1) file parameter in index.php, (2) editfile in glossary.php, or (3) editfile in newmultiplechoice.php.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/15249" source="XF" adv="1">owls-file-retrieval(15249)</ref>
      <ref url="http://www.zone-h.org/en/advisories/read/id=3973/" source="MISC">http://www.zone-h.org/en/advisories/read/id=3973/</ref>
      <ref url="http://www.securityfocus.com/bid/9689" source="BID" adv="1">9689</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107712123305706&amp;w=2" source="BUGTRAQ" adv="1">20040218 ZH2004-08SA (security advisory): OWLS 1.0 Remote arbitrary files</ref>
    </refs>
    <vuln_soft>
      <prod vendor="fools_workshop" name="owls_workshop">
        <vers num="1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0303" published="2004-11-23" name="CVE-2004-0303" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">OWLS 1.0 allows remote attackers to retrieve arbitrary files via absolute pathnames in (1) the file parameter in /glossaries/index.php, (2) the filename parameter in /readings/index.php, or (3) the filename parameter in /multiplechoice/resultsignore.php, as demonstrated using /etc/passwd.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/15249" source="XF" adv="1">owls-file-retrieval(15249)</ref>
      <ref url="http://www.zone-h.org/en/advisories/read/id=3973/" source="MISC">http://www.zone-h.org/en/advisories/read/id=3973/</ref>
      <ref url="http://www.securityfocus.com/bid/9689" source="BID" adv="1">9689</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107712123305706&amp;w=2" source="BUGTRAQ" adv="1">20040218 ZH2004-08SA (security advisory): OWLS 1.0 Remote arbitrary files</ref>
    </refs>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0304" published="2004-11-23" name="CVE-2004-0304" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">SQL injection vulnerability in browse_items.asp in WebCortex WebStores 2000 6.0 allows remote attackers to gain unauthorized access and execute arbitrary commands via the Search_Text parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" admin="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/15253" source="XF" adv="1">webstores-browseitems-sql-injection(15253)</ref>
      <ref url="http://www.securityfocus.com/bid/7766" source="BID" adv="1">7766</ref>
      <ref url="http://www.s-quadra.com/advisories/Adv-20040218.txt" source="MISC">http://www.s-quadra.com/advisories/Adv-20040218.txt</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107712159425226&amp;w=2" source="BUGTRAQ" adv="1">20040218 WebCortex Webstores2000 version 6.0 multiple security vulnerabilities</ref>
    </refs>
    <vuln_soft>
      <prod vendor="webcortex" name="webstores_2000">
        <vers num="6.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0305" published="2004-11-23" name="CVE-2004-0305" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in error.asp in WebCortex WebStores 2000 6.0 allows remote attackers to execute arbitrary script as other users and steal session IDs via the Message_id parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/15254" source="XF">webstores-error-xss(15254)</ref>
      <ref url="http://www.securityfocus.com/bid/9693" source="BID">9693</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107712159425226&amp;w=2" source="BUGTRAQ">20040218 WebCortex Webstores2000 version 6.0 multiple security vulnerabilities</ref>
    </refs>
    <vuln_soft>
      <prod vendor="webcortex" name="webstores_2000">
        <vers num="6.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0306" published="2004-11-23" name="CVE-2004-0306" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Cisco ONS 15327 before 4.1(3), ONS 15454 before 4.6(1), ONS 15454 SD before 4.1(3), and Cisco ONS 15600 before 1.3(0) enable TFTP service on UDP port 69 by default, which allows remote attackers to GET or PUT ONS system files on the current active TCC in the /flash0 or /flash1 directories.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/9699" source="BID" patch="1" adv="1">9699</ref>
      <ref url="http://www.cisco.com/warp/public/707/cisco-sa-20040219-ONS.shtml" source="CISCO" patch="1" adv="1">20040219 Cisco ONS 15327, ONS 15454, ONS 15454 SDH, and ONS 15600 Vulnerabilities</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15264" source="XF" adv="1">cisco-ons-file-upload(15264)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="ons_15327">
        <vers num="4.0" />
        <vers num="4.0(1)" />
        <vers num="4.0(2)" />
        <vers num="4.1(0)" />
        <vers num="4.1(1)" />
        <vers num="4.1(2)" />
      </prod>
      <prod vendor="cisco" name="ons_15454_optical_transport_platform">
        <vers num="4.0" />
        <vers num="4.0(1)" />
        <vers num="4.1" />
        <vers num="4.1(0)" />
        <vers num="4.1(1)" />
        <vers num="4.1(2)" />
        <vers num="4.1(3)" />
      </prod>
      <prod vendor="cisco" name="ons_15454sdh">
        <vers num="4.0" />
        <vers num="4.1(0)" />
        <vers num="4.1(1)" />
        <vers num="4.1(2)" />
        <vers num="4.5" />
      </prod>
      <prod vendor="cisco" name="ons_15600">
        <vers num="1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0307" published="2004-11-23" name="CVE-2004-0307" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Cisco ONS 15327 before 4.1(3), ONS 15454 before 4.6(1), and ONS 15454 SD before 4.1(3) allows remote attackers to cause a denial of service (reset) by not sending the ACK portion of the TCP three-way handshake and sending an invalid response instead.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/9699" source="BID" patch="1" adv="1">9699</ref>
      <ref url="http://www.cisco.com/warp/public/707/cisco-sa-20040219-ONS.shtml" source="CISCO" patch="1" adv="1">20040219 Cisco ONS 15327, ONS 15454, ONS 15454 SDH, and ONS 15600 Vulnerabilities</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15265" source="XF" adv="1">cisco-ons-ack-dos(15265)</ref>
      <ref url="http://www.osvdb.org/4009" source="OSVDB">4009</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="ons_15327">
        <vers num="4.0" />
        <vers num="4.0(1)" />
        <vers num="4.0(2)" />
        <vers num="4.1(0)" />
        <vers num="4.1(1)" />
        <vers num="4.1(2)" />
      </prod>
      <prod vendor="cisco" name="ons_15454_optical_transport_platform">
        <vers num="4.0" />
        <vers num="4.0(1)" />
        <vers num="4.1" />
        <vers num="4.1(0)" />
        <vers num="4.1(1)" />
        <vers num="4.1(2)" />
        <vers num="4.1(3)" />
      </prod>
      <prod vendor="cisco" name="ons_15454sdh">
        <vers num="4.0" />
        <vers num="4.1(0)" />
        <vers num="4.1(1)" />
        <vers num="4.1(2)" />
        <vers num="4.5" />
      </prod>
      <prod vendor="cisco" name="ons_15600">
        <vers num="1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0308" published="2004-11-24" name="CVE-2004-0308" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Unknown vulnerability in Cisco ONS 15327 before 4.1(3), ONS 15454 before 4.6(1), ONS 15454 SD before 4.1(3), and Cisco ONS15600 before 1.3(0) allows a superuser whose account is locked out, disabled, or suspended to gain unauthorized access via a Telnet connection to the VxWorks shell.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <other />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/9699" source="BID" patch="1" adv="1">9699</ref>
      <ref url="http://www.cisco.com/warp/public/707/cisco-sa-20040219-ONS.shtml" source="CISCO" patch="1" adv="1">20040219 Cisco ONS 15327, ONS 15454, ONS 15454 SDH, and ONS 15600 Vulnerabilities</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15266" source="XF" adv="1">cisco-ons-gain-access(15266)</ref>
      <ref url="http://www.osvdb.org/4010" source="OSVDB">4010</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="ons_15327">
        <vers num="4.0" />
        <vers num="4.0(1)" />
        <vers num="4.0(2)" />
        <vers num="4.1(0)" />
        <vers num="4.1(1)" />
        <vers num="4.1(2)" />
      </prod>
      <prod vendor="cisco" name="ons_15454_optical_transport_platform">
        <vers num="4.0" />
        <vers num="4.0(1)" />
        <vers num="4.1" />
        <vers num="4.1(0)" />
        <vers num="4.1(1)" />
        <vers num="4.1(2)" />
        <vers num="4.1(3)" />
      </prod>
      <prod vendor="cisco" name="ons_15454sdh">
        <vers num="4.0" />
        <vers num="4.1(0)" />
        <vers num="4.1(1)" />
        <vers num="4.1(2)" />
        <vers num="4.5" />
      </prod>
      <prod vendor="cisco" name="ons_15600">
        <vers num="1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0309" published="2004-11-23" name="CVE-2004-0309" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Stack-based buffer overflow in the SMTP service support in vsmon.exe in Zone Labs ZoneAlarm before 4.5.538.001, ZoneLabs Integrity client 4.0 before 4.0.146.046, and 4.5 before 4.5.085, allows remote attackers to execute arbitrary code via a long RCPT TO argument.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/619982" source="CERT-VN" adv="1">VU#619982</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107722656827427&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20040219 EEYE: ZoneLabs SMTP Processing Buffer Overflow</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/14991" source="XF" adv="1">zonelabs-multiple-products-bo(14991)</ref>
      <ref url="http://www.securityfocus.com/bid/9696" source="BID" adv="1">9696</ref>
      <ref url="http://download.zonelabs.com/bin/free/securityAlert/8.html" source="CONFIRM">http://download.zonelabs.com/bin/free/securityAlert/8.html</ref>
      <ref url="http://www.osvdb.org/3991" source="OSVDB">3991</ref>
      <ref url="http://www.ciac.org/ciac/bulletins/o-084.shtml" source="CIAC">O-084</ref>
    </refs>
    <vuln_soft>
      <prod vendor="zonelabs" name="integrity">
        <vers num="4.0" />
      </prod>
      <prod vendor="zonelabs" name="zonealarm">
        <vers num="4.0" edition="" />
        <vers num="4.0" edition=":pro" />
        <vers num="4.0" edition=":plus" />
        <vers num="4.5" edition="" />
        <vers num="4.5" edition=":pro" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0310" published="2004-11-23" name="CVE-2004-0310" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in LiveJournal 1.0 and 1.1 allows remote attackers to execute Javascript as other users via the stylesheet, which does not strip the semicolon or parentheses, as demonstrated using a background:url.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/15268" source="XF">livejournal-url-xss(15268)</ref>
      <ref url="http://www.securityfocus.com/bid/9700" source="BID">9700</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107722627800820&amp;w=2" source="BUGTRAQ">20040219 LiveJournal XSS</ref>
    </refs>
    <vuln_soft>
      <prod vendor="livejournal" name="livejournal">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0311" published="2004-11-23" name="CVE-2004-0311" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">American Power Conversion (APC) Web/SNMP Management SmartSlot Card 3.0 through 3.0.3 and 3.21 are shipped with a default password of TENmanUFactOryPOWER, which allows remote attackers to gain unauthorized access.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" admin="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/9681" source="BID" patch="1" adv="1">9681</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15238" source="XF" adv="1">apc-smartslot-default-password(15238)</ref>
      <ref url="http://nam-en.apc.com/cgi-bin/nam_en.cfg/php/enduser/std_adp.php?p_faqid=3131&amp;p_created=1077139129" source="CONFIRM">http://nam-en.apc.com/cgi-bin/nam_en.cfg/php/enduser/std_adp.php?p_faqid=3131&amp;p_created=1077139129</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107721020803565&amp;w=2" source="BUGTRAQ">20040219 Re: Fw: APC 9606 SmartSlot Web/SNMP management card "backdoor"</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107703696631367&amp;w=2" source="BUGTRAQ">20040216 APC 9606 SmartSlot Web/SNMP management card "backdoor"</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apc" name="ap9606">
        <vers num="3.0" />
        <vers num="3.0.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0312" published="2004-11-23" name="CVE-2004-0312" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)" CVSS_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_base_score="6.4">
    <desc>
      <descript source="cve">Linksys WAP55AG 1.07 allows remote attackers with access to an SNMP read only community string to gain access to read/write communtiy strings via a query for OID 1.3.6.1.4.1.3955.2.1.13.1.2.</descript>
    </desc>
    <loss_types>
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <config />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/15257" source="XF" adv="1">linksys-snmp-strings-disclosure(15257)</ref>
      <ref url="http://www.securityfocus.com/bid/9688" source="BID" adv="1">9688</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107730681012131&amp;w=2" source="BUGTRAQ" adv="1">20040219 Re: SNMP community string disclosure in Linksys WAP55AG</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107712101324233&amp;w=2" source="BUGTRAQ">20040217 SNMP community string disclosure in Linksys WAP55AG</ref>
    </refs>
    <vuln_soft>
      <prod vendor="linksys" name="wap55ag">
        <vers num="1.0.7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0313" published="2004-11-23" name="CVE-2004-0313" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Buffer overflow in PSOProxy 0.91 allows remote attackers to cause a denial of service and possibly execute arbitrary code via a long HTTP request, as demonstrated using a long (1) GET argument or (2) method name.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/15275" source="XF" adv="1">psoproxy-long-get-bo(15275)</ref>
      <ref url="http://www.securityfocus.com/bid/9706" source="BID" adv="1">9706</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107730731900261&amp;w=2" source="BUGTRAQ" adv="1">20040220 Remote Buffer Overflow in PSOProxy 0.91</ref>
    </refs>
    <vuln_soft>
      <prod vendor="psoproxy" name="psoproxy_server">
        <vers num="0.91" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0314" published="2004-11-23" name="CVE-2004-0314" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in done.jsp in WebzEdit 1.9 and earlier allows remote attackers to execute arbitrary script as other users via the message parameter.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/15289" source="XF" adv="1">webzedit-done-xss(15289)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107757029514146&amp;w=2" source="BUGTRAQ">20040221 Cross Site Scripting in WebzEdit</ref>
    </refs>
    <vuln_soft>
      <prod vendor="freewebs" name="webzedit">
        <vers prev="1" num="1.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0315" published="2004-11-23" name="CVE-2004-0315" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Buffer overflow in Avirt Voice 4.0 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long GET request on port 1080.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/15288" source="XF">avirt-voice-get-bo(15288)</ref>
      <ref url="http://www.securityfocus.com/bid/9721" source="BID" adv="1">9721</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107756584609841&amp;w=2" source="BUGTRAQ" adv="1">20040223 Remote Buffer Overflow in Avirt Voice 4.0</ref>
    </refs>
    <vuln_soft>
      <prod vendor="avirt" name="voice">
        <vers num="4.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0316" published="2004-11-23" name="CVE-2004-0316" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Buffer overflow in Avirt Soho 4.3 allows remote attackers to cause a denial of service (crash) via (1) a large GET request to port 1080 or (2) a large GET request of % characters to port 8080.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/15286" source="XF" adv="1">avirt-soho-multiple-bo(15286)</ref>
      <ref url="http://www.securityfocus.com/bid/9723" source="BID" adv="1">9723</ref>
      <ref url="http://www.securityfocus.com/bid/9722" source="BID" adv="1">9722</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107756666701194&amp;w=2" source="BUGTRAQ" adv="1">20030223 Multiple Remote Buffer Overflow in Avirt Soho 4.3</ref>
    </refs>
    <vuln_soft>
      <prod vendor="avirt" name="avirt_soho">
        <vers num="4.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0317" published="2004-11-23" name="CVE-2004-0317" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Buffer overflow in eauth in Load Sharing Facility 4.x, 5.x, and 6.x allows local users or remote attackers within the LSF cluster to cause a denial of service (segmentation fault) and possibly execute arbitrary code via a long LSF_From_PC parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/9719" source="BID" patch="1" adv="1">9719</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107756611501236&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20040223 Lam3rZ Security Advisory #1/2004: LSF eauth vulnerability leads to remote code execution</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15282" source="XF" adv="1">lsf-eauth-execute-code(15282)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="platform" name="lsf">
        <vers num="4.0" />
        <vers num="4.2" />
        <vers num="5.0" />
        <vers num="5.1" />
        <vers num="6.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0318" published="2004-11-23" name="CVE-2004-0318" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Load Sharing Facility (LSF) 4.x, 5.x, and 6.x uses the LSF_EAUTH_UID environment variable, if it exists, instead of the real UID of the user, which could allow remote attackers within the local cluster to gain privileges.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" admin="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/9724" source="BID" patch="1" adv="1">9724</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107756600403557&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20040223 Lam3rZ Security Advisory #2/2004: LSF eauth vulnerability leads to a possibility of controlling cluster jobs on behalf of other users</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15278" source="XF" adv="1">lsf-eauth-process-hijack(15278)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="platform" name="lsf">
        <vers num="4.0" />
        <vers num="4.2" />
        <vers num="5.0" />
        <vers num="5.1" />
        <vers num="6.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0319" published="2004-11-23" name="CVE-2004-0319" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in the font tag in ezBoard 7.3u allows remote attackers to execute arbitrary script as other users, as demonstrated using the background:url in a (1) font color or (2) font face argument.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/15287" source="XF">ezboard-font-xss(15287)</ref>
      <ref url="http://www.securityfocus.com/bid/9725" source="BID">9725</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107756639427140&amp;w=2" source="BUGTRAQ">20040223 ezBoard Cross Site Scripting Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ezboard" name="ezboard">
        <vers num="7.3u" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2004-0320" published="2004-11-23" name="CVE-2004-0320" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">Unknown vulnerability in nCipher Hardware Security Modules (HSM) 1.67.x through 1.99.x allows local users to access secrets stored in the module's run-time memory via certain sequences of commands.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
      <exception />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107755899018249&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20040223 nCipher Advisory #9: Host-side attackers can access secret data</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15281" source="XF" adv="1">ncipher-hsm-obtain-info(15281)</ref>
      <ref url="http://www.securityfocus.com/bid/9717" source="BID" adv="1">9717</ref>
      <ref url="http://www.osvdb.org/4055" source="OSVDB">4055</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ncipher" name="nshield">
        <vers num="1.71.11" />
        <vers num="1.71.15" />
        <vers num="1.71.90" />
        <vers num="1.75.15" />
        <vers num="1.77.9" />
        <vers num="1.77.93" />
        <vers num="1.77.97" />
        <vers num="1.79.12" />
        <vers num="1.79.80" />
        <vers num="1.79.81" />
        <vers num="2.0" />
        <vers num="2.0.4" />
        <vers num="2.12" />
        <vers num="2.12.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0321" published="2004-11-23" name="CVE-2004-0321" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Team Factor 1.25 and earlier allows remote attackers to cause a denial of service (crash) via a packet that uses a negative number to specify the size of the data block that follows, which causes Team Factor to read unallocated memory.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input bound="1" />
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107756001412888&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20040223 Remote server crash in Team Factor &lt;= 1.25</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15274" source="XF" adv="1">teamfactor-packet-dos(15274)</ref>
      <ref url="http://www.zone-h.org/advisories/read/id=4006" source="MISC">http://www.zone-h.org/advisories/read/id=4006</ref>
      <ref url="http://www.securityfocus.com/bid/9708" source="BID" adv="1">9708</ref>
    </refs>
    <vuln_soft>
      <prod vendor="singularity_software" name="team_factor">
        <vers num="1.25" />
        <vers num="1.25m" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0322" published="2004-02-23" name="CVE-2004-0322" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in XMB 1.8 Final SP2 allow remote attackers to execute arbitrary script as other users via the (1) member parameter in member.php, (2) uid parameter in u2uadmin.php, (3) user parameter in editprofile.php, (4) an onmouseover event in an align tag when bbcode is allowed, or (5) img tag where bbcode is allowed.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/15292" source="XF" patch="1" adv="1">xmb-multiple-scripts-xss(15292)</ref>
      <ref url="http://www.securityfocus.com/bid/9726" source="BID" patch="1" adv="1">9726</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107756526625179&amp;w=2" source="BUGTRAQ" adv="1">20040223 [waraxe-2004-SA#004] - Multiple vulnerabilities in XMB 1.8 Partagium Final SP2</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15294" source="XF">xmb-bbcode-execute-code(15294)</ref>
      <ref url="http://www.xmbforum.com/community/boards/viewthread.php?tid=746859" source="CONFIRM">http://www.xmbforum.com/community/boards/viewthread.php?tid=746859</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2004-02/0645.html" source="BUGTRAQ">20040225 Re: [waraxe-2004-SA#004] - Multiple vulnerabilities in XMB 1.8 Partagium Final SP2</ref>
    </refs>
    <vuln_soft>
      <prod vendor="xmb_forum" name="xmb">
        <vers num="1.8" />
        <vers num="1.8_sp1" />
        <vers num="1.8_sp2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0323" published="2004-12-31" name="CVE-2004-0323" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple SQL injection vulnerabilities in XMB 1.8 Final SP2 allow remote attackers to inject arbitrary SQL and gain privileges via the (1) ppp parameter in viewthread.php, (2) desc parameter in misc.php, (3) tpp parameter in forumdisplay.php, (4) ascdesc parameter in forumdisplay.php, or (5) the addon parameter in stats.php.  NOTE: it has also been shown that item (3) is also in XMB 1.9 beta.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/15295" source="XF" patch="1">xmb-multiple-sql-injection(15295)</ref>
      <ref url="http://www.securityfocus.com/bid/9726" source="BID" patch="1">9726</ref>
      <ref url="http://www.xmbforum.com/community/boards/viewthread.php?tid=746859" source="CONFIRM">http://www.xmbforum.com/community/boards/viewthread.php?tid=746859</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107756526625179&amp;w=2" source="BUGTRAQ" adv="1">20040223 [waraxe-2004-SA#004] - Multiple vulnerabilities in XMB 1.8 Partagium Final SP2</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2004-03/0265.html" source="BUGTRAQ">20040326 [waraxe-2004-SA#012 - Multiple vulnerabilities in XMB Forum 1.8 SP3 and 1.9 beta]</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2004-02/0645.html" source="BUGTRAQ">20040225 Re: [waraxe-2004-SA#004] - Multiple vulnerabilities in XMB 1.8 Partagium Final SP2</ref>
    </refs>
    <vuln_soft>
      <prod vendor="xmb_forum" name="xmb">
        <vers num="1.8" />
        <vers num="1.8_sp1" />
        <vers num="1.8_sp2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0324" published="2004-02-23" name="CVE-2004-0324" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Confirm 0.62 and earlier could allow remote attackers to execute arbitrary code via an e-mail header that contains shell metacharacters such as ", `, |, ;, or $.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/15290" source="XF" patch="1" adv="1">confirm-header-gain-access(15290)</ref>
      <ref url="http://www.securityfocus.com/bid/9728" source="BID" patch="1" adv="1">9728</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107757320401858&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20040223 Lam3rZ Security Advisory #3/2004: A bug in Confirm leads to remote command execution</ref>
    </refs>
    <vuln_soft>
      <prod vendor="confirm" name="confirm">
        <vers num="0.50" />
        <vers num="0.51" />
        <vers num="0.52" />
        <vers num="0.53" />
        <vers num="0.54" />
        <vers num="0.55" />
        <vers num="0.60" />
        <vers num="0.61" />
        <vers num="0.62" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2004-0325" published="2004-12-31" name="CVE-2004-0325" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">TYPSoft FTP Server 1.10 allows remote authenticated users to cause a denial of service (CPU consumption) via "//../" arguments to (1) mkd, (2) xmkd, (3) dele, (4) size, (5) retr, (6) stor, (7) appe, (8) rnfr, (9) rnto, (10) rmd, or (11) xrmd, as demonstrated using "//../qwerty".</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/15306" source="XF">typsoft-ftp-command-dos(15306)</ref>
      <ref url="http://www.securityfocus.com/bid/9702" source="BID">9702</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107764173821905&amp;w=2" source="BUGTRAQ" adv="1">20040223 TYPSoft FTP Server 1.10 multiple vulnerabilities</ref>
    </refs>
    <vuln_soft>
      <prod vendor="typsoft" name="typsoft_ftp_server">
        <vers num="1.10" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0326" published="2004-11-23" name="CVE-2004-0326" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Buffer overflow in the web proxy for GateKeeper Pro 4.7 allows remote attackers to execute arbitrary code via a long GET request.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/15277" source="XF" adv="1">gatekeeper-long-get-bo(15277)</ref>
      <ref url="http://www.securityfocus.com/bid/9716" source="BID" adv="1">9716</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107755692400728&amp;w=2" source="BUGTRAQ" adv="1">20040222 GateKeeper Pro 4.7 buffer overflow</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2004-February/017703.html" source="FULLDISC">20040222 GateKeeper Pro 4.7 buffer overflow</ref>
    </refs>
    <vuln_soft>
      <prod vendor="proxy-pro" name="professional_gatekeeper">
        <vers num="4.7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0327" published="2004-11-23" name="CVE-2004-0327" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in functions.php in PhpNewsManager 1.46 allows remote attackers to retrieve arbitrary files via ..  (dot dot) sequences in the clang parameter.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <access />
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/15283" source="XF" adv="1">phpnewsmanager-dotdot-directory-traversal(15283)</ref>
      <ref url="http://www.zone-h.org/advisories/read/id=4024" source="MISC">http://www.zone-h.org/advisories/read/id=4024</ref>
      <ref url="http://www.securityfocus.com/bid/9720" source="BID" adv="1">9720</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107772470111000&amp;w=2" source="BUGTRAQ" adv="1">20040223 ZH2004-09SA (security advisory): PhpNewsManager Remote arbitrary</ref>
    </refs>
    <vuln_soft>
      <prod vendor="skintech" name="phpnewsmanager">
        <vers num="1.36" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0328" published="2004-11-23" name="CVE-2004-0328" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Gigabyte Gn-B46B 2.4Ghz wireless broadband router firmware 1.003.00 allows local users on the same local network as the router to bypass authentication by using a copy of the router's html menu on a separate system.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" admin="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/15313" source="XF" adv="1">gigabyte-gnb46b-bypass-authentication(15313)</ref>
      <ref url="http://www.securityfocus.com/bid/9740" source="BID" adv="1">9740</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107766719227942&amp;w=2" source="BUGTRAQ" adv="1">20040224 Gigabyte Broadband Router  - Multiple Vulnerabilities</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gigabyte" name="gn-b46b">
        <vers num="1.003.00" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0329" published="2004-11-23" name="CVE-2004-0329" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">FreeChat 1.1.1a allows remote attackers to cause a denial of service (crash) via certain unexpected strings, as demonstrated using "aaaaa".</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/15321" source="XF" adv="1">freechat-string-dos(15321)</ref>
      <ref url="http://www.securityfocus.com/bid/9744" source="BID" adv="1">9744</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107781043621074&amp;w=2" source="BUGTRAQ" adv="1">20040226 Denial Of Service in FreeChat 1.1.1a</ref>
    </refs>
    <vuln_soft>
      <prod vendor="freechat" name="freechat">
        <vers num="0.1.1a" />
        <vers num="1.1.1a" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0330" published="2004-11-23" name="CVE-2004-0330" modified="2010-04-28" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Buffer overflow in Serv-U ftp before 5.0.0.4 allows remote authenticated users to execute arbitrary code via a long time zone argument to the MDTM command.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/15323" source="XF" adv="1">servu-mdtm-bo(15323)</ref>
      <ref url="http://www.securityfocus.com/bid/9751" source="BID" adv="1">9751</ref>
      <ref url="http://www.cnhonker.com/advisory/serv-u.mdtm.txt" source="MISC">http://www.cnhonker.com/advisory/serv-u.mdtm.txt</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107781164214399&amp;w=2" source="BUGTRAQ" adv="1">20040226 [vulnwatch] Serv-U MDTM Command Buffer Overflow Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="serv-u" name="serv-u">
        <vers num="3.0.0.16" />
        <vers num="3.0.0.17" />
        <vers num="3.1.0.0" />
        <vers num="3.1.0.1" />
        <vers num="3.1.0.3" />
        <vers num="4.0.0.4" />
        <vers num="4.1.0.0" />
        <vers num="4.1.0.3" />
        <vers prev="1" num="5.0.0.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0331" published="2004-11-23" name="CVE-2004-0331" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Heap-based buffer overflow in Dell OpenManage Web Server 3.4.0 allows remote attackers to cause a denial of service (crash) via a HTTP POST with a long application variable.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/9750" source="BID" patch="1" adv="1">9750</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15325" source="XF" adv="1">dell-openmanage-ocsgetoeminpathfile-bo(15325)</ref>
      <ref url="http://sh0dan.org/files/domadv.txt" source="MISC">http://sh0dan.org/files/domadv.txt</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107781539829143&amp;w=2" source="BUGTRAQ" adv="1">20040226  Dell OpenManage Web Server Heap Overflow (Pre-Auth)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="dell" name="openmanage">
        <vers num="3.2" />
        <vers num="3.4" />
        <vers num="3.7" />
        <vers num="3.7.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0332" published="2004-11-23" name="CVE-2004-0332" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Extremail 1.5.9 does not check passwords correctly when they are all digits or begin with a digit, which allows remote attackers to gain privileges.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" admin="1" />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/15329" source="XF" adv="1">extremail-password-gain-access(15329)</ref>
      <ref url="http://www.securityfocus.com/bid/9754" source="BID" adv="1">9754</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107783767517850&amp;w=2" source="BUGTRAQ" adv="1">20040226 Extremail Security Problem</ref>
    </refs>
    <vuln_soft>
      <prod vendor="extremail" name="extremail">
        <vers num="1.0" />
        <vers num="1.0.1" />
        <vers num="1.0.2" />
        <vers num="1.0.3" />
        <vers num="1.1" />
        <vers num="1.1.1" />
        <vers num="1.1.10" />
        <vers num="1.1.2" />
        <vers num="1.1.3" />
        <vers num="1.1.4" />
        <vers num="1.1.5" />
        <vers num="1.1.6" />
        <vers num="1.1.7" />
        <vers num="1.1.8" />
        <vers num="1.1.9" />
        <vers num="1.5" />
        <vers num="1.5.5" />
        <vers num="1.5.8" />
        <vers num="1.5.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0333" published="2004-11-23" name="CVE-2004-0333" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Buffer overflow in the UUDeview package, as used in WinZip 6.2 through WinZip 8.1 SR-1, and possibly other packages, allows remote attackers to execute arbitrary code via a MIME archive with certain long MIME parameters.</descript>
    </desc>
    <sols>
      <sol source="nvd">This was fixed in WinZip 8.1 SR-2 in March of 2004. You can find more information on the subject on the following pages of the winzip site:
http://www.winzip.com/wz81sr2.htm
http://www.winzip.com/fmwz90.htm</sol>
    </sols>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/116182" source="CERT-VN" adv="1">VU#116182</ref>
      <ref url="http://www.securityfocus.com/bid/9758" source="BID" patch="1" adv="1">9758</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15490" source="XF">uudeview-multiple-bo(15490)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15336" source="XF" adv="1">winzip-mime-bo(15336)</ref>
      <ref url="http://www.winzip.com/fmwz90.htm" source="CONFIRM">http://www.winzip.com/fmwz90.htm</ref>
      <ref url="http://www.osvdb.org/4119" source="OSVDB">4119</ref>
      <ref url="http://www.openpkg.org/security/OpenPKG-SA-2004.006-uudeview.html" source="CONFIRM">http://www.openpkg.org/security/OpenPKG-SA-2004.006-uudeview.html</ref>
      <ref url="http://www.idefense.com/application/poi/display?id=76&amp;type=vulnerabiliti&amp;flashstatus=true" source="IDEFENSE">20040227 WinZip MIME Parsing Buffer Overflow Vulnerability</ref>
      <ref url="http://www.ciac.org/ciac/bulletins/o-092.shtml" source="CIAC">O-092</ref>
      <ref url="http://secunia.com/advisories/11019" source="SECUNIA">11019</ref>
      <ref url="http://secunia.com/advisories/10995" source="SECUNIA">10995</ref>
    </refs>
    <vuln_soft>
      <prod vendor="openpkg" name="openpkg">
        <vers num="" />
      </prod>
      <prod vendor="uudeview" name="uudeview">
        <vers num="0.5.18" />
        <vers num="0.5.19" />
      </prod>
      <prod vendor="winzip" name="winzip">
        <vers num="7.0" />
        <vers num="8.0" />
        <vers num="8.1" edition="sr1" />
      </prod>
      <prod vendor="gentoo" name="linux">
        <vers num="1.4" edition="rc1" />
        <vers num="1.4" edition="rc2" />
        <vers num="1.4" edition="rc3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0334" published="2004-11-23" name="CVE-2004-0334" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">InnoMedia VideoPhone allows remote attackers to bypass Basic Authorization via an HTTP request to (1) videophone_admindetail.asp, (2) videophone_syscfg.asp, (3) videophone_upgrade.asp, or (4) videophone_sysctrl.asp that contains a trailing / (slash).  NOTE: the original report mentioned AXIS 2100 Network Camera, but this was likely a cut-and-paste error.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/15636" source="XF">InnoMedia-videophone-bypass-authentication(15636)</ref>
      <ref url="http://www.osvdb.org/4809" source="OSVDB">4809</ref>
      <ref url="http://securitytracker.com/alerts/2004/Mar/1009522.html" source="SECTRACK">1009522</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107799556111784&amp;w=2" source="BUGTRAQ">20040227 InnoMedia VideoPhone Authorization Bypass</ref>
    </refs>
    <vuln_soft>
      <prod vendor="innomedia" name="innomedia_videophone">
        <vers num="au75200xvi04010x" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0335" published="2004-11-23" name="CVE-2004-0335" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">LAN SUITE Web Mail 602Pro, when configured to use the "Directory browsing" feature, allows remote attackers to obtain a directory listing via an HTTP request to (1) index.html, (2) cgi-bin/, or (3) users/.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <config />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/15349" source="XF" adv="1">602pro-directory-listing(15349)</ref>
      <ref url="http://www.securityfocus.com/bid/9780" source="BID">9780</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2004-03/0096.html" source="BUGTRAQ">20040310 Re: LAN SUITE Web Mail 602Pro Multiple Vulnerabilities</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107799540630302&amp;w=2" source="BUGTRAQ">20040228 LAN SUITE Web Mail 602Pro Multiple Vulnerabilities</ref>
    </refs>
    <vuln_soft>
      <prod vendor="software602" name="602pro_lan_suite">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0336" published="2004-11-23" name="CVE-2004-0336" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">LAN SUITE Web Mail 602Pro allows remote attackers to gain sensitive information via the mail login form, which contains the path to the mail directory.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/15350" source="XF" adv="1">602pro-path-disclosure(15350)</ref>
      <ref url="http://www.securityfocus.com/bid/9781" source="BID" adv="1">9781</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107799540630302&amp;w=2" source="BUGTRAQ" adv="1">20040228 LAN SUITE Web Mail 602Pro Multiple Vulnerabilities</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2004-03/0096.html" source="BUGTRAQ">20040310 Re: LAN SUITE Web Mail 602Pro Multiple Vulnerabilities</ref>
    </refs>
    <vuln_soft>
      <prod vendor="software602" name="602pro_lan_suite">
        <vers num="2002" />
        <vers num="2003" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0337" published="2004-11-23" name="CVE-2004-0337" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in LAN SUITE Web Mail 602Pro allows remote attackers to execute arbitrary script or HTML as other users via a URL to index.html, followed by a / (slash) and the desired script.  NOTE: the vendor states that this bug could not be reproduced, so this issue may be REJECTed in the future.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/15351" source="XF">602pro-index-xss(15351)</ref>
      <ref url="http://www.securityfocus.com/bid/9777" source="BID">9777</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107799540630302&amp;w=2" source="BUGTRAQ">20040228 LAN SUITE Web Mail 602Pro Multiple Vulnerabilities</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2004-03/0096.html" source="BUGTRAQ">20040310 Re: LAN SUITE Web Mail 602Pro Multiple Vulnerabilities</ref>
    </refs>
    <vuln_soft>
      <prod vendor="software602" name="602pro_lan_suite">
        <vers num="2002" />
        <vers num="2003" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0338" published="2004-11-23" name="CVE-2004-0338" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">SQL injection vulnerability in search.php for Invision Board Forum allows remote attackers to execute arbitrary SQL queries via the st parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" admin="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107799527428834&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20040228 Invision Power Board SQL injection!</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15343" source="XF" adv="1">invision-search-sql-injection(15343)</ref>
      <ref url="http://www.securityfocus.com/bid/9766" source="BID">9766</ref>
    </refs>
    <vuln_soft>
      <prod vendor="invision_power_services" name="invision_board">
        <vers num="1.0" />
        <vers num="1.0.1" />
        <vers num="1.1.1" />
        <vers num="1.1.2" />
        <vers num="1.2" />
        <vers num="1.3" />
        <vers num="2.0_alpha_3" />
        <vers num="2.0_pdr3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0339" published="2004-11-23" name="CVE-2004-0339" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in ViewTopic.php in phpBB, possibly 2.0.6c and earlier, allows remote attackers to execute arbitrary script or HTML as other users via the postorder parameter.</descript>
    </desc>
    <sols>
      <sol source="nvd">This vulnerability is addressed in the following product release:
phpBB Group, phpBB, 2.0.7</sol>
    </sols>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/9765" source="BID" patch="1">9765</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15348" source="XF">phpbb-viewtopicphp-xss(15348)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107799508130700&amp;w=2" source="BUGTRAQ">20040228 New phpBB ViewTopic.php Cross Site Scripting Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="phpbb_group" name="phpbb">
        <vers num="2.0" />
        <vers num="2.0.1" />
        <vers num="2.0.2" />
        <vers num="2.0.3" />
        <vers num="2.0.4" />
        <vers num="2.0.5" />
        <vers num="2.0.6" />
        <vers num="2.0.6c" />
        <vers num="2.0_rc4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0340" published="2004-11-23" name="CVE-2004-0340" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Stack-based buffer overflow in WFTPD Pro Server 3.21 Release 1, Pro Server 3.20 Release 2, Server 3.21 Release 1, and Server 3.10 allows local users to execute arbitrary code via long (1) LIST, (2) NLST, or (3) STAT commands.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/9767" source="BID" patch="1" adv="1">9767</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15340" source="XF" adv="1">wftpd-ftp-commands-bo(15340)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107801208004699&amp;w=2" source="BUGTRAQ" adv="1">20040228 Critical WFTPD buffer overflow vulnerability</ref>
      <ref url="http://secunia.com/advisories/11001" source="SECUNIA">11001</ref>
    </refs>
    <vuln_soft>
      <prod vendor="texas_imperial_software" name="wftpd">
        <vers num="3.0" edition="" />
        <vers num="3.0" edition=":pro" />
        <vers num="3.0_0r3" />
        <vers num="3.0_0r4" edition="" />
        <vers num="3.0_0r4" edition=":pro" />
        <vers num="3.0_0r5" edition="" />
        <vers num="3.0_0r5" edition=":pro" />
        <vers num="3.10_r1" />
        <vers num="3.20" />
        <vers num="3.21" />
        <vers num="pro_3.10_r1" />
        <vers num="pro_3.20" />
        <vers num="pro_3.21" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2004-0341" published="2004-11-23" name="CVE-2004-0341" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">WFTPD Pro Server 3.21 Release 1 allocates memory for a command until a 0Ah byte (newline) is sent, which allows local users to cause a denial of service (CPU consumption) by continuing to send a long command that does not contain a newline.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/9767" source="BID" patch="1" adv="1">9767</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15341" source="XF" adv="1">wftpd-string-0Ahbyte-dos(15341)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107801142924976&amp;w=2" source="BUGTRAQ" adv="1">20040228 Multiple WFTPD Denial of Service vulnerabilities</ref>
      <ref url="http://www.osvdb.org/4115" source="OSVDB">4115</ref>
      <ref url="http://secunia.com/advisories/11001" source="SECUNIA">11001</ref>
    </refs>
    <vuln_soft>
      <prod vendor="texas_imperial_software" name="wftpd">
        <vers num="3.0" edition="" />
        <vers num="3.0" edition=":pro" />
        <vers num="3.0_0r3" />
        <vers num="3.0_0r4" edition="" />
        <vers num="3.0_0r4" edition=":pro" />
        <vers num="3.0_0r5" edition="" />
        <vers num="3.0_0r5" edition=":pro" />
        <vers num="3.10_r1" />
        <vers num="3.20" />
        <vers num="3.21" />
        <vers num="pro_3.10_r1" />
        <vers num="pro_3.20" />
        <vers num="pro_3.21" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2004-0342" published="2004-11-23" name="CVE-2004-0342" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">WFTPD Pro Server 3.21 Release 1, with the XeroxDocutech option enabled, allows local users to cause a denial of service (crash) via a (1) MKD or (2) XMKD command that causes an absolute path of 260 characters to be used, which overwrites a cookie with a null character, possibly due to an off-by-one error.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input bound="1" />
      <exception />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/9767" source="BID" patch="1" adv="1">9767</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15342" source="XF" adv="1">wftpd-ftp-command-dos(15342)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107801142924976&amp;w=2" source="BUGTRAQ" adv="1">20040228 Multiple WFTPD Denial of Service vulnerabilities</ref>
      <ref url="http://www.osvdb.org/4116" source="OSVDB">4116</ref>
      <ref url="http://secunia.com/advisories/11001" source="SECUNIA">11001</ref>
    </refs>
    <vuln_soft>
      <prod vendor="texas_imperial_software" name="wftpd">
        <vers num="3.0" edition="" />
        <vers num="3.0" edition=":pro" />
        <vers num="3.0_0r3" />
        <vers num="3.0_0r4" edition="" />
        <vers num="3.0_0r4" edition=":pro" />
        <vers num="3.0_0r5" edition="" />
        <vers num="3.0_0r5" edition=":pro" />
        <vers num="3.10_r1" />
        <vers num="3.20" />
        <vers num="3.21" />
        <vers num="pro_3.10_r1" />
        <vers num="pro_3.20" />
        <vers num="pro_3.21" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0343" published="2004-11-23" name="CVE-2004-0343" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Multiple SQL injection vulnerabilities in YaBB SE 1.5.4 through 1.5.5b allow remote attackers to execute arbitrary SQL via (1) the msg parameter in ModifyMessage.php or (2) the postid parameter in ModifyMessage.php.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" admin="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/9774" source="BID" patch="1" adv="1">9774</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15354" source="XF" adv="1">yabb-multiple-sql-injection(15354)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107816202813083&amp;w=2" source="BUGTRAQ">20040301 YabbSE  (3 on 1)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="yabb" name="yabb">
        <vers num="1.5.4" edition="" />
        <vers num="1.5.4" edition=":second_edition" />
        <vers num="1.5.5" edition="" />
        <vers num="1.5.5" edition=":second_edition" />
        <vers num="1.5.5b" edition="" />
        <vers num="1.5.5b" edition=":second_edition" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0344" published="2004-11-23" name="CVE-2004-0344" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:P)" CVSS_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_base_score="6.4">
    <desc>
      <descript source="cve">Directory traversal vulnerability in ModifyMessage.php in YaBB SE 1.5.4 through 1.5.5b allows remote attackers to delete arbitrary files via a .. (dot dot) in the attachOld parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/9774" source="BID" patch="1" adv="1">9774</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107816202813083&amp;w=2" source="BUGTRAQ">20040301 YabbSE  (3 on 1)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="yabb" name="yabb">
        <vers num="1.5.5" edition="" />
        <vers num="1.5.5" edition=":second_edition" />
        <vers num="1.5.5b" edition="" />
        <vers num="1.5.5b" edition=":second_edition" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0345" published="2004-11-23" name="CVE-2004-0345" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Buffer overflow in Red Faction client 1.20 and earlier allows remote servers to execute arbitrary code via a long server name.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/15353" source="XF" adv="1">redfaction-bo(15353)</ref>
      <ref url="http://www.securityfocus.com/bid/9775" source="BID" adv="1">9775</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107816217901923&amp;w=2" source="BUGTRAQ" adv="1">20040301 Clients broadcast buffer overflow in Red Faction &lt;= 1.20</ref>
    </refs>
    <vuln_soft>
      <prod vendor="volition" name="red_faction">
        <vers num="1.0" />
        <vers num="1.1" />
        <vers num="1.20" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0346" published="2004-11-23" name="CVE-2004-0346" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Off-by-one buffer overflow in _xlate_ascii_write() in ProFTPD 1.2.7 through 1.2.9rc2p allows local users to gain privileges via a 1024 byte RETR command.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/15387" source="XF" adv="1">proftpd-offbyone-bo(15387)</ref>
      <ref url="http://www.securityfocus.com/bid/9782" source="BID" adv="1">9782</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107824679817240&amp;w=2" source="BUGTRAQ">20040302 The Cult of a Cardinal Number</ref>
    </refs>
    <vuln_soft>
      <prod vendor="proftpd_project" name="proftpd">
        <vers num="1.2.7" />
        <vers num="1.2.8" />
        <vers num="1.2.9_rc1" />
        <vers num="1.2.9_rc2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0347" published="2004-11-23" name="CVE-2004-0347" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:S/C:P/I:P/A:P)" CVSS_score="6.0" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="6.8" CVSS_base_score="6.0">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in delhomepage.cgi in NetScreen-SA 5000 Series running firmware 3.3 Patch 1 (build 4797) allows remote authenticated users to execute arbitrary script as other users via the row parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/114070" source="CERT-VN">VU#114070</ref>
      <ref url="http://www.securityfocus.com/bid/9791" source="BID" patch="1">9791</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107850564102190&amp;w=2" source="BUGTRAQ" patch="1">20040304 NetScreen Advisory 58412: XSS Bug in NetScreen-SA SSL VPN</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107826362024112&amp;w=2" source="BUGTRAQ" patch="1">20040302 03-02-04 XSS Bug in NetScreen-SA 5000 Series of SSL VPN appliance</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15368" source="XF">netscreen-delhomepagecgi-xss(15368)</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2004-March/018120.html" source="FULLDISC">20040302 03-02-04 XSS Bug in NetScreen-SA 5000 Series of SSL VPN appliance</ref>
    </refs>
    <vuln_soft>
      <prod vendor="netscreen" name="netscreen-sa_5000_series">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0348" published="2004-11-23" name="CVE-2004-0348" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">SQL injection vulnerability in viewCart.asp in SpiderSales shopping cart software allows remote attackers to execute arbitrary SQL via the userId parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" admin="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/15371" source="XF" adv="1">spidersales-userid-sql-injection(15371)</ref>
      <ref url="http://www.securityfocus.com/bid/9799" source="BID" adv="1">9799</ref>
      <ref url="http://www.s-quadra.com/advisories/Adv-20040303.txt" source="MISC">http://www.s-quadra.com/advisories/Adv-20040303.txt</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107833097705486&amp;w=2" source="BUGTRAQ" adv="1">20040303 Spider Sales shopping cart software multiple security vulnerabilities</ref>
    </refs>
    <vuln_soft>
      <prod vendor="spidersales" name="spidersales">
        <vers num="2.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0349" published="2004-11-23" name="CVE-2004-0349" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in GWeb HTTP Server 0.6 allows remote attackers to view arbitrary files via a .. (dot dot) in the URL.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107833161617397&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20040303 directory traversal in GWeb 0.6</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15381" source="XF" adv="1">gweb-dotdot-directory-traversal(15381)</ref>
      <ref url="http://www.securityfocus.com/bid/9742" source="BID" adv="1">9742</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gweb" name="gweb_http_server">
        <vers num="0.5" />
        <vers num="0.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2004-0350" published="2004-11-23" name="CVE-2004-0350" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">SpiderSales shopping cart does not enforce a minimum length for the private key, which can make it easier for local users to obtain the private key by factoring.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/15370" source="XF" adv="1">spidersales-weak-encryption(15370)</ref>
      <ref url="http://www.securityfocus.com/bid/9799" source="BID" adv="1">9799</ref>
      <ref url="http://www.s-quadra.com/advisories/Adv-20040303.txt" source="MISC">http://www.s-quadra.com/advisories/Adv-20040303.txt</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107833097705486&amp;w=2" source="BUGTRAQ" adv="1">20040303 Spider Sales shopping cart software multiple security vulnerabilities</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2004-March/018177.html" source="FULLDISC">20040303 Spider Sales shopping cart software multiple security vulnerabilities</ref>
    </refs>
    <vuln_soft>
      <prod vendor="spidersales" name="spidersales">
        <vers num="2.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2004-0351" published="2004-11-23" name="CVE-2004-0351" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">Spider Sales shopping cart stores the private key in the same database and table as the public key, which allows local users with access to the database to decrypt data.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/15370" source="XF" adv="1">spidersales-weak-encryption(15370)</ref>
      <ref url="http://www.securityfocus.com/bid/9799" source="BID" adv="1">9799</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107833097705486&amp;w=2" source="BUGTRAQ" adv="1">20040303 Spider Sales shopping cart software multiple security vulnerabilities</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2004-March/018177.html" source="FULLDISC">20040303 Spider Sales shopping cart software multiple security vulnerabilities</ref>
    </refs>
    <vuln_soft>
      <prod vendor="spidersales" name="spidersales">
        <vers num="2.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0352" published="2004-11-23" name="CVE-2004-0352" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Cisco 11000 Series Content Services Switches (CSS) running WebNS 5.0(x) before 05.0(04.07)S, and 6.10(x) before 06.10(02.05)S allow remote attackers to cause a denial of service (device reset) via a malformed packet to UDP port 5002.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/363374" source="CERT-VN" adv="1">VU#363374</ref>
      <ref url="http://www.securityfocus.com/bid/9806" source="BID" patch="1" adv="1">9806</ref>
      <ref url="http://www.cisco.com/warp/public/707/cisco-sa-20040304-css.shtml" source="CISCO" patch="1" adv="1">20040304 Cisco CSS 11000 Series Content Services Switches Malformed UDP Packet Vulnerability</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15388" source="XF" adv="1">cisco-css-udp-dos(15388)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="content_services_switch_11000">
        <vers num="" />
      </prod>
      <prod vendor="cisco" name="content_services_switch_11050">
        <vers num="" />
      </prod>
      <prod vendor="cisco" name="content_services_switch_11150">
        <vers num="" />
      </prod>
      <prod vendor="cisco" name="content_services_switch_11800">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0353" published="2004-11-23" name="CVE-2004-0353" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Multiple buffer overflows in auth_ident() function in auth.c for GNU Anubis 3.6.0 through 3.6.2, 3.9.92 and 3.9.93 allow remote attackers to gain privileges via a long string.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/9772" source="BID" patch="1" adv="1">9772</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15345" source="XF" adv="1">anubis-ident-bo(15345)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107894315012081&amp;w=2" source="BUGTRAQ">20040310 GNU Anubis 3.6.2 remote root exploit</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107843915424588&amp;w=2" source="BUGTRAQ" adv="1">20040304 GNU Anubis buffer overflows and format string bugs</ref>
      <ref url="http://mail.gnu.org/archive/html/bug-anubis/2004-02/msg00000.html" source="MLIST">[bug-anubis] 20040228 Important security update</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gnu" name="anubis">
        <vers num="3.6.0" />
        <vers num="3.6.1" />
        <vers num="3.6.2" />
        <vers num="3.9.92" />
        <vers num="3.9.93" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0354" published="2004-11-23" name="CVE-2004-0354" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Multiple format string vulnerabilities in GNU Anubis 3.6.0 through 3.6.2, 3.9.92 and 3.9.93 allow remote attackers to execute arbitrary code via format string specifiers in strings passed to (1) the info function in log.c, (2) the anubis_error function in errs.c, or (3) the ssl_error function in ssl.c.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" admin="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/9772" source="BID" patch="1" adv="1">9772</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15346" source="XF" adv="1">anubis-format-string(15346)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107843915424588&amp;w=2" source="BUGTRAQ" adv="1">20040304 GNU Anubis buffer overflows and format string bugs</ref>
      <ref url="http://mail.gnu.org/archive/html/bug-anubis/2004-02/msg00000.html" source="MLIST">[bug-anubis] 20040228 Important security update</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gnu" name="anubis">
        <vers num="3.6.0" />
        <vers num="3.6.1" />
        <vers num="3.6.2" />
        <vers num="3.9.92" />
        <vers num="3.9.93" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0355" published="2004-11-23" name="CVE-2004-0355" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Invision Power Board 1.3 Final allows remote attackers to gain sensitive information by selecting a file for "Personal Photo" that is not an image file, which displays the installation path in an error message.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/15400" source="XF" adv="1">invision-invalid-path-disclosure(15400)</ref>
      <ref url="http://www.securityfocus.com/bid/9810" source="BID" adv="1">9810</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107850510428567&amp;w=2" source="BUGTRAQ" adv="1">20040305 Invision Power Board 1.3 Final Path Disclosure Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="invision_power_services" name="invision_board">
        <vers num="1.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0356" published="2004-11-23" name="CVE-2004-0356" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Stack-based buffer overflow in Supervisor Report Center in SL Mail Pro 2.0.9 and earlier allows remote attackers to execute arbitrary code via an HTTP request with a long HTTP sub-version.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/15398" source="XF" adv="1">slmail-src-stack-bo(15398)</ref>
      <ref url="http://www.securityfocus.com/bid/9809" source="BID" adv="1">9809</ref>
      <ref url="http://www.nextgenss.com/advisories/slmailsrc.txt" source="MISC">http://www.nextgenss.com/advisories/slmailsrc.txt</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107850488326232&amp;w=2" source="BUGTRAQ" adv="1">20040305 SLMail Pro Supervisor Report Center Buffer Overflow (#NISR05022004a)</ref>
      <ref url="http://216.26.170.92/Download/webfiles/Patches/SLMPPatch-2.0.14.pdf" source="CONFIRM">http://216.26.170.92/Download/webfiles/Patches/SLMPPatch-2.0.14.pdf</ref>
    </refs>
    <vuln_soft>
      <prod vendor="seattle_lab_software" name="slmail_pro">
        <vers num="2.0" />
        <vers num="2.0.1" />
        <vers num="2.0.2" />
        <vers num="2.0.3" />
        <vers num="2.0.4" />
        <vers num="2.0.5" />
        <vers num="2.0.6" />
        <vers num="2.0.7" />
        <vers num="2.0.8" />
        <vers num="2.0.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0357" published="2004-11-23" name="CVE-2004-0357" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Stack-based buffer overflows in SL Mail Pro 2.0.9 allow remote attackers to execute arbitrary code via (1) user.dll, (2) loadpageadmin.dll or (3) loadpageuser.dll.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/9808" source="BID" patch="1" adv="1">9808</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15399" source="XF" adv="1">slmail-slwebmail-bo(15399)</ref>
      <ref url="http://www.nextgenss.com/advisories/slmailwm.txt" source="MISC">http://www.nextgenss.com/advisories/slmailwm.txt</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107850432827699&amp;w=2" source="BUGTRAQ" adv="1">20040305 SLWebMail Multiple Buffer Overflow Vulnerabilities (#NISR05022004b)</ref>
      <ref url="http://216.26.170.92/Download/webfiles/Patches/SLMPPatch-2.0.14.pdf" source="CONFIRM">http://216.26.170.92/Download/webfiles/Patches/SLMPPatch-2.0.14.pdf</ref>
    </refs>
    <vuln_soft>
      <prod vendor="seattle_lab_software" name="slmail_pro">
        <vers num="2.0.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0358" published="2004-11-23" name="CVE-2004-0358" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in VirtuaNews Admin Panel Pro 1.0.3 allows remote attackers to execute arbitrary script as other users via (1) the mainnews parameter in admin.php, (2) the expand parameter in admin.php, (3) the id parameter in admin.php, (4) the catid parameter in admin.php, or (5) an unnamed parameter during the newslogo_upload action in admin.php.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/15402" source="XF">virtuanews-multiple-xss(15402)</ref>
      <ref url="http://www.securityfocus.com/bid/9819" source="BID">9819</ref>
      <ref url="http://www.securityfocus.com/bid/9812" source="BID">9812</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107851556116088&amp;w=2" source="BUGTRAQ" adv="1">20040305 VirtuaNews Admin Panel 1.0.3 Pro Cross Site Scripting Vulnerabillity</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2004-03/0069.html" source="BUGTRAQ">20040307 RE: VirtuaNews Admin Panel 1.0.3 Pro Cross Site Scripting Vulnerabillity</ref>
    </refs>
    <vuln_soft>
      <prod vendor="virtuasystems" name="virtuanews_pro">
        <vers num="1.0" />
        <vers num="1.0.1" />
        <vers num="1.0.2" />
        <vers num="1.0.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0359" published="2004-11-23" name="CVE-2004-0359" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in index.php for Invision Power Board 1.3 final allows remote attackers to execute arbitrary script as other users via the (1) c, (2) f, (3) showtopic, (4) showuser, or (5) username parameters.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/15403" source="XF">invision-xss(15403)</ref>
      <ref url="http://www.securityfocus.com/bid/9768" source="BID">9768</ref>
      <ref url="http://www.osvdb.org/4154" source="OSVDB">4154</ref>
      <ref url="http://secunia.com/advisories/11053" source="SECUNIA" adv="1">11053</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107851589701916&amp;w=2" source="BUGTRAQ" adv="1">20040305 Invision Power Board v1.3 Final Cross Site Scripting Vulnerabillity</ref>
    </refs>
    <vuln_soft>
      <prod vendor="invision_power_services" name="invision_board">
        <vers num="1.3.1_final" />
        <vers num="1.3_final" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0360" published="2004-11-23" name="CVE-2004-0360" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Unknown vulnerability in passwd(1) in Solaris 8.0 and 9.0 allows local users to gain privileges via unknown attack vectors.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" admin="1" />
    </loss_types>
    <vuln_types>
      <other />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/694782" source="CERT-VN" adv="1">VU#694782</ref>
      <ref url="http://www.securityfocus.com/bid/9757" source="BID" patch="1" adv="1">9757</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15327" source="XF" adv="1">solaris-passwd-gain-privileges(15327)</ref>
      <ref url="http://www.ciac.org/ciac/bulletins/o-088.shtml" source="CIAC">O-088</ref>
      <ref url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doc=fsalert/57454" source="SUNALERT">57454</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107852274423414&amp;w=2" source="BUGTRAQ" adv="1">200470305 O-088: Sun passwd(1) Command Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="solaris">
        <vers num="8.0" edition="" />
        <vers num="8.0" edition=":x86" />
        <vers num="9.0" edition="" />
        <vers num="9.0" edition=":sparc" />
        <vers num="9.0" edition=":x86" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0361" published="2004-11-23" name="CVE-2004-0361" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The Javascript engine in Safari 1.2 and earlier allows remote attackers to cause a denial of service (segmentation fault) by creating a new Array object with a large size value, then writing into that array.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/15413" source="XF" adv="1">safari-array-dos(15413)</ref>
      <ref url="http://www.securityfocus.com/bid/9815" source="BID" adv="1">9815</ref>
      <ref url="http://www.insecure.ws/article.php?story=2004021918172533" source="MISC">http://www.insecure.ws/article.php?story=2004021918172533</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107861828510106&amp;w=2" source="BUGTRAQ" adv="1">20040306 Safari javascript array overflow</ref>
    </refs>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0362" published="2004-04-15" name="CVE-2004-0362" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple stack-based buffer overflows in the ICQ parsing routines of the ISS Protocol Analysis Module (PAM) component, as used in various RealSecure, Proventia, and BlackICE products, allow remote attackers to execute arbitrary code via a SRV_MULTI response containing a SRV_USER_ONLINE response packet and a SRV_META_USER response packet with long (1) nickname, (2) firstname, (3) lastname, or (4) email address fields, as exploited by the Witty worm.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/947254" source="CERT-VN" patch="1" adv="1">VU#947254</ref>
      <ref url="http://xforce.iss.net/xforce/alerts/id/166" source="ISS" patch="1" adv="1">20040318 Vulnerability in ICQ Parsing in ISS Products</ref>
      <ref url="http://www.securityfocus.com/bid/9913" source="BID" patch="1" adv="1">9913</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107965651712378&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20040318 EEYE: Internet Security Systems PAM ICQ Server Response Processing Vulnerability</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15543" source="XF">witty-worm-propagation(15543)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15442" source="XF">pam-icq-parsing-bo(15442)</ref>
      <ref url="http://www.osvdb.org/4355" source="OSVDB">4355</ref>
      <ref url="http://www.eeye.com/html/Research/Advisories/AD20040318.html" source="EEYE">AD20040318</ref>
      <ref url="http://www.ciac.org/ciac/bulletins/o-104.shtml" source="CIAC">O-104</ref>
      <ref url="http://secunia.com/advisories/11073" source="SECUNIA">11073</ref>
    </refs>
    <vuln_soft>
      <prod vendor="iss" name="blackice_agent_server">
        <vers num="3.6ebz" />
        <vers num="3.6eca" />
        <vers num="3.6ecb" />
        <vers num="3.6ecc" />
        <vers num="3.6ecd" />
        <vers num="3.6ece" />
        <vers num="3.6ecf" />
      </prod>
      <prod vendor="iss" name="blackice_pc_protection">
        <vers num="3.6cbz" />
        <vers num="3.6cca" />
        <vers num="3.6ccb" />
        <vers num="3.6ccc" />
        <vers num="3.6ccd" />
        <vers num="3.6cce" />
        <vers num="3.6ccf" />
      </prod>
      <prod vendor="iss" name="blackice_server_protection">
        <vers num="3.6cbz" />
        <vers num="3.6cca" />
        <vers num="3.6ccb" />
        <vers num="3.6ccc" />
        <vers num="3.6ccd" />
        <vers num="3.6cce" />
        <vers num="3.6ccf" />
      </prod>
      <prod vendor="iss" name="realsecure_desktop">
        <vers num="3.6ebz" />
        <vers num="3.6eca" />
        <vers num="3.6ecb" />
        <vers num="3.6ecd" />
        <vers num="3.6ece" />
        <vers num="3.6ecf" />
        <vers num="7.0eba" />
        <vers num="7.0ebf" />
        <vers num="7.0ebg" />
        <vers num="7.0ebh" />
        <vers num="7.0ebj" />
        <vers num="7.0ebk" />
        <vers num="7.0ebl" />
      </prod>
      <prod vendor="iss" name="realsecure_guard">
        <vers num="3.6ebz" />
        <vers num="3.6eca" />
        <vers num="3.6ecb" />
        <vers num="3.6ecc" />
        <vers num="3.6ecd" />
        <vers num="3.6ece" />
        <vers num="3.6ecf" />
      </prod>
      <prod vendor="iss" name="realsecure_network_sensor">
        <vers num="7.0" edition="xpu_20.11" />
        <vers num="7.0" edition="xpu_22.10" />
        <vers num="7.0" edition="xpu_22.4" />
        <vers num="7.0" edition="xpu_22.9" />
      </prod>
      <prod vendor="iss" name="realsecure_sentry">
        <vers num="3.6ebz" />
        <vers num="3.6eca" />
        <vers num="3.6ecb" />
        <vers num="3.6ecc" />
        <vers num="3.6ecd" />
        <vers num="3.6ece" />
        <vers num="3.6ecf" />
      </prod>
      <prod vendor="iss" name="realsecure_server_sensor">
        <vers num="6.0" edition="" />
        <vers num="6.0" edition=":windows" />
        <vers num="6.0.1" edition="" />
        <vers num="6.0.1" edition=":windows" />
        <vers num="6.0.1_win_sr1.1" />
        <vers num="6.5" edition="" />
        <vers num="6.5" edition=":windows" />
        <vers num="6.5" edition="sr3.2" />
        <vers num="6.5" edition="sr3.2:windows" />
        <vers num="6.5" edition="sr3.3" />
        <vers num="6.5" edition="sr3.3:windows" />
        <vers num="6.5_win_sr3.1" />
        <vers num="6.5_win_sr3.10" />
        <vers num="6.5_win_sr3.4" />
        <vers num="6.5_win_sr3.5" />
        <vers num="6.5_win_sr3.6" />
        <vers num="6.5_win_sr3.7" />
        <vers num="6.5_win_sr3.8" />
        <vers num="6.5_win_sr3.9" />
        <vers num="7.0" edition="xpu22.1" />
        <vers num="7.0" edition="xpu22.10" />
        <vers num="7.0" edition="xpu22.11" />
        <vers num="7.0" edition="xpu22.2" />
        <vers num="7.0" edition="xpu22.3" />
        <vers num="7.0" edition="xpu22.4" />
        <vers num="7.0" edition="xpu22.5" />
        <vers num="7.0" edition="xpu22.6" />
        <vers num="7.0" edition="xpu22.7" />
        <vers num="7.0" edition="xpu22.8" />
        <vers num="7.0" edition="xpu22.9" />
      </prod>
      <prod vendor="iss" name="proventia_a_series_xpu">
        <vers num="20.11" />
        <vers num="22.1" />
        <vers num="22.10" />
        <vers num="22.2" />
        <vers num="22.3" />
        <vers num="22.4" />
        <vers num="22.5" />
        <vers num="22.6" />
        <vers num="22.7" />
        <vers num="22.8" />
        <vers num="22.9" />
      </prod>
      <prod vendor="iss" name="proventia_g_series_xpu">
        <vers num="22.1" />
        <vers num="22.10" />
        <vers num="22.11" />
        <vers num="22.2" />
        <vers num="22.3" />
        <vers num="22.4" />
        <vers num="22.5" />
        <vers num="22.6" />
        <vers num="22.7" />
        <vers num="22.8" />
        <vers num="22.9" />
      </prod>
      <prod vendor="iss" name="proventia_m_series_xpu">
        <vers num="1.1" />
        <vers num="1.2" />
        <vers num="1.3" />
        <vers num="1.4" />
        <vers num="1.5" />
        <vers num="1.6" />
        <vers num="1.7" />
        <vers num="1.8" />
        <vers num="1.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0363" published="2004-04-15" name="CVE-2004-0363" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Stack-based buffer overflow in the SymSpamHelper ActiveX component (symspam.dll) in Norton AntiSpam 2004, as used in Norton Internet Security 2004, allows remote attackers to execute arbitrary code via a long parameter to the LaunchCustomRuleWizard method.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/344718" source="CERT-VN">VU#344718</ref>
      <ref url="http://www.nextgenss.com/advisories/antispam.txt" source="MISC" patch="1" adv="1">http://www.nextgenss.com/advisories/antispam.txt</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15536" source="XF" adv="1">nas-launchcustomrulewizard-bo(15536)</ref>
      <ref url="http://www.securityfocus.com/bid/9916" source="BID" adv="1">9916</ref>
      <ref url="http://www.sarc.com/avcenter/security/Content/2004.03.19.html" source="CONFIRM">http://www.sarc.com/avcenter/security/Content/2004.03.19.html</ref>
      <ref url="http://secunia.com/advisories/11169" source="SECUNIA">11169</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107970870606638&amp;w=2" source="BUGTRAQ" adv="1">20040319 Norton AntiSpam Remote Buffer Overrun (#NISR19042004a)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107980262324362&amp;w=2" source="BUGTRAQ">20040319 Ref: NGSSoftware Advisories NISR19042004a and NISR19042004b</ref>
    </refs>
    <vuln_soft>
      <prod vendor="symantec" name="norton_antispam">
        <vers num="2004" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0364" published="2004-04-15" name="CVE-2004-0364" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">The WrapNISUM ActiveX component (WrapUM.dll) in Norton Internet Security 2004 is marked safe for scripting, which allows remote attackers to execute arbitrary programs via the LaunchURL method.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/549054" source="CERT-VN">VU#549054</ref>
      <ref url="http://www.nextgenss.com/advisories/nisrce.txt" source="MISC" patch="1" adv="1">http://www.nextgenss.com/advisories/nisrce.txt</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15538" source="XF" adv="1">norton-is-launchurl-command-execution(15538)</ref>
      <ref url="http://www.securityfocus.com/bid/9915" source="BID" adv="1">9915</ref>
      <ref url="http://www.sarc.com/avcenter/security/Content/2004.03.19.html" source="CONFIRM">http://www.sarc.com/avcenter/security/Content/2004.03.19.html</ref>
      <ref url="http://secunia.com/advisories/11168" source="SECUNIA">11168</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107970885922442&amp;w=2" source="BUGTRAQ" adv="1">20040319 Norton Internet Security Remote Command Execution (#NISR19042004b)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107980262324362&amp;w=2" source="BUGTRAQ">20040319 Ref: NGSSoftware Advisories NISR19042004a and NISR19042004b</ref>
    </refs>
    <vuln_soft>
      <prod vendor="symantec" name="norton_internet_security">
        <vers num="2004" edition="" />
        <vers num="2004" edition=":professional" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0365" published="2004-05-04" name="CVE-2004-0365" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The dissect_attribute_value_pairs function in packet-radius.c for Ethereal 0.8.13 to 0.10.2 allows remote attackers to cause a denial of service (crash) via a malformed RADIUS packet that triggers a null dereference.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/124454" source="CERT-VN">VU#124454</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108058005324316&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20040329 LNSA-#2004-0007: Multiple security problems in Ethereal</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15571" source="XF" adv="1">ethereal-radius-dos(15571)</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-137.html" source="REDHAT">RHSA-2004:137</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-136.html" source="REDHAT">RHSA-2004:136</ref>
      <ref url="http://www.ethereal.com/appnotes/enpa-sa-00013.html" source="CONFIRM">http://www.ethereal.com/appnotes/enpa-sa-00013.html</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200403-07.xml" source="GENTOO" adv="1">GLSA-200403-07</ref>
      <ref url="http://secunia.com/advisories/11185" source="SECUNIA">11185</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9196" source="OVAL">oval:org.mitre.oval:def:9196</ref>
      <ref url="http://marc.theaimsgroup.com/?l=ethereal-dev&amp;m=107962966700423&amp;w=2" source="MLIST" adv="1">[ethereal-dev] 20040318 ethereal radius dissector vulnerability</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2004:024" source="MANDRAKE">MDKSA-2004:024</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108213710306260&amp;w=2" source="BUGTRAQ">20040416 [OpenPKG-SA-2004.015] OpenPKG Security Advisory (ethereal)</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000835" source="CONECTIVA">CLA-2004:835</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:891" source="OVAL" sig="1">oval:org.mitre.oval:def:891</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:879" source="OVAL" sig="1">oval:org.mitre.oval:def:879</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ethereal_group" name="ethereal">
        <vers num="0.10" />
        <vers num="0.10.1" />
        <vers num="0.10.2" />
        <vers num="0.8.13" />
        <vers num="0.8.14" />
        <vers num="0.8.18" />
        <vers num="0.8.19" />
        <vers num="0.9" />
        <vers num="0.9.1" />
        <vers num="0.9.10" />
        <vers num="0.9.11" />
        <vers num="0.9.12" />
        <vers num="0.9.13" />
        <vers num="0.9.14" />
        <vers num="0.9.15" />
        <vers num="0.9.16" />
        <vers num="0.9.2" />
        <vers num="0.9.3" />
        <vers num="0.9.4" />
        <vers num="0.9.5" />
        <vers num="0.9.6" />
        <vers num="0.9.7" />
        <vers num="0.9.8" />
        <vers num="0.9.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0366" published="2004-05-04" name="CVE-2004-0366" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in the libpam-pgsql library before 0.5.2 allows attackers to execute arbitrary SQL statements.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/15651" source="XF" patch="1" adv="1">pam-pgsql-sql-injection(15651)</ref>
      <ref url="http://www.debian.org/security/2004/dsa-469" source="DEBIAN" patch="1" adv="1">DSA-469</ref>
      <ref url="http://www.securityfocus.com/bid/10266" source="BID">10266</ref>
      <ref url="http://secunia.com/advisories/11237" source="SECUNIA">11237</ref>
    </refs>
    <vuln_soft>
      <prod vendor="leon_j_breedt" name="pam-pgsql">
        <vers prev="1" num="0.5.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0367" published="2004-05-04" name="CVE-2004-0367" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Ethereal 0.10.1 to 0.10.2 allows remote attackers to cause a denial of service (crash) via a zero-length Presentation protocol selector.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/792286" source="CERT-VN">VU#792286</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-137.html" source="REDHAT" patch="1" adv="1">RHSA-2004:137</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15570" source="XF" adv="1">ethereal-zero-presentation-dos(15570)</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-136.html" source="REDHAT">RHSA-2004:136</ref>
      <ref url="http://www.ethereal.com/lists/ethereal-dev/200404/msg00296.html" source="MLIST">[Ethereal-dev] 20040416 Possibly incorrect CVE entry CAN-2004-0367</ref>
      <ref url="http://www.ethereal.com/appnotes/enpa-sa-00013.html" source="CONFIRM">http://www.ethereal.com/appnotes/enpa-sa-00013.html</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200403-07.xml" source="GENTOO">GLSA-200403-07</ref>
      <ref url="http://secunia.com/advisories/11185" source="SECUNIA">11185</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11071" source="OVAL">oval:org.mitre.oval:def:11071</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108058005324316&amp;w=2" source="BUGTRAQ" adv="1">20040329 LNSA-#2004-0007: Multiple security problems in Ethereal</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000835" source="CONECTIVA" adv="1">CLA-2004:835</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2004:024" source="MANDRAKE">MDKSA-2004:024</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:905" source="OVAL" sig="1">oval:org.mitre.oval:def:905</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:880" source="OVAL" sig="1">oval:org.mitre.oval:def:880</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ethereal_group" name="ethereal">
        <vers num="0.10" />
        <vers num="0.10.1" />
        <vers num="0.10.2" />
        <vers num="0.8.13" />
        <vers num="0.8.14" />
        <vers num="0.8.18" />
        <vers num="0.8.19" />
        <vers num="0.9" />
        <vers num="0.9.1" />
        <vers num="0.9.10" />
        <vers num="0.9.11" />
        <vers num="0.9.12" />
        <vers num="0.9.13" />
        <vers num="0.9.14" />
        <vers num="0.9.15" />
        <vers num="0.9.16" />
        <vers num="0.9.2" />
        <vers num="0.9.3" />
        <vers num="0.9.4" />
        <vers num="0.9.5" />
        <vers num="0.9.6" />
        <vers num="0.9.7" />
        <vers num="0.9.8" />
        <vers num="0.9.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0368" published="2004-05-04" name="CVE-2004-0368" modified="2008-09-10" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Double free vulnerability in dtlogin in CDE on Solaris, HP-UX, and other operating systems allows remote attackers to execute arbitrary code via a crafted XDMCP packet.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input />
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/179804" source="CERT-VN" adv="1">VU#179804</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15581" source="XF" adv="1">cde-dtlogin-double-free(15581)</ref>
      <ref url="http://www.securityfocus.com/bid/9958" source="BID">9958</ref>
      <ref url="http://www.immunitysec.com/downloads/dtlogin.sxw.pdf" source="MISC">http://www.immunitysec.com/downloads/dtlogin.sxw.pdf</ref>
      <ref url="http://www.ciac.org/ciac/bulletins/o-129.shtml" source="CIAC">O-129</ref>
      <ref url="http://www.auscert.org.au/render.html?it=4103&amp;cid=3734" source="HP">HPSBUX01038</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-57539-1&amp;searchclause=security" source="SUNALERT">57539</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-101478-1" source="SUNALERT">101478</ref>
      <ref url="http://secunia.com/advisories/11614/" source="SECUNIA" adv="1">11614</ref>
      <ref url="http://secunia.com/advisories/11495/" source="SECUNIA" adv="1">11495</ref>
      <ref url="http://secunia.com/advisories/11214/" source="SECUNIA" adv="1">11214</ref>
      <ref url="http://secunia.com/advisories/11210/" source="SECUNIA" adv="1">11210</ref>
      <ref url="http://lists.immunitysec.com/pipermail/dailydave/2004-March/000402.html" source="MLIST" adv="1">[Dailydave] 20040323 dtlogin advisory</ref>
      <ref url="http://archives.neohapsis.com/archives/vulnwatch/2004-q1/0064.html" source="VULNWATCH" adv="1">20040323 how much fun can you have with UDP?</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/20040801-01-P" source="SGI">20040801-01-P</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1436" source="OVAL" sig="1">oval:org.mitre.oval:def:1436</ref>
    </refs>
    <vuln_soft>
      <prod vendor="open_group" name="cde_common_desktop_environment">
        <vers num="1.0.1" />
        <vers num="1.0.2" />
        <vers num="1.1" />
        <vers num="1.2" />
        <vers num="2.0" />
        <vers num="2.1" />
        <vers num="2.1.20" />
      </prod>
      <prod vendor="xi_graphics" name="dextop">
        <vers num="2.1" />
        <vers num="3.0" />
      </prod>
      <prod vendor="ibm" name="aix">
        <vers num="4.3.3" />
        <vers num="5.1" />
        <vers num="5.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0369" published="2004-12-31" name="CVE-2004-0369" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in Entrust LibKmp ISAKMP library, as used by Symantec Enterprise Firewall 7.0 through 8.0, Gateway Security 5300 1.0, Gateway Security 5400 2.0, and VelociRaptor 1.5, allows remote attackers to execute arbitrary code via a crafted ISAKMP payload.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/15669" source="XF" patch="1">isakmp-spi-size-bo(15669)</ref>
      <ref url="http://xforce.iss.net/xforce/alerts/id/181" source="ISS" patch="1" adv="1">20040826 Entrust LibKmp Library Buffer Overflow</ref>
      <ref url="http://www.securityfocus.com/bid/11039" source="BID">11039</ref>
      <ref url="http://www.ciac.org/ciac/bulletins/o-206.shtml" source="CIAC" adv="1">O-206</ref>
      <ref url="http://www.auscert.org.au/render.html?it=4339" source="AUSCERT" adv="1">ESB-2004.0538</ref>
      <ref url="http://securityresponse.symantec.com/avcenter/security/Content/2004.08.26.html" source="CONFIRM" adv="1">http://securityresponse.symantec.com/avcenter/security/Content/2004.08.26.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="entrust" name="entrust_libkmp_isakmp_library">
        <vers num="" />
      </prod>
      <prod vendor="symantec" name="enterprise_firewall">
        <vers num="7.0" edition="" />
        <vers num="7.0" edition=":solaris" />
        <vers num="7.0.4" edition="" />
        <vers num="7.0.4" edition=":solaris" />
        <vers num="7.0.4" edition=":windows_2000_nt" />
        <vers num="8.0" edition="" />
        <vers num="8.0" edition=":solaris" />
        <vers num="8.0" edition=":windows_2000_nt" />
      </prod>
      <prod vendor="symantec" name="velociraptor">
        <vers num="1.5" />
      </prod>
      <prod vendor="symantec" name="gateway_security_5300">
        <vers num="1.0" />
      </prod>
      <prod vendor="symantec" name="gateway_security_5400">
        <vers num="2.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2004-0370" published="2004-05-04" name="CVE-2004-0370" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">The setsockopt call in the KAME Project IPv6 implementation, as used in FreeBSD 5.2, does not properly handle certain IPv6 socket options, which could allow attackers to read kernel memory and cause a system panic.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/15662" source="XF" patch="1" adv="1">freebsd-ipv6-dos(15662)</ref>
      <ref url="http://www.securityfocus.com/bid/9992" source="BID">9992</ref>
      <ref url="http://secunia.com/advisories/11233" source="SECUNIA">11233</ref>
      <ref url="ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-04:06.ipv6.asc" source="FREEBSD">FreeBSD-SA-04:06</ref>
    </refs>
    <vuln_soft>
      <prod vendor="freebsd" name="freebsd">
        <vers num="5.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0371" published="2004-05-04" name="CVE-2004-0371" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Heimdal 0.6.x before 0.6.1 and 0.5.x before 0.5.3 does not properly perform certain consistency checks for cross-realm requests, which allows remote attackers with control of a realm to impersonate others in the cross-realm trust path.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/15701" source="XF" patch="1" adv="1">heimdal-cross-realm-spoofing(15701)</ref>
      <ref url="http://www.debian.org/security/2004/dsa-476" source="DEBIAN" patch="1" adv="1">DSA-476</ref>
      <ref url="http://www.pdc.kth.se/heimdal/advisory/2004-04-01/" source="CONFIRM">http://www.pdc.kth.se/heimdal/advisory/2004-04-01/</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200404-09.xml" source="GENTOO" adv="1">GLSA-200404-09</ref>
      <ref url="ftp://ftp.openbsd.org/pub/OpenBSD/patches/3.5/common/009_kerberos.patch" source="OPENBSD">20040530 009: SECURITY FIX: May 30, 2004</ref>
      <ref url="ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-04:08.heimdal.asc" source="FREEBSD">FreeBSD-SA-04:08</ref>
    </refs>
    <vuln_soft>
      <prod vendor="kth" name="heimdal">
        <vers num="0.4a" />
        <vers num="0.4b" />
        <vers num="0.4c" />
        <vers num="0.4d" />
        <vers num="0.4e" />
        <vers num="0.5" />
        <vers num="0.5.1" />
        <vers num="0.5.2" />
        <vers num="0.6.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2004-0372" published="2004-04-15" name="CVE-2004-0372" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">xine allows local users to overwrite arbitrary files via a symlink attack on a bug report email that is generated by the (1) xine-bugreport or (2) xine-check scripts.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/15564" source="XF" patch="1" adv="1">xine-xinebugreport-xinecheck-symlink(15564)</ref>
      <ref url="http://www.debian.org/security/2004/dsa-477" source="DEBIAN" patch="1" adv="1">DSA-477</ref>
      <ref url="http://www.securityfocus.com/bid/9939" source="BID" adv="1">9939</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200404-20.xml" source="GENTOO">GLSA-200404-20</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107997911025558&amp;w=2" source="BUGTRAQ" adv="1">20040320 xine-check/xine-bugreport symlink vulnerability.</ref>
    </refs>
    <vuln_soft>
      <prod vendor="xine" name="xine">
        <vers num="0.9.13" />
        <vers num="1_beta1" />
        <vers num="1_beta10" />
        <vers num="1_beta11" />
        <vers num="1_beta12" />
        <vers num="1_beta2" />
        <vers num="1_beta3" />
        <vers num="1_beta4" />
        <vers num="1_beta5" />
        <vers num="1_beta6" />
        <vers num="1_beta7" />
        <vers num="1_beta8" />
        <vers num="1_beta9" />
        <vers num="1_rc0a" />
        <vers num="1_rc1" />
        <vers num="1_rc2" />
        <vers num="1_rc3" />
        <vers num="1_rc3a" />
        <vers num="1_rc3b" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0374" published="2004-05-04" name="CVE-2004-0374" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)" CVSS_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_base_score="6.4">
    <desc>
      <descript source="cve">Interchange before 5.0.1 allows remote attackers to "expose the content of arbitrary variables" and read or modify sensitive SQL information via an HTTP request ending with the "__SQLUSER__" string.</descript>
    </desc>
    <loss_types>
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <other />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/15670" source="XF" patch="1" adv="1">interchange-url-obtain-information(15670)</ref>
      <ref url="http://www.debian.org/security/2004/dsa-471" source="DEBIAN" patch="1" adv="1">DSA-471</ref>
      <ref url="http://www.securityfocus.com/bid/10005" source="BID">10005</ref>
      <ref url="http://secunia.com/advisories/11234" source="SECUNIA">11234</ref>
      <ref url="http://ftp.icdevgroup.org/interchange/5.0/WHATSNEW" source="CONFIRM">http://ftp.icdevgroup.org/interchange/5.0/WHATSNEW</ref>
      <ref url="http://www.icdevgroup.org/pipermail/interchange-announce/2004/000043.html" source="MLIST">[interchange-announce] 20040329 Security Problem in Interchange</ref>
    </refs>
    <vuln_soft>
      <prod vendor="interchange_development_group" name="interchange">
        <vers num="4.8.1" />
        <vers num="4.8.2" />
        <vers num="4.8.3" />
        <vers num="4.8.4" />
        <vers num="4.8.5" />
        <vers num="4.8.6" />
        <vers num="4.8.7" />
        <vers num="4.8.8" />
        <vers num="4.8.9" />
        <vers num="5.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0375" published="2004-08-18" name="CVE-2004-0375" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">SYMNDIS.SYS in Symantec Norton Internet Security 2003 and 2004, Norton Personal Firewall 2003 and 2004, Client Firewall 5.01 and 5.1.1, and Client Security 1.0 and 1.1 allow remote attackers to cause a denial of service (infinite loop) via a TCP packet with (1) SACK option or (2) Alternate Checksum Data option followed by a length of zero.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/15936" source="XF" adv="1">symantec-firewall-tcp-dos(15936)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15433" source="XF">norton-firewalls-dos(15433)</ref>
      <ref url="http://www.symantec.com/avcenter/security/Content/2004.04.20.html" source="CONFIRM">http://www.symantec.com/avcenter/security/Content/2004.04.20.html</ref>
      <ref url="http://www.securityfocus.com/bid/9912" source="BID" adv="1">9912</ref>
      <ref url="http://www.eeye.com/html/Research/Upcoming/20040309.html" source="MISC">http://www.eeye.com/html/Research/Upcoming/20040309.html</ref>
      <ref url="http://securitytracker.com/id?1009380" source="SECTRACK">1009380</ref>
      <ref url="http://securitytracker.com/id?1009379" source="SECTRACK">1009379</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108275582432246&amp;w=2" source="BUGTRAQ">20040423 EEYE: Symantec Multiple Firewall TCP Options Denial of Service</ref>
    </refs>
    <vuln_soft>
      <prod vendor="symantec" name="client_firewall">
        <vers num="5.01" />
        <vers num="5.1.1" />
      </prod>
      <prod vendor="symantec" name="client_security">
        <vers num="1.0" />
        <vers num="1.1" />
      </prod>
      <prod vendor="symantec" name="norton_internet_security">
        <vers num="2003" edition="" />
        <vers num="2003" edition=":pro" />
        <vers num="2004" edition="" />
        <vers num="2004" edition=":pro" />
      </prod>
      <prod vendor="symantec" name="norton_personal_firewall">
        <vers num="2003" />
        <vers num="2004" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0376" published="2004-05-04" name="CVE-2004-0376" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">oftpd 0.3.6 and earlier allows remote attackers to cause a denial of service (crash) via a PORT command with a large value.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/9980" source="BID" patch="1" adv="1">9980</ref>
      <ref url="http://www.debian.org/security/2004/dsa-473" source="DEBIAN" patch="1" adv="1">DSA-473</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15622" source="XF" adv="1">oftpd-port-dos(15622)</ref>
      <ref url="http://www.time-travellers.org/oftpd/oftpd-dos.html" source="CONFIRM">http://www.time-travellers.org/oftpd/oftpd-dos.html</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200403-08.xml" source="GENTOO">GLSA-200403-08</ref>
      <ref url="http://secunia.com/advisories/11220" source="SECUNIA">11220</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oftpd" name="oftpd">
        <vers prev="1" num="0.3.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0377" published="2004-05-04" name="CVE-2004-0377" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Buffer overflow in the win32_stat function for (1) ActiveState's ActivePerl and (2) Larry Wall's Perl before 5.8.3 allows local or remote attackers to execute arbitrary commands via filenames that end in a backslash character.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/722414" source="CERT-VN" patch="1" adv="1">VU#722414</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15732" source="XF" patch="1" adv="1">perl-win32stat-bo(15732)</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2004-April/019794.html" source="FULLDISC" patch="1" adv="1">20040405 iDEFENSE Security Advisory 04.05.04: Perl win32_stat Function</ref>
      <ref url="http://public.activestate.com/cgi-bin/perlbrowse?patch=22552" source="CONFIRM">http://public.activestate.com/cgi-bin/perlbrowse?patch=22552</ref>
      <ref url="http://www.idefense.com/application/poi/display?id=93&amp;type=vulnerabilities" source="MISC">http://www.idefense.com/application/poi/display?id=93&amp;type=vulnerabilities</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108118694327979&amp;w=2" source="BUGTRAQ">20040405 [Full-Disclosure] iDEFENSE Security Advisory 04.05.04: Perl win32_stat Function</ref>
    </refs>
    <vuln_soft>
      <prod vendor="activestate" name="activeperl">
        <vers num="" />
      </prod>
      <prod vendor="larry_wall" name="perl">
        <vers prev="1" num="5.8.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0379" published="2004-05-04" name="CVE-2004-0379" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in Microsoft SharePoint Portal Server 2001 allow remote attackers to process arbitrary web content and steal cookies via certain server scripts.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108118352303273&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20040405 Multiple XSS vulnerabilities in Microsoft SharePoint Portal Server 2001</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15729" source="XF" adv="1">sharepoint-portal-xss(15729)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="sharepoint_portal_server">
        <vers num="2001" edition="sp1" />
        <vers num="2001" edition="sp2" />
        <vers num="2001" edition="sp2a" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0380" published="2004-05-04" name="CVE-2004-0380" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">The MHTML protocol handler in Microsoft Outlook Express 5.5 SP2 through Outlook Express 6 SP1 allows remote attackers to bypass domain restrictions and execute arbitrary code, as demonstrated on Internet Explorer using script in a compiled help (CHM) file that references the InfoTech Storage (ITS) protocol handlers such as (1) ms-its, (2) ms-itss, (3) its, or (4) mk:@MSITStore, aka the "MHTML URL Processing Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/323070" source="CERT-VN">VU#323070</ref>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA04-104A.html" source="CERT">TA04-104A</ref>
      <ref url="http://www.securityfocus.com/archive/1/358913" source="BUGTRAQ" patch="1" adv="1">20040328 IE ms-its: and mk:@MSITStore: vulnerability</ref>
      <ref url="http://www.securityfocus.com/archive/1/354447" source="BUGTRAQ" patch="1" adv="1">20040219 Microsoft Internet Explorer Unspecified CHM File Processing Arbitrary Code Execution Vulnerability (bid 9658)</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/MS04-013.mspx" source="MS" patch="1" adv="1">MS04-013</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15705" source="XF" adv="1">outlook-mhtml-execute-code(15705)</ref>
      <ref url="http://www.securityfocus.com/bid/9658" source="BID">9658</ref>
      <ref url="http://www.k-otik.net/bugtraq/02.18.InternetExplorer.php" source="MISC">http://www.k-otik.net/bugtraq/02.18.InternetExplorer.php</ref>
      <ref url="http://www.securityfocus.com/bid/9105" source="BID">9105</ref>
      <ref url="http://secunia.com/advisories/10523" source="SECUNIA">10523</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:990" source="OVAL" sig="1">oval:org.mitre.oval:def:990</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:882" source="OVAL" sig="1">oval:org.mitre.oval:def:882</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1028" source="OVAL" sig="1">oval:org.mitre.oval:def:1028</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1010" source="OVAL" sig="1">oval:org.mitre.oval:def:1010</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="outlook_express">
        <vers num="5.5" />
        <vers num="6.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2004-0381" published="2004-05-04" name="CVE-2004-0381" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">mysqlbug in MySQL allows local users to overwrite arbitrary files via a symlink attack on the failed-mysql-bugreport temporary file.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/9976" source="BID" patch="1" adv="1">9976</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108206802810402&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20040414 [OpenPKG-SA-2004.014] OpenPKG Security Advisory (mysql)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15617" source="XF" adv="1">mysql-mysqlbug-symlink(15617)</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-597.html" source="REDHAT">RHSA-2004:597</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-569.html" source="REDHAT">RHSA-2004:569</ref>
      <ref url="http://www.debian.org/security/2004/dsa-483" source="DEBIAN">DSA-483</ref>
      <ref url="http://www.ciac.org/ciac/bulletins/p-018.shtml" source="CIAC">P-018</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200405-20.xml" source="GENTOO">GLSA-200405-20</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11557" source="OVAL">oval:org.mitre.oval:def:11557</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108023246916294&amp;w=2" source="BUGTRAQ">20040324 mysqlbug tmpfile/symlink vulnerability.</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2004:034" source="MANDRAKE">MDKSA-2004:034</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mysql" name="mysql">
        <vers num="3.20.32a" />
        <vers num="3.22.26" />
        <vers num="3.22.27" />
        <vers num="3.22.28" />
        <vers num="3.22.29" />
        <vers num="3.22.30" />
        <vers num="3.22.32" />
        <vers num="3.23.10" />
        <vers num="3.23.2" />
        <vers num="3.23.22" />
        <vers num="3.23.23" />
        <vers num="3.23.24" />
        <vers num="3.23.25" />
        <vers num="3.23.26" />
        <vers num="3.23.27" />
        <vers num="3.23.28" edition="gamma" />
        <vers num="3.23.29" />
        <vers num="3.23.3" />
        <vers num="3.23.30" />
        <vers num="3.23.31" />
        <vers num="3.23.32" />
        <vers num="3.23.33" />
        <vers num="3.23.34" />
        <vers num="3.23.36" />
        <vers num="3.23.37" />
        <vers num="3.23.38" />
        <vers num="3.23.39" />
        <vers num="3.23.40" />
        <vers num="3.23.41" />
        <vers num="3.23.42" />
        <vers num="3.23.43" />
        <vers num="3.23.44" />
        <vers num="3.23.45" />
        <vers num="3.23.46" />
        <vers num="3.23.47" />
        <vers num="3.23.48" />
        <vers num="3.23.49" />
        <vers num="3.23.5" />
        <vers num="3.23.50" />
        <vers num="3.23.51" />
        <vers num="3.23.52" />
        <vers num="3.23.53" />
        <vers num="3.23.53a" />
        <vers num="3.23.54" />
        <vers num="3.23.54a" />
        <vers num="3.23.55" />
        <vers num="3.23.56" />
        <vers num="3.23.58" />
        <vers num="3.23.8" />
        <vers num="3.23.9" />
        <vers num="4.0.0" />
        <vers num="4.0.1" />
        <vers num="4.0.10" />
        <vers num="4.0.11" edition="gamma" />
        <vers num="4.0.12" />
        <vers num="4.0.13" />
        <vers num="4.0.14" />
        <vers num="4.0.15" />
        <vers num="4.0.18" />
        <vers num="4.0.2" />
        <vers num="4.0.3" />
        <vers num="4.0.4" />
        <vers num="4.0.5" />
        <vers num="4.0.5a" />
        <vers num="4.0.6" />
        <vers num="4.0.7" edition="gamma" />
        <vers num="4.0.8" edition="gamma" />
        <vers num="4.0.9" edition="gamma" />
        <vers num="4.1.0" edition="alpha" />
        <vers num="4.1.0.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0382" published="2004-05-04" name="CVE-2004-0382" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Unknown vulnerability in the CUPS printing system in Mac OS X 10.3.3 and Mac OS X 10.2.8 with unknown impact, possibly related to a configuration file setting.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <config />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/15769" source="XF" patch="1" adv="1">macos-cups-configuration-unknown(15769)</ref>
      <ref url="http://lists.apple.com/mhonarc/security-announce/msg00047.html" source="CONFIRM">http://lists.apple.com/mhonarc/security-announce/msg00047.html</ref>
      <ref url="http://docs.info.apple.com/article.html?artnum=61798" source="CONFIRM">http://docs.info.apple.com/article.html?artnum=61798</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.2.8" />
        <vers num="10.3.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0383" published="2004-05-04" name="CVE-2004-0383" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Unknown vulnerability in Mail for Mac OS X 10.3.3 and 10.2.8, with unknown impact, related to "the handling of HTML-formatted email."</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/15768" source="XF" patch="1" adv="1">macos-mail-unknown(15768)</ref>
      <ref url="http://lists.apple.com/mhonarc/security-announce/msg00047.html" source="CONFIRM">http://lists.apple.com/mhonarc/security-announce/msg00047.html</ref>
      <ref url="http://docs.info.apple.com/article.html?artnum=61798" source="CONFIRM">http://docs.info.apple.com/article.html?artnum=61798</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.2.8" />
        <vers num="10.3.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0385" published="2004-06-01" name="CVE-2004-0385" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Heap-based buffer overflow in Oracle 9i Application Server Web Cache 9.0.4.0.0, 9.0.3.1.0, 9.0.2.3.0, and 9.0.0.4.0 allows remote attackers to execute arbitrary code via a long HTTP request method header to the Web Cache listener.  NOTE: due to the vagueness of the Oracle advisory, it is not clear whether there are additional issues besides this overflow, although the advisory alludes to multiple "vulnerabilities."</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" other="1" admin="1" />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/413006" source="CERT-VN" patch="1" adv="1">VU#413006</ref>
      <ref url="http://otn.oracle.com/deploy/security/pdf/2004alert66.pdf" source="CONFIRM" patch="1" adv="1">http://otn.oracle.com/deploy/security/pdf/2004alert66.pdf</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15463" source="XF">oracle-web-cache-vulnerabilities(15463)</ref>
      <ref url="http://www.securityfocus.com/bid/9868" source="BID">9868</ref>
      <ref url="http://www.inaccessnetworks.com/ian/services/secadv01.txt" source="MISC" adv="1">http://www.inaccessnetworks.com/ian/services/secadv01.txt</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107945649127635&amp;w=2" source="BUGTRAQ">20040316 new security alert #66 issued in Oracle web cache</ref>
      <ref url="http://archives.neohapsis.com/archives/vulnwatch/2004-q1/0078.html" source="VULNWATCH">20040408 Heap Overflow in Oracle 9iAS / 10g Application Server Web Cache</ref>
      <ref url="http://www.osvdb.org/4249" source="OSVDB">4249</ref>
      <ref url="http://secunia.com/advisories/11118" source="SECUNIA">11118</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108144419001770&amp;w=2" source="BUGTRAQ">20040408 Heap Overflow in Oracle 9iAS / 10g Application Server Web Cache</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="application_server_web_cache">
        <vers num="9.0.0.4.0" />
        <vers num="9.0.2.3.0" />
        <vers num="9.0.3.1.0" />
        <vers num="9.0.4.0.0" />
      </prod>
      <prod vendor="oracle" name="e-business_suite">
        <vers num="11i" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0386" published="2004-05-04" name="CVE-2004-0386" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Buffer overflow in the HTTP parser for MPlayer 1.0pre3 and earlier, 0.90, and 0.91 allows remote attackers to execute arbitrary code via a long Location header.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/723910" source="CERT-VN" patch="1" adv="1">VU#723910</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15675" source="XF" patch="1">mplayer-header-bo(15675)</ref>
      <ref url="http://www.securityfocus.com/bid/10008" source="BID" patch="1">10008</ref>
      <ref url="http://www.securityfocus.com/archive/1/359025" source="BUGTRAQ" patch="1" adv="1">20040330 Heap overflow in MPlayer</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200403-13.xml" source="GENTOO" patch="1" adv="1">GLSA-200403-13</ref>
      <ref url="http://secunia.com/advisories/11259" source="SECUNIA" patch="1" adv="1">11259</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108067020624076&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20040330 MPlayer Security Advisory #002 - HTTP parsing vulnerability</ref>
      <ref url="http://www.mplayerhq.hu/homepage/design6/news.html" source="CONFIRM">http://www.mplayerhq.hu/homepage/design6/news.html</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2004:026" source="MANDRAKE">MDKSA-2004:026</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mplayer" name="mplayer">
        <vers num="0.90" />
        <vers num="0.90_pre" />
        <vers num="0.90_rc" />
        <vers num="0.91" />
        <vers num="1.0_pre1" />
        <vers num="1.0_pre2" />
        <vers num="1.0_pre3" />
      </prod>
      <prod vendor="gentoo" name="linux">
        <vers num="0.5" />
        <vers num="0.7" />
        <vers num="1.1a" />
        <vers num="1.2" />
        <vers num="1.4" edition="rc1" />
        <vers num="1.4" edition="rc2" />
        <vers num="1.4" edition="rc3" />
      </prod>
      <prod vendor="mandrakesoft" name="mandrake_linux">
        <vers num="10.0" />
        <vers num="9.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0387" published="2004-06-01" name="CVE-2004-0387" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_score="5.1" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="4.9" CVSS_base_score="5.1">
    <desc>
      <descript source="cve">Stack-based buffer overflow in the RT3 plugin, as used in RealPlayer 8, RealOne Player, RealOne Player 10 beta, and RealOne Player Enterprise, allows remote attackers to execute arbitrary code via a malformed .R3T file.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/15774" source="XF" patch="1" adv="1">realplayer-r3t-bo(15774)</ref>
      <ref url="http://www.service.real.com/help/faq/security/040406_r3t/en/" source="CONFIRM" patch="1" adv="1">http://www.service.real.com/help/faq/security/040406_r3t/en/</ref>
      <ref url="http://www.ngssoftware.com/advisories/realr3t.txt" source="MISC" patch="1" adv="1">http://www.ngssoftware.com/advisories/realr3t.txt</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108135350810135&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20040307 REAL One Player R3T File Format Stack Overflow</ref>
      <ref url="http://www.securityfocus.com/bid/10070" source="BID">10070</ref>
      <ref url="http://www.osvdb.org/displayvuln.php?osvdb_id=4977" source="OSVDB">4977</ref>
      <ref url="http://secunia.com/advisories/11314" source="SECUNIA">11314</ref>
      <ref url="http://archives.neohapsis.com/archives/vulnwatch/2004-q1/0077.html" source="VULNWATCH">20040307 REAL One Player R3T File Format Stack Overflow</ref>
    </refs>
    <vuln_soft>
      <prod vendor="realnetworks" name="realone_player">
        <vers num="" edition=":enterprise" />
        <vers num="10_beta" />
      </prod>
      <prod vendor="realnetworks" name="realplayer">
        <vers num="8.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2004-0388" published="2004-06-01" name="CVE-2004-0388" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">The mysqld_multi script in MySQL allows local users to overwrite arbitrary files via a symlink attack.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <env />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.debian.org/security/2004/dsa-483" source="DEBIAN" patch="1" adv="1">DSA-483</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15883" source="XF">mysql-mysqldmulti-symlink(15883)</ref>
      <ref url="http://www.securityfocus.com/bid/10142" source="BID">10142</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-597.html" source="REDHAT">RHSA-2004:597</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-569.html" source="REDHAT">RHSA-2004:569</ref>
      <ref url="http://www.osvdb.org/6421" source="OSVDB">6421</ref>
      <ref url="http://www.ciac.org/ciac/bulletins/p-018.shtml" source="CIAC">P-018</ref>
      <ref url="http://securitytracker.com/id?1009784" source="SECTRACK">1009784</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200405-20.xml" source="GENTOO" adv="1">GLSA-200405-20</ref>
      <ref url="http://secunia.com/advisories/11223/" source="SECUNIA">11223</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10559" source="OVAL">oval:org.mitre.oval:def:10559</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108206802810402&amp;w=2" source="BUGTRAQ">20040414 [OpenPKG-SA-2004.014] OpenPKG Security Advisory (mysql)</ref>
      <ref url="http://dev.mysql.com/doc/mysql/en/news-4-1-2.html" source="CONFIRM">http://dev.mysql.com/doc/mysql/en/news-4-1-2.html</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2004:034" source="MANDRAKE">MDKSA-2004:034</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mysql" name="mysql">
        <vers num="5.0.33" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0389" published="2004-06-01" name="CVE-2004-0389" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">RealNetworks Helix Universal Server 9.0.1 and 9.0.2 allows remote attackers to cause a denial of service (crash) via malformed requests that trigger a null dereference, as demonstrated using (1) GET_PARAMETER or (2) DESCRIBE requests.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.idefense.com/application/poi/display?id=102&amp;type=vulnerabilities" source="IDEFENSE" patch="1" adv="1">20040415 RealNetworks Helix Universal Server Denial of Service Vulnerability</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15880" source="XF">helix-get-dos(15880)</ref>
      <ref url="http://www.securityfocus.com/bid/10157" source="BID">10157</ref>
      <ref url="http://secunia.com/advisories/11395" source="SECUNIA" adv="1">11395</ref>
    </refs>
    <vuln_soft>
      <prod vendor="realnetworks" name="helix_universal_server">
        <vers num="9.0.1" />
        <vers num="9.0.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0390" published="2004-12-31" name="CVE-2004-0390" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SCO OpenServer 5.0.5 through 5.0.7 only supports Xauthority style access control when users log in using scologin, which allows remote attackers to gain unauthorized access to an X session via other X login methods.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/16113" source="XF">openserver-x-session-insecure(16113)</ref>
      <ref url="http://www.securityfocus.com/advisories/6684" source="SCO">SCOSA-2004.5</ref>
      <ref url="http://archives.neohapsis.com/archives/fulldisclosure/2004-05/0424.html" source="FULLDISC">20040510 OpenServer 5.0.5 OpenServer 5.0.6 OpenServer 5.0.7 : X sessions which are not started by scologin cannot use the X authorization protocol</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sco" name="openserver">
        <vers num="5.0.5" />
        <vers num="5.0.6" />
        <vers num="5.0.7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0391" published="2004-06-01" name="CVE-2004-0391" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Cisco Wireless LAN Solution Engine (WLSE) 2.0 through 2.5 and Hosting Solution Engine (HSE) 1.7 through 1.7.3 have a hardcoded username and password, which allows remote attackers to add new users, modify existing users, and change configuration.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" other="1" admin="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/659228" source="CERT-VN" patch="1" adv="1">VU#659228</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15773" source="XF" patch="1" adv="1">cisco-default-password(15773)</ref>
      <ref url="http://www.cisco.com/warp/public/707/cisco-sa-20040407-username.shtml" source="CISCO" patch="1" adv="1">20040407 A Default Username and Password in WLSE and HSE Devices</ref>
      <ref url="http://www.ciac.org/ciac/bulletins/o-111.shtml" source="CIAC" patch="1" adv="1">O-111</ref>
      <ref url="http://www.securityfocus.com/bid/10076" source="BID">10076</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="wireless_lan_solution_engine">
        <vers num="2.0" />
        <vers num="2.1" />
        <vers num="2.2" />
        <vers num="2.3" />
        <vers num="2.4" />
        <vers num="2.5" />
      </prod>
      <prod vendor="cisco" name="hosting_solution_engine">
        <vers num="1.7" />
        <vers num="1.7.0" />
        <vers num="1.7.1" />
        <vers num="1.7.2" />
        <vers num="1.7.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0392" published="2004-06-14" name="CVE-2004-0392" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">racoon before 20040407b allows remote attackers to cause a denial of service (infinite loop and dropped connections) via an IKE message with a malformed Generic Payload Header containing invalid (1) "Security Association Next Payload" and (2) "RESERVED" fields.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/15893" source="XF" patch="1" adv="1">racoon-isakmp-dos(15893)</ref>
      <ref url="http://www.vuxml.org/freebsd/40fcf20f-8891-11d8-90d1-0020ed76ef5a.html" source="CONFIRM" adv="1">http://www.vuxml.org/freebsd/40fcf20f-8891-11d8-90d1-0020ed76ef5a.html</ref>
      <ref url="ftp://ftp.sco.com/pub/updates/UnixWare/SCOSA-2005.10/SCOSA-2005.10.txt" source="SCO">SCOSA-2005.10</ref>
      <ref url="http://orange.kame.net/dev/query-pr.cgi?pr=555" source="CONFIRM">http://orange.kame.net/dev/query-pr.cgi?pr=555</ref>
    </refs>
    <vuln_soft>
      <prod vendor="kame" name="racoon">
        <vers prev="1" num="2004-04-07a" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0393" published="2004-12-06" name="CVE-2004-0393" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Format string vulnerability in the msg function for rlpr daemon (rlprd) 2.0.4 allows remote attackers to execute arbitrary code via format string specifiers in a buffer that can not be resolved, which is provided to the syslog function.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" other="1" admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/16453" source="XF" patch="1" adv="1">rlpr-msg-format-string(16453)</ref>
      <ref url="http://www.securityfocus.com/bid/10578" source="BID" patch="1" adv="1">10578</ref>
      <ref url="http://www.debian.org/security/2004/dsa-524" source="DEBIAN" patch="1" adv="1">DSA-524</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108810992313652&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20040624 Rlpr Advisory</ref>
    </refs>
    <vuln_soft>
      <prod vendor="rlpr" name="rlpr">
        <vers num="2.0" />
        <vers num="2.0.1" />
        <vers num="2.0.2" />
        <vers num="2.0.3" />
        <vers num="2.0.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2004-0394" published="2004-08-18" name="CVE-2004-0394" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">A "potential" buffer overflow exists in the panic() function in Linux 2.4.x, although it may not be exploitable due to the functionality of panic.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/15953" source="XF" adv="1">linux-panic-bo(15953)</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2004_10_kernel.html" source="SUSE">SuSE-SA:2004:010</ref>
      <ref url="http://www.linuxsecurity.com/advisories/engarde_advisory-4285.html" source="ENGARDE">ESA-20040428-004</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200407-02.xml" source="GENTOO" adv="1">GLSA-200407-02</ref>
      <ref url="http://lwn.net/Articles/81773/" source="MLIST">[fedora-announce] 20040422 Fedora alert FEDORA-2004-111 (kernel)</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000846" source="CONECTIVA" adv="1">CLA-2004:846</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/20040505-01-U.asc" source="SGI">20040505-01-U</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/20040504-01-U.asc" source="SGI">20040504-01-U</ref>
      <ref url="http://www.securityfocus.com/bid/10233" source="BID">10233</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2004:037" source="MANDRAKE">MDKSA-2004:037</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1082" source="DEBIAN">DSA-1082</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1070" source="DEBIAN">DSA-1070</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1069" source="DEBIAN">DSA-1069</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1067" source="DEBIAN">DSA-1067</ref>
      <ref url="http://secunia.com/advisories/20338" source="SECUNIA">20338</ref>
      <ref url="http://secunia.com/advisories/20202" source="SECUNIA">20202</ref>
      <ref url="http://secunia.com/advisories/20163" source="SECUNIA">20163</ref>
      <ref url="http://secunia.com/advisories/20162" source="SECUNIA">20162</ref>
    </refs>
    <vuln_soft>
      <prod vendor="linux" name="linux_kernel">
        <vers num="2.6.20.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0395" published="2004-12-06" name="CVE-2004-0395" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">The xatitv program in the gatos package does not properly drop root privileges when the configuration file does not exist, which allows local users to execute arbitrary commands via shell metacharacters in a system call.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" other="1" admin="1" />
    </loss_types>
    <vuln_types>
      <design />
      <env />
      <config />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/16273" source="XF" patch="1" adv="1">gatos-xatitv-gain-privileges(16273)</ref>
      <ref url="http://www.securityfocus.com/bid/10437" source="BID" patch="1" adv="1">10437</ref>
      <ref url="http://www.debian.org/security/2004/dsa-509" source="DEBIAN" patch="1" adv="1">DSA-509</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gatos" name="gatos">
        <vers num=".5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0396" published="2004-06-14" name="CVE-2004-0396" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Heap-based buffer overflow in CVS 1.11.x up to 1.11.15, and 1.12.x up to 1.12.7, when using the pserver mechanism allows remote attackers to execute arbitrary code via Entry lines.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/192038" source="CERT-VN" patch="1" adv="1">VU#192038</ref>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA04-147A.html" source="CERT">TA04-147A</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-190.html" source="REDHAT" patch="1" adv="1">RHSA-2004:190</ref>
      <ref url="http://www.debian.org/security/2004/dsa-505" source="DEBIAN" patch="1" adv="1">DSA-505</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108498454829020&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20040519 Advisory 07/2004: CVS remote vulnerability</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200405-12.xml" source="GENTOO">GLSA-200405-12</ref>
      <ref url="http://security.e-matters.de/advisories/072004.html" source="MISC">http://security.e-matters.de/advisories/072004.html</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9058" source="OVAL">oval:org.mitre.oval:def:9058</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2004-May/021742.html" source="SUSE">SuSE-SA:2004:013</ref>
      <ref url="ftp://ftp.NetBSD.org/pub/NetBSD/security/advisories/NetBSD-SA2004-008.txt.asc" source="NETBSD">NetBSD-SA2004-008</ref>
      <ref url="ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-04:10.cvs.asc" source="FREEBSD">FreeBSD-SA-04:10</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/16193" source="XF">cvs-entry-line-bo(16193)</ref>
      <ref url="http://www.slackware.com/security/viewer.php?l=slackware-security&amp;y=2004&amp;m=slackware-security.395865" source="SLACKWARE">SSA:2004-140-01</ref>
      <ref url="http://www.securityfocus.com/bid/10384" source="BID">10384</ref>
      <ref url="http://www.osvdb.org/6305" source="OSVDB">6305</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2004:048" source="MANDRAKE">MDKSA-2004:048</ref>
      <ref url="http://www.ciac.org/ciac/bulletins/o-147.shtml" source="CIAC">O-147</ref>
      <ref url="http://secunia.com/advisories/11674" source="SECUNIA">11674</ref>
      <ref url="http://secunia.com/advisories/11652" source="SECUNIA">11652</ref>
      <ref url="http://secunia.com/advisories/11651" source="SECUNIA">11651</ref>
      <ref url="http://secunia.com/advisories/11647" source="SECUNIA">11647</ref>
      <ref url="http://secunia.com/advisories/11641" source="SECUNIA">11641</ref>
      <ref url="http://marc.theaimsgroup.com/?l=openbsd-security-announce&amp;m=108508894405639&amp;w=2" source="OPENBSD">20040520 cvs server buffer overflow vulnerability</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108636445031613&amp;w=2" source="FEDORA">FEDORA-2004-1620</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108500040719512&amp;w=2" source="BUGTRAQ">20040519 [OpenPKG-SA-2004.022] OpenPKG Security Advisory (cvs)</ref>
      <ref url="http://cert.uni-stuttgart.de/archive/bugtraq/2004/05/msg00219.html" source="BUGTRAQ">20040519 Advisory 07/2004: CVS remote vulnerability</ref>
      <ref url="http://archives.neohapsis.com/archives/fulldisclosure/2004-05/0980.html" source="FULLDISC">20040519 Advisory 07/2004: CVS remote vulnerability</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:970" source="OVAL" sig="1">oval:org.mitre.oval:def:970</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cvs" name="cvs">
        <vers num="1.11" />
        <vers num="1.12" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0397" published="2004-07-07" name="CVE-2004-0397" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Stack-based buffer overflow during the apr_time_t data conversion in Subversion 1.0.2 and earlier allows remote attackers to execute arbitrary code via a (1) DAV2 REPORT query or (2) get-dated-rev svn-protocol command.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/16191" source="XF" patch="1" adv="1">subversion-date-parsing-command-execution(16191)</ref>
      <ref url="http://www.securityfocus.com/bid/10386" source="BID" patch="1" adv="1">10386</ref>
      <ref url="http://www.securityfocus.com/archive/1/363814" source="BUGTRAQ" patch="1" adv="1">20040519 [OpenPKG-SA-2004.023] OpenPKG Security Advisory (subversion)</ref>
      <ref url="https://bugzilla.fedora.us/show_bug.cgi?id=1748" source="FEDORA">FLSA:1748</ref>
      <ref url="http://www.linuxsecurity.com/advisories/fedora_advisory-4373.html" source="FEDORA" adv="1">FEDORA-2004-128</ref>
      <ref url="http://security.e-matters.de/advisories/082004.html" source="MISC">http://security.e-matters.de/advisories/082004.html</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108498676517697&amp;w=2" source="BUGTRAQ" adv="1">20040519 Advisory 08/2004: Subversion remote vulnerability</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2004-May/021737.html" source="FULLDISC">20040519 Advisory 08/2004: Subversion remote vulnerability</ref>
      <ref url="http://www.osvdb.org/6301" source="OSVDB">6301</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200405-14.xml" source="GENTOO">GLSA-200405-14</ref>
      <ref url="http://subversion.tigris.org/svn-sscanf-advisory.txt" source="CONFIRM">http://subversion.tigris.org/svn-sscanf-advisory.txt</ref>
      <ref url="http://secunia.com/advisories/11675" source="SECUNIA">11675</ref>
      <ref url="http://secunia.com/advisories/11642" source="SECUNIA">11642</ref>
    </refs>
    <vuln_soft>
      <prod vendor="subversion" name="subversion">
        <vers num="1.0" />
        <vers num="1.0.1" />
        <vers num="1.0.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0398" published="2004-07-07" name="CVE-2004-0398" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Heap-based buffer overflow in the ne_rfc1036_parse date parsing function for the neon library (libneon) 0.24.5 and earlier, as used by cadaver before 0.22, allows remote WebDAV servers to execute arbitrary code on the client.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="https://bugzilla.fedora.us/show_bug.cgi?id=1552" source="FEDORA" patch="1">FEDORA-2004-1552</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/16192" source="XF" patch="1">neon-library-nerfc1036parse-bo(16192)</ref>
      <ref url="http://www.securityfocus.com/bid/10385" source="BID" patch="1">10385</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-191.html" source="REDHAT" patch="1" adv="1">RHSA-2004:191</ref>
      <ref url="http://www.debian.org/security/2004/dsa-507" source="DEBIAN" patch="1" adv="1">DSA-507</ref>
      <ref url="http://www.debian.org/security/2004/dsa-506" source="DEBIAN" patch="1" adv="1">DSA-506</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200405-15.xml" source="GENTOO" patch="1" adv="1">GLSA-200405-15</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200405-13.xml" source="GENTOO" patch="1" adv="1">GLSA-200405-13</ref>
      <ref url="http://secunia.com/advisories/11673" source="SECUNIA" patch="1" adv="1">11673</ref>
      <ref url="http://secunia.com/advisories/11650" source="SECUNIA" patch="1" adv="1">11650</ref>
      <ref url="http://secunia.com/advisories/11638" source="SECUNIA" patch="1" adv="1">11638</ref>
      <ref url="http://www.osvdb.org/6302" source="OSVDB">6302</ref>
      <ref url="http://www.ciac.org/ciac/bulletins/o-148.shtml" source="CIAC" adv="1">O-148</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000841" source="CONECTIVA" adv="1">CLA-2004:841</ref>
      <ref url="http://archives.neohapsis.com/archives/fulldisclosure/2004-05/0982.html" source="FULLDISC" adv="1">20040519 Advisory 06/2004: libneon date parsing vulnerability</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2004:049" source="MANDRAKE">MDKSA-2004:049</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108500057108022&amp;w=2" source="BUGTRAQ">20040519 [OpenPKG-SA-2004.024] OpenPKG Security Advisory (neon)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108498433632333&amp;w=2" source="BUGTRAQ">20040519 Advisory 06/2004: libneon date parsing vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cadaver" name="cadaver_webdav_client">
        <vers num="0.20.0" />
        <vers num="0.20.1" />
        <vers num="0.20.2" />
        <vers num="0.20.3" />
        <vers num="0.20.4" />
        <vers num="0.20.5" />
        <vers num="0.21.0" />
        <vers num="0.22.0" />
        <vers num="0.22.1" />
      </prod>
      <prod vendor="neon" name="neon_client_library">
        <vers num="0.19.3" />
        <vers num="0.23" />
        <vers num="0.23.1" />
        <vers num="0.23.2" />
        <vers num="0.23.3" />
        <vers num="0.23.4" />
        <vers num="0.23.5" />
        <vers num="0.23.6" />
        <vers num="0.23.7" />
        <vers num="0.23.8" />
        <vers num="0.24" />
        <vers num="0.24.1" />
        <vers num="0.24.2" />
        <vers num="0.24.3" />
        <vers num="0.24.4" />
      </prod>
      <prod vendor="openoffice" name="openoffice">
        <vers num="1.1.2" />
      </prod>
      <prod vendor="subversion" name="subversion">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0399" published="2004-07-07" name="CVE-2004-0399" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Stack-based buffer overflow in Exim 3.35, and other versions before 4, when the sender_verify option is true, allows remote attackers to cause a denial of service and possibly execute arbitrary code during sender verification.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/16079" source="XF" patch="1" adv="1">exim-requireverify-bo(16079)</ref>
      <ref url="http://www.guninski.com/exim1.html" source="MISC" patch="1" adv="1">http://www.guninski.com/exim1.html</ref>
      <ref url="http://www.debian.org/security/2004/dsa-502" source="DEBIAN" patch="1" adv="1">DSA-502</ref>
      <ref url="http://www.debian.org/security/2004/dsa-501" source="DEBIAN" patch="1" adv="1">DSA-501</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2004-May/021015.html" source="FULLDISC">20040506 Buffer overflows in exim, yet still exim much better than windows</ref>
      <ref url="http://secunia.com/advisories/11558" source="SECUNIA">11558</ref>
    </refs>
    <vuln_soft>
      <prod vendor="university_of_cambridge" name="exim">
        <vers num="3.35" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0400" published="2004-07-07" name="CVE-2004-0400" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Stack-based buffer overflow in Exim 4 before 4.33, when the headers_check_syntax option is enabled, allows remote attackers to cause a denial of service and possibly execute arbitrary code during the header check.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/16077" source="XF" patch="1" adv="1">exim-headerschecksyntax-bo(16077)</ref>
      <ref url="http://www.guninski.com/exim1.html" source="MISC" patch="1" adv="1">http://www.guninski.com/exim1.html</ref>
      <ref url="http://www.debian.org/security/2004/dsa-502" source="DEBIAN" patch="1" adv="1">DSA-502</ref>
      <ref url="http://www.debian.org/security/2004/dsa-501" source="DEBIAN" patch="1" adv="1">DSA-501</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2004-May/021015.html" source="FULLDISC">20040506 Buffer overflows in exim, yet still exim much better than windows</ref>
    </refs>
    <vuln_soft>
      <prod vendor="university_of_cambridge" name="exim">
        <vers prev="1" num="4.32" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0401" published="2004-07-07" name="CVE-2004-0401" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Unknown vulnerability in libtasn1 0.1.x before 0.1.2, and 0.2.x before 0.2.7, related to the DER parsing functions.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/16157" source="XF" patch="1">libtasn1-der-parsing(16157)</ref>
      <ref url="http://www.backports.org/changelog.html" source="MISC" adv="1">http://www.backports.org/changelog.html</ref>
      <ref url="http://www.securityfocus.com/bid/10360" source="BID">10360</ref>
      <ref url="http://www.osvdb.org/15126" source="OSVDB">15126</ref>
      <ref url="http://securitytracker.com/id?1010159" source="SECTRACK">1010159</ref>
      <ref url="http://packages.debian.org/changelogs/pool/main/libt/libtasn1-2/libtasn1-2_0.2.13-1/changelog" source="CONFIRM">http://packages.debian.org/changelogs/pool/main/libt/libtasn1-2/libtasn1-2_0.2.13-1/changelog</ref>
    </refs>
    <vuln_soft>
      <prod vendor="free_software_foundation_inc." name="libtasn1">
        <vers num="0.1" />
        <vers num="0.1.0" />
        <vers num="0.1.1" />
        <vers num="0.2.0" />
        <vers num="0.2.1" />
        <vers num="0.2.2" />
        <vers num="0.2.3" />
        <vers num="0.2.4" />
        <vers num="0.2.5" />
        <vers num="0.2.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0402" published="2004-07-07" name="CVE-2004-0402" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Buffer overflow in xpcd-svga in xpcd before 2.08, and possibly other versions, may allow local users to execute arbitrary code.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/10403" source="BID" patch="1" adv="1">10403</ref>
      <ref url="http://www.debian.org/security/2004/dsa-508" source="DEBIAN" patch="1" adv="1">DSA-508</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/16236" source="XF" adv="1">xpcd-svga-pcdopen-bo(16236)</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2004:053" source="MANDRAKE">MDKSA-2004:053</ref>
    </refs>
    <vuln_soft>
      <prod vendor="xpcd" name="xpcd">
        <vers num="2.08" />
      </prod>
      <prod vendor="mandrakesoft" name="mandrake_linux">
        <vers num="10.0" edition="" />
        <vers num="10.0" edition=":amd64" />
        <vers num="9.2" edition="" />
        <vers num="9.2" edition=":amd64" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0403" published="2004-06-01" name="CVE-2004-0403" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Racoon before 20040408a allows remote attackers to cause a denial of service (memory consumption) via an ISAKMP packet with a large length field.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-165.html" source="REDHAT" patch="1" adv="1">RHSA-2004:165</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108369640424244&amp;w=2" source="APPLE" patch="1" adv="1">APPLE-SA-2004-05-03</ref>
      <ref url="http://www.vuxml.org/freebsd/ccd698df-8e20-11d8-90d1-0020ed76ef5a.html" source="CONFIRM" adv="1">http://www.vuxml.org/freebsd/ccd698df-8e20-11d8-90d1-0020ed76ef5a.html</ref>
      <ref url="http://www.mandrakesecure.net/en/advisories/advisory.php?name=MDKSA-2004:069" source="MANDRAKE">MDKSA-2004:069</ref>
      <ref url="http://www.kame.net/dev/cvsweb2.cgi/kame/kame/kame/racoon/isakmp.c.diff?r1=1.180&amp;r2=1.181" source="CONFIRM">http://www.kame.net/dev/cvsweb2.cgi/kame/kame/kame/racoon/isakmp.c.diff?r1=1.180&amp;r2=1.181</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200404-17.xml" source="GENTOO">GLSA-200404-17</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11220" source="OVAL">oval:org.mitre.oval:def:11220</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/20040506-01-U.asc" source="SGI">20040506-01-U</ref>
      <ref url="ftp://ftp.sco.com/pub/updates/UnixWare/SCOSA-2005.10/SCOSA-2005.10.txt" source="SCO">SCOSA-2005.10</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15893" source="XF">racoon-isakmp-dos(15893)</ref>
      <ref url="http://www.securityfocus.com/bid/10172" source="BID">10172</ref>
      <ref url="http://www.osvdb.org/5491" source="OSVDB">5491</ref>
      <ref url="http://sourceforge.net/project/shownotes.php?release_id=232288" source="CONFIRM">http://sourceforge.net/project/shownotes.php?release_id=232288</ref>
      <ref url="http://securitytracker.com/id?1009937" source="SECTRACK">1009937</ref>
      <ref url="http://secunia.com/advisories/11877" source="SECUNIA">11877</ref>
      <ref url="http://secunia.com/advisories/11410" source="SECUNIA">11410</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:984" source="OVAL" sig="1">oval:org.mitre.oval:def:984</ref>
    </refs>
    <vuln_soft>
      <prod vendor="kame" name="racoon">
        <vers prev="1" num="2004-04-08a" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2004-0404" published="2004-07-07" name="CVE-2004-0404" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:H/Au:N/C:N/I:P/A:N)" CVSS_score="1.2" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="1.9" CVSS_base_score="1.2">
    <desc>
      <descript source="cve">logcheck before 1.1.1 allows local users to overwrite arbitrary files via a symlink attack on a temporary directory in /var/tmp.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <race />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/15888" source="XF" patch="1">logcheck-directory-symlink(15888)</ref>
      <ref url="http://www.securityfocus.com/bid/10162" source="BID" patch="1">10162</ref>
      <ref url="http://www.debian.org/security/2004/dsa-488" source="DEBIAN" patch="1" adv="1">DSA-488</ref>
      <ref url="http://secunia.com/advisories/11399" source="SECUNIA" adv="1">11399</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2004:155" source="MANDRAKE">MDKSA-2004:155</ref>
    </refs>
    <vuln_soft>
      <prod vendor="psionic" name="logcheck">
        <vers prev="1" num="1.1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0405" published="2004-06-01" name="CVE-2004-0405" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">CVS before 1.11 allows CVS clients to read arbitrary files via .. (dot dot) sequences in filenames via CVS client requests, a different vulnerability than CVE-2004-0180.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.debian.org/security/2004/dsa-486" source="DEBIAN" patch="1" adv="1">DSA-486</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108636445031613&amp;w=2" source="FEDORA" patch="1" adv="1">FEDORA-2004-1620</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/20040404-01-U.asc" source="SGI" patch="1" adv="1">20040404-01-U</ref>
      <ref url="ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-04:07.cvs.asc" source="FREEBSD" patch="1" adv="1">FreeBSD-SA-04:07</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10818" source="OVAL">oval:org.mitre.oval:def:10818</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15891" source="XF">cvs-dotdot-directory-traversal(15891)</ref>
      <ref url="http://www.slackware.com/security/viewer.php?l=slackware-security&amp;y=2004&amp;m=slackware-security.400181" source="SLACKWARE">SSA:2004-108-02</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200404-13.xml" source="GENTOO">GLSA-200404-13</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1060" source="OVAL" sig="1">oval:org.mitre.oval:def:1060</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cvs" name="cvs">
        <vers prev="1" num="1.10" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2004-0407" published="2004-06-01" name="CVE-2004-0407" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:N/A:P)" CVSS_score="2.6" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="4.9" CVSS_base_score="2.6">
    <desc>
      <descript source="cve">The HTML form upload capability in ColdFusion MX 6.1 does not reclaim disk space if an upload is interrupted, which allows remote attackers to cause a denial of service (disk consumption) by repeatedly uploading files and interrupting the uploads before they finish.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
      <env />
      <race />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.macromedia.com/devnet/security/security_zone/mpsb04-06.html" source="CONFIRM" patch="1" adv="1">http://www.macromedia.com/devnet/security/security_zone/mpsb04-06.html</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108213782629001&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20040416 [securityzone@macromedia.com: New Macromedia Security Zone Bulletin Posted]</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15882" source="XF">coldfusion-upload-file-dos(15882)</ref>
      <ref url="http://www.securityfocus.com/bid/10158" source="BID">10158</ref>
      <ref url="http://www.osvdb.org/5402" source="OSVDB">5402</ref>
      <ref url="http://securitytracker.com/id?1009825" source="SECTRACK">1009825</ref>
      <ref url="http://secunia.com/advisories/11392" source="SECUNIA">11392</ref>
    </refs>
    <vuln_soft>
      <prod vendor="macromedia" name="coldfusion">
        <vers num="6.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0408" published="2004-09-28" name="CVE-2004-0408" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in the child_service function in the ident2 ident daemon allows remote attackers to execute arbitrary code.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/15938" source="XF" patch="1" adv="1">ident2-childservice-bo(15938)</ref>
      <ref url="http://www.securityfocus.com/bid/10192" source="BID" patch="1" adv="1">10192</ref>
      <ref url="http://www.debian.org/security/2004/dsa-494" source="DEBIAN" patch="1" adv="1">DSA-494</ref>
    </refs>
    <vuln_soft>
      <prod vendor="michael_bacarella" name="ident2">
        <vers num=".999c" />
        <vers num="1.3" />
        <vers num="1.3_1" />
        <vers num="1.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0409" published="2004-06-01" name="CVE-2004-0409" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Stack-based buffer overflow in the Socks-5 proxy code for XChat 1.8.0 to 2.0.8, with socks5 traversal enabled, allows remote attackers to execute arbitrary code.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" other="1" />
    </loss_types>
    <vuln_types>
      <input bound="1" />
      <config />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.xchat.org/" source="CONFIRM" patch="1" adv="1">http://www.xchat.org/</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-177.html" source="REDHAT" patch="1" adv="1">RHSA-2004:177</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108258002427226&amp;w=2" source="DEBIAN" patch="1" adv="1">DSA-493</ref>
      <ref url="http://mail.nl.linux.org/xchat-announce/2004-04/msg00000.html" source="MLIST" patch="1" adv="1">[xchat-announce] 20040405 xchat 2.0.x Socks5 Vulnerability</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-585.html" source="REDHAT">RHSA-2004:585</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200404-15.xml" source="GENTOO">GLSA-200404-15</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11312" source="OVAL">oval:org.mitre.oval:def:11312</ref>
      <ref url="http://www.fedoralegacy.org/updates/FC2/2005-11-14-FLSA_2005_123013" source="FEDORA">FLSA:123013</ref>
    </refs>
    <vuln_soft>
      <prod vendor="xchat" name="xchat">
        <vers num="1.8.0" />
        <vers num="1.8.1" />
        <vers num="1.8.2" />
        <vers num="1.8.3" />
        <vers num="1.8.4" />
        <vers num="1.8.5" />
        <vers num="1.8.6" />
        <vers num="1.8.7" />
        <vers num="1.8.8" />
        <vers num="1.8.9" />
        <vers num="1.9.0" />
        <vers num="1.9.1" />
        <vers num="1.9.2" />
        <vers num="1.9.3" />
        <vers num="1.9.4" />
        <vers num="1.9.5" />
        <vers num="1.9.6" />
        <vers num="1.9.7" />
        <vers num="1.9.8" />
        <vers num="1.9.9" />
        <vers num="2.0.0" />
        <vers num="2.0.1" />
        <vers num="2.0.2" />
        <vers num="2.0.3" />
        <vers num="2.0.4" />
        <vers num="2.0.5" />
        <vers num="2.0.6" />
        <vers num="2.0.7" />
        <vers num="2.0.8" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" seq="2004-0410" reject="1" published="2004-12-31" name="CVE-2004-0410" modified="2008-09-10">
    <desc>
      <descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: none.  Reason: This candidate was withdrawn by its CNA.  Further investigation showed that it was not a security issue.  Notes: none.</descript>
    </desc>
    <refs />
  </entry>
  <entry type="CVE" severity="High" seq="2004-0411" published="2004-07-07" name="CVE-2004-0411" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">The URI handlers in Konqueror for KDE 3.2.2 and earlier do not properly filter "-" characters that begin a hostname in a (1) telnet, (2) rlogin, (3) ssh, or (4) mailto URI, which allows remote attackers to manipulate the options that are passed to the associated programs, possibly to read arbitrary files or execute arbitrary code.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kde.org/info/security/advisory-20040517-1.txt" source="CONFIRM" patch="1" adv="1">http://www.kde.org/info/security/advisory-20040517-1.txt</ref>
      <ref url="http://www.securityfocus.com/archive/1/363225" source="BUGTRAQ" adv="1">20040513 Opera Telnet URI Handler Vulnerability also applies to other browsers</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-222.html" source="REDHAT">RHSA-2004:222</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2004_14_kdelibs.html" source="SUSE">SuSE-SA:2003:014</ref>
      <ref url="http://www.debian.org/security/2004/dsa-518" source="DEBIAN">DSA-518</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200405-11.xml" source="GENTOO">GLSA-200405-11</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/16163" source="XF">kde-url-handler-gain-access(16163)</ref>
      <ref url="http://www.slackware.org/security/viewer.php?l=slackware-security&amp;y=2004&amp;m=slackware-security.362635" source="SLACKWARE">SSA:2004-238</ref>
      <ref url="http://www.securityfocus.com/bid/10358" source="BID">10358</ref>
      <ref url="http://www.securityfocus.com/advisories/6743" source="FEDORA">FEDORA-2004-122</ref>
      <ref url="http://www.securityfocus.com/advisories/6717" source="FEDORA">FEDORA-2004-121</ref>
      <ref url="http://www.osvdb.org/6107" source="OSVDB">6107</ref>
      <ref url="http://www.ciac.org/ciac/bulletins/o-146.shtml" source="CIAC">O-146</ref>
      <ref url="http://secunia.com/advisories/11602" source="SECUNIA">11602</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108481412427344&amp;w=2" source="BUGTRAQ">20040517 KDE Security Advisory: URI Handler Vulnerabilities</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000843" source="CONECTIVA">CLA-2004:843</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:954" source="OVAL" sig="1">oval:org.mitre.oval:def:954</ref>
    </refs>
    <vuln_soft>
      <prod vendor="kde" name="konqueror">
        <vers prev="1" num="3.2.2" />
      </prod>
      <prod vendor="opera_software" name="opera_web_browser">
        <vers num="9.10" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0412" published="2004-08-18" name="CVE-2004-0412" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Mailman before 2.1.5 allows remote attackers to obtain user passwords via a crafted email request to the Mailman server.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/10412" source="BID" patch="1" adv="1">10412</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109034869927955&amp;w=2" source="FEDORA" patch="1" adv="1">FEDORA-2004-1734</ref>
      <ref url="https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=123559" source="CONFIRM">https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=123559</ref>
      <ref url="http://www.mandrakesecure.net/en/advisories/advisory.php?name=MDKSA-2004:051" source="MANDRAKE">MDKSA-2004:051</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200406-04.xml" source="GENTOO" adv="1">GLSA-200406-04</ref>
      <ref url="http://mail.python.org/pipermail/mailman-announce/2004-May/000072.html" source="MLIST">[Mailman-Announce] 20040515 RELEASED Mailman 2.1.5</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000842" source="CONECTIVA" adv="1">CLA-2004:842</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/16256" source="XF">mailman-obtain-password(16256)</ref>
      <ref url="http://secunia.com/advisories/11701" source="SECUNIA">11701</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gnu" name="mailman">
        <vers num="2.1" />
        <vers num="2.1.1" />
        <vers num="2.1.2" />
        <vers num="2.1.3" />
        <vers num="2.1.4" />
        <vers num="2.1b1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0413" published="2004-08-06" name="CVE-2004-0413" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">libsvn_ra_svn in Subversion 1.0.4 trusts the length field of (1) svn://, (2) svn+ssh://, and (3) other svn protocol URL strings, which allows remote attackers to cause a denial of service (memory consumption) and possibly execute arbitrary code via an integer overflow that leads to a heap-based buffer overflow.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" bound="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/16396" source="XF" patch="1" adv="1">subversion-svn-bo(16396)</ref>
      <ref url="http://www.securityfocus.com/bid/10519" source="BID" patch="1" adv="1">10519</ref>
      <ref url="https://bugzilla.fedora.us/show_bug.cgi?id=1748" source="FEDORA">FLSA:1748</ref>
      <ref url="http://www.securityfocus.com/advisories/6847" source="FEDORA">FEDORA-2004-165</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2004_18_subversion.html" source="SUSE">SuSE-SA:2004:018</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200406-07.xml" source="GENTOO" adv="1">GLSA-200406-07</ref>
      <ref url="http://subversion.tigris.org/security/CAN-2004-0413-advisory.txt" source="CONFIRM">http://subversion.tigris.org/security/CAN-2004-0413-advisory.txt</ref>
      <ref url="http://www.securityfocus.com/archive/1/365836" source="BUGTRAQ">20041012 [FMADV] Subversion &lt;= 1.04 Heap Overflow</ref>
    </refs>
    <vuln_soft>
      <prod vendor="openpkg" name="openpkg">
        <vers num="2.0" />
      </prod>
      <prod vendor="subversion" name="subversion">
        <vers num="1.0" />
        <vers num="1.0.1" />
        <vers num="1.0.2" />
        <vers num="1.0.3" />
        <vers num="1.0.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0414" published="2004-08-06" name="CVE-2004-0414" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">CVS 1.12.x through 1.12.8, and 1.11.x through 1.11.16, does not properly handle malformed "Entry" lines, which prevents a NULL terminator from being used and may lead to a denial of service (crash), modification of critical program data, or arbitrary code execution.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.debian.org/security/2004/dsa-517" source="DEBIAN" patch="1" adv="1">DSA-517</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108716553923643&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20040611 [OpenPKG-SA-2004.027] OpenPKG Security Advisory (cvs)</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-233.html" source="REDHAT">RHSA-2004:233</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200406-06.xml" source="GENTOO" adv="1">GLSA-200406-06</ref>
      <ref url="http://security.e-matters.de/advisories/092004.html" source="MISC">http://security.e-matters.de/advisories/092004.html</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10575" source="OVAL">oval:org.mitre.oval:def:10575</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2004-June/022441.html" source="FULLDISC">20040609 Advisory 09/2004: More CVS remote vulnerabilities</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/20040605-01-U.asc" source="SGI">20040605-01-U</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/20040604-01-U.asc" source="SGI">20040604-01-U</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2004:058" source="MANDRAKE">MDKSA-2004:058</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:993" source="OVAL" sig="1">oval:org.mitre.oval:def:993</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cvs" name="cvs">
        <vers num="1.10.7" />
        <vers num="1.10.8" />
        <vers num="1.11" />
        <vers num="1.11.1" />
        <vers num="1.11.10" />
        <vers num="1.11.11" />
        <vers num="1.11.14" />
        <vers num="1.11.15" />
        <vers num="1.11.16" />
        <vers num="1.11.1_p1" />
        <vers num="1.11.2" />
        <vers num="1.11.3" />
        <vers num="1.11.4" />
        <vers num="1.11.5" />
        <vers num="1.11.6" />
        <vers num="1.12.1" />
        <vers num="1.12.2" />
        <vers num="1.12.5" />
        <vers num="1.12.7" />
        <vers num="1.12.8" />
      </prod>
      <prod vendor="openpkg" name="openpkg">
        <vers num="1.3" />
        <vers num="2.0" />
      </prod>
      <prod vendor="sgi" name="propack">
        <vers num="2.4" />
        <vers num="3.0" />
      </prod>
      <prod vendor="gentoo" name="linux">
        <vers num="1.4" />
      </prod>
      <prod vendor="openbsd" name="openbsd">
        <vers num="3.4" />
        <vers num="3.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2004-0415" published="2004-11-23" name="CVE-2004-0415" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">Linux kernel does not properly convert 64-bit file offset pointers to 32 bits, which allows local users to access portions of kernel memory.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-418.html" source="REDHAT" patch="1" adv="1">RHSA-2004:418</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/16877" source="XF" adv="1">linux-pointer-info-disclosure(16877)</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-413.html" source="REDHAT">RHSA-2004:413</ref>
      <ref url="http://www.mandrakesecure.net/en/advisories/advisory.php?name=MDKSA-2004:087" source="MANDRAKE">MDKSA-2004:087</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200408-24.xml" source="GENTOO">GLSA-200408-24</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9965" source="OVAL">oval:org.mitre.oval:def:9965</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/20040804-01-U.asc" source="SGI">20040804-01-U</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000879" source="CONECTIVA">CLA-2004:879</ref>
    </refs>
    <vuln_soft>
      <prod vendor="linux" name="linux_kernel">
        <vers num="2.4.0" edition="test1" />
        <vers num="2.4.0" edition="test10" />
        <vers num="2.4.0" edition="test11" />
        <vers num="2.4.0" edition="test12" />
        <vers num="2.4.0" edition="test2" />
        <vers num="2.4.0" edition="test3" />
        <vers num="2.4.0" edition="test4" />
        <vers num="2.4.0" edition="test5" />
        <vers num="2.4.0" edition="test6" />
        <vers num="2.4.0" edition="test7" />
        <vers num="2.4.0" edition="test8" />
        <vers num="2.4.0" edition="test9" />
        <vers num="2.4.1" />
        <vers num="2.4.10" />
        <vers num="2.4.11" />
        <vers num="2.4.12" />
        <vers num="2.4.13" />
        <vers num="2.4.14" />
        <vers num="2.4.15" />
        <vers num="2.4.16" />
        <vers num="2.4.17" />
        <vers num="2.4.18" edition="" />
        <vers num="2.4.18" edition=":x86" />
        <vers num="2.4.18" edition="pre1" />
        <vers num="2.4.18" edition="pre2" />
        <vers num="2.4.18" edition="pre3" />
        <vers num="2.4.18" edition="pre4" />
        <vers num="2.4.18" edition="pre5" />
        <vers num="2.4.18" edition="pre6" />
        <vers num="2.4.18" edition="pre7" />
        <vers num="2.4.18" edition="pre8" />
        <vers num="2.4.19" edition="pre1" />
        <vers num="2.4.19" edition="pre2" />
        <vers num="2.4.19" edition="pre3" />
        <vers num="2.4.19" edition="pre4" />
        <vers num="2.4.19" edition="pre5" />
        <vers num="2.4.19" edition="pre6" />
        <vers num="2.4.2" />
        <vers num="2.4.20" />
        <vers num="2.4.21" edition="pre1" />
        <vers num="2.4.21" edition="pre4" />
        <vers num="2.4.21" edition="pre7" />
        <vers num="2.4.22" />
        <vers num="2.4.23" edition="pre9" />
        <vers num="2.4.23_ow2" />
        <vers num="2.4.24" />
        <vers num="2.4.24_ow1" />
        <vers num="2.4.25" />
        <vers num="2.4.26" />
        <vers num="2.4.3" />
        <vers num="2.4.4" />
        <vers num="2.4.5" />
        <vers num="2.4.6" />
        <vers num="2.4.7" />
        <vers num="2.4.8" />
        <vers num="2.4.9" />
        <vers num="2.6.0" edition="test1" />
        <vers num="2.6.0" edition="test10" />
        <vers num="2.6.0" edition="test11" />
        <vers num="2.6.0" edition="test2" />
        <vers num="2.6.0" edition="test3" />
        <vers num="2.6.0" edition="test4" />
        <vers num="2.6.0" edition="test5" />
        <vers num="2.6.0" edition="test6" />
        <vers num="2.6.0" edition="test7" />
        <vers num="2.6.0" edition="test8" />
        <vers num="2.6.0" edition="test9" />
        <vers num="2.6.1" edition="rc1" />
        <vers num="2.6.1" edition="rc2" />
        <vers num="2.6.2" />
        <vers num="2.6.3" />
        <vers num="2.6.4" />
        <vers num="2.6.5" />
        <vers num="2.6.6" edition="rc1" />
        <vers num="2.6.7" edition="rc1" />
        <vers num="2.6_test9_cvs" />
      </prod>
      <prod vendor="redhat" name="fedora_core">
        <vers num="core_1.0" />
      </prod>
      <prod vendor="trustix" name="secure_linux">
        <vers num="2.0" />
        <vers num="2.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0416" published="2004-08-06" name="CVE-2004-0416" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Double free vulnerability for the error_prog_name string in CVS 1.12.x through 1.12.8, and 1.11.x through 1.11.16, may allow remote attackers to execute arbitrary code.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" admin="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.debian.org/security/2004/dsa-519" source="DEBIAN" patch="1" adv="1">DSA-519</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108716553923643&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20040611 [OpenPKG-SA-2004.027] OpenPKG Security Advisory (cvs)</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-233.html" source="REDHAT">RHSA-2004:233</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2004:058" source="MANDRAKE">MDKSA-2004:058</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200406-06.xml" source="GENTOO">GLSA-200406-06</ref>
      <ref url="http://security.e-matters.de/advisories/092004.html" source="MISC">http://security.e-matters.de/advisories/092004.html</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10070" source="OVAL">oval:org.mitre.oval:def:10070</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2004-June/022441.html" source="FULLDISC">20040609 Advisory 09/2004: More CVS remote vulnerabilities</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/20040605-01-U.asc" source="SGI">20040605-01-U</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/20040604-01-U.asc" source="SGI">20040604-01-U</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:994" source="OVAL" sig="1">oval:org.mitre.oval:def:994</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cvs" name="cvs">
        <vers num="1.10.7" />
        <vers num="1.10.8" />
        <vers num="1.11" />
        <vers num="1.11.1" />
        <vers num="1.11.10" />
        <vers num="1.11.11" />
        <vers num="1.11.14" />
        <vers num="1.11.15" />
        <vers num="1.11.16" />
        <vers num="1.11.1_p1" />
        <vers num="1.11.2" />
        <vers num="1.11.3" />
        <vers num="1.11.4" />
        <vers num="1.11.5" />
        <vers num="1.11.6" />
        <vers num="1.12.1" />
        <vers num="1.12.2" />
        <vers num="1.12.5" />
        <vers num="1.12.7" />
        <vers num="1.12.8" />
      </prod>
      <prod vendor="openpkg" name="openpkg">
        <vers num="1.3" />
        <vers num="2.0" />
      </prod>
      <prod vendor="sgi" name="propack">
        <vers num="2.4" />
        <vers num="3.0" />
      </prod>
      <prod vendor="gentoo" name="linux">
        <vers num="1.4" />
      </prod>
      <prod vendor="openbsd" name="openbsd">
        <vers num="3.4" />
        <vers num="3.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0417" published="2004-08-06" name="CVE-2004-0417" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Integer overflow in the "Max-dotdot" CVS protocol command (serve_max_dotdot) for CVS 1.12.x through 1.12.8, and 1.11.x through 1.11.16, may allow remote attackers to cause a server crash, which could cause temporary data to remain undeleted and consume disk space.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.debian.org/security/2004/dsa-519" source="DEBIAN" patch="1" adv="1">DSA-519</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108716553923643&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20040611 [OpenPKG-SA-2004.027] OpenPKG Security Advisory (cvs)</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-233.html" source="REDHAT">RHSA-2004:233</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200406-06.xml" source="GENTOO" adv="1">GLSA-200406-06</ref>
      <ref url="http://security.e-matters.de/advisories/092004.html" source="MISC">http://security.e-matters.de/advisories/092004.html</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11145" source="OVAL">oval:org.mitre.oval:def:11145</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2004-June/022441.html" source="FULLDISC">20040609 Advisory 09/2004: More CVS remote vulnerabilities</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/20040605-01-U.asc" source="SGI">20040605-01-U</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2004:058" source="MANDRAKE">MDKSA-2004:058</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1001" source="OVAL" sig="1">oval:org.mitre.oval:def:1001</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cvs" name="cvs">
        <vers num="1.10.7" />
        <vers num="1.10.8" />
        <vers num="1.11" />
        <vers num="1.11.1" />
        <vers num="1.11.10" />
        <vers num="1.11.11" />
        <vers num="1.11.14" />
        <vers num="1.11.15" />
        <vers num="1.11.16" />
        <vers num="1.11.1_p1" />
        <vers num="1.11.2" />
        <vers num="1.11.3" />
        <vers num="1.11.4" />
        <vers num="1.11.5" />
        <vers num="1.11.6" />
        <vers num="1.12.1" />
        <vers num="1.12.2" />
        <vers num="1.12.5" />
        <vers num="1.12.7" />
        <vers num="1.12.8" />
      </prod>
      <prod vendor="openpkg" name="openpkg">
        <vers num="1.3" />
        <vers num="2.0" />
      </prod>
      <prod vendor="sgi" name="propack">
        <vers num="2.4" />
        <vers num="3.0" />
      </prod>
      <prod vendor="gentoo" name="linux">
        <vers num="1.4" />
      </prod>
      <prod vendor="openbsd" name="openbsd">
        <vers num="3.4" />
        <vers num="3.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0418" published="2004-08-06" name="CVE-2004-0418" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">serve_notify in CVS 1.12.x through 1.12.8, and 1.11.x through 1.11.16, does not properly handle empty data lines, which may allow remote attackers to perform an "out-of-bounds" write for a single byte to execute arbitrary code or modify critical program data.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" admin="1" />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.debian.org/security/2004/dsa-519" source="DEBIAN" patch="1" adv="1">DSA-519</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108716553923643&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20040611 [OpenPKG-SA-2004.027] OpenPKG Security Advisory (cvs)</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-233.html" source="REDHAT">RHSA-2004:233</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200406-06.xml" source="GENTOO" adv="1">GLSA-200406-06</ref>
      <ref url="http://security.e-matters.de/advisories/092004.html" source="MISC">http://security.e-matters.de/advisories/092004.html</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11242" source="OVAL">oval:org.mitre.oval:def:11242</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2004-June/022441.html" source="FULLDISC">20040609 Advisory 09/2004: More CVS remote vulnerabilities</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/20040605-01-U.asc" source="SGI">20040605-01-U</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/20040604-01-U.asc" source="SGI">20040604-01-U</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2004:058" source="MANDRAKE">MDKSA-2004:058</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1003" source="OVAL" sig="1">oval:org.mitre.oval:def:1003</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cvs" name="cvs">
        <vers num="1.10.7" />
        <vers num="1.10.8" />
        <vers num="1.11" />
        <vers num="1.11.1" />
        <vers num="1.11.10" />
        <vers num="1.11.11" />
        <vers num="1.11.14" />
        <vers num="1.11.15" />
        <vers num="1.11.16" />
        <vers num="1.11.1_p1" />
        <vers num="1.11.2" />
        <vers num="1.11.3" />
        <vers num="1.11.4" />
        <vers num="1.11.5" />
        <vers num="1.11.6" />
        <vers num="1.12.1" />
        <vers num="1.12.2" />
        <vers num="1.12.5" />
        <vers num="1.12.7" />
        <vers num="1.12.8" />
      </prod>
      <prod vendor="openpkg" name="openpkg">
        <vers num="1.3" />
        <vers num="2.0" />
      </prod>
      <prod vendor="sgi" name="propack">
        <vers num="2.4" />
        <vers num="3.0" />
      </prod>
      <prod vendor="gentoo" name="linux">
        <vers num="1.4" />
      </prod>
      <prod vendor="openbsd" name="openbsd">
        <vers num="3.4" />
        <vers num="3.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0419" published="2004-08-18" name="CVE-2004-0419" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">XDM in XFree86 opens a chooserFd TCP socket even when DisplayManager.requestPort is 0, which could allow remote attackers to connect to the port, in violation of the intended restrictions.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/10423" source="BID" patch="1" adv="1">10423</ref>
      <ref url="http://www.mandrakesecure.net/en/advisories/advisory.php?name=MDKSA-2004:073" source="MANDRAKE" patch="1" adv="1">MDKSA-2004:073</ref>
      <ref url="https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=124900" source="CONFIRM">https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=124900</ref>
      <ref url="http://www.openbsd.org/errata.html#xdm" source="OPENBSD">20040526 008: SECURITY FIX: May 26, 2004</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200407-05.xml" source="GENTOO" adv="1">GLSA-200407-05</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10161" source="OVAL">oval:org.mitre.oval:def:10161</ref>
      <ref url="http://bugs.xfree86.org/show_bug.cgi?id=1376" source="CONFIRM">http://bugs.xfree86.org/show_bug.cgi?id=1376</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/16264" source="XF">xdm-socket-gain-access(16264)</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-478.html" source="REDHAT">RHSA-2004:478</ref>
      <ref url="http://www.ciac.org/ciac/bulletins/p-001.shtml" source="CIAC">P-001</ref>
      <ref url="http://securitytracker.com/id?1010306" source="SECTRACK">1010306</ref>
      <ref url="http://secunia.com/advisories/12019" source="SECUNIA">12019</ref>
    </refs>
    <vuln_soft>
      <prod vendor="x.org" name="x11r6">
        <vers num="6.7.0" />
      </prod>
      <prod vendor="xfree86_project" name="xdm">
        <vers num="cvs" />
      </prod>
      <prod vendor="gentoo" name="linux">
        <vers num="1.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0420" published="2004-07-07" name="CVE-2004-0420" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">The Windows Shell application in Windows 98, Windows ME, Windows NT 4.0, Windows 2000, Windows XP, and Windows Server 2003 allows remote attackers to execute arbitrary code by spoofing the type of a file via a CLSID specifier in the filename, as demonstrated using Internet Explorer 6.0.2800.1106 on Windows XP.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" admin="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA04-196A.html" source="CERT" adv="1">TA04-196A</ref>
      <ref url="http://www.kb.cert.org/vuls/id/106324" source="CERT-VN">VU#106324</ref>
      <ref url="http://www.securityfocus.com/bid/9510" source="BID" adv="1">9510</ref>
      <ref url="http://www.securityfocus.com/archive/1/351379" source="BUGTRAQ" adv="1">20040127 GOOROO CROSSING: File Spoofing Internet Explorer 6</ref>
      <ref url="http://www.security-express.com/archives/bugtraq/2004-01/0300.html" source="BUGTRAQ">20040127 RE: GOOROO CROSSING: File Spoofing Internet Explorer 6</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms04-024.asp" source="MS">MS04-024</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/14964" source="XF">ie-clsid-file-extension-spoofing(14964)</ref>
      <ref url="http://secunia.com/advisories/10736/" source="SECUNIA">10736</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:3604" source="OVAL" sig="1">oval:org.mitre.oval:def:3604</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:3533" source="OVAL" sig="1">oval:org.mitre.oval:def:3533</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:3386" source="OVAL" sig="1">oval:org.mitre.oval:def:3386</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2894" source="OVAL" sig="1">oval:org.mitre.oval:def:2894</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2381" source="OVAL" sig="1">oval:org.mitre.oval:def:2381</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2245" source="OVAL" sig="1">oval:org.mitre.oval:def:2245</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="ie">
        <vers num="6.0" edition="sp1" />
        <vers num="6.0.2800.1106" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0421" published="2004-08-18" name="CVE-2004-0421" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The Portable Network Graphics library (libpng) 1.0.15 and earlier allows attackers to cause a denial of service (crash) via a malformed PNG image file that triggers an error that causes an out-of-bounds read when creating the error message.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/10244" source="BID" patch="1" adv="1">10244</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-180.html" source="REDHAT" patch="1" adv="1">RHSA-2004:180</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/16022" source="XF" adv="1">libpng-png-dos(16022)</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-181.html" source="REDHAT">RHSA-2004:181</ref>
      <ref url="http://www.debian.org/security/2004/dsa-498" source="DEBIAN">DSA-498</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11710" source="OVAL">oval:org.mitre.oval:def:11710</ref>
      <ref url="http://marc.theaimsgroup.com/?l=fedora-announce-list&amp;m=108451353608968&amp;w=2" source="FEDORA">FEDORA-2004-106</ref>
      <ref url="http://marc.theaimsgroup.com/?l=fedora-announce-list&amp;m=108451350029261&amp;w=2" source="FEDORA">FEDORA-2004-105</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108335030208523&amp;w=2" source="TRUSTIX">2004-0025</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108334922320309&amp;w=2" source="BUGTRAQ">20040429 [OpenPKG-SA-2004.017] OpenPKG Security Advisory (png)</ref>
      <ref url="http://lists.apple.com/mhonarc/security-announce/msg00056.html" source="APPLE">APPLE-SA-2004-09-09</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:213" source="MANDRIVA">MDKSA-2006:213</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:212" source="MANDRIVA">MDKSA-2006:212</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2004:040" source="MANDRAKE">MDKSA-2004:040</ref>
      <ref url="http://secunia.com/advisories/22958" source="SECUNIA">22958</ref>
      <ref url="http://secunia.com/advisories/22957" source="SECUNIA">22957</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:971" source="OVAL" sig="1">oval:org.mitre.oval:def:971</ref>
    </refs>
    <vuln_soft>
      <prod vendor="greg_roelofs" name="libpng">
        <vers num="1.0" />
        <vers num="1.0.10" />
        <vers num="1.0.11" />
        <vers num="1.0.12" />
        <vers num="1.0.13" />
        <vers num="1.0.14" />
        <vers num="1.0.5" />
        <vers num="1.0.6" />
        <vers num="1.0.7" />
        <vers num="1.0.8" />
        <vers num="1.0.9" />
      </prod>
      <prod vendor="greg_roelofs" name="libpng3">
        <vers num="1.2.0" />
        <vers num="1.2.1" />
        <vers num="1.2.2" />
        <vers num="1.2.3" />
        <vers num="1.2.4" />
        <vers num="1.2.5" />
      </prod>
      <prod vendor="openpkg" name="openpkg">
        <vers num="1.3" />
        <vers num="2.0" />
      </prod>
      <prod vendor="redhat" name="libpng">
        <vers num="1.2.2-16" edition="" />
        <vers num="1.2.2-16" edition=":i386_dev" />
        <vers num="1.2.2-16" edition=":i386" />
        <vers num="1.2.2-20" edition="" />
        <vers num="1.2.2-20" edition=":i386" />
        <vers num="1.2.2-20" edition=":i386_dev" />
        <vers num="10.1.0.13.11" edition="" />
        <vers num="10.1.0.13.11" edition=":i386" />
        <vers num="10.1.0.13.11" edition=":i386_dev" />
        <vers num="10.1.0.13.8" edition="" />
        <vers num="10.1.0.13.8" edition=":i386" />
        <vers num="10.1.0.13.8" edition=":i386_dev" />
      </prod>
      <prod vendor="redhat" name="enterprise_linux">
        <vers num="2.1" edition="" />
        <vers num="2.1" edition=":advanced_server" />
        <vers num="2.1" edition=":enterprise_server" />
        <vers num="2.1" edition=":workstation" />
        <vers num="3.0" edition="" />
        <vers num="3.0" edition=":advanced_server" />
        <vers num="3.0" edition=":workstation_server" />
        <vers num="3.0" edition=":enterprise_server" />
      </prod>
      <prod vendor="redhat" name="enterprise_linux_desktop">
        <vers num="3.0" />
      </prod>
      <prod vendor="redhat" name="linux_advanced_workstation">
        <vers num="2.1" edition="" />
        <vers num="2.1" edition=":itanium_processor" />
        <vers num="2.1" edition=":ia64" />
      </prod>
      <prod vendor="trustix" name="secure_linux">
        <vers num="2.0" />
        <vers num="2.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2004-0422" published="2004-07-07" name="CVE-2004-0422" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">flim before 1.14.3 creates temporary files insecurely, which allows local users to overwrite arbitrary files of the Emacs user via a symlink attack.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/16027" source="XF" patch="1" adv="1">flim-insecure-temporary-file(16027)</ref>
      <ref url="http://www.debian.org/security/2004/dsa-500" source="DEBIAN" patch="1" adv="1">DSA-500</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-344.html" source="REDHAT">RHSA-2004:344</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gnu" name="flim">
        <vers prev="1" num="1.14.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2004-0423" published="2004-07-07" name="CVE-2004-0423" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">The log_event function in ssmtp 2.50.6 and earlier allows local users to overwrite arbitrary files via a symlink attack on the ssmtp.log temporary log file.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108239608131119&amp;w=2" source="BUGTRAQ">20040418 ssmtp insecure file creation</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ssmtp" name="ssmtp">
        <vers prev="1" num="2.50.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0424" published="2004-07-07" name="CVE-2004-0424" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Integer overflow in the ip_setsockopt function in Linux kernel 2.4.22 through 2.4.25 and 2.6.1 through 2.6.3 allows local users to cause a denial of service (crash) or execute arbitrary code via the MCAST_MSFILTER socket option.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" other="1" admin="1" />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/15907" source="XF" patch="1" adv="1">linux-ipsetsockopt-integer-bo(15907)</ref>
      <ref url="http://www.securityfocus.com/bid/10179" source="BID" patch="1" adv="1">10179</ref>
      <ref url="http://www.linuxsecurity.com/advisories/engarde_advisory-4285.html" source="ENGARDE" patch="1" adv="1">ESA-20040428-004</ref>
      <ref url="http://www.isec.pl/vulnerabilities/isec-0015-msfilter.txt" source="MISC" patch="1" adv="1">http://www.isec.pl/vulnerabilities/isec-0015-msfilter.txt</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108253171301153&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20040420 Linux kernel setsockopt MCAST_MSFILTER integer overflow</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2004_10_kernel.html" source="SUSE">SuSE-SA:2004:010</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11214" source="OVAL">oval:org.mitre.oval:def:11214</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/20040504-01-U.asc" source="SGI">20040504-01-U</ref>
      <ref url="http://www.slackware.com/security/viewer.php?l=slackware-security&amp;y=2004&amp;m=slackware-security.659586" source="SLACKWARE">SSA:2004-119</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-183.html" source="REDHAT">RHSA-2004:183</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2004:037" source="MANDRAKE">MDKSA-2004:037</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000852" source="CONECTIVA">CLA-2004:852</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:939" source="OVAL" sig="1">oval:org.mitre.oval:def:939</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sgi" name="propack">
        <vers num="3.0" />
      </prod>
      <prod vendor="linux" name="linux_kernel">
        <vers num="2.4.22" />
        <vers num="2.4.23" edition="pre9" />
        <vers num="2.4.23_ow2" />
        <vers num="2.4.24" />
        <vers num="2.4.24_ow1" />
        <vers num="2.4.25" />
        <vers num="2.6.1" edition="rc1" />
        <vers num="2.6.1" edition="rc2" />
        <vers num="2.6.2" />
        <vers num="2.6.3" />
      </prod>
      <prod vendor="slackware" name="slackware_linux">
        <vers num="9.1" />
        <vers num="current" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0425" published="2004-08-18" name="CVE-2004-0425" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Heap-based buffer overflow in SiteMinder Affiliate Agent 4.x allows remote attackers to execute arbitrary code via a large SMPROFILE cookie.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/15950" source="XF" adv="1">siteminder-affiliate-smprofile-bo(15950)</ref>
      <ref url="http://www.securityfocus.com/bid/10198" source="BID" adv="1">10198</ref>
      <ref url="http://www.atstake.com/research/advisories/2004/a042204-1.txt" source="ATSTAKE" adv="1">A042204-1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="netegrity" name="sideminder_affiliate_agent">
        <vers num="4.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0426" published="2004-07-07" name="CVE-2004-0426" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">rsync before 2.6.1 does not properly sanitize paths when running a read/write daemon without using chroot, which allows remote attackers to write files outside of the module's path.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-192.html" source="REDHAT" patch="1" adv="1">RHSA-2004:192</ref>
      <ref url="http://www.debian.org/security/2004/dsa-499" source="DEBIAN" patch="1" adv="1">DSA-499</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108515912212018&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20040521 [OpenPKG-SA-2004.025] OpenPKG Security Advisory (rsync)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/16014" source="XF">rsync-write-files(16014)</ref>
      <ref url="http://www.trustix.net/errata/misc/2004/TSL-2004-0024-rsync.asc.txt" source="TRUSTIX">TSL-2004-0024</ref>
      <ref url="http://www.slackware.org/security/viewer.php?l=slackware-security&amp;y=2004&amp;m=slackware-security.403462" source="SLACKWARE">SSA:2004-124-01</ref>
      <ref url="http://www.securityfocus.com/bid/10247" source="BID">10247</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200407-10.xml" source="GENTOO">GLSA-200407-10</ref>
      <ref url="http://www.ciac.org/ciac/bulletins/o-212.shtml" source="CIAC">O-212</ref>
      <ref url="http://www.ciac.org/ciac/bulletins/o-134.shtml" source="CIAC">O-134</ref>
      <ref url="http://secunia.com/advisories/12054" source="SECUNIA">12054</ref>
      <ref url="http://secunia.com/advisories/11993" source="SECUNIA">11993</ref>
      <ref url="http://secunia.com/advisories/11688" source="SECUNIA">11688</ref>
      <ref url="http://secunia.com/advisories/11669" source="SECUNIA">11669</ref>
      <ref url="http://secunia.com/advisories/11583" source="SECUNIA">11583</ref>
      <ref url="http://secunia.com/advisories/11537" source="SECUNIA">11537</ref>
      <ref url="http://secunia.com/advisories/11523" source="SECUNIA">11523</ref>
      <ref url="http://secunia.com/advisories/11515" source="SECUNIA">11515</ref>
      <ref url="http://secunia.com/advisories/11514" source="SECUNIA">11514</ref>
      <ref url="http://rsync.samba.org/" source="CONFIRM" adv="1">http://rsync.samba.org/</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9495" source="OVAL">oval:org.mitre.oval:def:9495</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2004:042" source="MANDRAKE">MDKSA-2004:042</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:967" source="OVAL" sig="1">oval:org.mitre.oval:def:967</ref>
    </refs>
    <vuln_soft>
      <prod vendor="andrew_tridgell" name="rsync">
        <vers prev="1" num="2.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2004-0427" published="2004-07-07" name="CVE-2004-0427" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">The do_fork function in Linux 2.4.x before 2.4.26, and 2.6.x before 2.6.6, does not properly decrement the mm_count counter when an error occurs after the mm_struct for a child process has been activated, which triggers a memory leak that allows local users to cause a denial of service (memory exhaustion) via the clone (CLONE_VM) system call.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=linux-kernel&amp;m=108139073506983&amp;w=2" source="MLIST" patch="1" adv="1">[linux-kernel] 20040408 [PATCH]: 2.4/2.6 do_fork() error path memory leak</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/20040505-01-U.asc" source="SGI" patch="1" adv="1">20040505-01-U</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/20040504-01-U.asc" source="SGI" patch="1" adv="1">20040504-01-U</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-255.html" source="REDHAT">RHSA-2004:255</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2004_10_kernel.html" source="SUSE">SuSE-SA:2004:010</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200407-02.xml" source="GENTOO">GLSA-200407-02</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10297" source="OVAL">oval:org.mitre.oval:def:10297</ref>
      <ref url="http://linux.bkbits.net:8080/linux-2.6/cset@407b1217x4jtqEkpFW2g_-RcF0726A" source="MISC">http://linux.bkbits.net:8080/linux-2.6/cset@407b1217x4jtqEkpFW2g_-RcF0726A</ref>
      <ref url="http://linux.bkbits.net:8080/linux-2.4/cset@407bf20eDeeejm8t36_tpvSE-8EFHA" source="MISC">http://linux.bkbits.net:8080/linux-2.4/cset@407bf20eDeeejm8t36_tpvSE-8EFHA</ref>
      <ref url="http://fedoranews.org/updates/FEDORA-2004-111.shtml" source="FEDORA">FEDORA-2004-111</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000846" source="CONECTIVA">CLA-2004:846</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/16002" source="XF">linux-dofork-memory-leak(16002)</ref>
      <ref url="http://www.turbolinux.com/security/2004/TLSA-2004-14.txt" source="TURBO">TLSA-2004-14</ref>
      <ref url="http://www.securityfocus.com/bid/10221" source="BID">10221</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-327.html" source="REDHAT">RHSA-2004:327</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-260.html" source="REDHAT">RHSA-2004:260</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2004:037" source="MANDRAKE">MDKSA-2004:037</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1082" source="DEBIAN">DSA-1082</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1070" source="DEBIAN">DSA-1070</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1069" source="DEBIAN">DSA-1069</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1067" source="DEBIAN">DSA-1067</ref>
      <ref url="http://www.ciac.org/ciac/bulletins/o-164.shtml" source="CIAC">O-164</ref>
      <ref url="http://secunia.com/advisories/20338" source="SECUNIA">20338</ref>
      <ref url="http://secunia.com/advisories/20202" source="SECUNIA">20202</ref>
      <ref url="http://secunia.com/advisories/20163" source="SECUNIA">20163</ref>
      <ref url="http://secunia.com/advisories/20162" source="SECUNIA">20162</ref>
      <ref url="http://secunia.com/advisories/11892" source="SECUNIA">11892</ref>
      <ref url="http://secunia.com/advisories/11891" source="SECUNIA">11891</ref>
      <ref url="http://secunia.com/advisories/11861" source="SECUNIA">11861</ref>
      <ref url="http://secunia.com/advisories/11541" source="SECUNIA">11541</ref>
      <ref url="http://secunia.com/advisories/11486" source="SECUNIA">11486</ref>
      <ref url="http://secunia.com/advisories/11464" source="SECUNIA">11464</ref>
      <ref url="http://secunia.com/advisories/11429" source="SECUNIA">11429</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2819" source="OVAL" sig="1">oval:org.mitre.oval:def:2819</ref>
    </refs>
    <vuln_soft>
      <prod vendor="linux" name="linux_kernel">
        <vers num="2.4.0" />
        <vers num="2.6.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0428" published="2004-05-03" name="CVE-2004-0428" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Unknown vulnerability in CoreFoundation in Mac OS X 10.3.3 and Mac OS X 10.3.3 Server, related to "the handling of an environment variable," has unknown attack vectors and unknown impact.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/16051" source="XF" patch="1" adv="1">macos-corefoundation-environment(16051)</ref>
      <ref url="http://www.securityfocus.com/bid/10270" source="BID" patch="1" adv="1">10270</ref>
      <ref url="http://www.auscert.org.au/render.html?it=4070" source="AUSCERT" patch="1" adv="1">ESB-2004.0314</ref>
      <ref url="http://securitytracker.com/id?1010045" source="SECTRACK" patch="1" adv="1">1010045</ref>
      <ref url="http://secunia.com/advisories/11539" source="SECUNIA" patch="1" adv="1">11539</ref>
      <ref url="http://lists.virus.org/macsec-0405/msg00000.html" source="APPLE" patch="1" adv="1">APPLE-SA-2004-05-03</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.2" />
        <vers num="10.2.1" />
        <vers num="10.2.2" />
        <vers num="10.2.3" />
        <vers num="10.2.4" />
        <vers num="10.2.5" />
        <vers num="10.2.6" />
        <vers num="10.2.7" />
        <vers num="10.2.8" />
        <vers num="10.3" />
        <vers num="10.3.1" />
        <vers num="10.3.2" />
        <vers num="10.3.3" />
      </prod>
      <prod vendor="apple" name="mac_os_x_server">
        <vers num="10.2" />
        <vers num="10.2.1" />
        <vers num="10.2.2" />
        <vers num="10.2.3" />
        <vers num="10.2.4" />
        <vers num="10.2.5" />
        <vers num="10.2.6" />
        <vers num="10.2.7" />
        <vers num="10.2.8" />
        <vers num="10.3" />
        <vers num="10.3.1" />
        <vers num="10.3.2" />
        <vers num="10.3.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0429" published="2004-12-31" name="CVE-2004-0429" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Unknown vulnerability related to "the handling of large requests" in RAdmin for Apple Mac OS X 10.3.3 and Mac OS X 10.2.8 may allow attackers to have unknown impact via unknown attack vectors.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.auscert.org.au/render.html?it=4070" source="AUSCERT" patch="1">ESB-2004.0314</ref>
      <ref url="http://securitytracker.com/id?1010045" source="SECTRACK" patch="1">1010045</ref>
      <ref url="http://secunia.com/advisories/11539/" source="SECUNIA" patch="1" adv="1">11539</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108369640424244&amp;w=2" source="BUGTRAQ" patch="1">20040503 [product-security@apple.com: APPLE-SA-2004-05-03 Security Update 2004-05-03]</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2004/May/msg00000.html" source="APPLE" patch="1">APPLE-SA-2004-05-03</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/16053" source="XF">macos-radmin-large-request(16053)</ref>
      <ref url="http://www.ciac.org/ciac/bulletins/o-138.shtml" source="CIAC">O-138</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.2.8" />
        <vers num="10.3.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0430" published="2004-07-07" name="CVE-2004-0430" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_score="5.1" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="4.9" CVSS_base_score="5.1">
    <desc>
      <descript source="cve">Stack-based buffer overflow in AppleFileServer for Mac OS X 10.3.3 and earlier allows remote attackers to execute arbitrary code via a LoginExt packet for a Cleartext Password User Authentication Method (UAM) request with a PathName argument that includes an AFPName type string that is longer than the associated length field.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/648406" source="CERT-VN">VU#648406</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/16049" source="XF" patch="1" adv="1">applefileserver-afp-pathname-bo(16049)</ref>
      <ref url="http://www.atstake.com/research/advisories/2004/a050304-1.txt" source="ATSTAKE" patch="1" adv="1">A050304-1</ref>
      <ref url="http://www.securiteam.com/securitynews/5QP0115CUO.html" source="MISC">http://www.securiteam.com/securitynews/5QP0115CUO.html</ref>
      <ref url="http://securitytracker.com/id?1010039" source="SECTRACK">1010039</ref>
      <ref url="http://secunia.com/advisories/11539" source="SECUNIA">11539</ref>
      <ref url="http://lists.apple.com/mhonarc/security-announce/msg00049.html" source="APPLE">APPLE-SA-2004-05-03</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers prev="1" num="10.3.3" />
      </prod>
      <prod vendor="apple" name="mac_os_x_server">
        <vers prev="1" num="10.3.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0431" published="2004-07-07" name="CVE-2004-0431" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_score="5.1" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="4.9" CVSS_base_score="5.1">
    <desc>
      <descript source="cve">Integer overflow in Apple QuickTime (QuickTime.qts) before 6.5.1 allows attackers to execute arbitrary code via a large "number of entries" field in the sample-to-chunk table data for a .mov movie file, which leads to a heap-based buffer overflow.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/782958" source="CERT-VN">VU#782958</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/16026" source="XF" patch="1" adv="1">quicktime-heap-bo(16026)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=108356485013237&amp;w=2" source="NTBUGTRAQ" patch="1" adv="1">20040502 EEYE: Apple QuickTime (QuickTime.qts) Heap Overflow</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108360110618389&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20040502 EEYE: Apple QuickTime (QuickTime.qts) Heap Overflow</ref>
      <ref url="http://lists.apple.com/mhonarc/security-announce/msg00048.html" source="APPLE">APPLE-SA-2004-04-30</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="quicktime">
        <vers prev="1" num="6.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0432" published="2004-08-18" name="CVE-2004-0432" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">ProFTPD 1.2.9 treats the Allow and Deny directives for CIDR based ACL entries as if they were AllowAll, which could allow FTP clients to bypass intended access restrictions.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/10252" source="BID" patch="1" adv="1">10252</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/16038" source="XF" adv="1">proftpd-cidr-acl-bypass(16038)</ref>
      <ref url="http://secunia.com/advisories/11527" source="SECUNIA">11527</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108335030208523&amp;w=2" source="TRUSTIX">2004-0025</ref>
      <ref url="http://bugs.proftpd.org/show_bug.cgi?id=2267" source="CONFIRM">http://bugs.proftpd.org/show_bug.cgi?id=2267</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2004:041" source="MANDRAKE">MDKSA-2004:041</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108335051011341&amp;w=2" source="BUGTRAQ">20040430 [OpenPKG-SA-2004.018] OpenPKG Security Advisory (proftpd)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="proftpd_project" name="proftpd">
        <vers num="1.2.9" />
      </prod>
      <prod vendor="gentoo" name="linux">
        <vers num="0.5" />
        <vers num="0.7" />
        <vers num="1.1a" />
        <vers num="1.2" />
        <vers num="1.4" edition="rc1" />
        <vers num="1.4" edition="rc2" />
        <vers num="1.4" edition="rc3" />
      </prod>
      <prod vendor="trustix" name="secure_linux">
        <vers num="2.0" />
        <vers num="2.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0433" published="2004-08-18" name="CVE-2004-0433" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Multiple buffer overflows in the Real-Time Streaming Protocol (RTSP) client for (1) MPlayer before 1.0pre4 and (2) xine lib (xine-lib) before 1-rc4, when playing Real RTSP (realrtsp) streams, allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via (a) long URLs, (b) long Real server responses, or (c) long Real Data Transport (RDT) packets.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/16019" source="XF" adv="1">mplayer-rtsp-rdt-bo(16019)</ref>
      <ref url="http://www.xinehq.de/index.php/security/XSA-2004-3" source="CONFIRM">http://www.xinehq.de/index.php/security/XSA-2004-3</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200405-24.xml" source="GENTOO" adv="1">GLSA-200405-24</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mplayer" name="mplayer">
        <vers num="1.0_pre3try2" />
      </prod>
      <prod vendor="xine" name="xine-lib">
        <vers num="1_beta1" />
        <vers num="1_beta10" />
        <vers num="1_beta11" />
        <vers num="1_beta2" />
        <vers num="1_beta3" />
        <vers num="1_beta4" />
        <vers num="1_beta5" />
        <vers num="1_beta6" />
        <vers num="1_beta7" />
        <vers num="1_beta8" />
        <vers num="1_beta9" />
        <vers num="1_rc2" />
        <vers num="1_rc3a" />
        <vers num="1_rc3b" />
        <vers num="1_rc3c" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0434" published="2004-07-07" name="CVE-2004-0434" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">k5admind (kadmind) for Heimdal allows remote attackers to execute arbitrary code via a Kerberos 4 compatibility administration request whose framing length is less than 2, which leads to a heap-based buffer overflow.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" other="1" admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/16071" source="XF" patch="1" adv="1">heimdal-kadmind-bo(16071)</ref>
      <ref url="http://www.debian.org/security/2004/dsa-504" source="DEBIAN" patch="1" adv="1">DSA-504</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200405-23.xml" source="GENTOO">GLSA-200405-23</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108386148126457&amp;w=2" source="BUGTRAQ" adv="1">20040505 Advisory: Heimdal kadmind version4 remote heap overflow</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2004-May/020998.html" source="FULLDISC">20040506 Advisory: Heimdal kadmind version4 remote heap overflow</ref>
      <ref url="ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-04:09.kadmind.asc" source="FREEBSD">FreeBSD-SA-04:09</ref>
    </refs>
    <vuln_soft>
      <prod vendor="kth" name="heimdal">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2004-0435" published="2004-08-18" name="CVE-2004-0435" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:P)" CVSS_score="3.6" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="3.9" CVSS_base_score="3.6">
    <desc>
      <descript source="cve">Certain "programming errors" in the msync system call for FreeBSD 5.2.1 and earlier, and 4.10 and earlier, do not properly handle the MS_INVALIDATE operation, which leads to cache consistency problems that allow a local user to prevent certain changes to files from being committed to disk.</descript>
    </desc>
    <loss_types>
      <avail />
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-04:11.msync.asc" source="FREEBSD">FreeBSD-SA-04:11</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/16254" source="XF">freebsd-msync-gain-privileges(16254)</ref>
      <ref url="http://www.securityfocus.com/bid/10416" source="BID">10416</ref>
      <ref url="http://secunia.com/advisories/11714" source="SECUNIA">11714</ref>
    </refs>
    <vuln_soft>
      <prod vendor="freebsd" name="freebsd">
        <vers num="4.0" edition="releng" />
        <vers num="4.10" edition="release" />
        <vers num="4.10" edition="releng" />
        <vers num="4.8" edition="pre-release" />
        <vers num="4.8" edition="release_p6" />
        <vers num="4.8" edition="releng" />
        <vers num="4.9" edition="pre-release" />
        <vers num="4.9" edition="releng" />
        <vers num="5.2" />
        <vers num="5.2.1" edition="release" />
        <vers num="5.2.1" edition="releng" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0437" published="2004-07-07" name="CVE-2004-0437" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Titan FTP Server version 3.01 build 163, and possibly other versions before build 169, allows remote authenticated users to cause a denial of service (crash) by disconnecting from the system during a "LIST -L" command, which causes Titan to access an invalid socket.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/16057" source="XF" patch="1" adv="1">titan-list-command-dos(16057)</ref>
      <ref url="http://www.securiteam.com/windowsntfocus/5RP0215CUU.html" source="MISC" patch="1" adv="1">http://www.securiteam.com/windowsntfocus/5RP0215CUU.html</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108378048513596&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20040505 Titan FTP Server Aborted LIST DoS</ref>
      <ref url="http://archives.neohapsis.com/archives/vulnwatch/2004-q2/0025.html" source="VULNWATCH" patch="1" adv="1">20040505 Titan FTP Server Aborted LIST DoS</ref>
    </refs>
    <vuln_soft>
      <prod vendor="south_river_technologies" name="titan_ftp_server">
        <vers num="3.01_build_163" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0444" published="2004-07-07" name="CVE-2004-0444" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Multiple vulnerabilities in SYMDNS.SYS for Symantec Norton Internet Security and Professional 2002 through 2004, Norton Personal Firewall 2002 through 2004, Norton AntiSpam 2004, Client Firewall 5.01 and 5.1.1, and Client Security 1.0 through 2.0 allow remote attackers to cause a denial of service or execute arbitrary code via (1) a manipulated length byte in the first-level decoding routine for NetBIOS Name Service (NBNS) that modifies an index variable and leads to a stack-based buffer overflow, (2) a heap-based corruption problem in an NBNS response that is missing certain RR fields, and (3) a stack-based buffer overflow in the DNS component via a Resource Record (RR) with a long canonical name (CNAME) field composed of many smaller components.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" other="1" admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" bound="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/634414" source="CERT-VN" patch="1" adv="1">VU#634414</ref>
      <ref url="http://www.kb.cert.org/vuls/id/294998" source="CERT-VN" patch="1" adv="1">VU#294998</ref>
      <ref url="http://www.kb.cert.org/vuls/id/637318" source="CERT-VN">VU#637318</ref>
      <ref url="http://www.securityfocus.com/bid/10335" source="BID">10335</ref>
      <ref url="http://www.securityfocus.com/bid/10334" source="BID">10334</ref>
      <ref url="http://www.securityfocus.com/bid/10333" source="BID">10333</ref>
      <ref url="http://securityresponse.symantec.com/avcenter/security/Content/2004.05.12.html" source="CONFIRM">http://securityresponse.symantec.com/avcenter/security/Content/2004.05.12.html</ref>
      <ref url="http://secunia.com/advisories/11066" source="SECUNIA">11066</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2004-May/021362.html" source="FULLDISC">20040512 EEYE: Symantec Multiple Firewall NBNS Response Remote Heap Corruption</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2004-May/021361.html" source="FULLDISC">20040512 EEYE: Symantec Multiple Firewall Remote DNS KERNEL Overflow</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2004-May/021360.html" source="FULLDISC">20040512 EEYE: Symantec Multiple Firewall NBNS Response Processing Stack Overflow</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/16137" source="XF">symantec-dns-response-bo(16137)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/16135" source="XF">symantec-firewalls-nbns-bo(16135)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/16134" source="XF">symantec-nbns-response-bo(16134)</ref>
      <ref url="http://www.osvdb.org/6102" source="OSVDB">6102</ref>
      <ref url="http://www.osvdb.org/6101" source="OSVDB">6101</ref>
      <ref url="http://www.osvdb.org/6099" source="OSVDB">6099</ref>
      <ref url="http://www.ciac.org/ciac/bulletins/o-141.shtml" source="CIAC">O-141</ref>
      <ref url="http://securitytracker.com/id?1010146" source="SECTRACK">1010146</ref>
      <ref url="http://securitytracker.com/id?1010145" source="SECTRACK">1010145</ref>
      <ref url="http://securitytracker.com/id?1010144" source="SECTRACK">1010144</ref>
    </refs>
    <vuln_soft>
      <prod vendor="symantec" name="client_firewall">
        <vers num="5.01" />
        <vers num="5.1.1" />
      </prod>
      <prod vendor="symantec" name="client_security">
        <vers num="1.0" />
        <vers num="1.1" />
        <vers num="1.2" />
        <vers num="1.3" />
        <vers num="1.4" />
        <vers num="1.5" />
        <vers num="1.6" />
        <vers num="1.7" />
        <vers num="1.8" />
        <vers num="1.9" />
        <vers num="2.0" />
      </prod>
      <prod vendor="symantec" name="norton_antispam">
        <vers num="2004" />
      </prod>
      <prod vendor="symantec" name="norton_internet_security">
        <vers num="2002" edition="" />
        <vers num="2002" edition=":pro" />
        <vers num="2003" edition="" />
        <vers num="2003" edition=":pro" />
        <vers num="2004" edition="" />
        <vers num="2004" edition=":pro" />
      </prod>
      <prod vendor="symantec" name="norton_personal_firewall">
        <vers num="2002" />
        <vers num="2003" />
        <vers num="2004" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2004-0445" published="2004-07-07" name="CVE-2004-0445" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:N/A:P)" CVSS_score="2.6" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="4.9" CVSS_base_score="2.6">
    <desc>
      <descript source="cve">The SYMDNS.SYS driver in Symantec Norton Internet Security and Professional 2002 through 2004, Norton Personal Firewall 2002 through 2004, Norton AntiSpam 2004, Client Firewall 5.01 and 5.1.1, and Client Security 1.0 through 2.0 allows remote attackers to cause a denial of service (CPU consumption from infinite loop) via a DNS response with a compressed name pointer that points to itself.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/682110" source="CERT-VN" patch="1" adv="1">VU#682110</ref>
      <ref url="http://securityresponse.symantec.com/avcenter/security/Content/2004.05.12.html" source="CONFIRM" patch="1" adv="1">http://securityresponse.symantec.com/avcenter/security/Content/2004.05.12.html</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/16132" source="XF">symantec-firewall-dns-dos(16132)</ref>
      <ref url="http://www.securityfocus.com/bid/10336" source="BID">10336</ref>
      <ref url="http://secunia.com/advisories/11066" source="SECUNIA">11066</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2004-May/021359.html" source="FULLDISC">20040512 EEYE: Symantec Multiple Firewall DNS Response Denial-of-Service</ref>
      <ref url="http://www.osvdb.org/6100" source="OSVDB">6100</ref>
      <ref url="http://www.ciac.org/ciac/bulletins/o-141.shtml" source="CIAC">O-141</ref>
      <ref url="http://securitytracker.com/id?1010146" source="SECTRACK">1010146</ref>
      <ref url="http://securitytracker.com/id?1010145" source="SECTRACK">1010145</ref>
      <ref url="http://securitytracker.com/id?1010144" source="SECTRACK">1010144</ref>
    </refs>
    <vuln_soft>
      <prod vendor="symantec" name="client_firewall">
        <vers num="5.01" />
        <vers num="5.1.1" />
      </prod>
      <prod vendor="symantec" name="client_security">
        <vers num="1.0" />
        <vers num="1.1" />
        <vers num="1.2" />
        <vers num="1.3" />
        <vers num="1.4" />
        <vers num="1.5" />
        <vers num="1.6" />
        <vers num="1.7" />
        <vers num="1.8" />
        <vers num="1.9" />
        <vers num="2.0" />
      </prod>
      <prod vendor="symantec" name="norton_antispam">
        <vers num="2004" />
      </prod>
      <prod vendor="symantec" name="norton_internet_security">
        <vers num="2002" edition="" />
        <vers num="2002" edition=":pro" />
        <vers num="2003" edition="" />
        <vers num="2003" edition=":pro" />
        <vers num="2004" edition="" />
        <vers num="2004" edition=":pro" />
      </prod>
      <prod vendor="symantec" name="norton_personal_firewall">
        <vers num="2002" />
        <vers num="2003" />
        <vers num="2004" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0447" published="2004-08-06" name="CVE-2004-0447" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Unknown vulnerability in Linux before 2.4.26 for IA64 allows local users to cause a denial of service, with unknown impact.  NOTE: due to a typo, this issue was accidentally assigned CVE-2004-0477.  This is the proper candidate to use for the Linux local DoS.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <exception />
      <other />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/10783" source="BID" patch="1" adv="1">10783</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/16661" source="XF">linux-ia64-dos(16661)</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-413.html" source="REDHAT">RHSA-2004:413</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1082" source="DEBIAN">DSA-1082</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1070" source="DEBIAN">DSA-1070</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1069" source="DEBIAN">DSA-1069</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1067" source="DEBIAN">DSA-1067</ref>
      <ref url="http://www.ciac.org/ciac/bulletins/o-193.shtml" source="CIAC">O-193</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200407-16.xml" source="GENTOO">GLSA-200407-16</ref>
      <ref url="http://secunia.com/advisories/20338" source="SECUNIA">20338</ref>
      <ref url="http://secunia.com/advisories/20202" source="SECUNIA">20202</ref>
      <ref url="http://secunia.com/advisories/20163" source="SECUNIA">20163</ref>
      <ref url="http://secunia.com/advisories/20162" source="SECUNIA">20162</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10918" source="OVAL">oval:org.mitre.oval:def:10918</ref>
      <ref url="http://archives.neohapsis.com/archives/linux/owl/2004-q2/0038.html" source="MLIST" adv="1">[owl-users] 20040619 Linux 2.4.26-ow2</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/20040804-01-U.asc" source="SGI">20040804-01-U</ref>
    </refs>
    <vuln_soft>
      <prod vendor="linux" name="linux_kernel">
        <vers prev="1" num="2.4.25" edition="" />
        <vers prev="1" num="2.4.25" edition=":ia64" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0448" published="2004-12-06" name="CVE-2004-0448" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Format string vulnerability in the log function for jftpgw 0.13.4 and earlier allows remote authenticated users to execute arbitrary code via format string specifiers in certain syslog messages.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input />
      <design />
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/16271" source="XF" patch="1" adv="1">jftpgw-log-format-string(16271)</ref>
      <ref url="http://www.securityfocus.com/bid/10438" source="BID" patch="1" adv="1">10438</ref>
      <ref url="http://www.debian.org/security/2004/dsa-510" source="DEBIAN" patch="1" adv="1">DSA-510</ref>
    </refs>
    <vuln_soft>
      <prod vendor="jftpgw" name="jftpgw">
        <vers num="0.13" />
        <vers num="0.13.1" />
        <vers num="0.13.2" />
        <vers num="0.13.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0450" published="2004-08-06" name="CVE-2004-0450" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Format string vulnerability in the printlog function in log2mail before 0.2.5.2 allows local users or remote attackers to execute arbitrary code via format string specifiers in a logfile monitored by log2mail.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" admin="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/10460" source="BID" patch="1" adv="1">10460</ref>
      <ref url="http://www.debian.org/security/2004/dsa-513" source="DEBIAN" patch="1" adv="1">DSA-513</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/16311" source="XF">log2mail-syslog-format-string(16311)</ref>
      <ref url="http://secunia.com/advisories/11769" source="SECUNIA">11769</ref>
      <ref url="http://secunia.com/advisories/11768" source="SECUNIA">11768</ref>
      <ref url="http://osvdb.org/6711" source="OSVDB">6711</ref>
      <ref url="http://felinemenace.org/~jaguar/advisories/log2mail.txt" source="MISC">http://felinemenace.org/~jaguar/advisories/log2mail.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="log2mail" name="log2mail">
        <vers num="0.2.2.2" />
        <vers num="0.2.5.0" />
        <vers num="0.2.5.1" />
        <vers num="0.2.5.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0451" published="2004-12-06" name="CVE-2004-0451" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Multiple format string vulnerabilities in the (1) logquit, (2) logerr, or (3) loginfo functions in Software Upgrade Protocol (SUP) allows remote attackers to execute arbitrary code via format string specifiers in messages that are logged by syslog.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input />
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/16459" source="XF" patch="1" adv="1">sup-format-string(16459)</ref>
      <ref url="http://www.securityfocus.com/bid/10571" source="BID" patch="1" adv="1">10571</ref>
      <ref url="http://www.debian.org/security/2004/dsa-521" source="DEBIAN" patch="1" adv="1">DSA-521</ref>
      <ref url="http://securitytracker.com/id?1010539" source="SECTRACK">1010539</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sup" name="sup">
        <vers num="1.8" />
      </prod>
      <prod vendor="debian" name="debian_linux">
        <vers num="3.0" edition="" />
        <vers num="3.0" edition=":hppa" />
        <vers num="3.0" edition=":mips" />
        <vers num="3.0" edition=":ia-32" />
        <vers num="3.0" edition=":m68k" />
        <vers num="3.0" edition=":s-390" />
        <vers num="3.0" edition=":alpha" />
        <vers num="3.0" edition=":arm" />
        <vers num="3.0" edition=":ia-64" />
        <vers num="3.0" edition=":mipsel" />
        <vers num="3.0" edition=":sparc" />
        <vers num="3.0" edition=":ppc" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2004-0452" published="2004-12-21" name="CVE-2004-0452" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:H/Au:N/C:N/I:P/A:P)" CVSS_score="2.6" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="1.9" CVSS_base_score="2.6">
    <desc>
      <descript source="cve">Race condition in the rmtree function in the File::Path module in Perl 5.6.1 and 5.8.4 sets read/write permissions for the world, which allows local users to delete arbitrary files and directories, and possibly read files and directories, via a symlink attack.</descript>
    </desc>
    <loss_types>
      <avail />
      <int />
    </loss_types>
    <vuln_types>
      <race />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-103.html" source="REDHAT" patch="1" adv="1">RHSA-2005:103</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200501-38.xml" source="GENTOO" patch="1" adv="1">GLSA-200501-38</ref>
      <ref url="http://www.debian.org/security/2004/dsa-620" source="DEBIAN" patch="1" adv="1">DSA-620</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110547693019788&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20050111 [OpenPKG-SA-2005.001] OpenPKG Security Advisory (perl)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/18650" source="XF">perl-filepathrmtree-insecure-permissions(18650)</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9938" source="OVAL">oval:org.mitre.oval:def:9938</ref>
      <ref url="http://marc.free.net.ph/message/20041221.102713.5d5e603a.html" source="UBUNTU" adv="1">USN-44-1</ref>
      <ref url="http://www.securityfocus.com/bid/12072" source="BID">12072</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-105.html" source="REDHAT">RHSA-2005:105</ref>
      <ref url="http://secunia.com/advisories/18517" source="SECUNIA">18517</ref>
      <ref url="http://secunia.com/advisories/12991" source="SECUNIA">12991</ref>
      <ref url="http://fedoranews.org/updates/FEDORA--.shtml" source="FEDORA">FLSA-2006:152845</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/20060101-01-U" source="SGI">20060101-01-U</ref>
    </refs>
    <vuln_soft>
      <prod vendor="larry_wall" name="perl">
        <vers num="5.6.1" />
        <vers num="5.8.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0453" published="2004-08-06" name="CVE-2004-0453" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Format string vulnerability in the monitor "memory dump" command in VICE 1.6 to 1.14 allows local users to cause a denial of service (emulator crash) and possibly execute arbitrary code via format string specifiers in an output string.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" admin="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/10543" source="BID" patch="1" adv="1">10543</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/16404" source="XF" adv="1">vice-memory-dump-format-string(16404)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108723630730487&amp;w=2" source="BUGTRAQ" adv="1">20040614 VICE emulator format string vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="vice" name="vice">
        <vers num="1.13" />
        <vers num="1.14" />
        <vers num="1.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0454" published="2004-12-06" name="CVE-2004-0454" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Buffer overflow in the msg function for rlpr daemon (rlprd) 2.04 allows local users to execute arbitrary code.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/16454" source="XF" patch="1" adv="1">rlpr-msg-bo(16454)</ref>
      <ref url="http://www.securityfocus.com/bid/10578" source="BID" patch="1" adv="1">10578</ref>
      <ref url="http://www.debian.org/security/2004/dsa-524" source="DEBIAN" patch="1" adv="1">DSA-524</ref>
    </refs>
    <vuln_soft>
      <prod vendor="rlpr" name="rlpr">
        <vers num="2.0" />
        <vers num="2.0.1" />
        <vers num="2.0.2" />
        <vers num="2.0.3" />
        <vers num="2.0.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0455" published="2004-12-06" name="CVE-2004-0455" modified="2005-10-20" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Buffer overflow in cgi.c in www-sql before 0.5.7 allows local users to execute arbitrary code via a web page that is processed by www-sql.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/16455" source="XF">wwwsql-cgi-command-execution(16455)</ref>
      <ref url="http://www.securityfocus.com/bid/10577" source="BID">10577</ref>
      <ref url="http://www.debian.org/security/2004/dsa-523" source="DEBIAN">DSA-523</ref>
    </refs>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0456" published="2004-12-06" name="CVE-2004-0456" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:H/Au:N/C:C/I:C/A:C)" CVSS_score="7.6" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="4.9" CVSS_base_score="7.6">
    <desc>
      <descript source="cve">Stack-based buffer overflow in pavuk 0.9pl28, 0.9pl27, and possibly other versions allows remote web sites to execute arbitrary code via a long HTTP Location header.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/16551" source="XF" patch="1" adv="1">pavuk-location-bo(16551)</ref>
      <ref url="http://www.securityfocus.com/bid/10633" source="BID" patch="1" adv="1">10633</ref>
      <ref url="http://www.debian.org/security/2004/dsa-527" source="DEBIAN" patch="1" adv="1">DSA-527</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200406-22.xml" source="GENTOO" patch="1" adv="1">GLSA-200406-22</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2004-July/023322.html" source="FULLDISC">20040702 pavuk buffer overflow</ref>
    </refs>
    <vuln_soft>
      <prod vendor="pavuk" name="pavuk">
        <vers num="0.928r1" />
        <vers num="0.9pl28i" />
      </prod>
      <prod vendor="debian" name="debian_linux">
        <vers num="3.0" edition="" />
        <vers num="3.0" edition=":hppa" />
        <vers num="3.0" edition=":mips" />
        <vers num="3.0" edition=":ia-32" />
        <vers num="3.0" edition=":m68k" />
        <vers num="3.0" edition=":s-390" />
        <vers num="3.0" edition=":alpha" />
        <vers num="3.0" edition=":arm" />
        <vers num="3.0" edition=":ia-64" />
        <vers num="3.0" edition=":mipsel" />
        <vers num="3.0" edition=":sparc" />
        <vers num="3.0" edition=":ppc" />
      </prod>
      <prod vendor="gentoo" name="linux">
        <vers num="1.1a" />
        <vers num="1.2" />
        <vers num="1.4" edition="rc1" />
        <vers num="1.4" edition="rc2" />
        <vers num="1.4" edition="rc3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0457" published="2004-09-28" name="CVE-2004-0457" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">The mysqlhotcopy script in mysql 4.0.20 and earlier, when using the scp method from the mysql-server package, allows local users to overwrite arbitrary files via a symlink attack on temporary files.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/17030" source="XF" patch="1" adv="1">mysql-mysqlhotcopy-insecure-file(17030)</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-597.html" source="REDHAT" patch="1" adv="1">RHSA-2004:597</ref>
      <ref url="http://www.debian.org/security/2004/dsa-540" source="DEBIAN" patch="1" adv="1">DSA-540</ref>
      <ref url="http://www.ciac.org/ciac/bulletins/p-018.shtml" source="CIAC">P-018</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10693" source="OVAL">oval:org.mitre.oval:def:10693</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mysql" name="mysql">
        <vers prev="1" num="4.0.20" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0458" published="2004-09-28" name="CVE-2004-0458" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">mah-jong before 1.6.2 allows remote attackers to cause a denial of service (server crash) via a missing argument, which triggers a null pointer dereference.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/16143" source="XF" patch="1" adv="1">mah-jong-null-dos(16143)</ref>
      <ref url="http://www.securityfocus.com/bid/10343" source="BID" patch="1" adv="1">10343</ref>
      <ref url="http://www.debian.org/security/2004/dsa-503" source="DEBIAN" patch="1" adv="1">DSA-503</ref>
    </refs>
    <vuln_soft>
      <prod vendor="nicolas_boullis" name="mah-jong">
        <vers num="1.4" />
        <vers num="1.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0459" published="2004-07-07" name="CVE-2004-0459" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The Clear Channel Assessment (CCA) algorithm in the IEEE 802.11 wireless protocol, when using DSSS transmission encoding, allows remote attackers to cause a denial of service via a certain RF signal that causes a channel to appear busy (aka "jabber"), which prevents devices from transmitting data.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/106678" source="CERT-VN" adv="1">VU#106678</ref>
      <ref url="http://www.auscert.org.au/render.html?it=4091" source="AUSCERT" adv="1">AA-2004.02</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/16138" source="XF">ieee80211-cca-dos(16138)</ref>
      <ref url="http://www.securityfocus.com/bid/10342" source="BID">10342</ref>
      <ref url="http://www.osvdb.org/16034" source="OSVDB">16034</ref>
      <ref url="http://support.avaya.com/elmodocs2/security/ASA-2004-009.pdf" source="MISC">http://support.avaya.com/elmodocs2/security/ASA-2004-009.pdf</ref>
      <ref url="http://securitytracker.com/id?1010152" source="SECTRACK">1010152</ref>
      <ref url="http://archives.neohapsis.com/archives/fulldisclosure/2004-05/0631.html" source="FULLDISC">20040513 802.11b (others) single packet DoS</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ieee" name="802.11_wireless_protocol">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0460" published="2004-08-06" name="CVE-2004-0460" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Buffer overflow in the logging capability for the DHCP daemon (DHCPD) for ISC DHCP 3.0.1rc12 and 3.0.1rc13 allows remote attackers to cause a denial of service (server crash) and possibly execute arbitrary code via multiple hostname options in (1) DISCOVER, (2) OFFER, (3) REQUEST, (4) ACK, or (5) NAK messages, which can generate a long string when writing to a log file.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA04-174A.html" source="CERT" adv="1">TA04-174A</ref>
      <ref url="http://www.kb.cert.org/vuls/id/317350" source="CERT-VN">VU#317350</ref>
      <ref url="http://www.securityfocus.com/bid/10590" source="BID" patch="1" adv="1">10590</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/16475" source="XF" adv="1">dhcp-ascii-log-bo(16475)</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2004_19_dhcp_server.html" source="SUSE">SuSE-SA:2004:019</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108843959502356&amp;w=2" source="BUGTRAQ" adv="1">20040628 ISC DHCP overflows</ref>
      <ref url="http://www.xerox.com/downloads/usa/en/c/cert_XRX06_004_v11.pdf" source="CONFIRM">http://www.xerox.com/downloads/usa/en/c/cert_XRX06_004_v11.pdf</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2004:061" source="MANDRAKE">MDKSA-2004:061</ref>
      <ref url="http://secunia.com/advisories/23265" source="SECUNIA">23265</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108938625206063&amp;w=2" source="BUGTRAQ">20040708 [OpenPKG-SA-2004.031] OpenPKG Security Advisory (dhcpd)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108795911203342&amp;w=2" source="BUGTRAQ">20040622 DHCP Vuln // no code 0day //</ref>
    </refs>
    <vuln_soft>
      <prod vendor="isc" name="dhcpd">
        <vers num="3.0.1" edition="rc12" />
        <vers num="3.0.1" edition="rc13" />
      </prod>
      <prod vendor="suse" name="suse_email_server">
        <vers num="iii" />
      </prod>
      <prod vendor="suse" name="suse_linux_admin-cd_for_firewall">
        <vers num="" />
      </prod>
      <prod vendor="suse" name="suse_linux_connectivity_server">
        <vers num="" />
      </prod>
      <prod vendor="suse" name="suse_linux_database_server">
        <vers num="" />
      </prod>
      <prod vendor="suse" name="suse_linux_firewall_cd">
        <vers num="" />
      </prod>
      <prod vendor="suse" name="suse_linux_office_server">
        <vers num="" />
      </prod>
      <prod vendor="infoblox" name="dns_one_appliance">
        <vers num="2.3.1_r5" />
        <vers num="2.4.0.8" />
        <vers num="2.4.0.8a" />
      </prod>
      <prod vendor="mandrakesoft" name="mandrake_linux">
        <vers num="10.0" edition="" />
        <vers num="10.0" edition=":amd64" />
        <vers num="9.0" />
        <vers num="9.1" edition="" />
        <vers num="9.1" edition=":ppc" />
        <vers num="9.2" edition="" />
        <vers num="9.2" edition=":amd64" />
      </prod>
      <prod vendor="redhat" name="fedora_core">
        <vers num="core_2.0" />
      </prod>
      <prod vendor="suse" name="suse_linux">
        <vers num="7" edition="" />
        <vers num="7" edition=":enterprise_server" />
        <vers num="8" edition="" />
        <vers num="8" edition=":enterprise_server" />
        <vers num="8.0" edition="" />
        <vers num="8.0" edition=":i386" />
        <vers num="8.1" />
        <vers num="8.2" />
        <vers num="9.0" edition="" />
        <vers num="9.0" edition=":x86_64" />
        <vers num="9.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0461" published="2004-08-06" name="CVE-2004-0461" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">The DHCP daemon (DHCPD) for ISC DHCP 3.0.1rc12 and 3.0.1rc13, when compiled in environments that do not provide the vsnprintf function, uses C include files that define vsnprintf to use the less safe vsprintf function, which can lead to buffer overflow vulnerabilities that enable a denial of service (server crash) and possibly execute arbitrary code.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA04-174A.html" source="CERT" adv="1">TA04-174A</ref>
      <ref url="http://www.kb.cert.org/vuls/id/654390" source="CERT-VN">VU#654390</ref>
      <ref url="http://www.securityfocus.com/bid/10591" source="BID" patch="1" adv="1">10591</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/16476" source="XF" adv="1">dhcp-c-include-bo(16476)</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2004_19_dhcp_server.html" source="SUSE">SuSE-SA:2004:019</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108843959502356&amp;w=2" source="BUGTRAQ" adv="1">20040628 ISC DHCP overflows</ref>
      <ref url="http://www.xerox.com/downloads/usa/en/c/cert_XRX06_004_v11.pdf" source="CONFIRM">http://www.xerox.com/downloads/usa/en/c/cert_XRX06_004_v11.pdf</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2004:061" source="MANDRAKE">MDKSA-2004:061</ref>
      <ref url="http://secunia.com/advisories/23265" source="SECUNIA">23265</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108938625206063&amp;w=2" source="BUGTRAQ">20040708 [OpenPKG-SA-2004.031] OpenPKG Security Advisory (dhcpd)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108795911203342&amp;w=2" source="BUGTRAQ">20040622 DHCP Vuln // no code 0day //</ref>
    </refs>
    <vuln_soft>
      <prod vendor="isc" name="dhcpd">
        <vers num="3.0.1" edition="rc12" />
        <vers num="3.0.1" edition="rc13" />
      </prod>
      <prod vendor="suse" name="suse_email_server">
        <vers num="iii" />
      </prod>
      <prod vendor="suse" name="suse_linux_admin-cd_for_firewall">
        <vers num="" />
      </prod>
      <prod vendor="suse" name="suse_linux_connectivity_server">
        <vers num="" />
      </prod>
      <prod vendor="suse" name="suse_linux_database_server">
        <vers num="" />
      </prod>
      <prod vendor="suse" name="suse_linux_firewall_cd">
        <vers num="" />
      </prod>
      <prod vendor="suse" name="suse_linux_office_server">
        <vers num="" />
      </prod>
      <prod vendor="infoblox" name="dns_one_appliance">
        <vers num="2.3.1_r5" />
        <vers num="2.4.0.8" />
        <vers num="2.4.0.8a" />
      </prod>
      <prod vendor="mandrakesoft" name="mandrake_linux">
        <vers num="10.0" edition="" />
        <vers num="10.0" edition=":amd64" />
        <vers num="9.0" />
        <vers num="9.1" edition="" />
        <vers num="9.1" edition=":ppc" />
        <vers num="9.2" edition="" />
        <vers num="9.2" edition=":amd64" />
      </prod>
      <prod vendor="redhat" name="fedora_core">
        <vers num="core_2.0" />
      </prod>
      <prod vendor="suse" name="suse_linux">
        <vers num="7" edition="" />
        <vers num="7" edition=":enterprise_server" />
        <vers num="8" edition="" />
        <vers num="8" edition=":enterprise_server" />
        <vers num="8.0" edition="" />
        <vers num="8.0" edition=":i386" />
        <vers num="8.1" />
        <vers num="8.2" />
        <vers num="9.0" edition="" />
        <vers num="9.0" edition=":x86_64" />
        <vers num="9.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2004-0462" published="2004-12-31" name="CVE-2004-0462" modified="2005-10-20" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">The built-in web servers for multiple networking devices do not set the Secure attribute for sensitive cookies in HTTPS sessions, which could cause the user agent to send those cookies in plaintext over an HTTP session with the same server.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/546483" source="CERT-VN" adv="1">VU#546483</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/17702" source="XF">network-device-secure-plaintext(17702)</ref>
    </refs>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0465" published="2004-12-31" name="CVE-2004-0465" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in jretest.html in WebConnect 6.5 and 6.4.4, and possibly earlier versions, allows remote attackers to read keys within arbitrary INI formatted files via "..//" sequences in the WCP_USER parameter.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/JSHA-69HVPK" source="CONFIRM" adv="1">http://www.kb.cert.org/vuls/id/JSHA-69HVPK</ref>
      <ref url="http://www.kb.cert.org/vuls/id/628411" source="CERT-VN" adv="1">VU#628411</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/19394" source="XF" patch="1">webconnect-wcpuser-directory-traversal(19394)</ref>
      <ref url="http://www.cirt.dk/advisories/cirt-29-advisory.pdf" source="MISC" patch="1" adv="1">http://www.cirt.dk/advisories/cirt-29-advisory.pdf</ref>
      <ref url="http://secunia.com/advisories/14006/" source="SECUNIA" patch="1">14006</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110910838600145&amp;w=2" source="BUGTRAQ" adv="1">20050220 The WebConnect 6.4.4 and 6.5 contains several vulnerabilities</ref>
    </refs>
    <vuln_soft>
      <prod vendor="openconnect" name="webconnect">
        <vers num="6.4.4" />
        <vers num="6.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0466" published="2004-02-21" name="CVE-2004-0466" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">WebConnect 6.5, 6.4.4, and possibly earlier versions allows remote attackers to cause a denial of service (hang) via a URL containing an MS-DOS device name such as (1) AUX, (2) CON, (3) PRN, (4) COM1, or (5) LPT1.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/JSHA-69FVMM" source="CONFIRM" patch="1" adv="1">http://www.kb.cert.org/vuls/id/JSHA-69FVMM</ref>
      <ref url="http://www.kb.cert.org/vuls/id/552561" source="CERT-VN" patch="1" adv="1">VU#552561</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/19393" source="XF" patch="1" adv="1">webconnect-device-name-dos(19393)</ref>
      <ref url="http://secunia.com/advisories/14006/" source="SECUNIA" patch="1" adv="1">14006</ref>
      <ref url="http://www.cirt.dk/advisories/cirt-29-advisory.pdf" source="MISC" adv="1">http://www.cirt.dk/advisories/cirt-29-advisory.pdf</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110910838600145&amp;w=2" source="BUGTRAQ" adv="1">20050220 The WebConnect 6.4.4 and 6.5 contains several vulnerabilities</ref>
    </refs>
    <vuln_soft>
      <prod vendor="openconnect" name="webconnect">
        <vers num="6.4.4" />
        <vers num="6.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0467" published="2004-12-31" name="CVE-2004-0467" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Juniper JUNOS 5.x through JUNOS 7.x allows remote attackers to cause a denial of service (routing disabled) via a large number of MPLS packets, which are not filtered or verified before being sent to the Routing Engine, which reduces the speed at which other packets are processed.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/JSHA-68ZJCQ" source="CONFIRM" patch="1" adv="1">http://www.kb.cert.org/vuls/id/JSHA-68ZJCQ</ref>
      <ref url="http://www.kb.cert.org/vuls/id/409555" source="CERT-VN" patch="1" adv="1">VU#409555</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/19094" source="XF" patch="1">junos-dos(19094)</ref>
      <ref url="http://www.securityfocus.com/bid/12379" source="BID" patch="1">12379</ref>
      <ref url="http://www.niscc.gov.uk/niscc/docs/al-20050126-00067.html?lang=en" source="MISC" patch="1" adv="1">http://www.niscc.gov.uk/niscc/docs/al-20050126-00067.html?lang=en</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-081.html" source="REDHAT">RHSA-2005:081</ref>
      <ref url="http://securitytracker.com/id?1013039" source="SECTRACK">1013039</ref>
      <ref url="http://secunia.com/advisories/14049" source="SECUNIA">14049</ref>
    </refs>
    <vuln_soft>
      <prod vendor="juniper" name="junos">
        <vers num="5.0" />
        <vers num="5.1" />
        <vers num="5.2" />
        <vers num="5.3" />
        <vers num="5.4" />
        <vers num="5.5" />
        <vers num="5.6" />
        <vers num="5.7" />
        <vers num="6.1" />
        <vers num="6.2" />
        <vers num="6.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0468" published="2004-12-06" name="CVE-2004-0468" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Memory leak in Juniper JUNOS Packet Forwarding Engine (PFE) allows remote attackers to cause a denial of service (memory exhaustion and device reboot) via certain IPv6 packets.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <design />
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/658859" source="CERT-VN" patch="1" adv="1">VU#658859</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/16548" source="XF" patch="1" adv="1">juniper-ipv6-dos(16548)</ref>
      <ref url="http://www.kb.cert.org/vuls/id/JSHA-6253CC" source="CONFIRM" patch="1" adv="1">http://www.kb.cert.org/vuls/id/JSHA-6253CC</ref>
      <ref url="http://www.jpcert.or.jp/at/2004/at040009.txt" source="MISC" patch="1" adv="1">http://www.jpcert.or.jp/at/2004/at040009.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="juniper" name="junos">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0469" published="2004-07-07" name="CVE-2004-0469" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Buffer overflow in the ISAKMP functionality for Check Point VPN-1 and FireWall-1 NG products, before VPN-1/FireWall-1 R55 HFA-03, R54 HFA-410 and NG FP3 HFA-325, or VPN-1 SecuRemote/SecureClient R56, may allow remote attackers to execute arbitrary code during VPN tunnel negotiation.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" other="1" admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/16060" source="XF" patch="1" adv="1">vpn1-isakmp-bo(16060)</ref>
      <ref url="http://www.securityfocus.com/bid/10273" source="BID" patch="1" adv="1">10273</ref>
      <ref url="http://www.checkpoint.com/techsupport/alerts/ike_vpn.html" source="CHECKPOINT" patch="1" adv="1">20040504 ISAKMP Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="checkpoint" name="firewall-1">
        <vers num="" edition=":vsx-ng-ai" />
        <vers num="2.0" edition="" />
        <vers num="2.0" edition=":gx" />
        <vers num="2.0.1" edition="" />
        <vers num="2.0.1" edition=":vsx" />
      </prod>
      <prod vendor="checkpoint" name="next_generation">
        <vers num="" edition=":fp3" />
      </prod>
      <prod vendor="checkpoint" name="ng-ai">
        <vers num="r54" />
        <vers num="r55" />
      </prod>
      <prod vendor="checkpoint" name="vpn-1">
        <vers num="vsx_2.0.1" />
        <vers num="vsx_ng_with_application_intelligence" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0470" published="2004-07-07" name="CVE-2004-0470" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">BEA WebLogic Server and WebLogic Express 7.0 through SP5 and 8.1 through SP2, when editing weblogic.xml using WebLogic Builder or the SecurityRoleAssignmentMBean.toXML method, inadvertently removes security-role-assignment tags when weblogic.xml does not have a principal-name tag, which can remove intended access restrictions for the associated web application.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <design />
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/950070" source="CERT-VN" adv="1">VU#950070</ref>
      <ref url="http://dev2dev.bea.com/resourcelibrary/advisoriesnotifications/BEA04_59.00.jsp" source="CONFIRM" patch="1" adv="1">http://dev2dev.bea.com/resourcelibrary/advisoriesnotifications/BEA04_59.00.jsp</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/16123" source="XF">weblogic-application-unauth-access(16123)</ref>
      <ref url="http://www.securityfocus.com/bid/10328" source="BID">10328</ref>
      <ref url="http://www.osvdb.org/6076" source="OSVDB">6076</ref>
      <ref url="http://securitytracker.com/id?1010128" source="SECTRACK">1010128</ref>
      <ref url="http://secunia.com/advisories/11593" source="SECUNIA">11593</ref>
    </refs>
    <vuln_soft>
      <prod vendor="bea" name="weblogic_server">
        <vers num="7.0" edition="" />
        <vers num="7.0" edition=":express" />
        <vers num="8.1" edition="" />
        <vers num="8.1" edition=":express" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2004-0471" published="2004-07-07" name="CVE-2004-0471" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">BEA WebLogic Server and WebLogic Express 7.0 through SP5 and 8.1 through SP2 does not enforce site restrictions for starting and stopping servers for users in the Admin and Operator security roles, which allows unauthorized users to cause a denial of service (service shutdown).</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://dev2dev.bea.com/resourcelibrary/advisoriesnotifications/BEA04_60.00.jsp" source="CONFIRM" patch="1" adv="1">http://dev2dev.bea.com/resourcelibrary/advisoriesnotifications/BEA04_60.00.jsp</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/16121" source="XF">weblogic-server-policy-bypass(16121)</ref>
      <ref url="http://www.securityfocus.com/bid/10327" source="BID">10327</ref>
      <ref url="http://www.osvdb.org/6077" source="OSVDB">6077</ref>
      <ref url="http://securitytracker.com/id?1010129" source="SECTRACK">1010129</ref>
      <ref url="http://secunia.com/advisories/11594" source="SECUNIA">11594</ref>
    </refs>
    <vuln_soft>
      <prod vendor="bea" name="weblogic_server">
        <vers num="7.0" edition="" />
        <vers num="7.0" edition=":express" />
        <vers num="8.1" edition="" />
        <vers num="8.1" edition=":express" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" seq="2004-0472" reject="1" published="2004-07-07" name="CVE-2004-0472" modified="2008-09-10">
    <desc>
      <descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: none.  Reason: This candidate is a reservation duplicate of CVE-2004-0434.  Notes: All CVE users should reference CVE-2004-0434 instead of this candidate.  All references and descriptions in this candidate have been removed to prevent accidental usage.</descript>
    </desc>
    <refs />
  </entry>
  <entry type="CVE" severity="Low" seq="2004-0473" published="2004-07-07" name="CVE-2004-0473" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:P/A:N)" CVSS_score="2.6" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="4.9" CVSS_base_score="2.6">
    <desc>
      <descript source="cve">Argument injection vulnerability in Opera before 7.50 does not properly filter "-" characters that begin a hostname in a telnet URI, which allows remote attackers to insert options to the resulting command line and overwrite arbitrary files via (1) the "-f" option on Windows XP or (2) the "-n" option on Linux.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
      <exception />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.opera.com/linux/changelogs/750/index.dml" source="CONFIRM">http://www.opera.com/linux/changelogs/750/index.dml</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200405-19.xml" source="GENTOO">GLSA-200405-19</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/16139" source="XF">opera-telnet-file-overwrite(16139)</ref>
      <ref url="http://www.securityfocus.com/bid/10341" source="BID">10341</ref>
      <ref url="http://www.idefense.com/application/poi/display?id=104&amp;type=vulnerabilities" source="IDEFENSE">20040512 Opera Telnet URI Handler File Creation/Truncation Vulnerability</ref>
      <ref url="http://securitytracker.com/id?1010142" source="SECTRACK">1010142</ref>
    </refs>
    <vuln_soft>
      <prod vendor="opera_software" name="opera_web_browser">
        <vers num="9.10" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0474" published="2004-07-07" name="CVE-2004-0474" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_score="5.1" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="4.9" CVSS_base_score="5.1">
    <desc>
      <descript source="cve">Help Center (HelpCtr.exe) may allow remote attackers to read or execute arbitrary files via an "http://" or "file://" argument to the topic parameter in an hcp:// URL.  NOTE: since the initial report of this problem, several researchers have been unable to reproduce this issue.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/15101" source="XF" adv="1">winxp-helpctr-hcp-xss(15101)</ref>
      <ref url="http://www.securityfocus.com/bid/9621" source="BID" adv="1">9621</ref>
      <ref url="http://www.securityfocus.com/archive/1/353248" source="BUGTRAQ">20040207 HelpCtr - allow open any page or run</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107652584102003&amp;w=2" source="BUGTRAQ" adv="1">20040211 Re: HelpCtr - allow open any page or run</ref>
      <ref url="http://archives.neohapsis.com/archives/fulldisclosure/2004-02/0688.html" source="FULLDISC">20040213 Re: HelpCtr - allow open any page or run</ref>
      <ref url="http://archives.neohapsis.com/archives/fulldisclosure/2004-02/0450.html" source="FULLDISC">20040210 Re: HelpCtr - allow open any page or run</ref>
      <ref url="http://archives.neohapsis.com/archives/fulldisclosure/2004-02/0440.html" source="FULLDISC" adv="1">20040210 Re: HelpCtr - allow open any page or run</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_xp">
        <vers num="" edition=":home" />
        <vers num="" edition="gold" />
        <vers num="" edition="gold:professional" />
        <vers num="" edition="sp1" />
        <vers num="" edition="sp1:home" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0475" published="2004-07-07" name="CVE-2004-0475" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_score="5.1" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="4.9" CVSS_base_score="5.1">
    <desc>
      <descript source="cve">The showHelp function in Internet Explorer 6 on Windows XP Pro allows remote attackers to execute arbitrary local .CHM files via a double backward slash ("\\") before the target CHM file, as demonstrated using an "ms-its" URL to ntshared.chm.  NOTE: this bug may overlap CVE-2003-1041.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/16147" source="XF" adv="1">ie-showhelp-chm-execution(16147)</ref>
      <ref url="http://www.securityfocus.com/bid/10348" source="BID" adv="1">10348</ref>
      <ref url="http://www.securityfocus.com/archive/1/363202" source="BUGTRAQ" adv="1">20040513 Showhelp() local CHM file execution</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="ie">
        <vers num="6.0" edition="sp1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0476" published="2004-08-18" name="CVE-2004-0476" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Buffer overflow in 3Com OfficeConnect Remote 812 ADSL Router 1.1.9.4 allows remote attackers to cause a denial of service (reboot or packet loss) via a long string containing Telnet escape characters to the Telnet port.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/10419" source="BID" adv="1">10419</ref>
      <ref url="http://www.idefense.com/application/poi/display?id=105&amp;type=vulnerabilities" source="IDEFENSE" adv="1">20040526 OfficeConnect Remote 812 ADSL Router Telnet Protocol DoS Vulnerability</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/16257" source="XF">3com-officeconnect-telnet-bo(16257)</ref>
      <ref url="http://secunia.com/advisories/11716" source="SECUNIA">11716</ref>
    </refs>
    <vuln_soft>
      <prod vendor="3com" name="3cp4144">
        <vers num="1.1.9.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0477" published="2004-12-06" name="CVE-2004-0477" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Unknown vulnerability in 3Com OfficeConnect Remote 812 ADSL Router allows remote attackers to bypass authentication via repeated attempts using any username and password.  NOTE: this identifier was inadvertently re-used for another issue due to a typo; that issue was assigned CVE-2004-0447.  This candidate is ONLY for the ADSL router bypass.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" other="1" admin="1" />
    </loss_types>
    <vuln_types>
      <access />
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/10426" source="BID" patch="1" adv="1">10426</ref>
      <ref url="http://www.idefense.com/application/poi/display?id=106&amp;type=vulnerabilities&amp;flashstatus=false" source="IDEFENSE" patch="1" adv="1">20040527 iDEFENSE Security Advisory 05.27.04: 3Com OfficeConnect Remote 812 ADSL Router Authentication Bypass Vulnerability</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/16267" source="XF" adv="1">3com-officeconnect-gain-access(16267)</ref>
      <ref url="http://secunia.com/advisories/11716" source="SECUNIA">11716</ref>
    </refs>
    <vuln_soft>
      <prod vendor="3com" name="3cp4144">
        <vers num="1.1.9.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2004-0478" published="2004-07-07" name="CVE-2004-0478" modified="2008-09-10" CVSS_version="2.0" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:N/A:P)" CVSS_score="2.6" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="4.9" CVSS_base_score="2.6">
    <desc>
      <descript source="cve">Unknown versions of Mozilla allow remote attackers to cause a denial of service (high CPU/RAM consumption) using Javascript with an infinite loop that continues to add input to a form, possibly as the result of inserting control characters, as demonstrated using an embedded ctrl-U.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <design />
      <exception />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/16225" source="XF">mozilla-javascript-dos(16225)</ref>
      <ref url="http://lists.immunitysec.com/pipermail/dailydave/2004-May/000587.html" source="MLIST" adv="1">[Dailydave] 20040514 Mozilla bug might even get fixed!</ref>
      <ref url="http://bugzilla.mozilla.org/show_bug.cgi?id=243540" source="CONFIRM" adv="1">http://bugzilla.mozilla.org/show_bug.cgi?id=243540</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="mozilla">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0479" published="2004-07-07" name="CVE-2004-0479" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Internet Explorer 6 allows remote attackers to cause a denial of service (crash) via Javascript that creates a new popup window and disables the imagetoolbar functionality with a META tag, which triggers a null dereference.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=vuln-dev&amp;m=108476938219070&amp;w=2" source="VULN-DEV" adv="1">20040516 Re: IE Crash - Anyone Seen This Before?</ref>
      <ref url="http://marc.theaimsgroup.com/?l=vuln-dev&amp;m=108457938412310&amp;w=2" source="VULN-DEV" adv="1">20040514 IE Crash - Anyone Seen This Before?</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2004-May/021500.html" source="FULLDISC">20040514 IE Crash - Anyone Seen This Before?</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="ie">
        <vers num="6" edition="windows_server_2003_sp1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0480" published="2004-12-06" name="CVE-2004-0480" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Argument injection vulnerability in IBM Lotus Notes 6.0.3 and 6.5 allows remote attackers to execute arbitrary code via a notes: URI that uses a UNC network share pathname to provide an alternate notes.ini configuration file to notes.exe.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" other="1" admin="1" />
    </loss_types>
    <vuln_types>
      <input />
      <config />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/16496" source="XF" patch="1" adv="1">lotus-notes-xss(16496)</ref>
      <ref url="http://www.securityfocus.com/bid/10600" source="BID" patch="1" adv="1">10600</ref>
      <ref url="http://www.idefense.com/application/poi/display?id=111&amp;type=vulnerabilities" source="MISC" patch="1" adv="1">http://www.idefense.com/application/poi/display?id=111&amp;type=vulnerabilities</ref>
      <ref url="http://www-1.ibm.com/support/docview.wss?rs=475/context=SSKTWP&amp;uid=swg21169510" source="CONFIRM" patch="1" adv="1">http://www-1.ibm.com/support/docview.wss?rs=475/context=SSKTWP&amp;uid=swg21169510</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108843896506099&amp;w=2" source="BUGTRAQ" adv="1">20040627 Lotus Notes URL argument injection vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="lotus_notes">
        <vers num="6.0" />
        <vers num="6.0.1" />
        <vers num="6.0.2" />
        <vers num="6.0.3" />
        <vers num="6.5" />
        <vers num="6.5.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2004-0481" published="2005-02-23" name="CVE-2004-0481" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">The logging feature in kcms_configure in the KCMS package on Solaris 8 and 9, and possibly other versions, allows local users to corrupt arbitrary files via a symlink attack on the KCS_ClogFile file.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.idefense.com/application/poi/display?id=206&amp;type=vulnerabilities" source="IDEFENSE" patch="1" adv="1">20050223 Sun Solaris kcms_configure Arbitrary File Corruption Vulnerability</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-57706-1" source="SUNALERT" patch="1" adv="1">57706</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="solaris">
        <vers num="8.0" edition="" />
        <vers num="8.0" edition=":x86" />
        <vers num="8.1" />
        <vers num="8.2" />
        <vers num="9.0" edition="" />
        <vers num="9.0" edition=":sparc" />
        <vers num="9.0" edition=":x86" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0482" published="2004-07-07" name="CVE-2004-0482" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Multiple integer overflows in (1) procfs_cmdline.c, (2) procfs_fpregs.c, (3) procfs_linux.c, (4) procfs_regs.c, (5) procfs_status.c, and (6) procfs_subr.c in procfs for OpenBSD 3.5 and earlier allow local users to read sensitive kernel memory and possibly perform other unauthorized activities.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=openbsd-security-announce&amp;m=108445767103004&amp;w=2" source="MLIST" patch="1" adv="1">[openbsd-security-announce] 20040513 procfs vulnerability</ref>
      <ref url="ftp://ftp.openbsd.org/pub/OpenBSD/patches/3.5/common/006_procfs.patch" source="CONFIRM" patch="1">ftp://ftp.openbsd.org/pub/OpenBSD/patches/3.5/common/006_procfs.patch</ref>
      <ref url="ftp://ftp.openbsd.org/pub/OpenBSD/patches/3.4/common/020_procfs.patch" source="CONFIRM" patch="1">ftp://ftp.openbsd.org/pub/OpenBSD/patches/3.4/common/020_procfs.patch</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/16226" source="XF">openbsd-procfs-gain-privileges(16226)</ref>
      <ref url="http://www.osvdb.org/6114" source="OSVDB">6114</ref>
      <ref url="http://www.openbsd.org/errata35.html" source="OPENBSD">20040513 [3.5] 006: SECURITY FIX: May 13, 2004</ref>
      <ref url="http://www.openbsd.org/errata34.html" source="OPENBSD">20040513 [3.4] 020: SECURITY FIX: May 13, 2004</ref>
      <ref url="http://www.deprotect.com/advisories/DEPROTECT-20041305.txt" source="MISC">http://www.deprotect.com/advisories/DEPROTECT-20041305.txt</ref>
      <ref url="http://secunia.com/advisories/11605" source="SECUNIA">11605</ref>
      <ref url="http://marc.theaimsgroup.com/?l=full-disclosure&amp;m=108481812926420&amp;w=2" source="FULLDISC">20040517 OpenBSD procfs</ref>
    </refs>
    <vuln_soft>
      <prod vendor="openbsd" name="openbsd">
        <vers num="3.4" />
        <vers num="3.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0483" published="2004-07-07" name="CVE-2004-0483" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Unknown vulnerability in rpc.mountd for SGI IRIX 6.5.24 allows remote attackers to cause a denial of service (infinite loop) via certain RPC requests.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/10372" source="BID" patch="1">10372</ref>
      <ref url="http://secunia.com/advisories/11628" source="SECUNIA" patch="1" adv="1">11628</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/16175" source="XF">rpcmountd-rpc-dos(16175)</ref>
      <ref url="http://www.osvdb.org/6201" source="OSVDB">6201</ref>
      <ref url="http://securitytracker.com/id?1010185" source="SECTRACK">1010185</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/20040503-01-P" source="SGI">20040503-01-P</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sgi" name="irix">
        <vers num="6.5.24" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2004-0484" published="2004-07-07" name="CVE-2004-0484" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:N/A:P)" CVSS_score="2.6" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="4.9" CVSS_base_score="2.6">
    <desc>
      <descript source="cve">mshtml.dll in Microsoft Internet Explorer 6.0.2800 allows remote attackers to cause a denial of service (crash) via a table containing a form that crosses multiple td elements, and whose "float: left" class is defined in a link to a CSS stylesheet after the end of the table, which may trigger a null dereference.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/16189" source="XF">ie-css-dos(16189)</ref>
      <ref url="http://www.securityfocus.com/bid/10382" source="BID">10382</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108490218632590&amp;w=2" source="BUGTRAQ" adv="1">20040518 Unknown IE bug with css-styles</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="ie">
        <vers num="6.0.2900" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0485" published="2004-07-07" name="CVE-2004-0485" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The default protocol helper for the disk: URI on Mac OS X 10.3.3 and 10.2.8 allows remote attackers to write arbitrary files by causing a disk image file (.dmg) to be mounted as a disk volume.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/210606" source="CERT-VN" patch="1" adv="1">VU#210606</ref>
      <ref url="http://secunia.com/advisories/11622/" source="SECUNIA" patch="1" adv="1">11622</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/16166" source="XF" adv="1">macos-runscript-code-execution(16166)</ref>
      <ref url="http://lists.apple.com/mhonarc/security-announce/msg00053.html" source="APPLE">APPLE-SA-2004-05-21</ref>
      <ref url="http://fundisom.com/owned/warning" source="MISC" adv="1">http://fundisom.com/owned/warning</ref>
      <ref url="http://lists.seifried.org/pipermail/security/2004-May/003743.html" source="APPLE">APPLE-SA-2004-05-28</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.2.8" />
        <vers num="10.3.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0486" published="2004-07-07" name="CVE-2004-0486" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:H/Au:N/C:C/I:C/A:C)" CVSS_score="7.6" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="4.9" CVSS_base_score="7.6">
    <desc>
      <descript source="cve">HelpViewer in Mac OS X 10.3.3 and 10.2.8 processes scripts that it did not initiate, which can allow attackers to execute arbitrary code, an issue that was originally reported as a directory traversal vulnerability in the Safari web browser using the runscript parameter in a help: URI handler.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" other="1" admin="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/578798" source="CERT-VN" patch="1" adv="1">VU#578798</ref>
      <ref url="http://www.securityfocus.com/bid/10356" source="BID" patch="1" adv="1">10356</ref>
      <ref url="http://secunia.com/advisories/11622/" source="SECUNIA" patch="1" adv="1">11622</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/16166" source="XF" adv="1">macos-runscript-code-execution(16166)</ref>
      <ref url="http://www.fundisom.com/owned/warning" source="MISC" adv="1">http://www.fundisom.com/owned/warning</ref>
      <ref url="http://lists.apple.com/mhonarc/security-announce/msg00053.html" source="APPLE">APPLE-SA-2004-05-21</ref>
      <ref url="http://www.osvdb.org/6184" source="OSVDB">6184</ref>
      <ref url="http://securitytracker.com/id?1010167" source="SECTRACK">1010167</ref>
      <ref url="http://archives.neohapsis.com/archives/fulldisclosure/2004-05/0837.html" source="FULLDISC">20040516 Vuln. MacOSX/Safari: Remote help-call, execute scripts</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.3" />
        <vers num="10.3.1" />
        <vers num="10.3.2" />
        <vers num="10.3.3" />
      </prod>
      <prod vendor="apple" name="mac_os_x_server">
        <vers num="10.3" />
        <vers num="10.3.1" />
        <vers num="10.3.2" />
        <vers num="10.3.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0487" published="2004-08-18" name="CVE-2004-0487" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">A certain ActiveX control in Symantec Norton AntiVirus 2004 allows remote attackers to cause a denial of service (resource consumption) and possibly execute arbitrary programs.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" admin="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/312510" source="CERT-VN" adv="1">VU#312510</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/16220" source="XF" adv="1">nav-activex-code-execution(16220)</ref>
      <ref url="http://www.symantec.com/avcenter/security/Content/2004.05.20.html" source="CONFIRM">http://www.symantec.com/avcenter/security/Content/2004.05.20.html</ref>
      <ref url="http://www.securityfocus.com/bid/10392" source="BID" adv="1">10392</ref>
      <ref url="http://www.lac.co.jp/security/csl/intelligence/SNSadvisory_e/72_e.html" source="MISC">http://www.lac.co.jp/security/csl/intelligence/SNSadvisory_e/72_e.html</ref>
      <ref url="http://www.ciac.org/ciac/bulletins/o-149.shtml" source="CIAC">O-149</ref>
      <ref url="http://secunia.com/advisories/11676" source="SECUNIA">11676</ref>
      <ref url="http://www.osvdb.org/6303" source="OSVDB">6303</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108515369718455&amp;w=2" source="BUGTRAQ">20040521 [SNS Advisory No.72] Symantec Norton AntiVirus 2004 ActiveX Control Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="symantec" name="norton_antivirus">
        <vers num="2.1" edition="" />
        <vers num="2.1" edition=":ms_exchange" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0488" published="2004-07-07" name="CVE-2004-0488" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Stack-based buffer overflow in the ssl_util_uuencode_binary function in ssl_util.c for Apache mod_ssl, when mod_ssl is configured to trust the issuing CA, may allow remote attackers to execute arbitrary code via a client certificate with a long subject DN.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/10355" source="BID" patch="1" adv="1">10355</ref>
      <ref url="https://bugzilla.fedora.us/show_bug.cgi?id=1888" source="FEDORA">FLSA:1888</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/16214" source="XF" adv="1">apache-modssl-uuencode-bo(16214)</ref>
      <ref url="http://www.trustix.net/errata/2004/0031/" source="TRUSTIX">2004-0031</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-405.html" source="REDHAT">RHSA-2004:405</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-342.html" source="REDHAT">RHSA-2004:342</ref>
      <ref url="http://www.debian.org/security/2004/dsa-532" source="DEBIAN">DSA-532</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200406-05.xml" source="GENTOO">GLSA-200406-05</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2004-245.html" source="REDHAT">RHSA-2004:245</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11458" source="OVAL">oval:org.mitre.oval:def:11458</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109215056218824&amp;w=2" source="HP">SSRT4788</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109181600614477&amp;w=2" source="HP">SSRT4777</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108619129727620&amp;w=2" source="BUGTRAQ">20040601 TSSA-2004-008 - apache</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2004-May/021610.html" source="FULLDISC">20040517 mod_ssl ssl_util_uuencode_binary potential problem</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/20040605-01-U.asc" source="SGI">20040605-01-U</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-816.html" source="REDHAT">RHSA-2005:816</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2004:055" source="MANDRAKE">MDKSA-2004:055</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2004:054" source="MANDRAKE">MDKSA-2004:054</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108567431823750&amp;w=2" source="BUGTRAQ">20040527 [OpenPKG-SA-2004.026] OpenPKG Security Advisory (apache)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apache" name="http_server">
        <vers num="1.3" />
        <vers num="1.3.1" />
        <vers num="1.3.11" />
        <vers num="1.3.12" />
        <vers num="1.3.14" />
        <vers num="1.3.17" />
        <vers num="1.3.18" />
        <vers num="1.3.19" />
        <vers num="1.3.20" />
        <vers num="1.3.22" />
        <vers num="1.3.23" />
        <vers num="1.3.24" />
        <vers num="1.3.25" />
        <vers num="1.3.26" />
        <vers num="1.3.27" />
        <vers num="1.3.28" />
        <vers num="1.3.29" />
        <vers num="1.3.3" />
        <vers num="1.3.31" />
        <vers num="1.3.4" />
        <vers num="1.3.6" />
        <vers num="1.3.7" edition="" />
        <vers num="1.3.7" edition=":dev" />
        <vers num="1.3.9" />
        <vers num="2.0" />
        <vers num="2.0.28" edition="beta" />
        <vers num="2.0.32" />
        <vers num="2.0.35" />
        <vers num="2.0.36" />
        <vers num="2.0.37" />
        <vers num="2.0.38" />
        <vers num="2.0.39" />
        <vers num="2.0.40" />
        <vers num="2.0.41" />
        <vers num="2.0.42" />
        <vers num="2.0.43" />
        <vers num="2.0.44" />
        <vers num="2.0.45" />
        <vers num="2.0.46" />
        <vers num="2.0.47" />
        <vers num="2.0.48" />
        <vers num="2.0.49" />
        <vers num="2.0.9" />
      </prod>
      <prod vendor="mandrakesoft" name="mandrake_multi_network_firewall">
        <vers num="8.2" />
      </prod>
      <prod vendor="mod_ssl" name="mod_ssl">
        <vers num="2.8.10" />
        <vers num="2.8.12" />
        <vers num="2.8.15" />
        <vers num="2.8.16" />
        <vers num="2.8.7" />
      </prod>
      <prod vendor="sgi" name="propack">
        <vers num="2.4" />
      </prod>
      <prod vendor="tinysofa" name="tinysofa_enterprise_server">
        <vers num="1.0" />
        <vers num="1.0_u1" />
      </prod>
      <prod vendor="gentoo" name="linux">
        <vers num="1.4" />
      </prod>
      <prod vendor="mandrakesoft" name="mandrake_linux">
        <vers num="10.0" edition="" />
        <vers num="10.0" edition=":amd64" />
        <vers num="9.1" edition="" />
        <vers num="9.1" edition=":ppc" />
        <vers num="9.2" edition="" />
        <vers num="9.2" edition=":amd64" />
      </prod>
      <prod vendor="mandrakesoft" name="mandrake_linux_corporate_server">
        <vers num="2.1" edition="" />
        <vers num="2.1" edition=":x86_64" />
      </prod>
      <prod vendor="openbsd" name="openbsd">
        <vers num="3.4" />
        <vers num="3.5" />
        <vers num="current" />
      </prod>
      <prod vendor="trustix" name="secure_linux">
        <vers num="1.5" />
        <vers num="2.0" />
        <vers num="2.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0489" published="2004-07-07" name="CVE-2004-0489" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:H/Au:N/C:C/I:C/A:C)" CVSS_score="7.6" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="4.9" CVSS_base_score="7.6">
    <desc>
      <descript source="cve">Argument injection vulnerability in the SSH URI handler for Safari on Mac OS 10.3.3 and earlier allows remote attackers to (1) execute arbitrary code via the ProxyCommand option or (2) conduct port forwarding via the -R option.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" other="1" admin="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/16242" source="XF" adv="1">macos-ssh-code-execution(16242)</ref>
      <ref url="http://www.insecure.ws/article.php?story=200405222251133" source="MISC" adv="1">http://www.insecure.ws/article.php?story=200405222251133</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2004-May/021871.html" source="FULLDISC">20040524 SSH URI handler remote arbitrary code execution</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.3.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0490" published="2004-08-18" name="CVE-2004-0490" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">cPanel, when compiling Apache 1.3.29 and PHP with the mod_phpsuexec option, does not set the --enable-discard-path option, which causes php to use the SCRIPT_FILENAME variable to find and execute a script instead of the PATH_TRANSLATED variable, which allows local users to execute arbitrary PHP code as other users via a URL that references the attacker's script after the user's script, which executes the attacker's script with the user's privileges, a different vulnerability than CVE-2004-0529.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" admin="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/16239" source="XF" adv="1">cpanel-modphpsuexec-execute-commands(16239)</ref>
      <ref url="http://www.securityfocus.com/bid/10407" source="BID" adv="1">10407</ref>
      <ref url="http://www.securityfocus.com/archive/1/364112" source="BUGTRAQ">20040524 cPanel mod_phpsuexec Vulnerability</ref>
      <ref url="http://www.securiteam.com/tools/5TP0N15CUA.html" source="MISC" adv="1">http://www.securiteam.com/tools/5TP0N15CUA.html</ref>
      <ref url="http://www.a-squad.com/audit/explain10.html" source="MISC">http://www.a-squad.com/audit/explain10.html</ref>
      <ref url="http://bugzilla.cpanel.net/show_bug.cgi?id=664" source="CONFIRM">http://bugzilla.cpanel.net/show_bug.cgi?id=664</ref>
      <ref url="http://bugzilla.cpanel.net/show_bug.cgi?id=283" source="MISC">http://bugzilla.cpanel.net/show_bug.cgi?id=283</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cpanel" name="cpanel">
        <vers num="5.0" />
        <vers num="5.3" />
        <vers num="6.0" />
        <vers num="6.2" />
        <vers num="6.4" />
        <vers num="6.4.1" />
        <vers num="6.4.2" />
        <vers num="6.4.2_stable_48" />
        <vers num="7.0" />
        <vers num="8.0" />
        <vers num="9.0" />
        <vers num="9.1" />
        <vers num="9.1.0_r85" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2004-0491" published="2004-12-31" name="CVE-2004-0491" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">The linux-2.4.21-mlock.patch in Red Hat Enterprise Linux 3 does not properly maintain the mlock page count when one process unlocks pages that belong to another process, which allows local users to mlock more memory than specified by the rlimit.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=linux-kernel&amp;m=108087017610947&amp;w=2" source="MLIST" patch="1">[linux-kernel] 20040402 Re: disable-cap-mlock</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10672" source="OVAL">oval:org.mitre.oval:def:10672</ref>
      <ref url="http://www.securityfocus.com/bid/13769" source="BID">13769</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-472.html" source="REDHAT">RHSA-2005:472</ref>
      <ref url="http://secunia.com/advisories/19607" source="SECUNIA">19607</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/20060402-01-U" source="SGI">20060402-01-U</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1117" source="OVAL" sig="1">oval:org.mitre.oval:def:1117</ref>
    </refs>
    <vuln_soft>
      <prod vendor="redhat" name="enterprise_linux">
        <vers num="3.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0492" published="2004-08-06" name="CVE-2004-0492" modified="2011-09-06" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Heap-based buffer overflow in proxy_util.c for mod_proxy in Apache 1.3.25 to 1.3.31 allows remote attackers to cause a denial of service (process crash) and possibly execute arbitrary code via a negative Content-Length HTTP header field, which causes a large amount of data to be copied.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/541310" source="CERT-VN">VU#541310</ref>
      <ref url="http://www.debian.org/security/2004/dsa-525" source="DEBIAN" patch="1" adv="1">DSA-525</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2004-245.html" source="REDHAT" patch="1" adv="1">RHSA-2004:245</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108711172710140&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20040611 [OpenPKG-SA-2004.029] OpenPKG Security Advisory (apache)</ref>
      <ref url="https://bugzilla.fedora.us/show_bug.cgi?id=1737" source="FEDORA">FLSA:1737</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/16387" source="XF" adv="1">apache-modproxy-contentlength-bo(16387)</ref>
      <ref url="http://www.guninski.com/modproxy1.html" source="MISC">http://www.guninski.com/modproxy1.html</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-57628-1" source="SUNALERT">57628</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-101841-1" source="SUNALERT">101841</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-101555-1" source="SUNALERT">101555</ref>
      <ref url="http://secunia.com/advisories/11841" source="SECUNIA">11841</ref>
      <ref url="http://seclists.org/lists/fulldisclosure/2004/Jun/0296.html" source="FULLDISC">20040610 Buffer overflow in apache mod_proxy,yet still apache much better than windows</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=130497311408250&amp;w=2" source="HP">SSRT090208</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=130497311408250&amp;w=2" source="HP">HPSBOV02683</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/20040605-01-U.asc" source="SGI">20040605-01-U</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2004:065" source="MANDRAKE">MDKSA-2004:065</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:4863" source="OVAL" sig="1">oval:org.mitre.oval:def:4863</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:100112" source="OVAL" sig="1">oval:org.mitre.oval:def:100112</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apache" name="http_server">
        <vers num="1.3.26" />
        <vers num="1.3.27" />
        <vers num="1.3.28" />
        <vers num="1.3.29" />
        <vers num="1.3.31" />
      </prod>
      <prod vendor="hp" name="virtualvault">
        <vers num="11.0.4" />
      </prod>
      <prod vendor="hp" name="webproxy">
        <vers num="2.0" />
        <vers num="2.1" />
      </prod>
      <prod vendor="ibm" name="http_server">
        <vers num="1.3.26" />
        <vers num="1.3.26.1" />
        <vers num="1.3.26.2" />
        <vers num="1.3.28" />
      </prod>
      <prod vendor="sgi" name="propack">
        <vers num="2.4" />
      </prod>
      <prod vendor="hp" name="vvos">
        <vers num="11.04" />
      </prod>
      <prod vendor="openbsd" name="openbsd">
        <vers num="3.4" />
        <vers num="3.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0493" published="2004-08-06" name="CVE-2004-0493" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:P)" CVSS_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_base_score="6.4">
    <desc>
      <descript source="cve">The ap_get_mime_headers_core function in Apache httpd 2.0.49 allows remote attackers to cause a denial of service (memory exhaustion), and possibly an integer signedness error leading to a heap-based buffer overflow on 64 bit systems, via long header lines with large numbers of space or tab characters.</descript>
    </desc>
    <loss_types>
      <avail />
      <int />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/10619" source="BID" patch="1" adv="1">10619</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/16524" source="XF" adv="1">apache-apgetmimeheaderscore-dos(16524)</ref>
      <ref url="http://www.trustix.org/errata/2004/0039/" source="TRUSTIX">2004-0039</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-342.html" source="REDHAT">RHSA-2004:342</ref>
      <ref url="http://www.guninski.com/httpd1.html" source="MISC">http://www.guninski.com/httpd1.html</ref>
      <ref url="http://www.apacheweek.com/features/security-20" source="CONFIRM">http://www.apacheweek.com/features/security-20</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200407-03.xml" source="GENTOO">GLSA-200407-03</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10605" source="OVAL">oval:org.mitre.oval:def:10605</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109181600614477&amp;w=2" source="HP">SSRT4777</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2004-June/023133.html" source="FULLDISC">20040628 DoS in apache httpd 2.0.49, yet still apache much better than windows</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2004:064" source="MANDRAKE">MDKSA-2004:064</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108853066800184&amp;w=2" source="BUGTRAQ">20040629 TSSA-2004-012 - apache</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apache" name="http_server">
        <vers num="2.0.47" />
        <vers num="2.0.48" />
        <vers num="2.0.49" />
      </prod>
      <prod vendor="ibm" name="http_server">
        <vers num="2.0.42" />
        <vers num="2.0.42.1" />
        <vers num="2.0.42.2" />
        <vers num="2.0.47" />
        <vers num="2.0.47.1" />
      </prod>
      <prod vendor="avaya" name="converged_communications_server">
        <vers num="2.0" />
      </prod>
      <prod vendor="avaya" name="s8300">
        <vers num="r2.0.0" />
      </prod>
      <prod vendor="avaya" name="s8500">
        <vers num="r2.0.0" />
      </prod>
      <prod vendor="avaya" name="s8700">
        <vers num="r2.0.0" />
      </prod>
      <prod vendor="gentoo" name="linux">
        <vers num="1.4" />
      </prod>
      <prod vendor="trustix" name="secure_linux">
        <vers num="1.5" />
        <vers num="2.0" />
        <vers num="2.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0494" published="2004-11-23" name="CVE-2004-0494" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple extfs backend scripts for GNOME virtual file system (VFS) before 1.0.1 may allow remote attackers to perform certain unauthorized actions via a gnome-vfs URI.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-373.html" source="REDHAT" patch="1" adv="1">RHSA-2004:373</ref>
      <ref url="https://bugzilla.fedora.us/show_bug.cgi?id=1944" source="FEDORA">FLSA:1944</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/16897" source="XF" adv="1">gnome-vfs-extfs-gain-access(16897)</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9854" source="OVAL">oval:org.mitre.oval:def:9854</ref>
      <ref url="http://rpmfind.net/linux/RPM/suse/9.3/i386/suse/i586/gnome-vfs-1.0.5-816.2.i586.html" source="CONFIRM">http://rpmfind.net/linux/RPM/suse/9.3/i386/suse/i586/gnome-vfs-1.0.5-816.2.i586.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="avaya" name="cvlan">
        <vers num="" />
      </prod>
      <prod vendor="redhat" name="enterprise_linux">
        <vers num="2.1" edition="" />
        <vers num="2.1" edition=":advanced_server_ia64" />
        <vers num="2.1" edition=":workstation_ia64" />
        <vers num="2.1" edition=":workstation" />
        <vers num="2.1" edition=":advanced_server" />
        <vers num="2.1" edition=":enterprise_server_ia64" />
        <vers num="2.1" edition=":enterprise_server" />
        <vers num="3.0" edition="" />
        <vers num="3.0" edition=":advanced_server" />
        <vers num="3.0" edition=":workstation_server" />
        <vers num="3.0" edition=":enterprise_server" />
      </prod>
      <prod vendor="redhat" name="enterprise_linux_desktop">
        <vers num="3.0" />
      </prod>
      <prod vendor="redhat" name="linux_advanced_workstation">
        <vers num="2.1" edition="" />
        <vers num="2.1" edition=":ia64" />
        <vers num="2.1" edition=":itanium_processor" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0495" published="2004-08-06" name="CVE-2004-0495" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Multiple unknown vulnerabilities in Linux kernel 2.4 and 2.6 allow local users to gain privileges or access kernel memory, as found by the Sparse source code checking tool.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" admin="1" />
    </loss_types>
    <vuln_types>
      <other />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/10566" source="BID" patch="1" adv="1">10566</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-255.html" source="REDHAT" patch="1" adv="1">RHSA-2004:255</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/16449" source="XF" adv="1">linux-drivers-gain-privileges(16449)</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-260.html" source="REDHAT">RHSA-2004:260</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2004_20_kernel.html" source="SUSE">SUSE-SA:2004:020</ref>
      <ref url="http://www.mandrakesecure.net/en/advisories/advisory.php?name=MDKSA-2004:066" source="MANDRAKE">MDKSA-2004:066</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200407-02.xml" source="GENTOO" adv="1">GLSA-200407-02</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10155" source="OVAL">oval:org.mitre.oval:def:10155</ref>
      <ref url="http://lwn.net/Articles/91155/" source="FEDORA">FEDORA-2004-186</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000846" source="CONECTIVA">CLA-2004:846</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000845" source="CONECTIVA">CLA-2004:845</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2961" source="OVAL" sig="1">oval:org.mitre.oval:def:2961</ref>
    </refs>
    <vuln_soft>
      <prod vendor="avaya" name="intuity_audix">
        <vers num="" edition=":lx" />
      </prod>
      <prod vendor="suse" name="suse_email_server">
        <vers num="3.1" />
        <vers num="iii" />
      </prod>
      <prod vendor="suse" name="suse_linux_admin-cd_for_firewall">
        <vers num="" />
      </prod>
      <prod vendor="suse" name="suse_linux_connectivity_server">
        <vers num="" />
      </prod>
      <prod vendor="suse" name="suse_linux_database_server">
        <vers num="" />
      </prod>
      <prod vendor="suse" name="suse_linux_firewall_cd">
        <vers num="" />
      </prod>
      <prod vendor="suse" name="suse_linux_office_server">
        <vers num="" />
      </prod>
      <prod vendor="suse" name="suse_office_server">
        <vers num="" />
      </prod>
      <prod vendor="avaya" name="converged_communications_server">
        <vers num="2.0" />
      </prod>
      <prod vendor="avaya" name="s8300">
        <vers num="r2.0.0" />
        <vers num="r2.0.1" />
      </prod>
      <prod vendor="avaya" name="s8500">
        <vers num="r2.0.0" />
        <vers num="r2.0.1" />
      </prod>
      <prod vendor="avaya" name="s8700">
        <vers num="r2.0.0" />
        <vers num="r2.0.1" />
      </prod>
      <prod vendor="avaya" name="modular_messaging_message_storage_server">
        <vers num="s3400" />
      </prod>
      <prod vendor="conectiva" name="linux">
        <vers num="8.0" />
        <vers num="9.0" />
      </prod>
      <prod vendor="gentoo" name="linux">
        <vers num="1.4" />
      </prod>
      <prod vendor="linux" name="linux_kernel">
        <vers num="2.4.18" />
        <vers num="2.4.19" />
        <vers num="2.4.21" />
        <vers num="2.4.22" />
        <vers num="2.4.23" />
        <vers num="2.4.24" />
        <vers num="2.4.25" />
        <vers num="2.4.26" />
        <vers num="2.6.0" />
        <vers num="2.6.1" edition="rc1" />
        <vers num="2.6.1" edition="rc2" />
        <vers num="2.6.2" />
        <vers num="2.6.3" />
        <vers num="2.6.4" />
        <vers num="2.6.5" />
        <vers num="2.6.6" edition="rc1" />
        <vers num="2.6.7" edition="rc1" />
      </prod>
      <prod vendor="redhat" name="enterprise_linux">
        <vers num="2.1" edition="" />
        <vers num="2.1" edition=":advanced_server" />
        <vers num="2.1" edition=":enterprise_server" />
        <vers num="2.1" edition=":workstation" />
        <vers num="3.0" edition="" />
        <vers num="3.0" edition=":enterprise_server" />
        <vers num="3.0" edition=":workstation" />
        <vers num="3.0" edition=":advanced_servers" />
      </prod>
      <prod vendor="suse" name="suse_linux">
        <vers num="7" edition="" />
        <vers num="7" edition=":enterprise_server" />
        <vers num="8" edition="" />
        <vers num="8" edition=":enterprise_server" />
        <vers num="8.0" edition="" />
        <vers num="8.0" edition=":i386" />
        <vers num="8.1" />
        <vers num="8.2" />
        <vers num="9.0" edition="" />
        <vers num="9.0" edition=":x86_64" />
        <vers num="9.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0496" published="2004-12-06" name="CVE-2004-0496" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Multiple unknown vulnerabilities in Linux kernel 2.6 allow local users to gain privileges or access kernel memory, a different set of vulnerabilities than those identified in CVE-2004-0495, as found by the Sparse source code checking tool.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/16625" source="XF" patch="1" adv="1">linux-gain-privileges(16625)</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2004_20_kernel.html" source="SUSE">SUSE-SA:2004:020</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mandrakesoft" name="mandrake_multi_network_firewall">
        <vers num="8.2" />
      </prod>
      <prod vendor="suse" name="suse_email_server">
        <vers num="3" />
        <vers num="3.1" />
      </prod>
      <prod vendor="suse" name="suse_linux_connectivity_server">
        <vers num="" />
      </prod>
      <prod vendor="suse" name="suse_linux_database_server">
        <vers num="" />
      </prod>
      <prod vendor="suse" name="suse_linux_firewall">
        <vers num="" />
      </prod>
      <prod vendor="suse" name="suse_linux_office_server">
        <vers num="" />
      </prod>
      <prod vendor="gentoo" name="linux">
        <vers num="" />
      </prod>
      <prod vendor="linux" name="linux_kernel">
        <vers num="2.6.0" />
      </prod>
      <prod vendor="mandrakesoft" name="mandrake_linux">
        <vers num="10.0" />
        <vers num="9.1" />
        <vers num="9.2" />
      </prod>
      <prod vendor="mandrakesoft" name="mandrake_linux_corporate_server">
        <vers num="2.1" />
      </prod>
      <prod vendor="sun" name="solaris">
        <vers num="8.0" />
        <vers num="8.1" />
        <vers num="8.2" />
        <vers num="9.0" edition="" />
        <vers num="9.0" edition=":sparc" />
        <vers num="9.1" />
      </prod>
      <prod vendor="suse" name="suse_linux">
        <vers num="7" edition="" />
        <vers num="7" edition=":enterprise_server" />
        <vers num="8" edition="" />
        <vers num="8" edition=":enterprise_server" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2004-0497" published="2004-12-06" name="CVE-2004-0497" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">Unknown vulnerability in Linux kernel 2.x may allow local users to modify the group ID of files, such as NFS exported files in kernel 2.4.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/16599" source="XF" patch="1" adv="1">linux-fchown-groupid-modify(16599)</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-354.html" source="REDHAT" patch="1" adv="1">RHSA-2004:354</ref>
      <ref url="http://www.mandrakesecure.net/en/advisories/advisory.php?name=MDKSA-2004:066" source="MANDRAKE" patch="1" adv="1">MDKSA-2004:066</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000852" source="CONECTIVA" patch="1" adv="1">CLA-2004:852</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-360.html" source="REDHAT">RHSA-2004:360</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2004_20_kernel.html" source="SUSE">SUSE-SA:2004:020</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9867" source="OVAL">oval:org.mitre.oval:def:9867</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mandrakesoft" name="mandrake_multi_network_firewall">
        <vers num="8.2" />
      </prod>
      <prod vendor="conectiva" name="linux">
        <vers num="10" />
      </prod>
      <prod vendor="gentoo" name="linux">
        <vers num="" />
      </prod>
      <prod vendor="linux" name="linux_kernel">
        <vers num="2.0" />
      </prod>
      <prod vendor="mandrakesoft" name="mandrake_linux">
        <vers num="10.0" />
        <vers num="9.1" />
        <vers num="9.2" />
      </prod>
      <prod vendor="mandrakesoft" name="mandrake_linux_corporate_server">
        <vers num="2.1" />
      </prod>
      <prod vendor="redhat" name="enterprise_linux">
        <vers num="2.1" edition="" />
        <vers num="2.1" edition=":workstation" />
        <vers num="2.1" edition=":advanced_server" />
        <vers num="2.1" edition=":enterprise_server" />
        <vers num="3.0" edition="" />
        <vers num="3.0" edition=":advanced_server" />
        <vers num="3.0" edition=":workstation_server" />
        <vers num="3.0" edition=":enterprise_server" />
      </prod>
      <prod vendor="suse" name="suse_linux">
        <vers num="8.0" />
        <vers num="8.1" />
        <vers num="8.2" />
        <vers num="9.0" />
        <vers num="9.1" />
      </prod>
      <prod vendor="trustix" name="secure_linux">
        <vers num="2" />
        <vers num="2.0" />
        <vers num="2.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0498" published="2004-12-31" name="CVE-2004-0498" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The H.323 protocol agent in StoneSoft firewall engine 2.2.8 and earlier allows remote attackers to cause a denial of service (crash) via crafted H.323 packets.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.uniras.gov.uk/niscc/docs/re-20041026-00956.pdf?lang=en" source="MISC" adv="1">http://www.uniras.gov.uk/niscc/docs/re-20041026-00956.pdf?lang=en</ref>
      <ref url="http://www.stonesoft.com/support/Security_Advisories/6735.html" source="MISC" adv="1">http://www.stonesoft.com/support/Security_Advisories/6735.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="stonesoft" name="firewall_engine">
        <vers prev="1" num="2.2.8" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" seq="2004-0499" reject="1" published="2004-12-31" name="CVE-2004-0499" modified="2008-09-10">
    <desc>
      <descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: none.  Reason: This candidate was withdrawn by its CNA.  Notes: none.</descript>
    </desc>
    <refs />
  </entry>
  <entry type="CVE" severity="High" seq="2004-0500" published="2004-09-28" name="CVE-2004-0500" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in the MSN protocol plugins (1) object.c and (2) slp.c for Gaim before 0.82 allows remote attackers to cause a denial of service and possibly execute arbitrary code via MSNSLP protocol messages that are not properly handled in a strncpy call.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/16920" source="XF" patch="1" adv="1">gaim-msn-bo(16920)</ref>
      <ref url="http://www.securityfocus.com/bid/10865" source="BID" patch="1" adv="1">10865</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200408-12.xml" source="GENTOO" patch="1" adv="1">GLSA-200408-12</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-400.html" source="REDHAT">RHSA-2004:400</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2004_25_gaim.html" source="SUSE">SUSE-SA:2004:025</ref>
      <ref url="http://www.mandrakesecure.net/en/advisories/advisory.php?name=MDKSA-2004:081" source="MANDRAKE">MDKSA-2004:081</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200408-27.xml" source="GENTOO">GLSA-200408-27</ref>
      <ref url="http://www.fedoranews.org/updates/FEDORA-2004-279.shtml" source="FEDORA">FEDORA-2004-279</ref>
      <ref url="http://www.fedoranews.org/updates/FEDORA-2004-278.shtml" source="FEDORA">FEDORA-2004-278</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9429" source="OVAL">oval:org.mitre.oval:def:9429</ref>
      <ref url="http://gaim.sourceforge.net/security/?id=0" source="CONFIRM">http://gaim.sourceforge.net/security/?id=0</ref>
    </refs>
    <vuln_soft>
      <prod vendor="rob_flynn" name="gaim">
        <vers num="0.10" />
        <vers num="0.10.3" />
        <vers num="0.50" />
        <vers num="0.51" />
        <vers num="0.52" />
        <vers num="0.53" />
        <vers num="0.54" />
        <vers num="0.55" />
        <vers num="0.56" />
        <vers num="0.57" />
        <vers num="0.58" />
        <vers num="0.59" />
        <vers num="0.59.1" />
        <vers num="0.60" />
        <vers num="0.61" />
        <vers num="0.62" />
        <vers num="0.63" />
        <vers num="0.64" />
        <vers num="0.65" />
        <vers num="0.66" />
        <vers num="0.67" />
        <vers num="0.68" />
        <vers num="0.69" />
        <vers num="0.70" />
        <vers num="0.71" />
        <vers num="0.72" />
        <vers num="0.73" />
        <vers num="0.74" />
        <vers num="0.75" />
      </prod>
      <prod vendor="gentoo" name="linux">
        <vers num="1.4" />
      </prod>
      <prod vendor="mandrakesoft" name="mandrake_linux">
        <vers num="10.0" edition="" />
        <vers num="10.0" edition=":amd64" />
        <vers num="9.2" edition="" />
        <vers num="9.2" edition=":amd64" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0501" published="2004-08-18" name="CVE-2004-0501" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Outlook 2003 allows remote attackers to bypass intended access restrictions and cause Outlook to request a URL from a remote site via an HTML e-mail message containing a Vector Markup Language (VML) entity whose src parameter points to the remote site, which could allow remote attackers to know when a message has been read, verify valid e-mail addresses, and possibly leak other information.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/16116" source="XF" adv="1">outlook-vml-obtain-information(16116)</ref>
      <ref url="http://www.securityfocus.com/bid/10323" source="BID" adv="1">10323</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108430168919965&amp;w=2" source="BUGTRAQ" adv="1">20040511 PING: Outlook 2003 Spam</ref>
      <ref url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=108644231209698&amp;w=2" source="NTBUGTRAQ">20040604 RE: PING: Outlook 2003 Spam</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108637351805607&amp;w=2" source="BUGTRAQ">20040604 RE: PING: Outlook 2003 Spam</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="outlook">
        <vers num="2003" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0502" published="2004-08-18" name="CVE-2004-0502" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Outlook 2003, when replying to an e-mail message, stores certain files in a predictable location for the "src" of an img tag of the original message, which allows remote attackers to bypass zone restrictions and exploit other issues that rely on predictable locations, as demonstrated using a shell: URI.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/16104" source="XF">outlook-file-location-predictable(16104)</ref>
      <ref url="http://www.securityfocus.com/bid/10307" source="BID" adv="1">10307</ref>
      <ref url="http://secunia.com/advisories/11572" source="SECUNIA">11572</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108637351805607&amp;w=2" source="BUGTRAQ" adv="1">20040604 RE: PING: Outlook 2003 Spam</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108420583612655&amp;w=2" source="BUGTRAQ" adv="1">20040509 OUTLOOK 2003: OuchLook</ref>
      <ref url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=108644231209698&amp;w=2" source="NTBUGTRAQ">20040604 RE: PING: Outlook 2003 Spam</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="outlook">
        <vers num="2003" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0503" published="2004-08-18" name="CVE-2004-0503" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Microsoft Outlook 2003 allows remote attackers to bypass the default zone restrictions and execute script within media files via a Rich Text Format (RTF) message containing an OLE object for the Windows Media Player, which bypasses Media Player's setting to disallow scripting and may lead to unprompted installation of an executable when exploited in conjunction with predictable-file-location exposures such as CVE-2004-0502.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/10369" source="BID" patch="1" adv="1">10369</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/16173" source="XF" adv="1">outlook-ole-restriction-bypass(16173)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108483193328605&amp;w=2" source="BUGTRAQ" adv="1">20040517 ROCKET SCIENCE: Outllook 2003</ref>
      <ref url="http://www.osvdb.org/6217" source="OSVDB">6217</ref>
      <ref url="http://secunia.com/advisories/11629" source="SECUNIA">11629</ref>
      <ref url="http://archives.neohapsis.com/archives/fulldisclosure/2004-05/0885.html" source="FULLDISC">20040517 ROCKET SCIENCE: Outllook 2003</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="outlook">
        <vers num="2003" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0504" published="2004-08-18" name="CVE-2004-0504" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Ethereal 0.10.3 allows remote attackers to cause a denial of service (crash) via certain SIP messages between Hotsip servers and clients.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
      <design />
      <other />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/10347" source="BID" patch="1" adv="1">10347</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-234.html" source="REDHAT" patch="1" adv="1">RHSA-2004:234</ref>
      <ref url="http://www.ethereal.com/lists/ethereal-users/200405/msg00018.html" source="MLIST">[Ethereal-users] 20040503 Re: HotSIP sip-messages crasching ethereal</ref>
      <ref url="http://www.ethereal.com/appnotes/enpa-sa-00014.html" source="CONFIRM">http://www.ethereal.com/appnotes/enpa-sa-00014.html</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200406-01.xml" source="GENTOO" adv="1">GLSA-200406-01</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9769" source="OVAL">oval:org.mitre.oval:def:9769</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000916" source="CONECTIVA">CLA-2005:916</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/20040605-01-U.asc" source="SGI">20040605-01-U</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/20040604-01-U.asc" source="SGI">20040604-01-U</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/16148" source="XF">ethereal-sip-packet-dos(16148)</ref>
      <ref url="http://www.osvdb.org/6131" source="OSVDB">6131</ref>
      <ref url="http://www.ciac.org/ciac/bulletins/o-150.shtml" source="CIAC">O-150</ref>
      <ref url="http://securitytracker.com/id?1010158" source="SECTRACK">1010158</ref>
      <ref url="http://secunia.com/advisories/11836" source="SECUNIA">11836</ref>
      <ref url="http://secunia.com/advisories/11776" source="SECUNIA">11776</ref>
      <ref url="http://secunia.com/advisories/11608" source="SECUNIA">11608</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:982" source="OVAL" sig="1">oval:org.mitre.oval:def:982</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ethereal_group" name="ethereal">
        <vers num="0.10.1" />
        <vers num="0.10.2" />
        <vers num="0.10.3" />
      </prod>
      <prod vendor="sgi" name="propack">
        <vers num="2.4" />
        <vers num="3.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0505" published="2004-08-18" name="CVE-2004-0505" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The AIM dissector in Ethereal 0.10.3 allows remote attackers to cause a denial of service (assert error) via unknown attack vectors.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
      <design />
      <other />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/10347" source="BID" patch="1" adv="1">10347</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-234.html" source="REDHAT" patch="1" adv="1">RHSA-2004:234</ref>
      <ref url="http://www.ethereal.com/appnotes/enpa-sa-00014.html" source="CONFIRM">http://www.ethereal.com/appnotes/enpa-sa-00014.html</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200406-01.xml" source="GENTOO" adv="1">GLSA-200406-01</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9433" source="OVAL">oval:org.mitre.oval:def:9433</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000916" source="CONECTIVA">CLA-2005:916</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/20040605-01-U.asc" source="SGI">20040605-01-U</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/20040604-01-U.asc" source="SGI">20040604-01-U</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/16150" source="XF">ethereal-aim-dissector-dos(16150)</ref>
      <ref url="http://www.osvdb.org/6132" source="OSVDB">6132</ref>
      <ref url="http://www.ciac.org/ciac/bulletins/o-150.shtml" source="CIAC">O-150</ref>
      <ref url="http://securitytracker.com/id?1010158" source="SECTRACK">1010158</ref>
      <ref url="http://secunia.com/advisories/11836" source="SECUNIA">11836</ref>
      <ref url="http://secunia.com/advisories/11776" source="SECUNIA">11776</ref>
      <ref url="http://secunia.com/advisories/11608" source="SECUNIA">11608</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:986" source="OVAL" sig="1">oval:org.mitre.oval:def:986</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ethereal_group" name="ethereal">
        <vers num="0.10.1" />
        <vers num="0.10.2" />
        <vers num="0.10.3" />
      </prod>
      <prod vendor="sgi" name="propack">
        <vers num="2.4" />
        <vers num="3.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0506" published="2004-08-18" name="CVE-2004-0506" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The SPNEGO dissector in Ethereal 0.9.8 to 0.10.3 allows remote attackers to cause a denial of service (crash) via unknown attack vectors that cause a null pointer dereference.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
      <design />
      <other />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/10347" source="BID" patch="1" adv="1">10347</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-234.html" source="REDHAT" patch="1" adv="1">RHSA-2004:234</ref>
      <ref url="http://www.ethereal.com/appnotes/enpa-sa-00014.html" source="CONFIRM">http://www.ethereal.com/appnotes/enpa-sa-00014.html</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200406-01.xml" source="GENTOO" adv="1">GLSA-200406-01</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9695" source="OVAL">oval:org.mitre.oval:def:9695</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000916" source="CONECTIVA">CLA-2005:916</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/20040605-01-U.asc" source="SGI">20040605-01-U</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/20040604-01-U.asc" source="SGI">20040604-01-U</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/16151" source="XF">ethereal-spnego-dos(16151)</ref>
      <ref url="http://www.ciac.org/ciac/bulletins/o-150.shtml" source="CIAC">O-150</ref>
      <ref url="http://securitytracker.com/id?1010158" source="SECTRACK">1010158</ref>
      <ref url="http://secunia.com/advisories/11836" source="SECUNIA">11836</ref>
      <ref url="http://secunia.com/advisories/11776" source="SECUNIA">11776</ref>
      <ref url="http://secunia.com/advisories/11608" source="SECUNIA">11608</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:987" source="OVAL" sig="1">oval:org.mitre.oval:def:987</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ethereal_group" name="ethereal">
        <vers num="0.10.1" />
        <vers num="0.10.2" />
        <vers num="0.10.3" />
      </prod>
      <prod vendor="sgi" name="propack">
        <vers num="2.4" />
        <vers num="3.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0507" published="2004-08-18" name="CVE-2004-0507" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Buffer overflow in the MMSE dissector for Ethereal 0.10.1 to 0.10.3 allows remote attackers to cause a denial of service and possibly execute arbitrary code.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.ethereal.com/appnotes/enpa-sa-00014.html" source="CONFIRM" adv="1">http://www.ethereal.com/appnotes/enpa-sa-00014.html</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200406-01.xml" source="GENTOO" adv="1">GLSA-200406-01</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2004-234.html" source="REDHAT">RHSA-2004:234</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11026" source="OVAL">oval:org.mitre.oval:def:11026</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000916" source="CONECTIVA">CLA-2005:916</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/20040605-01-U.asc" source="SGI">20040605-01-U</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/20040604-01-U.asc" source="SGI">20040604-01-U</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/16152" source="XF">ethereal-mmse-bo(16152)</ref>
      <ref url="http://www.securityfocus.com/bid/10347" source="BID">10347</ref>
      <ref url="http://www.osvdb.org/6134" source="OSVDB">6134</ref>
      <ref url="http://www.ciac.org/ciac/bulletins/o-150.shtml" source="CIAC">O-150</ref>
      <ref url="http://securitytracker.com/id?1010158" source="SECTRACK">1010158</ref>
      <ref url="http://secunia.com/advisories/11836" source="SECUNIA">11836</ref>
      <ref url="http://secunia.com/advisories/11776" source="SECUNIA">11776</ref>
      <ref url="http://secunia.com/advisories/11608" source="SECUNIA">11608</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:988" source="OVAL" sig="1">oval:org.mitre.oval:def:988</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ethereal_group" name="ethereal">
        <vers num="0.10.1" />
        <vers num="0.10.2" />
        <vers num="0.10.3" />
      </prod>
      <prod vendor="sgi" name="propack">
        <vers num="2.4" />
        <vers num="3.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0510" published="2004-12-23" name="CVE-2004-0510" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Multiple buffer overflows in MMDF on OpenServer 5.0.6 and 5.0.7, and possibly other operating systems, may allow attackers to execute arbitrary code, as demonstrated via the execmail program.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/16738" source="XF" patch="1" adv="1">openserver-mmdf-bo(16738)</ref>
      <ref url="http://www.securityfocus.com/bid/10758" source="BID" patch="1" adv="1">10758</ref>
      <ref url="http://www.deprotect.com/advisories/DEPROTECT-20040206.txt" source="MISC">http://www.deprotect.com/advisories/DEPROTECT-20040206.txt</ref>
      <ref url="ftp://ftp.sco.com/pub/updates/OpenServer/SCOSA-2004.7/SCOSA-2004.7.txt" source="SCO">SCOSA-2004.7</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109889281711636&amp;w=2" source="BUGTRAQ">20041027 MMDF deliver local root exploit for SCO OpenServer 5.0.7 x86</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sco" name="openserver">
        <vers num="5.0.6" />
        <vers num="5.0.6a" />
        <vers num="5.0.7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2004-0511" published="2004-12-23" name="CVE-2004-0511" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">Multiple unknown vulnerabilities in MMDF on OpenServer 5.0.6 and 5.0.7, and possibly other operating systems, may allow attackers to cause a denial of service by triggering a null dereference.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/16739" source="XF" patch="1" adv="1">openserver-mmdf-name-dos(16739)</ref>
      <ref url="http://www.securityfocus.com/bid/10758" source="BID" patch="1" adv="1">10758</ref>
      <ref url="ftp://ftp.sco.com/pub/updates/OpenServer/SCOSA-2004.7/SCOSA-2004.7.txt" source="SCO" patch="1" adv="1">SCOSA-2004.7</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sco" name="openserver">
        <vers num="5.0.6" />
        <vers num="5.0.6a" />
        <vers num="5.0.7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2004-0512" published="2004-12-23" name="CVE-2004-0512" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">Multiple unknown vulnerabilities in MMDF on OpenServer 5.0.6 and 5.0.7, and possibly other operating systems, may allow attackers to cause a denial of service by triggering a core dump.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/16740" source="XF" patch="1" adv="1">openserver-mmdf-dos(16740)</ref>
      <ref url="http://www.securityfocus.com/bid/10758" source="BID" patch="1" adv="1">10758</ref>
      <ref url="ftp://ftp.sco.com/pub/updates/OpenServer/SCOSA-2004.7/SCOSA-2004.7.txt" source="SCO" patch="1" adv="1">SCOSA-2004.7</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sco" name="openserver">
        <vers num="5.0.6" />
        <vers num="5.0.6a" />
        <vers num="5.0.7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0513" published="2004-08-18" name="CVE-2004-0513" modified="2008-09-10" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in Mac OS X before 10.3.4 has unknown impact and attack vectors related to "logging when tracing system calls."</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <other />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/16291" source="XF">macosx-nfs-logging(16291)</ref>
      <ref url="http://www.securitytracker.com/alerts/2004/May/1010329.html" source="SECTRACK">1010329</ref>
      <ref url="http://www.securityfocus.com/bid/10432" source="BID">10432</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2004/May/msg00005.html" source="APPLE">APPLE-SA-2004-05-28</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers prev="1" num="10.3.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0514" published="2004-08-18" name="CVE-2004-0514" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Unknown vulnerability in LoginWindow for Mac OS X 10.3.4, related to "handling of directory services lookups."</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" admin="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/174790" source="CERT-VN" adv="1">VU#174790</ref>
      <ref url="http://www.securityfocus.com/bid/10432" source="BID" patch="1" adv="1">10432</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/16289" source="XF">macosx-loginwindow-gain-privileges(16289)</ref>
      <ref url="http://securitytracker.com/id?1010330" source="SECTRACK">1010330</ref>
      <ref url="http://lists.seifried.org/pipermail/security/2004-May/003743.html" source="APPLE">APPLE-SA-2004-05-28</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.3" />
        <vers num="10.3.1" />
        <vers num="10.3.2" />
        <vers num="10.3.3" />
      </prod>
      <prod vendor="apple" name="mac_os_x_server">
        <vers num="10.3" />
        <vers num="10.3.1" />
        <vers num="10.3.2" />
        <vers num="10.3.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0515" published="2004-08-18" name="CVE-2004-0515" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Unknown vulnerability in LoginWindow for Mac OS X 10.3.4, related to "handling of console log files."</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <other />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/10432" source="BID" patch="1" adv="1">10432</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/16289" source="XF">macosx-loginwindow-gain-privileges(16289)</ref>
      <ref url="http://securitytracker.com/id?1010330" source="SECTRACK">1010330</ref>
      <ref url="http://lists.seifried.org/pipermail/security/2004-May/003743.html" source="APPLE">APPLE-SA-2004-05-28</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.3" />
        <vers num="10.3.1" />
        <vers num="10.3.2" />
        <vers num="10.3.3" />
      </prod>
      <prod vendor="apple" name="mac_os_x_server">
        <vers num="10.3" />
        <vers num="10.3.1" />
        <vers num="10.3.2" />
        <vers num="10.3.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0516" published="2004-08-18" name="CVE-2004-0516" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Unknown vulnerability in Mac OS X 10.3.4, related to "package installation scripts," a different vulnerability than CVE-2004-0517.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <other />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/10432" source="BID" patch="1" adv="1">10432</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/16290" source="XF">macosx-package-installation(16290)</ref>
      <ref url="http://securitytracker.com/id?1010331" source="SECTRACK">1010331</ref>
      <ref url="http://lists.seifried.org/pipermail/security/2004-May/003743.html" source="APPLE">APPLE-SA-2004-05-28</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.3" />
        <vers num="10.3.1" />
        <vers num="10.3.2" />
        <vers num="10.3.3" />
      </prod>
      <prod vendor="apple" name="mac_os_x_server">
        <vers num="10.3" />
        <vers num="10.3.1" />
        <vers num="10.3.2" />
        <vers num="10.3.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0517" published="2004-08-18" name="CVE-2004-0517" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Unknown vulnerability in Mac OS X 10.3.4, related to "handling of process IDs during package installation," a different vulnerability than CVE-2004-0516.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <other />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/10432" source="BID" patch="1" adv="1">10432</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/16290" source="XF">macosx-package-installation(16290)</ref>
      <ref url="http://securitytracker.com/id?1010331" source="SECTRACK">1010331</ref>
      <ref url="http://lists.seifried.org/pipermail/security/2004-May/003743.html" source="APPLE">APPLE-SA-2004-05-28</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.3" />
        <vers num="10.3.1" />
        <vers num="10.3.2" />
        <vers num="10.3.3" />
      </prod>
      <prod vendor="apple" name="mac_os_x_server">
        <vers num="10.3" />
        <vers num="10.3.1" />
        <vers num="10.3.2" />
        <vers num="10.3.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0518" published="2004-08-18" name="CVE-2004-0518" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Unknown vulnerability in AppleFileServer for Mac OS X 10.3.4, related to "the use of SSH and reporting errors," has unknown impact and attack vectors.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <other />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/16288" source="XF">applefileserver-reporting-error(16288)</ref>
      <ref url="http://securitytracker.com/id?1010333" source="SECTRACK">1010333</ref>
      <ref url="http://lists.seifried.org/pipermail/security/2004-May/003743.html" source="APPLE">APPLE-SA-2004-05-28</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.3" />
        <vers num="10.3.1" />
        <vers num="10.3.2" />
        <vers num="10.3.3" />
      </prod>
      <prod vendor="apple" name="mac_os_x_server">
        <vers num="10.3" />
        <vers num="10.3.1" />
        <vers num="10.3.2" />
        <vers num="10.3.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0519" published="2004-08-18" name="CVE-2004-0519" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in SquirrelMail 1.4.2 allow remote attackers to execute arbitrary script as other users and possibly steal authentication information via multiple attack vectors, including the mailbox parameter in compose.php.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="https://bugzilla.fedora.us/show_bug.cgi?id=1733" source="FEDORA" patch="1">FEDORA-2004-1733</ref>
      <ref url="http://www.securityfocus.com/bid/10246" source="BID" patch="1">10246</ref>
      <ref url="http://www.securityfocus.com/advisories/6827" source="FEDORA" patch="1" adv="1">FEDORA-2004-160</ref>
      <ref url="http://www.debian.org/security/2004/dsa-535" source="DEBIAN" patch="1" adv="1">DSA-535</ref>
      <ref url="http://secunia.com/advisories/12289" source="SECUNIA" patch="1">12289</ref>
      <ref url="http://secunia.com/advisories/11870" source="SECUNIA" patch="1" adv="1">11870</ref>
      <ref url="http://secunia.com/advisories/11686" source="SECUNIA" patch="1" adv="1">11686</ref>
      <ref url="http://secunia.com/advisories/11531" source="SECUNIA" patch="1" adv="1">11531</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2004-240.html" source="REDHAT" patch="1" adv="1">RHSA-2004:240</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/20040604-01-U.asc" source="SGI" patch="1">20040604-01-U</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/16025" source="XF">squirrel-composephp-xss(16025)</ref>
      <ref url="http://www.securityfocus.com/archive/1/361857" source="BUGTRAQ">20040430 Re: SquirrelMail Cross Scripting Attacks....</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2005_19_sr.html" source="SUSE" adv="1">SUSE-SR:2005:019</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200405-16.xml" source="GENTOO" adv="1">GLSA-200405-16</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10274" source="OVAL">oval:org.mitre.oval:def:10274</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108334862800260" source="BUGTRAQ">20040429 SquirrelMail Cross Scripting Attacks....</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000858" source="CONECTIVA">CLA-2004:858</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1006" source="OVAL" sig="1">oval:org.mitre.oval:def:1006</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sgi" name="propack">
        <vers num="3.0" />
      </prod>
      <prod vendor="squirrelmail" name="squirrelmail">
        <vers num="1.0.4" />
        <vers num="1.0.5" />
        <vers num="1.2.0" />
        <vers num="1.2.1" />
        <vers num="1.2.10" />
        <vers num="1.2.11" />
        <vers num="1.2.2" />
        <vers num="1.2.3" />
        <vers num="1.2.4" />
        <vers num="1.2.5" />
        <vers num="1.2.6" />
        <vers num="1.2.7" />
        <vers num="1.2.8" />
        <vers num="1.2.9" />
        <vers num="1.4" />
        <vers num="1.4.1" />
        <vers num="1.4.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0520" published="2004-08-18" name="CVE-2004-0520" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in mime.php for SquirrelMail before 1.4.3 allows remote attackers to insert arbitrary HTML and script via the content-type mail header, as demonstrated using read_body.php.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="https://bugzilla.fedora.us/show_bug.cgi?id=1733" source="FEDORA" patch="1">FEDORA-2004-1733</ref>
      <ref url="http://www.securityfocus.com/bid/10439" source="BID" patch="1">10439</ref>
      <ref url="http://www.securityfocus.com/advisories/6827" source="FEDORA" patch="1" adv="1">FEDORA-2004-160</ref>
      <ref url="http://www.debian.org/security/2004/dsa-535" source="DEBIAN" patch="1" adv="1">DSA-535</ref>
      <ref url="http://secunia.com/advisories/12289" source="SECUNIA" patch="1" adv="1">12289</ref>
      <ref url="http://secunia.com/advisories/11870" source="SECUNIA" patch="1" adv="1">11870</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2004-240.html" source="REDHAT" patch="1" adv="1">RHSA-2004:240</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/20040604-01-U.asc" source="SGI" patch="1">20040604-01-U</ref>
      <ref url="http://www.rs-labs.com/adv/RS-Labs-Advisory-2004-1.txt" source="MISC" adv="1">http://www.rs-labs.com/adv/RS-Labs-Advisory-2004-1.txt</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200406-08.xml" source="GENTOO" adv="1">GLSA-200406-08</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10766" source="OVAL">oval:org.mitre.oval:def:10766</ref>
      <ref url="http://marc.theaimsgroup.com/?l=squirrelmail-cvs&amp;m=108532891231712" source="MLIST">[squirrelmail-cvs] 20040523 [SM-CVS] CVS: squirrelmail/functions mime.php,1.265.2.27,1.265.2.28</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108611554415078&amp;w=2" source="BUGTRAQ" adv="1">20040530 RS-2004-1: SquirrelMail "Content-Type" XSS vulnerability</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000858" source="CONECTIVA">CLA-2004:858</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1012" source="OVAL" sig="1">oval:org.mitre.oval:def:1012</ref>
    </refs>
    <vuln_soft>
      <prod vendor="open_webmail" name="open_webmail">
        <vers num="2.30" />
        <vers num="2.31" />
        <vers num="2.32" />
      </prod>
      <prod vendor="sgi" name="propack">
        <vers num="3.0" />
      </prod>
      <prod vendor="squirrelmail" name="squirrelmail">
        <vers num="1.2.0" />
        <vers num="1.2.1" />
        <vers num="1.2.10" />
        <vers num="1.2.11" />
        <vers num="1.2.2" />
        <vers num="1.2.3" />
        <vers num="1.2.4" />
        <vers num="1.2.5" />
        <vers num="1.2.6" />
        <vers num="1.2.7" />
        <vers num="1.2.8" />
        <vers num="1.2.9" />
        <vers num="1.4" />
        <vers num="1.4.1" />
        <vers num="1.4.2" />
        <vers num="1.4.3_rc1" />
        <vers num="1.5_dev" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0521" published="2004-08-18" name="CVE-2004-0521" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">SQL injection vulnerability in SquirrelMail before 1.4.3 RC1 allows remote attackers to execute unauthorized SQL statements, with unknown impact, probably via abook_database.php.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" admin="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/10397" source="BID" patch="1" adv="1">10397</ref>
      <ref url="https://bugzilla.fedora.us/show_bug.cgi?id=1733" source="FEDORA">FEDORA-2004-1733</ref>
      <ref url="http://www.debian.org/security/2004/dsa-535" source="DEBIAN">DSA-535</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200405-16.xml" source="GENTOO" adv="1">GLSA-200405-16</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2004-240.html" source="REDHAT">RHSA-2004:240</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11446" source="OVAL">oval:org.mitre.oval:def:11446</ref>
      <ref url="http://marc.theaimsgroup.com/?l=squirrelmail-cvs&amp;m=108309375029888" source="MLIST" adv="1">[squirrelmail-cvs] 20040427 [SM-CVS] CVS: squirrelmail/functions abook_database.php,1.15.2.1,1.15.2.2</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/20040604-01-U.asc" source="SGI">20040604-01-U</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/16235" source="XF">squirrelmail-sql-injection(16235)</ref>
      <ref url="http://www.securityfocus.com/advisories/7148" source="APPLE">APPLE-SA-2004-09-07</ref>
      <ref url="http://www.securityfocus.com/advisories/6827" source="FEDORA">FEDORA-2004-160</ref>
      <ref url="http://www.osvdb.org/6841" source="OSVDB">6841</ref>
      <ref url="http://www.ciac.org/ciac/bulletins/o-212.shtml" source="CIAC">O-212</ref>
      <ref url="http://secunia.com/advisories/12289" source="SECUNIA">12289</ref>
      <ref url="http://secunia.com/advisories/11870" source="SECUNIA">11870</ref>
      <ref url="http://secunia.com/advisories/11686" source="SECUNIA">11686</ref>
      <ref url="http://secunia.com/advisories/11685" source="SECUNIA">11685</ref>
      <ref url="http://marc.theaimsgroup.com/?l=squirrelmail-cvs&amp;m=108532891231712" source="MLIST">[squirrelmail-devel] 20040511 [SM-DEVEL] SquirrelMail 1.4.3-RC1 Release</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000858" source="CONECTIVA">CLA-2004:858</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1033" source="OVAL" sig="1">oval:org.mitre.oval:def:1033</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sgi" name="propack">
        <vers num="3.0" />
      </prod>
      <prod vendor="squirrelmail" name="squirrelmail">
        <vers num="1.0.4" />
        <vers num="1.0.5" />
        <vers num="1.2.0" />
        <vers num="1.2.1" />
        <vers num="1.2.10" />
        <vers num="1.2.11" />
        <vers num="1.2.2" />
        <vers num="1.2.3" />
        <vers num="1.2.4" />
        <vers num="1.2.5" />
        <vers num="1.2.6" />
        <vers num="1.2.7" />
        <vers num="1.2.8" />
        <vers num="1.2.9" />
        <vers num="1.4" />
        <vers num="1.4.1" />
        <vers num="1.4.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0522" published="2004-08-06" name="CVE-2004-0522" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Gallery 1.4.3 and earlier allows remote attackers to bypass authentication and obtain Gallery administrator privileges.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/10451" source="BID" patch="1" adv="1">10451</ref>
      <ref url="http://www.debian.org/security/2004/dsa-512" source="DEBIAN" patch="1" adv="1">DSA-512</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/16301" source="XF" adv="1">gallery-user-bypass-authentication(16301)</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200406-10.xml" source="GENTOO">GLSA-200406-10</ref>
      <ref url="http://secunia.com/advisories/11752" source="SECUNIA">11752</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gallery_project" name="gallery">
        <vers num="1.4" />
        <vers num="1.4.1" />
        <vers num="1.4.2" />
        <vers num="1.4.3_pl1" />
        <vers num="1.4_pl1" />
        <vers num="1.4_pl2" />
      </prod>
      <prod vendor="debian" name="debian_linux">
        <vers num="3.0" edition="" />
        <vers num="3.0" edition=":hppa" />
        <vers num="3.0" edition=":mips" />
        <vers num="3.0" edition=":ia-32" />
        <vers num="3.0" edition=":m68k" />
        <vers num="3.0" edition=":s-390" />
        <vers num="3.0" edition=":alpha" />
        <vers num="3.0" edition=":arm" />
        <vers num="3.0" edition=":ia-64" />
        <vers num="3.0" edition=":mipsel" />
        <vers num="3.0" edition=":sparc" />
        <vers num="3.0" edition=":ppc" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0523" published="2004-08-18" name="CVE-2004-0523" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Multiple buffer overflows in krb5_aname_to_localname for MIT Kerberos 5 (krb5) 1.3.3 and earlier allow remote attackers to execute arbitrary code as root.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/686862" source="CERT-VN" adv="1">VU#686862</ref>
      <ref url="http://www.debian.org/security/2004/dsa-520" source="DEBIAN" patch="1" adv="1">DSA-520</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/16268" source="XF">Kerberos-krb5anametolocalname-bo(16268)</ref>
      <ref url="http://www.securityfocus.com/bid/10448" source="BID">10448</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-236.html" source="REDHAT">RHSA-2004:236</ref>
      <ref url="http://www.mandrakesecure.net/en/advisories/advisory.php?name=MDKSA-2004:056" source="MANDRAKE">MDKSA-2004:056</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200406-21.xml" source="GENTOO">GLSA-200406-21</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-101512-1" source="SUNALERT">101512</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10295" source="OVAL">oval:org.mitre.oval:def:10295</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108619250923790&amp;w=2" source="TRUSTIX">2004-0032</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108619161815320&amp;w=2" source="BUGTRAQ">20040602 TSSA-2004-009 - kerberos5</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108612325909496&amp;w=2" source="BUGTRAQ">20040601 MITKRB5-SA-2004-001: buffer overflows in krb5_aname_to_localname</ref>
      <ref url="http://lwn.net/Articles/88206/" source="FEDORA">FEDORA-2004-149</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000860" source="CONECTIVA">CLA-2004:860</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/20040605-01-U.asc" source="SGI">20040605-01-U</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/20040604-01-U.asc" source="SGI">20040604-01-U</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:991" source="OVAL" sig="1">oval:org.mitre.oval:def:991</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:724" source="OVAL" sig="1">oval:org.mitre.oval:def:724</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2002" source="OVAL" sig="1">oval:org.mitre.oval:def:2002</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mit" name="kerberos">
        <vers num="1.0" />
        <vers num="1.0.8" />
        <vers num="1.2.2.beta1" />
        <vers num="5-1.1" />
        <vers num="5-1.2" />
        <vers num="5-1.2.1" />
        <vers num="5-1.2.2" />
        <vers num="5-1.2.3" />
        <vers num="5-1.2.4" />
        <vers num="5-1.2.5" />
        <vers num="5-1.2.6" />
        <vers num="5-1.2.7" />
        <vers num="5-1.3" edition="alpha1" />
        <vers num="5_1.0" />
        <vers num="5_1.0.6" />
        <vers num="5_1.1" />
        <vers num="5_1.1.1" />
        <vers num="5_1.2" edition="beta1" />
        <vers num="5_1.2" edition="beta2" />
        <vers num="5_1.3.3" />
      </prod>
      <prod vendor="sgi" name="propack">
        <vers num="2.4" />
        <vers num="3.0" />
      </prod>
      <prod vendor="sun" name="seam">
        <vers num="1.0" />
        <vers num="1.0.1" />
        <vers num="1.0.2" />
      </prod>
      <prod vendor="tinysofa" name="tinysofa_enterprise_server">
        <vers num="1.0" />
        <vers num="1.0_u1" />
      </prod>
      <prod vendor="sun" name="solaris">
        <vers num="8.0" edition="" />
        <vers num="8.0" edition=":x86" />
        <vers num="9.0" edition="" />
        <vers num="9.0" edition=":sparc" />
        <vers num="9.0" edition=":x86" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0524" published="2004-08-06" name="CVE-2004-0524" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Buffer overflow in the chpasswd command in the Change_passwd plugin before 4.0, as used in SquirrelMail, allows local users to gain root privileges via a long user name.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/10166" source="BID" patch="1" adv="1">10166</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108311782032370&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20040427 Re:  Squirrelmail Chpasswod bof</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15889" source="XF" adv="1">squirrelmail-chpasswd-binary-bo(15889)</ref>
      <ref url="http://www.squirrelmail.org/plugin_view.php?id=117" source="CONFIRM">http://www.squirrelmail.org/plugin_view.php?id=117</ref>
      <ref url="http://secunia.com/advisories/11415" source="SECUNIA">11415</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108222863917958&amp;w=2" source="BUGTRAQ">20040417 Squirrelmail Chpasswod bof</ref>
    </refs>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0525" published="2004-08-06" name="CVE-2004-0525" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">HP Integrated Lights-Out (iLO) 1.10 and other versions before 1.55 allows remote attackers to cause a denial of service (hang) by accessing iLO using the TCP/IP reserved port zero.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/10415" source="BID" patch="1" adv="1">10415</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/16251" source="XF" adv="1">ilo-port-zero-dos(16251)</ref>
      <ref url="http://seclists.org/lists/bugtraq/2004/May/0281.html" source="HP">SSRT4724</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hp" name="integrated_lights_out">
        <vers num="1.10" />
        <vers num="1.15" />
        <vers num="1.15a" />
        <vers num="1.16a" />
        <vers num="1.20a" />
        <vers num="1.26a" />
        <vers num="1.27a" />
        <vers num="1.40a" />
        <vers num="1.41a" />
        <vers num="1.42a" />
        <vers num="1.50" />
        <vers num="1.50a" />
        <vers num="1.51a" />
        <vers num="1.6a" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0526" published="2004-08-06" name="CVE-2004-0526" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Unknown versions of Internet Explorer and Outlook allow remote attackers to spoof a legitimate URL in the status bar via A HREF tags with modified "alt" values that point to the legitimate site, combined with an image map whose href points to the malicious site, which facilitates a "phishing" attack.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/16102" source="XF" adv="1">ie-ahref-url-spoofing(16102)</ref>
      <ref url="http://www.securityfocus.com/bid/10308" source="BID" adv="1">10308</ref>
      <ref url="http://www.kurczaba.com/securityadvisories/0405132poc.htm" source="MISC">http://www.kurczaba.com/securityadvisories/0405132poc.htm</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108422905510713&amp;w=2" source="BUGTRAQ" adv="1">20040510 DEEP SEA PHISHING: Internet Explorer / Outlook Express</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2004-05/0161.html" source="BUGTRAQ">20040517 Microsoft Internet Explorer ImageMap URL Spoof Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="ie">
        <vers num="5.0" />
        <vers num="5.0.1" edition="sp1" />
        <vers num="5.0.1" edition="sp2" />
        <vers num="5.0.1" edition="sp3" />
        <vers num="5.0.1" edition="sp4" />
        <vers num="5.5" edition="sp1" />
        <vers num="5.5" edition="sp2" />
        <vers num="6.0" edition="sp1" />
      </prod>
      <prod vendor="microsoft" name="outlook">
        <vers num="2000" edition="sp2" />
        <vers num="2000" edition="sp3" />
        <vers num="2000" edition="sr1" />
        <vers num="2002" edition="sp1" />
        <vers num="2002" edition="sp2" />
        <vers num="2002" edition="sp3" />
        <vers num="2003" />
        <vers num="97" />
        <vers num="98" />
      </prod>
      <prod vendor="microsoft" name="outlook_express">
        <vers num="4.0" />
        <vers num="4.01" edition="sp2" />
        <vers num="4.27.3110" />
        <vers num="4.72.2106" />
        <vers num="4.72.3120.0" />
        <vers num="4.72.3612" />
        <vers num="5.0" />
        <vers num="5.0.1" />
        <vers num="5.5" />
        <vers num="6.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0527" published="2004-08-06" name="CVE-2004-0527" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">KDE Konqueror 2.1.1 and 2.2.2 allows remote attackers to spoof a legitimate URL in the status bar via A HREF tags with modified "alt" values that point to the legitimate site, combined with an image map whose href points to the malicious site, which facilitates a "phishing" attack.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/10383" source="BID" adv="1">10383</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/16102" source="XF">ie-ahref-url-spoofing(16102)</ref>
      <ref url="http://www.osvdb.org/6579" source="OSVDB">6579</ref>
    </refs>
    <vuln_soft>
      <prod vendor="kde" name="konqueror">
        <vers num="2.1.1" />
        <vers num="2.2.2" />
        <vers num="3.0" />
        <vers num="3.0.1" />
        <vers num="3.0.2" />
        <vers num="3.0.3" />
        <vers num="3.0.5" />
        <vers num="3.1" />
        <vers num="3.1.1" />
        <vers num="3.1.2" />
        <vers num="3.1.3" />
        <vers num="3.2.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0528" published="2004-08-06" name="CVE-2004-0528" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Netscape Navigator 7.1 allows remote attackers to spoof a legitimate URL in the status bar via A HREF tags with modified "alt" values that point to the legitimate site, combined with an image map whose href points to the malicious site, which facilitates a "phishing" attack.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/10389" source="BID" adv="1">10389</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/16102" source="XF">ie-ahref-url-spoofing(16102)</ref>
      <ref url="http://www.osvdb.org/6580" source="OSVDB">6580</ref>
    </refs>
    <vuln_soft>
      <prod vendor="netscape" name="navigator">
        <vers num="7.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0529" published="2004-08-06" name="CVE-2004-0529" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">The modified suexec program in cPanel, when configured for mod_php and compiled for Apache 1.3.31 and earlier without mod_phpsuexec, allows local users to execute untrusted shared scripts and gain privileges, as demonstrated using untainted scripts such as (1) proftpdvhosts or (2) addalink.cgi, a different vulnerability than CVE-2004-0490.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" admin="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108663003608211&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20040605 cPanel mod_php suEXEC Taint Vulnerability</ref>
      <ref url="http://www.securityfocus.com/bid/10478" source="BID" adv="1">10478</ref>
      <ref url="http://bugzilla.cpanel.net/show_bug.cgi?id=668" source="CONFIRM">http://bugzilla.cpanel.net/show_bug.cgi?id=668</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/16347" source="XF">cpanel-suexec-command-execute(16347)</ref>
      <ref url="http://securitytracker.com/id?1010411" source="SECTRACK">1010411</ref>
      <ref url="http://secunia.com/advisories/11798" source="SECUNIA">11798</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cluecentral" name="suexec.patch">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0530" published="2004-08-06" name="CVE-2004-0530" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">The PHP package in Slackware 8.1, 9.0, and 9.1, when linked against a static library, includes /tmp in the search path, which allows local users to execute arbitrary code as the PHP user by inserting shared libraries into the appropriate path.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" admin="1" />
    </loss_types>
    <vuln_types>
      <config />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.slackware.com/security/viewer.php?l=slackware-security&amp;y=2004&amp;m=slackware-security.419765" source="SLACKWARE" patch="1" adv="1">SSA:2004-154</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/16310" source="XF">linux-php-gain-privileges(16310)</ref>
      <ref url="http://www.securityfocus.com/bid/10461" source="BID">10461</ref>
      <ref url="http://secunia.com/advisories/11760" source="SECUNIA">11760</ref>
    </refs>
  </entry>
  <entry type="CVE" severity="Low" seq="2004-0533" published="2004-12-31" name="CVE-2004-0533" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">Business Objects WebIntelligence 2.7.0 through 2.7.4 only enforces access controls on the client, which allows remote authenticated users to delete arbitrary files on the server via a crafted delete request using the InfoView web client.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/17422" source="XF" patch="1">webintelligence-url-delete-files(17422)</ref>
      <ref url="http://www.securityfocus.com/bid/11208" source="BID">11208</ref>
      <ref url="http://secunia.com/advisories/12587/" source="SECUNIA" adv="1">12587</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2004-September/026549.html" source="FULLDISC" adv="1">20040907 Corsaire Security Advisory - Business Objects WebIntelligence arbitrary document deletion issue</ref>
      <ref url="http://archives.neohapsis.com/archives/vulnwatch/2004-q3/0056.html" source="VULNWATCH" adv="1">20040917 Corsaire Security Advisory - Business Objects WebIntelligence arbitrary document deletion issue</ref>
    </refs>
    <vuln_soft>
      <prod vendor="businessobjects" name="infoview">
        <vers num="5.1.4" />
        <vers num="5.1.5" />
        <vers num="5.1.6" />
        <vers num="5.1.7" />
        <vers num="5.1.8" />
      </prod>
      <prod vendor="businessobjects" name="webintelligence">
        <vers num="2.7" />
        <vers num="2.7.1" />
        <vers num="2.7.2" />
        <vers num="2.7.3" />
        <vers num="2.7.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0534" published="2004-09-17" name="CVE-2004-0534" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in Business Objects InfoView 5.1.4 through 5.1.8 for WebIntelligence 2.7.0 through 2.7.4 allows remote attackers to inject arbitrary web script or HTML via document names when uploading a document.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/17419" source="XF" patch="1" adv="1">webintelligence-input-document-xss(17419)</ref>
      <ref url="http://secunia.com/advisories/12587/" source="SECUNIA" patch="1" adv="1">12587</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2004-September/026550.html" source="FULLDISC" patch="1" adv="1">20040907 Corsaire Security Advisory - Business Objects WebIntelligence XSS issue</ref>
      <ref url="http://archives.neohapsis.com/archives/vulnwatch/2004-q3/0057.html" source="VULNWATCH" patch="1" adv="1">20040917 Corsaire Security Advisory - Business Objects WebIntelligence XSS issue</ref>
      <ref url="http://www.securityfocus.com/bid/11209" source="BID">11209</ref>
    </refs>
    <vuln_soft>
      <prod vendor="businessobjects" name="infoview">
        <vers num="5.1.4" />
        <vers num="5.1.5" />
        <vers num="5.1.6" />
        <vers num="5.1.7" />
        <vers num="5.1.8" />
      </prod>
      <prod vendor="businessobjects" name="webintelligence">
        <vers num="2.7" />
        <vers num="2.7.1" />
        <vers num="2.7.2" />
        <vers num="2.7.3" />
        <vers num="2.7.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2004-0535" published="2004-08-06" name="CVE-2004-0535" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">The e1000 driver for Linux kernel 2.4.26 and earlier does not properly initialize memory before using it, which allows local users to read portions of kernel memory.  NOTE: this issue was originally incorrectly reported as a "buffer overflow" by some sources.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <env />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/10352" source="BID" patch="1" adv="1">10352</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-413.html" source="REDHAT" patch="1" adv="1">RHSA-2004:413</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/16159" source="XF" adv="1">linux-e1000-bo(16159)</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-418.html" source="REDHAT">RHSA-2004:418</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2004_20_kernel.html" source="SUSE">SUSE-SA:2004:020</ref>
      <ref url="http://www.kernel.org/pub/linux/kernel/v2.4/testing/patch-2.4.27.log" source="CONFIRM">http://www.kernel.org/pub/linux/kernel/v2.4/testing/patch-2.4.27.log</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200407-02.xml" source="GENTOO" adv="1">GLSA-200407-02</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11136" source="OVAL">oval:org.mitre.oval:def:11136</ref>
      <ref url="http://lwn.net/Articles/91155/" source="FEDORA">FEDORA-2004-186</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000845" source="CONECTIVA">CLA-2004:845</ref>
      <ref url="http://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=125168" source="CONFIRM">http://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=125168</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/20040804-01-U.asc" source="SGI">20040804-01-U</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2004:062" source="MANDRAKE">MDKSA-2004:062</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mandrakesoft" name="mandrake_multi_network_firewall">
        <vers num="8.2" />
      </prod>
      <prod vendor="suse" name="suse_email_server">
        <vers num="3.1" />
        <vers num="iii" />
      </prod>
      <prod vendor="suse" name="suse_linux_admin-cd_for_firewall">
        <vers num="" />
      </prod>
      <prod vendor="suse" name="suse_linux_connectivity_server">
        <vers num="" />
      </prod>
      <prod vendor="suse" name="suse_linux_database_server">
        <vers num="" />
      </prod>
      <prod vendor="suse" name="suse_linux_firewall_cd">
        <vers num="" />
      </prod>
      <prod vendor="suse" name="suse_linux_firewall_live-cd">
        <vers num="" />
      </prod>
      <prod vendor="suse" name="suse_linux_office_server">
        <vers num="" />
      </prod>
      <prod vendor="suse" name="suse_office_server">
        <vers num="" />
      </prod>
      <prod vendor="conectiva" name="linux">
        <vers num="8.0" />
        <vers num="9.0" />
      </prod>
      <prod vendor="engardelinux" name="secure_community">
        <vers num="2.0" />
      </prod>
      <prod vendor="engardelinux" name="secure_linux">
        <vers num="1.5" edition="" />
        <vers num="1.5" edition=":professional" />
      </prod>
      <prod vendor="gentoo" name="linux">
        <vers num="1.4" />
      </prod>
      <prod vendor="linux" name="linux_kernel">
        <vers num="2.4.0" edition="test1" />
        <vers num="2.4.0" edition="test10" />
        <vers num="2.4.0" edition="test11" />
        <vers num="2.4.0" edition="test12" />
        <vers num="2.4.0" edition="test2" />
        <vers num="2.4.0" edition="test3" />
        <vers num="2.4.0" edition="test4" />
        <vers num="2.4.0" edition="test5" />
        <vers num="2.4.0" edition="test6" />
        <vers num="2.4.0" edition="test7" />
        <vers num="2.4.0" edition="test8" />
        <vers num="2.4.0" edition="test9" />
        <vers num="2.4.1" />
        <vers num="2.4.10" />
        <vers num="2.4.11" />
        <vers num="2.4.12" />
        <vers num="2.4.13" />
        <vers num="2.4.14" />
        <vers num="2.4.15" />
        <vers num="2.4.16" />
        <vers num="2.4.17" />
        <vers num="2.4.18" edition="" />
        <vers num="2.4.18" edition=":x86" />
        <vers num="2.4.18" edition="pre1" />
        <vers num="2.4.18" edition="pre2" />
        <vers num="2.4.18" edition="pre3" />
        <vers num="2.4.18" edition="pre4" />
        <vers num="2.4.18" edition="pre5" />
        <vers num="2.4.18" edition="pre6" />
        <vers num="2.4.18" edition="pre7" />
        <vers num="2.4.18" edition="pre8" />
        <vers num="2.4.19" edition="pre1" />
        <vers num="2.4.19" edition="pre2" />
        <vers num="2.4.19" edition="pre3" />
        <vers num="2.4.19" edition="pre4" />
        <vers num="2.4.19" edition="pre5" />
        <vers num="2.4.19" edition="pre6" />
        <vers num="2.4.2" />
        <vers num="2.4.20" />
        <vers num="2.4.21" edition="pre1" />
        <vers num="2.4.21" edition="pre4" />
        <vers num="2.4.21" edition="pre7" />
        <vers num="2.4.22" />
        <vers num="2.4.23" edition="pre9" />
        <vers num="2.4.23_ow2" />
        <vers num="2.4.24" />
        <vers num="2.4.24_ow1" />
        <vers num="2.4.25" />
        <vers num="2.4.26" />
        <vers num="2.4.27" edition="pre1" />
        <vers num="2.4.3" />
        <vers num="2.4.4" />
        <vers num="2.4.5" />
        <vers num="2.4.6" />
        <vers num="2.4.7" />
        <vers num="2.4.8" />
        <vers num="2.4.9" />
      </prod>
      <prod vendor="mandrakesoft" name="mandrake_linux">
        <vers num="10.0" edition="" />
        <vers num="10.0" edition=":amd64" />
        <vers num="9.1" edition="" />
        <vers num="9.1" edition=":ppc" />
        <vers num="9.2" edition="" />
        <vers num="9.2" edition=":amd64" />
      </prod>
      <prod vendor="mandrakesoft" name="mandrake_linux_corporate_server">
        <vers num="2.1" edition="" />
        <vers num="2.1" edition=":x86_64" />
      </prod>
      <prod vendor="suse" name="suse_linux">
        <vers num="7" edition="" />
        <vers num="7" edition=":enterprise_server" />
        <vers num="8" edition="" />
        <vers num="8" edition=":enterprise_server" />
        <vers num="8.0" edition="" />
        <vers num="8.0" edition=":i386" />
        <vers num="8.1" />
        <vers num="8.2" />
        <vers num="9.0" edition="" />
        <vers num="9.0" edition=":x86_64" />
        <vers num="9.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0536" published="2004-08-06" name="CVE-2004-0536" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Format string vulnerability in Tripwire commercial 4.0.1 and earlier, including 2.4, and open source 2.3.1 and earlier, allows local users to gain privileges via format string specifiers in a file name, which is used in the generation of an email report.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" admin="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://security.gentoo.org/glsa/glsa-200406-02.xml" source="GENTOO" adv="1">GLSA-200406-02</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/16309" source="XF">tripwire-fprintf-format-string(16309)</ref>
      <ref url="http://www.securityfocus.com/bid/10454" source="BID">10454</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-244.html" source="REDHAT">RHSA-2004:244</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108630983009228&amp;w=2" source="BUGTRAQ">20040603 Re: Format String Vulnerability in Tripwire</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108627481507249&amp;w=2" source="BUGTRAQ">20040602 Format String Vulnerability in Tripwire</ref>
    </refs>
    <vuln_soft>
      <prod vendor="tripwire" name="tripwire">
        <vers num="2.2.1" />
        <vers num="2.3.0" />
        <vers num="2.3.1" />
        <vers num="2.3.1.2" />
        <vers num="2.4.0" />
        <vers num="2.4.2" />
        <vers num="3.0" />
        <vers num="3.0.1" />
        <vers num="4.0" />
        <vers num="4.0.1" />
        <vers num="4.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0537" published="2004-08-06" name="CVE-2004-0537" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Opera 7.50 and earlier allows remote web sites to provide a "Shortcut Icon" (favicon) that is wider than expected, which could allow the web sites to spoof a trusted domain and facilitate phishing attacks using a wide icon and extra spaces.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/10452" source="BID" patch="1" adv="1">10452</ref>
      <ref url="http://www.opera.com/linux/changelogs/751/index.dml" source="CONFIRM">http://www.opera.com/linux/changelogs/751/index.dml</ref>
      <ref url="http://security.greymagic.com/security/advisories/gm007-op/" source="MISC">http://security.greymagic.com/security/advisories/gm007-op/</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108627581717738&amp;w=2" source="BUGTRAQ" adv="1">20040603 Phishing for Opera (GM#007-OP)</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2004-June/022263.html" source="FULLDISC">20040603 Phishing for Opera (GM#007-OP)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/16307" source="XF">opera-favicon-spoofing(16307)</ref>
      <ref url="http://secunia.com/advisories/11762" source="SECUNIA">11762</ref>
      <ref url="http://osvdb.org/6590" source="OSVDB">6590</ref>
    </refs>
    <vuln_soft>
      <prod vendor="opera_software" name="opera_web_browser">
        <vers num="7.23" />
        <vers num="7.50" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0538" published="2004-08-06" name="CVE-2004-0538" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">LaunchServices in Mac OS X 10.3.4 and 10.2.8 automatically registers and executes new applications, which could allow attackers to execute arbitrary code without warning the user.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs />
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.2.8" />
        <vers num="10.3.4" />
      </prod>
      <prod vendor="apple" name="mac_os_x_server">
        <vers num="10.2.8" />
        <vers num="10.3.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0539" published="2004-08-06" name="CVE-2004-0539" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">The "Show in Finder" button in the Safari web browser in Mac OS X 10.3.4 and 10.2.8 may execute downloaded applications, which could allow remote attackers to execute arbitrary code.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" admin="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/773190" source="CERT-VN">VU#773190</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.2.8" />
        <vers num="10.3.4" />
      </prod>
      <prod vendor="apple" name="mac_os_x_server">
        <vers num="10.2.8" />
        <vers num="10.3.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0540" published="2004-08-06" name="CVE-2004-0540" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Microsoft Windows 2000, when running in a domain whose Fully Qualified Domain Name (FQDN) is exactly 8 characters long, does not prevent users with expired passwords from logging on to the domain.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" admin="1" />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://support.microsoft.com/default.aspx?scid=kb;en-us;830847" source="MSKB" adv="1">830847</ref>
      <ref url="http://secunia.com/advisories/11746/" source="SECUNIA">11746</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_2000">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0541" published="2004-08-06" name="CVE-2004-0541" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Buffer overflow in the ntlm_check_auth (NTLM authentication) function for Squid Web Proxy Cache 2.5.x and 3.x, when compiled with NTLM handlers enabled, allows remote attackers to execute arbitrary code via a long password ("pass" variable).</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/16360" source="XF" patch="1" adv="1">squid-ntlm-bo(16360)</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-242.html" source="REDHAT" patch="1" adv="1">RHSA-2004:242</ref>
      <ref url="http://www.idefense.com/application/poi/display?id=107&amp;type=vulnerabilities" source="MISC" patch="1" adv="1">http://www.idefense.com/application/poi/display?id=107&amp;type=vulnerabilities</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200406-13.xml" source="GENTOO" patch="1" adv="1">GLSA-200406-13</ref>
      <ref url="http://www.trustix.net/errata/2004/0033/" source="TRUSTIX" adv="1">2004-0033</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10722" source="OVAL">oval:org.mitre.oval:def:10722</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/20040604-01-U.asc" source="SGI">20040604-01-U</ref>
      <ref url="http://www.securityfocus.com/bid/10500" source="BID">10500</ref>
      <ref url="http://fedoranews.org/updates/FEDORA--.shtml" source="FEDORA">FLSA-2006:152809</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:980" source="OVAL" sig="1">oval:org.mitre.oval:def:980</ref>
    </refs>
    <vuln_soft>
      <prod vendor="national_science_foundation" name="squid_web_proxy_cache">
        <vers num="2.5_stable" />
        <vers num="3_pre" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0542" published="2004-08-06" name="CVE-2004-0542" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">PHP before 4.3.7 on Win32 platforms does not properly filter all shell metacharacters, which allows local or remote attackers to execute arbitrary code, overwrite files, and access internal environment variables via (1) the "%", "|", or ">" characters to the escapeshellcmd function, or (2) the "%" character to the escapeshellarg function.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" admin="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/16331" source="XF" patch="1" adv="1">php-escapeshellarg-execute-command(16331)</ref>
      <ref url="http://www.php.net/release_4_3_7.php" source="CONFIRM" patch="1">http://www.php.net/release_4_3_7.php</ref>
      <ref url="http://www.idefense.com/application/poi/display?id=108" source="MISC" adv="1">http://www.idefense.com/application/poi/display?id=108</ref>
    </refs>
    <vuln_soft>
      <prod vendor="php" name="php">
        <vers num="4.4.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0543" published="2004-08-06" name="CVE-2004-0543" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Multiple SQL injection vulnerabilities in Oracle Applications 11.0 and Oracle E-Business Suite 11.5.1 through 11.5.8 allow remote attackers to execute arbitrary SQL procedures and queries.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" admin="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA04-160A.html" source="CERT" patch="1" adv="1">TA04-160A</ref>
      <ref url="http://www.kb.cert.org/vuls/id/961579" source="CERT-VN" patch="1" adv="1">VU#961579</ref>
      <ref url="http://www.securityfocus.com/bid/10465" source="BID" patch="1" adv="1">10465</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/16324" source="XF" adv="1">oracle-ebusiness-sql-injection(16324)</ref>
      <ref url="http://www.integrigy.com/alerts/OraAppsSQLInjection.htm" source="MISC">http://www.integrigy.com/alerts/OraAppsSQLInjection.htm</ref>
      <ref url="http://otn.oracle.com/deploy/security/pdf/2004alert67.pdf" source="CONFIRM">http://otn.oracle.com/deploy/security/pdf/2004alert67.pdf</ref>
      <ref url="http://www.ciac.org/ciac/bulletins/o-153.shtml" source="CIAC">O-153</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108638417302229&amp;w=2" source="BUGTRAQ">20040604 Integrigy Security Alert - Multiple SQL Injection Vulnerabilities in Oracle E-Business Suite</ref>
      <ref url="http://archives.neohapsis.com/archives/vulnwatch/2004-q2/0032.html" source="VULNWATCH">20040604 Integrigy Security Alert - Multiple SQL Injection Vulnerabilities in Oracle E-Business Suite</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="applications">
        <vers num="11.0" />
      </prod>
      <prod vendor="oracle" name="e-business_suite">
        <vers num="11.5.1" />
        <vers num="11.5.2" />
        <vers num="11.5.3" />
        <vers num="11.5.4" />
        <vers num="11.5.5" />
        <vers num="11.5.6" />
        <vers num="11.5.7" />
        <vers num="11.5.8" />
        <vers num="11i" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0544" published="2004-08-06" name="CVE-2004-0544" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Multiple buffer overflows in LVM for AIX 5.1 and 5.2 allow local users to gain privileges via the (1) putlvcb or (2) getlvcb commands.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/9905" source="BID" patch="1" adv="1">9905</ref>
      <ref url="http://www.ciac.org/ciac/bulletins/o-131.shtml" source="CIAC" patch="1" adv="1">O-131</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15555" source="XF" adv="1">aix-putlvcb-bo(15555)</ref>
      <ref url="http://www-1.ibm.com/support/docview.wss?uid=isg1IY55682" source="AIXAPAR">IY55682</ref>
      <ref url="http://www-1.ibm.com/support/docview.wss?uid=isg1IY55681" source="AIXAPAR">IY55681</ref>
      <ref url="http://www-1.ibm.com/services/continuity/recover1.nsf/mss/MSS-OAR-E01-2004.0544.2" source="IBM">MSS-OAR-E01-2004.0544</ref>
      <ref url="http://secunia.com/advisories/11158/" source="SECUNIA">11158</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/18317" source="XF">aix-getlvcb-bo(18317)</ref>
      <ref url="http://www.securityfocus.com/bid/9906" source="BID">9906</ref>
      <ref url="http://www.osvdb.org/4393" source="OSVDB">4393</ref>
      <ref url="http://www.osvdb.org/4392" source="OSVDB">4392</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="aix">
        <vers num="4.3.3" />
        <vers num="5.1" />
        <vers num="5.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0545" published="2004-08-06" name="CVE-2004-0545" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">LVM for AIX 5.1 and 5.2 allows local users to overwrite arbitrary files via a symlink attack.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" admin="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/10230" source="BID" patch="1" adv="1">10230</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/16011" source="XF" adv="1">aix-lvm-commands-symlink(16011)</ref>
      <ref url="http://www.ciac.org/ciac/bulletins/o-131.shtml" source="CIAC">O-131</ref>
      <ref url="http://www-1.ibm.com/services/continuity/recover1.nsf/mss/MSS-OAR-E01-2004.0544.2" source="IBM">MSS-OAR-E01-2004.0544</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="aix">
        <vers num="5.1" />
        <vers num="5.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0547" published="2004-08-06" name="CVE-2004-0547" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Buffer overflow in the ODBC driver for PostgreSQL before 7.2.1 allows remote attackers to cause a denial of service (crash).</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.debian.org/security/2004/dsa-516" source="DEBIAN" patch="1" adv="1">DSA-516</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/16329" source="XF" adv="1">postgresql-odbc-bo(16329)</ref>
      <ref url="http://www.mandrakesecure.net/en/advisories/advisory.php?name=MDKSA-2004:072" source="MANDRAKE">MDKSA-2004:072</ref>
    </refs>
    <vuln_soft>
      <prod vendor="postgresql" name="postgresql">
        <vers num="7.2.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0548" published="2004-08-06" name="CVE-2004-0548" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Multiple stack-based buffer overflows in the word-list-compress functionality in compress.c for Aspell allow local users to execute arbitrary code via a long entry in the wordlist that is not properly handled when using the (1) "c" compress option or (2) "d" decompress option.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108675120224531&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20040608 Aspell 'word-list-compress' stack overflow vulnerability</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200406-14.xml" source="GENTOO" adv="1">GLSA-200406-14</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gnu" name="aspell">
        <vers num="0.50.5" />
      </prod>
      <prod vendor="gentoo" name="linux">
        <vers num="1.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0549" published="2004-08-06" name="CVE-2004-0549" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">The WebBrowser ActiveX control, or the Internet Explorer HTML rendering engine (MSHTML), as used in Internet Explorer 6, allows remote attackers to execute arbitrary code in the Local Security context by using the showModalDialog method and modifying the location to execute code such as Javascript, as demonstrated using (1) delayed HTTP redirect operations, and an HTTP response with a Location: header containing a "URL:" prepended to a "ms-its" protocol URI, or (2) modifying the location attribute of the window, as exploited by the Download.ject (aka Scob aka Toofer) using the ADODB.Stream object.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" admin="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA04-163A.html" source="CERT" patch="1" adv="1">TA04-163A</ref>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA04-212A.html" source="CERT">TA04-212A</ref>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA04-184A.html" source="CERT">TA04-184A</ref>
      <ref url="http://www.kb.cert.org/vuls/id/713878" source="CERT-VN">VU#713878</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms04-025.mspx" source="MS">MS04-025</ref>
      <ref url="http://umbrella.name/originalvuln/msie/InsiderPrototype/" source="MISC">http://umbrella.name/originalvuln/msie/InsiderPrototype/</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108852642021426&amp;w=2" source="BUGTRAQ">20040628 JS.Scob.Trojan Source Code ...</ref>
      <ref url="http://archives.neohapsis.com/archives/fulldisclosure/2004-06/0104.html" source="FULLDISC">20040606 Internet explorer 6 execution of arbitrary code (An analysis of the 180 Solutions Trojan)</ref>
      <ref url="http://archives.neohapsis.com/archives/fulldisclosure/2004-06/0031.html" source="FULLDISC">20040602 180 Solutions Exploits and Toolbars Hacking Patched Users(I.E Exploits)</ref>
      <ref url="http://62.131.86.111/analysis.htm" source="MISC">http://62.131.86.111/analysis.htm</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/16348" source="XF">ie-location-restriction-bypass(16348)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108786396622284&amp;w=2" source="BUGTRAQ">20040621 IE/0DAY -> Insider Prototype</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:519" source="OVAL" sig="1">oval:org.mitre.oval:def:519</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:241" source="OVAL" sig="1">oval:org.mitre.oval:def:241</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:207" source="OVAL" sig="1">oval:org.mitre.oval:def:207</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1133" source="OVAL" sig="1">oval:org.mitre.oval:def:1133</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="ie">
        <vers num="5.01" />
        <vers num="5.5" />
        <vers num="6.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0550" published="2004-08-06" name="CVE-2004-0550" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in Real Networks RealPlayer 10 allows remote attackers to execute arbitrary code via a URL with a large number of "." (period) characters.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/16388" source="XF" adv="1">realplayer-dot-file-bo(16388)</ref>
      <ref url="http://www.idefense.com/application/poi/display?id=109&amp;type=vulnerabilities&amp;flashstatus=false" source="MISC" adv="1">http://www.idefense.com/application/poi/display?id=109&amp;type=vulnerabilities&amp;flashstatus=false</ref>
    </refs>
    <vuln_soft>
      <prod vendor="realnetworks" name="realplayer">
        <vers num="10.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0551" published="2004-08-06" name="CVE-2004-0551" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Cisco CatOS 5.x before 5.5(20) through 8.x before 8.2(2) and 8.3(2)GLX, as used in Catalyst switches, allows remote attackers to cause a denial of service (system crash and reload) by sending invalid packets instead of the final ACK portion of the three-way handshake to the (1) Telnet, (2) HTTP, or (3) SSH services, aka "TCP-ACK DoS attack."</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/245190" source="CERT-VN" adv="1">VU#245190</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/16370" source="XF" adv="1">cisco-catalyst-ack-dos(16370)</ref>
      <ref url="http://www.cisco.com/warp/public/707/cisco-sa-20040609-catos.shtml" source="CISCO">20040609 Cisco CatOS Telnet, HTTP and SSH Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="catalyst_2901">
        <vers num="" />
      </prod>
      <prod vendor="cisco" name="catalyst_2902">
        <vers num="" />
      </prod>
      <prod vendor="cisco" name="catalyst_2926">
        <vers num="" />
      </prod>
      <prod vendor="cisco" name="catalyst_2926f">
        <vers num="" />
      </prod>
      <prod vendor="cisco" name="catalyst_2926gl">
        <vers num="" />
      </prod>
      <prod vendor="cisco" name="catalyst_2926gs">
        <vers num="" />
      </prod>
      <prod vendor="cisco" name="catalyst_2926t">
        <vers num="" />
      </prod>
      <prod vendor="cisco" name="catalyst_2948">
        <vers num="" />
      </prod>
      <prod vendor="cisco" name="catalyst_2948-ge-tx">
        <vers num="" />
      </prod>
      <prod vendor="cisco" name="catalyst_2948g-l3">
        <vers num="" />
      </prod>
      <prod vendor="cisco" name="catalyst_2980g">
        <vers num="" />
      </prod>
      <prod vendor="cisco" name="catalyst_2980g-a">
        <vers num="" />
      </prod>
      <prod vendor="cisco" name="catalyst_4000">
        <vers num="" />
      </prod>
      <prod vendor="cisco" name="catalyst_4500">
        <vers num="" />
      </prod>
      <prod vendor="cisco" name="catalyst_4503">
        <vers num="" />
      </prod>
      <prod vendor="cisco" name="catalyst_4506">
        <vers num="" />
      </prod>
      <prod vendor="cisco" name="catalyst_4507r">
        <vers num="" />
      </prod>
      <prod vendor="cisco" name="catalyst_4510r">
        <vers num="" />
      </prod>
      <prod vendor="cisco" name="catalyst_4912g">
        <vers num="" />
      </prod>
      <prod vendor="cisco" name="catalyst_5000">
        <vers num="" />
      </prod>
      <prod vendor="cisco" name="catalyst_6000_ws-svc-nam-1">
        <vers num="2.2(1a)" />
        <vers num="3.1(1a)" />
      </prod>
      <prod vendor="cisco" name="catalyst_6000_ws-svc-nam-2">
        <vers num="2.2(1a)" />
        <vers num="3.1(1a)" />
      </prod>
      <prod vendor="cisco" name="catalyst_6000_ws-x6380-nam">
        <vers num="2.1(2)" />
        <vers num="3.1(1a)" />
      </prod>
      <prod vendor="cisco" name="catos">
        <vers num="2.1(1)" />
        <vers num="2.1(10)" />
        <vers num="2.1(11)" />
        <vers num="2.1(12)" />
        <vers num="2.1(2)" />
        <vers num="2.1(3)" />
        <vers num="2.1(4)" />
        <vers num="2.1(5)" />
        <vers num="2.1(6)" />
        <vers num="2.1(7)" />
        <vers num="2.1(8)" />
        <vers num="2.1(9)" />
        <vers num="2.2(1)" />
        <vers num="2.2(2)" />
        <vers num="2.3(1)" />
        <vers num="2.4(1)" />
        <vers num="2.4(2)" />
        <vers num="2.4(3)" />
        <vers num="2.4(4)" />
        <vers num="2.4(5)" />
        <vers num="2.4(5a)" />
        <vers num="3.0(7)" />
        <vers num="3.1(1)" />
        <vers num="3.1(2)" />
        <vers num="3.1(2a)" />
        <vers num="3.2(1)" />
        <vers num="3.2(1b)" />
        <vers num="3.2(2)" />
        <vers num="3.2(3)" />
        <vers num="3.2(4)" />
        <vers num="3.2(5)" />
        <vers num="3.2(6)" />
        <vers num="3.2(7)" />
        <vers num="3.2(8)gdr" />
        <vers num="4.1(1)" />
        <vers num="4.1(2)" />
        <vers num="4.1(3)" />
        <vers num="4.2(1)" />
        <vers num="4.2(2)" />
        <vers num="4.3(1a)" />
        <vers num="4.4(1)" />
        <vers num="4.5(1)" />
        <vers num="4.5(10)" />
        <vers num="4.5(11)" />
        <vers num="4.5(12)" />
        <vers num="4.5(12a)" />
        <vers num="4.5(13)" />
        <vers num="4.5(13a)" />
        <vers num="4.5(14)" />
        <vers num="4.5(2)" />
        <vers num="4.5(3)" />
        <vers num="4.5(4)" />
        <vers num="4.5(4b)" />
        <vers num="4.5(5)" />
        <vers num="4.5(6)" />
        <vers num="4.5(6a)" />
        <vers num="4.5(7)" />
        <vers num="4.5(8)" />
        <vers num="4.5(9)" />
        <vers num="4.5.10" />
        <vers num="5.1" />
        <vers num="5.1(1)" />
        <vers num="5.1(1)csx" />
        <vers num="5.1(1a)" />
        <vers num="5.1(1a)csx" />
        <vers num="5.1(2a)" />
        <vers num="5.1(2b)" />
        <vers num="5.2" />
        <vers num="5.2(1)" />
        <vers num="5.2(1)csx" />
        <vers num="5.2(1a)" />
        <vers num="5.2(2)" />
        <vers num="5.2(2)csx" />
        <vers num="5.2(3)" />
        <vers num="5.2(3)csx" />
        <vers num="5.2(3a)csx" />
        <vers num="5.2(4)" />
        <vers num="5.2(5)" />
        <vers num="5.2(6)" />
        <vers num="5.2(7)" />
        <vers num="5.2(7a)" />
        <vers num="5.3(1)csx" />
        <vers num="5.3(1a)csx" />
        <vers num="5.3(2)csx" />
        <vers num="5.3(3)csx" />
        <vers num="5.3(4)csx" />
        <vers num="5.3(5)csx" />
        <vers num="5.3(5a)csx" />
        <vers num="5.3(6)csx" />
        <vers num="5.3(6a)csx" />
        <vers num="5.4" />
        <vers num="5.4(1)" />
        <vers num="5.4(1)deferred" />
        <vers num="5.4(2)" />
        <vers num="5.4(2a)" />
        <vers num="5.4(3)" />
        <vers num="5.4(4)" />
        <vers num="5.4(4a)" />
        <vers num="5.5" />
        <vers num="5.5(1)" />
        <vers num="5.5(10)" />
        <vers num="5.5(10a)" />
        <vers num="5.5(11)" />
        <vers num="5.5(11a)" />
        <vers num="5.5(12)" />
        <vers num="5.5(12a)" />
        <vers num="5.5(13)" />
        <vers num="5.5(13.5)" />
        <vers num="5.5(13a)" />
        <vers num="5.5(14)" />
        <vers num="5.5(15)" />
        <vers num="5.5(16)" />
        <vers num="5.5(16.2)" />
        <vers num="5.5(17)" />
        <vers num="5.5(18)" />
        <vers num="5.5(19)" />
        <vers num="5.5(1a)" />
        <vers num="5.5(2)" />
        <vers num="5.5(3)" />
        <vers num="5.5(4)" />
        <vers num="5.5(4a)" />
        <vers num="5.5(4b)" />
        <vers num="5.5(5)" />
        <vers num="5.5(6)" />
        <vers num="5.5(6a)" />
        <vers num="5.5(7)" />
        <vers num="5.5(7a)" />
        <vers num="5.5(8)" />
        <vers num="5.5(8a)" />
        <vers num="5.5(8a)cv" />
        <vers num="5.5(9)" />
        <vers num="6.1" />
        <vers num="6.1(1)" />
        <vers num="6.1(1a)" />
        <vers num="6.1(1b)" />
        <vers num="6.1(1c)" />
        <vers num="6.1(1d)" />
        <vers num="6.1(1e)" />
        <vers num="6.1(2)" />
        <vers num="6.1(2.13)" />
        <vers num="6.1(2a)" />
        <vers num="6.1(3)" />
        <vers num="6.1(3a)" />
        <vers num="6.1(4)" />
        <vers num="6.1(4b)" />
        <vers num="6.2(0.110)" />
        <vers num="6.2(0.111)" />
        <vers num="6.2(1)" />
        <vers num="6.2(1a)" />
        <vers num="6.2(2)" />
        <vers num="6.2(2a)" />
        <vers num="6.2(3)" />
        <vers num="6.2(3a)" />
        <vers num="6.3(0.7)pan" />
        <vers num="6.3(1)" />
        <vers num="6.3(10)" />
        <vers num="6.3(1a)" />
        <vers num="6.3(2)" />
        <vers num="6.3(2a)" />
        <vers num="6.3(3)" />
        <vers num="6.3(3)x" />
        <vers num="6.3(3)x1" />
        <vers num="6.3(3a)" />
        <vers num="6.3(4)" />
        <vers num="6.3(4a)" />
        <vers num="6.3(5)" />
        <vers num="6.3(5.10)" />
        <vers num="6.3(6)" />
        <vers num="6.3(7)" />
        <vers num="6.3(8)" />
        <vers num="6.3(8.3)" />
        <vers num="6.3(9)" />
        <vers num="6.4(1)" />
        <vers num="6.4(2)" />
        <vers num="6.4(3)" />
        <vers num="6.4(4a)" />
        <vers num="6.4(5)" />
        <vers num="6.4(6)" />
        <vers num="6.4(7)" />
        <vers num="6.4(8)" />
        <vers num="7.1" />
        <vers num="7.1(1)" />
        <vers num="7.1(1a)" />
        <vers num="7.1(2)" />
        <vers num="7.1(2a)" />
        <vers num="7.2(0.65)" />
        <vers num="7.2(1)" />
        <vers num="7.2(2)" />
        <vers num="7.3" />
        <vers num="7.3(1)" />
        <vers num="7.3(2)" />
        <vers num="7.4" />
        <vers num="7.4(0.2)clr" />
        <vers num="7.4(0.63)" />
        <vers num="7.4(1)" />
        <vers num="7.4(2)" />
        <vers num="7.4(3)" />
        <vers num="7.5" />
        <vers num="7.5(1)" />
        <vers num="7.6" />
        <vers num="7.6(1)" />
        <vers num="7.6(2)" />
        <vers num="7.6(3)" />
        <vers num="7.6(4)" />
        <vers num="7.6(5)" />
        <vers num="8.1" />
        <vers num="8.1(2)" />
        <vers num="8.1(3)" />
        <vers num="8.2" />
        <vers num="8.2(1)" />
        <vers num="8.3(1)glx" />
        <vers num="8.3glx" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0552" published="2004-11-03" name="CVE-2004-0552" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Sophos Small Business Suite 1.00 on Windows does not properly handle files whose names contain reserved MS-DOS device names such as (1) LPT1, (2) COM1, (3) AUX, (4) CON, or (5) PRN, which can allow malicious code to bypass detection when it is installed, copied, or executed.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/17468" source="XF" patch="1" adv="1">sophos-business-security-bypass(17468)</ref>
      <ref url="http://www.seifried.org/security/advisories/kssa-005.html" source="MISC" patch="1" adv="1">http://www.seifried.org/security/advisories/kssa-005.html</ref>
      <ref url="http://www.idefense.com/application/poi/display?id=143&amp;type=vulnerabilities" source="IDEFENSE">20040922 Sophos Small Business Suite Reserved Device Name Handling Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sophos" name="small_business_suite">
        <vers prev="1" num="1.00" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2004-0554" published="2004-08-06" name="CVE-2004-0554" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">Linux kernel 2.4.x and 2.6.x for x86 allows local users to cause a denial of service (system crash), possibly via an infinite loop that triggers a signal handler with a certain sequence of fsave and frstor instructions, as originally demonstrated using a "crash.c" program.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/973654" source="CERT-VN" adv="1">VU#973654</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/16412" source="XF" adv="1">linux-dos(16412)</ref>
      <ref url="http://www.trustix.net/errata/2004/0034/" source="TRUSTIX">2004-0034</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-260.html" source="REDHAT">RHSA-2004:260</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-255.html" source="REDHAT">RHSA-2004:255</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2004_17_kernel.html" source="SUSE">SuSE-SA:2004:017</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200407-02.xml" source="GENTOO">GLSA-200407-02</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9426" source="OVAL">oval:org.mitre.oval:def:9426</ref>
      <ref url="http://marc.theaimsgroup.com/?l=linux-kernel&amp;m=108681568931323&amp;w=2" source="MLIST">[linux-kernel] 20040609 timer + fpu stuff locks my console race</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108793699910896&amp;w=2" source="ENGARDE">ESA-20040621-005</ref>
      <ref url="http://lwn.net/Articles/91155/" source="FEDORA">FEDORA-2004-186</ref>
      <ref url="http://linuxreviews.org/news/2004-06-11_kernel_crash/index.html" source="MISC">http://linuxreviews.org/news/2004-06-11_kernel_crash/index.html</ref>
      <ref url="http://gcc.gnu.org/bugzilla/show_bug.cgi?id=15905" source="MISC">http://gcc.gnu.org/bugzilla/show_bug.cgi?id=15905</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000845" source="CONECTIVA">CLA-2004:845</ref>
      <ref url="http://www.securityfocus.com/bid/10538" source="BID">10538</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2004:062" source="MANDRAKE">MDKSA-2004:062</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1082" source="DEBIAN">DSA-1082</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1070" source="DEBIAN">DSA-1070</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1069" source="DEBIAN">DSA-1069</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1067" source="DEBIAN">DSA-1067</ref>
      <ref url="http://secunia.com/advisories/20338" source="SECUNIA">20338</ref>
      <ref url="http://secunia.com/advisories/20202" source="SECUNIA">20202</ref>
      <ref url="http://secunia.com/advisories/20163" source="SECUNIA">20163</ref>
      <ref url="http://secunia.com/advisories/20162" source="SECUNIA">20162</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108786114032681&amp;w=2" source="BUGTRAQ">20040620 TSSA-2004-011 - kernel</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2915" source="OVAL" sig="1">oval:org.mitre.oval:def:2915</ref>
    </refs>
    <vuln_soft>
      <prod vendor="avaya" name="intuity_audix">
        <vers num="" edition=":lx" />
      </prod>
      <prod vendor="suse" name="suse_email_server">
        <vers num="3.1" />
        <vers num="iii" />
      </prod>
      <prod vendor="suse" name="suse_linux_admin-cd_for_firewall">
        <vers num="" />
      </prod>
      <prod vendor="suse" name="suse_linux_connectivity_server">
        <vers num="" />
      </prod>
      <prod vendor="suse" name="suse_linux_database_server">
        <vers num="" />
      </prod>
      <prod vendor="suse" name="suse_linux_firewall_cd">
        <vers num="" />
      </prod>
      <prod vendor="suse" name="suse_linux_office_server">
        <vers num="" />
      </prod>
      <prod vendor="suse" name="suse_office_server">
        <vers num="" />
      </prod>
      <prod vendor="avaya" name="converged_communications_server">
        <vers num="2.0" />
      </prod>
      <prod vendor="avaya" name="s8300">
        <vers num="r2.0.0" />
        <vers num="r2.0.1" />
      </prod>
      <prod vendor="avaya" name="s8500">
        <vers num="r2.0.0" />
        <vers num="r2.0.1" />
      </prod>
      <prod vendor="avaya" name="s8700">
        <vers num="r2.0.0" />
        <vers num="r2.0.1" />
      </prod>
      <prod vendor="avaya" name="modular_messaging_message_storage_server">
        <vers num="s3400" />
      </prod>
      <prod vendor="conectiva" name="linux">
        <vers num="8.0" />
        <vers num="9.0" />
      </prod>
      <prod vendor="gentoo" name="linux">
        <vers num="1.4" />
      </prod>
      <prod vendor="linux" name="linux_kernel">
        <vers num="2.4.18" />
        <vers num="2.4.19" />
        <vers num="2.4.21" />
        <vers num="2.4.22" />
        <vers num="2.4.23" />
        <vers num="2.4.24" />
        <vers num="2.4.25" />
        <vers num="2.4.26" />
        <vers num="2.6.0" />
        <vers num="2.6.1" edition="rc1" />
        <vers num="2.6.1" edition="rc2" />
        <vers num="2.6.2" />
        <vers num="2.6.3" />
        <vers num="2.6.4" />
        <vers num="2.6.5" />
        <vers num="2.6.6" edition="rc1" />
        <vers num="2.6.7" edition="rc1" />
      </prod>
      <prod vendor="redhat" name="enterprise_linux">
        <vers num="2.1" edition="" />
        <vers num="2.1" edition=":advanced_server" />
        <vers num="2.1" edition=":enterprise_server" />
        <vers num="2.1" edition=":workstation" />
        <vers num="3.0" edition="" />
        <vers num="3.0" edition=":enterprise_server" />
        <vers num="3.0" edition=":workstation" />
        <vers num="3.0" edition=":advanced_servers" />
      </prod>
      <prod vendor="suse" name="suse_linux">
        <vers num="7" edition="" />
        <vers num="7" edition=":enterprise_server" />
        <vers num="8" edition="" />
        <vers num="8" edition=":enterprise_server" />
        <vers num="8.0" edition="" />
        <vers num="8.0" edition=":i386" />
        <vers num="8.1" />
        <vers num="8.2" />
        <vers num="9.0" edition="" />
        <vers num="9.0" edition=":x86_64" />
        <vers num="9.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0555" published="2004-12-31" name="CVE-2004-0555" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in (1) queue.c and (2) queued.c in queue before 1.30.1 may allow remote attackers to execute arbitrary code.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/18945" source="XF" patch="1">queue-bo(18945)</ref>
      <ref url="http://www.debian.org/security/2005/dsa-643" source="DEBIAN" patch="1" adv="1">DSA-643</ref>
      <ref url="http://securitytracker.com/id?1012929" source="SECTRACK">1012929</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gnu" name="queue">
        <vers num="1.12.7" />
        <vers num="1.12.8" />
        <vers num="1.12.9" />
        <vers num="1.20.0" />
        <vers num="1.20.1" />
        <vers num="1.20.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0557" published="2004-08-06" name="CVE-2004-0557" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Multiple buffer overflows in the st_wavstartread function in wav.c for Sound eXchange (SoX) 12.17.2 through 12.17.4 allow remote attackers to execute arbitrary code via certain WAV file header fields.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/10819" source="BID" patch="1" adv="1">10819</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-409.html" source="REDHAT" patch="1" adv="1">RHSA-2004:409</ref>
      <ref url="https://bugzilla.fedora.us/show_bug.cgi?id=1945" source="FEDORA">FLSA:1945</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/16827" source="XF" adv="1">sox-wav-bo(16827)</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200407-23.xml" source="GENTOO" adv="1">GLSA-200407-23</ref>
      <ref url="http://www.debian.org/security/2004/dsa-565" source="DEBIAN">DSA-565</ref>
      <ref url="http://secunia.com/advisories/12175" source="SECUNIA">12175</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9801" source="OVAL">oval:org.mitre.oval:def:9801</ref>
      <ref url="http://lwn.net/Articles/95530/" source="FEDORA">FEDORA-2004-244</ref>
      <ref url="http://lwn.net/Articles/95529/" source="FEDORA">FEDORA-2004-235</ref>
      <ref url="http://archives.neohapsis.com/archives/vulnwatch/2004-q3/0014.html" source="VULNWATCH">20040728 SoX buffer overflows when handling .WAV files</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2004:076" source="MANDRAKE">MDKSA-2004:076</ref>
      <ref url="http://seclists.org/fulldisclosure/2004/Jul/1227.html" source="FULLDISC">20040728 SoX buffer overflows when handling .WAV files</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000855" source="CONECTIVA">CLA-2004:855</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sox" name="sox">
        <vers num="12.17.2" />
        <vers num="12.17.3" />
        <vers num="12.17.4" />
      </prod>
      <prod vendor="conectiva" name="linux">
        <vers num="10.0" />
        <vers num="8.0" />
        <vers num="9.0" />
      </prod>
      <prod vendor="gentoo" name="linux">
        <vers num="1.4" />
      </prod>
      <prod vendor="redhat" name="enterprise_linux">
        <vers num="3.0" edition="" />
        <vers num="3.0" edition=":workstation" />
        <vers num="3.0" edition=":advanced_servers" />
        <vers num="3.0" edition=":enterprise_server" />
      </prod>
      <prod vendor="redhat" name="enterprise_linux_desktop">
        <vers num="3.0" />
      </prod>
      <prod vendor="redhat" name="fedora_core">
        <vers num="core_1.0" />
        <vers num="core_2.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0558" published="2004-09-28" name="CVE-2004-0558" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The Internet Printing Protocol (IPP) implementation in CUPS before 1.1.21 allows remote attackers to cause a denial of service (service hang) via a certain UDP packet to the IPP port.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="https://bugzilla.fedora.us/show_bug.cgi?id=2072" source="FEDORA" patch="1">FLSA:2072</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/17389" source="XF" patch="1">cups-udp-dos(17389)</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-449.html" source="REDHAT" patch="1" adv="1">RHSA-2004:449</ref>
      <ref url="http://www.debian.org/security/2004/dsa-545" source="DEBIAN" patch="1" adv="1">DSA-545</ref>
      <ref url="http://www.trustix.org/errata/2004/0047/" source="TRUSTIX" adv="1">2004-0047</ref>
      <ref url="http://www.suse.com/de/security/2004_31_cups.html" source="SUSE">SUSE-SA:2004:031</ref>
      <ref url="http://www.securityfocus.com/bid/11183" source="BID">11183</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-77-1000757.1-1" source="SUNALERT">1000757</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-66-201005-1" source="SUNALERT">201005</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-57646-1" source="SUNALERT">57646</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11732" source="OVAL">oval:org.mitre.oval:def:11732</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109760654431316&amp;w=2" source="SCO">SCOSA-2004.15</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2004/Oct/msg00000.html" source="APPLE">APPLE-SA-2004-09-30</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000872" source="CONECTIVA">CLA-2004:872</ref>
    </refs>
    <vuln_soft>
      <prod vendor="easy_software_products" name="cups">
        <vers prev="1" num="1.1.21" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2004-0559" published="2004-10-20" name="CVE-2004-0559" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">The maketemp.pl script in Usermin 1.070 and 1.080 allows local users to overwrite arbitrary files at install time via a symlink attack on the /tmp/.usermin directory.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/17299" source="XF" patch="1" adv="1">usermin-installation-unspecified(17299)</ref>
      <ref url="http://www.securityfocus.com/bid/11153" source="BID" patch="1" adv="1">11153</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200409-15.xml" source="GENTOO" patch="1" adv="1">GLSA-200409-15</ref>
      <ref url="http://secunia.com/advisories/12488/" source="SECUNIA" patch="1" adv="1">12488</ref>
      <ref url="http://www.webmin.com/uchanges-1.089.html" source="CONFIRM">http://www.webmin.com/uchanges-1.089.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="usermin" name="usermin">
        <vers num="1.000" />
        <vers num="1.010" />
        <vers num="1.020" />
        <vers num="1.030" />
        <vers num="1.040" />
        <vers num="1.051" />
        <vers num="1.060" />
        <vers num="1.070" />
        <vers num="1.080" />
      </prod>
      <prod vendor="webmin" name="webmin">
        <vers num="1.0.00" />
        <vers num="1.0.20" />
        <vers num="1.0.50" />
        <vers num="1.0.60" />
        <vers num="1.0.70" />
        <vers num="1.0.80" />
        <vers num="1.0.90" />
        <vers num="1.1.00" />
        <vers num="1.1.10" />
        <vers num="1.1.21" />
        <vers num="1.1.30" />
        <vers num="1.1.40" />
        <vers num="1.1.50" />
      </prod>
      <prod vendor="mandrakesoft" name="mandrake_linux">
        <vers num="10.0" edition="" />
        <vers num="10.0" edition=":amd64" />
        <vers num="9.2" edition="" />
        <vers num="9.2" edition=":amd64" />
      </prod>
      <prod vendor="mandrakesoft" name="mandrake_linux_corporate_server">
        <vers num="2.1" edition="" />
        <vers num="2.1" edition=":x86_64" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0560" published="2004-12-31" name="CVE-2004-0560" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Integer overflow in gopher daemon (gopherd) 3.0.3 allows remote attackers to cause a denial of service and possibly execute arbitrary code via crafted content of a certain size that triggers the overflow.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.debian.org/security/2004/dsa-638" source="DEBIAN">DSA-638</ref>
      <ref url="http://secunia.com/advisories/13855" source="SECUNIA">13855</ref>
    </refs>
    <vuln_soft>
      <prod vendor="university_of_minnesota" name="gopherd">
        <vers num="3.0.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0561" published="2004-12-31" name="CVE-2004-0561" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Format string vulnerability in the log routine for gopher daemon (gopherd) 3.0.3 allows remote attackers to cause a denial of service and possibly execute arbitrary code.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.debian.org/security/2004/dsa-638" source="DEBIAN">DSA-638</ref>
      <ref url="http://secunia.com/advisories/13855" source="SECUNIA">13855</ref>
    </refs>
    <vuln_soft>
      <prod vendor="university_of_minnesota" name="gopherd">
        <vers num="3.0.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2004-0563" published="2004-12-23" name="CVE-2004-0563" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">The tspc.conf configuration file in freenet6 before 0.9.6 and before 1.0 on Debian Linux has world readable permissions, which could allow local users to gain sensitive information, such as a username and password.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <config />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/17544" source="XF" patch="1" adv="1">freenet6-world-readable(17544)</ref>
      <ref url="http://www.securityfocus.com/bid/11280" source="BID" patch="1" adv="1">11280</ref>
      <ref url="http://www.debian.org/security/2004/dsa-555" source="DEBIAN" patch="1" adv="1">DSA-555</ref>
      <ref url="http://securitytracker.com/id?1011460" source="SECTRACK">1011460</ref>
      <ref url="http://secunia.com/advisories/12705/" source="SECUNIA">12705</ref>
    </refs>
    <vuln_soft>
      <prod vendor="freenet6" name="freenet6">
        <vers num="0.9.6" />
        <vers num="1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2004-0564" published="2004-12-23" name="CVE-2004-0564" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">Roaring Penguin pppoe (rp-ppoe), if installed or configured to run setuid root contrary to its design, allows local users to overwrite arbitrary files.  NOTE: the developer has publicly disputed the claim that this is a vulnerability because pppoe "is NOT designed to run setuid-root."  Therefore this identifier applies *only* to those configurations and installations under which pppoe is run setuid root despite the developer's warnings.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <design />
      <config />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/17576" source="XF" patch="1" adv="1">pppoe-file-overwrite(17576)</ref>
      <ref url="http://www.securityfocus.com/bid/11315" source="BID" patch="1" adv="1">11315</ref>
      <ref url="http://www.debian.org/security/2004/dsa-557" source="DEBIAN" patch="1" adv="1">DSA-557</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110247119200510&amp;w=2" source="MANDRAKE" patch="1" adv="1">MDKSA-2004:145</ref>
      <ref url="http://www.fedoralegacy.org/updates/FC1/2005-11-14-FLSA_2005_152794__Updated_rp_pppoe_package_fixes_security_issue.html" source="FEDORA">FLSA:152794</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110253341209450&amp;w=2" source="BUGTRAQ">20041208 Re: MDKSA-2004:145 - Updated rp-pppoe packages fix vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="roaring_penguin" name="pppoe">
        <vers num="3.0" />
        <vers num="3.3" />
        <vers num="3.5" />
      </prod>
      <prod vendor="debian" name="debian_linux">
        <vers num="3.0" edition="" />
        <vers num="3.0" edition=":hppa" />
        <vers num="3.0" edition=":mips" />
        <vers num="3.0" edition=":ia-32" />
        <vers num="3.0" edition=":m68k" />
        <vers num="3.0" edition=":s-390" />
        <vers num="3.0" edition=":alpha" />
        <vers num="3.0" edition=":arm" />
        <vers num="3.0" edition=":ia-64" />
        <vers num="3.0" edition=":mipsel" />
        <vers num="3.0" edition=":sparc" />
        <vers num="3.0" edition=":ppc" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2004-0565" published="2004-12-06" name="CVE-2004-0565" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">Floating point information leak in the context switch code for Linux 2.4.x only checks the MFH bit but does not verify the FPH owner, which allows local users to read register values of other processes by setting the MFH bit.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <access />
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/16644" source="XF" patch="1" adv="1">linux-ia64-info-disclosure(16644)</ref>
      <ref url="https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=124734" source="MISC" adv="1">https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=124734</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10714" source="OVAL">oval:org.mitre.oval:def:10714</ref>
      <ref url="http://archives.neohapsis.com/archives/linux/owl/2004-q2/0038.html" source="MLIST" adv="1">[owl-users] 20040619 Linux 2.4.26-ow2</ref>
      <ref url="http://www.securityfocus.com/bid/10687" source="BID">10687</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-504.html" source="REDHAT">RHSA-2004:504</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2004:066" source="MANDRAKE">MDKSA-2004:066</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1082" source="DEBIAN">DSA-1082</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1070" source="DEBIAN">DSA-1070</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1069" source="DEBIAN">DSA-1069</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1067" source="DEBIAN">DSA-1067</ref>
      <ref url="http://secunia.com/advisories/20338" source="SECUNIA">20338</ref>
      <ref url="http://secunia.com/advisories/20202" source="SECUNIA">20202</ref>
      <ref url="http://secunia.com/advisories/20163" source="SECUNIA">20163</ref>
      <ref url="http://secunia.com/advisories/20162" source="SECUNIA">20162</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mandrakesoft" name="mandrake_multi_network_firewall">
        <vers num="8.2" />
      </prod>
      <prod vendor="gentoo" name="linux">
        <vers num="" />
      </prod>
      <prod vendor="linux" name="linux_kernel">
        <vers num="2.4.0" />
      </prod>
      <prod vendor="mandrakesoft" name="mandrake_linux">
        <vers num="10.0" />
        <vers num="9.1" />
        <vers num="9.2" />
      </prod>
      <prod vendor="mandrakesoft" name="mandrake_linux_corporate_server">
        <vers num="2.1" />
      </prod>
      <prod vendor="trustix" name="secure_linux">
        <vers num="2" />
        <vers num="2.0" />
        <vers num="2.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0566" published="2004-07-27" name="CVE-2004-0566" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Integer overflow in imgbmp.cxx for Windows 2000 allows remote attackers to execute arbitrary code via a BMP image with a large bfOffBits value.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA04-212A.html" source="CERT" adv="1">TA04-212A</ref>
      <ref url="http://www.kb.cert.org/vuls/id/266926" source="CERT-VN">VU#266926</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15210" source="XF" adv="1">ie-bmp-integer-overflow(15210)</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms04-025.mspx" source="MS">MS04-025</ref>
      <ref url="http://archives.neohapsis.com/archives/fulldisclosure/2004-02/0806.html" source="FULLDISC" adv="1">20040215 GAYER THAN AIDS ADVISORY #01: IE 5 remote code execution</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:515" source="OVAL" sig="1">oval:org.mitre.oval:def:515</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:507" source="OVAL" sig="1">oval:org.mitre.oval:def:507</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:322" source="OVAL" sig="1">oval:org.mitre.oval:def:322</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:306" source="OVAL" sig="1">oval:org.mitre.oval:def:306</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:216" source="OVAL" sig="1">oval:org.mitre.oval:def:216</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="ie">
        <vers num="5.0" />
        <vers num="5.0.1" edition="sp1" />
        <vers num="5.0.1" edition="sp2" />
        <vers num="5.0.1" edition="sp3" />
        <vers num="5.0.1" edition="sp4" />
        <vers num="5.5" edition="sp1" />
        <vers num="5.5" edition="sp2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0567" published="2004-12-31" name="CVE-2004-0567" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">The Windows Internet Naming Service (WINS) in Windows NT Server 4.0 SP 6a, NT Terminal Server 4.0 SP 6, Windows 2000 Server SP3 and SP4, and Windows Server 2003 does not properly validate the computer name value in a WINS packet, which allows remote attackers to execute arbitrary code or cause a denial of service (server crash), which results in an "unchecked buffer" and possibly triggers a buffer overflow, aka the "Name Validation Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/378160" source="CERT-VN" patch="1" adv="1">VU#378160</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/18259" source="XF" patch="1">wins-memory-pointer-hijack(18259)</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/MS04-045.mspx" source="MS" patch="1" adv="1">MS04-045</ref>
      <ref url="http://www.ciac.org/ciac/bulletins/p-054.shtml" source="CIAC" patch="1" adv="1">P-054</ref>
      <ref url="http://www.securityfocus.com/bid/11922" source="BID">11922</ref>
      <ref url="http://www.osvdb.org/12370" source="OSVDB">12370</ref>
      <ref url="http://securitytracker.com/id?1012517" source="SECTRACK">1012517</ref>
      <ref url="http://secunia.com/advisories/13466" source="SECUNIA">13466</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_2000">
        <vers num="" edition="sp3" />
        <vers num="" edition="sp3:server" />
        <vers num="" edition="sp4" />
        <vers num="" edition="sp4:server" />
      </prod>
      <prod vendor="microsoft" name="windows_2003_server">
        <vers num="64-bit" />
        <vers num="r2" />
      </prod>
      <prod vendor="microsoft" name="windows_nt">
        <vers num="4.0" edition="sp6" />
        <vers num="4.0" edition="sp6:terminal_server" />
        <vers num="4.0" edition="sp6a" />
        <vers num="4.0" edition="sp6a:server" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0568" published="2005-01-10" name="CVE-2004-0568" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">HyperTerminal application for Windows NT 4.0, Windows 2000, Windows XP, and Windows Server 2003 does not properly validate the length of a value that is saved in a session file, which allows remote attackers to execute arbitrary code via a malicious HyperTerminal session file (.ht), web site, or Telnet URL contained in an e-mail message, triggering a buffer overflow.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms04-043.asp" source="MS" patch="1" adv="1">MS04-043</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/18336" source="XF">win-hyperterminal-session-bo(18336)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110312618614849&amp;w=2" source="BUGTRAQ" adv="1">20041214 HyperTerminal - Buffer Overflow In .ht File</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:4741" source="OVAL" sig="1">oval:org.mitre.oval:def:4741</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:4508" source="OVAL" sig="1">oval:org.mitre.oval:def:4508</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:3973" source="OVAL" sig="1">oval:org.mitre.oval:def:3973</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:3138" source="OVAL" sig="1">oval:org.mitre.oval:def:3138</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2545" source="OVAL" sig="1">oval:org.mitre.oval:def:2545</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1603" source="OVAL" sig="1">oval:org.mitre.oval:def:1603</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_2000">
        <vers num="" edition=":professional" />
        <vers num="" edition=":server" />
        <vers num="" edition=":advanced_server" />
        <vers num="" edition=":datacenter_server" />
        <vers num="" edition="sp1" />
        <vers num="" edition="sp1:datacenter_server" />
        <vers num="" edition="sp1:professional" />
        <vers num="" edition="sp1:server" />
        <vers num="" edition="sp1:advanced_server" />
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:advanced_server" />
        <vers num="" edition="sp2:professional" />
        <vers num="" edition="sp2:datacenter_server" />
        <vers num="" edition="sp2:server" />
        <vers num="" edition="sp3" />
        <vers num="" edition="sp3:datacenter_server" />
        <vers num="" edition="sp3:server" />
        <vers num="" edition="sp3:professional" />
        <vers num="" edition="sp3:advanced_server" />
        <vers num="" edition="sp4" />
        <vers num="" edition="sp4:datacenter_server" />
        <vers num="" edition="sp4:server" />
        <vers num="" edition="sp4:professional" />
        <vers num="" edition="sp4:advanced_server" />
      </prod>
      <prod vendor="microsoft" name="windows_2003_server">
        <vers num="datacenter_64-bit" edition="sp1_beta_1" />
        <vers num="enterprise" edition="" />
        <vers num="enterprise" edition=":64-bit" />
        <vers num="enterprise" edition="sp1_beta_1" />
        <vers num="enterprise_64-bit" edition="sp1_beta_1" />
        <vers num="r2" edition="" />
        <vers num="r2" edition=":datacenter_64-bit" />
        <vers num="r2" edition=":64-bit" />
        <vers num="r2" edition="sp1_beta_1" />
        <vers num="standard" edition="" />
        <vers num="standard" edition=":64-bit" />
        <vers num="standard" edition="sp1_beta_1" />
        <vers num="web" edition="sp1_beta_1" />
      </prod>
      <prod vendor="microsoft" name="windows_nt">
        <vers num="4.0" edition="" />
        <vers num="4.0" edition=":server" />
        <vers num="4.0" edition=":enterprise_server" />
        <vers num="4.0" edition=":terminal_server" />
        <vers num="4.0" edition=":alpha" />
        <vers num="4.0" edition=":terminal_server_alpha" />
        <vers num="4.0" edition=":workstation" />
        <vers num="4.0" edition="sp1" />
        <vers num="4.0" edition="sp1:server" />
        <vers num="4.0" edition="sp1:workstation" />
        <vers num="4.0" edition="sp1:terminal_server" />
        <vers num="4.0" edition="sp1:enterprise_server" />
        <vers num="4.0" edition="sp1:alpha" />
        <vers num="4.0" edition="sp2" />
        <vers num="4.0" edition="sp2:enterprise_server" />
        <vers num="4.0" edition="sp2:server" />
        <vers num="4.0" edition="sp2:workstation" />
        <vers num="4.0" edition="sp2:alpha" />
        <vers num="4.0" edition="sp2:terminal_server" />
        <vers num="4.0" edition="sp3" />
        <vers num="4.0" edition="sp3:workstation" />
        <vers num="4.0" edition="sp3:server" />
        <vers num="4.0" edition="sp3:terminal_server" />
        <vers num="4.0" edition="sp3:alpha" />
        <vers num="4.0" edition="sp3:enterprise_server" />
        <vers num="4.0" edition="sp4" />
        <vers num="4.0" edition="sp4:workstation" />
        <vers num="4.0" edition="sp4:alpha" />
        <vers num="4.0" edition="sp4:enterprise_server" />
        <vers num="4.0" edition="sp4:terminal_server" />
        <vers num="4.0" edition="sp4:server" />
        <vers num="4.0" edition="sp5" />
        <vers num="4.0" edition="sp5:workstation" />
        <vers num="4.0" edition="sp5:alpha" />
        <vers num="4.0" edition="sp5:enterprise_server" />
        <vers num="4.0" edition="sp5:server" />
        <vers num="4.0" edition="sp5:terminal_server" />
        <vers num="4.0" edition="sp6" />
        <vers num="4.0" edition="sp6:alpha" />
        <vers num="4.0" edition="sp6:terminal_server" />
        <vers num="4.0" edition="sp6:server" />
        <vers num="4.0" edition="sp6:enterprise_server" />
        <vers num="4.0" edition="sp6:workstation" />
        <vers num="4.0" edition="sp6a" />
        <vers num="4.0" edition="sp6a:server" />
        <vers num="4.0" edition="sp6a:enterprise_server" />
        <vers num="4.0" edition="sp6a:workstation" />
        <vers num="4.0" edition="sp6a:alpha" />
      </prod>
      <prod vendor="microsoft" name="windows_xp">
        <vers num="" edition=":home" />
        <vers num="" edition=":64-bit" />
        <vers num="" edition=":media_center" />
        <vers num="" edition="gold" />
        <vers num="" edition="gold:professional" />
        <vers num="" edition="sp1" />
        <vers num="" edition="sp1:home" />
        <vers num="" edition="sp1:media_center" />
        <vers num="" edition="sp1:64-bit" />
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:home" />
        <vers num="" edition="sp2:media_center" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0569" published="2004-11-03" name="CVE-2004-0569" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">The RPC Runtime Library for Microsoft Windows NT 4.0 allows remote attackers to read active memory or cause a denial of service (system crash) via a malicious message, possibly related to improper length values.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/17663" source="XF" patch="1" adv="1">win-ms04029-patch(17663)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/17646" source="XF" patch="1" adv="1">wins-rpc-obtain-information(17646)</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms04-029.asp" source="MS" patch="1" adv="1">MS04-029</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109769394209518&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20041013 BindView Advisory: Memory Leak and DoS in NT4 RPC server</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5277" source="OVAL" sig="1">oval:org.mitre.oval:def:5277</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2505" source="OVAL" sig="1">oval:org.mitre.oval:def:2505</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_nt">
        <vers num="4.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0571" published="2005-01-10" name="CVE-2004-0571" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Microsoft Word for Windows 6.0 Converter does not properly validate certain data lengths, which allows remote attackers to execute arbitrary code via a .wri, .rtf, and .doc file sent by email or malicious web site, aka "Table Conversion Vulnerability," a different vulnerability than CVE-2004-0901.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms04-041.asp" source="MS" patch="1" adv="1">MS04-041</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/18337" source="XF">win-converter-table-code-execution(18337)</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:685" source="OVAL" sig="1">oval:org.mitre.oval:def:685</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:4328" source="OVAL" sig="1">oval:org.mitre.oval:def:4328</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:3743" source="OVAL" sig="1">oval:org.mitre.oval:def:3743</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:3416" source="OVAL" sig="1">oval:org.mitre.oval:def:3416</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1976" source="OVAL" sig="1">oval:org.mitre.oval:def:1976</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1959" source="OVAL" sig="1">oval:org.mitre.oval:def:1959</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1417" source="OVAL" sig="1">oval:org.mitre.oval:def:1417</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1168" source="OVAL" sig="1">oval:org.mitre.oval:def:1168</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_2000">
        <vers num="" edition=":professional" />
        <vers num="" edition=":server" />
        <vers num="" edition=":advanced_server" />
        <vers num="" edition=":datacenter_server" />
        <vers num="" edition="sp1" />
        <vers num="" edition="sp1:datacenter_server" />
        <vers num="" edition="sp1:professional" />
        <vers num="" edition="sp1:server" />
        <vers num="" edition="sp1:advanced_server" />
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:advanced_server" />
        <vers num="" edition="sp2:professional" />
        <vers num="" edition="sp2:datacenter_server" />
        <vers num="" edition="sp2:server" />
        <vers num="" edition="sp3" />
        <vers num="" edition="sp3:datacenter_server" />
        <vers num="" edition="sp3:server" />
        <vers num="" edition="sp3:professional" />
        <vers num="" edition="sp3:advanced_server" />
        <vers num="" edition="sp4" />
        <vers num="" edition="sp4:datacenter_server" />
        <vers num="" edition="sp4:server" />
        <vers num="" edition="sp4:professional" />
        <vers num="" edition="sp4:advanced_server" />
      </prod>
      <prod vendor="microsoft" name="windows_2003_server">
        <vers num="enterprise" edition="" />
        <vers num="enterprise" edition=":64-bit" />
        <vers num="enterprise_64-bit" />
        <vers num="r2" edition="" />
        <vers num="r2" edition=":datacenter_64-bit" />
        <vers num="r2" edition=":64-bit" />
        <vers num="standard" edition="" />
        <vers num="standard" edition=":64-bit" />
        <vers num="web" />
      </prod>
      <prod vendor="microsoft" name="windows_98">
        <vers num="" edition="gold" />
      </prod>
      <prod vendor="microsoft" name="windows_98se">
        <vers num="" />
      </prod>
      <prod vendor="microsoft" name="windows_me">
        <vers num="" />
      </prod>
      <prod vendor="microsoft" name="windows_nt">
        <vers num="4.0" edition="" />
        <vers num="4.0" edition=":server" />
        <vers num="4.0" edition=":enterprise_server" />
        <vers num="4.0" edition=":terminal_server" />
        <vers num="4.0" edition=":workstation" />
        <vers num="4.0" edition="sp1" />
        <vers num="4.0" edition="sp1:server" />
        <vers num="4.0" edition="sp1:workstation" />
        <vers num="4.0" edition="sp1:terminal_server" />
        <vers num="4.0" edition="sp1:enterprise_server" />
        <vers num="4.0" edition="sp2" />
        <vers num="4.0" edition="sp2:enterprise_server" />
        <vers num="4.0" edition="sp2:server" />
        <vers num="4.0" edition="sp2:workstation" />
        <vers num="4.0" edition="sp2:terminal_server" />
        <vers num="4.0" edition="sp3" />
        <vers num="4.0" edition="sp3:workstation" />
        <vers num="4.0" edition="sp3:server" />
        <vers num="4.0" edition="sp3:terminal_server" />
        <vers num="4.0" edition="sp3:enterprise_server" />
        <vers num="4.0" edition="sp4" />
        <vers num="4.0" edition="sp4:workstation" />
        <vers num="4.0" edition="sp4:enterprise_server" />
        <vers num="4.0" edition="sp4:terminal_server" />
        <vers num="4.0" edition="sp4:server" />
        <vers num="4.0" edition="sp5" />
        <vers num="4.0" edition="sp5:workstation" />
        <vers num="4.0" edition="sp5:enterprise_server" />
        <vers num="4.0" edition="sp5:server" />
        <vers num="4.0" edition="sp5:terminal_server" />
        <vers num="4.0" edition="sp6" />
        <vers num="4.0" edition="sp6:terminal_server" />
        <vers num="4.0" edition="sp6:server" />
        <vers num="4.0" edition="sp6:enterprise_server" />
        <vers num="4.0" edition="sp6:workstation" />
        <vers num="4.0" edition="sp6a" />
        <vers num="4.0" edition="sp6a:server" />
        <vers num="4.0" edition="sp6a:enterprise_server" />
        <vers num="4.0" edition="sp6a:workstation" />
      </prod>
      <prod vendor="microsoft" name="windows_xp">
        <vers num="" edition=":home" />
        <vers num="" edition=":64-bit" />
        <vers num="" edition="gold" />
        <vers num="" edition="gold:professional" />
        <vers num="" edition="sp1" />
        <vers num="" edition="sp1:home" />
        <vers num="" edition="sp1:64-bit" />
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:home" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0572" published="2004-11-03" name="CVE-2004-0572" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Buffer overflow in the Windows Program Group Converter (grpconv.exe) may allow remote attackers to execute arbitrary code via a shell: URL with a long filename and a .grp extension, which is not properly handled when the shell capability launches grpconv.exe.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/543864" source="CERT-VN" patch="1" adv="1">VU#543864</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/16664" source="XF" patch="1" adv="1">win-grpconv-bo(16664)</ref>
      <ref url="http://www.securityfocus.com/bid/10677" source="BID" patch="1" adv="1">10677</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms04-037.asp" source="MS" patch="1" adv="1">MS04-037</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/17662" source="XF">win-ms04037-patch(17662)</ref>
      <ref url="http://archives.neohapsis.com/archives/fulldisclosure/2004-07/0290.html" source="FULLDISC" adv="1">20040707 Re: shell:windows command question</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:4493" source="OVAL" sig="1">oval:org.mitre.oval:def:4493</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:4244" source="OVAL" sig="1">oval:org.mitre.oval:def:4244</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:3822" source="OVAL" sig="1">oval:org.mitre.oval:def:3822</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:3768" source="OVAL" sig="1">oval:org.mitre.oval:def:3768</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:3071" source="OVAL" sig="1">oval:org.mitre.oval:def:3071</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2753" source="OVAL" sig="1">oval:org.mitre.oval:def:2753</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1843" source="OVAL" sig="1">oval:org.mitre.oval:def:1843</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1837" source="OVAL" sig="1">oval:org.mitre.oval:def:1837</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1279" source="OVAL" sig="1">oval:org.mitre.oval:def:1279</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="grpconv">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0573" published="2004-09-28" name="CVE-2004-0573" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in the converter for Microsoft WordPerfect 5.x on Office 2000, Office XP, Office 2003, and Works Suites 2001 through 2004 allows remote attackers to execute arbitrary code via a malicious document or website.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/449438" source="CERT-VN">VU#449438</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/17306" source="XF" patch="1" adv="1">wordperfect-converter-message-bo(17306)</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms04-027.asp" source="MS" patch="1" adv="1">MS04-027</ref>
      <ref url="http://securitytracker.com/id?1011252" source="SECTRACK">1011252</ref>
      <ref url="http://securitytracker.com/id?1011251" source="SECTRACK">1011251</ref>
      <ref url="http://securitytracker.com/id?1011250" source="SECTRACK">1011250</ref>
      <ref url="http://securitytracker.com/id?1011249" source="SECTRACK">1011249</ref>
      <ref url="http://secunia.com/advisories/12529" source="SECUNIA">12529</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109519646030906&amp;w=2" source="BUGTRAQ" adv="1">20040914 Microsoft Office WordPerfect Converter Buffer Overflow Vulnerability</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5021" source="OVAL" sig="1">oval:org.mitre.oval:def:5021</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:4005" source="OVAL" sig="1">oval:org.mitre.oval:def:4005</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:3333" source="OVAL" sig="1">oval:org.mitre.oval:def:3333</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:3311" source="OVAL" sig="1">oval:org.mitre.oval:def:3311</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2670" source="OVAL" sig="1">oval:org.mitre.oval:def:2670</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="frontpage">
        <vers num="2000" />
        <vers num="2002" />
        <vers num="2003" />
      </prod>
      <prod vendor="microsoft" name="office">
        <vers num="2000" />
        <vers num="2003" edition="" />
        <vers num="2003" edition=":student_teacher" />
        <vers num="xp" />
      </prod>
      <prod vendor="microsoft" name="publisher">
        <vers num="2000" />
        <vers num="2002" />
        <vers num="2003" />
      </prod>
      <prod vendor="microsoft" name="word">
        <vers num="2000" />
        <vers num="2002" />
        <vers num="2003" />
      </prod>
      <prod vendor="microsoft" name="works">
        <vers num="2001" />
        <vers num="2002" />
        <vers num="2003" />
        <vers num="2004" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0574" published="2004-11-03" name="CVE-2004-0574" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">The Network News Transfer Protocol (NNTP) component of Microsoft Windows NT Server 4.0, Windows 2000 Server, Windows Server 2003, Exchange 2000 Server, and Exchange Server 2003 allows remote attackers to execute arbitrary code via XPAT patterns, possibly related to improper length validation and an "unchecked buffer," leading to off-by-one and heap-based buffer overflows.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/203126" source="CERT-VN" patch="1" adv="1">VU#203126</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/17641" source="XF" patch="1" adv="1">win-nntp-bo(17641)</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms04-036.asp" source="MS" patch="1" adv="1">MS04-036</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/17661" source="XF">win-ms04036-patch(17661)</ref>
      <ref url="http://www.coresecurity.com/common/showdoc.php?idx=420&amp;idxseccion=10" source="MISC">http://www.coresecurity.com/common/showdoc.php?idx=420&amp;idxseccion=10</ref>
      <ref url="http://www.ciac.org/ciac/bulletins/p-012.shtml" source="CIAC" adv="1">P-012</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109761632831563&amp;w=2" source="BUGTRAQ">20041012 CORE-2004-0802: IIS NNTP Service XPAT Command Vulnerabilities</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5926" source="OVAL" sig="1">oval:org.mitre.oval:def:5926</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5070" source="OVAL" sig="1">oval:org.mitre.oval:def:5070</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5021" source="OVAL" sig="1">oval:org.mitre.oval:def:5021</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:4392" source="OVAL" sig="1">oval:org.mitre.oval:def:4392</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:246" source="OVAL" sig="1">oval:org.mitre.oval:def:246</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="exchange_server">
        <vers num="2000" />
        <vers num="2003" />
      </prod>
      <prod vendor="microsoft" name="windows_2000">
        <vers num="" edition=":server" />
      </prod>
      <prod vendor="microsoft" name="windows_2003_server">
        <vers num="r2" />
      </prod>
      <prod vendor="microsoft" name="windows_nt">
        <vers num="4.0" edition="" />
        <vers num="4.0" edition=":server" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0575" published="2004-11-03" name="CVE-2004-0575" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Integer overflow in DUNZIP32.DLL for Microsoft Windows XP, Windows XP 64-bit Edition, Windows Server 2003, and Windows Server 2003 64-bit Edition allows remote attackers to execute arbitrary code via compressed (zipped) folders that involve an "unchecked buffer" and improper length validation.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/649374" source="CERT-VN">VU#649374</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/17659" source="XF" patch="1" adv="1">win-ms04034-patch(17659)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/17624" source="XF" patch="1" adv="1">win-compressed-folders-bo(17624)</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms04-034.asp" source="MS" patch="1" adv="1">MS04-034</ref>
      <ref url="http://www.eeye.com/html/research/advisories/AD20041012A.html" source="MISC">http://www.eeye.com/html/research/advisories/AD20041012A.html</ref>
      <ref url="http://www.ciac.org/ciac/bulletins/p-010.shtml" source="CIAC" adv="1">P-010</ref>
      <ref url="http://securitytracker.com/id?1011637" source="SECTRACK">1011637</ref>
      <ref url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=109767342326300&amp;w=2" source="BUGTRAQ">20041013 EEYE: Windows Shell ZIP File Decompression DUNZIP32.DLL Buffer Overflow Vulnerability</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6397" source="OVAL" sig="1">oval:org.mitre.oval:def:6397</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:4276" source="OVAL" sig="1">oval:org.mitre.oval:def:4276</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:3913" source="OVAL" sig="1">oval:org.mitre.oval:def:3913</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1053" source="OVAL" sig="1">oval:org.mitre.oval:def:1053</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_2003_server">
        <vers num="64-bit" />
        <vers num="r2" />
      </prod>
      <prod vendor="microsoft" name="windows_xp">
        <vers num="" edition=":64-bit" />
        <vers num="" edition="gold" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0576" published="2004-12-06" name="CVE-2004-0576" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The radius daemon (radiusd) for GNU Radius 1.1, when compiled with the -enable-snmp option, allows remote attackers to cause a denial of service (server crash) via malformed SNMP messages containing an invalid OID.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
      <config />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/16466" source="XF" patch="1" adv="1">radius-snmp-oid-dos(16466)</ref>
      <ref url="http://www.idefense.com/application/poi/display?id=110&amp;type=vulnerabilities" source="MISC" patch="1" adv="1">http://www.idefense.com/application/poi/display?id=110&amp;type=vulnerabilities</ref>
      <ref url="http://marc.theaimsgroup.com/?l=full-disclosure&amp;m=108785242716726&amp;w=2" source="FULLDISC" patch="1" adv="1">20040621 [Full-Disclosure] iDEFENSE Security Advisory 06.21.04 - GNU Radius SNMP Invalid OID Denial of Service Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gnu" name="radius">
        <vers num="1.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0577" published="2004-12-06" name="CVE-2004-0577" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">WinGate 5.2.3 build 901 and 6.0 beta 2 build 942, and other versions such as 5.0.5, allows remote attackers to read arbitrary files from the root directory via a URL request to the wingate-internal directory.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/16589" source="XF" patch="1" adv="1">wingate-directory-traversal(16589)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=full-disclosure&amp;m=108872788123695&amp;w=2" source="FULLDISC" patch="1" adv="1">20040701 iDEFENSE Security Advisory 07.01.04: WinGate Information Disclosure</ref>
      <ref url="http://www.idefense.com/application/poi/display?id=113" source="MISC">http://www.idefense.com/application/poi/display?id=113</ref>
    </refs>
    <vuln_soft>
      <prod vendor="qbik" name="wingate">
        <vers num="5.0.5" />
        <vers num="5.2.3" />
        <vers num="6.0_beta_2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0578" published="2004-12-06" name="CVE-2004-0578" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">WinGate 5.2.3 build 901 and 6.0 beta 2 build 942, and other versions such as 5.0.5, allows remote attackers to read arbitrary files via leading slash (//) characters in a URL request to the wingate-internal directory.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/16589" source="XF" patch="1" adv="1">wingate-directory-traversal(16589)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=full-disclosure&amp;m=108872788123695&amp;w=2" source="FULLDISC" patch="1" adv="1">20040701 iDEFENSE Security Advisory 07.01.04: WinGate Information Disclosure</ref>
      <ref url="http://www.idefense.com/application/poi/display?id=113" source="MISC">http://www.idefense.com/application/poi/display?id=113</ref>
    </refs>
    <vuln_soft>
      <prod vendor="qbik" name="wingate">
        <vers num="5.0.5" />
        <vers num="5.2.3" />
        <vers num="6.0_beta_2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0579" published="2004-08-06" name="CVE-2004-0579" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Format string vulnerability in super before 3.23 allows local users to execute arbitrary code as root.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.debian.org/security/2004/dsa-522" source="DEBIAN" patch="1" adv="1">DSA-522</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/16458" source="XF" adv="1">super-format-string(16458)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="william_deich" name="super">
        <vers num="3.12" />
        <vers num="3.16" />
        <vers num="3.17" />
        <vers num="3.18" />
        <vers num="3.19" />
      </prod>
      <prod vendor="debian" name="debian_linux">
        <vers num="3.0" edition="" />
        <vers num="3.0" edition=":hppa" />
        <vers num="3.0" edition=":mips" />
        <vers num="3.0" edition=":ia-32" />
        <vers num="3.0" edition=":m68k" />
        <vers num="3.0" edition=":s-390" />
        <vers num="3.0" edition=":alpha" />
        <vers num="3.0" edition=":arm" />
        <vers num="3.0" edition=":ia-64" />
        <vers num="3.0" edition=":mipsel" />
        <vers num="3.0" edition=":sparc" />
        <vers num="3.0" edition=":ppc" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0580" published="2004-08-06" name="CVE-2004-0580" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">DHCP on Linksys BEFSR11, BEFSR41, BEFSR81, and BEFSRU31 Cable/DSL Routers, firmware version 1.45.7, does not properly clear previously used buffer contents in a BOOTP reply packet, which allows remote attackers to obtain sensitive information.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/16142" source="XF" adv="1">linksys-etherfast-bootp-dos(16142)</ref>
      <ref url="http://www.securityfocus.com/bid/10329" source="BID" adv="1">10329</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108662876129301&amp;w=2" source="BUGTRAQ" adv="1">20040607 Linksys BEFSR41 DHCP vulnerability server leaks network data</ref>
      <ref url="http://linksys.custhelp.com/cgi-bin/linksys.cfg/php/enduser/std_adp.php?p_faqid=832&amp;p_%20%5Ccreated=1086294093&amp;p_sid=pU1X1idh&amp;p_lva=&amp;p_sp=cF9zcmNoPSZwX3NvcnRfYnk9JnBfZ3JpZHNvcnQ9%20%5CJnBfcm93X2NudD02NTQmcF9wYWdlPTE%2A&amp;p_li=" source="CONFIRM">http://linksys.custhelp.com/cgi-bin/linksys.cfg/php/enduser/std_adp.php?p_faqid=832&amp;p_%20\created=1086294093&amp;p_sid=pU1X1idh&amp;p_lva=&amp;p_sp=cF9zcmNoPSZwX3NvcnRfYnk9JnBfZ3JpZHNvcnQ9%20\JnBfcm93X2NudD02NTQmcF9wYWdlPTE*&amp;p_li=</ref>
      <ref url="http://www.osvdb.org/6325" source="OSVDB">6325</ref>
      <ref url="http://securitytracker.com/alerts/2004/May/1010288.html" source="SECTRACK">1010288</ref>
      <ref url="http://secunia.com/advisories/11606" source="SECUNIA">11606</ref>
    </refs>
    <vuln_soft>
      <prod vendor="linksys" name="befcmu10">
        <vers num="" />
      </prod>
      <prod vendor="linksys" name="befn2ps4">
        <vers num="1.42.7" />
      </prod>
      <prod vendor="linksys" name="befsr11">
        <vers num="1.40.2" />
        <vers num="1.41" />
        <vers num="1.42.3" />
        <vers num="1.42.7" />
        <vers num="1.43" />
        <vers num="1.43.3" />
        <vers num="1.44" />
      </prod>
      <prod vendor="linksys" name="befsr41">
        <vers num="1.35" />
        <vers num="1.36" />
        <vers num="1.37" />
        <vers num="1.38.5" />
        <vers num="1.39" />
        <vers num="1.40.2" />
        <vers num="1.41" />
        <vers num="1.42.3" />
        <vers num="1.42.7" />
        <vers num="1.43" />
        <vers num="1.43.3" />
        <vers num="1.44" />
        <vers num="1.45.7" />
      </prod>
      <prod vendor="linksys" name="befsr41w">
        <vers num="" />
      </prod>
      <prod vendor="linksys" name="befsr81">
        <vers num="2.42.7.1" />
        <vers num="2.44" />
      </prod>
      <prod vendor="linksys" name="befsru31">
        <vers num="1.40.2" />
        <vers num="1.41" />
        <vers num="1.42.3" />
        <vers num="1.42.7" />
        <vers num="1.43" />
        <vers num="1.43.3" />
        <vers num="1.44" />
      </prod>
      <prod vendor="linksys" name="befsx41">
        <vers num="1.42.7" />
        <vers num="1.43" />
        <vers num="1.43.3" />
        <vers num="1.43.4" />
        <vers num="1.44" />
        <vers num="1.44.3" />
        <vers num="1.45.3" />
      </prod>
      <prod vendor="linksys" name="befvp41">
        <vers num="1.39.64" />
        <vers num="1.40.3f" />
        <vers num="1.40.4" />
        <vers num="1.42.7" />
      </prod>
      <prod vendor="linksys" name="rv082">
        <vers num="" />
      </prod>
      <prod vendor="linksys" name="wap55ag">
        <vers num="1.0.7" />
      </prod>
      <prod vendor="linksys" name="wrt54g">
        <vers num="1.42.3" />
        <vers num="2.00.8" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0581" published="2004-08-06" name="CVE-2004-0581" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">ksymoops-gznm script in Mandrake Linux 9.1 through 10.0, and Corporate Server 2.1, allows local users to delete arbitrary files via a symlink attack on files in /tmp.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/10516" source="BID" patch="1" adv="1">10516</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/16392" source="XF" adv="1">ksymoops-symlink(16392)</ref>
      <ref url="http://www.mandrakesecure.net/en/advisories/advisory.php?name=MDKSA-2004:060" source="MANDRAKE">MDKSA-2004:060</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gnu" name="ksymoops">
        <vers num="2.4.5" />
        <vers num="2.4.8" />
        <vers num="2.4.9" />
      </prod>
      <prod vendor="mandrakesoft" name="mandrake_linux">
        <vers num="10.0" edition="" />
        <vers num="10.0" edition=":amd64" />
        <vers num="9.1" edition="" />
        <vers num="9.1" edition=":ppc" />
        <vers num="9.2" edition="" />
        <vers num="9.2" edition=":amd64" />
      </prod>
      <prod vendor="mandrakesoft" name="mandrake_linux_corporate_server">
        <vers num="2.1" edition="" />
        <vers num="2.1" edition=":x86_64" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0582" published="2004-08-06" name="CVE-2004-0582" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Unknown vulnerability in Webmin 1.140 allows remote attackers to bypass access control rules and gain read access to configuration information for a module.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/10522" source="BID" patch="1" adv="1">10522</ref>
      <ref url="http://www.securityfocus.com/bid/10474" source="BID" patch="1" adv="1">10474</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108697184602191&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20040611 [SNS Advisory No.74] Webmin Access Control Rule Bypass Vulnerability</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/16333" source="XF" adv="1">webmin-bypass-security(16333)</ref>
      <ref url="http://www.webmin.com/changes-1.150.html" source="CONFIRM">http://www.webmin.com/changes-1.150.html</ref>
      <ref url="http://www.mandrakesecure.net/en/advisories/advisory.php?name=MDKSA-2004:074" source="MANDRAKE">MDKSA-2004:074</ref>
      <ref url="http://www.lac.co.jp/security/csl/intelligence/SNSadvisory_e/74_e.html" source="MISC">http://www.lac.co.jp/security/csl/intelligence/SNSadvisory_e/74_e.html</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200406-12.xml" source="GENTOO">GLSA-200406-12</ref>
      <ref url="http://www.debian.org/security/2004/dsa-526" source="DEBIAN">DSA-526</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000848" source="CONECTIVA">CLA-2004:848</ref>
    </refs>
    <vuln_soft>
      <prod vendor="webmin" name="webmin">
        <vers num="1.1.40" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0583" published="2004-08-06" name="CVE-2004-0583" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The account lockout functionality in (1) Webmin 1.140 and (2) Usermin 1.070 does not parse certain character strings, which allows remote attackers to conduct a brute force attack to guess user IDs and passwords.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/10523" source="BID" patch="1" adv="1">10523</ref>
      <ref url="http://www.securityfocus.com/bid/10474" source="BID" patch="1" adv="1">10474</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/16334" source="XF" adv="1">webmin-username-password-dos(16334)</ref>
      <ref url="http://www.webmin.com/changes-1.150.html" source="CONFIRM">http://www.webmin.com/changes-1.150.html</ref>
      <ref url="http://www.mandrakesecure.net/en/advisories/advisory.php?name=MDKSA-2004:074" source="MANDRAKE">MDKSA-2004:074</ref>
      <ref url="http://www.lac.co.jp/security/csl/intelligence/SNSadvisory_e/75_e.html" source="MISC">http://www.lac.co.jp/security/csl/intelligence/SNSadvisory_e/75_e.html</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200406-15.xml" source="GENTOO">GLSA-200406-15</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200406-12.xml" source="GENTOO">GLSA-200406-12</ref>
      <ref url="http://www.debian.org/security/2004/dsa-526" source="DEBIAN">DSA-526</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108737059313829&amp;w=2" source="BUGTRAQ" adv="1">20040611 [SNS Advisory No.75] Webmin/Usermin Account Lockout Bypass Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="usermin" name="usermin">
        <vers num="1.070" />
      </prod>
      <prod vendor="webmin" name="webmin">
        <vers num="1.1.40" />
      </prod>
      <prod vendor="debian" name="debian_linux">
        <vers num="3.0" edition="" />
        <vers num="3.0" edition=":hppa" />
        <vers num="3.0" edition=":mips" />
        <vers num="3.0" edition=":ia-32" />
        <vers num="3.0" edition=":m68k" />
        <vers num="3.0" edition=":s-390" />
        <vers num="3.0" edition=":alpha" />
        <vers num="3.0" edition=":arm" />
        <vers num="3.0" edition=":ia-64" />
        <vers num="3.0" edition=":mipsel" />
        <vers num="3.0" edition=":sparc" />
        <vers num="3.0" edition=":ppc" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0584" published="2004-08-06" name="CVE-2004-0584" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Unknown vulnerability in Horde IMP 3.2.3 and earlier, before a "security fix," does not properly validate input, which allows remote attackers to execute arbitrary script as other users via script or HTML in an e-mail message, possibly triggering a cross-site scripting (XSS) vulnerability.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/16357" source="XF" patch="1">imp-content-type-xss(16357)</ref>
      <ref url="http://www.securityfocus.com/bid/10501" source="BID" patch="1">10501</ref>
      <ref url="http://www.horde.org/imp/3.2/" source="MISC" patch="1">http://www.horde.org/imp/3.2/</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200406-11.xml" source="GENTOO" patch="1" adv="1">GLSA-200406-11</ref>
      <ref url="http://secunia.com/advisories/11805" source="SECUNIA" patch="1" adv="1">11805</ref>
    </refs>
    <vuln_soft>
      <prod vendor="horde" name="imp">
        <vers num="2.0" />
        <vers num="2.2" />
        <vers num="2.2.1" />
        <vers num="2.2.2" />
        <vers num="2.2.3" />
        <vers num="2.2.4" />
        <vers num="2.2.5" />
        <vers num="2.2.6" />
        <vers num="2.2.7" />
        <vers num="2.2.8" />
        <vers num="2.3" />
        <vers num="3.0" />
        <vers num="3.1" />
        <vers num="3.1.2" />
        <vers num="3.2" />
        <vers num="3.2.1" />
        <vers num="3.2.2" />
        <vers num="3.2.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" seq="2004-0585" reject="1" published="2004-08-06" name="CVE-2004-0585" modified="2008-09-10">
    <desc>
      <descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: CVE-2004-0589.  Reason: This candidate is a duplicate of CVE-2004-0589.  Notes: All CVE users should reference CVE-2004-0589 instead of this candidate.  All references and descriptions in this candidate have been removed to prevent accidental usage.</descript>
    </desc>
    <refs />
  </entry>
  <entry type="CVE" severity="High" seq="2004-0586" published="2004-08-06" name="CVE-2004-0586" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">acpRunner ActiveX 1.2.5.0 allows remote attackers to execute arbitrary code via the (1) DownLoadURL, (2) SaveFilePath, and (3) Download ActiveX methods.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" admin="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/16429" source="XF" adv="1">ibm-acprunner-execute-code(16429)</ref>
      <ref url="http://www-306.ibm.com/pc/support/site.wss/document.do?lndocid=MIGR-54588" source="CONFIRM">http://www-306.ibm.com/pc/support/site.wss/document.do?lndocid=MIGR-54588</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108745652205176&amp;w=2" source="BUGTRAQ" adv="1">20040616 IBM acpRunner Activex Dangerous Methods Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="acprunner">
        <vers num="1.2.5.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2004-0587" published="2004-08-06" name="CVE-2004-0587" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">Insecure permissions for the /proc/scsi/qla2300/HbaApiNode file in Linux allows local users to cause a denial of service.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <access />
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/10279" source="BID" patch="1" adv="1">10279</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/16062" source="XF" adv="1">suse-hbaapinode-dos(16062)</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-418.html" source="REDHAT">RHSA-2004:418</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-413.html" source="REDHAT">RHSA-2004:413</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2004_10_kernel.html" source="SUSE">SuSE-SA:2004:010</ref>
      <ref url="http://www.mandrakesecure.net/en/advisories/advisory.php?name=MDKSA-2004:066" source="MANDRAKE">MDKSA-2004:066</ref>
      <ref url="http://securitytracker.com/id?1010057" source="SECTRACK">1010057</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9398" source="OVAL">oval:org.mitre.oval:def:9398</ref>
      <ref url="http://lwn.net/Articles/91155/" source="FEDORA">FEDORA-2004-186</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/20040804-01-U.asc" source="SGI">20040804-01-U</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mandrakesoft" name="mandrake_linux">
        <vers num="10.0" edition="" />
        <vers num="10.0" edition=":amd64" />
        <vers num="9.2" edition="" />
        <vers num="9.2" edition=":amd64" />
      </prod>
      <prod vendor="mandrakesoft" name="mandrake_linux_corporate_server">
        <vers num="2.1" edition="" />
        <vers num="2.1" edition=":x86_64" />
      </prod>
      <prod vendor="redhat" name="fedora_core">
        <vers num="core_1.0" />
      </prod>
      <prod vendor="suse" name="suse_linux">
        <vers num="8" edition="" />
        <vers num="8" edition=":enterprise_server" />
        <vers num="8.1" />
        <vers num="9.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0588" published="2004-08-06" name="CVE-2004-0588" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in the web mail module for Usermin 1.070 allows remote attackers to insert arbitrary HTML and script via e-mail messages.</descript>
    </desc>
    <sols>
      <sol source="nvd">This vulnerability is addressed in the following product update:
Usermin, Usermin, 1.080</sol>
    </sols>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/10521" source="BID" patch="1">10521</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200406-15.xml" source="GENTOO" patch="1" adv="1">GLSA-200406-15</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108781564518287&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20040611 [SNS Advisory No.73] Usermin Cross-site Scripting Vulnerability</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/16494" source="XF">usermin-email-xss(16494)</ref>
      <ref url="http://www.lac.co.jp/security/csl/intelligence/SNSadvisory_e/73_e.html" source="MISC">http://www.lac.co.jp/security/csl/intelligence/SNSadvisory_e/73_e.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="usermin" name="usermin">
        <vers num="1.070" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0589" published="2004-08-06" name="CVE-2004-0589" modified="2009-03-04" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Cisco IOS 11.1(x) through 11.3(x) and 12.0(x) through 12.2(x), when configured for BGP routing, allows remote attackers to cause a denial of service (device reload) via malformed BGP (1) OPEN or (2) UPDATE messages.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/784540" source="CERT-VN" patch="1" adv="1">VU#784540</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/16427" source="XF" adv="1">cisco-ios-bgp-packet-dos(16427)</ref>
      <ref url="http://www.cisco.com/warp/public/707/cisco-sa-20040616-bgp.shtml" source="CISCO">20040616 Cisco IOS Malformed BGP Packet Causes Reload</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:4948" source="OVAL">oval:org.mitre.oval:def:4948</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="ios">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0590" published="2004-12-06" name="CVE-2004-0590" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">FreeS/WAN 1.x and 2.x, and other related products including superfreeswan 1.x, openswan 1.x before 1.0.6, openswan 2.x before 2.1.4, and strongSwan before 2.1.3, allows remote attackers to authenticate using spoofed PKCS#7 certificates in which a self-signed certificate identifies an alternate Certificate Authority (CA) and spoofed issuer and subject.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" other="1" admin="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/16515" source="XF" patch="1" adv="1">ipsec-verifyx509cert-auth-bypass(16515)</ref>
      <ref url="http://www.openswan.org/support/vuln/can-2004-0590/" source="CONFIRM" patch="1" adv="1">http://www.openswan.org/support/vuln/can-2004-0590/</ref>
      <ref url="http://www.mandrakesecure.net/en/advisories/advisory.php?name=MDKSA-2004:070" source="MANDRAKE" patch="1" adv="1">MDKSA-2004:070</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200406-20.xml" source="GENTOO" patch="1" adv="1">GLSA-200406-20</ref>
    </refs>
    <vuln_soft>
      <prod vendor="frees_wan" name="frees_wan">
        <vers num="1" />
        <vers num="2" />
      </prod>
      <prod vendor="frees_wan" name="super_frees_wan">
        <vers num="1" />
      </prod>
      <prod vendor="openswan" name="openswan">
        <vers num="1" />
        <vers num="2" />
      </prod>
      <prod vendor="strongswan" name="strongswan">
        <vers prev="1" num="2.1.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0591" published="2004-08-06" name="CVE-2004-0591" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in the print_header_uc function for SqWebMail 4.0.4 and earlier, and possibly 3.x, allows remote attackers to inject arbitrary web script or HRML via (1) e-mail headers or (2) a message with a "message/delivery-status" MIME Content-Type.</descript>
    </desc>
    <sols>
      <sol source="nvd">This vulnerability is addressed in the following product release:
Inter7, SqWebMail, 4.0.5</sol>
    </sols>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/10588" source="BID" patch="1">10588</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200408-02.xml" source="GENTOO" patch="1" adv="1">GLSA-200408-02</ref>
      <ref url="http://www.debian.org/security/2004/dsa-533" source="DEBIAN" patch="1" adv="1">DSA-533</ref>
      <ref url="http://secunia.com/advisories/11918/" source="SECUNIA" patch="1" adv="1">11918</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/16467" source="XF">sqwebmail-print-header-xss(16467)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108786212220140&amp;w=2" source="BUGTRAQ" adv="1">20040621 XSS vulnerability in Sqwebmail 4.0.4</ref>
    </refs>
    <vuln_soft>
      <prod vendor="inter7" name="sqwebmail">
        <vers num="4.0.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0592" published="2004-12-31" name="CVE-2004-0592" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The tcp_find_option function of the netfilter subsystem for IPv6 in the SUSE Linux 2.6.5 kernel with USAGI patches, when using iptables and TCP options rules, allows remote attackers to cause a denial of service (CPU consumption by infinite loop) via a large option length that produces a negative integer after a casting operation to the char type, a similar flaw to CVE-2004-0626.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.novell.com/linux/security/advisories/2004_20_kernel.html" source="SUSE" patch="1" adv="1">SUSE-SA:2004:020</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2004-July/023408.html" source="FULLDISC">20040703 Re: SUSE Security Announcement: kernel (SUSE-SA:2004:020)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/43137" source="XF">linux-kernel-tcpfindoption-dos(43137)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="suse" name="suse_linux">
        <vers num="2.6.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0593" published="2004-09-28" name="CVE-2004-0593" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Sygate Enforcer 3.5MR1 and earlier passes broadcast traffic before authentication, which could allow remote attackers to bypass filtering rules.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <access />
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/16948" source="XF" patch="1" adv="1">sygate-enforcer-filter-bypass(16948)</ref>
      <ref url="http://www.corsaire.com/advisories/c031120-003.txt" source="MISC" patch="1" adv="1">http://www.corsaire.com/advisories/c031120-003.txt</ref>
      <ref url="http://www.securityfocus.com/bid/10908" source="BID" adv="1">10908</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109215731626998&amp;w=2" source="BUGTRAQ">20040810 Corsaire Security Advisory - Sygate Enforcer unauthenticated broadcast issue</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sygate_technologies" name="enforcer">
        <vers prev="1" num="3.5mr1" />
      </prod>
      <prod vendor="sygate_technologies" name="secure_enterprise">
        <vers num="3.0" />
        <vers num="3.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0594" published="2004-07-27" name="CVE-2004-0594" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_score="5.1" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="4.9" CVSS_base_score="5.1">
    <desc>
      <descript source="cve">The memory_limit functionality in PHP 4.x up to 4.3.7, and 5.x up to 5.0.0RC3, under certain conditions such as when register_globals is enabled, allows remote attackers to execute arbitrary code by triggering a memory_limit abort during execution of the zend_hash_init function and overwriting a HashTable destructor pointer before the initialization of key data structures is complete.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <exception />
      <race />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/16693" source="XF" patch="1" adv="1">php-memorylimit-code-execution(16693)</ref>
      <ref url="http://www.trustix.org/errata/2004/0039/" source="TRUSTIX">2004-0039</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-405.html" source="REDHAT">RHSA-2004:405</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-395.html" source="REDHAT">RHSA-2004:395</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-392.html" source="REDHAT">RHSA-2004:392</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2004_21_php4.html" source="SUSE">SUSE-SA:2004:021</ref>
      <ref url="http://www.mandrakesecure.net/en/advisories/advisory.php?name=MDKSA-2004:068" source="MANDRAKE">MDKSA-2004:068</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200407-13.xml" source="GENTOO">GLSA-200407-13</ref>
      <ref url="http://www.debian.org/security/2005/dsa-669" source="DEBIAN">DSA-669</ref>
      <ref url="http://www.debian.org/security/2004/dsa-531" source="DEBIAN">DSA-531</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10896" source="OVAL">oval:org.mitre.oval:def:10896</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108981780109154&amp;w=2" source="BUGTRAQ" adv="1">20040713 Advisory 11/2004: PHP memory_limit remote vulnerability</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2004-July/023908.html" source="FULLDISC">20040714 Advisory 11/2004: PHP memory_limit remote vulnerability</ref>
      <ref url="http://www.securityfocus.com/bid/10725" source="BID">10725</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-816.html" source="REDHAT">RHSA-2005:816</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109181600614477&amp;w=2" source="HP">SSRT4777</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109051444105182&amp;w=2" source="BUGTRAQ">20040722 [OpenPKG-SA-2004.034] OpenPKG Security Advisory (php)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108982983426031&amp;w=2" source="BUGTRAQ">20040714 TSSA-2004-013 - php</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000847" source="CONECTIVA">CLA-2004:847</ref>
    </refs>
    <vuln_soft>
      <prod vendor="avaya" name="integrated_management">
        <vers num="" />
      </prod>
      <prod vendor="php" name="php">
        <vers num="3.0" />
        <vers num="3.0.1" />
        <vers num="3.0.10" />
        <vers num="3.0.11" />
        <vers num="3.0.12" />
        <vers num="3.0.13" />
        <vers num="3.0.14" />
        <vers num="3.0.15" />
        <vers num="3.0.16" />
        <vers num="3.0.17" />
        <vers num="3.0.18" />
        <vers num="3.0.2" />
        <vers num="3.0.3" />
        <vers num="3.0.4" />
        <vers num="3.0.5" />
        <vers num="3.0.6" />
        <vers num="3.0.7" />
        <vers num="3.0.8" />
        <vers num="3.0.9" />
        <vers num="4.0" />
        <vers num="4.0.1" edition="patch1" />
        <vers num="4.0.1" edition="patch2" />
        <vers num="4.0.2" />
        <vers num="4.0.3" edition="patch1" />
        <vers num="4.0.4" />
        <vers num="4.0.5" />
        <vers num="4.0.6" />
        <vers num="4.0.7" edition="rc1" />
        <vers num="4.0.7" edition="rc2" />
        <vers num="4.0.7" edition="rc3" />
        <vers num="4.1.0" />
        <vers num="4.1.1" />
        <vers num="4.1.2" />
        <vers num="4.2" edition="" />
        <vers num="4.2" edition=":dev" />
        <vers num="4.2.0" />
        <vers num="4.2.1" />
        <vers num="4.2.2" />
        <vers num="4.2.3" />
        <vers num="4.3" />
        <vers num="4.3.1" />
        <vers num="4.3.2" />
        <vers num="4.3.3" />
        <vers num="4.3.5" />
        <vers num="4.3.6" />
        <vers num="4.3.7" />
        <vers num="5.0" edition="rc1" />
        <vers num="5.0" edition="rc2" />
        <vers num="5.0" edition="rc3" />
      </prod>
      <prod vendor="avaya" name="converged_communications_server">
        <vers num="2.0" />
      </prod>
      <prod vendor="avaya" name="s8300">
        <vers num="r2.0.0" />
        <vers num="r2.0.1" />
      </prod>
      <prod vendor="avaya" name="s8500">
        <vers num="r2.0.0" />
        <vers num="r2.0.1" />
      </prod>
      <prod vendor="avaya" name="s8700">
        <vers num="r2.0.0" />
        <vers num="r2.0.1" />
      </prod>
      <prod vendor="redhat" name="fedora_core">
        <vers num="core_1.0" />
        <vers num="core_2.0" />
      </prod>
      <prod vendor="trustix" name="secure_linux">
        <vers num="1.5" />
        <vers num="2.0" />
        <vers num="2.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0595" published="2004-07-27" name="CVE-2004-0595" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">The strip_tags function in PHP 4.x up to 4.3.7, and 5.x up to 5.0.0RC3, does not filter null (\0) characters within tag names when restricting input to allowed tags, which allows dangerous tags to be processed by web browsers such as Internet Explorer and Safari, which ignore null characters and facilitate the exploitation of cross-site scripting (XSS) vulnerabilities.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/10724" source="BID" patch="1" adv="1">10724</ref>
      <ref url="http://www.debian.org/security/2004/dsa-531" source="DEBIAN" patch="1" adv="1">DSA-531</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/16692" source="XF" adv="1">php-strip-tag-bypass(16692)</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-405.html" source="REDHAT">RHSA-2004:405</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-395.html" source="REDHAT">RHSA-2004:395</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-392.html" source="REDHAT">RHSA-2004:392</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2004_21_php4.html" source="SUSE">SUSE-SA:2004:021</ref>
      <ref url="http://www.mandrakesecure.net/en/advisories/advisory.php?name=MDKSA-2004:068" source="MANDRAKE">MDKSA-2004:068</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200407-13.xml" source="GENTOO">GLSA-200407-13</ref>
      <ref url="http://www.debian.org/security/2005/dsa-669" source="DEBIAN">DSA-669</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10619" source="OVAL">oval:org.mitre.oval:def:10619</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108981780109154&amp;w=2" source="BUGTRAQ" adv="1">20040713 Advisory 11/2004: PHP memory_limit remote vulnerability</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2004-July/023909.html" source="FULLDISC">20040714 Advisory 12/2004: PHP strip_tags() bypass vulnerability</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-816.html" source="REDHAT">RHSA-2005:816</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109181600614477&amp;w=2" source="HP">SSRT4777</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109051444105182&amp;w=2" source="BUGTRAQ">20040722 [OpenPKG-SA-2004.034] OpenPKG Security Advisory (php)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108982983426031&amp;w=2" source="BUGTRAQ">20040714 TSSA-2004-013 - php</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000847" source="CONECTIVA">CLA-2004:847</ref>
    </refs>
    <vuln_soft>
      <prod vendor="avaya" name="integrated_management">
        <vers num="" />
      </prod>
      <prod vendor="php" name="php">
        <vers num="4.0" />
        <vers num="4.0.1" />
        <vers num="4.0.2" />
        <vers num="4.0.3" />
        <vers num="4.0.4" />
        <vers num="4.0.5" />
        <vers num="4.0.6" />
        <vers num="4.0.7" />
        <vers num="4.1.0" />
        <vers num="4.1.1" />
        <vers num="4.1.2" />
        <vers num="4.2.0" />
        <vers num="4.2.1" />
        <vers num="4.2.2" />
        <vers num="4.2.3" />
        <vers num="4.3" />
        <vers num="4.3.1" />
        <vers num="4.3.2" />
        <vers num="4.3.3" />
        <vers num="4.3.5" />
        <vers num="4.3.6" />
        <vers num="4.3.7" />
        <vers num="5.0" edition="rc1" />
        <vers num="5.0" edition="rc2" />
        <vers num="5.0" edition="rc3" />
      </prod>
      <prod vendor="avaya" name="converged_communications_server">
        <vers num="2.0" />
      </prod>
      <prod vendor="avaya" name="s8300">
        <vers num="r2.0.0" />
        <vers num="r2.0.1" />
      </prod>
      <prod vendor="avaya" name="s8500">
        <vers num="r2.0.0" />
        <vers num="r2.0.1" />
      </prod>
      <prod vendor="avaya" name="s8700">
        <vers num="r2.0.0" />
        <vers num="r2.0.1" />
      </prod>
      <prod vendor="redhat" name="fedora_core">
        <vers num="core_1.0" />
        <vers num="core_2.0" />
      </prod>
      <prod vendor="trustix" name="secure_linux">
        <vers num="1.5" />
        <vers num="2.0" />
        <vers num="2.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2004-0596" published="2004-08-06" name="CVE-2004-0596" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">The Equalizer Load-balancer for serial network interfaces (eql.c) in Linux kernel 2.6.x up to 2.6.7 allows local users to cause a denial of service via a non-existent device name that triggers a null dereference.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/10730" source="BID" patch="1" adv="1">10730</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/16694" source="XF" adv="1">linux-eql-dos(16694)</ref>
      <ref url="http://linux.bkbits.net:8080/linux-2.6/cset@40d4aa72hPLWy-jMLr0eJAXMxHcNZg" source="CONFIRM">http://linux.bkbits.net:8080/linux-2.6/cset@40d4aa72hPLWy-jMLr0eJAXMxHcNZg</ref>
    </refs>
    <vuln_soft>
      <prod vendor="linux" name="linux_kernel">
        <vers num="2.6.0" edition="test1" />
        <vers num="2.6.0" edition="test10" />
        <vers num="2.6.0" edition="test11" />
        <vers num="2.6.0" edition="test2" />
        <vers num="2.6.0" edition="test3" />
        <vers num="2.6.0" edition="test4" />
        <vers num="2.6.0" edition="test5" />
        <vers num="2.6.0" edition="test6" />
        <vers num="2.6.0" edition="test7" />
        <vers num="2.6.0" edition="test8" />
        <vers num="2.6.0" edition="test9" />
        <vers num="2.6.1" edition="rc1" />
        <vers num="2.6.1" edition="rc2" />
        <vers num="2.6.2" />
        <vers num="2.6.3" />
        <vers num="2.6.4" />
        <vers num="2.6.5" />
        <vers num="2.6.6" edition="rc1" />
        <vers num="2.6.7" />
        <vers num="2.6_test9_cvs" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0597" published="2004-11-23" name="CVE-2004-0597" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Multiple buffer overflows in libpng 1.2.5 and earlier, as used in multiple products, allow remote attackers to execute arbitrary code via malformed PNG images in which (1) the png_handle_tRNS function does not properly validate the length of transparency chunk (tRNS) data, or the (2) png_handle_sBIT or (3) png_handle_hIST functions do not perform sufficient bounds checking.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA05-039A.html" source="CERT" adv="1">TA05-039A</ref>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA04-217A.html" source="CERT" adv="1">TA04-217A</ref>
      <ref url="http://www.kb.cert.org/vuls/id/817368" source="CERT-VN" adv="1">VU#817368</ref>
      <ref url="http://www.kb.cert.org/vuls/id/388984" source="CERT-VN" adv="1">VU#388984</ref>
      <ref url="https://bugzilla.fedora.us/show_bug.cgi?id=1943" source="FEDORA" patch="1">FLSA:1943</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/16894" source="XF" patch="1" adv="1">libpng-pnghandle-bo(16894)</ref>
      <ref url="http://www.trustix.net/errata/2004/0040/" source="TRUSTIX" patch="1" adv="1">2004-0040</ref>
      <ref url="http://www.securityfocus.com/bid/10857" source="BID" patch="1" adv="1">10857</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2004_23_libpng.html" source="SUSE" patch="1" adv="1">SUSE-SA:2004:023</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms05-009.mspx" source="MS" patch="1" adv="1">MS05-009</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200408-22.xml" source="GENTOO" patch="1" adv="1">GLSA-200408-22</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200408-03.xml" source="GENTOO" patch="1" adv="1">GLSA-200408-03</ref>
      <ref url="http://www.debian.org/security/2004/dsa-536" source="DEBIAN" patch="1" adv="1">DSA-536</ref>
      <ref url="http://www.adobe.com/support/downloads/detail.jsp?ftpID=2679" source="CONFIRM" patch="1">http://www.adobe.com/support/downloads/detail.jsp?ftpID=2679</ref>
      <ref url="http://www.securityfocus.com/bid/15495" source="BID">15495</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-429.html" source="REDHAT" adv="1">RHSA-2004:429</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-421.html" source="REDHAT" adv="1">RHSA-2004:421</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-402.html" source="REDHAT">RHSA-2004:402</ref>
      <ref url="http://www.mozilla.org/projects/security/known-vulnerabilities.html" source="CONFIRM">http://www.mozilla.org/projects/security/known-vulnerabilities.html</ref>
      <ref url="http://www.coresecurity.com/common/showdoc.php?idx=421&amp;idxseccion=10" source="MISC">http://www.coresecurity.com/common/showdoc.php?idx=421&amp;idxseccion=10</ref>
      <ref url="http://scary.beasts.org/security/CESA-2004-001.txt" source="MISC" adv="1">http://scary.beasts.org/security/CESA-2004-001.txt</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:7709" source="OVAL">oval:org.mitre.oval:def:7709</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11284" source="OVAL">oval:org.mitre.oval:def:11284</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110796779903455&amp;w=2" source="BUGTRAQ">20050209 MSN Messenger PNG Image Buffer Overflow Download Shellcoded Exploit</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109900315219363&amp;w=2" source="FEDORA">FLSA:2089</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109761239318458&amp;w=2" source="SCO">SCOSA-2004.16</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109181639602978&amp;w=2" source="HP">SSRT4778</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109163866717909&amp;w=2" source="BUGTRAQ">20040804 [OpenPKG-SA-2004.035] OpenPKG Security Advisory (png)</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000856" source="CONECTIVA">CLA-2004:856</ref>
      <ref url="ftp://ftp.sco.com/pub/updates/OpenServer/SCOSA-2005.49/SCOSA-2005.49.txt" source="SCO">SCOSA-2005.49</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:213" source="MANDRIVA">MDKSA-2006:213</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:212" source="MANDRIVA">MDKSA-2006:212</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2004:079" source="MANDRAKE">MDKSA-2004:079</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=urn:cds:docid:1-21-114816-02-1" source="CONFIRM">http://sunsolve.sun.com/search/document.do?assetkey=urn:cds:docid:1-21-114816-02-1</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-66-200663-1" source="SUNALERT">200663</ref>
      <ref url="http://secunia.com/advisories/22958" source="SECUNIA">22958</ref>
      <ref url="http://secunia.com/advisories/22957" source="SECUNIA">22957</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:594" source="OVAL" sig="1">oval:org.mitre.oval:def:594</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:4492" source="OVAL" sig="1">oval:org.mitre.oval:def:4492</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2378" source="OVAL" sig="1">oval:org.mitre.oval:def:2378</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2274" source="OVAL" sig="1">oval:org.mitre.oval:def:2274</ref>
    </refs>
    <vuln_soft>
      <prod vendor="greg_roelofs" name="libpng">
        <vers prev="1" num="1.2.5" />
      </prod>
      <prod vendor="microsoft" name="msn_messenger">
        <vers num="6.1" />
        <vers num="6.2" />
      </prod>
      <prod vendor="microsoft" name="windows_media_player">
        <vers num="9" />
      </prod>
      <prod vendor="microsoft" name="windows_messenger">
        <vers num="5.0" />
      </prod>
      <prod vendor="microsoft" name="windows_98se">
        <vers num="" />
      </prod>
      <prod vendor="microsoft" name="windows_me">
        <vers num="" edition=":second_edition" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0598" published="2004-11-23" name="CVE-2004-0598" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The png_handle_iCCP function in libpng 1.2.5 and earlier allows remote attackers to cause a denial of service (application crash) via a certain PNG image that triggers a null dereference.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA04-217A.html" source="CERT" adv="1">TA04-217A</ref>
      <ref url="http://www.kb.cert.org/vuls/id/236656" source="CERT-VN" adv="1">VU#236656</ref>
      <ref url="https://bugzilla.fedora.us/show_bug.cgi?id=1943" source="FEDORA" patch="1">FLSA:1943</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/16895" source="XF" patch="1" adv="1">libpng-pnghandleiccp-dos(16895)</ref>
      <ref url="http://www.securityfocus.com/bid/10857" source="BID" patch="1" adv="1">10857</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2004_23_libpng.html" source="SUSE" patch="1" adv="1">SUSE-SA:2004:023</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200408-22.xml" source="GENTOO" patch="1" adv="1">GLSA-200408-22</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200408-03.xml" source="GENTOO" patch="1" adv="1">GLSA-200408-03</ref>
      <ref url="http://www.debian.org/security/2004/dsa-536" source="DEBIAN" patch="1" adv="1">DSA-536</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109761239318458&amp;w=2" source="SCO" patch="1" adv="1">SCOSA-2004.16</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109181639602978&amp;w=2" source="HP" patch="1" adv="1">SSRT4778</ref>
      <ref url="http://www.trustix.net/errata/2004/0040/" source="TRUSTIX" adv="1">2004-0040</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-429.html" source="REDHAT" adv="1">RHSA-2004:429</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-402.html" source="REDHAT" adv="1">RHSA-2004:402</ref>
      <ref url="http://www.mozilla.org/projects/security/known-vulnerabilities.html" source="CONFIRM">http://www.mozilla.org/projects/security/known-vulnerabilities.html</ref>
      <ref url="http://scary.beasts.org/security/CESA-2004-001.txt" source="MISC" adv="1">http://scary.beasts.org/security/CESA-2004-001.txt</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10203" source="OVAL">oval:org.mitre.oval:def:10203</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109163866717909&amp;w=2" source="BUGTRAQ">20040804 [OpenPKG-SA-2004.035] OpenPKG Security Advisory (png)</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000856" source="CONECTIVA">CLA-2004:856</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:213" source="MANDRIVA">MDKSA-2006:213</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:212" source="MANDRIVA">MDKSA-2006:212</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2004:079" source="MANDRAKE">MDKSA-2004:079</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-66-200663-1" source="SUNALERT">200663</ref>
      <ref url="http://secunia.com/advisories/22958" source="SECUNIA">22958</ref>
      <ref url="http://secunia.com/advisories/22957" source="SECUNIA">22957</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2572" source="OVAL" sig="1">oval:org.mitre.oval:def:2572</ref>
    </refs>
    <vuln_soft>
      <prod vendor="greg_roelofs" name="libpng">
        <vers prev="1" num="1.2.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0599" published="2004-11-23" name="CVE-2004-0599" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Multiple integer overflows in the (1) png_read_png in pngread.c or (2) png_handle_sPLT functions in pngrutil.c or (3) progressive display image reading capability in libpng 1.2.5 and earlier allow remote attackers to cause a denial of service (application crash) via a malformed PNG image.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA04-217A.html" source="CERT" adv="1">TA04-217A</ref>
      <ref url="http://www.kb.cert.org/vuls/id/477512" source="CERT-VN" adv="1">VU#477512</ref>
      <ref url="http://www.kb.cert.org/vuls/id/286464" source="CERT-VN" adv="1">VU#286464</ref>
      <ref url="http://www.kb.cert.org/vuls/id/160448" source="CERT-VN" adv="1">VU#160448</ref>
      <ref url="https://bugzilla.fedora.us/show_bug.cgi?id=1943" source="FEDORA" patch="1">FLSA:1943</ref>
      <ref url="http://www.securityfocus.com/bid/10857" source="BID" patch="1" adv="1">10857</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2004_23_libpng.html" source="SUSE" patch="1" adv="1">SUSE-SA:2004:023</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200408-22.xml" source="GENTOO" patch="1" adv="1">GLSA-200408-22</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200408-03.xml" source="GENTOO" patch="1" adv="1">GLSA-200408-03</ref>
      <ref url="http://www.debian.org/security/2004/dsa-571" source="DEBIAN" patch="1" adv="1">DSA-571</ref>
      <ref url="http://www.debian.org/security/2004/dsa-570" source="DEBIAN" patch="1" adv="1">DSA-570</ref>
      <ref url="http://www.debian.org/security/2004/dsa-536" source="DEBIAN" patch="1" adv="1">DSA-536</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109900315219363&amp;w=2" source="FEDORA" patch="1" adv="1">FLSA:2089</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109761239318458&amp;w=2" source="SCO" patch="1" adv="1">SCOSA-2004.16</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109181639602978&amp;w=2" source="HP" patch="1" adv="1">SSRT4778</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109163866717909&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20040804 [OpenPKG-SA-2004.035] OpenPKG Security Advisory (png)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/16896" source="XF" adv="1">lilbpng-integer-bo(16896)</ref>
      <ref url="http://www.trustix.net/errata/2004/0040/" source="TRUSTIX" adv="1">2004-0040</ref>
      <ref url="http://www.securityfocus.com/bid/15495" source="BID">15495</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-429.html" source="REDHAT" adv="1">RHSA-2004:429</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-421.html" source="REDHAT" adv="1">RHSA-2004:421</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-402.html" source="REDHAT" adv="1">RHSA-2004:402</ref>
      <ref url="http://www.mozilla.org/projects/security/known-vulnerabilities.html" source="CONFIRM">http://www.mozilla.org/projects/security/known-vulnerabilities.html</ref>
      <ref url="http://scary.beasts.org/security/CESA-2004-001.txt" source="MISC" adv="1">http://scary.beasts.org/security/CESA-2004-001.txt</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10938" source="OVAL">oval:org.mitre.oval:def:10938</ref>
      <ref url="http://lists.apple.com/mhonarc/security-announce/msg00056.html" source="APPLE">APPLE-SA-2004-09-09</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000856" source="CONECTIVA">CLA-2004:856</ref>
      <ref url="ftp://ftp.sco.com/pub/updates/OpenServer/SCOSA-2005.49/SCOSA-2005.49.txt" source="SCO">SCOSA-2005.49</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:213" source="MANDRIVA">MDKSA-2006:213</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:212" source="MANDRIVA">MDKSA-2006:212</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2004:079" source="MANDRAKE">MDKSA-2004:079</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-66-200663-1" source="SUNALERT">200663</ref>
      <ref url="http://secunia.com/advisories/22958" source="SECUNIA">22958</ref>
      <ref url="http://secunia.com/advisories/22957" source="SECUNIA">22957</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1479" source="OVAL" sig="1">oval:org.mitre.oval:def:1479</ref>
    </refs>
    <vuln_soft>
      <prod vendor="greg_roelofs" name="libpng">
        <vers prev="1" num="1.2.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0600" published="2004-07-27" name="CVE-2004-0600" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Buffer overflow in the Samba Web Administration Tool (SWAT) in Samba 3.0.2 to 3.0.4 allows remote attackers to execute arbitrary code via an invalid base-64 character during HTTP basic authentication.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-259.html" source="REDHAT" patch="1" adv="1">RHSA-2004:259</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109052647928375&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20040722 Samba 3.x swat preauthentication buffer overflow</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/16785" source="XF" adv="1">samba-swat-base64-bo(16785)</ref>
      <ref url="http://www.trustix.org/errata/2004/0039/" source="TRUSTIX">2004-0039</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2004_22_samba.html" source="SUSE">SUSE-SA:2004:022</ref>
      <ref url="http://www.mandrakesecure.net/en/advisories/advisory.php?name=MDKSA-2004:071" source="MANDRAKE">MDKSA-2004:071</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200407-21.xml" source="GENTOO">GLSA-200407-21</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11445" source="OVAL">oval:org.mitre.oval:def:11445</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109053195818351&amp;w=2" source="BUGTRAQ">20040722 SWAT PreAuthorization PoC</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109052891507263&amp;w=2" source="BUGTRAQ">20040722 TSSA-2004-014 - samba</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109051533021376&amp;w=2" source="BUGTRAQ">20040722 [OpenPKG-SA-2004.033] OpenPKG Security Advisory (samba)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109051340810458&amp;w=2" source="BUGTRAQ">20040722 Security Release - Samba 3.0.5 and 2.2.10</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000854" source="CONECTIVA">CLA-2004:854</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000851" source="CONECTIVA">CLA-2004:851</ref>
    </refs>
    <vuln_soft>
      <prod vendor="samba" name="samba">
        <vers num="3.0.2" />
        <vers num="3.0.2a" />
        <vers num="3.0.3" />
        <vers num="3.0.4" />
      </prod>
      <prod vendor="trustix" name="secure_linux">
        <vers num="1.5" />
        <vers num="2.0" />
        <vers num="2.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0601" published="2004-12-23" name="CVE-2004-0601" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">distcc before 2.16, when running on 64-bit platforms, does not interpret IP-based access control rules correctly, which could allow remote attackers to bypass intended restrictions.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/11319" source="BID" patch="1" adv="1">11319</ref>
      <ref url="http://secunia.com/advisories/12711/" source="SECUNIA" patch="1" adv="1">12711</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/17581" source="XF" adv="1">distcc-ip-gain-privileges(17581)</ref>
      <ref url="http://distcc.samba.org/ftp/distcc/distcc-2.17.NEWS" source="CONFIRM" adv="1">http://distcc.samba.org/ftp/distcc/distcc-2.17.NEWS</ref>
    </refs>
    <vuln_soft>
      <prod vendor="distcc" name="distcc">
        <vers num="2.10" />
        <vers num="2.11" />
        <vers num="2.12" />
        <vers num="2.13" />
        <vers num="2.14" />
        <vers num="2.15" />
        <vers num="2.7" />
        <vers num="2.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2004-0602" published="2004-12-06" name="CVE-2004-0602" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">The binary compatibility mode for FreeBSD 4.x and 5.x does not properly handle certain Linux system calls, which could allow local users to access kernel memory to gain privileges or cause a system panic.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/16558" source="XF" patch="1" adv="1">freebsd-binary-information-disclosure(16558)</ref>
      <ref url="ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-04:13.linux.asc" source="FREEBSD" patch="1" adv="1">FreeBSD-SA-04:13</ref>
      <ref url="http://www.securityfocus.com/bid/10643" source="BID" adv="1">10643</ref>
    </refs>
    <vuln_soft>
      <prod vendor="freebsd" name="freebsd">
        <vers num="4.0" />
        <vers num="5.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0603" published="2004-12-06" name="CVE-2004-0603" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">gzexe in gzip 1.3.3 and earlier will execute an argument when the creation of a temp file fails instead of exiting the program, which could allow remote attackers or local users to execute arbitrary commands, a different vulnerability than CVE-1999-1332.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" other="1" admin="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/16506" source="XF" patch="1" adv="1">gzip-gzexe-tmpfile(16506)</ref>
      <ref url="http://www.securityfocus.com/bid/10603" source="BID" patch="1" adv="1">10603</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200406-18.xml" source="GENTOO" patch="1" adv="1">GLSA-200406-18</ref>
      <ref url="http://bugs.gentoo.org/show_bug.cgi?id=54890" source="CONFIRM" adv="1">http://bugs.gentoo.org/show_bug.cgi?id=54890</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gnu" name="gzip">
        <vers prev="1" num="1.3.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0604" published="2004-12-06" name="CVE-2004-0604" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The HTTP client and server in giFT-FastTrack 0.8.6 and earlier allows remote attackers to cause a denial of service (crash), possibly via an empty search query, which triggers a NULL dereference.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/16508" source="XF" patch="1" adv="1">gift-fasttrack-daemon-dos(16508)</ref>
      <ref url="http://www.securityfocus.com/bid/10604" source="BID" patch="1" adv="1">10604</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200406-19.xml" source="GENTOO" adv="1">GLSA-200406-19</ref>
      <ref url="http://secunia.com/advisories/11941/" source="SECUNIA">11941</ref>
      <ref url="http://gift-fasttrack.berlios.de/" source="CONFIRM">http://gift-fasttrack.berlios.de/</ref>
      <ref url="http://developer.berlios.de/bugs/?func=detailbug&amp;bug_id=1573&amp;group_id=809" source="MISC">http://developer.berlios.de/bugs/?func=detailbug&amp;bug_id=1573&amp;group_id=809</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gift-fasttrack" name="gift-fasttrack">
        <vers num="0.8.0" />
        <vers num="0.8.1" />
        <vers num="0.8.2" />
        <vers num="0.8.3" />
        <vers num="0.8.4" />
        <vers num="0.8.5" />
        <vers num="0.8.6" />
      </prod>
      <prod vendor="gentoo" name="linux">
        <vers num="1.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0605" published="2004-12-06" name="CVE-2004-0605" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Non-registered IRC users using (1) ircd-hybrid 7.0.1 and earlier, (2) ircd-ratbox 1.5.1 and earlier, or (3) ircd-ratbox 2.0rc6 and earlier do not have a rate-limit imposed, which could allow remote attackers to cause a denial of service by repeatedly making requests, which are slowly dequeued.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/16457" source="XF" patch="1" adv="1">ircd-parseclientqueued-dos(16457)</ref>
      <ref url="http://www.securityfocus.com/bid/10572" source="BID" patch="1" adv="1">10572</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108766803817406&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20040618 ircd-hybrid-7 / ircd-ratbox low-bandwidth DoS</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ircd-hybrid" name="ircd-hybrid">
        <vers prev="1" num="7.0.1" />
      </prod>
      <prod vendor="ircd-ratbox" name="ircd-ratbox">
        <vers prev="1" num="1.5.1" />
        <vers prev="1" num="2.0_rc6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0606" published="2004-12-06" name="CVE-2004-0606" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in Infoblox DNS One running firmware 2.4.0-8 and earlier allows remote attackers to execute arbitrary scripts as other users via the (1) CLIENTID or (2) HOSTNAME option of a DHCP request.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" other="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/16456" source="XF" patch="1" adv="1">dnsone-dhcp-report-xss(16456)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108769996925349&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20040619 Script injection in DNSONE appliance</ref>
      <ref url="http://www.securityfocus.com/bid/10573" source="BID" adv="1">10573</ref>
    </refs>
    <vuln_soft>
      <prod vendor="infoblox" name="dns_one_appliance">
        <vers num="2.4.0.8" />
        <vers num="2.4.0.8a" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0607" published="2004-12-06" name="CVE-2004-0607" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">The eay_check_x509cert function in KAME Racoon successfully verifies certificates even when OpenSSL validation fails, which could allow remote attackers to bypass authentication.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" other="1" admin="1" />
    </loss_types>
    <vuln_types>
      <access />
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/16414" source="XF" patch="1" adv="1">racoon-eaycheckx509cert-auth-bypass(16414)</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200406-17.xml" source="GENTOO" patch="1" adv="1">GLSA-200406-17</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108731967126033&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20040615 Re: authentication bug in KAME's racoon</ref>
      <ref url="http://www.securityfocus.com/bid/10546" source="BID" adv="1">10546</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-308.html" source="REDHAT">RHSA-2004:308</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9163" source="OVAL">oval:org.mitre.oval:def:9163</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108726102304507&amp;w=2" source="BUGTRAQ" adv="1">20040614 authentication bug in KAME's racoon</ref>
      <ref url="ftp://ftp.sco.com/pub/updates/UnixWare/SCOSA-2005.10/SCOSA-2005.10.txt" source="SCO">SCOSA-2005.10</ref>
      <ref url="http://www.osvdb.org/7113" source="OSVDB">7113</ref>
      <ref url="http://sourceforge.net/project/shownotes.php?release_id=245982" source="CONFIRM">http://sourceforge.net/project/shownotes.php?release_id=245982</ref>
      <ref url="http://securitytracker.com/id?1010495" source="SECTRACK">1010495</ref>
      <ref url="http://secunia.com/advisories/11877" source="SECUNIA">11877</ref>
      <ref url="http://secunia.com/advisories/11863" source="SECUNIA">11863</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ipsec-tools" name="ipsec-tools">
        <vers num="0.3" />
        <vers num="0.3.1" />
        <vers num="0.3.2" />
        <vers num="0.3_rc1" />
        <vers num="0.3_rc2" />
        <vers num="0.3_rc3" />
        <vers num="0.3_rc4" />
        <vers num="0.3_rc5" />
      </prod>
      <prod vendor="kame" name="racoon">
        <vers num="2003-07-11" />
        <vers num="2004-04-05" />
        <vers num="2004-04-07b" />
        <vers num="2004-05-03" />
      </prod>
      <prod vendor="redhat" name="enterprise_linux">
        <vers num="3.0" edition="" />
        <vers num="3.0" edition=":workstation" />
        <vers num="3.0" edition=":advanced_servers" />
        <vers num="3.0" edition=":enterprise_server" />
      </prod>
      <prod vendor="redhat" name="enterprise_linux_desktop">
        <vers num="3.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0608" published="2004-12-06" name="CVE-2004-0608" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">The Unreal Engine, as used in DeusEx 1.112fm and earlier, Devastation 390 and earlier, Mobile Forces 20000 and earlier, Nerf Arena Blast 1.2 and earlier, Postal 2 1337 and earlier, Rune 107 and earlier, Tactical Ops 3.4.0 and earlier, Unreal 1 226f and earlier, Unreal II XMP 7710 and earlier, Unreal Tournament 451b and earlier, Unreal Tournament 2003 2225 and earlier, Unreal Tournament 2004 before 3236, Wheel of Time 333b and earlier, and X-com Enforcer, allows remote attackers to execute arbitrary code via a UDP packet containing a secure query with a long value, which overwrites memory.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" other="1" admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/16451" source="XF" patch="1" adv="1">unreal-secure-query-command-execute(16451)</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200407-14.xml" source="GENTOO" patch="1" adv="1">GLSA-200407-14</ref>
      <ref url="http://www.securityfocus.com/bid/10570" source="BID" adv="1">10570</ref>
      <ref url="http://aluigi.altervista.org/adv/unsecure-adv.txt" source="MISC" adv="1">http://aluigi.altervista.org/adv/unsecure-adv.txt</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108787105023304&amp;w=2" source="BUGTRAQ">20040618 Code execution in the Unreal Engine through \secure\ packet</ref>
    </refs>
    <vuln_soft>
      <prod vendor="arush" name="devastation">
        <vers num="390.0" />
      </prod>
      <prod vendor="dreamforge" name="tnn_outdoors_pro_hunter">
        <vers num="" />
      </prod>
      <prod vendor="epic_games" name="unreal_engine">
        <vers num="226f" />
        <vers num="433" />
        <vers num="436" />
      </prod>
      <prod vendor="epic_games" name="unreal_tournament">
        <vers num="451b" />
      </prod>
      <prod vendor="epic_games" name="unreal_tournament_2003">
        <vers num="2199_linux" />
        <vers num="2199_macos" />
        <vers num="2199_win32" />
        <vers num="2225_macos" />
        <vers num="2225_win32" />
      </prod>
      <prod vendor="epic_games" name="unreal_tournament_2004">
        <vers num="macos" />
        <vers num="win32" />
      </prod>
      <prod vendor="infogrames" name="tacticalops">
        <vers num="3.4" />
      </prod>
      <prod vendor="infogrames" name="x-com_enforcer">
        <vers num="" />
      </prod>
      <prod vendor="ion_storm" name="deusex">
        <vers num="1.112_fm" />
      </prod>
      <prod vendor="nerf_arena_blast" name="nerf_arena_blast">
        <vers num="1.2" />
      </prod>
      <prod vendor="rage_software" name="mobile_forces">
        <vers num="20000.0" />
      </prod>
      <prod vendor="robert_jordan" name="wheel_of_time">
        <vers num="333.0b" />
      </prod>
      <prod vendor="running_with_scissors" name="postal_2">
        <vers num="1337" />
      </prod>
      <prod vendor="gentoo" name="linux">
        <vers num="1.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0609" published="2004-12-06" name="CVE-2004-0609" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">rssh 2.0 through 2.1.x expands command line arguments before entering a chroot jail, which allows remote authenticated users to determine the existence of files in a directory outside the jail.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <access />
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/16470" source="XF" patch="1" adv="1">rssh-jail-obtain-info(16470)</ref>
      <ref url="http://www.securityfocus.com/bid/10574" source="BID" patch="1" adv="1">10574</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108787373022844&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20040619 Security flaw in rssh</ref>
    </refs>
    <vuln_soft>
      <prod vendor="rssh" name="rssh">
        <vers num="2.0" />
        <vers num="2.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0610" published="2004-12-06" name="CVE-2004-0610" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The Web administration interface in Microsoft MN-500 Wireless Router allows remote attackers to cause a denial of service (connection refusal) via a large number of open HTTP connections.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <design />
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/16448" source="XF" adv="1">mn500-web-admin-dos(16448)</ref>
      <ref url="http://www.securityfocus.com/bid/10585" source="BID" adv="1">10585</ref>
      <ref url="http://www.kurczaba.com/securityadvisories/0406213.htm" source="MISC" adv="1">http://www.kurczaba.com/securityadvisories/0406213.htm</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108796481501258&amp;w=2" source="BUGTRAQ" adv="1">20040621 Microsoft MN-500 Wireless Router Web-Based Administration DoS</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="mn-500_wireless_base_station">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0611" published="2004-12-06" name="CVE-2004-0611" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Web-Based Administration in Netgear FVS318 VPN Router allows remote attackers to cause a denial of service (no new connections) via a large number of open HTTP connections.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <design />
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/16462" source="XF" adv="1">netgear-fvs318-dos(16462)</ref>
      <ref url="http://www.securityfocus.com/bid/10585" source="BID" adv="1">10585</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108787199201059&amp;w=2" source="BUGTRAQ" adv="1">20040621 NETGEAR FVS318 Web-Based Administration DoS</ref>
    </refs>
    <vuln_soft>
      <prod vendor="netgear" name="fvs318">
        <vers num="1.0" />
        <vers num="1.1" />
        <vers num="1.2" />
        <vers num="1.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0612" published="2004-12-06" name="CVE-2004-0612" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_score="5.1" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="4.9" CVSS_base_score="5.1">
    <desc>
      <descript source="cve">The Mobile Code filter in ZoneAlarm Pro 5.0.590.015 does not filter mobile code within an SSL encrypted session, which could allow remote attackers to bypass the mobile code filtering.  NOTE: it has been disputed by the vendor that this behavior is required by the SSL specification.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <other />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/16471" source="XF" adv="1">zonealarm-mobile-code-bypass(16471)</ref>
      <ref url="http://www.securityfocus.com/bid/10584" source="BID">10584</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108786444608208&amp;w=2" source="BUGTRAQ" adv="1">20040621 ZoneAlarm Pro 'Mobile Code' Bypass Vulnerability</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2004-06/0420.html" source="BUGTRAQ" adv="1">20040625 Zone Labs response to "ZoneAlarm Pro 'Mobile Code' Bypass Vulnerability"</ref>
    </refs>
    <vuln_soft>
      <prod vendor="zonelabs" name="zonealarm">
        <vers num="5.0.590.015" edition="" />
        <vers num="5.0.590.015" edition=":pro" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0613" published="2004-12-06" name="CVE-2004-0613" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">osTicket allows remote attackers to view sensitive uploaded files and possibly execute arbitrary code via an HTTP request that uploads a PHP file to the ticket attachments directory.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <design />
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/10586" source="BID" patch="1" adv="1">10586</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108786779500957&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20040621 Multiple osTicket exploits!</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/16478" source="XF" adv="1">osticket-view-attachments(16478)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/16477" source="XF" adv="1">osticket-php-file-upload(16477)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="osticket" name="osticket_sts">
        <vers num="1.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0614" published="2004-12-06" name="CVE-2004-0614" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:P)" CVSS_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_base_score="6.4">
    <desc>
      <descript source="cve">osTicket trusts a hidden form field in the submit form to limit the upload size of a document, which could allow remote attackers to upload a file of any size.</descript>
    </desc>
    <loss_types>
      <avail />
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108786779500957&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20040621 Multiple osTicket exploits!</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/16477" source="XF" adv="1">osticket-php-file-upload(16477)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="osticket" name="osticket_sts">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0615" published="2004-12-06" name="CVE-2004-0615" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_score="5.1" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="4.9" CVSS_base_score="5.1">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in D-Link DI-614+ SOHO router running firmware 2.30, and DI-704 SOHO router running firmware 2.60B2, and DI-624, allows remote attackers to inject arbitrary script or HTML via the DHCP HOSTNAME option in a DHCP request.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <design />
      <env />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/16468" source="XF" adv="1">dlink614-dhcp-xss(16468)</ref>
      <ref url="http://securitytracker.com/id?1010562" source="SECTRACK">1010562</ref>
      <ref url="http://www.securityfocus.com/bid/10587" source="BID">10587</ref>
      <ref url="http://www.osvdb.org/7211" source="OSVDB">7211</ref>
      <ref url="http://secunia.com/advisories/11919" source="SECUNIA">11919</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108797273127182&amp;w=2" source="BUGTRAQ">20040621 DLINK 704, script injection vulnerability</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108786257609932&amp;w=2" source="BUGTRAQ">20040621 DLINK 614+, script injection vulnerability</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2004-07/0014.html" source="BUGTRAQ">20040701 DLINK 624, script injection vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="d-link" name="di-614+">
        <vers num="2.30" />
      </prod>
      <prod vendor="d-link" name="di-624">
        <vers prev="1" num="1.28" />
      </prod>
      <prod vendor="d-link" name="di-704p">
        <vers num="2.60b2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0616" published="2004-12-06" name="CVE-2004-0616" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The BT Voyager 2000 Wireless ADSL Router has a default public SNMP community name, which allows remote attackers to obtain sensitive information such as the password, which is stored in plaintext.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108794963119034&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20040622 Wireless Modem (BT Voyager 2000 Wireless ADSL Router cleartext password)</ref>
      <ref url="http://archives.neohapsis.com/archives/fulldisclosure/2004-06/0710.html" source="FULLDISC" patch="1" adv="1">20040622 Wireless Modem (BT Voyager 2000 Wireless ADSL Router cleartext password)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/16472" source="XF" adv="1">bt-voyager-password-plaintext(16472)</ref>
      <ref url="http://www.securityfocus.com/bid/10589" source="BID" adv="1">10589</ref>
    </refs>
    <vuln_soft>
      <prod vendor="bt" name="voyager_2000_wireless_adsl_router">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0617" published="2004-12-06" name="CVE-2004-0617" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in ArbitroWeb 0.6 allows remote attackers to inject arbitrary script or HTML via the rawURL parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/16481" source="XF">arbitroweb-rawurl-xss(16481)</ref>
      <ref url="http://www.securityfocus.com/bid/10592" source="BID">10592</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108794392303244&amp;w=2" source="BUGTRAQ" adv="1">20040622 ArbitroWeb v0.6 Javascript injection vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="arbitroweb" name="arbitroweb">
        <vers num="0.5" />
        <vers num="0.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2004-0618" published="2004-12-06" name="CVE-2004-0618" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">FreeBSD 5.1 for the Alpha processor allows local users to cause a denial of service (crash) via an execve system call with an unaligned memory address as an argument.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/10596" source="BID" patch="1" adv="1">10596</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108816603102865&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20040623 Security Advisory : FreeBSD local DoS</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/16499" source="XF" adv="1">freebsd-execve-dos(16499)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="freebsd" name="freebsd">
        <vers num="4.10" edition="release" />
        <vers num="5.1" edition="alpha" />
        <vers num="5.1" edition="release" />
        <vers num="5.1" edition="release_p5" />
        <vers num="5.1" edition="releng" />
        <vers num="5.2.1" edition="release" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0619" published="2004-12-06" name="CVE-2004-0619" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Integer overflow in the ubsec_keysetup function for Linux Broadcom 5820 cryptonet driver allows local users to cause a denial of service (crash) and possibly execute arbitrary code via a negative add_dsa_buf_bytes variable, which leads to a buffer overflow.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" other="1" admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
      <exception />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/16459" source="XF" patch="1" adv="1">bcm5820-adddsabufbytes-integer-bo(16459)</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-549.html" source="REDHAT" patch="1" adv="1">RHSA-2004:549</ref>
      <ref url="http://www.securityfocus.com/bid/10599" source="BID" adv="1">10599</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-283.html" source="REDHAT">RHSA-2005:283</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9773" source="OVAL">oval:org.mitre.oval:def:9773</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108802653409053&amp;w=2" source="BUGTRAQ" adv="1">20040623 Linux Broadcom 5820 Cryptonet Driver Integer Overflow</ref>
      <ref url="http://www.ciac.org/ciac/bulletins/p-047.shtml" source="CIAC">P-047</ref>
      <ref url="http://secunia.com/advisories/11936" source="SECUNIA">11936</ref>
    </refs>
    <vuln_soft>
      <prod vendor="redhat" name="kernel">
        <vers num="2.4.20-8" edition="" />
        <vers num="2.4.20-8" edition=":i586" />
        <vers num="2.4.20-8" edition=":i686_smp" />
        <vers num="2.4.20-8" edition=":athlon" />
        <vers num="2.4.20-8" edition=":i386_src" />
        <vers num="2.4.20-8" edition=":i386" />
        <vers num="2.4.20-8" edition=":i686" />
        <vers num="2.4.20-8" edition=":i586_smp" />
        <vers num="2.4.20-8" edition=":athlon_smp" />
      </prod>
      <prod vendor="redhat" name="fedora_core">
        <vers num="core_1.0" />
      </prod>
      <prod vendor="redhat" name="linux">
        <vers num="8.0" edition="" />
        <vers num="8.0" edition=":i386" />
        <vers num="8.0" edition=":i686" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0620" published="2004-12-06" name="CVE-2004-0620" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in (1) newreply.php or (2) newthread.php in vBulletin 3.0.1 allows remote attackers to inject arbitrary HTML or script as other users via the Edit-panel.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/16502" source="XF" adv="1">vbulletin-newreply-newthread-xss(16502)</ref>
      <ref url="http://www.securityfocus.com/bid/10602" source="BID" adv="1">10602</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108809720026642&amp;w=2" source="BUGTRAQ">20040624 vBulletin HTML Injection Vuln</ref>
    </refs>
    <vuln_soft>
      <prod vendor="jelsoft" name="vbulletin">
        <vers num="3.0.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0621" published="2004-12-06" name="CVE-2004-0621" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">admin.php in Newsletter ZWS allows remote attackers to gain administrative privileges via a list_user operation with the ulevel parameter set to 1 (administrator level), which lists all users and their passwords.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" other="1" admin="1" />
    </loss_types>
    <vuln_types>
      <env />
      <config />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/16507" source="XF" adv="1">zws-gain-admin-access(16507)</ref>
      <ref url="http://www.securityfocus.com/bid/10605" source="BID" adv="1">10605</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108811585025216&amp;w=2" source="BUGTRAQ" adv="1">20040624 ZWS Newsletter &amp; Mailing List Manager</ref>
    </refs>
    <vuln_soft>
      <prod vendor="zaireweb_solutions" name="newsletter_zws">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2004-0622" published="2004-12-06" name="CVE-2004-0622" modified="2010-12-28" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">Apple Mac OS X 10.3.4, 10.4, 10.5, and possibly other versions does not properly clear memory for login (aka Loginwindow.app), Keychain, or FileVault passwords, which could allow the root user or an attacker with physical access to obtain sensitive information by reading memory.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/16557" source="XF" adv="1">macos-memory-view-passwords(16557)</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/488948/100/100/threaded" source="BUGTRAQ">20080229 Re: Loginwindow.app and Mac OS X</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/488930/100/100/threaded" source="BUGTRAQ">20080228 Loginwindow.app and Mac OS X</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108819559925981&amp;w=2" source="BUGTRAQ" adv="1">20040625 Mac OS X stores login/Keychain/FileVault passwords on disk</ref>
      <ref url="http://citp.princeton.edu/pub/coldboot.pdf" source="MISC">http://citp.princeton.edu/pub/coldboot.pdf</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.3.4" />
        <vers num="10.4" />
        <vers num="10.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0623" published="2004-12-06" name="CVE-2004-0623" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Format string vulnerability in misc.c in GNU GNATS 4.00 may allow remote attackers to execute arbitrary code via format string specifiers in a string that gets logged by syslog.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" admin="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/10609" source="BID" patch="1" adv="1">10609</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/16517" source="XF" adv="1">gnats-format-string(16517)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108820000823191&amp;w=2" source="BUGTRAQ" adv="1">20040625 format string vulnerability in Gnats</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gnu" name="gnats">
        <vers num="3.0_02" />
        <vers num="3.113" />
        <vers num="3.113.1" />
        <vers num="3.113.1.6" />
        <vers num="3.14b" />
        <vers num="3.2" />
        <vers num="4.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0624" published="2004-12-06" name="CVE-2004-0624" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">PHP remote file inclusion vulnerability in index.php for Artmedic links 5.0 (artmedic_links5) allows remote attackers to execute arbitrary PHP code by modifying the id parameter to reference a URL on a remote web server that contains the code.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/16518" source="XF" adv="1">artmedic-url-file-disclosure(16518)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108820257812904&amp;w=2" source="BUGTRAQ" adv="1">20040625 artmedic_links5 PHP Script (include path) vuln</ref>
    </refs>
    <vuln_soft>
      <prod vendor="artmedic_webdesign" name="artmedic_links">
        <vers num="5.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0625" published="2004-12-06" name="CVE-2004-0625" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in Infinity WEB 1.0 allows remote attackers to bypass authentication and gain privileges via the login page.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <access />
      <input />
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/16513" source="XF" patch="1" adv="1">infinity-web-sql-injection(16513)</ref>
      <ref url="http://www.zone-h.org/en/advisories/read/id=4892/" source="MISC" patch="1" adv="1">http://www.zone-h.org/en/advisories/read/id=4892/</ref>
      <ref url="http://www.securityfocus.com/bid/10614" source="BID" patch="1" adv="1">10614</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108844087931959&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20040627 ZH2004-14SA (security advisory):Sql Injection in Infinity WEB</ref>
      <ref url="http://archives.neohapsis.com/archives/fulldisclosure/2004-06/0893.html" source="FULLDISC" patch="1" adv="1">20040627 ZH2004-14SA (security advisory):Sql Injection in Infinity WEB</ref>
    </refs>
    <vuln_soft>
      <prod vendor="websoft" name="infinity_web">
        <vers num="1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0626" published="2004-12-06" name="CVE-2004-0626" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The tcp_find_option function of the netfilter subsystem in Linux kernel 2.6, when using iptables and TCP options rules, allows remote attackers to cause a denial of service (CPU consumption by infinite loop) via a large option length that produces a negative integer after a casting operation to the char type.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/16554" source="XF" patch="1" adv="1">linux-tcpfindoption-dos(16554)</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200407-12.xml" source="GENTOO" patch="1" adv="1">GLSA-200407-12</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108861141304495&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20040630 Remote DoS vulnerability in Linux kernel 2.6.x</ref>
      <ref url="http://lwn.net/Articles/91964/" source="FEDORA" patch="1" adv="1">FEDORA-2004-202</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000852" source="CONECTIVA" patch="1" adv="1">CLA-2004:852</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2004_20_kernel.html" source="SUSE">SUSE-SA:2004:020</ref>
    </refs>
    <vuln_soft>
      <prod vendor="conectiva" name="linux">
        <vers num="10" />
      </prod>
      <prod vendor="gentoo" name="linux">
        <vers num="" />
      </prod>
      <prod vendor="linux" name="linux_kernel">
        <vers num="2.6.0" />
      </prod>
      <prod vendor="suse" name="suse_linux">
        <vers num="8.0" />
        <vers num="8.1" />
        <vers num="8.2" />
        <vers num="9.0" />
        <vers num="9.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0627" published="2004-12-06" name="CVE-2004-0627" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">The check_scramble_323 function in MySQL 4.1.x before 4.1.3, and 5.0, allows remote attackers to bypass authentication via a zero-length scrambled string.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" other="1" admin="1" />
    </loss_types>
    <vuln_types>
      <access />
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/184030" source="CERT-VN" patch="1" adv="1">VU#184030</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108904917528205&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20040705 MySQL Authentication Bypass</ref>
      <ref url="http://archives.neohapsis.com/archives/vulnwatch/2004-q3/0001.html" source="VULNWATCH" patch="1" adv="1">20040705 MySQL Authentication Bypass</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mysql" name="mysql">
        <vers num="4.1" />
        <vers num="5.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0628" published="2004-12-06" name="CVE-2004-0628" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Stack-based buffer overflow in MySQL 4.1.x before 4.1.3, and 5.0, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long scramble string.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" other="1" admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/645326" source="CERT-VN" patch="1" adv="1">VU#645326</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/16612" source="XF" patch="1" adv="1">mysql-myrnd-bo(16612)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108904917528205&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20040705 MySQL Authentication Bypass</ref>
      <ref url="http://archives.neohapsis.com/archives/vulnwatch/2004-q3/0001.html" source="VULNWATCH" patch="1" adv="1">20040705 MySQL Authentication Bypass</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mysql" name="mysql">
        <vers num="4.1" />
        <vers num="5.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0629" published="2004-09-28" name="CVE-2004-0629" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in the ActiveX component (pdf.ocx) for Adobe Acrobat 5.0.5 and Acrobat Reader, and possibly other versions, allows remote attackers to execute arbitrary code via a URI for a PDF file with a null terminator (%00) followed by a long string.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/10947" source="BID" patch="1" adv="1">10947</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200408-14.xml" source="GENTOO" patch="1" adv="1">GLSA-200408-14</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/16998" source="XF">acrobat-reader-activex-bo(16998)</ref>
      <ref url="http://www.adobe.com/support/techdocs/330527.html" source="CONFIRM">http://www.adobe.com/support/techdocs/330527.html</ref>
      <ref url="http://www.idefense.com/application/poi/display?id=126&amp;type=vulnerabilities" source="IDEFENSE">20040813 Adobe Acrobat/Acrobat Reader ActiveX Control Buffer Overflow Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="adobe" name="acrobat">
        <vers num="5.0" />
        <vers num="5.0.5" />
        <vers num="6.0" />
        <vers num="6.0.1" />
        <vers num="6.0.2" />
      </prod>
      <prod vendor="adobe" name="acrobat_reader">
        <vers num="5.0" />
        <vers num="5.0.5" />
        <vers num="5.1" />
        <vers num="6.0" />
        <vers num="6.0.1" />
        <vers num="6.0.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0630" published="2004-08-18" name="CVE-2004-0630" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">The uudecoding feature in Adobe Acrobat Reader 5.0.5 and 5.0.6 for Unix and Linux, and possibly other versions including those before 5.0.9, allows remote attackers to execute arbitrary code via shell metacharacters ("`" or backtick) in the filename of the PDF file that is provided to the uudecode command.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" admin="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/10931" source="BID" patch="1" adv="1">10931</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/16973" source="XF" adv="1">acrobat-reader-execute-code(16973)</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-432.html" source="REDHAT">RHSA-2004:432</ref>
      <ref url="http://www.adobe.com/support/techdocs/322914.html" source="CONFIRM">http://www.adobe.com/support/techdocs/322914.html</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200408-14.xml" source="GENTOO" adv="1">GLSA-200408-14</ref>
      <ref url="http://www.idefense.com/application/poi/display?id=124&amp;type=vulnerabilities" source="IDEFENSE">20040812 Adobe Acrobat Reader (Unix) Shell Metacharacter Code Execution Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="adobe" name="acrobat_reader">
        <vers num="5.0" />
        <vers num="5.0.5" />
        <vers num="5.0.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0631" published="2004-08-18" name="CVE-2004-0631" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Buffer overflow in the uudecoding feature for Adobe Acrobat Reader 5.0.5 and 5.0.6 for Unix and Linux, and possibly other versions including those before 5.0.9, allows remote attackers to execute arbitrary code via a long filename for the PDF file that is provided to the uudecode command.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/16972" source="XF" adv="1">adobe-acrobat-uudecode-bo(16972)</ref>
      <ref url="http://www.securityfocus.com/bid/10932" source="BID" adv="1">10932</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-432.html" source="REDHAT">RHSA-2004:432</ref>
      <ref url="http://www.adobe.com/support/techdocs/322914.html" source="CONFIRM">http://www.adobe.com/support/techdocs/322914.html</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200408-14.xml" source="GENTOO" adv="1">GLSA-200408-14</ref>
      <ref url="http://www.idefense.com/application/poi/display?id=125&amp;type=vulnerabilities" source="IDEFENSE">20040812 Adobe Acrobat Reader (Unix) 5.0 Uudecode Filename Buffer Overflow Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="adobe" name="acrobat_reader">
        <vers num="5.0" />
        <vers num="5.0.5" />
        <vers num="5.0.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0632" published="2004-07-27" name="CVE-2004-0632" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Adobe Reader 6.0 does not properly handle null characters when splitting a filename path into components, which allows remote attackers to execute arbitrary code via a file with a long extension that is not normally handled by Reader, triggering a buffer overflow.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/16667" source="XF" adv="1">adobe-acrobat-null-bo(16667)</ref>
      <ref url="http://www.adobe.com/support/techdocs/34222.htm" source="MISC">http://www.adobe.com/support/techdocs/34222.htm</ref>
      <ref url="http://www.adobe.com/support/techdocs/330527.html" source="CONFIRM">http://www.adobe.com/support/techdocs/330527.html</ref>
      <ref url="http://www.idefense.com/application/poi/display?id=116&amp;type=vulnerabilities" source="IDEFENSE">20040712 Adobe Reader 6.0 Filename Handler Buffer Overflow Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="adobe" name="acrobat">
        <vers num="6.0" />
        <vers num="6.0.1" />
      </prod>
      <prod vendor="adobe" name="acrobat_reader">
        <vers num="6.0" />
        <vers num="6.0.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0633" published="2004-12-06" name="CVE-2004-0633" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The iSNS dissector for Ethereal 0.10.3 through 0.10.4 allows remote attackers to cause a denial of service (process abort) via an integer overflow.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/829422" source="CERT-VN">VU#829422</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/16630" source="XF" patch="1" adv="1">ethereal-isns-dos(16630)</ref>
      <ref url="http://www.redhat.com/archives/fedora-announce-list/2004-July/msg00014.html" source="FEDORA" patch="1" adv="1">FEDORA-2004-220</ref>
      <ref url="http://www.redhat.com/archives/fedora-announce-list/2004-July/msg00013.html" source="FEDORA" patch="1" adv="1">FEDORA-2004-219</ref>
      <ref url="http://www.mandrakesecure.net/en/advisories/advisory.php?name=MDKSA-2004:067" source="MANDRAKE" patch="1" adv="1">MDKSA-2004:067</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200407-08.xml" source="GENTOO" patch="1" adv="1">GLSA-200407-08</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-378.html" source="REDHAT">RHSA-2004:378</ref>
      <ref url="http://www.ethereal.com/appnotes/enpa-sa-00015.html" source="CONFIRM">http://www.ethereal.com/appnotes/enpa-sa-00015.html</ref>
      <ref url="http://securitytracker.com/id?1010655" source="SECTRACK">1010655</ref>
      <ref url="http://secunia.com/advisories/12024" source="SECUNIA">12024</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9931" source="OVAL">oval:org.mitre.oval:def:9931</ref>
      <ref url="http://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=127381" source="CONFIRM">http://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=127381</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000916" source="CONECTIVA">CLA-2005:916</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ethereal_group" name="ethereal">
        <vers num="0.10.3" />
        <vers num="0.10.4" />
      </prod>
      <prod vendor="gentoo" name="linux">
        <vers num="" />
      </prod>
      <prod vendor="mandrakesoft" name="mandrake_linux">
        <vers num="10.0" />
        <vers num="9.2" />
      </prod>
      <prod vendor="redhat" name="enterprise_linux">
        <vers num="2.1" edition="" />
        <vers num="2.1" edition=":workstation" />
        <vers num="2.1" edition=":advanced_server" />
        <vers num="2.1" edition=":enterprise_server" />
        <vers num="3.0" edition="" />
        <vers num="3.0" edition=":enterprise_server" />
        <vers num="3.0" edition=":advanced_server" />
        <vers num="3.0" edition=":workstation_server" />
      </prod>
      <prod vendor="redhat" name="linux_advanced_workstation">
        <vers num="2.1" edition="" />
        <vers num="2.1" edition=":as" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0634" published="2004-12-06" name="CVE-2004-0634" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The SMB SID snooping capability in Ethereal 0.9.15 to 0.10.4 allows remote attackers to cause a denial of service (process crash) via a handle without a policy name, which causes a null dereference.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/518782" source="CERT-VN">VU#518782</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/16631" source="XF" patch="1" adv="1">ethereal-smb-sid-dos(16631)</ref>
      <ref url="http://www.redhat.com/archives/fedora-announce-list/2004-July/msg00014.html" source="FEDORA" patch="1" adv="1">FEDORA-2004-220</ref>
      <ref url="http://www.redhat.com/archives/fedora-announce-list/2004-July/msg00013.html" source="FEDORA" patch="1" adv="1">FEDORA-2004-219</ref>
      <ref url="http://www.mandrakesecure.net/en/advisories/advisory.php?name=MDKSA-2004:067" source="MANDRAKE" patch="1" adv="1">MDKSA-2004:067</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200407-08.xml" source="GENTOO" patch="1" adv="1">GLSA-200407-08</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-378.html" source="REDHAT">RHSA-2004:378</ref>
      <ref url="http://www.ethereal.com/appnotes/enpa-sa-00015.html" source="CONFIRM">http://www.ethereal.com/appnotes/enpa-sa-00015.html</ref>
      <ref url="http://securitytracker.com/id?1010655" source="SECTRACK">1010655</ref>
      <ref url="http://secunia.com/advisories/12024" source="SECUNIA">12024</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10252" source="OVAL">oval:org.mitre.oval:def:10252</ref>
      <ref url="http://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=127381" source="CONFIRM">http://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=127381</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000916" source="CONECTIVA">CLA-2005:916</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ethereal_group" name="ethereal">
        <vers num="0.10.4" />
        <vers num="0.9.15" />
      </prod>
      <prod vendor="gentoo" name="linux">
        <vers num="" />
      </prod>
      <prod vendor="mandrakesoft" name="mandrake_linux">
        <vers num="10.0" />
        <vers num="9.2" />
      </prod>
      <prod vendor="redhat" name="enterprise_linux">
        <vers num="2.1" edition="" />
        <vers num="2.1" edition=":workstation" />
        <vers num="2.1" edition=":advanced_server" />
        <vers num="2.1" edition=":enterprise_server" />
        <vers num="3.0" edition="" />
        <vers num="3.0" edition=":enterprise_server" />
        <vers num="3.0" edition=":advanced_server" />
        <vers num="3.0" edition=":workstation_server" />
      </prod>
      <prod vendor="redhat" name="linux_advanced_workstation">
        <vers num="2.1" edition="" />
        <vers num="2.1" edition=":as" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0635" published="2004-12-06" name="CVE-2004-0635" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The SNMP dissector in Ethereal 0.8.15 through 0.10.4 allows remote attackers to cause a denial of service (process crash) via a (1) malformed or (2) missing community string, which causes an out-of-bounds read.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/835846" source="CERT-VN">VU#835846</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/16632" source="XF" patch="1" adv="1">ethereal-snmp-community-dos(16632)</ref>
      <ref url="http://www.redhat.com/archives/fedora-announce-list/2004-July/msg00014.html" source="FEDORA" patch="1" adv="1">FEDORA-2004-220</ref>
      <ref url="http://www.redhat.com/archives/fedora-announce-list/2004-July/msg00013.html" source="FEDORA" patch="1" adv="1">FEDORA-2004-219</ref>
      <ref url="http://www.mandrakesecure.net/en/advisories/advisory.php?name=MDKSA-2004:067" source="MANDRAKE" patch="1" adv="1">MDKSA-2004:067</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200407-08.xml" source="GENTOO" patch="1" adv="1">GLSA-200407-08</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-378.html" source="REDHAT">RHSA-2004:378</ref>
      <ref url="http://www.ethereal.com/appnotes/enpa-sa-00015.html" source="CONFIRM">http://www.ethereal.com/appnotes/enpa-sa-00015.html</ref>
      <ref url="http://www.debian.org/security/2004/dsa-528" source="DEBIAN">DSA-528</ref>
      <ref url="http://securitytracker.com/id?1010655" source="SECTRACK">1010655</ref>
      <ref url="http://secunia.com/advisories/12024" source="SECUNIA">12024</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9721" source="OVAL">oval:org.mitre.oval:def:9721</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000916" source="CONECTIVA">CLA-2005:916</ref>
      <ref url="http://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=127381" source="CONFIRM">http://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=127381</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ethereal_group" name="ethereal">
        <vers num="0.10" />
        <vers num="0.10.1" />
        <vers num="0.10.2" />
        <vers num="0.10.3" />
        <vers num="0.10.4" />
        <vers num="0.8.15" />
        <vers num="0.8.16" />
        <vers num="0.8.17" />
        <vers num="0.8.18" />
        <vers num="0.8.19" />
        <vers num="0.9" />
        <vers num="0.9.1" />
        <vers num="0.9.10" />
        <vers num="0.9.11" />
        <vers num="0.9.12" />
        <vers num="0.9.13" />
        <vers num="0.9.14" />
        <vers num="0.9.15" />
        <vers num="0.9.16" />
        <vers num="0.9.2" />
        <vers num="0.9.3" />
        <vers num="0.9.4" />
        <vers num="0.9.5" />
        <vers num="0.9.6" />
        <vers num="0.9.7" />
        <vers num="0.9.8" />
        <vers num="0.9.9" />
      </prod>
      <prod vendor="gentoo" name="linux">
        <vers num="" />
      </prod>
      <prod vendor="mandrakesoft" name="mandrake_linux">
        <vers num="10.0" />
        <vers num="9.2" />
      </prod>
      <prod vendor="redhat" name="enterprise_linux">
        <vers num="2.1" edition="" />
        <vers num="2.1" edition=":advanced_server" />
        <vers num="2.1" edition=":enterprise_server" />
        <vers num="2.1" edition=":workstation" />
        <vers num="3.0" edition="" />
        <vers num="3.0" edition=":advanced_server" />
        <vers num="3.0" edition=":workstation_server" />
        <vers num="3.0" edition=":enterprise_server" />
      </prod>
      <prod vendor="redhat" name="linux_advanced_workstation">
        <vers num="2.1" edition="" />
        <vers num="2.1" edition=":as" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0636" published="2004-11-23" name="CVE-2004-0636" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Buffer overflow in the goaway function in the aim:goaway URI handler for AOL Instant Messenger (AIM) 5.5, including 5.5.3595, allows remote attackers to execute arbitrary code via a long Away message.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/735966" source="CERT-VN">VU#735966</ref>
      <ref url="http://www.idefense.com/application/poi/display?id=121&amp;type=vulnerabilities" source="MISC" patch="1" adv="1">http://www.idefense.com/application/poi/display?id=121&amp;type=vulnerabilities</ref>
      <ref url="http://secunia.com/advisories/12198/" source="SECUNIA" patch="1" adv="1">12198</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/16926" source="XF">aim-away-bo(16926)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="aol" name="instant_messenger">
        <vers num="5.5" />
        <vers num="5.5.3415_beta" />
        <vers num="5.5.3595" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0637" published="2004-09-02" name="CVE-2004-0637" modified="2008-09-10" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:P/A:P)" CVSS_score="6.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.0" CVSS_base_score="6.5">
    <desc>
      <descript source="cve">Oracle Database Server 8.1.7.4 through 9.2.0.4 allows local users to execute commands with additional privileges via the ctxsys.driload package, which is publicly accessible.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/316206" source="CERT-VN" patch="1" adv="1">VU#316206</ref>
      <ref url="http://www.idefense.com/application/poi/display?id=136&amp;type=vulnerabilities&amp;flashstatus=true" source="IDEFENSE" patch="1" adv="1">20040902 Oracle Database Server ctxsys.driload Access Validation Vulnerability</ref>
      <ref url="http://secunia.com/advisories/12409/" source="SECUNIA" patch="1" adv="1">12409</ref>
      <ref url="http://www.securityfocus.com/bid/11099" source="BID">11099</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="oracle8i">
        <vers num="enterprise_8.1.7_.4" />
        <vers num="standard_8.1.7_.4" />
      </prod>
      <prod vendor="oracle" name="oracle9i">
        <vers num="enterprise_9.2.0.4" />
        <vers num="personal_9.2.0.4" />
        <vers num="standard_9.0.1.3" />
        <vers num="standard_9.2.0.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0638" published="2004-12-31" name="CVE-2004-0638" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:S/C:C/I:C/A:C)" CVSS_score="8.5" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="6.8" CVSS_base_score="8.5">
    <desc>
      <descript source="cve">Buffer overflow in the KSDWRTB function in the dbms_system package (dbms_system.ksdwrt) for Oracle 9i Database Server Release 2 9.2.0.3 and 9.2.0.4, 9i Release 1 9.0.1.4 and 9.0.1.5, and 8i Release 1 8.1.7.4, allows remote authorized users to execute arbitrary code via a long second argument.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/17254" source="XF" patch="1" adv="1">oracle-dbmssystem-bo(17254)</ref>
      <ref url="http://www.securityfocus.com/bid/11100" source="BID" patch="1">11100</ref>
      <ref url="http://www.red-database-security.com/advisory/advisory_20040903_3.htm" source="MISC" patch="1" adv="1">http://www.red-database-security.com/advisory/advisory_20040903_3.htm</ref>
      <ref url="http://www.idefense.com/application/poi/display?id=135&amp;type=vulnerabilities&amp;flashstatus=false" source="IDEFENSE" patch="1" adv="1">20040902 Oracle Database Server dbms_system.ksdwrt Buffer Overflow Vulnerability</ref>
      <ref url="http://archives.neohapsis.com/archives/fulldisclosure/2004-09/0178.html" source="FULLDISC" patch="1" adv="1">20040905 Buffer Overflow in DBMS_SYSTEM.KSDWRT() in Oracle8i - 9i</ref>
      <ref url="http://www.oracle.com/technology/deploy/security/pdf/2004alert68.pdf" source="CONFIRM" adv="1">http://www.oracle.com/technology/deploy/security/pdf/2004alert68.pdf</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="oracle8i">
        <vers num="enterprise_8.1.7.4" />
        <vers num="standard_8.1.7.4" />
      </prod>
      <prod vendor="oracle" name="oracle9i">
        <vers num="enterprise_9.0.1.4" />
        <vers num="enterprise_9.0.1.5" />
        <vers num="enterprise_9.2.0.3" />
        <vers num="enterprise_9.2.0.4" />
        <vers num="personal_9.0.1.4" />
        <vers num="personal_9.0.1.5" />
        <vers num="personal_9.2.0.3" />
        <vers num="personal_9.2.0.4" />
        <vers num="standard_9.0.1.4" />
        <vers num="standard_9.0.1.5" />
        <vers num="standard_9.2.0.3" />
        <vers num="standard_9.2.0.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0639" published="2004-08-06" name="CVE-2004-0639" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in Squirrelmail 1.2.10 and earlier allow remote attackers to inject arbitrary HTML or script via (1) the $mailer variable in read_body.php, (2) the $senderNames_part variable in mailbox_display.php, and possibly other vectors including (3) the $event_title variable or (4) the $event_text variable.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/10450" source="BID" patch="1">10450</ref>
      <ref url="http://www.debian.org/security/2004/dsa-535" source="DEBIAN" patch="1" adv="1">DSA-535</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/16285" source="XF">squirrelmail-from-header-xss(16285)</ref>
      <ref url="http://www.rs-labs.com/adv/RS-Labs-Advisory-2004-1.txt" source="MISC" adv="1">http://www.rs-labs.com/adv/RS-Labs-Advisory-2004-1.txt</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108611554415078&amp;w=2" source="BUGTRAQ">20040530 RS-2004-1: SquirrelMail "Content-Type" XSS vulnerability</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000858" source="CONECTIVA">CLA-2004:858</ref>
      <ref url="http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=257973" source="CONFIRM">http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=257973</ref>
    </refs>
    <vuln_soft>
      <prod vendor="open_webmail" name="open_webmail">
        <vers num="2.30" />
        <vers num="2.31" />
        <vers num="2.32" />
      </prod>
      <prod vendor="sgi" name="propack">
        <vers num="3.0" />
      </prod>
      <prod vendor="squirrelmail" name="squirrelmail">
        <vers num="1.2.0" />
        <vers num="1.2.1" />
        <vers num="1.2.10" />
        <vers num="1.2.11" />
        <vers num="1.2.2" />
        <vers num="1.2.3" />
        <vers num="1.2.4" />
        <vers num="1.2.5" />
        <vers num="1.2.6" />
        <vers num="1.2.7" />
        <vers num="1.2.8" />
        <vers num="1.2.9" />
        <vers num="1.4" />
        <vers num="1.4.1" />
        <vers num="1.4.2" />
        <vers num="1.4.3_rc1" />
        <vers num="1.5_dev" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0640" published="2004-08-06" name="CVE-2004-0640" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Format string vulnerability in the SSL_set_verify function in telnetd.c for SSLtelnet daemon (SSLtelnetd) 0.13 allows remote attackers to execute arbitrary code.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" admin="1" />
    </loss_types>
    <vuln_types>
      <input />
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.debian.org/security/2004/dsa-529" source="DEBIAN" patch="1" adv="1">DSA-529</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/16653" source="XF" adv="1">ssltelnetd-format-string(16653)</ref>
      <ref url="http://www.idefense.com/application/poi/display?id=114&amp;type=vulnerabilities" source="MISC">http://www.idefense.com/application/poi/display?id=114&amp;type=vulnerabilities</ref>
    </refs>
    <vuln_soft>
      <prod vendor="netkit" name="linux_netkit">
        <vers num="0.17" />
        <vers num="0.17.17" />
      </prod>
      <prod vendor="ssltelnetd" name="secure_telnet">
        <vers num="0.13.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0641" published="2004-08-05" name="CVE-2004-0641" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Thomson SpeedTouch 510 ADSL Router with firmware GV8BAA3.270, and possibly earlier versions, generates predictable TCP Initial Sequence Numbers (ISNs), which allows remote attackers to spoof or hijack TCP connections.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/16919" source="XF" adv="1">speedtouch-hijack-connection(16919)</ref>
      <ref url="http://www.securityfocus.com/bid/10881" source="BID" adv="1">10881</ref>
      <ref url="http://www.idefense.com/application/poi/display?id=120&amp;type=vulnerabilities&amp;flashstatus=true" source="IDEFENSE" adv="1">20040805 Thompson SpeedTouch Home ADSL Modem Predictable TCP ISN Generation</ref>
      <ref url="http://www.auscert.org.au/render.html?it=4299" source="AUSCERT" adv="1">ESB-2004.0504</ref>
      <ref url="http://secunia.com/advisories/12238/" source="SECUNIA" adv="1">12238</ref>
    </refs>
    <vuln_soft>
      <prod vendor="thomson" name="speedtouch">
        <vers num="510_adsl_router" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0642" published="2004-09-28" name="CVE-2004-0642" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Double free vulnerabilities in the error handling code for ASN.1 decoders in the (1) Key Distribution Center (KDC) library and (2) client library for MIT Kerberos 5 (krb5) 1.3.4 and earlier may allow remote attackers to execute arbitrary code.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA04-247A.html" source="CERT">TA04-247A</ref>
      <ref url="http://www.kb.cert.org/vuls/id/795632" source="CERT-VN">VU#795632</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/17157" source="XF" patch="1" adv="1">kerberos-kdc-double-free(17157)</ref>
      <ref url="http://www.trustix.net/errata/2004/0045/" source="TRUSTIX" patch="1" adv="1">2004-0045</ref>
      <ref url="http://www.securityfocus.com/bid/11078" source="BID">11078</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200409-09.xml" source="GENTOO" adv="1">GLSA-200409-09</ref>
      <ref url="http://www.debian.org/security/2004/dsa-543" source="DEBIAN">DSA-543</ref>
      <ref url="http://web.mit.edu/kerberos/www/advisories/MITKRB5-SA-2004-002-dblfree.txt" source="CONFIRM">http://web.mit.edu/kerberos/www/advisories/MITKRB5-SA-2004-002-dblfree.txt</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2004-350.html" source="REDHAT">RHSA-2004:350</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10709" source="OVAL">oval:org.mitre.oval:def:10709</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109508872524753&amp;w=2" source="BUGTRAQ">20040913 [OpenPKG-SA-2004.039] OpenPKG Security Advisory (kerberos)</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000860" source="CONECTIVA">CLA-2004:860</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:4936" source="OVAL" sig="1">oval:org.mitre.oval:def:4936</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mit" name="kerberos">
        <vers prev="1" num="5-1.3.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0643" published="2004-09-28" name="CVE-2004-0643" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Double free vulnerability in the krb5_rd_cred function for MIT Kerberos 5 (krb5) 1.3.1 and earlier may allow local users to execute arbitrary code.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA04-247A.html" source="CERT">TA04-247A</ref>
      <ref url="http://www.kb.cert.org/vuls/id/866472" source="CERT-VN">VU#866472</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/17159" source="XF" patch="1" adv="1">kerberos-krb5rdcred-double-free(17159)</ref>
      <ref url="http://www.trustix.net/errata/2004/0045/" source="TRUSTIX" patch="1" adv="1">2004-0045</ref>
      <ref url="http://www.securityfocus.com/bid/11078" source="BID">11078</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200409-09.xml" source="GENTOO" adv="1">GLSA-200409-09</ref>
      <ref url="http://www.debian.org/security/2004/dsa-543" source="DEBIAN">DSA-543</ref>
      <ref url="http://web.mit.edu/kerberos/www/advisories/MITKRB5-SA-2004-002-dblfree.txt" source="CONFIRM">http://web.mit.edu/kerberos/www/advisories/MITKRB5-SA-2004-002-dblfree.txt</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2004-350.html" source="REDHAT">RHSA-2004:350</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10267" source="OVAL">oval:org.mitre.oval:def:10267</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109508872524753&amp;w=2" source="BUGTRAQ">20040913 [OpenPKG-SA-2004.039] OpenPKG Security Advisory (kerberos)</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000860" source="CONECTIVA">CLA-2004:860</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:3322" source="OVAL" sig="1">oval:org.mitre.oval:def:3322</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mit" name="kerberos">
        <vers prev="1" num="5-1.3.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0644" published="2004-09-28" name="CVE-2004-0644" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The asn1buf_skiptail function in the ASN.1 decoder library for MIT Kerberos 5 (krb5) 1.2.2 through 1.3.4 allows remote attackers to cause a denial of service (infinite loop) via a certain BER encoding.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA04-247A.html" source="CERT">TA04-247A</ref>
      <ref url="http://www.kb.cert.org/vuls/id/550464" source="CERT-VN">VU#550464</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/17160" source="XF" patch="1" adv="1">kerberos-asn1-library-dos(17160)</ref>
      <ref url="http://www.trustix.net/errata/2004/0045/" source="TRUSTIX" patch="1" adv="1">2004-0045</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200409-09.xml" source="GENTOO" patch="1" adv="1">GLSA-200409-09</ref>
      <ref url="http://www.securityfocus.com/bid/11079" source="BID">11079</ref>
      <ref url="http://www.debian.org/security/2004/dsa-543" source="DEBIAN">DSA-543</ref>
      <ref url="http://web.mit.edu/kerberos/www/advisories/MITKRB5-SA-2004-003-asn1.txt" source="CONFIRM">http://web.mit.edu/kerberos/www/advisories/MITKRB5-SA-2004-003-asn1.txt</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2004-350.html" source="REDHAT">RHSA-2004:350</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10014" source="OVAL">oval:org.mitre.oval:def:10014</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109508872524753&amp;w=2" source="BUGTRAQ">20040913 [OpenPKG-SA-2004.039] OpenPKG Security Advisory (kerberos)</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000860" source="CONECTIVA">CLA-2004:860</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2139" source="OVAL" sig="1">oval:org.mitre.oval:def:2139</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mit" name="kerberos">
        <vers num="5-1.2.2" />
        <vers num="5-1.2.3" />
        <vers num="5-1.2.4" />
        <vers num="5-1.2.5" />
        <vers num="5-1.2.6" />
        <vers num="5-1.2.7" />
        <vers num="5-1.2.8" />
        <vers num="5-1.3" edition="alpha1" />
        <vers num="5-1.3.1" />
        <vers num="5-1.3.2" />
        <vers num="5-1.3.3" />
        <vers num="5-1.3.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0645" published="2004-08-06" name="CVE-2004-0645" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Buffer overflow in the wvHandleDateTimePicture function in wv library (wvWare) 0.7.4 through 0.7.6 and 1.0.0 allows remote attackers to execute arbitrary code via a document with a long DateTime field.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.idefense.com/application/poi/display?id=115&amp;type=vulnerabilities" source="IDEFENSE" patch="1" adv="1">20040709 wvWare Library Buffer Overflow Vulnerability</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200407-11.xml" source="GENTOO" patch="1" adv="1">GLSA-200407-11</ref>
      <ref url="https://bugzilla.fedora.us/show_bug.cgi?id=1906" source="FEDORA">FLSA:1906</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/16660" source="XF" adv="1">wvware-wvhandledatetimepicture-bo(16660)</ref>
      <ref url="http://www.osvdb.org/7761" source="OSVDB">7761</ref>
      <ref url="http://www.mandrakesecure.net/en/advisories/advisory.php?name=MDKSA-2004:077" source="MANDRAKE">MDKSA-2004:077</ref>
      <ref url="http://www.freebsd.org/ports/portaudit/7a5430df-d562-11d8-b479-02e0185c0b53.html" source="CONFIRM">http://www.freebsd.org/ports/portaudit/7a5430df-d562-11d8-b479-02e0185c0b53.html</ref>
      <ref url="http://www.debian.org/security/2004/dsa-579" source="DEBIAN">DSA-579</ref>
      <ref url="http://cpan.cybercomm.nl/pub/gentoo-portage/app-text/wv/files/wv-1.0.0-fix_overflow.patch" source="CONFIRM">http://cpan.cybercomm.nl/pub/gentoo-portage/app-text/wv/files/wv-1.0.0-fix_overflow.patch</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000863" source="CONECTIVA">CLA-2004:863</ref>
    </refs>
    <vuln_soft>
      <prod vendor="abisource" name="community_abiword">
        <vers num="2.0.3" />
        <vers num="2.0.4" />
        <vers num="2.0.5" />
        <vers num="2.0.6" />
        <vers num="2.0.7" />
      </prod>
      <prod vendor="wvware" name="wvware">
        <vers num="0.7.4" />
        <vers num="0.7.5" />
        <vers num="0.7.6" />
        <vers num="1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0646" published="2004-12-23" name="CVE-2004-0646" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Buffer overflow in the WriteToLog function for JRun 3.0 through 4.0 web server connectors, such as (1) mod_jrun and (2) mod_jrun20 for Apache, with verbose logging enabled, allows remote attackers to execute arbitrary code via a long HTTP header Content-Type field or other fields.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/990200" source="CERT-VN">VU#990200</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/17485" source="XF" patch="1" adv="1">coldfusion-jrun-verbose-bo(17485)</ref>
      <ref url="http://www.securityfocus.com/bid/11245" source="BID" patch="1" adv="1">11245</ref>
      <ref url="http://www.macromedia.com/devnet/security/security_zone/mpsb04-08.html" source="CONFIRM" patch="1">http://www.macromedia.com/devnet/security/security_zone/mpsb04-08.html</ref>
      <ref url="http://www.securityfocus.com/archive/1/377194" source="BUGTRAQ">20040929 iDEFENSE Security Advisory 09.29.04 - Macromedia JRun 4 mod_jrun Apache Module Buffer Overflow Vulnerability</ref>
      <ref url="http://www.macromedia.com/devnet/security/security_zone/mpsb04-09.html" source="CONFIRM">http://www.macromedia.com/devnet/security/security_zone/mpsb04-09.html</ref>
      <ref url="http://secunia.com/advisories/12647/" source="SECUNIA">12647</ref>
    </refs>
    <vuln_soft>
      <prod vendor="macromedia" name="coldfusion">
        <vers num="6.0" />
        <vers num="6.1" />
      </prod>
      <prod vendor="macromedia" name="jrun">
        <vers num="3.0" />
        <vers num="3.1" />
        <vers num="4.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0647" published="2004-08-06" name="CVE-2004-0647" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">shorewall 1.4.10c and earlier, and 2.0.x before 2.0.3a, allows local users to overwrite arbitrary files via a symlink attack on the chains-$$ temporary file.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <access />
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200407-07.xml" source="GENTOO" patch="1" adv="1">GLSA-200407-07 </ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/16651" source="XF" adv="1">shorewall-symlink(16651)</ref>
      <ref url="http://www.mandrakesecure.net/en/advisories/advisory.php?name=MDKSA-2004:080" source="MANDRAKE">MDKSA-2004:080</ref>
      <ref url="http://lists.shorewall.net/pipermail/shorewall-announce/2004-June/000385.html" source="MLIST">[Shorewall-announce] 20040628 URGENT: Shorewall Security Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="shorewall" name="shorewall">
        <vers num="1.4" />
        <vers num="1.4.1" />
        <vers num="1.4.10" />
        <vers num="1.4.2" />
        <vers num="1.4.3" />
        <vers num="1.4.3a" />
        <vers num="1.4.4" />
        <vers num="1.4.5" />
        <vers num="1.4.6" />
        <vers num="1.4.7" />
        <vers num="1.4.8" />
        <vers num="1.4.9" />
        <vers num="2.0" />
        <vers num="2.0.1" />
        <vers num="2.0.2" />
        <vers num="2.0.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0648" published="2004-08-06" name="CVE-2004-0648" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Mozilla (Suite) before 1.7.1, Firefox before 0.9.2, and Thunderbird before 0.7.2 allow remote attackers to launch arbitrary programs via a URI referencing the shell: protocol.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" admin="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/927014" source="CERT-VN" adv="1">VU#927014</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108938712815719&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20040708 Mozilla Security Advisory 2004-07-08</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/16655" source="XF" adv="1">mozilla-shell-program-execution(16655)</ref>
      <ref url="http://www.mozilla.org/security/shell.html" source="CONFIRM">http://www.mozilla.org/security/shell.html</ref>
      <ref url="http://www.mozilla.org/projects/security/known-vulnerabilities.html" source="CONFIRM">http://www.mozilla.org/projects/security/known-vulnerabilities.html</ref>
      <ref url="http://www.ciac.org/ciac/bulletins/o-175.shtml" source="CIAC">O-175</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2004-July/023573.html" source="FULLDISC">20040707 shell:windows command question</ref>
      <ref url="http://secunia.com/advisories/12027" source="SECUNIA">12027</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="firefox">
        <vers prev="1" num="0.9.2" />
      </prod>
      <prod vendor="mozilla" name="mozilla">
        <vers prev="1" num="1.7.1" />
      </prod>
      <prod vendor="mozilla" name="thunderbird">
        <vers prev="1" num="0.7.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0649" published="2004-08-06" name="CVE-2004-0649" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Buffer overflow in write_packet in control.c for l2tpd may allow remote attackers to execute arbitrary code.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.debian.org/security/2004/dsa-530" source="DEBIAN" patch="1" adv="1">DSA-530</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/16326" source="XF" adv="1">l2tpd-writepacket-bo(16326)</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200407-17.xml" source="GENTOO" adv="1">GLSA-200407-17</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108640917925735&amp;w=2" source="BUGTRAQ" adv="1">20040604 bss-based buffer overflow in l2tpd</ref>
    </refs>
    <vuln_soft>
      <prod vendor="l2tpd" name="l2tpd">
        <vers num="0.62" />
        <vers num="0.63" />
        <vers num="0.64" />
        <vers num="0.65" />
        <vers num="0.66" />
        <vers num="0.67" />
        <vers num="0.68" />
        <vers num="0.69" />
      </prod>
      <prod vendor="gentoo" name="linux">
        <vers num="1.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0650" published="2004-08-06" name="CVE-2004-0650" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">UploadServlet in Cisco Collaboration Server (CCS) running ServletExec before 3.0E allows remote attackers to upload and execute arbitrary files via a direct call to the UploadServlet URL.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" admin="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/718896" source="CERT-VN" patch="1" adv="1">VU#718896</ref>
      <ref url="http://www.securityfocus.com/bid/10639" source="BID" patch="1" adv="1">10639</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/16553" source="XF" adv="1">ccs-servletexec-gain-privileges(16553)</ref>
      <ref url="http://www.cisco.com/warp/public/707/cisco-sa-20040630-CCS.shtml" source="CISCO">20040630 Cisco Collaboration Server Vulnerability</ref>
      <ref url="http://secunia.com/advisories/11979/" source="SECUNIA">11979</ref>
    </refs>
    <vuln_soft>
      <prod vendor="newatlanta" name="servletexec">
        <vers num="2.2" />
        <vers num="3.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0651" published="2004-08-06" name="CVE-2004-0651" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Unknown vulnerability in Sun Java Runtime Environment (JRE) 1.4.2 through 1.4.2_03 allows remote attackers to cause a denial of service (virtual machine hang).</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <other />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/118558" source="CERT-VN" patch="1" adv="1">VU#118558</ref>
      <ref url="http://www.securityfocus.com/bid/10301" source="BID" patch="1" adv="1">10301</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/16085" source="XF" adv="1">sun-java-dos(16085)</ref>
      <ref url="http://www.securityfocus.com/advisories/6773" source="HP">SSRT4749</ref>
      <ref url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doc=fsalert/57555" source="SUNALERT">57555</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108559041910233&amp;w=2" source="HP">HPSBUX01044</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="jre">
        <vers num="1.4.2" edition="update3" />
      </prod>
      <prod vendor="sun" name="sdk">
        <vers num="1.4.2" />
        <vers num="1.4.2_03" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0652" published="2004-08-06" name="CVE-2004-0652" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">BEA WebLogic Server and WebLogic Express 7.0 through 7.0 Service Pack 4, and 8.1 through 8.1 Service Pack 2, allows attackers to obtain the username and password for booting the server by directly accessing certain internal methods.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/352110" source="CERT-VN" patch="1" adv="1">VU#352110</ref>
      <ref url="http://www.securityfocus.com/bid/10133" source="BID" patch="1" adv="1">10133</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15865" source="XF" adv="1">bea-gain-privileges(15865)</ref>
      <ref url="http://dev2dev.bea.com/resourcelibrary/advisoriesnotifications/BEA04_55.00.jsp" source="CONFIRM">http://dev2dev.bea.com/resourcelibrary/advisoriesnotifications/BEA04_55.00.jsp</ref>
      <ref url="http://www.osvdb.org/5296" source="OSVDB">5296</ref>
      <ref url="http://securitytracker.com/id?1009766" source="SECTRACK">1009766</ref>
      <ref url="http://secunia.com/advisories/11359" source="SECUNIA">11359</ref>
    </refs>
    <vuln_soft>
      <prod vendor="bea" name="weblogic_server">
        <vers num="7.0" edition="" />
        <vers num="7.0" edition=":win32" />
        <vers num="7.0" edition=":express" />
        <vers num="7.0" edition="sp1" />
        <vers num="7.0" edition="sp1:express" />
        <vers num="7.0" edition="sp1:win32" />
        <vers num="7.0" edition="sp2" />
        <vers num="7.0" edition="sp2:win32" />
        <vers num="7.0" edition="sp2:express" />
        <vers num="7.0" edition="sp3" />
        <vers num="7.0" edition="sp3:win32" />
        <vers num="7.0" edition="sp3:express" />
        <vers num="7.0" edition="sp4" />
        <vers num="7.0" edition="sp4:express" />
        <vers num="7.0" edition="sp4:win32" />
        <vers num="7.0.0.1" edition="" />
        <vers num="7.0.0.1" edition=":express" />
        <vers num="7.0.0.1" edition=":win32" />
        <vers num="7.0.0.1" edition="sp1" />
        <vers num="7.0.0.1" edition="sp1:express" />
        <vers num="7.0.0.1" edition="sp1:win32" />
        <vers num="7.0.0.1" edition="sp2" />
        <vers num="7.0.0.1" edition="sp2:win32" />
        <vers num="7.0.0.1" edition="sp2:express" />
        <vers num="7.0.0.1" edition="sp3" />
        <vers num="7.0.0.1" edition="sp3:express" />
        <vers num="7.0.0.1" edition="sp4" />
        <vers num="7.0.0.1" edition="sp4:express" />
        <vers num="8.1" edition="" />
        <vers num="8.1" edition=":express" />
        <vers num="8.1" edition=":win32" />
        <vers num="8.1" edition="sp1" />
        <vers num="8.1" edition="sp1:express" />
        <vers num="8.1" edition="sp1:win32" />
        <vers num="8.1" edition="sp2" />
        <vers num="8.1" edition="sp2:express" />
        <vers num="8.1" edition="sp2:win32" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2004-0653" published="2004-08-06" name="CVE-2004-0653" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">Solaris 9, when configured as a Kerberos client with patch 112908-12 or 115168-03 and using pam_krb5 as an "auth" module with the debug feature enabled, records passwords in plaintext, which could allow local users to gain other user's passwords by reading log files.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <config />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/523710" source="CERT-VN" patch="1" adv="1">VU#523710</ref>
      <ref url="http://www.ciac.org/ciac/bulletins/o-172.shtml" source="CIAC" patch="1" adv="1">O-172</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/16450" source="XF" adv="1">solaris-kerberos-password-plaintext(16450)</ref>
      <ref url="http://www.securityfocus.com/bid/10606" source="BID">10606</ref>
      <ref url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doc=fsalert/57587" source="SUNALERT">57587</ref>
      <ref url="http://secunia.com/advisories/11940/" source="SECUNIA">11940</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-101519-1" source="SUNALERT">101519</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:255" source="OVAL" sig="1">oval:org.mitre.oval:def:255</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2065" source="OVAL" sig="1">oval:org.mitre.oval:def:2065</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="solaris">
        <vers num="9.0" edition="" />
        <vers num="9.0" edition=":sparc" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2004-0654" published="2004-08-06" name="CVE-2004-0654" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">Unknown vulnerability in the Basic Security Module (BSM), when configured to audit either the Administrative (ad) or the System-Wide Administration (as) audit class in Solaris 7, 8, and 9, allows local users to cause a denial of service (kernel panic).</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <config />
      <other />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/901582" source="CERT-VN" patch="1" adv="1">VU#901582</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/16483" source="XF" adv="1">solaris-bsm-audit-dos(16483)</ref>
      <ref url="http://www.securityfocus.com/bid/10594" source="BID">10594</ref>
      <ref url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doc=fsalert/57497" source="SUNALERT">57497</ref>
      <ref url="http://secunia.com/advisories/11930/" source="SECUNIA">11930</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2426" source="OVAL" sig="1">oval:org.mitre.oval:def:2426</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="solaris">
        <vers num="7.0" edition="" />
        <vers num="7.0" edition=":x86" />
        <vers num="8.0" edition="" />
        <vers num="8.0" edition=":x86" />
        <vers num="9.0" edition="" />
        <vers num="9.0" edition=":sparc" />
        <vers num="9.0" edition=":x86" />
        <vers num="9.0" edition="x86_update_2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0655" published="2004-08-06" name="CVE-2004-0655" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">eupdatedb in esearch 0.6.1 and earlier allows local users to create arbitrary files via a symlink attack on the esearchdb.py.tmp temporary file.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" admin="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/10644" source="BID" patch="1" adv="1">10644</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/16584" source="XF" adv="1">esearch-eupdatedb-symlink(16584)</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200407-01.xml" source="GENTOO" adv="1">GLSA-200407-01</ref>
    </refs>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0656" published="2004-08-06" name="CVE-2004-0656" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The accept_client function in PureFTPd 1.0.18 and earlier allows remote attackers to cause a denial of service by exceeding the maximum number of connections.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200407-04.xml" source="GENTOO" patch="1" adv="1">GLSA-200407-04</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/16611" source="XF" adv="1">pure-ftpd-acceptclient-dos(16611)</ref>
      <ref url="http://www.pureftpd.org/" source="CONFIRM">http://www.pureftpd.org/</ref>
    </refs>
    <vuln_soft>
      <prod vendor="pureftpd" name="pureftpd">
        <vers num="0.96" />
        <vers num="1.0" />
        <vers num="1.0.1" />
        <vers num="1.0.11" />
        <vers num="1.0.12" />
        <vers num="1.0.13a" />
        <vers num="1.0.14" />
        <vers num="1.0.15" />
        <vers num="1.0.16" />
        <vers num="1.0.16a" />
        <vers num="1.0.16b" />
        <vers num="1.0.16c" />
        <vers num="1.0.17a" />
        <vers num="1.0.18" />
        <vers num="1.0.2" />
        <vers num="1.0.3" />
        <vers num="1.0.4" />
        <vers num="1.0.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0657" published="2004-08-06" name="CVE-2004-0657" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Integer overflow in the NTP daemon (NTPd) before 4.0 causes the NTP server to return the wrong date/time offset when a client requests a date/time that is more than 34 years away from the server's time.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/584606" source="CERT-VN" patch="1" adv="1">VU#584606</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15406" source="XF" patch="1" adv="1">ntp-integer-bo(15406)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108922292425219&amp;w=2" source="HP">SSRT4718</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ntp" name="ntp">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0658" published="2004-08-06" name="CVE-2004-0658" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Integer overflow in the hpsb_alloc_packet function (incorrectly reported as alloc_hpsb_packet) in IEEE 1394 (Firewire) driver 2.4 and 2.6 allows local users to cause a denial of service (crash) and possibly execute arbitrary code via the functions (1) raw1394_write, (2) state_connected, (3) handle_remote_request, or (4) hpsb_make_writebpacket.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" admin="1" />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/16480" source="XF" adv="1">linux-1394-integer-bo(16480)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108793792820740" source="BUGTRAQ" adv="1">20040622 linux kernel IEEE1394(Firewire) driver integer overflow</ref>
    </refs>
    <vuln_soft>
      <prod vendor="linux" name="linux_kernel">
        <vers num="2.4.0" edition="test1" />
        <vers num="2.4.0" edition="test10" />
        <vers num="2.4.0" edition="test11" />
        <vers num="2.4.0" edition="test12" />
        <vers num="2.4.0" edition="test2" />
        <vers num="2.4.0" edition="test3" />
        <vers num="2.4.0" edition="test4" />
        <vers num="2.4.0" edition="test5" />
        <vers num="2.4.0" edition="test6" />
        <vers num="2.4.0" edition="test7" />
        <vers num="2.4.0" edition="test8" />
        <vers num="2.4.0" edition="test9" />
        <vers num="2.4.1" />
        <vers num="2.4.10" />
        <vers num="2.4.11" />
        <vers num="2.4.12" />
        <vers num="2.4.13" />
        <vers num="2.4.14" />
        <vers num="2.4.15" />
        <vers num="2.4.16" />
        <vers num="2.4.17" />
        <vers num="2.4.18" edition="" />
        <vers num="2.4.18" edition=":x86" />
        <vers num="2.4.18" edition="pre1" />
        <vers num="2.4.18" edition="pre2" />
        <vers num="2.4.18" edition="pre3" />
        <vers num="2.4.18" edition="pre4" />
        <vers num="2.4.18" edition="pre5" />
        <vers num="2.4.18" edition="pre6" />
        <vers num="2.4.18" edition="pre7" />
        <vers num="2.4.18" edition="pre8" />
        <vers num="2.4.19" edition="pre1" />
        <vers num="2.4.19" edition="pre2" />
        <vers num="2.4.19" edition="pre3" />
        <vers num="2.4.19" edition="pre4" />
        <vers num="2.4.19" edition="pre5" />
        <vers num="2.4.19" edition="pre6" />
        <vers num="2.4.2" />
        <vers num="2.4.20" />
        <vers num="2.4.21" edition="pre1" />
        <vers num="2.4.21" edition="pre4" />
        <vers num="2.4.21" edition="pre7" />
        <vers num="2.4.22" />
        <vers num="2.4.23" edition="pre9" />
        <vers num="2.4.23_ow2" />
        <vers num="2.4.24" />
        <vers num="2.4.24_ow1" />
        <vers num="2.4.25" />
        <vers num="2.4.26" />
        <vers num="2.4.27" edition="pre1" />
        <vers num="2.4.27" edition="pre2" />
        <vers num="2.4.3" />
        <vers num="2.4.4" />
        <vers num="2.4.5" />
        <vers num="2.4.6" />
        <vers num="2.4.7" />
        <vers num="2.4.8" />
        <vers num="2.4.9" />
        <vers num="2.5.0" />
        <vers num="2.5.1" />
        <vers num="2.5.10" />
        <vers num="2.5.11" />
        <vers num="2.5.12" />
        <vers num="2.5.13" />
        <vers num="2.5.14" />
        <vers num="2.5.15" />
        <vers num="2.5.16" />
        <vers num="2.5.17" />
        <vers num="2.5.18" />
        <vers num="2.5.19" />
        <vers num="2.5.2" />
        <vers num="2.5.20" />
        <vers num="2.5.21" />
        <vers num="2.5.22" />
        <vers num="2.5.23" />
        <vers num="2.5.24" />
        <vers num="2.5.25" />
        <vers num="2.5.26" />
        <vers num="2.5.27" />
        <vers num="2.5.28" />
        <vers num="2.5.29" />
        <vers num="2.5.3" />
        <vers num="2.5.30" />
        <vers num="2.5.31" />
        <vers num="2.5.32" />
        <vers num="2.5.33" />
        <vers num="2.5.34" />
        <vers num="2.5.35" />
        <vers num="2.5.36" />
        <vers num="2.5.37" />
        <vers num="2.5.38" />
        <vers num="2.5.39" />
        <vers num="2.5.4" />
        <vers num="2.5.40" />
        <vers num="2.5.41" />
        <vers num="2.5.42" />
        <vers num="2.5.43" />
        <vers num="2.5.44" />
        <vers num="2.5.45" />
        <vers num="2.5.46" />
        <vers num="2.5.47" />
        <vers num="2.5.48" />
        <vers num="2.5.49" />
        <vers num="2.5.5" />
        <vers num="2.5.50" />
        <vers num="2.5.51" />
        <vers num="2.5.52" />
        <vers num="2.5.53" />
        <vers num="2.5.54" />
        <vers num="2.5.55" />
        <vers num="2.5.56" />
        <vers num="2.5.57" />
        <vers num="2.5.58" />
        <vers num="2.5.59" />
        <vers num="2.5.6" />
        <vers num="2.5.60" />
        <vers num="2.5.61" />
        <vers num="2.5.62" />
        <vers num="2.5.63" />
        <vers num="2.5.64" />
        <vers num="2.5.65" />
        <vers num="2.5.66" />
        <vers num="2.5.67" />
        <vers num="2.5.68" />
        <vers num="2.5.69" />
        <vers num="2.5.7" />
        <vers num="2.5.8" />
        <vers num="2.5.9" />
        <vers num="2.6.0" edition="test1" />
        <vers num="2.6.0" edition="test10" />
        <vers num="2.6.0" edition="test11" />
        <vers num="2.6.0" edition="test2" />
        <vers num="2.6.0" edition="test3" />
        <vers num="2.6.0" edition="test4" />
        <vers num="2.6.0" edition="test5" />
        <vers num="2.6.0" edition="test6" />
        <vers num="2.6.0" edition="test7" />
        <vers num="2.6.0" edition="test8" />
        <vers num="2.6.0" edition="test9" />
        <vers num="2.6.1" edition="rc1" />
        <vers num="2.6.1" edition="rc2" />
        <vers num="2.6.2" />
        <vers num="2.6.3" />
        <vers num="2.6.4" />
        <vers num="2.6.5" />
        <vers num="2.6.6" edition="rc1" />
        <vers num="2.6.7" edition="rc1" />
        <vers num="2.6_test9_cvs" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0659" published="2004-08-06" name="CVE-2004-0659" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Buffer overflow in TranslateFilename for common.c in MPlayer 1.0pre4 allows remote attackers to execute arbitrary code via a long file name.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/16532" source="XF" adv="1">mplayer-common-bo(16532)</ref>
      <ref url="http://www.securityfocus.com/bid/10615" source="BID" adv="1">10615</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200408-01.xml" source="GENTOO">GLSA-200408-01</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108844316930791&amp;w=2" source="BUGTRAQ" adv="1">20040627 MPlayer MeMPlayer.c</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mplayer" name="mplayer">
        <vers num="0.90" />
        <vers num="0.90_pre" />
        <vers num="0.90_rc" />
        <vers num="0.90_rc4" />
        <vers num="0.91" />
        <vers num="0.92" />
        <vers num="0.92.1" />
        <vers num="0.92_cvs" />
        <vers num="1.0_pre1" />
        <vers num="1.0_pre2" />
        <vers num="1.0_pre3" />
        <vers num="1.0_pre3try2" />
        <vers num="1.0_pre4" />
        <vers num="head_cvs" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0660" published="2004-08-06" name="CVE-2004-0660" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in (1) show_archives.php, (2) show_news.php, and possibly other php files in CuteNews 1.3.1 allows remote attackers to inject arbitrary script or HTML via the id parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/16525" source="XF">cutenews-id-xss(16525)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108844000409449&amp;w=2" source="BUGTRAQ">20040628 Cross-Site Scripting CuteNews</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cutephp" name="cutenews">
        <vers num="0.88" />
        <vers num="1.3" />
        <vers num="1.3.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0661" published="2004-08-06" name="CVE-2004-0661" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Integer signedness error in D-Link AirPlus DI-614+ running firmware 2.30 and earlier allows remote attackers to cause a denial of service (IP lease depletion) via a DHCP request with the LEASETIME option set to -1, which makes the DHCP lease valid for thirteen or more years.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/16531" source="XF" adv="1">dlink-dhcp-request-dos(16531)</ref>
      <ref url="http://www.securityfocus.com/bid/10621" source="BID" adv="1">10621</ref>
      <ref url="http://www.securityfocus.com/archive/1/367485" source="BUGTRAQ">20040629 Re: DLINK 614+ - SOHO routers, system DOS</ref>
      <ref url="http://www.osvdb.org/7294" source="OSVDB">7294</ref>
      <ref url="http://secunia.com/advisories/12018" source="SECUNIA">12018</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108844250013785&amp;w=2" source="BUGTRAQ">20040628 DLINK 614+ - SOHO routers, DHCP service DOS</ref>
    </refs>
    <vuln_soft>
      <prod vendor="d-link" name="di-604">
        <vers num="" />
      </prod>
      <prod vendor="d-link" name="di-614+">
        <vers num="2.30" />
      </prod>
      <prod vendor="d-link" name="di-624">
        <vers num="1.28" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0662" published="2004-08-06" name="CVE-2004-0662" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">PowerPortal 1.x allows remote attackers to gain sensitive information via invalid or missing parameters in HTTP requests to (1) resize.php or (2) modules.php, which reveals the path in an error message.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/16529" source="XF" adv="1">powerportal-path-disclosure(16529)</ref>
      <ref url="http://www.swp-zone.org/archivos/advisory-07.txt" source="MISC">http://www.swp-zone.org/archivos/advisory-07.txt</ref>
      <ref url="http://www.securityfocus.com/bid/10622" source="BID" adv="1">10622</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108844362627811&amp;w=2" source="BUGTRAQ" adv="1">20040628 Multiple vulnerabilities PowerPortal</ref>
    </refs>
    <vuln_soft>
      <prod vendor="powerportal" name="powerportal">
        <vers num="1.1b" />
        <vers num="1.3" />
        <vers num="1.3b" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0663" published="2004-08-06" name="CVE-2004-0663" modified="2009-10-14" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in modules.php in PowerPortal 1.x allows remote attackers to inject arbitrary script or HTML via the (1) id parameter to the (a) private_messages module; (2) search parameter to the (b) links and (c) content modules; and (3) files parameter to the gallery module.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/16528" source="XF">powerportal-multiple-xss(16528)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108844362627811&amp;w=2" source="BUGTRAQ" adv="1">20040628 Multiple vulnerabilities PowerPortal</ref>
    </refs>
    <vuln_soft>
      <prod vendor="powerportal" name="powerportal">
        <vers num="1.1b" />
        <vers num="1.3" />
        <vers num="1.3b" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0664" published="2004-08-06" name="CVE-2004-0664" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in modules.php in PowerPortal 1.x allows remote attackers to list arbitrary directories via a .. (dot dot) in the files parameter.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/16530" source="XF" adv="1">powerportal-dotdot-directory-traversal(16530)</ref>
      <ref url="http://www.swp-zone.org/archivos/advisory-07.txt" source="MISC">http://www.swp-zone.org/archivos/advisory-07.txt</ref>
      <ref url="http://www.securityfocus.com/bid/10622" source="BID" adv="1">10622</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108844362627811&amp;w=2" source="BUGTRAQ" adv="1">20040628 Multiple vulnerabilities PowerPortal</ref>
    </refs>
    <vuln_soft>
      <prod vendor="powerportal" name="powerportal">
        <vers num="1.1b" />
        <vers num="1.3" />
        <vers num="1.3b" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0665" published="2004-08-06" name="CVE-2004-0665" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">csFAQ.cgi in csFAQ allows remote attackers to gain sensitive information via an invalid database parameter, which reveals the path to the web server in an error message.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/16526" source="XF" adv="1">csfaq-path-disclosure(16526)</ref>
      <ref url="http://www.swp-zone.org/archivos/advisory-08.txt" source="MISC">http://www.swp-zone.org/archivos/advisory-08.txt</ref>
      <ref url="http://www.securityfocus.com/bid/10618" source="BID" adv="1">10618</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108844203121238&amp;w=2" source="BUGTRAQ" adv="1">20040628 Full path disclosure csFAQ</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cgiscript.net" name="csfaq">
        <vers num="1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0666" published="2004-08-06" name="CVE-2004-0666" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Off-by-one error in the POP3_readmsg function in popclient 3.0b6 allows remote attackers to cause a denial of service (application crash) via an e-mail message with a certain line length, which leads to a buffer overflow.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/16538" source="XF" adv="1">popclient-pop3readmsg-offbyone-bo(16538)</ref>
      <ref url="http://www.securityfocus.com/bid/10625" source="BID" adv="1">10625</ref>
      <ref url="http://www.grok.org.uk/advisories/popclient.html" source="MISC">http://www.grok.org.uk/advisories/popclient.html</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108852915403293&amp;w=2" source="BUGTRAQ" adv="1">20040629 DoS in popclient 3.0b6</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2004-June/023147.html" source="FULLDISC">20040629 DoS in popclient 3.0b6</ref>
    </refs>
    <vuln_soft>
      <prod vendor="popclient" name="popclient">
        <vers num="3.0_b6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0667" published="2004-08-06" name="CVE-2004-0667" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Rule Set Based Access Control (RSBAC) 1.2.2 through 1.2.3 allows access to sys_creat, sys_open, and sys_mknod inside jails, which could allow local users to gain elevated privileges.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" admin="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/10640" source="BID" patch="1" adv="1">10640</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/16552" source="XF" adv="1">rsbac-jail-gain-privileges(16552)</ref>
      <ref url="http://www.rsbac.org/download/bugfixes/" source="CONFIRM">http://www.rsbac.org/download/bugfixes/</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108879977120430&amp;w=2" source="BUGTRAQ" adv="1">20040702 Announce: RSBAC v1.2.3 released</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108861182906067&amp;w=2" source="BUGTRAQ" adv="1">20040630 rsbac 1.2.3 jail security problems</ref>
    </refs>
    <vuln_soft>
      <prod vendor="rsbac" name="rsbac">
        <vers num="1.2.2" />
        <vers num="1.2.3" />
      </prod>
      <prod vendor="gentoo" name="linux">
        <vers num="1.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0668" published="2004-08-06" name="CVE-2004-0668" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Web Access in Lotus Domino 6.5.1 allows remote attackers to cause a denial of service (server crash) via a large e-mail message, as demonstrated using a large image attachment.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/16596" source="XF" adv="1">lotus-domino-web-dos(16596)</ref>
      <ref url="http://www.securityfocus.com/bid/10641" source="BID" adv="1">10641</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108871093704307&amp;w=2" source="BUGTRAQ" adv="1">20040630 DoS against Domino 6.5.1</ref>
    </refs>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0669" published="2004-08-06" name="CVE-2004-0669" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Lotus Domino 6.5.0 and 6.5.1, with IMAP enabled, allows remote authenticated users to change their quota by using the IMAP setquota command.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/16575" source="XF" adv="1">lotus-quota-change(16575)</ref>
      <ref url="http://www.securityfocus.com/bid/10642" source="BID" adv="1">10642</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108869022708571&amp;w=2" source="BUGTRAQ" adv="1">20040630 Unprevileged user can change quota on Domino</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="lotus_domino">
        <vers num="6.5.0" />
        <vers num="6.5.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0670" published="2004-08-06" name="CVE-2004-0670" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Prestige 650HW-31 running Rompager 4.7 software allows remote attackers to cause a denial of service (device reboot) via a long password.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/16547" source="XF" adv="1">zyxel-long-password-dos(16547)</ref>
      <ref url="http://www.securityfocus.com/bid/10638" source="BID" adv="1">10638</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108862133005952&amp;w=2" source="BUGTRAQ" adv="1">20040630 DSL router Prestige 650HW-31</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2004-June/023196.html" source="FULLDISC">20040630 DSL router Prestige 650HW-31</ref>
    </refs>
    <vuln_soft>
      <prod vendor="zyxel" name="prestige">
        <vers num="650hw_31" />
        <vers num="650r_11" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0671" published="2004-08-06" name="CVE-2004-0671" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Brightmail Spamfilter 6.0 and earlier beta releases allows remote attackers to read mail from other users by modifying the id parameter in a viewMsgDetails.do request.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/16609" source="XF" adv="1">symantec-brightmail-view-mail(16609)</ref>
      <ref url="http://www.securityfocus.com/bid/10657" source="BID" adv="1">10657</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108880205115802&amp;w=2" source="BUGTRAQ">20040701 Brightmail leaks other user's spam</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108981452101353&amp;w=2" source="BUGTRAQ">20040714 Ref: http://www.securityfocus.com/archive/1/367866, Jul 1 2004 1:19PM, Subj:  Brightmail</ref>
    </refs>
    <vuln_soft>
      <prod vendor="symantec" name="brightmail_antispam">
        <vers num="6.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0672" published="2004-08-06" name="CVE-2004-0672" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in the primary and management web interfaces in Netegrity IdentityMinder Web Edition 5.6 allows remote attackers to execute script as other users via (1) script that starts with %00 in the numOfExpressions parameter or (2) the mobjtype parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/16618" source="XF">identityminder-xss(16618)</ref>
      <ref url="http://www.securityfocus.com/bid/10645" source="BID">10645</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108881203114336&amp;w=2" source="BUGTRAQ">20040701 [HW-MED] XSS in Netegrity IdentityMinder</ref>
    </refs>
    <vuln_soft>
      <prod vendor="netegrity" name="identityminder">
        <vers num="web_5.6" />
        <vers num="web_5.6_sp1" />
        <vers num="web_5.6_sp2" />
      </prod>
      <prod vendor="netegrity" name="policy_server">
        <vers num="5.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0673" published="2004-08-06" name="CVE-2004-0673" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in SCI Photo Chat Server 3.4.9 allows remote attackers to execute arbitrary web script as other users via an invalid request that is echoed in the resulting error message.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/16602" source="XF">sci-server-xss(16602)</ref>
      <ref url="http://www.securityfocus.com/bid/10648" source="BID">10648</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108880460730833&amp;w=2" source="BUGTRAQ">20040702 XSS in SCI Photo Chat Server 3.4.9</ref>
    </refs>
    <vuln_soft>
      <prod vendor="simm-comm" name="sci_photo_chat">
        <vers num="3.4.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0674" published="2004-08-06" name="CVE-2004-0674" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Enterasys XSR-1800 series Security Routers, when running firmware 7.0.0.0 and using Policy-Based Routing, allow remote attackers to cause a denial of service (crash) via a packet with the IP record route option set.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/16616" source="XF" adv="1">xsr-ip-record-dos(16616)</ref>
      <ref url="http://www.securityfocus.com/bid/10653" source="BID" adv="1">10653</ref>
      <ref url="http://www.enterasys.com/support/security/incidents/2004/07/11036.html" source="CONFIRM">http://www.enterasys.com/support/security/incidents/2004/07/11036.html</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108886995627906&amp;w=2" source="BUGTRAQ" adv="1">20040702 Enterasys XSR Security Routers DoS</ref>
    </refs>
    <vuln_soft>
      <prod vendor="enterasys" name="xsr-1805">
        <vers num="7.0.0.0" />
      </prod>
      <prod vendor="enterasys" name="xsr-1850">
        <vers num="7.0.0.0" />
      </prod>
      <prod vendor="enterasys" name="xsr-3000">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0675" published="2004-08-06" name="CVE-2004-0675" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in (1) cart32.exe or (2) c32web.exe in Cart32 shopping cart allows remote attackers to execute arbitrary web script via the cart32 parameter to a GetLatestBuilds command.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/16535" source="XF">cart32-getlatestbuilds-xss(16535)</ref>
      <ref url="http://www.securityfocus.com/bid/10617" source="BID">10617</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108887778628398&amp;w=2" source="BUGTRAQ">20040703 Cart32 Input Validation Flaw in 'GetLatestBuilds?cart32=' Permits Remote Cross-Site Scripting Attacks </ref>
    </refs>
    <vuln_soft>
      <prod vendor="mcmurtrey_whitaker_and_associates" name="cart32">
        <vers num="2.5a" />
        <vers num="2.6" />
        <vers num="3.0" />
        <vers num="3.1" />
        <vers num="3.5" />
        <vers num="3.5_build619" />
        <vers num="3.5a" />
        <vers num="3.5a_build710" />
        <vers num="4.4" />
        <vers num="5.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0676" published="2004-08-06" name="CVE-2004-0676" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in Fastream NETFile FTP/Web Server 6.7.2.1085 and earlier allows remote attackers to create or delete arbitrary files via .. (dot dot) and // (double slash) sequences in the filename parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" admin="1" />
    </loss_types>
    <vuln_types>
      <input />
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/10658" source="BID" patch="1" adv="1">10658</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/16613" source="XF" adv="1">fastream-mkdir-file-upload(16613)</ref>
      <ref url="http://www.haxorcitos.com/Fastream_advisory.txt" source="MISC">http://www.haxorcitos.com/Fastream_advisory.txt</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108904874104880&amp;w=2" source="BUGTRAQ" adv="1">20040704 Fastream NETFile FTP/Web Server Input validation Errors</ref>
    </refs>
    <vuln_soft>
      <prod vendor="fastream" name="netfile_ftp_web_server">
        <vers num="6.5.1.980" />
        <vers num="6.5.1.981" />
        <vers num="6.7.2.1085" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0677" published="2004-08-06" name="CVE-2004-0677" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Fastream NETFile FTP Server 6.7.2.1085 and earlier allows remote attackers to cause a denial of service (temporary hang) via the cd command with an unusual argument, possibly due to multiple leading slashes and/or an access to the floppy drive ("A").</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/16615" source="XF" adv="1">fastream-cd-dos(16615)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108904874104880&amp;w=2" source="BUGTRAQ">20040704 Fastream NETFile FTP/Web Server Input validation Errors</ref>
    </refs>
    <vuln_soft>
      <prod vendor="fastream" name="netfile_ftp_web_server">
        <vers prev="1" num="6.7.2.1085" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0678" published="2004-08-06" name="CVE-2004-0678" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) in one2planet.infolet.InfoServlet in 12Planet Chat Server 2.9 allows remote attackers to execute arbirary script as other users via the page parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/16605" source="XF">12planet-chat-server-xss(16605)</ref>
      <ref url="http://www.securityfocus.com/bid/10659" source="BID">10659</ref>
      <ref url="http://www.autistici.org/fdonato/advisory/12PlanetChatServer2.9-adv.txt" source="MISC">http://www.autistici.org/fdonato/advisory/12PlanetChatServer2.9-adv.txt</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108904648728706&amp;w=2" source="BUGTRAQ">20040705 XSS in 12Planet Chat Server 2.9</ref>
    </refs>
    <vuln_soft>
      <prod vendor="12planet" name="chat_server">
        <vers num="2.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0679" published="2004-08-06" name="CVE-2004-0679" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The IP cloaking feature (cloak.c) in UnrealIRCd 3.2, and possibly other versions, uses a weak hashing scheme to hide IP addresses, which could allow remote attackers to use brute force methods to gain other user's IP addresses.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/10663" source="BID" patch="1" adv="1">10663</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/16610" source="XF" adv="1">unreal-ircd-information-disclosure(16610)</ref>
      <ref url="http://www.unrealircd.com/" source="CONFIRM">http://www.unrealircd.com/</ref>
      <ref url="http://www.bandecon.com/advisory/unreal.txt" source="MISC">http://www.bandecon.com/advisory/unreal.txt</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108904813003166&amp;w=2" source="BUGTRAQ" adv="1">20040705 unreal ircd ip cloaking subsystem vulnerability</ref>
      <ref url="http://securityreason.com/securityalert/560" source="SREASON">560</ref>
    </refs>
    <vuln_soft>
      <prod vendor="unreal" name="unrealircd">
        <vers num="3.1.1" />
        <vers num="3.1.3" />
        <vers num="3.2" />
        <vers num="3.2_.0_beta_10" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0680" published="2004-08-06" name="CVE-2004-0680" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Zoom X3 ADSL modem has a terminal running on port 254 that can be accessed using the default HTML management password, even if the password has been changed for the HTTP interface, which could allow remote attackers to gain unauthorized access.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" admin="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/16639" source="XF" adv="1">conexant-chipset-settings-restore(16639)</ref>
      <ref url="http://www.securityfocus.com/bid/10669" source="BID" adv="1">10669</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108915255520924&amp;w=2" source="BUGTRAQ" adv="1">20040706 backdoor menu on conexant chipset dsl router (Zoom X3)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="zoom" name="model_5560_x3_ethernet_adsl_modem">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0681" published="2004-08-06" name="CVE-2004-0681" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in (1) comersus_customerAuthenticateForm.asp, (2) comersus_backoffice_message.asp, (3) comersus_supportError.asp, or (4) comersus_message.asp in Comersus Cart 5.09 allow remote attackers to execute web script as other users via the message parameter.</descript>
    </desc>
    <sols>
      <sol source="nvd">This vulnerability is addressed in the following product update:
Comersus Open Technologies, Comersus Cart, 5.098</sol>
    </sols>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/10674" source="BID" patch="1">10674</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/16646" source="XF">comersus-cart-xss(16646)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108922169327403&amp;w=2" source="BUGTRAQ">20040707 Comersus Cart Cross-Site Scripting Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="comersus_open_technologies" name="comersus_cart">
        <vers num="5.09" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0682" published="2004-08-06" name="CVE-2004-0682" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">comersus_gatewayPayPal.asp in Comersus Cart 5.09, and possibly other versions before 5.098, allows remote attackers to change the prices of items by directly modifying them in the URL.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/16645" source="XF" adv="1">comersus-cart-price-modification(16645)</ref>
      <ref url="http://www.securityfocus.com/bid/10674" source="BID" adv="1">10674</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108922336529987&amp;w=2" source="BUGTRAQ" adv="1">20040707 Comersus Cart Improper Request Handling</ref>
    </refs>
    <vuln_soft>
      <prod vendor="comersus_open_technologies" name="comersus_cart">
        <vers num="5.0.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0683" published="2004-08-06" name="CVE-2004-0683" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Symantec Norton AntiVirus 2002 and 2003 allows remote attackers to cause a denial of service (CPU consumption) via a compressed archive that contains a large number of directories.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/16658" source="XF" adv="1">nav-compressed-dos(16658)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108938579712894&amp;w=2" source="BUGTRAQ">20040709 Norton AntiVirus Denial Of Service Vulnerability [Part: !!!]</ref>
    </refs>
    <vuln_soft>
      <prod vendor="symantec" name="norton_antivirus">
        <vers num="2002" />
        <vers num="2003" edition="" />
        <vers num="2003" edition=":pro" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0684" published="2004-08-06" name="CVE-2004-0684" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">WebSphere Edge Component Caching Proxy in WebSphere Edge Server 5.02, with the JunctionRewrite directive enabled, allows remote attackers to cause a denial of service via an HTTP GET request without any parameters.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
      <config />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/16607" source="XF" adv="1">ibm-edge-caching-dos(16607)</ref>
      <ref url="http://www.cybsec.com/vuln/IBM-WebSphere-Edge-Server-DOS.pdf" source="MISC">http://www.cybsec.com/vuln/IBM-WebSphere-Edge-Server-DOS.pdf</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108938997528245&amp;w=2" source="BUGTRAQ" adv="1">20040708 CYBSEC - Security Advisory: Denial of Service in IBM WebSphere</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="websphere_caching_proxy_server">
        <vers num="5.0.2" />
      </prod>
      <prod vendor="ibm" name="websphere_edge_server_caching_proxy">
        <vers num="5.0.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0685" published="2004-12-23" name="CVE-2004-0685" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Certain USB drivers in the Linux 2.4 kernel use the copy_to_user function on uninitialized structures, which could allow local users to obtain sensitive information by reading memory that was not cleared from previous usage.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <env />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/981134" source="CERT-VN" adv="1">VU#981134</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/16931" source="XF" patch="1" adv="1">linux-usb-gain-privileges(16931)</ref>
      <ref url="http://www.securityfocus.com/bid/10892" source="BID" patch="1" adv="1">10892</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200408-24.xml" source="GENTOO" patch="1" adv="1">GLSA-200408-24</ref>
      <ref url="https://bugzilla.fedora.us/show_bug.cgi?id=2336" source="FEDORA">FLSA:2336</ref>
      <ref url="http://www.trustix.net/errata/2004/0041/" source="TRUSTIX">2004-0041</ref>
      <ref url="http://www.securityspace.com/smysecure/catid.html?id=14580" source="MISC">http://www.securityspace.com/smysecure/catid.html?id=14580</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-505.html" source="REDHAT">RHSA-2004:505</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-504.html" source="REDHAT">RHSA-2004:504</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1082" source="DEBIAN">DSA-1082</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1070" source="DEBIAN">DSA-1070</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1069" source="DEBIAN">DSA-1069</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1067" source="DEBIAN">DSA-1067</ref>
      <ref url="http://secunia.com/advisories/20338" source="SECUNIA">20338</ref>
      <ref url="http://secunia.com/advisories/20202" source="SECUNIA">20202</ref>
      <ref url="http://secunia.com/advisories/20163" source="SECUNIA">20163</ref>
      <ref url="http://secunia.com/advisories/20162" source="SECUNIA">20162</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10665" source="OVAL">oval:org.mitre.oval:def:10665</ref>
      <ref url="http://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=127921" source="CONFIRM">http://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=127921</ref>
    </refs>
    <vuln_soft>
      <prod vendor="linux" name="linux_kernel">
        <vers num="2.2.0" />
        <vers num="2.2.1" />
        <vers num="2.2.10" />
        <vers num="2.2.11" />
        <vers num="2.2.12" />
        <vers num="2.2.13" />
        <vers num="2.2.14" />
        <vers num="2.2.15" edition="pre16" />
        <vers num="2.2.15_pre20" />
        <vers num="2.2.16" edition="pre6" />
        <vers num="2.2.17" />
        <vers num="2.2.18" />
        <vers num="2.2.19" />
        <vers num="2.2.2" />
        <vers num="2.2.20" />
        <vers num="2.2.21" />
        <vers num="2.2.22" />
        <vers num="2.2.23" />
        <vers num="2.2.24" />
        <vers num="2.2.25" />
        <vers num="2.2.3" />
        <vers num="2.2.4" />
        <vers num="2.2.5" />
        <vers num="2.2.6" />
        <vers num="2.2.7" />
        <vers num="2.2.8" />
        <vers num="2.2.9" />
        <vers num="2.3.0" />
        <vers num="2.3.99" edition="pre1" />
        <vers num="2.3.99" edition="pre2" />
        <vers num="2.3.99" edition="pre3" />
        <vers num="2.3.99" edition="pre4" />
        <vers num="2.3.99" edition="pre5" />
        <vers num="2.3.99" edition="pre6" />
        <vers num="2.3.99" edition="pre7" />
        <vers num="2.4.0" edition="test1" />
        <vers num="2.4.0" edition="test10" />
        <vers num="2.4.0" edition="test11" />
        <vers num="2.4.0" edition="test12" />
        <vers num="2.4.0" edition="test2" />
        <vers num="2.4.0" edition="test3" />
        <vers num="2.4.0" edition="test4" />
        <vers num="2.4.0" edition="test5" />
        <vers num="2.4.0" edition="test6" />
        <vers num="2.4.0" edition="test7" />
        <vers num="2.4.0" edition="test8" />
        <vers num="2.4.0" edition="test9" />
        <vers num="2.4.1" />
        <vers num="2.4.10" />
        <vers num="2.4.11" />
        <vers num="2.4.12" />
        <vers num="2.4.13" />
        <vers num="2.4.14" />
        <vers num="2.4.15" />
        <vers num="2.4.16" />
        <vers num="2.4.17" />
        <vers num="2.4.18" edition="" />
        <vers num="2.4.18" edition=":x86" />
        <vers num="2.4.18" edition="pre1" />
        <vers num="2.4.18" edition="pre2" />
        <vers num="2.4.18" edition="pre3" />
        <vers num="2.4.18" edition="pre4" />
        <vers num="2.4.18" edition="pre5" />
        <vers num="2.4.18" edition="pre6" />
        <vers num="2.4.18" edition="pre7" />
        <vers num="2.4.18" edition="pre8" />
        <vers num="2.4.19" edition="pre1" />
        <vers num="2.4.19" edition="pre2" />
        <vers num="2.4.19" edition="pre3" />
        <vers num="2.4.19" edition="pre4" />
        <vers num="2.4.19" edition="pre5" />
        <vers num="2.4.19" edition="pre6" />
        <vers num="2.4.2" />
        <vers num="2.4.20" />
        <vers num="2.4.21" edition="pre1" />
        <vers num="2.4.21" edition="pre4" />
        <vers num="2.4.21" edition="pre7" />
        <vers num="2.4.22" />
        <vers num="2.4.23" edition="pre9" />
        <vers num="2.4.23_ow2" />
        <vers num="2.4.24" />
        <vers num="2.4.24_ow1" />
        <vers num="2.4.25" />
        <vers num="2.4.26" />
        <vers num="2.4.27" edition="pre1" />
        <vers num="2.4.27" edition="pre2" />
        <vers num="2.4.27" edition="pre3" />
        <vers num="2.4.27" edition="pre4" />
        <vers num="2.4.27" edition="pre5" />
        <vers num="2.4.3" />
        <vers num="2.4.4" />
        <vers num="2.4.5" />
        <vers num="2.4.6" />
        <vers num="2.4.7" />
        <vers num="2.4.8" />
        <vers num="2.4.9" />
        <vers num="2.5.0" />
        <vers num="2.5.1" />
        <vers num="2.5.10" />
        <vers num="2.5.11" />
        <vers num="2.5.12" />
        <vers num="2.5.13" />
        <vers num="2.5.14" />
        <vers num="2.5.15" />
        <vers num="2.5.16" />
        <vers num="2.5.17" />
        <vers num="2.5.18" />
        <vers num="2.5.19" />
        <vers num="2.5.2" />
        <vers num="2.5.20" />
        <vers num="2.5.21" />
        <vers num="2.5.22" />
        <vers num="2.5.23" />
        <vers num="2.5.24" />
        <vers num="2.5.25" />
        <vers num="2.5.26" />
        <vers num="2.5.27" />
        <vers num="2.5.28" />
        <vers num="2.5.29" />
        <vers num="2.5.3" />
        <vers num="2.5.30" />
        <vers num="2.5.31" />
        <vers num="2.5.32" />
        <vers num="2.5.33" />
        <vers num="2.5.34" />
        <vers num="2.5.35" />
        <vers num="2.5.36" />
        <vers num="2.5.37" />
        <vers num="2.5.38" />
        <vers num="2.5.39" />
        <vers num="2.5.4" />
        <vers num="2.5.40" />
        <vers num="2.5.41" />
        <vers num="2.5.42" />
        <vers num="2.5.43" />
        <vers num="2.5.44" />
        <vers num="2.5.45" />
        <vers num="2.5.46" />
        <vers num="2.5.47" />
        <vers num="2.5.48" />
        <vers num="2.5.49" />
        <vers num="2.5.5" />
        <vers num="2.5.50" />
        <vers num="2.5.51" />
        <vers num="2.5.52" />
        <vers num="2.5.53" />
        <vers num="2.5.54" />
        <vers num="2.5.55" />
        <vers num="2.5.56" />
        <vers num="2.5.57" />
        <vers num="2.5.58" />
        <vers num="2.5.59" />
        <vers num="2.5.6" />
        <vers num="2.5.60" />
        <vers num="2.5.61" />
        <vers num="2.5.62" />
        <vers num="2.5.63" />
        <vers num="2.5.64" />
        <vers num="2.5.65" />
        <vers num="2.5.66" />
        <vers num="2.5.67" />
        <vers num="2.5.68" />
        <vers num="2.5.69" />
        <vers num="2.5.7" />
        <vers num="2.5.8" />
        <vers num="2.5.9" />
        <vers num="2.6.0" edition="test1" />
        <vers num="2.6.0" edition="test10" />
        <vers num="2.6.0" edition="test11" />
        <vers num="2.6.0" edition="test2" />
        <vers num="2.6.0" edition="test3" />
        <vers num="2.6.0" edition="test4" />
        <vers num="2.6.0" edition="test5" />
        <vers num="2.6.0" edition="test6" />
        <vers num="2.6.0" edition="test7" />
        <vers num="2.6.0" edition="test8" />
        <vers num="2.6.0" edition="test9" />
        <vers num="2.6.1" edition="rc1" />
        <vers num="2.6.1" edition="rc2" />
        <vers num="2.6.2" />
        <vers num="2.6.3" />
        <vers num="2.6.4" />
        <vers num="2.6.5" />
        <vers num="2.6.6" edition="rc1" />
        <vers num="2.6.7" edition="rc1" />
        <vers num="2.6.8" edition="rc1" />
        <vers num="2.6.8" edition="rc2" />
        <vers num="2.6.8" edition="rc3" />
        <vers num="2.6_test9_cvs" />
      </prod>
      <prod vendor="redhat" name="enterprise_linux">
        <vers num="3.0" edition="" />
        <vers num="3.0" edition=":workstation" />
        <vers num="3.0" edition=":advanced_servers" />
        <vers num="3.0" edition=":enterprise_server" />
      </prod>
      <prod vendor="redhat" name="enterprise_linux_desktop">
        <vers num="3.0" />
      </prod>
      <prod vendor="trustix" name="secure_linux">
        <vers num="2.0" />
        <vers num="2.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0686" published="2004-07-27" name="CVE-2004-0686" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Buffer overflow in Samba 2.2.x to 2.2.9, and 3.0.0 to 3.0.4, when the "mangling method = hash" option is enabled in smb.conf, has unknown impact and attack vectors.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-259.html" source="REDHAT" patch="1" adv="1">RHSA-2004:259</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109051340810458&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20040722 Security Release - Samba 3.0.5 and 2.2.10</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/16786" source="XF" adv="1">samba-mangling-method-bo(16786)</ref>
      <ref url="http://www.trustix.org/errata/2004/0039/" source="TRUSTIX">2004-0039</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2004_22_samba.html" source="SUSE">SUSE-SA:2004:022</ref>
      <ref url="http://www.mandrakesecure.net/en/advisories/advisory.php?name=MDKSA-2004:071" source="MANDRAKE">MDKSA-2004:071</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200407-21.xml" source="GENTOO">GLSA-200407-21</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10461" source="OVAL">oval:org.mitre.oval:def:10461</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-57664-1" source="SUNALERT">57664</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-101584-1" source="SUNALERT">101584</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109785827607823&amp;w=2" source="FEDORA">FLSA:2102</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109094272328981&amp;w=2" source="HP">SSRT4782</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109052891507263&amp;w=2" source="BUGTRAQ">20040722 TSSA-2004-014 - samba</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109051533021376&amp;w=2" source="BUGTRAQ">20040722 [OpenPKG-SA-2004.033] OpenPKG Security Advisory (samba)</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000854" source="CONECTIVA">CLA-2004:854</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000851" source="CONECTIVA">CLA-2004:851</ref>
    </refs>
    <vuln_soft>
      <prod vendor="samba" name="samba">
        <vers num="3.0" />
        <vers num="3.0.0" />
        <vers num="3.0.1" />
        <vers num="3.0.2" />
        <vers num="3.0.2a" />
        <vers num="3.0.3" />
        <vers num="3.0.4" />
      </prod>
      <prod vendor="trustix" name="secure_linux">
        <vers num="1.5" />
        <vers num="2.0" />
        <vers num="2.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0687" published="2004-10-20" name="CVE-2004-0687" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple stack-based buffer overflows in (1) xpmParseColors in parse.c, (2) ParseAndPutPixels in create.c, and (3) ParsePixels in parse.c for libXpm before 6.8.1 allow remote attackers to execute arbitrary code via a malformed XPM image file.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/882750" source="CERT-VN">VU#882750</ref>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA05-136A.html" source="CERT">TA05-136A</ref>
      <ref url="http://www.securityfocus.com/bid/11196" source="BID" patch="1" adv="1">11196</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/17414" source="XF" adv="1">libxpm-multiple-stack-bo(17414)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1914" source="VUPEN">ADV-2006-1914</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/434715/100/0/threaded" source="HP">HPSBUX02119</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/434715/100/0/threaded" source="HP">HPSBUX02119</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-004.html" source="REDHAT">RHSA-2005:004</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-537.html" source="REDHAT">RHSA-2004:537</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2004_34_xfree86_libs_xshared.html" source="SUSE">SUSE-SA:2004:034</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200502-07.xml" source="GENTOO">GLSA-200502-07</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200409-34.xml" source="GENTOO">GLSA-200409-34</ref>
      <ref url="http://www.debian.org/security/2004/dsa-560" source="DEBIAN">DSA-560</ref>
      <ref url="http://scary.beasts.org/security/CESA-2004-003.txt" source="MISC">http://scary.beasts.org/security/CESA-2004-003.txt</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9187" source="OVAL">oval:org.mitre.oval:def:9187</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109530851323415&amp;w=2" source="BUGTRAQ" adv="1">20040915 CESA-2004-004: libXpm</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2005/May/msg00001.html" source="APPLE">APPLE-SA-2005-05-03</ref>
      <ref url="http://ftp.x.org/pub/X11R6.8.0/patches/README.xorg-CAN-2004-0687-0688.patch" source="CONFIRM">http://ftp.x.org/pub/X11R6.8.0/patches/README.xorg-CAN-2004-0687-0688.patch</ref>
      <ref url="http://www.ubuntulinux.org/support/documentation/usn/usn-27-1" source="UBUNTU">USN-27-1</ref>
      <ref url="http://www.redhat.com/archives/fedora-legacy-announce/2006-January/msg00001.html" source="FEDORA">FLSA-2006:152803</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2004:098" source="MANDRAKE">MDKSA-2004:098</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-57653-1" source="SUNALERT">57653</ref>
      <ref url="http://secunia.com/advisories/20235" source="SECUNIA">20235</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000924" source="CONECTIVA">CLA-2005:924</ref>
    </refs>
    <vuln_soft>
      <prod vendor="x.org" name="x11r6">
        <vers num="6.7.0" />
        <vers num="6.8" />
      </prod>
      <prod vendor="xfree86_project" name="x11r6">
        <vers num="3.3.6" />
        <vers num="4.0" />
        <vers num="4.0.1" />
        <vers num="4.0.2.11" />
        <vers num="4.0.3" />
        <vers num="4.1.0" />
        <vers num="4.1.11" />
        <vers num="4.1.12" />
        <vers num="4.2.0" />
        <vers num="4.2.1" edition="" />
        <vers num="4.2.1" edition=":errata" />
        <vers num="4.3.0" />
      </prod>
      <prod vendor="openbsd" name="openbsd">
        <vers num="3.4" />
        <vers num="3.5" />
      </prod>
      <prod vendor="suse" name="suse_linux">
        <vers num="8" edition="" />
        <vers num="8" edition=":enterprise_server" />
        <vers num="8.1" />
        <vers num="8.2" />
        <vers num="9.0" edition="" />
        <vers num="9.0" edition=":enterprise_server" />
        <vers num="9.0" edition=":x86_64" />
        <vers num="9.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0688" published="2004-10-20" name="CVE-2004-0688" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple integer overflows in (1) the xpmParseColors function in parse.c, (2) XpmCreateImageFromXpmImage, (3) CreateXImage, (4) ParsePixels, and (5) ParseAndPutPixels for libXpm before 6.8.1 may allow remote attackers to execute arbitrary code via a malformed XPM image file.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/537878" source="CERT-VN">VU#537878</ref>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA05-136A.html" source="CERT">TA05-136A</ref>
      <ref url="http://www.securityfocus.com/bid/11196" source="BID" patch="1" adv="1">11196</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/17416" source="XF" adv="1">libxpm-xpmfile-integer-overflow(17416)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1914" source="VUPEN">ADV-2006-1914</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/434715/100/0/threaded" source="HP">SSRT4848</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-004.html" source="REDHAT">RHSA-2005:004</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-537.html" source="REDHAT">RHSA-2004:537</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2004_34_xfree86_libs_xshared.html" source="SUSE">SUSE-SA:2004:034</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200502-07.xml" source="GENTOO">GLSA-200502-07</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200409-34.xml" source="GENTOO">GLSA-200409-34</ref>
      <ref url="http://www.debian.org/security/2004/dsa-560" source="DEBIAN">DSA-560</ref>
      <ref url="http://scary.beasts.org/security/CESA-2004-003.txt" source="MISC">http://scary.beasts.org/security/CESA-2004-003.txt</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11796" source="OVAL">oval:org.mitre.oval:def:11796</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109530851323415&amp;w=2" source="BUGTRAQ" adv="1">20040915 CESA-2004-004: libXpm</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2005/May/msg00001.html" source="APPLE">APPLE-SA-2005-05-03</ref>
      <ref url="http://ftp.x.org/pub/X11R6.8.0/patches/README.xorg-CAN-2004-0687-0688.patch" source="CONFIRM">http://ftp.x.org/pub/X11R6.8.0/patches/README.xorg-CAN-2004-0687-0688.patch</ref>
      <ref url="http://www.ubuntulinux.org/support/documentation/usn/usn-27-1" source="UBUNTU">USN-27-1</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/434715/100/0/threaded" source="HP">HPSBUX02119</ref>
      <ref url="http://www.redhat.com/archives/fedora-legacy-announce/2006-January/msg00001.html" source="FEDORA">FLSA-2006:152803</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2004:098" source="MANDRAKE">MDKSA-2004:098</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-57653-1" source="SUNALERT">57653</ref>
      <ref url="http://secunia.com/advisories/20235" source="SECUNIA">20235</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000924" source="CONECTIVA">CLA-2005:924</ref>
    </refs>
    <vuln_soft>
      <prod vendor="x.org" name="x11r6">
        <vers num="6.7.0" />
        <vers num="6.8" />
      </prod>
      <prod vendor="xfree86_project" name="x11r6">
        <vers num="3.3.6" />
        <vers num="4.0" />
        <vers num="4.0.1" />
        <vers num="4.0.2.11" />
        <vers num="4.0.3" />
        <vers num="4.1.0" />
        <vers num="4.1.11" />
        <vers num="4.1.12" />
        <vers num="4.2.0" />
        <vers num="4.2.1" edition="" />
        <vers num="4.2.1" edition=":errata" />
        <vers num="4.3.0" />
      </prod>
      <prod vendor="openbsd" name="openbsd">
        <vers num="3.4" />
        <vers num="3.5" />
      </prod>
      <prod vendor="suse" name="suse_linux">
        <vers num="8" edition="" />
        <vers num="8" edition=":enterprise_server" />
        <vers num="8.1" />
        <vers num="8.2" />
        <vers num="9.0" edition="" />
        <vers num="9.0" edition=":enterprise_server" />
        <vers num="9.0" edition=":x86_64" />
        <vers num="9.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0689" published="2004-09-28" name="CVE-2004-0689" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">KDE before 3.3.0 does not properly handle when certain symbolic links point to "stale" locations, which could allow local users to create or truncate arbitrary files.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/16963" source="XF" patch="1" adv="1">kde-application-symlink(16963)</ref>
      <ref url="http://www.kde.org/info/security/advisory-20040811-1.txt" source="CONFIRM" patch="1" adv="1">http://www.kde.org/info/security/advisory-20040811-1.txt</ref>
      <ref url="http://www.debian.org/security/2004/dsa-539" source="DEBIAN" patch="1" adv="1">DSA-539</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200408-13.xml" source="GENTOO" patch="1" adv="1">200408-13</ref>
      <ref url="http://secunia.com/advisories/12276/" source="SECUNIA" patch="1" adv="1">12276</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9334" source="OVAL">oval:org.mitre.oval:def:9334</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109225538901170&amp;w=2" source="BUGTRAQ">20040811 KDE Security Advisories: Temporary File and Konqueror Frame Injection Vulnerabilities</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000864" source="CONECTIVA">CLA-2004:864</ref>
    </refs>
    <vuln_soft>
      <prod vendor="kde" name="kde">
        <vers prev="1" num="3.3.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0690" published="2004-09-28" name="CVE-2004-0690" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">The DCOPServer in KDE 3.2.3 and earlier allows local users to gain unauthorized access via a symlink attack on DCOP files in the /tmp directory.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <other />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/330638" source="CERT-VN">VU#330638</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/16962" source="XF" patch="1" adv="1">kde-dcopserver-symlink(16962)</ref>
      <ref url="http://www.kde.org/info/security/advisory-20040811-2.txt" source="CONFIRM" patch="1" adv="1">http://www.kde.org/info/security/advisory-20040811-2.txt</ref>
      <ref url="http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=261386" source="MISC" patch="1" adv="1">http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=261386</ref>
      <ref url="http://www.securityfocus.com/bid/10924" source="BID">10924</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200408-13.xml" source="GENTOO">200408-13</ref>
      <ref url="http://secunia.com/advisories/12276" source="SECUNIA">12276</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2004:086" source="MANDRAKE">MDKSA-2004:086</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109225538901170&amp;w=2" source="BUGTRAQ">20040811 KDE Security Advisories: Temporary File and Konqueror Frame Injection Vulnerabilities</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000864" source="CONECTIVA">CLA-2004:864</ref>
    </refs>
    <vuln_soft>
      <prod vendor="kde" name="kde">
        <vers num="3.2.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0691" published="2004-09-28" name="CVE-2004-0691" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Heap-based buffer overflow in the BMP image format parser for the QT library (qt3) before 3.3.3 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/17040" source="XF" patch="1" adv="1">qt-bmp-bo(17040)</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-414.html" source="REDHAT" patch="1" adv="1">RHSA-2004:414</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200408-20.xml" source="GENTOO" patch="1" adv="1">GLSA-200408-20</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2004_27_qt3.html" source="SUSE">SUSE-SA:2004:027</ref>
      <ref url="http://www.debian.org/security/2004/dsa-542" source="DEBIAN">DSA-542</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-66-201610-1" source="SUNALERT">201610</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9485" source="OVAL">oval:org.mitre.oval:def:9485</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109295309008309&amp;w=2" source="BUGTRAQ">20040818 CESA-2004-004: qt</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2004:085" source="MANDRAKE">MDKSA-2004:085</ref>
    </refs>
    <vuln_soft>
      <prod vendor="trolltech" name="qt">
        <vers prev="1" num="3.3.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0692" published="2004-09-28" name="CVE-2004-0692" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The XPM parser in the QT library (qt3) before 3.3.3 allows remote attackers to cause a denial of service (application crash) via a malformed image file that triggers a null dereference, a different vulnerability than CVE-2004-0693.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/17041" source="XF" patch="1" adv="1">qt-xpm-dos(17041)</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200408-20.xml" source="GENTOO" patch="1" adv="1">GLSA-200408-20</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-414.html" source="REDHAT">RHSA-2004:414</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2004_27_qt3.html" source="SUSE">SUSE-SA:2004:027</ref>
      <ref url="http://www.debian.org/security/2004/dsa-542" source="DEBIAN">DSA-542</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-66-201610-1" source="SUNALERT">201610</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10327" source="OVAL">oval:org.mitre.oval:def:10327</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110979666528890&amp;w=2" source="FEDORA">FLSA:2314</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2004:085" source="MANDRAKE">MDKSA-2004:085</ref>
    </refs>
    <vuln_soft>
      <prod vendor="trolltech" name="qt">
        <vers prev="1" num="3.3.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0693" published="2004-09-28" name="CVE-2004-0693" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The GIF parser in the QT library (qt3) before 3.3.3 allows remote attackers to cause a denial of service (application crash) via a malformed image file that triggers a null dereference, a different vulnerability than CVE-2004-0692.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/17042" source="XF" patch="1" adv="1">qt-gif-dos(17042)</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200408-20.xml" source="GENTOO" patch="1" adv="1">GLSA-200408-20</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-414.html" source="REDHAT">RHSA-2004:414</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2004_27_qt3.html" source="SUSE">SUSE-SA:2004:027</ref>
      <ref url="http://www.debian.org/security/2004/dsa-542" source="DEBIAN">DSA-542</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-66-201610-1" source="SUNALERT">201610</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10883" source="OVAL">oval:org.mitre.oval:def:10883</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2004:085" source="MANDRAKE">MDKSA-2004:085</ref>
    </refs>
    <vuln_soft>
      <prod vendor="trolltech" name="qt">
        <vers prev="1" num="3.3.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0694" published="2011-02-03" name="CVE-2004-0694" modified="2011-07-18" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Buffer overflow in LHA 1.14 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via unknown vectors related to "command line processing," a different vulnerability than CVE-2004-0771.  NOTE: this issue may be REJECTED if there are not any cases in which LHA is setuid or is otherwise used across security boundaries.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-440.html" source="REDHAT">RHSA-2004:440</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-323.html" source="REDHAT">RHSA-2004:323</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9981" source="OVAL">oval:org.mitre.oval:def:9981</ref>
    </refs>
    <vuln_soft>
      <prod vendor="tsugio_okamoto" name="lha">
        <vers prev="1" num="1.14" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0695" published="2004-07-27" name="CVE-2004-0695" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Stack-based buffer overflow in the FTP service for 4D WebSTAR 5.3.2 and earlier allows remote attackers to execute arbitrary code via a long FTP command.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/16686" source="XF" adv="1">4dwebstar-long-ftp-bo(16686)</ref>
      <ref url="http://www.atstake.com/research/advisories/2004/a071304-1.txt" source="ATSTAKE" adv="1">A071304-1</ref>
      <ref url="ftp://ftp.4d.com/ACI_PRODUCT_REFERENCE_LIBRARY/4D_PRODUCT_DOCUMENTATION/PDF_Docs_by_4D_Product_A-Z/4D_WebSTAR/Software_Change_History.txt" source="MISC">ftp://ftp.4d.com/ACI_PRODUCT_REFERENCE_LIBRARY/4D_PRODUCT_DOCUMENTATION/PDF_Docs_by_4D_Product_A-Z/4D_WebSTAR/Software_Change_History.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="4d" name="webstar">
        <vers num="4.0" />
        <vers num="5.2" />
        <vers num="5.2.1" />
        <vers num="5.2.2" />
        <vers num="5.2.3" />
        <vers num="5.2.4" />
        <vers num="5.3" />
        <vers num="5.3.1" />
        <vers num="5.3.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0696" published="2004-07-27" name="CVE-2004-0696" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The ShellExample.cgi script in 4D WebSTAR 5.3.2 and earlier allows remote attackers to list arbitrary directories via a URL with the desired path and a "*" (asterisk) character.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/16687" source="XF" adv="1">4dwebstar-view-directory-listing(16687)</ref>
      <ref url="http://www.atstake.com/research/advisories/2004/a071304-1.txt" source="ATSTAKE" adv="1">A071304-1</ref>
      <ref url="ftp://ftp.4d.com/ACI_PRODUCT_REFERENCE_LIBRARY/4D_PRODUCT_DOCUMENTATION/PDF_Docs_by_4D_Product_A-Z/4D_WebSTAR/Software_Change_History.txt" source="MISC">ftp://ftp.4d.com/ACI_PRODUCT_REFERENCE_LIBRARY/4D_PRODUCT_DOCUMENTATION/PDF_Docs_by_4D_Product_A-Z/4D_WebSTAR/Software_Change_History.txt</ref>
      <ref url="http://www.securityfocus.com/bid/10721" source="BID">10721</ref>
    </refs>
    <vuln_soft>
      <prod vendor="4d" name="webstar">
        <vers num="4.0" />
        <vers num="5.2" />
        <vers num="5.2.1" />
        <vers num="5.2.2" />
        <vers num="5.2.3" />
        <vers num="5.2.4" />
        <vers num="5.3" />
        <vers num="5.3.1" />
        <vers num="5.3.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0697" published="2004-07-27" name="CVE-2004-0697" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Unknown vulnerability in 4D WebSTAR 5.3.2 and earlier allows remote attackers to read the php.ini configuration file and possibly obtain sensitive information.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <other />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/16688" source="XF" adv="1">4dwebstar-view-phpini-files(16688)</ref>
      <ref url="http://www.atstake.com/research/advisories/2004/a071304-1.txt" source="ATSTAKE" adv="1">A071304-1</ref>
      <ref url="ftp://ftp.4d.com/ACI_PRODUCT_REFERENCE_LIBRARY/4D_PRODUCT_DOCUMENTATION/PDF_Docs_by_4D_Product_A-Z/4D_WebSTAR/Software_Change_History.txt" source="MISC">ftp://ftp.4d.com/ACI_PRODUCT_REFERENCE_LIBRARY/4D_PRODUCT_DOCUMENTATION/PDF_Docs_by_4D_Product_A-Z/4D_WebSTAR/Software_Change_History.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="4d" name="webstar">
        <vers num="4.0" />
        <vers num="5.2" />
        <vers num="5.2.1" />
        <vers num="5.2.2" />
        <vers num="5.2.3" />
        <vers num="5.2.4" />
        <vers num="5.3" />
        <vers num="5.3.1" />
        <vers num="5.3.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2004-0698" published="2004-07-27" name="CVE-2004-0698" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:N)" CVSS_score="3.6" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="3.9" CVSS_base_score="3.6">
    <desc>
      <descript source="cve">4D WebSTAR 5.3.2 and earlier allows local users to read and modify arbitrary files via a symlink attack.</descript>
    </desc>
    <loss_types>
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/16689" source="XF" adv="1">4dwebstar-symlink(16689)</ref>
      <ref url="http://www.atstake.com/research/advisories/2004/a071304-1.txt" source="ATSTAKE" adv="1">A071304-1</ref>
      <ref url="ftp://ftp.4d.com/ACI_PRODUCT_REFERENCE_LIBRARY/4D_PRODUCT_DOCUMENTATION/PDF_Docs_by_4D_Product_A-Z/4D_WebSTAR/Software_Change_History.txt" source="MISC">ftp://ftp.4d.com/ACI_PRODUCT_REFERENCE_LIBRARY/4D_PRODUCT_DOCUMENTATION/PDF_Docs_by_4D_Product_A-Z/4D_WebSTAR/Software_Change_History.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="4d" name="webstar">
        <vers num="4.0" />
        <vers num="5.2" />
        <vers num="5.2.1" />
        <vers num="5.2.2" />
        <vers num="5.2.3" />
        <vers num="5.2.4" />
        <vers num="5.3" />
        <vers num="5.3.1" />
        <vers num="5.3.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0699" published="2004-09-28" name="CVE-2004-0699" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Heap-based buffer overflow in ASN.1 decoding library in Check Point VPN-1 products, when Aggressive Mode IKE is implemented, allows remote attackers to execute arbitrary code by initiating an IKE negotiation and then sending an IKE packet with malformed ASN.1 data.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/435358" source="CERT-VN">VU#435358</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/16824" source="XF" patch="1" adv="1">vpn1-asn1-decoding-bo(16824)</ref>
      <ref url="http://xforce.iss.net/xforce/alerts/id/178" source="ISS" patch="1" adv="1">20040728 Check Point VPN-1 ASN.1 Decoding Remote Compromise</ref>
      <ref url="http://www.checkpoint.com/techsupport/alerts/asn1.html" source="CONFIRM" patch="1" adv="1">http://www.checkpoint.com/techsupport/alerts/asn1.html</ref>
      <ref url="http://www.ciac.org/ciac/bulletins/o-190.shtml" source="CIAC">O-190</ref>
      <ref url="http://secunia.com/advisories/12177/" source="SECUNIA">12177</ref>
      <ref url="http://www.securityfocus.com/bid/10820" source="BID">10820</ref>
      <ref url="http://www.osvdb.org/displayvuln.php?osvdb_id=8290" source="OSVDB">8290</ref>
      <ref url="http://securitytracker.com/alerts/2004/Jul/1010799.html" source="SECTRACK">1010799</ref>
    </refs>
    <vuln_soft>
      <prod vendor="checkpoint" name="firewall-1">
        <vers num="4.1" edition="sp6" />
      </prod>
      <prod vendor="checkpoint" name="vpn-1">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0700" published="2004-07-27" name="CVE-2004-0700" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Format string vulnerability in the mod_proxy hook functions function in ssl_engine_log.c in mod_ssl before 2.8.19 for Apache before 1.3.31 may allow remote attackers to execute arbitrary messages via format string specifiers in certain log messages for HTTPS that are handled by the ssl_log function.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/303448" source="CERT-VN" adv="1">VU#303448</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/16705" source="XF" patch="1" adv="1">apache-modssl-format-string(16705)</ref>
      <ref url="https://bugzilla.fedora.us/show_bug.cgi?id=1888" source="FEDORA">FLSA:1888</ref>
      <ref url="http://www.securityfocus.com/bid/10736" source="BID">10736</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-408.html" source="REDHAT">RHSA-2004:408</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-405.html" source="REDHAT">RHSA-2004:405</ref>
      <ref url="http://www.osvdb.org/7929" source="OSVDB">7929</ref>
      <ref url="http://www.mandrakesecure.net/en/advisories/advisory.php?name=MDKSA-2004:075" source="MANDRAKE">MDKSA-2004:075</ref>
      <ref url="http://www.debian.org/security/2004/dsa-532" source="DEBIAN">DSA-532</ref>
      <ref url="http://virulent.siyahsapka.org/" source="MISC">http://virulent.siyahsapka.org/</ref>
      <ref url="http://packetstormsecurity.org/0407-advisories/modsslFormat.txt" source="MISC">http://packetstormsecurity.org/0407-advisories/modsslFormat.txt</ref>
      <ref url="http://marc.theaimsgroup.com/?l=apache-modssl&amp;m=109001100906749&amp;w=2" source="MLIST" adv="1">[apache-modssl] 20040716  [ANNOUNCE] mod_ssl 2.8.19 for Apache 1.3.31</ref>
      <ref url="http://www.ubuntu.com/usn/usn-177-1" source="UBUNTU">USN-177-1</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109005001205991&amp;w=2" source="BUGTRAQ">20040716 [OpenPKG-SA-2004.032] OpenPKG Security Advisory (apache)</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000857" source="CONECTIVA">CLA-2004:857</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mod_ssl" name="mod_ssl">
        <vers num="2.3.11" />
        <vers num="2.4.0" />
        <vers num="2.4.1" />
        <vers num="2.4.10" />
        <vers num="2.4.2" />
        <vers num="2.4.3" />
        <vers num="2.4.4" />
        <vers num="2.4.5" />
        <vers num="2.4.6" />
        <vers num="2.4.7" />
        <vers num="2.4.8" />
        <vers num="2.4.9" />
        <vers num="2.5.0" />
        <vers num="2.5.1" />
        <vers num="2.6.0" />
        <vers num="2.6.1" />
        <vers num="2.6.2" />
        <vers num="2.6.3" />
        <vers num="2.6.4" />
        <vers num="2.6.5" />
        <vers num="2.6.6" />
        <vers num="2.7.0" />
        <vers num="2.7.1" />
        <vers num="2.8.0" />
        <vers num="2.8.1" />
        <vers num="2.8.1.2" />
        <vers num="2.8.10" />
        <vers num="2.8.12" />
        <vers num="2.8.14" />
        <vers num="2.8.15" />
        <vers num="2.8.16" />
        <vers num="2.8.17" />
        <vers num="2.8.18" />
        <vers num="2.8.2" />
        <vers num="2.8.3" />
        <vers num="2.8.4" />
        <vers num="2.8.5" />
        <vers num="2.8.5.1" />
        <vers num="2.8.5.2" />
        <vers num="2.8.6" />
        <vers num="2.8.7" />
        <vers num="2.8.8" />
        <vers num="2.8.9" />
      </prod>
      <prod vendor="gentoo" name="linux">
        <vers num="1.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0701" published="2004-07-27" name="CVE-2004-0701" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Sun Ray Server Software (SRSS) 1.3 and 2.0 for Solaris 2.6, 7 and 8 does not properly detect a smartcard removal when the card is quickly removed, reinserted, and removed again, which could cause a user session to stay logged in and allow local users to gain unauthorized access.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/100780" source="CERT-VN">VU#100780</ref>
      <ref url="http://www.securityfocus.com/bid/7457" source="BID" patch="1" adv="1">7457</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/11905" source="XF" adv="1">sun-ray-session-access(11905)</ref>
      <ref url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doc=fsalert%2F53922" source="SUNALERT">53922</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="ray_server_software">
        <vers num="1.3" />
        <vers num="2.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0702" published="2004-07-27" name="CVE-2004-0702" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">DBI in Bugzilla 2.17.1 through 2.17.7 displays the database password in an error message when the SQL server is not running, which could allow remote attackers to gain sensitive information.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/10698" source="BID" patch="1" adv="1">10698</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/16673" source="XF" adv="1">bugzilla-database-password-disclosure(16673)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108965446813639&amp;w=2" source="BUGTRAQ">20040710 [BUGZILLA] Multiple vulnerabilities in Bugzilla 2.16.5 and 2.17.7</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="bugzilla">
        <vers num="2.10" />
        <vers num="2.12" />
        <vers num="2.14" />
        <vers num="2.14.1" />
        <vers num="2.14.2" />
        <vers num="2.14.3" />
        <vers num="2.14.4" />
        <vers num="2.14.5" />
        <vers num="2.16" />
        <vers num="2.16.1" />
        <vers num="2.16.2" />
        <vers num="2.16.3" />
        <vers num="2.16.4" />
        <vers num="2.16.5" />
        <vers num="2.17" />
        <vers num="2.17.1" />
        <vers num="2.17.3" />
        <vers num="2.17.4" />
        <vers num="2.17.5" />
        <vers num="2.17.6" />
        <vers num="2.17.7" />
        <vers num="2.4" />
        <vers num="2.6" />
        <vers num="2.8" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0703" published="2004-07-27" name="CVE-2004-0703" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Unknown vulnerability in the administrative controls in Bugzilla 2.17.1 through 2.17.7 allows users with "grant membership" privileges to grant memberships to groups that the user does not control.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" other="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/10698" source="BID" patch="1" adv="1">10698</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/16672" source="XF" adv="1">bugzilla-editusers-gain-privileges(16672)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108965446813639&amp;w=2" source="BUGTRAQ" adv="1">20040710 [BUGZILLA] Multiple vulnerabilities in Bugzilla 2.16.5 and 2.17.7</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="bugzilla">
        <vers num="2.10" />
        <vers num="2.12" />
        <vers num="2.14" />
        <vers num="2.14.1" />
        <vers num="2.14.2" />
        <vers num="2.14.3" />
        <vers num="2.14.4" />
        <vers num="2.14.5" />
        <vers num="2.16" />
        <vers num="2.16.1" />
        <vers num="2.16.2" />
        <vers num="2.16.3" />
        <vers num="2.16.4" />
        <vers num="2.16.5" />
        <vers num="2.17" />
        <vers num="2.17.1" />
        <vers num="2.17.3" />
        <vers num="2.17.4" />
        <vers num="2.17.5" />
        <vers num="2.17.6" />
        <vers num="2.17.7" />
        <vers num="2.4" />
        <vers num="2.6" />
        <vers num="2.8" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0704" published="2004-07-27" name="CVE-2004-0704" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Unknown vulnerability in (1) duplicates.cgi and (2) buglist.cgi in Bugzilla 2.16.x before 2.16.6, 2.18 before 2.18rc1, when configured to hide products, allows remote attackers to view hidden products.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <config />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/10698" source="BID" patch="1" adv="1">10698</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/16671" source="XF" adv="1">bugzilla-product-name-disclosure(16671)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108965446813639&amp;w=2" source="BUGTRAQ" adv="1">20040710 [BUGZILLA] Multiple vulnerabilities in Bugzilla 2.16.5 and 2.17.7</ref>
    </refs>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0705" published="2004-07-27" name="CVE-2004-0705" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in (1) editcomponents.cgi, (2) editgroups.cgi, (3) editmilestones.cgi, (4) editproducts.cgi, (5) editusers.cgi, and (6) editversions.cgi in Bugzilla 2.16.x before 2.16.6, and 2.18 before 2.18rc1, allow remote attackers to execute arbitrary JavaScript as other users via a URL parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/10698" source="BID" patch="1" adv="1">10698</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/16670" source="XF" adv="1">bugzilla-edit-xss(16670)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108965446813639&amp;w=2" source="BUGTRAQ" adv="1">20040710 [BUGZILLA] Multiple vulnerabilities in Bugzilla 2.16.5 and 2.17.7</ref>
      <ref url="http://bugzilla.mozilla.org/show_bug.cgi?id=235265" source="CONFIRM">http://bugzilla.mozilla.org/show_bug.cgi?id=235265</ref>
    </refs>
  </entry>
  <entry type="CVE" severity="Low" seq="2004-0706" published="2004-07-27" name="CVE-2004-0706" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">Bugzilla 2.17.5 through 2.17.7 embeds the password in an image URL, which could allow local users to view the password in the web server log files.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/10698" source="BID" patch="1" adv="1">10698</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/16669" source="XF" adv="1">bugzilla-chart-view-password(16669)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108965446813639&amp;w=2" source="BUGTRAQ" adv="1">20040710 [BUGZILLA] Multiple vulnerabilities in Bugzilla 2.16.5 and 2.17.7</ref>
      <ref url="http://bugzilla.mozilla.org/show_bug.cgi?id=235510" source="CONFIRM">http://bugzilla.mozilla.org/show_bug.cgi?id=235510</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="bugzilla">
        <vers num="2.10" />
        <vers num="2.12" />
        <vers num="2.14" />
        <vers num="2.14.1" />
        <vers num="2.14.2" />
        <vers num="2.14.3" />
        <vers num="2.14.4" />
        <vers num="2.14.5" />
        <vers num="2.16" />
        <vers num="2.16.1" />
        <vers num="2.16.2" />
        <vers num="2.16.3" />
        <vers num="2.16.4" />
        <vers num="2.16.5" />
        <vers num="2.17" />
        <vers num="2.17.1" />
        <vers num="2.17.3" />
        <vers num="2.17.4" />
        <vers num="2.17.5" />
        <vers num="2.17.6" />
        <vers num="2.17.7" />
        <vers num="2.4" />
        <vers num="2.6" />
        <vers num="2.8" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0707" published="2004-07-27" name="CVE-2004-0707" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in editusers.cgi in Bugzilla 2.16.x before 2.16.6, and 2.18 before 2.18rc1, allows remote attackers with privileges to grant membership to any group to execute arbitrary SQL.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/10698" source="BID" patch="1" adv="1">10698</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/16668" source="XF" adv="1">bugzilla-editusers-sql-injection(16668)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108965446813639&amp;w=2" source="BUGTRAQ" adv="1">20040710 [BUGZILLA] Multiple vulnerabilities in Bugzilla 2.16.5 and 2.17.7</ref>
      <ref url="http://bugzilla.mozilla.org/show_bug.cgi?id=244272" source="CONFIRM">http://bugzilla.mozilla.org/show_bug.cgi?id=244272</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="bugzilla">
        <vers num="2.10" />
        <vers num="2.12" />
        <vers num="2.14" />
        <vers num="2.14.1" />
        <vers num="2.14.2" />
        <vers num="2.14.3" />
        <vers num="2.14.4" />
        <vers num="2.14.5" />
        <vers num="2.16" />
        <vers num="2.16.1" />
        <vers num="2.16.2" />
        <vers num="2.16.3" />
        <vers num="2.16.4" />
        <vers num="2.16.5" />
        <vers num="2.17" />
        <vers num="2.17.1" />
        <vers num="2.17.3" />
        <vers num="2.17.4" />
        <vers num="2.17.5" />
        <vers num="2.17.6" />
        <vers num="2.17.7" />
        <vers num="2.4" />
        <vers num="2.6" />
        <vers num="2.8" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0708" published="2004-07-27" name="CVE-2004-0708" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">MoinMoin 1.2.1 and earlier allows remote attackers to gain privileges by creating a user with the same name as an existing group that has higher privileges.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <access />
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/10568" source="BID" patch="1" adv="1">10568</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200407-09.xml" source="GENTOO" patch="1" adv="1">GLSA-200407-09</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/16465" source="XF" adv="1">moinmoin-gain-admin-access(16465)</ref>
      <ref url="http://www.osvdb.org/6704" source="OSVDB">6704</ref>
      <ref url="http://www.osvdb.org/6704" source="MISC">http://www.osvdb.org/6704</ref>
      <ref url="http://sourceforge.net/tracker/index.php?func=detail&amp;aid=948103&amp;group_id=8482&amp;atid=108482" source="CONFIRM">http://sourceforge.net/tracker/index.php?func=detail&amp;aid=948103&amp;group_id=8482&amp;atid=108482</ref>
      <ref url="http://secunia.com/advisories/11807" source="SECUNIA">11807</ref>
    </refs>
    <vuln_soft>
      <prod vendor="moinmoin" name="moinmoin">
        <vers num="1.1" />
        <vers num="1.2" />
        <vers num="1.2.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0709" published="2004-07-27" name="CVE-2004-0709" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">HP OpenView Select Access 5.0 through 6.0 does not correctly decode UTF-8 encoded unicode characters in a URL, which could allow remote attackers to bypass access restrictions.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <access />
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/205766" source="CERT-VN" patch="1" adv="1">VU#205766</ref>
      <ref url="http://www.securityfocus.com/bid/10414" source="BID" patch="1" adv="1">10414</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/16247" source="XF" adv="1">openview-select-gain-access(16247)</ref>
      <ref url="http://www.securityfocus.com/advisories/6774" source="HP">SSRT4719</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hp" name="openview_select_access">
        <vers num="5.0" edition="patch_4" />
        <vers num="5.1" edition="patch_1" />
        <vers num="5.2" />
        <vers num="6.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0710" published="2004-07-27" name="CVE-2004-0710" modified="2009-03-04" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">IP Security VPN Services Module (VPNSM) in Cisco Catalyst 6500 Series Switch and the Cisco 7600 Series Internet Routers running IOS before 12.2(17b)SXA, before 12.2(17d)SXB, or before 12.2(14)SY03 could allow remote attackers to cause a denial of service (device crash and reload) via a malformed Internet Key Exchange (IKE) packet.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/904310" source="CERT-VN" adv="1">VU#904310</ref>
      <ref url="http://www.cisco.com/warp/public/707/cisco-sa-20040408-vpnsm.shtml" source="CISCO" patch="1" adv="1">20040408 Cisco IPSec VPN Services Module Malformed IKE Packet Vulnerability</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15797" source="XF">cisco-vpnsm-ike-dos(15797)</ref>
      <ref url="http://www.securityfocus.com/bid/10083" source="BID" adv="1">10083</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5696" source="OVAL">oval:org.mitre.oval:def:5696</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="ios">
        <vers num="12.2(14)sy" />
        <vers num="12.2(14)za" />
        <vers num="12.2(14)za2" />
        <vers num="12.2(17a)sxa" />
        <vers num="12.2sxa" />
        <vers num="12.2sxb" />
        <vers num="12.2sy" />
        <vers num="12.2za" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0711" published="2004-07-27" name="CVE-2004-0711" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">The URL pattern matching feature in BEA WebLogic Server 6.x matches illegal patterns ending in "*" as wildcards as if they were the legal "/*" pattern, which could cause WebLogic 7.x to allow remote attackers to bypass intended access restrictions because the illegal patterns are properly rejected.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
      <env />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/184558" source="CERT-VN" adv="1">VU#184558</ref>
      <ref url="http://www.securityfocus.com/bid/10184" source="BID" patch="1" adv="1">10184</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15927" source="XF" adv="1">weblogic-urlpattern-obtain-information(15927)</ref>
      <ref url="http://dev2dev.bea.com/resourcelibrary/advisoriesnotifications/BEA04_56.00.jsp" source="CONFIRM">http://dev2dev.bea.com/resourcelibrary/advisoriesnotifications/BEA04_56.00.jsp</ref>
    </refs>
    <vuln_soft>
      <prod vendor="bea" name="weblogic_server">
        <vers num="7.0" edition="" />
        <vers num="7.0" edition=":win32" />
        <vers num="7.0" edition=":express" />
        <vers num="7.0" edition="sp1" />
        <vers num="7.0" edition="sp1:win32" />
        <vers num="7.0" edition="sp1:express" />
        <vers num="7.0" edition="sp2" />
        <vers num="7.0" edition="sp2:express" />
        <vers num="7.0" edition="sp2:win32" />
        <vers num="7.0" edition="sp3" />
        <vers num="7.0" edition="sp3:express" />
        <vers num="7.0" edition="sp3:win32" />
        <vers num="7.0" edition="sp4" />
        <vers num="7.0" edition="sp4:win32" />
        <vers num="7.0" edition="sp4:express" />
        <vers num="8.1" edition="" />
        <vers num="8.1" edition=":win32" />
        <vers num="8.1" edition=":express" />
        <vers num="8.1" edition="sp1" />
        <vers num="8.1" edition="sp1:express" />
        <vers num="8.1" edition="sp1:win32" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0712" published="2004-07-27" name="CVE-2004-0712" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">The configuration tools (1) config.sh in Unix or (2) config.cmd in Windows for BEA WebLogic Server 8.1 through SP2 create a log file that contains the administrative username and password in cleartext, which could allow local users to gain privileges.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/574222" source="CERT-VN" patch="1" adv="1">VU#574222</ref>
      <ref url="http://www.securityfocus.com/bid/10188" source="BID" patch="1" adv="1">10188</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15926" source="XF" adv="1">weblogic-admin-password-plaintext(15926)</ref>
      <ref url="http://dev2dev.bea.com/resourcelibrary/advisoriesnotifications/BEA04_58.00.jsp" source="CONFIRM">http://dev2dev.bea.com/resourcelibrary/advisoriesnotifications/BEA04_58.00.jsp</ref>
    </refs>
    <vuln_soft>
      <prod vendor="bea" name="weblogic_server">
        <vers num="8.1" edition="" />
        <vers num="8.1" edition=":win32" />
        <vers num="8.1" edition=":express" />
        <vers num="8.1" edition="sp1" />
        <vers num="8.1" edition="sp1:express" />
        <vers num="8.1" edition="sp1:win32" />
        <vers num="8.1" edition="sp2" />
        <vers num="8.1" edition="sp2:express" />
        <vers num="8.1" edition="sp2:win32" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0713" published="2004-07-27" name="CVE-2004-0713" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:P)" CVSS_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_base_score="6.4">
    <desc>
      <descript source="cve">The remove method in a stateful Enterprise JavaBean (EJB) in BEA WebLogic Server and WebLogic Express version 8.1 through SP2, 7.0 through SP4, and 6.1 through SP6, does not properly check EJB permissions before unexporting a bean, which allows remote authenticated users to remove EJB objects from remote views before the security exception is thrown.</descript>
    </desc>
    <loss_types>
      <avail />
      <int />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/658878" source="CERT-VN" adv="1">VU#658878</ref>
      <ref url="http://www.securityfocus.com/bid/10185" source="BID" patch="1" adv="1">10185</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15928" source="XF" adv="1">weblogic-ejb-object-deletion(15928)</ref>
      <ref url="http://dev2dev.bea.com/resourcelibrary/advisoriesnotifications/BEA04_57.00.jsp" source="CONFIRM">http://dev2dev.bea.com/resourcelibrary/advisoriesnotifications/BEA04_57.00.jsp</ref>
    </refs>
    <vuln_soft>
      <prod vendor="bea" name="weblogic_server">
        <vers num="6.1" edition="" />
        <vers num="6.1" edition=":express" />
        <vers num="6.1" edition=":win32" />
        <vers num="6.1" edition="sp1" />
        <vers num="6.1" edition="sp1:express" />
        <vers num="6.1" edition="sp1:win32" />
        <vers num="6.1" edition="sp2" />
        <vers num="6.1" edition="sp2:win32" />
        <vers num="6.1" edition="sp2:express" />
        <vers num="6.1" edition="sp3" />
        <vers num="6.1" edition="sp3:win32" />
        <vers num="6.1" edition="sp3:express" />
        <vers num="6.1" edition="sp4" />
        <vers num="6.1" edition="sp4:win32" />
        <vers num="6.1" edition="sp4:express" />
        <vers num="6.1" edition="sp5" />
        <vers num="6.1" edition="sp5:win32" />
        <vers num="6.1" edition="sp5:express" />
        <vers num="6.1" edition="sp6" />
        <vers num="6.1" edition="sp6:win32" />
        <vers num="7.0" edition="" />
        <vers num="7.0" edition=":win32" />
        <vers num="7.0" edition=":express" />
        <vers num="7.0" edition="sp1" />
        <vers num="7.0" edition="sp1:express" />
        <vers num="7.0" edition="sp1:win32" />
        <vers num="7.0" edition="sp2" />
        <vers num="7.0" edition="sp2:win32" />
        <vers num="7.0" edition="sp2:express" />
        <vers num="7.0" edition="sp3" />
        <vers num="7.0" edition="sp3:win32" />
        <vers num="7.0" edition="sp3:express" />
        <vers num="7.0" edition="sp4" />
        <vers num="7.0" edition="sp4:express" />
        <vers num="7.0" edition="sp4:win32" />
        <vers num="8.1" edition="" />
        <vers num="8.1" edition=":express" />
        <vers num="8.1" edition=":win32" />
        <vers num="8.1" edition="sp1" />
        <vers num="8.1" edition="sp1:express" />
        <vers num="8.1" edition="sp1:win32" />
        <vers num="8.1" edition="sp2" />
        <vers num="8.1" edition="sp2:express" />
        <vers num="8.1" edition="sp2:win32" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0714" published="2004-07-27" name="CVE-2004-0714" modified="2009-03-04" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Cisco Internetwork Operating System (IOS) 12.0S through 12.3T attempts to process SNMP solicited operations on improper ports (UDP 162 and a randomly chosen UDP port), which allows remote attackers to cause a denial of service (device reload and memory corruption).</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/162451" source="CERT-VN" patch="1" adv="1">VU#162451</ref>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA04-111B.html" source="CERT" adv="1">TA04-111B</ref>
      <ref url="http://www.securityfocus.com/bid/10186" source="BID" patch="1" adv="1">10186</ref>
      <ref url="http://www.cisco.com/warp/public/707/cisco-sa-20040420-snmp.shtml" source="CISCO" patch="1" adv="1">20040420 Vulnerabilities in SNMP Message Processing</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15921" source="XF">cisco-ios-snmp-udp-dos(15921)</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5845" source="OVAL">oval:org.mitre.oval:def:5845</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="ios">
        <vers num="12.0(23)s4" />
        <vers num="12.0(23)s5" />
        <vers num="12.0(24)s4" />
        <vers num="12.0(24)s5" />
        <vers num="12.0(26)s1" />
        <vers num="12.0(27)s" />
        <vers num="12.0(27)sv" />
        <vers num="12.0(27)sv1" />
        <vers num="12.0s" />
        <vers num="12.0sv" />
        <vers num="12.1(20)e" />
        <vers num="12.1(20)e1" />
        <vers num="12.1(20)e2" />
        <vers num="12.1(20)ea1" />
        <vers num="12.1(20)ec" />
        <vers num="12.1(20)ec1" />
        <vers num="12.1(20)eo" />
        <vers num="12.1(20)ew" />
        <vers num="12.1(20)ew1" />
        <vers num="12.1e" />
        <vers num="12.1ea" />
        <vers num="12.1eb" />
        <vers num="12.1ec" />
        <vers num="12.1eo" />
        <vers num="12.1eu" />
        <vers num="12.1ew" />
        <vers num="12.2" />
        <vers num="12.2(12g)" />
        <vers num="12.2(12h)" />
        <vers num="12.2(20)s" />
        <vers num="12.2(20)s1" />
        <vers num="12.2(21)" />
        <vers num="12.2(21a)" />
        <vers num="12.2(23)" />
        <vers num="12.2s" />
        <vers num="12.2sw" />
        <vers num="12.2zq" />
        <vers num="12.3" />
        <vers num="12.3(2)t3" />
        <vers num="12.3(2)xc1" />
        <vers num="12.3(2)xc2" />
        <vers num="12.3(4)t" />
        <vers num="12.3(4)t1" />
        <vers num="12.3(4)t2" />
        <vers num="12.3(4)t3" />
        <vers num="12.3(4)xd" />
        <vers num="12.3(4)xd1" />
        <vers num="12.3(5)" />
        <vers num="12.3(5a)" />
        <vers num="12.3(5a)b" />
        <vers num="12.3(5b)" />
        <vers num="12.3(6)" />
        <vers num="12.3b" />
        <vers num="12.3t" />
        <vers num="12.3xc" />
        <vers num="12.3xd" />
        <vers num="12.3xe" />
        <vers num="12.3xf" />
        <vers num="12.3xg" />
        <vers num="12.3xh" />
        <vers num="12.3xk" />
        <vers num="12.3xq" />
      </prod>
      <prod vendor="cisco" name="ons_15454_optical_transport_platform">
        <vers num="3.0" />
        <vers num="3.1_.0" />
        <vers num="3.2_.0" />
        <vers num="3.3" />
        <vers num="3.4" />
        <vers num="4.0" />
        <vers num="4.0(1)" />
        <vers num="4.0(2)" />
        <vers num="4.1" />
        <vers num="4.1(0)" />
        <vers num="4.1(1)" />
        <vers num="4.1(2)" />
        <vers num="4.1(3)" />
      </prod>
      <prod vendor="cisco" name="ons_15454e_optical_transport_platform">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0715" published="2004-07-27" name="CVE-2004-0715" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_score="5.1" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="4.9" CVSS_base_score="5.1">
    <desc>
      <descript source="cve">The WebLogic Authentication provider for BEA WebLogic Server and WebLogic Express 8.1 through SP2 and 7.0 through SP4 does not properly clear member relationships when a group is deleted, which can cause a new group with the same name to have the members of the old group, which allows group members to gain privileges.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <access />
      <design />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/470470" source="CERT-VN" adv="1">VU#470470</ref>
      <ref url="http://www.securityfocus.com/bid/10130" source="BID" patch="1" adv="1">10130</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15861" source="XF" adv="1">weblogic-authentication-gain-privileges(15861)</ref>
      <ref url="http://dev2dev.bea.com/resourcelibrary/advisoriesnotifications/BEA04_52.01.jsp" source="CONFIRM">http://dev2dev.bea.com/resourcelibrary/advisoriesnotifications/BEA04_52.01.jsp</ref>
      <ref url="http://www.osvdb.org/5299" source="OSVDB">5299</ref>
      <ref url="http://securitytracker.com/id?1009763" source="SECTRACK">1009763</ref>
      <ref url="http://secunia.com/advisories/11356" source="SECUNIA">11356</ref>
    </refs>
    <vuln_soft>
      <prod vendor="bea" name="weblogic_server">
        <vers num="7.0" edition="" />
        <vers num="7.0" edition=":win32" />
        <vers num="7.0" edition=":express" />
        <vers num="7.0" edition="sp1" />
        <vers num="7.0" edition="sp1:win32" />
        <vers num="7.0" edition="sp1:express" />
        <vers num="7.0" edition="sp2" />
        <vers num="7.0" edition="sp2:express" />
        <vers num="7.0" edition="sp2:win32" />
        <vers num="7.0" edition="sp3" />
        <vers num="7.0" edition="sp3:express" />
        <vers num="7.0" edition="sp3:win32" />
        <vers num="7.0" edition="sp4" />
        <vers num="7.0" edition="sp4:win32" />
        <vers num="7.0" edition="sp4:express" />
        <vers num="8.1" edition="" />
        <vers num="8.1" edition=":win32" />
        <vers num="8.1" edition=":express" />
        <vers num="8.1" edition="sp1" />
        <vers num="8.1" edition="sp1:express" />
        <vers num="8.1" edition="sp1:win32" />
        <vers num="8.1" edition="sp2" />
        <vers num="8.1" edition="sp2:express" />
        <vers num="8.1" edition="sp2:win32" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0716" published="2004-08-06" name="CVE-2004-0716" modified="2008-10-24" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Buffer overflow in the DCE daemon (DCED) for the DCE endpoint mapper (epmap) on HP-UX 11 allows remote attackers to execute arbitrary code via a request with a small fragment length and a large amount of data.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://support.entegrity.com/private/patches/dce/ssrt4741.asp" source="CONFIRM" patch="1">http://support.entegrity.com/private/patches/dce/ssrt4741.asp</ref>
      <ref url="http://www.atstake.com/research/advisories/2004/a072204-1.txt" source="ATSTAKE">A072204-1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hp" name="hp-ux">
        <vers num="11" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0717" published="2004-07-27" name="CVE-2004-0717" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Opera 7.51 for Windows and 7.50 for Linux does not properly prevent a frame in one domain from injecting content into a frame that belongs to another domain, which facilitates web site spoofing and other attacks, aka the frame injection vulnerability.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/1598" source="XF" adv="1">http-frame-spoof(1598)</ref>
      <ref url="http://secunia.com/multiple_browsers_frame_injection_vulnerability_test/" source="MISC" adv="1">http://secunia.com/multiple_browsers_frame_injection_vulnerability_test/</ref>
      <ref url="http://secunia.com/advisories/11978" source="SECUNIA" adv="1">11978</ref>
    </refs>
    <vuln_soft>
      <prod vendor="opera_software" name="opera_web_browser">
        <vers num="7.50" />
        <vers num="7.51" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0718" published="2004-07-27" name="CVE-2004-0718" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">The (1) Mozilla 1.6, (2) Firebird 0.7, (3) Firefox 0.8, and (4) Netscape 7.1 web browsers do not properly prevent a frame in one domain from injecting content into a frame that belongs to another domain, which facilitates web site spoofing and other attacks, aka the frame injection vulnerability.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/1598" source="XF" adv="1">http-frame-spoof(1598)</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-421.html" source="REDHAT">RHSA-2004:421</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2004_36_mozilla.html" source="SUSE">SUSE-SA:2004:036</ref>
      <ref url="http://secunia.com/multiple_browsers_frame_injection_vulnerability_test/" source="MISC" adv="1">http://secunia.com/multiple_browsers_frame_injection_vulnerability_test/</ref>
      <ref url="http://secunia.com/advisories/11978" source="SECUNIA" adv="1">11978</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9997" source="OVAL">oval:org.mitre.oval:def:9997</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109900315219363&amp;w=2" source="FEDORA">FLSA:2089</ref>
      <ref url="http://bugzilla.mozilla.org/show_bug.cgi?id=246448" source="CONFIRM">http://bugzilla.mozilla.org/show_bug.cgi?id=246448</ref>
      <ref url="http://www.securityfocus.com/bid/15495" source="BID">15495</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2004:082" source="MANDRAKE">MDKSA-2004:082</ref>
      <ref url="http://www.debian.org/security/2005/dsa-810" source="DEBIAN">DSA-810</ref>
      <ref url="http://www.debian.org/security/2005/dsa-777" source="DEBIAN">DSA-777</ref>
      <ref url="ftp://ftp.sco.com/pub/updates/OpenServer/SCOSA-2005.49/SCOSA-2005.49.txt" source="SCO">SCOSA-2005.49</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:4756" source="OVAL" sig="1">oval:org.mitre.oval:def:4756</ref>
    </refs>
    <vuln_soft>
      <prod vendor="firebirdsql" name="firebird">
        <vers num="0.7" />
      </prod>
      <prod vendor="mozilla" name="mozilla">
        <vers num="1.6" />
      </prod>
      <prod vendor="netscape" name="navigator">
        <vers num="7.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0719" published="2004-07-27" name="CVE-2004-0719" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Internet Explorer for Mac 5.2.3, Internet Explorer 6 on Windows XP, and possibly other versions, does not properly prevent a frame in one domain from injecting content into a frame that belongs to another domain, which facilitates web site spoofing and other attacks, aka the frame injection vulnerability.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/11966" source="SECUNIA" patch="1" adv="1">11966</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/1598" source="XF" adv="1">http-frame-spoof(1598)</ref>
      <ref url="http://secunia.com/multiple_browsers_frame_injection_vulnerability_test/" source="MISC" adv="1">http://secunia.com/multiple_browsers_frame_injection_vulnerability_test/</ref>
      <ref url="http://secunia.com/advisories/11978" source="SECUNIA" adv="1">11978</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="ie">
        <vers num="5.0.1" edition="sp1" />
        <vers num="5.0.1" edition="sp2" />
        <vers num="5.0.1" edition="sp3" />
        <vers num="5.0.1" edition="sp4" />
        <vers num="5.5" edition="sp1" />
        <vers num="5.5" edition="sp2" />
        <vers num="6.0" edition="sp1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0720" published="2004-07-27" name="CVE-2004-0720" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Safari 1.2.2 does not properly prevent a frame in one domain from injecting content into a frame that belongs to another domain, which facilitates web site spoofing and other attacks, aka the frame injection vulnerability.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <design />
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/1598" source="XF" adv="1">http-frame-spoof(1598)</ref>
      <ref url="http://secunia.com/multiple_browsers_frame_injection_vulnerability_test/" source="MISC" adv="1">http://secunia.com/multiple_browsers_frame_injection_vulnerability_test/</ref>
      <ref url="http://secunia.com/advisories/11978" source="SECUNIA" adv="1">11978</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="safari">
        <vers num="1.2.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0721" published="2004-07-27" name="CVE-2004-0721" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Konqueror 3.1.3, 3.2.2, and possibly other versions does not properly prevent a frame in one domain from injecting content into a frame that belongs to another domain, which facilitates web site spoofing and other attacks, aka the frame injection vulnerability.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <design />
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/1598" source="XF" adv="1">http-frame-spoof(1598)</ref>
      <ref url="http://www.kde.org/info/security/advisory-20040811-3.txt" source="CONFIRM">http://www.kde.org/info/security/advisory-20040811-3.txt</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200408-13.xml" source="GENTOO">200408-13</ref>
      <ref url="http://secunia.com/multiple_browsers_frame_injection_vulnerability_test/" source="MISC" adv="1">http://secunia.com/multiple_browsers_frame_injection_vulnerability_test/</ref>
      <ref url="http://secunia.com/advisories/11978" source="SECUNIA" adv="1">11978</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11371" source="OVAL">oval:org.mitre.oval:def:11371</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109225538901170&amp;w=2" source="BUGTRAQ">20040811 KDE Security Advisories: Temporary File and Konqueror Frame Injection Vulnerabilities</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000864" source="CONECTIVA">CLA-2004:864</ref>
    </refs>
    <vuln_soft>
      <prod vendor="kde" name="konqueror">
        <vers num="3.1.3" />
        <vers num="3.2.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0722" published="2004-08-18" name="CVE-2004-0722" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Integer overflow in the SOAPParameter object constructor in (1) Netscape version 7.0 and 7.1 and (2) Mozilla 1.6, and possibly earlier versions, allows remote attackers to execute arbitrary code.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" admin="1" />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/16862" source="XF">mozilla-netscape-soapparameter-bo(16862)</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-421.html" source="REDHAT">RHSA-2004:421</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2004_36_mozilla.html" source="SUSE">SUSE-SA:2004:036</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9378" source="OVAL">oval:org.mitre.oval:def:9378</ref>
      <ref url="http://bugzilla.mozilla.org/show_bug.cgi?id=236618" source="CONFIRM">http://bugzilla.mozilla.org/show_bug.cgi?id=236618</ref>
      <ref url="http://www.securityfocus.com/bid/15495" source="BID">15495</ref>
      <ref url="http://www.idefense.com/application/poi/display?id=117&amp;type=vulnerabilities" source="MISC">http://www.idefense.com/application/poi/display?id=117&amp;type=vulnerabilities</ref>
      <ref url="ftp://ftp.sco.com/pub/updates/OpenServer/SCOSA-2005.49/SCOSA-2005.49.txt" source="SCO">SCOSA-2005.49</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:4629" source="OVAL" sig="1">oval:org.mitre.oval:def:4629</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="mozilla">
        <vers num="1.6" />
      </prod>
      <prod vendor="netscape" name="navigator">
        <vers num="7.0" />
        <vers num="7.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0723" published="2004-07-27" name="CVE-2004-0723" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)" CVSS_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_base_score="6.4">
    <desc>
      <descript source="cve">Microsoft Java virtual machine (VM) 5.0.0.3810 allows remote attackers to bypass sandbox restrictions to read or write certain data between applets from different domains via the "GET/Key" and "PUT/Key/Value" commands, aka "cross-site Java."</descript>
    </desc>
    <loss_types>
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/16666" source="XF">msjvm-sandbox-bypass(16666)</ref>
      <ref url="http://www.securityfocus.com/bid/10688" source="BID" adv="1">10688</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108948405808522&amp;w=2" source="BUGTRAQ" adv="1">20040710 Covert Channels allow Cross-Site-Java in Microsoft VM</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="java_virtual_machine">
        <vers num="5.0.0.3810" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0724" published="2004-07-27" name="CVE-2004-0724" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The Half-Life engine before July 7 2004 allows remote attackers to cause a denial of service (server or client crash) via an empty fragmented packet.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/16674" source="XF" adv="1">halflife-packet-dos(16674)</ref>
      <ref url="http://www.securityfocus.com/bid/10700" source="BID">10700</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108966465302107&amp;w=2" source="BUGTRAQ">20040712 Remote crash of Half-Life servers and clients (versions before the 07 July 2004)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="valve_software" name="half-life">
        <vers num="1.1.0.4" edition="" />
        <vers num="1.1.0.4" edition=":windows" />
        <vers num="1.1.0.4" edition=":linux" />
        <vers num="1.1.0.8" />
        <vers num="1.1.0.9" />
        <vers num="1.1.1.0" />
      </prod>
      <prod vendor="valve_software" name="half-life_dedicated_server">
        <vers num="3.1" />
        <vers num="3.1.0.4" edition="" />
        <vers num="3.1.0.4" edition=":linux" />
        <vers num="3.1.0.5" edition="" />
        <vers num="3.1.0.5" edition=":linux" />
        <vers num="3.1.0.6" edition="" />
        <vers num="3.1.0.6" edition=":linux" />
        <vers num="3.1.0.7" edition="" />
        <vers num="3.1.0.7" edition=":linux" />
        <vers num="3.1.0.8" edition="" />
        <vers num="3.1.0.8" edition=":linux" />
        <vers num="3.1.0.9" edition="" />
        <vers num="3.1.0.9" edition=":linux" />
        <vers num="3.1.1.0" edition="" />
        <vers num="3.1.1.0" edition=":linux" />
        <vers num="3.1.1.1c1" edition="" />
        <vers num="3.1.1.1c1" edition=":linux" />
        <vers num="3.1.1.1d" edition="" />
        <vers num="3.1.1.1d" edition=":linux" />
        <vers num="3.1.1.1e" edition="" />
        <vers num="3.1.1.1e" edition=":win32" />
        <vers num="3.1.1.1e" edition=":linux" />
        <vers num="3.1.3" />
        <vers num="4.1.0.4" edition="" />
        <vers num="4.1.0.4" edition=":win32" />
        <vers num="4.1.0.6" edition="" />
        <vers num="4.1.0.6" edition=":win32" />
        <vers num="4.1.0.7" edition="" />
        <vers num="4.1.0.7" edition=":win32" />
        <vers num="4.1.0.8" edition="" />
        <vers num="4.1.0.8" edition=":win32" />
        <vers num="4.1.0.9" edition="" />
        <vers num="4.1.0.9" edition=":win32" />
        <vers num="4.1.1.0" edition="" />
        <vers num="4.1.1.0" edition=":win32" />
        <vers num="4.1.1.1c1" edition="" />
        <vers num="4.1.1.1c1" edition=":win32" />
        <vers num="4.1.1.1d_beta" edition="" />
        <vers num="4.1.1.1d_beta" edition=":win32" />
        <vers num="4.1.1.1e" edition="" />
        <vers num="4.1.1.1e" edition=":win32" />
        <vers num="4.1.1.1e" edition=":linux" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0725" published="2004-07-27" name="CVE-2004-0725" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in help.php in Moodle 1.3.2 and 1.4 dev allows remote attackers to inject arbitrary web script or HTML via the file parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/10718" source="BID" patch="1" adv="1">10718</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108973588000027&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20040713 Moodle XSS Vulnerability</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/16684" source="XF" adv="1">moodle-help-file-xss(16684)</ref>
      <ref url="http://cvs.sourceforge.net/viewcvs.py/moodle/moodle/help.php" source="CONFIRM">http://cvs.sourceforge.net/viewcvs.py/moodle/moodle/help.php</ref>
    </refs>
    <vuln_soft>
      <prod vendor="moodle" name="moodle">
        <vers num="1.1.1" />
        <vers num="1.2" />
        <vers num="1.2.1" />
        <vers num="1.3" />
        <vers num="1.3.1" />
        <vers num="1.3.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0726" published="2004-07-27" name="CVE-2004-0726" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">The Windows Media Player control in Microsoft Windows 2000 allows remote attackers to execute arbitrary script in the local computer zone via an ASX filename that contains javascript, which is executed in the local context in a preview panel.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/16704" source="XF" adv="1">win2k-media-code-execution(16704)</ref>
      <ref url="http://www.securityfocus.com/bid/10693" source="BID" adv="1">10693</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108965512912175&amp;w=2" source="BUGTRAQ" adv="1">20040711 Media Preview Script Execution Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_2000">
        <vers num="" edition=":datacenter_server" />
        <vers num="" edition=":server" />
        <vers num="" edition=":advanced_server" />
        <vers num="" edition=":professional" />
        <vers num="" edition="sp1" />
        <vers num="" edition="sp1:professional" />
        <vers num="" edition="sp1:datacenter_server" />
        <vers num="" edition="sp1:server" />
        <vers num="" edition="sp1:advanced_server" />
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:datacenter_server" />
        <vers num="" edition="sp2:advanced_server" />
        <vers num="" edition="sp2:professional" />
        <vers num="" edition="sp2:server" />
        <vers num="" edition="sp3" />
        <vers num="" edition="sp3:professional" />
        <vers num="" edition="sp3:datacenter_server" />
        <vers num="" edition="sp3:advanced_server" />
        <vers num="" edition="sp3:server" />
        <vers num="" edition="sp4" />
        <vers num="" edition="sp4:datacenter_server" />
        <vers num="" edition="sp4:server" />
        <vers num="" edition="sp4:professional" />
        <vers num="" edition="sp4:advanced_server" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0727" published="2004-07-27" name="CVE-2004-0727" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Microsoft Internet Explorer 6.0.2800.1106 on Microsoft Windows XP SP2, and other versions including 5.01 and 5.5, allows remote web servers to bypass zone restrictions and execute arbitrary code in the local computer zone by redirecting a function to another function with the same name, as demonstrated by SimilarMethodNameRedir, aka the "Similar Method Name Redirection Cross Domain Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA04-293A.html" source="CERT">TA04-293A</ref>
      <ref url="http://www.kb.cert.org/vuls/id/207264" source="CERT-VN">VU#207264</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/16681" source="XF" adv="1">ie-function-redirect-xss(16681)</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms04-038.asp" source="MS">MS04-038</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108966512815373&amp;w=2" source="BUGTRAQ" adv="1">20040711 MSIE Similar Method Name Redirection Cross Site/Zone Scripting</ref>
      <ref url="http://freehost07.websamba.com/greyhats/similarmethodnameredir.htm" source="MISC">http://freehost07.websamba.com/greyhats/similarmethodnameredir.htm</ref>
      <ref url="http://secunia.com/advisories/12048" source="SECUNIA">12048</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:7906" source="OVAL" sig="1">oval:org.mitre.oval:def:7906</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:7496" source="OVAL" sig="1">oval:org.mitre.oval:def:7496</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:7448" source="OVAL" sig="1">oval:org.mitre.oval:def:7448</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:7084" source="OVAL" sig="1">oval:org.mitre.oval:def:7084</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6829" source="OVAL" sig="1">oval:org.mitre.oval:def:6829</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:4702" source="OVAL" sig="1">oval:org.mitre.oval:def:4702</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="ie">
        <vers num="6.0.2800.1106" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0728" published="2004-07-27" name="CVE-2004-0728" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The Remote Control Client service in Microsoft's Systems Management Server (SMS) 2.50.2726.0 allows remote attackers to cause a denial of service (crash) via a data packet to TCP port 2702 that causes the server to read or write to an invalid memory address.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/16696" source="XF" adv="1">sms-remote-service-dos(16696)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108983763710315&amp;w=2" source="BUGTRAQ" adv="1">20040714 [HV-MED] DoS in Microsoft SMS Client</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="systems_management_server">
        <vers num="1.2" edition="sp1" />
        <vers num="1.2" edition="sp2" />
        <vers num="1.2" edition="sp3" />
        <vers num="1.2" edition="sp4" />
        <vers num="2.0" edition="sp1" />
        <vers num="2.50.2726" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0729" published="2004-07-27" name="CVE-2004-0729" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">PhpBB 2.0.8 allows remote attackers to gain sensitive information via an invalid (1) category_rows parameter to index.php, (2) faq parameter to faq.php, or (3) ranksrow parameter to profile.php, which reveal the full path in an error message.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108999024506020&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20040716 [waraxe-2004-SA#034 - XSS and path full path disclosure in PhpBB 2.0.8]</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/16723" source="XF" adv="1">phpbb-usercpviewprofile-path-disclosure(16723)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/16720" source="XF">phpbb-lang-faq-path-disclosure(16720)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/16716" source="XF">phpbb-indexphp-path-disclosure(16716)</ref>
      <ref url="http://www.waraxe.us/index.php?modname=sa&amp;id=34" source="MISC">http://www.waraxe.us/index.php?modname=sa&amp;id=34</ref>
    </refs>
    <vuln_soft>
      <prod vendor="phpbb_group" name="phpbb">
        <vers num="2.0.8" />
        <vers num="2.0.8a" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0730" published="2004-07-27" name="CVE-2004-0730" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in PhpBB 2.0.8 allow remote attackers to inject arbitrary web script or HTML via (1) the cat_title parameter in index.php, (2) the faq[0][0] parameter in lang_faq.php as accessible from faq.php, or (3) the faq[0][0] parameter in lang_bbcode.php as accessible from faq.php.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108999024506020&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20040716 [waraxe-2004-SA#034 - XSS and path full path disclosure in PhpBB 2.0.8]</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/16726" source="XF">phpbb-lang-bbcode-xss(16726)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/16725" source="XF" adv="1">phpbb-lang-faq-xss(16725)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/16724" source="XF">phpbb-indexphp-xss(16724)</ref>
      <ref url="http://www.waraxe.us/index.php?modname=sa&amp;id=34" source="MISC">http://www.waraxe.us/index.php?modname=sa&amp;id=34</ref>
      <ref url="http://www.securityfocus.com/bid/10738" source="BID">10738</ref>
    </refs>
    <vuln_soft>
      <prod vendor="phpbb_group" name="phpbb">
        <vers num="2.0.8" />
        <vers num="2.0.8a" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0731" published="2004-07-27" name="CVE-2004-0731" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in index.php in the Search module for Php-Nuke allows remote attackers to inject arbitrary script as other users via the input field.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/16721" source="XF" adv="1">phpnuke-search-module-xss(16721)</ref>
      <ref url="http://www.waraxe.us/index.php?modname=sa&amp;id=35" source="MISC" adv="1">http://www.waraxe.us/index.php?modname=sa&amp;id=35</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109002107329823&amp;w=2" source="BUGTRAQ" adv="1">20040716 [waraxe-2004-SA#035 - Multiple security holes in PhpNuke - part 2]</ref>
    </refs>
    <vuln_soft>
      <prod vendor="francisco_burzi" name="php-nuke">
        <vers num="8.0_final" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0732" published="2004-07-27" name="CVE-2004-0732" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in index.php in the Search module for Php-Nuke allows remote attackers to execute arbitrary SQL statements via the instory parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/16728" source="XF" adv="1">phpnuke-search-module-sql-injection(16728)</ref>
      <ref url="http://www.waraxe.us/index.php?modname=sa&amp;id=35" source="MISC" adv="1">http://www.waraxe.us/index.php?modname=sa&amp;id=35</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109002107329823&amp;w=2" source="BUGTRAQ" adv="1">20040716 [waraxe-2004-SA#035 - Multiple security holes in PhpNuke - part 2]</ref>
    </refs>
    <vuln_soft>
      <prod vendor="francisco_burzi" name="php-nuke">
        <vers num="8.0_final" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0733" published="2004-07-27" name="CVE-2004-0733" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Format string vulnerability in OllyDbg 1.10 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via format string specifiers that are directly provided to the OutputDebugString function call.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/16711" source="XF" adv="1">ollydbg-outputdebugstring-format-string(16711)</ref>
      <ref url="http://www.securityfocus.com/bid/10742" source="BID" adv="1">10742</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109007978822810&amp;w=2" source="BUGTRAQ" adv="1">20040717 [FMADV] Format String Bug in OllyDbg 1.10</ref>
      <ref url="http://archives.neohapsis.com/archives/fulldisclosure/2004-07/0711.html" source="FULLDISC">20040717 [FMADV] Format String Bug in OllyDbg 1.10</ref>
      <ref url="http://www.milw0rm.com/exploits/3757" source="MILW0RM">3757</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ollydbg" name="ollydbg">
        <vers num="1.0.6" />
        <vers num="1.0.8b" />
        <vers num="1.0.9" />
        <vers num="1.10" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0734" published="2004-07-27" name="CVE-2004-0734" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Web_Store.cgi allows remote attackers to execute arbitrary commands via shell metacharacters in the page parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/16710" source="XF" adv="1">extropia-webstore-command-execution(16710)</ref>
      <ref url="http://www.securityfocus.com/bid/10744" source="BID" adv="1">10744</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109008402715874&amp;w=2" source="BUGTRAQ">20040717 Web_Store.cgi allows Command Execution</ref>
    </refs>
    <vuln_soft>
      <prod vendor="extropia" name="extropia_webstore">
        <vers num="1.0" />
        <vers num="2.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0735" published="2004-07-27" name="CVE-2004-0735" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in Medal of Honor (1) Allied Assault 1.11v9 and earlier, (2) Breakthrough 2.40b and earlier, and (3) Spearhead 2.15 and earlier, when playing on a Local Area Network (LAN), allows remote attackers to execute arbitrary code via vectors such as (1) the getinfo query, (2) the connect packet, and other unknown vectors.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/10743" source="BID" patch="1" adv="1">10743</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/16715" source="XF" adv="1">medalofhonor-packet-bo(16715)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109008314631518&amp;w=2" source="BUGTRAQ">20040717 Medal of Honor remote buffer-overflow</ref>
    </refs>
    <vuln_soft>
      <prod vendor="electronic_arts" name="medal_of_honor_allied_assault">
        <vers num="1.0" />
        <vers num="1.1" />
        <vers num="1.11_v9" />
        <vers num="breakthrough_2.40_b" />
        <vers num="spearhead_2.15" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0736" published="2004-07-27" name="CVE-2004-0736" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The search module in Php-Nuke allows remote attackers to gain sensitive information via the (1) "**" or (2) "+" search patterns, which reveals the path in an error message.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/16736" source="XF" adv="1">phpnuke-asterisk-plus-path-disclosure(16736)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109026609504767&amp;w=2" source="BUGTRAQ" adv="1">20040718 [waraxe-2004-SA#036 - Multiple security holes in PhpNuke - part 3]</ref>
    </refs>
    <vuln_soft>
      <prod vendor="francisco_burzi" name="php-nuke">
        <vers num="8.0_final" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0737" published="2004-07-27" name="CVE-2004-0737" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple cross-site scripting vulnerabilities in index.php in the Search module for Php-Nuke allows remote attackers to inject arbitrary web script or HTML via the (1) sid, (2) max, (3) sel1, (4) sel2, (5) sel3, (6) sel4, (7) sel5, (8) match, (9) mod1, (10) mod2, or (11) mod3 parameters.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/16721" source="XF" adv="1">phpnuke-search-module-xss(16721)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109026609504767&amp;w=2" source="BUGTRAQ" adv="1">20040718 [waraxe-2004-SA#036 - Multiple security holes in PhpNuke - part 3]</ref>
    </refs>
    <vuln_soft>
      <prod vendor="francisco_burzi" name="php-nuke">
        <vers num="8.0_final" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0738" published="2004-07-27" name="CVE-2004-0738" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple SQL injection vulnerabilities in the Search module in Php-Nuke allow remote attackers to execute arbitrary SQL via the (1) min or (2) categ parameters.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/16737" source="XF" adv="1">phpnuke-search-min-sql-injection(16737)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109026609504767&amp;w=2" source="BUGTRAQ" adv="1">20040718 [waraxe-2004-SA#036 - Multiple security holes in PhpNuke - part 3]</ref>
    </refs>
    <vuln_soft>
      <prod vendor="francisco_burzi" name="php-nuke">
        <vers num="8.0_final" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0739" published="2004-07-27" name="CVE-2004-0739" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in Whisper FTP Surfer 1.0.7 allows remote FTP servers to cause a denial of service (client crash) and possibly execute arbitrary code via a long filename.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/16742" source="XF" adv="1">whisper-long-file-name-bo(16742)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109035224715409&amp;w=2" source="BUGTRAQ" adv="1">20040719 Buffer overflow in Whisper FTP Surfer 1.0.7</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2004-July/024087.html" source="FULLDISC">20040719 Buffer overflow in Whisper FTP Surfer 1.0.7</ref>
    </refs>
    <vuln_soft>
      <prod vendor="snapfiles" name="whisper_ftp_surfer">
        <vers num="1.0.7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0740" published="2004-07-27" name="CVE-2004-0740" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The HTTP server in Lexmark T522 and possibly other models allows remote attackers to cause a denial of service (server crash, reload, or hang) via an HTTP header with a long Host field, possibly triggering a buffer overflow.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/16752" source="XF" adv="1">lexmark-long-host-bo(16752)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109035701329111&amp;w=2" source="BUGTRAQ" adv="1">20040720 Denial of Service vulnerability in several Lexmark HTTP servers</ref>
    </refs>
    <vuln_soft>
      <prod vendor="lexmark" name="t522_network_printer">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0741" published="2004-07-27" name="CVE-2004-0741" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">LionMax Software WWW File Share Pro 2.60 allows remote attackers to cause a denial of service (crash or hang) via a long URL, possibly triggering a buffer overflow.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/16754" source="XF" adv="1">wwwfilesharepro-http-get-dos(16754)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109035774701051&amp;w=2" source="BUGTRAQ" adv="1">20040720 dos_in_file_share_2.6</ref>
    </refs>
    <vuln_soft>
      <prod vendor="lionmax_software" name="www_file_share_pro">
        <vers num="2.40" />
        <vers num="2.41" />
        <vers num="2.42" />
        <vers num="2.46" />
        <vers num="2.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0742" published="2004-07-27" name="CVE-2004-0742" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Sun Java System Portal Server 6.2 (formerly Sun ONE) allows remote authenticated users to obtain Calendar Server privileges and modify Calendar data by changing the display options to a non-default view.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/881254" source="CERT-VN">VU#881254</ref>
      <ref url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doc=fsalert/57586" source="SUNALERT" patch="1" adv="1">57586</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/16776" source="XF" adv="1">sunjavaportal-calendar-gain-access(16776)</ref>
      <ref url="http://www.securityfocus.com/bid/10788" source="BID">10788</ref>
      <ref url="http://secunia.com/advisories/12134" source="SECUNIA">12134</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="java_system_calendar_server">
        <vers num="6.2" edition="" />
        <vers num="6.2" edition=":x86" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0743" published="2004-11-23" name="CVE-2004-0743" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Safari in Mac OS X before 10.3.5, after sending form data using the POST method, may re-send the data to a GET method URL if that URL is redirected after the POST data and the user uses the forward or backward buttons, which may cause an information leak.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/128414" source="CERT-VN">VU#128414</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/16944" source="XF">safari-web-info-disclosure(16944)</ref>
      <ref url="http://lists.apple.com/mhonarc/security-announce/msg00056.html" source="APPLE">APPLE-SA-2004-09-09</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.2" />
        <vers num="10.2.1" />
        <vers num="10.2.2" />
        <vers num="10.2.3" />
        <vers num="10.2.4" />
        <vers num="10.2.5" />
        <vers num="10.2.6" />
        <vers num="10.2.7" />
        <vers num="10.2.8" />
        <vers num="10.3" />
        <vers num="10.3.1" />
        <vers num="10.3.2" />
        <vers num="10.3.3" />
        <vers num="10.3.4" />
      </prod>
      <prod vendor="apple" name="mac_os_x_server">
        <vers num="10.2" />
        <vers num="10.2.1" />
        <vers num="10.2.2" />
        <vers num="10.2.3" />
        <vers num="10.2.4" />
        <vers num="10.2.5" />
        <vers num="10.2.6" />
        <vers num="10.2.7" />
        <vers num="10.2.8" />
        <vers num="10.3" />
        <vers num="10.3.1" />
        <vers num="10.3.2" />
        <vers num="10.3.3" />
        <vers num="10.3.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0744" published="2004-11-23" name="CVE-2004-0744" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The TCP/IP Networking component in Mac OS X before 10.3.5 allows remote attackers to cause a denial of service (memory and resource consumption) via a "Rose Attack" that involves sending a subset of small IP fragments that do not form a complete, larger packet.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/16946" source="XF">macos-tcp-ip-dos(16946)</ref>
      <ref url="http://www.auscert.org.au/render.html?it=4291" source="APPLE">APPLE-SA-2004-09-09</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108308604119618&amp;w=2" source="BUGTRAQ">20040427 Source Code To Test IPv4 fragmentation --> The Rose Attack</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108075899619193&amp;w=2" source="BUGTRAQ">20040331 IPv4 fragmentation  --> The Rose Attack</ref>
      <ref url="http://digital.net/~gandalf/Rose_Frag_Attack_Explained.txt" source="MISC">http://digital.net/~gandalf/Rose_Frag_Attack_Explained.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.2" />
        <vers num="10.2.1" />
        <vers num="10.2.2" />
        <vers num="10.2.3" />
        <vers num="10.2.4" />
        <vers num="10.2.5" />
        <vers num="10.2.6" />
        <vers num="10.2.7" />
        <vers num="10.2.8" />
        <vers num="10.3" />
        <vers num="10.3.1" />
        <vers num="10.3.2" />
        <vers num="10.3.3" />
        <vers num="10.3.4" />
      </prod>
      <prod vendor="apple" name="mac_os_x_server">
        <vers num="10.2" />
        <vers num="10.2.1" />
        <vers num="10.2.2" />
        <vers num="10.2.3" />
        <vers num="10.2.4" />
        <vers num="10.2.5" />
        <vers num="10.2.6" />
        <vers num="10.2.7" />
        <vers num="10.2.8" />
        <vers num="10.3" />
        <vers num="10.3.1" />
        <vers num="10.3.2" />
        <vers num="10.3.3" />
        <vers num="10.3.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0745" published="2004-09-28" name="CVE-2004-0745" modified="2011-02-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">LHA 1.14 and earlier allows attackers to execute arbitrary commands via a directory with shell metacharacters in its name.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/17198" source="XF" patch="1" adv="1">lha-metacharacter-command-execution(17198)</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-440.html" source="REDHAT" patch="1" adv="1">RHSA-2004:440</ref>
      <ref url="https://bugzilla.fedora.us/show_bug.cgi?id=1833" source="FEDORA">FLSA:1833</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-323.html" source="REDHAT">RHSA-2004:323</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200409-13.xml" source="GENTOO" adv="1">GLSA-200409-13</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11088" source="OVAL">oval:org.mitre.oval:def:11088</ref>
    </refs>
    <vuln_soft>
      <prod vendor="tsugio_okamoto" name="lha">
        <vers prev="1" num="1.14" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0746" published="2004-10-20" name="CVE-2004-0746" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Konqueror in KDE 3.2.3 and earlier allows web sites to set cookies for country-specific top-level domains, such as .ltd.uk, .plc.uk and .firm.in, which could allow remote attackers to perform a session fixation attack and hijack a user's HTTP session.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/17063" source="XF" patch="1" adv="1">kde-konqueror-cookie-set(17063)</ref>
      <ref url="http://www.securityfocus.com/bid/10991" source="BID" patch="1" adv="1">10991</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109327681304401&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20040823 KDE Security Advisory: Konqueror Cross-Domain Cookie Injection</ref>
      <ref url="http://www.mandrakesecure.net/en/advisories/advisory.php?name=MDKSA-2004:086" source="MANDRAKE">MDKSA-2004:086</ref>
      <ref url="http://www.kde.org/info/security/advisory-20040823-1.txt" source="CONFIRM">http://www.kde.org/info/security/advisory-20040823-1.txt</ref>
      <ref url="http://secunia.com/advisories/12341" source="SECUNIA">12341</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11281" source="OVAL">oval:org.mitre.oval:def:11281</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000864" source="CONECTIVA">CLA-2004:864</ref>
    </refs>
    <vuln_soft>
      <prod vendor="kde" name="konqueror">
        <vers num="3.0" />
        <vers num="3.0.1" />
        <vers num="3.0.2" />
        <vers num="3.0.3" />
        <vers num="3.0.5" />
        <vers num="3.0.5b" />
        <vers num="3.1" />
        <vers num="3.1.1" />
        <vers num="3.1.2" />
        <vers num="3.1.3" />
        <vers num="3.1.5" />
        <vers num="3.2.1" />
        <vers num="3.2.3" />
      </prod>
      <prod vendor="gentoo" name="linux">
        <vers num="1.4" />
      </prod>
      <prod vendor="kde" name="kde">
        <vers num="3.1.3" />
        <vers num="3.2" />
      </prod>
      <prod vendor="mandrakesoft" name="mandrake_linux">
        <vers num="10.0" edition="" />
        <vers num="10.0" edition=":amd64" />
        <vers num="9.2" edition="" />
        <vers num="9.2" edition=":amd64" />
      </prod>
      <prod vendor="suse" name="suse_linux">
        <vers num="8" edition="" />
        <vers num="8" edition=":enterprise_server" />
        <vers num="8.1" />
        <vers num="8.2" />
        <vers num="9.0" edition="" />
        <vers num="9.0" edition=":enterprise_server" />
        <vers num="9.0" edition=":x86_64" />
        <vers num="9.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0747" published="2004-10-20" name="CVE-2004-0747" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Buffer overflow in Apache 2.0.50 and earlier allows local users to gain apache privileges via a .htaccess file that causes the overflow during expansion of environment variables.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/481998" source="CERT-VN">VU#481998</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-463.html" source="REDHAT" patch="1" adv="1">RHSA-2004:463</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/17384" source="XF">apache-env-configuration-bo(17384)</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1233" source="VUPEN">ADV-2009-1233</ref>
      <ref url="http://www.trustix.org/errata/2004/0047/" source="TRUSTIX">2004-0047</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2004_32_apache2.html" source="SUSE">SUSE-SA:2004:032</ref>
      <ref url="http://www.mandrakesecure.net/en/advisories/advisory.php?name=MDKSA-2004:096" source="MANDRAKE">MDKSA-2004:096</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200409-21.xml" source="GENTOO">GLSA-200409-21</ref>
      <ref url="http://support.ca.com/irj/portal/anonymous/phpsupcontent?contentID=205147" source="MISC">http://support.ca.com/irj/portal/anonymous/phpsupcontent?contentID=205147</ref>
      <ref url="http://securitytracker.com/id?1011303" source="SECTRACK">1011303</ref>
      <ref url="http://secunia.com/advisories/34920" source="SECUNIA">34920</ref>
      <ref url="http://secunia.com/advisories/12540" source="SECUNIA">12540</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11561" source="OVAL">oval:org.mitre.oval:def:11561</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apache" name="http_server">
        <vers num="2.0" />
        <vers num="2.0.28" />
        <vers num="2.0.32" />
        <vers num="2.0.35" />
        <vers num="2.0.36" />
        <vers num="2.0.37" />
        <vers num="2.0.38" />
        <vers num="2.0.39" />
        <vers num="2.0.40" />
        <vers num="2.0.41" />
        <vers num="2.0.42" />
        <vers num="2.0.43" />
        <vers num="2.0.44" />
        <vers num="2.0.45" />
        <vers num="2.0.46" />
        <vers num="2.0.47" />
        <vers num="2.0.48" />
        <vers num="2.0.49" />
        <vers num="2.0.50" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0748" published="2004-10-20" name="CVE-2004-0748" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">mod_ssl in Apache 2.0.50 and earlier allows remote attackers to cause a denial of service (CPU consumption) by aborting an SSL connection in a way that causes an Apache child process to enter an infinite loop.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/17200" source="XF" patch="1" adv="1">apache-modssl-dos(17200)</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-349.html" source="REDHAT" patch="1" adv="1">RHSA-2004:349</ref>
      <ref url="https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=130750" source="CONFIRM">https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=130750</ref>
      <ref url="http://www.trustix.org/errata/2004/0047/" source="TRUSTIX">2004-0047</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2004_30_apache2.html" source="SUSE">SUSE-SA:2004:030</ref>
      <ref url="http://www.mandrakesecure.net/en/advisories/advisory.php?name=MDKSA-2004:096" source="MANDRAKE">MDKSA-2004:096</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200409-21.xml" source="GENTOO">GLSA-200409-21</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11126" source="OVAL">oval:org.mitre.oval:def:11126</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apache" name="http_server">
        <vers num="2.0" />
        <vers num="2.0.28" />
        <vers num="2.0.32" />
        <vers num="2.0.35" />
        <vers num="2.0.36" />
        <vers num="2.0.37" />
        <vers num="2.0.38" />
        <vers num="2.0.39" />
        <vers num="2.0.40" />
        <vers num="2.0.41" />
        <vers num="2.0.42" />
        <vers num="2.0.43" />
        <vers num="2.0.44" />
        <vers num="2.0.45" />
        <vers num="2.0.46" />
        <vers num="2.0.47" />
        <vers num="2.0.48" />
        <vers num="2.0.49" />
        <vers num="2.0.50" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0749" published="2004-12-23" name="CVE-2004-0749" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The mod_authz_svn module in Subversion 1.0.7 and earlier does not properly restrict access to all metadata on unreadable paths, which could allow remote attackers to gain sensitive information via (1) svn log -v, (2) svn propget, or (3) svn blame, and other commands that follow renames.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/17472" source="XF" patch="1" adv="1">subversion-information-disclosure(17472)</ref>
      <ref url="http://www.securityfocus.com/bid/11243" source="BID" patch="1" adv="1">11243</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200409-35.xml" source="GENTOO" patch="1" adv="1">GLSA-200409-35</ref>
      <ref url="http://subversion.tigris.org/security/CAN-2004-0749-advisory.txt" source="CONFIRM" patch="1" adv="1">http://subversion.tigris.org/security/CAN-2004-0749-advisory.txt</ref>
      <ref url="http://fedoranews.org/updates/FEDORA-2004-318.shtml" source="FEDORA">FEDORA-2004-318</ref>
    </refs>
    <vuln_soft>
      <prod vendor="subversion" name="subversion">
        <vers num="1.0" />
        <vers num="1.0.1" />
        <vers num="1.0.2" />
        <vers num="1.0.3" />
        <vers num="1.0.4" />
        <vers num="1.0.5" />
        <vers num="1.0.6" />
        <vers num="1.0.7" />
        <vers num="1.1.0_rc1" />
        <vers num="1.1.0_rc2" />
        <vers num="1.1.0_rc3" />
      </prod>
      <prod vendor="gentoo" name="linux">
        <vers num="0.5" />
        <vers num="0.7" />
        <vers num="1.1a" />
        <vers num="1.2" />
        <vers num="1.4" edition="rc1" />
        <vers num="1.4" edition="rc2" />
        <vers num="1.4" edition="rc3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0750" published="2004-10-20" name="CVE-2004-0750" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Unknown vulnerability in redhat-config-nfs before 1.0.13, when shares are exported to multiple hosts, can produce incorrect permissions and prevent the all_squash option from being applied.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <config />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-434.html" source="REDHAT" patch="1" adv="1">RHSA-2004:434</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/17478" source="XF">red-hat-permission-gain-privileges(17478)</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10696" source="OVAL">oval:org.mitre.oval:def:10696</ref>
      <ref url="http://www.securityfocus.com/bid/11240" source="BID">11240</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/419762/100/0/threaded" source="FEDORA">FLSA:152787</ref>
    </refs>
    <vuln_soft>
      <prod vendor="redhat" name="enterprise_linux">
        <vers num="3.0" edition="" />
        <vers num="3.0" edition=":workstation" />
        <vers num="3.0" edition=":enterprise_server" />
        <vers num="3.0" edition=":advanced_servers" />
      </prod>
      <prod vendor="redhat" name="enterprise_linux_desktop">
        <vers num="3.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0751" published="2004-10-20" name="CVE-2004-0751" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The char_buffer_read function in the mod_ssl module for Apache 2.x, when using reverse proxying to an SSL server, allows remote attackers to cause a denial of service (segmentation fault).</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/17273" source="XF" patch="1" adv="1">apache-modssl-speculative-dos(17273)</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-463.html" source="REDHAT" patch="1" adv="1">RHSA-2004:463</ref>
      <ref url="http://www.trustix.org/errata/2004/0047/" source="TRUSTIX">2004-0047</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2004_30_apache2.html" source="SUSE">SUSE-SA:2004:030</ref>
      <ref url="http://www.mandrakesecure.net/en/advisories/advisory.php?name=MDKSA-2004:096" source="MANDRAKE">MDKSA-2004:096</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200409-21.xml" source="GENTOO">GLSA-200409-21</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11864" source="OVAL">oval:org.mitre.oval:def:11864</ref>
      <ref url="http://issues.apache.org/bugzilla/show_bug.cgi?id=30134" source="CONFIRM">http://issues.apache.org/bugzilla/show_bug.cgi?id=30134</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2004-09/0096.html" source="BUGTRAQ">20040911 Remote buffer overflow in Apache mod_ssl when reverse proxying SSL</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apache" name="http_server">
        <vers num="2.0" />
        <vers num="2.0.28" />
        <vers num="2.0.32" />
        <vers num="2.0.35" />
        <vers num="2.0.36" />
        <vers num="2.0.37" />
        <vers num="2.0.38" />
        <vers num="2.0.39" />
        <vers num="2.0.40" />
        <vers num="2.0.41" />
        <vers num="2.0.42" />
        <vers num="2.0.43" />
        <vers num="2.0.44" />
        <vers num="2.0.45" />
        <vers num="2.0.46" />
        <vers num="2.0.47" />
        <vers num="2.0.48" />
        <vers num="2.0.49" />
        <vers num="2.0.50" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2004-0752" published="2004-10-20" name="CVE-2004-0752" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">OpenOffice (OOo) 1.1.2 creates predictable directory names with insecure permissions during startup, which may allow local users to read or list files of other users.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-446.html" source="REDHAT" patch="1" adv="1">RHSA-2004:446</ref>
      <ref url="http://www.openoffice.org/issues/show_bug.cgi?id=33357" source="CONFIRM" patch="1" adv="1">http://www.openoffice.org/issues/show_bug.cgi?id=33357</ref>
      <ref url="http://securitytracker.com/id?1011205" source="SECTRACK" patch="1" adv="1">1011205</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10294" source="OVAL">oval:org.mitre.oval:def:10294</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/17312" source="XF">openofficeorg-tmpfile-insecure-permissions(17312)</ref>
      <ref url="http://www.securityfocus.com/bid/11151" source="BID">11151</ref>
      <ref url="http://www.osvdb.org/9804" source="OSVDB">9804</ref>
      <ref url="http://secunia.com/advisories/12932/" source="SECUNIA">12932</ref>
      <ref url="http://secunia.com/advisories/12914/" source="SECUNIA">12914</ref>
      <ref url="http://secunia.com/advisories/12668/" source="SECUNIA">12668</ref>
      <ref url="http://secunia.com/advisories/12546/" source="SECUNIA">12546</ref>
      <ref url="http://secunia.com/advisories/12302/" source="SECUNIA">12302</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109483308421566&amp;w=2" source="BUGTRAQ">20040910 OpenOffice World-Readable Temporary Files Disclose Files to Local Users</ref>
    </refs>
    <vuln_soft>
      <prod vendor="openoffice" name="openoffice">
        <vers num="1.1.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0753" published="2004-10-20" name="CVE-2004-0753" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The BMP image processor for (1) gdk-pixbuf before 0.22 and (2) gtk2 before 2.2.4 allows remote attackers to cause a denial of service (infinite loop) via a crafted BMP file.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/825374" source="CERT-VN">VU#825374</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-466.html" source="REDHAT" patch="1" adv="1">RHSA-2004:466</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-447.html" source="REDHAT" patch="1" adv="1">RHSA-2004:447</ref>
      <ref url="https://bugzilla.fedora.us/show_bug.cgi?id=2005" source="FEDORA">FLSA:2005</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/17383" source="XF">gtk-bmp-dos(17383)</ref>
      <ref url="http://www.mandrakesecure.net/en/advisories/advisory.php?name=MDKSA-2004:095" source="MANDRAKE">MDKSA-2004:095</ref>
      <ref url="http://www.debian.org/security/2004/dsa-546" source="DEBIAN">DSA-546</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10585" source="OVAL">oval:org.mitre.oval:def:10585</ref>
      <ref url="http://www.securityfocus.com/bid/11195" source="BID">11195</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/419771/100/0/threaded" source="FEDORA">FLSA-2005:155510</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:214" source="MANDRIVA">MDKSA-2005:214</ref>
      <ref url="http://secunia.com/advisories/17657" source="SECUNIA">17657</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000875" source="CONECTIVA">CLA-2004:875</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gnome" name="gdkpixbuf">
        <vers num="0.17" />
        <vers num="0.18" />
        <vers num="0.20" />
        <vers num="0.22" />
      </prod>
      <prod vendor="gtk" name="gtk+">
        <vers num="2.0.2" />
        <vers num="2.0.6" />
        <vers num="2.2.1" />
        <vers num="2.2.3" />
        <vers num="2.2.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0754" published="2004-10-20" name="CVE-2004-0754" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Integer overflow in Gaim before 0.82 allows remote attackers to cause a denial of service and possibly execute arbitrary code via the size variable in Groupware server messages.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.fedoranews.org/updates/FEDORA-2004-279.shtml" source="FEDORA" patch="1" adv="1">FEDORA-2004-279</ref>
      <ref url="http://www.fedoranews.org/updates/FEDORA-2004-278.shtml" source="FEDORA" patch="1" adv="1">FEDORA-2004-278</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-400.html" source="REDHAT">RHSA-2004:400</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200408-27.xml" source="GENTOO" adv="1">GLSA-200408-27</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10220" source="OVAL">oval:org.mitre.oval:def:10220</ref>
      <ref url="http://gaim.sourceforge.net/security/?id=2" source="CONFIRM" adv="1">http://gaim.sourceforge.net/security/?id=2</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/17140" source="XF">gaim-groupware-integer-overflow(17140)</ref>
      <ref url="http://www.securityfocus.com/bid/11056" source="BID">11056</ref>
      <ref url="http://www.osvdb.org/9260" source="OSVDB">9260</ref>
      <ref url="http://securitytracker.com/id?1011083" source="SECTRACK">1011083</ref>
      <ref url="http://secunia.com/advisories/13101" source="SECUNIA">13101</ref>
      <ref url="http://secunia.com/advisories/12480" source="SECUNIA">12480</ref>
      <ref url="http://secunia.com/advisories/12383" source="SECUNIA">12383</ref>
    </refs>
    <vuln_soft>
      <prod vendor="rob_flynn" name="gaim">
        <vers num="0.10" />
        <vers num="0.10.3" />
        <vers num="0.50" />
        <vers num="0.51" />
        <vers num="0.52" />
        <vers num="0.53" />
        <vers num="0.54" />
        <vers num="0.55" />
        <vers num="0.56" />
        <vers num="0.57" />
        <vers num="0.58" />
        <vers num="0.59" />
        <vers num="0.59.1" />
        <vers num="0.60" />
        <vers num="0.61" />
        <vers num="0.62" />
        <vers num="0.63" />
        <vers num="0.64" />
        <vers num="0.65" />
        <vers num="0.66" />
        <vers num="0.67" />
        <vers num="0.68" />
        <vers num="0.69" />
        <vers num="0.70" />
        <vers num="0.71" />
        <vers num="0.72" />
        <vers num="0.73" />
        <vers num="0.74" />
        <vers num="0.75" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2004-0755" published="2004-10-20" name="CVE-2004-0755" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">The FileStore capability in CGI::Session for Ruby before 1.8.1, and possibly PStore, creates files with insecure permissions, which can allow local users to steal session information and hijack sessions.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/16996" source="XF" patch="1" adv="1">ruby-filestore-pstore-insecure-permission(16996)</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200409-08.xml" source="GENTOO" patch="1" adv="1">GLSA-200409-08</ref>
      <ref url="http://www.debian.org/security/2004/dsa-537" source="DEBIAN" patch="1" adv="1">DSA-537</ref>
      <ref url="http://secunia.com/advisories/12290/" source="SECUNIA">12290</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11128" source="OVAL">oval:org.mitre.oval:def:11128</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2004:128" source="MANDRAKE">MDKSA-2004:128</ref>
    </refs>
    <vuln_soft>
      <prod vendor="yukihiro_matsumoto" name="ruby">
        <vers num="1.6" />
        <vers num="1.8" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0757" published="2004-08-18" name="CVE-2004-0757" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Heap-based buffer overflow in the SendUidl in the POP3 capability for Mozilla before 1.7, Firefox before 0.9, and Thunderbird before 0.7, may allow remote POP3 mail servers to execute arbitrary code.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/561022" source="CERT-VN">VU#561022</ref>
      <ref url="http://bugzilla.mozilla.org/show_bug.cgi?id=229374" source="CONFIRM" patch="1" adv="1">http://bugzilla.mozilla.org/show_bug.cgi?id=229374</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/16869" source="XF">mozilla-senduidl-pop3-bo(16869)</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-421.html" source="REDHAT">RHSA-2004:421</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2004_36_mozilla.html" source="SUSE">SUSE-SA:2004:036</ref>
      <ref url="http://www.mozilla.org/projects/security/known-vulnerabilities.html#mozilla1.7" source="CONFIRM">http://www.mozilla.org/projects/security/known-vulnerabilities.html#mozilla1.7</ref>
      <ref url="http://secunia.com/advisories/10856" source="SECUNIA">10856</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11042" source="OVAL">oval:org.mitre.oval:def:11042</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109900315219363&amp;w=2" source="FEDORA">FLSA:2089</ref>
      <ref url="http://www.securityfocus.com/bid/15495" source="BID">15495</ref>
      <ref url="ftp://ftp.sco.com/pub/updates/OpenServer/SCOSA-2005.49/SCOSA-2005.49.txt" source="SCO">SCOSA-2005.49</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:3250" source="OVAL" sig="1">oval:org.mitre.oval:def:3250</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="firefox">
        <vers prev="1" num="0.9" />
      </prod>
      <prod vendor="mozilla" name="mozilla">
        <vers prev="1" num="1.7" />
      </prod>
      <prod vendor="mozilla" name="thunderbird">
        <vers prev="1" num="0.7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0758" published="2004-08-18" name="CVE-2004-0758" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Mozilla 1.5 through 1.7 allows a CA certificate to be imported even when their DN is the same as that of the built-in CA root certificate, which allows remote attackers to cause a denial of service to SSL pages because the malicious certificate is treated as invalid.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/784278" source="CERT-VN">VU#784278</ref>
      <ref url="http://bugzilla.mozilla.org/show_bug.cgi?id=249004" source="CONFIRM" patch="1" adv="1">http://bugzilla.mozilla.org/show_bug.cgi?id=249004</ref>
      <ref url="https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=127186" source="CONFIRM">https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=127186</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/16706" source="XF">mozilla-certificate-dos(16706)</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-421.html" source="REDHAT">RHSA-2004:421</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2004_36_mozilla.html" source="SUSE">SUSE-SA:2004:036</ref>
      <ref url="http://www.mozilla.org/projects/security/known-vulnerabilities.html" source="CONFIRM">http://www.mozilla.org/projects/security/known-vulnerabilities.html</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200408-22.xml" source="GENTOO">GLSA-200408-22</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10304" source="OVAL">oval:org.mitre.oval:def:10304</ref>
      <ref url="http://www.securityfocus.com/bid/15495" source="BID">15495</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109900315219363&amp;w=2" source="FEDORA">FLSA:2089</ref>
      <ref url="ftp://ftp.sco.com/pub/updates/OpenServer/SCOSA-2005.49/SCOSA-2005.49.txt" source="SCO">SCOSA-2005.49</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:3134" source="OVAL" sig="1">oval:org.mitre.oval:def:3134</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="mozilla">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0759" published="2004-08-18" name="CVE-2004-0759" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)" CVSS_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_base_score="6.4">
    <desc>
      <descript source="cve">Mozilla before 1.7 allows remote web servers to read arbitrary files via Javascript that sets the value of an &lt;input type="file"> tag.</descript>
    </desc>
    <loss_types>
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <design />
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://bugzilla.mozilla.org/show_bug.cgi?id=241924" source="CONFIRM" patch="1" adv="1">http://bugzilla.mozilla.org/show_bug.cgi?id=241924</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/16870" source="XF">mozilla-warning-file-upload(16870)</ref>
      <ref url="http://www.securityfocus.com/bid/15495" source="BID">15495</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-421.html" source="REDHAT">RHSA-2004:421</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2004_36_mozilla.html" source="SUSE">SUSE-SA:2004:036</ref>
      <ref url="http://www.mozilla.org/projects/security/known-vulnerabilities.html#mozilla1.7" source="CONFIRM">http://www.mozilla.org/projects/security/known-vulnerabilities.html#mozilla1.7</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11153" source="OVAL">oval:org.mitre.oval:def:11153</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109900315219363&amp;w=2" source="FEDORA">FLSA:2089</ref>
      <ref url="ftp://ftp.sco.com/pub/updates/OpenServer/SCOSA-2005.49/SCOSA-2005.49.txt" source="SCO">SCOSA-2005.49</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="mozilla">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0760" published="2004-08-18" name="CVE-2004-0760" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)" CVSS_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_base_score="6.4">
    <desc>
      <descript source="cve">Mozilla allows remote attackers to cause Mozilla to open a URI as a different MIME type than expected via a null character (%00) in an FTP URI.</descript>
    </desc>
    <loss_types>
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://bugzilla.mozilla.org/show_bug.cgi?id=250906" source="CONFIRM" patch="1" adv="1">http://bugzilla.mozilla.org/show_bug.cgi?id=250906</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/16691" source="XF">mozilla-modify-mime-type(16691)</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-421.html" source="REDHAT">RHSA-2004:421</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2004_36_mozilla.html" source="SUSE">SUSE-SA:2004:036</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11090" source="OVAL">oval:org.mitre.oval:def:11090</ref>
      <ref url="http://www.securityfocus.com/bid/15495" source="BID">15495</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109900315219363&amp;w=2" source="FEDORA">FLSA:2089</ref>
      <ref url="ftp://ftp.sco.com/pub/updates/OpenServer/SCOSA-2005.49/SCOSA-2005.49.txt" source="SCO">SCOSA-2005.49</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1227" source="OVAL" sig="1">oval:org.mitre.oval:def:1227</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="mozilla">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0761" published="2004-08-18" name="CVE-2004-0761" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Mozilla before 1.7, Firefox before 0.9, and Thunderbird before 0.7, allow remote attackers to use certain redirect sequences to spoof the security lock icon that makes a web page appear to be encrypted.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://bugzilla.mozilla.org/show_bug.cgi?id=240053" source="CONFIRM" patch="1" adv="1">http://bugzilla.mozilla.org/show_bug.cgi?id=240053</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/16871" source="XF">mozilla-redirect-ssl-spoof(16871)</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-421.html" source="REDHAT">RHSA-2004:421</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2004_36_mozilla.html" source="SUSE">SUSE-SA:2004:036</ref>
      <ref url="http://www.mozilla.org/projects/security/known-vulnerabilities.html#mozilla1.7" source="CONFIRM">http://www.mozilla.org/projects/security/known-vulnerabilities.html#mozilla1.7</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9240" source="OVAL">oval:org.mitre.oval:def:9240</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109900315219363&amp;w=2" source="FEDORA">FLSA:2089</ref>
      <ref url="http://www.securityfocus.com/bid/15495" source="BID">15495</ref>
      <ref url="ftp://ftp.sco.com/pub/updates/OpenServer/SCOSA-2005.49/SCOSA-2005.49.txt" source="SCO">SCOSA-2005.49</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:3603" source="OVAL" sig="1">oval:org.mitre.oval:def:3603</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="firefox">
        <vers prev="1" num="0.9" />
      </prod>
      <prod vendor="mozilla" name="mozilla">
        <vers prev="1" num="1.7" />
      </prod>
      <prod vendor="mozilla" name="thunderbird">
        <vers prev="1" num="0.7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0762" published="2004-08-18" name="CVE-2004-0762" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Mozilla before 1.7, Firefox before 0.9, and Thunderbird before 0.7, allow remote web sites to install arbitrary extensions by using interactive events to manipulate the XPInstall Security dialog box.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://bugzilla.mozilla.org/show_bug.cgi?id=162020" source="CONFIRM" patch="1" adv="1">http://bugzilla.mozilla.org/show_bug.cgi?id=162020</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/16623" source="XF">mozilla-dialog-code-execution(16623)</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-421.html" source="REDHAT">RHSA-2004:421</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2004_36_mozilla.html" source="SUSE">SUSE-SA:2004:036</ref>
      <ref url="http://www.mozilla.org/projects/security/known-vulnerabilities.html#mozilla1.7" source="CONFIRM">http://www.mozilla.org/projects/security/known-vulnerabilities.html#mozilla1.7</ref>
      <ref url="http://secunia.com/advisories/11999/" source="SECUNIA">11999</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10032" source="OVAL">oval:org.mitre.oval:def:10032</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109900315219363&amp;w=2" source="FEDORA">FLSA:2089</ref>
      <ref url="http://www.squarefree.com/2004/07/01/race-conditions-in-security-dialogs/" source="MISC">http://www.squarefree.com/2004/07/01/race-conditions-in-security-dialogs/</ref>
      <ref url="http://www.securityfocus.com/bid/15495" source="BID">15495</ref>
      <ref url="http://archives.neohapsis.com/archives/fulldisclosure/2004-07/0264.html" source="FULLDISC">20040407 Race conditions in security dialogs</ref>
      <ref url="ftp://ftp.sco.com/pub/updates/OpenServer/SCOSA-2005.49/SCOSA-2005.49.txt" source="SCO">SCOSA-2005.49</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:4403" source="OVAL" sig="1">oval:org.mitre.oval:def:4403</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="firefox">
        <vers prev="1" num="0.9" />
      </prod>
      <prod vendor="mozilla" name="mozilla">
        <vers prev="1" num="1.7" />
      </prod>
      <prod vendor="mozilla" name="thunderbird">
        <vers prev="1" num="0.7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0763" published="2004-08-18" name="CVE-2004-0763" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Mozilla Firefox 0.9.1 and 0.9.2 allows remote web sites to spoof certificates of trusted web sites via redirects and Javascript that uses the "onunload" method.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://bugzilla.mozilla.org/show_bug.cgi?id=253121" source="CONFIRM" patch="1" adv="1">http://bugzilla.mozilla.org/show_bug.cgi?id=253121</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/16796" source="XF">mozilla-ssl-certificate-spoofing(16796)</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-421.html" source="REDHAT">RHSA-2004:421</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2004_36_mozilla.html" source="SUSE">SUSE-SA:2004:036</ref>
      <ref url="http://www.mozilla.org/projects/security/known-vulnerabilities.html" source="CONFIRM">http://www.mozilla.org/projects/security/known-vulnerabilities.html</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200408-22.xml" source="GENTOO">GLSA-200408-22</ref>
      <ref url="http://www.cipher.org.uk/index.php?p=advisories/Certificate_Spoofing_Mozilla_FireFox_25-07-2004.advisory" source="MISC">http://www.cipher.org.uk/index.php?p=advisories/Certificate_Spoofing_Mozilla_FireFox_25-07-2004.advisory</ref>
      <ref url="http://secunia.com/advisories/12160/" source="SECUNIA" adv="1">12160</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9436" source="OVAL">oval:org.mitre.oval:def:9436</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109087067730938&amp;w=2" source="BUGTRAQ" adv="1">20040726 Mozilla Firefox Certificate Spoofing</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2004-July/024372.html" source="FULLDISC">20040725 Mozilla Firefox Certificate Spoofing</ref>
      <ref url="http://www.securityfocus.com/bid/15495" source="BID">15495</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109900315219363&amp;w=2" source="FEDORA">FLSA:2089</ref>
      <ref url="ftp://ftp.sco.com/pub/updates/OpenServer/SCOSA-2005.49/SCOSA-2005.49.txt" source="SCO">SCOSA-2005.49</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:3989" source="OVAL" sig="1">oval:org.mitre.oval:def:3989</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="firefox">
        <vers num="0.9.1" />
        <vers num="0.9.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0764" published="2004-08-18" name="CVE-2004-0764" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Mozilla before 1.7, Firefox before 0.9, and Thunderbird before 0.7, allow remote web sites to hijack the user interface via the "chrome" flag and XML User Interface Language (XUL) files.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/262350" source="CERT-VN">VU#262350</ref>
      <ref url="http://bugzilla.mozilla.org/show_bug.cgi?id=244965" source="CONFIRM" patch="1" adv="1">http://bugzilla.mozilla.org/show_bug.cgi?id=244965</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/16837" source="XF">mozilla-user-interface-spoofing(16837)</ref>
      <ref url="http://www.securityfocus.com/bid/10832" source="BID">10832</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-421.html" source="REDHAT">RHSA-2004:421</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2004_36_mozilla.html" source="SUSE">SUSE-SA:2004:036</ref>
      <ref url="http://www.mozilla.org/projects/security/known-vulnerabilities.html#mozilla1.7" source="CONFIRM">http://www.mozilla.org/projects/security/known-vulnerabilities.html#mozilla1.7</ref>
      <ref url="http://secunia.com/advisories/12188" source="SECUNIA">12188</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9419" source="OVAL">oval:org.mitre.oval:def:9419</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109900315219363&amp;w=2" source="FEDORA">FLSA:2089</ref>
      <ref url="http://www.securityfocus.com/bid/15495" source="BID">15495</ref>
      <ref url="ftp://ftp.sco.com/pub/updates/OpenServer/SCOSA-2005.49/SCOSA-2005.49.txt" source="SCO">SCOSA-2005.49</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2418" source="OVAL" sig="1">oval:org.mitre.oval:def:2418</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="firefox">
        <vers prev="1" num="0.9" />
      </prod>
      <prod vendor="mozilla" name="mozilla">
        <vers prev="1" num="1.7" />
      </prod>
      <prod vendor="mozilla" name="thunderbird">
        <vers prev="1" num="0.7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0765" published="2004-08-18" name="CVE-2004-0765" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">The cert_TestHostName function in Mozilla before 1.7, Firefox before 0.9, and Thunderbird before 0.7, only checks the hostname portion of a certificate when the hostname portion of the URI is not a fully qualified domain name (FQDN), which allows remote attackers to spoof trusted certificates.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-421.html" source="REDHAT" patch="1" adv="1">RHSA-2004:421</ref>
      <ref url="http://bugzilla.mozilla.org/show_bug.cgi?id=234058" source="CONFIRM" patch="1" adv="1">http://bugzilla.mozilla.org/show_bug.cgi?id=234058</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/16868" source="XF">mozilla-certtesthostname-certificate-spoof(16868)</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2004_36_mozilla.html" source="SUSE" adv="1">SUSE-SA:2004:036</ref>
      <ref url="http://www.mozilla.org/projects/security/known-vulnerabilities.html#mozilla1.7" source="CONFIRM">http://www.mozilla.org/projects/security/known-vulnerabilities.html#mozilla1.7</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11162" source="OVAL">oval:org.mitre.oval:def:11162</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109900315219363&amp;w=2" source="FEDORA">FLSA:2089</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="firefox">
        <vers prev="1" num="0.9" />
      </prod>
      <prod vendor="mozilla" name="mozilla">
        <vers prev="1" num="1.7" />
      </prod>
      <prod vendor="mozilla" name="thunderbird">
        <vers prev="1" num="0.7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0766" published="2004-08-18" name="CVE-2004-0766" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">NGSEC StackDefender 2.0 allows attackers to cause a denial of service (system crash) via an invalid address for the BaseAddress parameter to the hooks for the (1) ZwAllocateVirtualMemory or (2) ZwProtectVirtualMemory functions.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/16892" source="XF">stackdefender-baseaddress-dos(16892)</ref>
      <ref url="http://www.idefense.com/application/poi/display?id=119&amp;type=vulnerabilities&amp;flashstatus=false" source="MISC" adv="1">http://www.idefense.com/application/poi/display?id=119&amp;type=vulnerabilities&amp;flashstatus=false</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ngsec" name="stackdefender">
        <vers num="2.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0767" published="2004-08-18" name="CVE-2004-0767" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">NGSEC StackDefender 1.10 allows attackers to cause a denial of service (system crash) via an invalid address for the ObjectAttribues parameter to the hooks for the (1) ZwCreateFile or (2) ZwOpenFile functions.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/16879" source="XF">stackdefender-objectattributes-dos(16879)</ref>
      <ref url="http://www.idefense.com/application/poi/display?id=118&amp;type=vulnerabilities&amp;flashstatus=false" source="MISC" adv="1">http://www.idefense.com/application/poi/display?id=118&amp;type=vulnerabilities&amp;flashstatus=false</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ngsec" name="stackdefender">
        <vers num="1.10" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0768" published="2004-10-20" name="CVE-2004-0768" modified="2009-01-23" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">libpng 1.2.5 and earlier does not properly calculate certain buffer offsets, which could allow remote attackers to execute arbitrary code via a buffer overflow attack.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/16914" source="XF" patch="1" adv="1">libpng-offset-bo(16914)</ref>
      <ref url="http://www.debian.org/security/2004/dsa-536" source="DEBIAN" patch="1" adv="1">DSA-536</ref>
      <ref url="https://bugzilla.fedora.us/show_bug.cgi?id=1943" source="FEDORA">FLSA:1943</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200812-15.xml" source="GENTOO">GLSA-200812-15</ref>
      <ref url="http://secunia.com/advisories/33137" source="SECUNIA">33137</ref>
    </refs>
    <vuln_soft>
      <prod vendor="greg_roelofs" name="libpng3">
        <vers num="1.2.0" />
        <vers num="1.2.1" />
        <vers num="1.2.2" />
        <vers num="1.2.3" />
        <vers num="1.2.4" />
        <vers num="1.2.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0769" published="2004-08-18" name="CVE-2004-0769" modified="2011-02-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Buffer overflow in LHA allows remote attackers to execute arbitrary code via long pathnames in LHarc format 2 headers for a .LHZ archive, as originally demonstrated using the "x" option but also exploitable through "l" and "v", and fixed in header.c, a different issue than CVE-2004-0771.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://bugs.gentoo.org/show_bug.cgi?id=51285" source="CONFIRM" patch="1" adv="1">http://bugs.gentoo.org/show_bug.cgi?id=51285</ref>
      <ref url="https://bugzilla.fedora.us/show_bug.cgi?id=1833" source="FEDORA">FLSA:1833</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/16917" source="XF">lha-long-pathname-bo(16917)</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-440.html" source="REDHAT">RHSA-2004:440</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-323.html" source="REDHAT">RHSA-2004:323</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200409-13.xml" source="GENTOO">GLSA-200409-13</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11047" source="OVAL">oval:org.mitre.oval:def:11047</ref>
      <ref url="http://lw.ftw.zamosc.pl/lha-exploit.txt" source="MISC">http://lw.ftw.zamosc.pl/lha-exploit.txt</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108745217504379&amp;w=2" source="BUGTRAQ">20040616 Re: [SECURITY] [DSA 515-1] New lha packages fix several vulnerabilities; Re:</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="bugzilla">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2004-0770" published="2005-01-10" name="CVE-2004-0770" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">romload.c in DGen Emulator 1.23 and earlier allows local users to overwrite arbitrary files via a symlink attack on temporary files during decompression of (1) gzip or (2) bzip ROM files.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/16884" source="XF" adv="1">dgen-rom-decompression-symlink(16884)</ref>
      <ref url="http://www.securityfocus.com/bid/10855" source="BID" adv="1">10855</ref>
      <ref url="http://secunia.com/advisories/12214" source="SECUNIA">12214</ref>
      <ref url="http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=263282&amp;archive=yes" source="CONFIRM">http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=263282&amp;archive=yes</ref>
    </refs>
    <vuln_soft>
      <prod vendor="dgen" name="emulator">
        <vers num="1.15" />
        <vers num="1.16" />
        <vers num="1.17" />
        <vers num="1.18" />
        <vers num="1.20" />
        <vers num="1.20_a" />
        <vers num="1.21" />
        <vers num="1.22" />
        <vers num="1.23" />
      </prod>
      <prod vendor="debian" name="debian_linux">
        <vers num="3.0" edition="" />
        <vers num="3.0" edition=":hppa" />
        <vers num="3.0" edition=":mips" />
        <vers num="3.0" edition=":ia-32" />
        <vers num="3.0" edition=":m68k" />
        <vers num="3.0" edition=":s-390" />
        <vers num="3.0" edition=":alpha" />
        <vers num="3.0" edition=":arm" />
        <vers num="3.0" edition=":ia-64" />
        <vers num="3.0" edition=":mipsel" />
        <vers num="3.0" edition=":sparc" />
        <vers num="3.0" edition=":ppc" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0771" published="2004-11-23" name="CVE-2004-0771" modified="2011-02-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Buffer overflow in the extract_one function from lhext.c in LHA may allow attackers to execute arbitrary code via a long w (working directory) command line option, a different issue than CVE-2004-0769. NOTE: this issue may be REJECTED if there are not any cases in which LHA is setuid or is otherwise used across security boundaries.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/10354" source="BID" patch="1" adv="1">10354</ref>
      <ref url="https://bugzilla.fedora.us/show_bug.cgi?id=1833" source="FEDORA">FLSA:1833</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/16196" source="XF" adv="1">lha-extractone-bo(16196)</ref>
      <ref url="http://www.securityfocus.com/archive/1/363418" source="BUGTRAQ">20040515 lha buffer overflow(s) again</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-440.html" source="REDHAT">RHSA-2004:440</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-323.html" source="REDHAT">RHSA-2004:323</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200409-13.xml" source="GENTOO">GLSA-200409-13</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9595" source="OVAL">oval:org.mitre.oval:def:9595</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108668791510153" source="BUGTRAQ">20040606 Re: [SECURITY] [DSA 515-1] New lha packages fix several</ref>
      <ref url="http://bugs.gentoo.org/show_bug.cgi?id=51285" source="MISC">http://bugs.gentoo.org/show_bug.cgi?id=51285</ref>
    </refs>
    <vuln_soft>
      <prod vendor="tsugio_okamoto" name="lha">
        <vers num="1.14" />
        <vers num="1.15" />
        <vers num="1.17" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0772" published="2004-10-20" name="CVE-2004-0772" modified="2008-09-10" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Double free vulnerabilities in error handling code in krb524d for MIT Kerberos 5 (krb5) 1.2.8 and earlier may allow remote attackers to execute arbitrary code.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA04-247A.html" source="CERT" patch="1" adv="1">TA04-247A</ref>
      <ref url="http://www.kb.cert.org/vuls/id/350792" source="CERT-VN">VU#350792</ref>
      <ref url="http://web.mit.edu/kerberos/www/advisories/MITKRB5-SA-2004-002-dblfree.txt" source="CONFIRM" patch="1" adv="1">http://web.mit.edu/kerberos/www/advisories/MITKRB5-SA-2004-002-dblfree.txt</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/17158" source="XF" adv="1">kerberos-krb524d-double-free(17158)</ref>
      <ref url="http://www.trustix.net/errata/2004/0045/" source="TRUSTIX">2004-0045</ref>
      <ref url="http://www.securityfocus.com/bid/11078" source="BID">11078</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2004:088" source="MANDRAKE">MDKSA-2004:088</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200409-09.xml" source="GENTOO">GLSA-200409-09</ref>
      <ref url="http://www.debian.org/security/2004/dsa-543" source="DEBIAN">DSA-543</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109508872524753&amp;w=2" source="BUGTRAQ">20040913 [OpenPKG-SA-2004.039] OpenPKG Security Advisory (kerberos)</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000860" source="CONECTIVA">CLA-2004:860</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:4661" source="OVAL" sig="1">oval:org.mitre.oval:def:4661</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mit" name="kerberos">
        <vers num="1.0" />
        <vers num="1.0.8mit" />
        <vers num="1.2.2.beta1" />
        <vers num="5-1.2" />
        <vers num="5-1.2.1" />
        <vers num="5-1.2.2" />
        <vers num="5-1.2.3" />
        <vers num="5-1.2.4" />
        <vers num="5-1.2.5" />
        <vers num="5-1.2.6" />
        <vers num="5-1.2.7" />
        <vers num="5-1.2.8" />
        <vers num="5-1.3" edition="alpha1" />
        <vers num="5-1.3.1" />
        <vers num="5-1.3.2" />
        <vers num="5-1.3.3" />
        <vers num="5-1.3.4" />
        <vers num="5_1.0.6" />
        <vers num="5_1.1.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0774" published="2004-11-03" name="CVE-2004-0774" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">RealNetworks Helix Universal Server 9.0.2 for Linux and 9.0.3 for Windows allows remote attackers to cause a denial of service (CPU and memory exhaustion) via a POST request with a Content-Length header set to -1.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/17648" source="XF" patch="1">helix-post-dos(17648)</ref>
      <ref url="http://www.idefense.com/application/poi/display?id=151&amp;type=vulnerabilities" source="IDEFENSE" adv="1">20041007 RealNetworks Helix Server Content-Length Denial of Service Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="realnetworks" name="helix_universal_mobile_server_and_gateway">
        <vers prev="1" num="10.3.1.716" />
      </prod>
      <prod vendor="realnetworks" name="helix_universal_server">
        <vers num="9.0.2" />
        <vers prev="1" num="9.0.4.958" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0775" published="2004-10-20" name="CVE-2004-0775" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in WIDCOMM Bluetooth Connectivity Software, as used in products such as BTStackServer 1.3.2.7 and 1.4.2.10, Windows XP and Windows 98 with MSI Bluetooth Dongles, and HP IPAQ 5450 running WinCE 3.0, allows remote attackers to execute arbitrary code via certain service requests.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.pentest.co.uk/documents/ptl-2004-03.html" source="MISC" patch="1" adv="1">http://www.pentest.co.uk/documents/ptl-2004-03.html</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/16953" source="XF" adv="1">bluetooth-btw-service-bo(16953)</ref>
      <ref url="http://archives.neohapsis.com/archives/vulnwatch/2004-q3/0029.html" source="VULNWATCH">20040811 ptl-2004-03: WIDCOMM Bluetooth Connectivity Software Buffer Overflows</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/418633/100/0/threaded" source="BUGTRAQ">20051204 have you ever been BluePIMped?</ref>
      <ref url="http://www.internetnews.com/security/article.php/3394181" source="MISC">http://www.internetnews.com/security/article.php/3394181</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109223783402624&amp;w=2" source="BUGTRAQ">20040811 ptl-2004-03: WIDCOMM Bluetooth Connectivity Software Buffer Overflows</ref>
    </refs>
    <vuln_soft>
      <prod vendor="widcomm" name="bluetooth_communication_software">
        <vers num="1.4.1.03" />
      </prod>
      <prod vendor="widcomm" name="btstackserver">
        <vers num="1.3.2.7" />
        <vers num="1.4.2.10" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0777" published="2004-10-20" name="CVE-2004-0777" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Format string vulnerability in the auth_debug function in Courier-IMAP 1.6.0 to 2.2.1, when login debugging (DEBUG_LOGIN) is enabled, allows remote attackers to execute arbitrary code.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/17034" source="XF" patch="1" adv="1">courierimap-authdebug-format-string(17034)</ref>
      <ref url="http://www.idefense.com/application/poi/display?id=131&amp;type=vulnerabilities" source="IDEFENSE" patch="1" adv="1">20040818 Courier-IMAP Remote Format String Vulnerability</ref>
      <ref url="http://www.trustix.net/errata/2004/0043/" source="TRUSTIX">2004-0043</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200408-19.xml" source="GENTOO">GLSA-200408-19</ref>
      <ref url="http://www.securityfocus.com/bid/10976" source="BID">10976</ref>
    </refs>
    <vuln_soft>
      <prod vendor="inter7" name="courier-imap">
        <vers num="1.6" />
        <vers num="1.7" />
        <vers num="2.0.0" />
        <vers num="2.1" />
        <vers num="2.1.1" />
        <vers num="2.1.2" />
        <vers num="2.2.0" />
        <vers num="2.2.1" />
        <vers num="3.0.0." />
        <vers num="3.0.1" />
        <vers num="3.0.2" />
        <vers num="3.0.2_r1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0778" published="2004-10-20" name="CVE-2004-0778" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">CVS 1.11.x before 1.11.17, and 1.12.x before 1.12.9, allows remote attackers to determine the existence of arbitrary files and directories via the -X command for an alternate history file, which causes different error messages to be returned.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/579225" source="CERT-VN" patch="1" adv="1">VU#579225</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/17001" source="XF" patch="1" adv="1">cvs-history-info-disclosure(17001)</ref>
      <ref url="http://www.securityfocus.com/bid/10955" source="BID" patch="1" adv="1">10955</ref>
      <ref url="http://www.mandrakesecure.net/en/advisories/advisory.php?name=MDKSA-2004:108" source="MANDRAKE">MDKSA-2004:108</ref>
      <ref url="http://www.idefense.com/application/poi/display?id=130&amp;type=vulnerabilities" source="IDEFENSE" adv="1">20040816 CVS Undocumented Flag Information Disclosure Vulnerability</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10688" source="OVAL">oval:org.mitre.oval:def:10688</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cvs" name="cvs">
        <vers num="1.10.6" />
        <vers num="1.10.7" />
        <vers num="1.10.8" />
        <vers num="1.11" />
        <vers num="1.11.1" />
        <vers num="1.11.10" />
        <vers num="1.11.11" />
        <vers num="1.11.14" />
        <vers num="1.11.15" />
        <vers num="1.11.16" />
        <vers num="1.11.1_p1" />
        <vers num="1.11.2" />
        <vers num="1.11.3" />
        <vers num="1.11.4" />
        <vers num="1.11.5" />
        <vers num="1.11.6" />
        <vers num="1.12.1" />
        <vers num="1.12.2" />
        <vers num="1.12.5" />
        <vers num="1.12.7" />
        <vers num="1.12.8" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0779" published="2004-08-18" name="CVE-2004-0779" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">The (1) Mozilla 1.6, (2) Firebird 0.7 and (3) Firefox 0.8 web browsers do not properly verify that cached passwords for SSL encrypted sites are only sent via SSL encrypted sessions to the site, which allows a remote attacker to cause a cached password to be sent in cleartext to a spoofed site.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/17018" source="XF">mozilla-plaintext-password(17018)</ref>
      <ref url="http://www.mozilla.org/projects/security/known-vulnerabilities.html#mozilla1.7" source="CONFIRM">http://www.mozilla.org/projects/security/known-vulnerabilities.html#mozilla1.7</ref>
      <ref url="http://bugzilla.mozilla.org/show_bug.cgi?id=226278" source="CONFIRM">http://bugzilla.mozilla.org/show_bug.cgi?id=226278</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2004:082" source="MANDRAKE">MDKSA-2004:082</ref>
    </refs>
    <vuln_soft>
      <prod vendor="firebirdsql" name="firebird">
        <vers num="0.7" />
      </prod>
      <prod vendor="mozilla" name="firefox">
        <vers num="0.8" />
      </prod>
      <prod vendor="mozilla" name="mozilla">
        <vers num="1.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0780" published="2004-12-31" name="CVE-2004-0780" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Buffer overflow in uustat in Sun Solaris 8 and 9 allows local users to execute arbitrary code via a long -S command line argument.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/16193" source="BID" patch="1">16193</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-101933-1" source="SUNALERT" patch="1" adv="1">101933</ref>
      <ref url="http://secunia.com/advisories/18371" source="SECUNIA" patch="1" adv="1">18371</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0113" source="VUPEN">ADV-2006-0113</ref>
      <ref url="http://www.idefense.com/intelligence/vulnerabilities/display.php?id=366" source="IDEFENSE" adv="1">20060110 Sun Solaris uustat Buffer Overflow Vulnerability</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24045" source="XF">solaris-uustat-bo(24045)</ref>
      <ref url="http://support.avaya.com/elmodocs2/security/ASA-2006-056.htm" source="CONFIRM">http://support.avaya.com/elmodocs2/security/ASA-2006-056.htm</ref>
      <ref url="http://securitytracker.com/id?1015455" source="SECTRACK">1015455</ref>
      <ref url="http://secunia.com/advisories/19087" source="SECUNIA">19087</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="solaris">
        <vers num="8.0" edition="" />
        <vers num="8.0" edition=":x86" />
        <vers num="9.0" edition="" />
        <vers num="9.0" edition=":sparc" />
        <vers num="9.0" edition=":x86" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0781" published="2004-10-20" name="CVE-2004-0781" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in list.cgi in the Icecast internal web server (icecast-server) 1.3.12 and earlier allows remote attackers to inject arbitrary web script via the UserAgent parameter.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/17086" source="XF" patch="1" adv="1">icecast-list-useragent-xss(17086)</ref>
      <ref url="http://www.securityfocus.com/bid/11021" source="BID" patch="1" adv="1">11021</ref>
      <ref url="http://www.debian.org/security/2004/dsa-541" source="DEBIAN" patch="1" adv="1">DSA-541</ref>
    </refs>
    <vuln_soft>
      <prod vendor="icecast" name="icecast">
        <vers num="1.3.0" />
        <vers num="1.3.10" />
        <vers num="1.3.10.1" />
        <vers num="1.3.11" />
        <vers num="1.3.12" />
        <vers num="1.3.5" />
        <vers num="1.3.5.1" />
        <vers num="1.3.7" />
        <vers num="1.3.7.1" />
        <vers num="1.3.8" />
        <vers num="1.3.9" />
        <vers num="1.3.9.1" />
        <vers num="1.3.9.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0782" published="2004-10-20" name="CVE-2004-0782" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Integer overflow in pixbuf_create_from_xpm (io-xpm.c) in the XPM image decoder for gtk+ 2.4.4 (gtk2) and earlier, and gdk-pixbuf before 0.22, allows remote attackers to execute arbitrary code via certain n_col and cpp values that enable a heap-based buffer overflow.  NOTE: this identifier is ONLY for gtk+.  It was incorrectly referenced in an advisory for a different issue (CVE-2004-0687).</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/729894" source="CERT-VN">VU#729894</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-466.html" source="REDHAT" patch="1" adv="1">RHSA-2004:466</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-447.html" source="REDHAT" patch="1" adv="1">RHSA-2004:447</ref>
      <ref url="https://bugzilla.fedora.us/show_bug.cgi?id=2005" source="FEDORA">FLSA:2005</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/17386" source="XF">gtk-xpm-pixbufcreatefromxpm-bo(17386)</ref>
      <ref url="http://www.mandrakesecure.net/en/advisories/advisory.php?name=MDKSA-2004:095" source="MANDRAKE">MDKSA-2004:095</ref>
      <ref url="http://www.debian.org/security/2004/dsa-546" source="DEBIAN">DSA-546</ref>
      <ref url="http://scary.beasts.org/security/CESA-2004-005.txt" source="MISC">http://scary.beasts.org/security/CESA-2004-005.txt</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11539" source="OVAL">oval:org.mitre.oval:def:11539</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109528994916275&amp;w=2" source="BUGTRAQ" adv="1">20040915 CESA-2004-005: gtk+ XPM decoder</ref>
      <ref url="http://www.securityfocus.com/bid/11195" source="BID">11195</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/419771/100/0/threaded" source="FEDORA">FLSA-2005:155510</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:214" source="MANDRIVA">MDKSA-2005:214</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-101776-1" source="SUNALERT">101776</ref>
      <ref url="http://secunia.com/advisories/17657" source="SECUNIA">17657</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000875" source="CONECTIVA">CLA-2004:875</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1617" source="OVAL" sig="1">oval:org.mitre.oval:def:1617</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gnome" name="gdkpixbuf">
        <vers num="0.17" />
        <vers num="0.18" />
        <vers num="0.20" />
        <vers num="0.22" />
      </prod>
      <prod vendor="gtk" name="gtk+">
        <vers num="2.0.2" />
        <vers num="2.0.6" />
        <vers num="2.2.1" />
        <vers num="2.2.3" />
        <vers num="2.2.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0783" published="2004-10-20" name="CVE-2004-0783" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Stack-based buffer overflow in xpm_extract_color (io-xpm.c) in the XPM image decoder for gtk+ 2.4.4 (gtk2) and earlier, and gdk-pixbuf before 0.22, may allow remote attackers to execute arbitrary code via a certain color string.  NOTE: this identifier is ONLY for gtk+.  It was incorrectly referenced in an advisory for a different issue (CVE-2004-0688).</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/369358" source="CERT-VN">VU#369358</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-466.html" source="REDHAT" patch="1" adv="1">RHSA-2004:466</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-447.html" source="REDHAT" patch="1" adv="1">RHSA-2004:447</ref>
      <ref url="https://bugzilla.fedora.us/show_bug.cgi?id=2005" source="FEDORA">FLSA:2005</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/17385" source="XF">gtk-xpm-xpmextractcolor-bo(17385)</ref>
      <ref url="http://www.mandrakesecure.net/en/advisories/advisory.php?name=MDKSA-2004:096" source="MANDRAKE">MDKSA-2004:096</ref>
      <ref url="http://www.mandrakesecure.net/en/advisories/advisory.php?name=MDKSA-2004:095" source="MANDRAKE">MDKSA-2004:095</ref>
      <ref url="http://scary.beasts.org/security/CESA-2004-005.txt" source="MISC">http://scary.beasts.org/security/CESA-2004-005.txt</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9348" source="OVAL">oval:org.mitre.oval:def:9348</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109528994916275&amp;w=2" source="BUGTRAQ" adv="1">20040915 CESA-2004-005: gtk+ XPM decoder</ref>
      <ref url="http://www.securityfocus.com/bid/11195" source="BID">11195</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/419771/100/0/threaded" source="FEDORA">FLSA-2005:155510</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:214" source="MANDRIVA">MDKSA-2005:214</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-101776-1" source="SUNALERT">101776</ref>
      <ref url="http://secunia.com/advisories/17657" source="SECUNIA">17657</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000875" source="CONECTIVA">CLA-2004:875</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1786" source="OVAL" sig="1">oval:org.mitre.oval:def:1786</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gnome" name="gdkpixbuf">
        <vers num="0.17" />
        <vers num="0.18" />
        <vers num="0.20" />
        <vers num="0.22" />
      </prod>
      <prod vendor="gtk" name="gtk+">
        <vers num="2.0.2" />
        <vers num="2.0.6" />
        <vers num="2.2.1" />
        <vers num="2.2.3" />
        <vers num="2.2.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0784" published="2004-10-20" name="CVE-2004-0784" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">The smiley theme functionality in Gaim before 0.82 allows remote attackers to execute arbitrary commands via shell metacharacters in the filename of the tar file that is dragged to the smiley selector.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/17144" source="XF" patch="1" adv="1">gaim-smiley-command-execution(17144)</ref>
      <ref url="http://www.fedoranews.org/updates/FEDORA-2004-279.shtml" source="FEDORA" patch="1" adv="1">FEDORA-2004-279</ref>
      <ref url="http://www.fedoranews.org/updates/FEDORA-2004-278.shtml" source="FEDORA" patch="1" adv="1">FEDORA-2004-278</ref>
      <ref url="http://gaim.sourceforge.net/security/?id=1" source="CONFIRM" patch="1" adv="1">http://gaim.sourceforge.net/security/?id=1</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-400.html" source="REDHAT">RHSA-2004:400</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200408-27.xml" source="GENTOO" adv="1">GLSA-200408-27</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10008" source="OVAL">oval:org.mitre.oval:def:10008</ref>
    </refs>
    <vuln_soft>
      <prod vendor="rob_flynn" name="gaim">
        <vers num="0.10" />
        <vers num="0.10.3" />
        <vers num="0.50" />
        <vers num="0.51" />
        <vers num="0.52" />
        <vers num="0.53" />
        <vers num="0.54" />
        <vers num="0.55" />
        <vers num="0.56" />
        <vers num="0.57" />
        <vers num="0.58" />
        <vers num="0.59" />
        <vers num="0.59.1" />
        <vers num="0.60" />
        <vers num="0.61" />
        <vers num="0.62" />
        <vers num="0.63" />
        <vers num="0.64" />
        <vers num="0.65" />
        <vers num="0.66" />
        <vers num="0.67" />
        <vers num="0.68" />
        <vers num="0.69" />
        <vers num="0.70" />
        <vers num="0.71" />
        <vers num="0.72" />
        <vers num="0.73" />
        <vers num="0.74" />
        <vers num="0.75" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0785" published="2004-10-20" name="CVE-2004-0785" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple buffer overflows in Gaim before 0.82 allow remote attackers to cause a denial of service and possibly execute arbitrary code via (1) Rich Text Format (RTF) messages, (2) a long hostname for the local system as obtained from DNS, or (3) a long URL that is not properly handled by the URL decoder.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.fedoranews.org/updates/FEDORA-2004-279.shtml" source="FEDORA" patch="1" adv="1">FEDORA-2004-279</ref>
      <ref url="http://www.fedoranews.org/updates/FEDORA-2004-278.shtml" source="FEDORA" patch="1" adv="1">FEDORA-2004-278</ref>
      <ref url="http://gaim.sourceforge.net/security/?id=3" source="CONFIRM" patch="1" adv="1">http://gaim.sourceforge.net/security/?id=3</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-400.html" source="REDHAT">RHSA-2004:400</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200408-27.xml" source="GENTOO" adv="1">GLSA-200408-27</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10907" source="OVAL">oval:org.mitre.oval:def:10907</ref>
      <ref url="http://gaim.sourceforge.net/security/?id=5" source="CONFIRM">http://gaim.sourceforge.net/security/?id=5</ref>
      <ref url="http://gaim.sourceforge.net/security/?id=4" source="CONFIRM">http://gaim.sourceforge.net/security/?id=4</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/17143" source="XF">gaim-url-bo(17143)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/17142" source="XF">gaim-hostname-bo(17142)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/17141" source="XF">gaim-rtf-bo(17141)</ref>
      <ref url="http://www.securityfocus.com/bid/11056" source="BID">11056</ref>
      <ref url="http://www.osvdb.org/9263" source="OSVDB">9263</ref>
      <ref url="http://www.osvdb.org/9262" source="OSVDB">9262</ref>
      <ref url="http://www.osvdb.org/9261" source="OSVDB">9261</ref>
      <ref url="http://securitytracker.com/id?1011083" source="SECTRACK">1011083</ref>
      <ref url="http://secunia.com/advisories/13101" source="SECUNIA">13101</ref>
      <ref url="http://secunia.com/advisories/12929" source="SECUNIA">12929</ref>
      <ref url="http://secunia.com/advisories/12480" source="SECUNIA">12480</ref>
      <ref url="http://secunia.com/advisories/12383" source="SECUNIA">12383</ref>
    </refs>
    <vuln_soft>
      <prod vendor="rob_flynn" name="gaim">
        <vers num="0.10" />
        <vers num="0.10.3" />
        <vers num="0.50" />
        <vers num="0.51" />
        <vers num="0.52" />
        <vers num="0.53" />
        <vers num="0.54" />
        <vers num="0.55" />
        <vers num="0.56" />
        <vers num="0.57" />
        <vers num="0.58" />
        <vers num="0.59" />
        <vers num="0.59.1" />
        <vers num="0.60" />
        <vers num="0.61" />
        <vers num="0.62" />
        <vers num="0.63" />
        <vers num="0.64" />
        <vers num="0.65" />
        <vers num="0.66" />
        <vers num="0.67" />
        <vers num="0.68" />
        <vers num="0.69" />
        <vers num="0.70" />
        <vers num="0.71" />
        <vers num="0.72" />
        <vers num="0.73" />
        <vers num="0.74" />
        <vers num="0.75" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0786" published="2004-10-20" name="CVE-2004-0786" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The IPv6 URI parsing routines in the apr-util library for Apache 2.0.50 and earlier allow remote attackers to cause a denial of service (child process crash) via a certain URI, as demonstrated using the Codenomicon HTTP Test Tool.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-463.html" source="REDHAT" patch="1" adv="1">RHSA-2004:463</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/17382" source="XF">apache-ipv6-aprutil-dos(17382)</ref>
      <ref url="http://www.trustix.org/errata/2004/0047/" source="TRUSTIX">2004-0047</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2004_32_apache2.html" source="SUSE">SUSE-SA:2004:032</ref>
      <ref url="http://www.mandrakesecure.net/en/advisories/advisory.php?name=MDKSA-2004:096" source="MANDRAKE">MDKSA-2004:096</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200409-21.xml" source="GENTOO">GLSA-200409-21</ref>
      <ref url="http://secunia.com/advisories/12540" source="SECUNIA">12540</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11380" source="OVAL">oval:org.mitre.oval:def:11380</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apache" name="http_server">
        <vers num="2.0" />
        <vers num="2.0.28" />
        <vers num="2.0.32" />
        <vers num="2.0.35" />
        <vers num="2.0.36" />
        <vers num="2.0.37" />
        <vers num="2.0.38" />
        <vers num="2.0.39" />
        <vers num="2.0.40" />
        <vers num="2.0.41" />
        <vers num="2.0.42" />
        <vers num="2.0.43" />
        <vers num="2.0.44" />
        <vers num="2.0.45" />
        <vers num="2.0.46" />
        <vers num="2.0.47" />
        <vers num="2.0.48" />
        <vers num="2.0.49" />
        <vers num="2.0.50" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0787" published="2004-10-20" name="CVE-2004-0787" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in the web frontend in OpenCA 0.9.1-8 and earlier, and 0.9.2 RC6 and earlier, allows remote attackers to inject arbitrary web script or HTML via the form input fields.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/17274" source="XF" patch="1" adv="1">openca-frontend-xss(17274)</ref>
      <ref url="http://www.securityfocus.com/bid/11113" source="BID" patch="1" adv="1">11113</ref>
      <ref url="http://www.openca.org/news/CAN-2004-0787.txt" source="CONFIRM" patch="1" adv="1">http://www.openca.org/news/CAN-2004-0787.txt</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109448767123954&amp;w=2" source="BUGTRAQ">20040906 OpenCA Security Advisory: Cross Site Scripting vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="openca" name="openca">
        <vers num="0.8.0" />
        <vers num="0.8.1" />
        <vers num="0.8.6" />
        <vers num="0.9.0" />
        <vers num="0.9.0.1" />
        <vers num="0.9.0.2" />
        <vers num="0.9.1" />
        <vers num="0.9.1.2" />
        <vers num="0.9.1.3" />
        <vers num="0.9.1.4" />
        <vers num="0.9.1.5" />
        <vers num="0.9.1.6" />
        <vers num="0.9.1.7" />
        <vers num="0.9.1.8" />
        <vers num="0.9.2_rc6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0788" published="2004-10-20" name="CVE-2004-0788" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Integer overflow in the ICO image decoder for (1) gdk-pixbuf before 0.22 and (2) gtk2 before 2.2.4 allows remote attackers to cause a denial of service (application crash) via a crafted ICO file.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/577654" source="CERT-VN">VU#577654</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-466.html" source="REDHAT" patch="1" adv="1">RHSA-2004:466</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-447.html" source="REDHAT" patch="1" adv="1">RHSA-2004:447</ref>
      <ref url="https://bugzilla.fedora.us/show_bug.cgi?id=2005" source="FEDORA">FLSA:2005</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/17387" source="XF">gtk-ico-integer-bo(17387)</ref>
      <ref url="http://www.mandrakesecure.net/en/advisories/advisory.php?name=MDKSA-2004:095" source="MANDRAKE">MDKSA-2004:095</ref>
      <ref url="http://www.debian.org/security/2004/dsa-546" source="DEBIAN">DSA-546</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10506" source="OVAL">oval:org.mitre.oval:def:10506</ref>
      <ref url="http://www.securityfocus.com/bid/11195" source="BID">11195</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/419771/100/0/threaded" source="FEDORA">FLSA-2005:155510</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:214" source="MANDRIVA">MDKSA-2005:214</ref>
      <ref url="http://secunia.com/advisories/17657" source="SECUNIA">17657</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000875" source="CONECTIVA">CLA-2004:875</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gnome" name="gdkpixbuf">
        <vers num="0.17" />
        <vers num="0.18" />
        <vers num="0.20" />
        <vers num="0.22" />
      </prod>
      <prod vendor="gtk" name="gtk+">
        <vers num="2.0.2" />
        <vers num="2.0.6" />
        <vers num="2.2.1" />
        <vers num="2.2.3" />
        <vers num="2.2.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0789" published="2004-12-31" name="CVE-2004-0789" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Multiple implementations of the DNS protocol, including (1) Poslib 1.0.2-1 and earlier as used by Posadis, (2) Axis Network products before firmware 3.13, and (3) Men &amp; Mice Suite 2.2x before 2.2.3 and 3.5.x before 3.5.2, allow remote attackers to cause a denial of service (CPU and network bandwidth consumption) by triggering a communications loop via (a) DNS query packets with localhost as a spoofed source address, or (b) a response packet that triggers a response packet.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/17997" source="XF" patch="1">dns-localhost-dos(17997)</ref>
      <ref url="http://www.securityfocus.com/bid/11642" source="BID" patch="1">11642</ref>
      <ref url="http://www.posadis.org/advisories/pos_adv_006.txt" source="CONFIRM" patch="1" adv="1">http://www.posadis.org/advisories/pos_adv_006.txt</ref>
      <ref url="http://securitytracker.com/id?1012157" source="SECTRACK" patch="1">1012157</ref>
      <ref url="http://secunia.com/advisories/13145" source="SECUNIA" patch="1">13145</ref>
      <ref url="http://www.niscc.gov.uk/niscc/docs/re-20041109-00957.pdf" source="MISC" adv="1">http://www.niscc.gov.uk/niscc/docs/re-20041109-00957.pdf</ref>
      <ref url="http://www.niscc.gov.uk/niscc/docs/al-20041130-00862.html?lang=en" source="MISC" adv="1">http://www.niscc.gov.uk/niscc/docs/al-20041130-00862.html?lang=en</ref>
    </refs>
    <vuln_soft>
      <prod vendor="delegate" name="delegate">
        <vers num="7.7.0" />
        <vers num="7.7.1" />
        <vers num="7.8.0" />
        <vers num="7.8.1" />
        <vers num="7.8.2" />
        <vers num="7.9.11" />
        <vers num="8.3.3" />
        <vers num="8.3.4" />
        <vers num="8.4.0" />
        <vers num="8.5.0" />
        <vers num="8.9" />
        <vers num="8.9.1" />
        <vers num="8.9.2" />
        <vers num="8.9.3" />
        <vers num="8.9.4" />
        <vers num="8.9.5" />
      </prod>
      <prod vendor="dnrd" name="dnrd">
        <vers num="1.0" />
        <vers num="1.1" />
        <vers num="1.2" />
        <vers num="1.3" />
        <vers num="1.4" />
        <vers num="2.0" />
        <vers num="2.1" />
        <vers num="2.10" />
        <vers num="2.2" />
        <vers num="2.3" />
        <vers num="2.4" />
        <vers num="2.5" />
        <vers num="2.6" />
        <vers num="2.7" />
        <vers num="2.8" />
        <vers num="2.9" />
      </prod>
      <prod vendor="don_moore" name="mydns">
        <vers num="0.10.0" />
        <vers num="0.6" />
        <vers num="0.7" />
        <vers num="0.8" />
        <vers num="0.9" />
      </prod>
      <prod vendor="maradns" name="maradns">
        <vers num="0.5.28" />
        <vers num="0.5.29" />
        <vers num="0.5.30" />
        <vers num="0.5.31" />
        <vers num="0.8.05" />
      </prod>
      <prod vendor="pliant" name="pliant_dns_server">
        <vers num="" />
      </prod>
      <prod vendor="posadis" name="posadis">
        <vers num="0.50.4" />
        <vers num="0.50.5" />
        <vers num="0.50.6" />
        <vers num="0.50.7" />
        <vers num="0.50.8" />
        <vers num="0.50.9" />
        <vers num="0.60.0" />
        <vers num="0.60.1" />
        <vers num="m5pre1" />
        <vers num="m5pre2" />
      </prod>
      <prod vendor="qbik" name="wingate">
        <vers num="3.0" />
        <vers num="4.0.1" />
        <vers num="4.1_beta_a" />
        <vers num="6.0" />
        <vers num="6.0.1_build_993" />
        <vers num="6.0.1_build_995" />
      </prod>
      <prod vendor="team_johnlong" name="raidendnsd">
        <vers num="" />
      </prod>
      <prod vendor="axis" name="2100_network_camera">
        <vers num="2.0" />
        <vers num="2.01" />
        <vers num="2.02" />
        <vers num="2.03" />
        <vers num="2.12" />
        <vers num="2.30" />
        <vers num="2.31" />
        <vers num="2.32" />
        <vers num="2.33" />
        <vers num="2.34" />
        <vers num="2.40" />
        <vers num="2.41" />
      </prod>
      <prod vendor="axis" name="2110_network_camera">
        <vers num="2.12" />
        <vers num="2.30" />
        <vers num="2.31" />
        <vers num="2.32" />
        <vers num="2.34" />
        <vers num="2.40" />
        <vers num="2.41" />
      </prod>
      <prod vendor="axis" name="2120_network_camera">
        <vers num="2.12" />
        <vers num="2.30" />
        <vers num="2.31" />
        <vers num="2.32" />
        <vers num="2.34" />
        <vers num="2.40" />
        <vers num="2.41" />
      </prod>
      <prod vendor="axis" name="2400_video_server">
        <vers num="3.11" />
        <vers num="3.12" />
      </prod>
      <prod vendor="axis" name="2401_video_server">
        <vers num="3.12" />
      </prod>
      <prod vendor="axis" name="2420_network_camera">
        <vers num="2.12" />
        <vers num="2.30" />
        <vers num="2.31" />
        <vers num="2.32" />
        <vers num="2.33" />
        <vers num="2.34" />
        <vers num="2.40" />
        <vers num="2.41" />
      </prod>
      <prod vendor="axis" name="2460_network_dvr">
        <vers num="3.12" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0790" published="2005-04-12" name="CVE-2004-0790" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Multiple TCP/IP and ICMP implementations allow remote attackers to cause a denial of service (reset TCP connections) via spoofed ICMP error messages, aka the "blind connection-reset attack."  NOTE: CVE-2004-0790, CVE-2004-0791, and CVE-2004-1060 have been SPLIT based on different attacks; CVE-2005-0065, CVE-2005-0066, CVE-2005-0067, and CVE-2005-0068 are related identifiers that are SPLIT based on the underlying vulnerability.  While CVE normally SPLITs based on vulnerability, the attack-based identifiers exist due to the variety and number of affected implementations and solutions that address the attacks instead of the underlying vulnerabilities.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms05-019.mspx" source="MS" patch="1" adv="1">MS05-019</ref>
      <ref url="http://www.watersprings.org/pub/id/draft-gont-tcpm-icmp-attacks-03.txt" source="MISC">http://www.watersprings.org/pub/id/draft-gont-tcpm-icmp-attacks-03.txt</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/3983" source="VUPEN">ADV-2006-3983</ref>
      <ref url="http://www.uniras.gov.uk/niscc/docs/al-20050412-00308.html?lang=en" source="MISC" adv="1">http://www.uniras.gov.uk/niscc/docs/al-20050412-00308.html?lang=en</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/449179/100/0/threaded" source="HP">HPSBST02161</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/418882/100/0/threaded" source="HP">SSRT4884</ref>
      <ref url="http://www.gont.com.ar/drafts/icmp-attacks-against-tcp.html" source="MISC">http://www.gont.com.ar/drafts/icmp-attacks-against-tcp.html</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-57746-1" source="SUNALERT" adv="1">57746</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112861397904255&amp;w=2" source="HP">HPSBTU01210</ref>
      <ref url="http://www.securityfocus.com/bid/13124" source="BID">13124</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/449179/100/0/threaded" source="HP">SSRT061264</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/418882/100/0/threaded" source="HP">HPSBUX01164</ref>
      <ref url="http://www.microsoft.com/technet/security/Bulletin/MS06-064.mspx" source="MS">MS06-064</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-101658-1" source="SUNALERT">101658</ref>
      <ref url="http://securityreason.com/securityalert/57" source="SREASON">57</ref>
      <ref url="http://securityreason.com/securityalert/19" source="SREASON">19</ref>
      <ref url="http://secunia.com/advisories/22341" source="SECUNIA">22341</ref>
      <ref url="http://secunia.com/advisories/18317" source="SECUNIA">18317</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112861397904255&amp;w=2" source="HP">SSRT4743</ref>
      <ref url="ftp://ftp.sco.com/pub/updates/OpenServer/SCOSA-2006.4/SCOSA-2006.4.txt" source="SCO">SCOSA-2006.4</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:622" source="OVAL" sig="1">oval:org.mitre.oval:def:622</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:53" source="OVAL" sig="1">oval:org.mitre.oval:def:53</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:514" source="OVAL" sig="1">oval:org.mitre.oval:def:514</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:4804" source="OVAL" sig="1">oval:org.mitre.oval:def:4804</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:412" source="OVAL" sig="1">oval:org.mitre.oval:def:412</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:3458" source="OVAL" sig="1">oval:org.mitre.oval:def:3458</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:211" source="OVAL" sig="1">oval:org.mitre.oval:def:211</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1910" source="OVAL" sig="1">oval:org.mitre.oval:def:1910</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:176" source="OVAL" sig="1">oval:org.mitre.oval:def:176</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1177" source="OVAL" sig="1">oval:org.mitre.oval:def:1177</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_2000">
        <vers num="" edition="sp3" />
        <vers num="" edition="sp4" />
        <vers num="" edition="sp4:" />
        <vers num="" edition="sp4::fr" />
      </prod>
      <prod vendor="microsoft" name="windows_2003_server">
        <vers num="r2" />
      </prod>
      <prod vendor="microsoft" name="windows_98">
        <vers num="" edition="gold" />
      </prod>
      <prod vendor="microsoft" name="windows_98se">
        <vers num="" />
      </prod>
      <prod vendor="microsoft" name="windows_me">
        <vers num="" />
      </prod>
      <prod vendor="microsoft" name="windows_xp">
        <vers num="" edition=":64-bit" />
        <vers num="" edition="sp1" />
        <vers num="" edition="sp1:tablet_pc" />
        <vers num="" edition="sp1:64-bit" />
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:tablet_pc" />
      </prod>
      <prod vendor="sun" name="solaris">
        <vers num="10.0" edition="" />
        <vers num="10.0" edition=":sparc" />
        <vers num="7.0" />
        <vers num="8.0" />
        <vers num="9.0" edition="" />
        <vers num="9.0" edition=":sparc" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0791" published="2005-04-12" name="CVE-2004-0791" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Multiple TCP/IP and ICMP implementations allow remote attackers to cause a denial of service (network throughput reduction for TCP connections) via a blind throughput-reduction attack using spoofed Source Quench packets, aka the "ICMP Source Quench attack."  NOTE: CVE-2004-0790, CVE-2004-0791, and CVE-2004-1060 have been SPLIT based on different attacks; CVE-2005-0065, CVE-2005-0066, CVE-2005-0067, and CVE-2005-0068 are related identifiers that are SPLIT based on the underlying vulnerability.  While CVE normally SPLITs based on vulnerability, the attack-based identifiers exist due to the variety and number of affected implementations and solutions that address the attacks instead of the underlying vulnerabilities.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.watersprings.org/pub/id/draft-gont-tcpm-icmp-attacks-03.txt" source="MISC">http://www.watersprings.org/pub/id/draft-gont-tcpm-icmp-attacks-03.txt</ref>
      <ref url="http://www.uniras.gov.uk/niscc/docs/al-20050412-00308.html?lang=en" source="MISC" adv="1">http://www.uniras.gov.uk/niscc/docs/al-20050412-00308.html?lang=en</ref>
      <ref url="http://www.gont.com.ar/drafts/icmp-attacks-against-tcp.html" source="MISC">http://www.gont.com.ar/drafts/icmp-attacks-against-tcp.html</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-57746-1" source="SUNALERT" adv="1">57746</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10228" source="OVAL">oval:org.mitre.oval:def:10228</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112861397904255&amp;w=2" source="HP">HPSBTU01210</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112861397904255&amp;w=2" source="HP">SSRT4884</ref>
      <ref url="http://www.securityfocus.com/bid/13124" source="BID">13124</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/428058/100/0/threaded" source="FEDORA">FLSA:157459-2</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/428028/100/0/threaded" source="FEDORA">FLSA:157459-1</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/418882/100/0/threaded" source="HP">HPSBUX01164</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-043.html" source="REDHAT">RHSA-2005:043</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-017.html" source="REDHAT">RHSA-2005:017</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-016.html" source="REDHAT">RHSA-2005:016</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-101658-1" source="SUNALERT">101658</ref>
      <ref url="http://securityreason.com/securityalert/57" source="SREASON">57</ref>
      <ref url="http://securityreason.com/securityalert/19" source="SREASON">19</ref>
      <ref url="http://secunia.com/advisories/18317" source="SECUNIA">18317</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112861397904255&amp;w=2" source="HP">SSRT4743</ref>
      <ref url="ftp://ftp.sco.com/pub/updates/OpenServer/SCOSA-2006.4/SCOSA-2006.4.txt" source="SCO">SCOSA-2006.4</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:726" source="OVAL" sig="1">oval:org.mitre.oval:def:726</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:688" source="OVAL" sig="1">oval:org.mitre.oval:def:688</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:596" source="OVAL" sig="1">oval:org.mitre.oval:def:596</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:464" source="OVAL" sig="1">oval:org.mitre.oval:def:464</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:184" source="OVAL" sig="1">oval:org.mitre.oval:def:184</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1112" source="OVAL" sig="1">oval:org.mitre.oval:def:1112</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="solaris">
        <vers num="10.0" edition="" />
        <vers num="10.0" edition=":sparc" />
        <vers num="7.0" />
        <vers num="8.0" />
        <vers num="9.0" edition="" />
        <vers num="9.0" edition=":sparc" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0792" published="2004-10-20" name="CVE-2004-0792" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)" CVSS_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_base_score="6.4">
    <desc>
      <descript source="cve">Directory traversal vulnerability in the sanitize_path function in util.c for rsync 2.6.2 and earlier, when chroot is disabled, allows attackers to read or write certain files.</descript>
    </desc>
    <loss_types>
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200408-17.xml" source="GENTOO" patch="1" adv="1">GLSA-200408-17</ref>
      <ref url="http://www.debian.org/security/2004/dsa-538" source="DEBIAN" patch="1" adv="1">DSA-538</ref>
      <ref url="http://www.trustix.net/errata/2004/0042/" source="TRUSTIX">2004-0042</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2004_26_rsync.html" source="SUSE">SUSE-SA:2004:026</ref>
      <ref url="http://samba.org/rsync/#security_aug04" source="CONFIRM">http://samba.org/rsync/#security_aug04</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10561" source="OVAL">oval:org.mitre.oval:def:10561</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109277141223839&amp;w=2" source="BUGTRAQ">20040817 LNSA-#2004-0017: rsync (Aug, 17 2004)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109268147522290&amp;w=2" source="BUGTRAQ">20040816 TSSA-2004-020-ES - rsync</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2004:083" source="MANDRAKE">MDKSA-2004:083</ref>
    </refs>
    <vuln_soft>
      <prod vendor="andrew_tridgell" name="rsync">
        <vers num="2.3.1" />
        <vers num="2.3.2" />
        <vers num="2.3.2_1.2" edition="" />
        <vers num="2.3.2_1.2" edition=":arm" />
        <vers num="2.3.2_1.2" edition=":sparc" />
        <vers num="2.3.2_1.2" edition=":intel" />
        <vers num="2.3.2_1.2" edition=":alpha" />
        <vers num="2.3.2_1.2" edition=":m68k" />
        <vers num="2.3.2_1.2" edition=":ppc" />
        <vers num="2.3.2_1.3" />
        <vers num="2.4.0" />
        <vers num="2.4.1" />
        <vers num="2.4.3" />
        <vers num="2.4.4" />
        <vers num="2.4.5" />
        <vers num="2.4.6" />
        <vers num="2.4.8" />
        <vers num="2.5.0" />
        <vers num="2.5.1" />
        <vers num="2.5.2" />
        <vers num="2.5.3" />
        <vers num="2.5.4" />
        <vers num="2.5.5" />
        <vers num="2.5.6" />
        <vers num="2.5.7" />
        <vers num="2.6" />
        <vers num="2.6.1" />
        <vers num="2.6.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0793" published="2004-10-20" name="CVE-2004-0793" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">The calendar program in bsdmainutils 6.0 through 6.0.14 does not drop root privileges when executed with the -a flag, which allows attackers to execute arbitrary commands via a calendar event file.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/17162" source="XF" patch="1" adv="1">bsdmainutils-calendar-gain-privileges(17162)</ref>
      <ref url="http://www.securityfocus.com/bid/11077" source="BID" patch="1" adv="1">11077</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109396230317359&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20040830 Possible root compromose with bsdmainutils 6.0.x &lt; 6.0.15 (Debian testing/unstable)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="debian" name="debian_linux">
        <vers num="6.0" />
        <vers num="6.0.14" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0794" published="2004-10-20" name="CVE-2004-0794" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_score="5.1" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="4.9" CVSS_base_score="5.1">
    <desc>
      <descript source="cve">Multiple signal handler race conditions in lukemftpd (aka tnftpd before 20040810) allow remote authenticated attackers to cause a denial of service or execute arbitrary code.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <race />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="ftp://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2004-009.txt.asc" source="NETBSD" patch="1" adv="1">NetBSD-SA2004-009</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/17020" source="XF">tnftpd-gain-access(17020)</ref>
      <ref url="http://www.vuxml.org/freebsd/c4b025bb-f05d-11d8-9837-000c41e2cdad.html" source="CONFIRM" adv="1">http://www.vuxml.org/freebsd/c4b025bb-f05d-11d8-9837-000c41e2cdad.html</ref>
      <ref url="http://www.debian.org/security/2004/dsa-551" source="DEBIAN">DSA-551</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2004-August/025418.html" source="FULLDISC">20040817 Multiple remote vulnerabilities in lukemftpd aka. tnftpd</ref>
    </refs>
    <vuln_soft>
      <prod vendor="luke_mewburn" name="lukemftp">
        <vers num="1.1" />
        <vers num="1.5" />
      </prod>
      <prod vendor="luke_mewburn" name="tnftpd">
        <vers num="2003-12-17" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0795" published="2004-10-20" name="CVE-2004-0795" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">DB2 8.1 remote command server (DB2RCMD.EXE) executes the db2rcmdc.exe program as the db2admin administrator, which allows local users to gain privileges via the DB2REMOTECMD named pipe.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/15420" source="XF" patch="1" adv="1">db2-rcs-gain-privileges(15420)</ref>
      <ref url="http://www.securityfocus.com/bid/9821" source="BID" patch="1" adv="1">9821</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107885081414173&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20040309 IBM DB2 Remote Command Execution Privilege Upgrade (#NISR09032004)</ref>
      <ref url="http://www.nextgenss.com/advisories/db2rmtcmd.txt" source="MISC">http://www.nextgenss.com/advisories/db2rmtcmd.txt</ref>
      <ref url="http://www-1.ibm.com/support/docview.wss?uid=swg1IY53894" source="AIXAPAR" adv="1">IY53894</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="db2_universal_database">
        <vers num="8.1" edition="" />
        <vers num="8.1" edition=":aix" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0796" published="2004-10-20" name="CVE-2004-0796" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">SpamAssassin 2.5x, and 2.6x before 2.64, allows remote attackers to cause a denial of service via certain malformed messages.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/10957" source="BID" patch="1" adv="1">10957</ref>
      <ref url="https://bugzilla.fedora.us/show_bug.cgi?id=2268" source="FEDORA">FLSA:2268</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/16938" source="XF">spamassassin-dos(16938)</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200408-06.xml" source="GENTOO">GLSA-200408-06</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10413" source="OVAL">oval:org.mitre.oval:def:10413</ref>
      <ref url="http://marc.theaimsgroup.com/?l=spamassassin-announce&amp;m=109168121628767&amp;w=2" source="MLIST" adv="1">[spamassassin-announce] 20040805 [SA-Announce] SpamAssassin 2.64 is released!</ref>
      <ref url="http://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=129337" source="CONFIRM">http://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=129337</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2004:084" source="MANDRAKE">MDKSA-2004:084</ref>
    </refs>
    <vuln_soft>
      <prod vendor="spamassassin" name="spamassassin">
        <vers num="2.40" />
        <vers num="2.41" />
        <vers num="2.42" />
        <vers num="2.43" />
        <vers num="2.44" />
        <vers num="2.50" />
        <vers num="2.55" />
        <vers num="2.60" />
        <vers num="2.63" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2004-0797" published="2004-10-20" name="CVE-2004-0797" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">The error handling in the (1) inflate and (2) inflateBack functions in ZLib compression library 1.2.x allows local users to cause a denial of service (application crash).</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/238678" source="CERT-VN">VU#238678</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109353792914900&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20040825 [OpenPKG-SA-2004.038] OpenPKG Security Advisory (zlib)</ref>
      <ref url="https://bugzilla.fedora.us/show_bug.cgi?id=2043" source="FEDORA">FLSA:2043</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/17119" source="XF">zlib-inflate-inflateback-dos(17119)</ref>
      <ref url="http://www.slackware.com/security/viewer.php?l=slackware-security&amp;y=2004&amp;m=slackware-security.319160" source="SLACKWARE">SSA:2004-278</ref>
      <ref url="http://www.securityfocus.com/bid/11051" source="BID">11051</ref>
      <ref url="http://www.osvdb.org/9361" source="OSVDB">9361</ref>
      <ref url="http://www.osvdb.org/9360" source="OSVDB">9360</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2004_29_zlib.html" source="SUSE">SUSE-SA:2004:029</ref>
      <ref url="http://securitytracker.com/id?1011085" source="SECTRACK">1011085</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200408-26.xml" source="GENTOO">GLSA-200408-26</ref>
      <ref url="http://secunia.com/advisories/18377" source="SECUNIA">18377</ref>
      <ref url="http://secunia.com/advisories/17054" source="SECUNIA">17054</ref>
      <ref url="http://secunia.com/advisories/11129" source="SECUNIA">11129</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000878" source="CONECTIVA">CLA-2004:878</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000865" source="CONECTIVA">CLA-2004:865</ref>
      <ref url="http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=252253" source="CONFIRM">http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=252253</ref>
      <ref url="ftp://ftp.sco.com/pub/updates/UnixWare/SCOSA-2004.17/SCOSA-2004.17.txt" source="SCO">SCOSA-2004.17</ref>
      <ref url="ftp://ftp.sco.com/pub/updates/OpenServer/SCOSA-2006.6/SCOSA-2006.6.txt" source="SCO">SCOSA-2006.6</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2004:090" source="MANDRAKE">MDKSA-2004:090</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gnu" name="zlib">
        <vers num="1.2.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0798" published="2004-10-20" name="CVE-2004-0798" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in the _maincfgret.cgi script for Ipswitch WhatsUp Gold before 8.03 Hotfix 1 allows remote attackers to execute arbitrary code via a long instancename parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/17111" source="XF" patch="1" adv="1">whatsup-maincfgret-bo(17111)</ref>
      <ref url="http://www.ipswitch.com/Support/WhatsUp/patch-upgrades.html" source="MISC">http://www.ipswitch.com/Support/WhatsUp/patch-upgrades.html</ref>
      <ref url="http://www.idefense.com/application/poi/display?type=vulnerabilities" source="IDEFENSE">20040825 Ipswitch WhatsUp Gold Remote Buffer Overflow Vulnerability</ref>
      <ref url="http://www.securityfocus.com/bid/11043" source="BID">11043</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ipswitch" name="whatsup_gold">
        <vers num="7.0" />
        <vers num="7.03" />
        <vers num="7.04" />
        <vers num="8.0" />
        <vers num="8.01" />
        <vers num="8.03" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0799" published="2004-10-20" name="CVE-2004-0799" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The HTTP daemon in Ipswitch WhatsUp Gold 8.03 and 8.03 Hotfix 1 allows remote attackers to cause a denial of service (server crash) via a GET request containing an MS-DOS device name, as demonstrated using "prn.htm".</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.ipswitch.com/Support/WhatsUp/patch-upgrades.html" source="CONFIRM" patch="1">http://www.ipswitch.com/Support/WhatsUp/patch-upgrades.html</ref>
      <ref url="http://www.idefense.com/application/poi/display?id=142&amp;type=vulnerabilities" source="IDEFENSE" patch="1" adv="1">20040916 Ipswitch WhatsUp Gold Remote Denial of Service Vulnerability</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/17418" source="XF">whatsup-get-prn-dos(17418)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ipswitch" name="whatsup_gold">
        <vers num="7.0" />
        <vers num="7.03" />
        <vers num="7.04" />
        <vers num="8.0" />
        <vers num="8.01" />
        <vers num="8.03" />
        <vers num="8.03_hotfix_1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0800" published="2004-08-24" name="CVE-2004-0800" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Format string vulnerability in CDE Mailer (dtmail) on Solaris 8 and 9 allows local users to gain privileges via format strings in the argv[0] value.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/928598" source="CERT-VN" patch="1" adv="1">VU#928598</ref>
      <ref url="http://www.idefense.com/application/poi/display?id=132&amp;type=vulnerabilities" source="IDEFENSE" patch="1" adv="1">20040824 CDE Mailer argv[0] Format String Vulnerability</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/17095" source="XF">dtmail-argv-format-string(17095)</ref>
      <ref url="http://www.securityfocus.com/bid/11027" source="BID">11027</ref>
      <ref url="http://www.ciac.org/ciac/bulletins/o-202.shtml" source="CIAC">O-202</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:4030" source="OVAL" sig="1">oval:org.mitre.oval:def:4030</ref>
    </refs>
    <vuln_soft>
      <prod vendor="avaya" name="call_management_system_server">
        <vers num="11.0" />
        <vers num="12.0" />
        <vers num="9.0" />
      </prod>
      <prod vendor="sun" name="dtmail">
        <vers num="" />
      </prod>
      <prod vendor="sun" name="solaris">
        <vers num="8.0" edition="" />
        <vers num="8.0" edition=":x86" />
        <vers num="9.0" edition="" />
        <vers num="9.0" edition=":sparc" />
        <vers num="9.0" edition=":x86" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0801" published="2004-09-16" name="CVE-2004-0801" modified="2010-05-25" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Unknown vulnerability in foomatic-rip in Foomatic before 3.0.2 allows local users or remote attackers with access to CUPS to execute arbitrary commands.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/17388" source="XF" patch="1" adv="1">foomatic-command-execution(17388)</ref>
      <ref url="http://www.trustix.net/errata/2004/0047/" source="TRUSTIX" patch="1" adv="1">2004-0047</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2004_31_cups.html" source="SUSE" patch="1" adv="1">SUSE-SA:2004:031</ref>
      <ref url="http://secunia.com/advisories/12557/" source="SECUNIA" patch="1" adv="1">12557</ref>
      <ref url="ftp://ftp.sco.com/pub/updates/UnixWare/SCOSA-2005.12/SCOSA-2005.12.txt" source="SCO" patch="1" adv="1">SCOSA-2005.12</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-77-1000757.1-1" source="SUNALERT">1000757</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-66-201005-1" source="SUNALERT">201005</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000880" source="CONECTIVA" adv="1">CLA-2004:880</ref>
      <ref url="http://www.securityfocus.com/bid/11184" source="BID">11184</ref>
      <ref url="http://secunia.com/advisories/20312" source="SECUNIA">20312</ref>
      <ref url="http://lists.suse.com/archive/suse-security-announce/2006-May/0007.html" source="SUSE">SUSE-SA:2006:026</ref>
    </refs>
    <vuln_soft>
      <prod vendor="linuxprinting.org" name="foomatic-filters">
        <vers num="3.0" />
        <vers num="3.0.1" />
        <vers num="3.0.2" />
        <vers num="3.1" />
      </prod>
      <prod vendor="sun" name="java_desktop_system">
        <vers num="2.0" />
        <vers num="2003" />
      </prod>
      <prod vendor="conectiva" name="linux">
        <vers num="10.0" />
        <vers num="9.0" />
      </prod>
      <prod vendor="trustix" name="secure_linux">
        <vers num="2.0" />
        <vers num="2.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0802" published="2004-12-31" name="CVE-2004-0802" modified="2010-01-28" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_score="5.1" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="4.9" CVSS_base_score="5.1">
    <desc>
      <descript source="cve">Buffer overflow in the BMP loader in imlib2 before 1.1.2 allows remote attackers to execute arbitrary code via a specially-crafted BMP image, a different vulnerability than CVE-2004-0817.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/17183" source="XF" patch="1">imlib2-bmp-bo(17183)</ref>
      <ref url="http://www.securityfocus.com/bid/11084" source="BID" patch="1">11084</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200409-12.xml" source="GENTOO" patch="1" adv="1">GLSA-200409-12</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000870" source="CONECTIVA" patch="1">CLA-2004:870</ref>
      <ref url="http://www.vuxml.org/freebsd/ba005226-fb5b-11d8-9837-000c41e2cdad.html" source="CONFIRM" adv="1">http://www.vuxml.org/freebsd/ba005226-fb5b-11d8-9837-000c41e2cdad.html</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-66-201611-1" source="SUNALERT">201611</ref>
      <ref url="http://cvs.sourceforge.net/viewcvs.py/enlightenment/e17/libs/imlib2/ChangeLog?rev=1.20&amp;view=markup" source="MISC">http://cvs.sourceforge.net/viewcvs.py/enlightenment/e17/libs/imlib2/ChangeLog?rev=1.20&amp;view=markup</ref>
    </refs>
    <vuln_soft>
      <prod vendor="enlightenment" name="imlib">
        <vers num="1.9" />
        <vers num="1.9.1" />
        <vers num="1.9.10" />
        <vers num="1.9.11" />
        <vers num="1.9.12" />
        <vers num="1.9.13" />
        <vers num="1.9.14" />
        <vers num="1.9.2" />
        <vers num="1.9.3" />
        <vers num="1.9.4" />
        <vers num="1.9.5" />
        <vers num="1.9.6" />
        <vers num="1.9.7" />
        <vers num="1.9.8" />
        <vers num="1.9.9" />
      </prod>
      <prod vendor="enlightenment" name="imlib2">
        <vers num="1.0" />
        <vers num="1.0.1" />
        <vers num="1.0.2" />
        <vers num="1.0.3" />
        <vers num="1.0.4" />
        <vers num="1.0.5" />
        <vers num="1.1" />
        <vers num="1.1.1" />
      </prod>
      <prod vendor="imagemagick" name="imagemagick">
        <vers num="5.3.3" />
        <vers num="5.4.3" />
        <vers num="5.4.4.5" />
        <vers num="5.4.7" />
        <vers num="5.4.8" />
        <vers num="5.4.8.2.1.1.0" />
        <vers num="5.5.3.2.1.2.0" />
        <vers num="5.5.6.0_2003-04-09" />
        <vers num="5.5.7" />
        <vers num="6.0.2" />
      </prod>
      <prod vendor="sun" name="java_desktop_system">
        <vers num="2.0" />
        <vers num="2003" />
      </prod>
      <prod vendor="conectiva" name="linux">
        <vers num="10.0" />
        <vers num="9.0" />
      </prod>
      <prod vendor="mandrakesoft" name="mandrake_linux">
        <vers num="10.0" edition="" />
        <vers num="10.0" edition=":amd64" />
        <vers num="9.2" edition="" />
        <vers num="9.2" edition=":amd64" />
      </prod>
      <prod vendor="mandrakesoft" name="mandrake_linux_corporate_server">
        <vers num="2.1" edition="" />
        <vers num="2.1" edition=":x86_64" />
      </prod>
      <prod vendor="redhat" name="enterprise_linux">
        <vers num="2.1" edition="" />
        <vers num="2.1" edition=":workstation_ia64" />
        <vers num="2.1" edition=":advanced_server" />
        <vers num="2.1" edition=":enterprise_server" />
        <vers num="2.1" edition=":advanced_server_ia64" />
        <vers num="2.1" edition=":enterprise_server_ia64" />
        <vers num="2.1" edition=":workstation" />
        <vers num="3.0" edition="" />
        <vers num="3.0" edition=":enterprise_server" />
        <vers num="3.0" edition=":workstation" />
        <vers num="3.0" edition=":advanced_servers" />
      </prod>
      <prod vendor="redhat" name="enterprise_linux_desktop">
        <vers num="3.0" />
      </prod>
      <prod vendor="redhat" name="fedora_core">
        <vers num="core_1.0" />
        <vers num="core_2.0" />
        <vers num="core_3.0" />
      </prod>
      <prod vendor="redhat" name="linux_advanced_workstation">
        <vers num="2.1" edition="" />
        <vers num="2.1" edition=":itanium_processor" />
        <vers num="2.1" edition=":ia64" />
      </prod>
      <prod vendor="suse" name="suse_linux">
        <vers num="8.0" edition="" />
        <vers num="8.0" edition=":i386" />
        <vers num="8.1" />
        <vers num="8.2" />
        <vers num="9.0" edition="" />
        <vers num="9.0" edition=":x86_64" />
        <vers num="9.1" />
        <vers num="9.2" />
      </prod>
      <prod vendor="turbolinux" name="turbolinux_desktop">
        <vers num="10.0" />
      </prod>
      <prod vendor="turbolinux" name="turbolinux_server">
        <vers num="7.0" />
        <vers num="8.0" />
      </prod>
      <prod vendor="turbolinux" name="turbolinux_workstation">
        <vers num="7.0" />
        <vers num="8.0" />
      </prod>
      <prod vendor="ubuntu" name="ubuntu_linux">
        <vers num="4.1" edition="" />
        <vers num="4.1" edition=":ia64" />
        <vers num="4.1" edition=":ppc" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0803" published="2004-12-23" name="CVE-2004-0803" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple vulnerabilities in the RLE (run length encoding) decoders for libtiff 3.6.1 and earlier, related to buffer overflows and integer overflows, allow remote attackers to execute arbitrary code via TIFF files.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/948752" source="CERT-VN" adv="1">VU#948752</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/17703" source="XF" patch="1" adv="1">libtiff-library-decoding-bo(17703)</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-577.html" source="REDHAT" patch="1" adv="1">RHSA-2004:577</ref>
      <ref url="http://www.debian.org/security/2004/dsa-567" source="DEBIAN" patch="1" adv="1">DSA-567</ref>
      <ref url="http://www.securityfocus.com/bid/11406" source="BID">11406</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-354.html" source="REDHAT">RHSA-2005:354</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-021.html" source="REDHAT">RHSA-2005:021</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2004_38_libtiff.html" source="SUSE">SUSE-SA:2004:038</ref>
      <ref url="http://www.kde.org/info/security/advisory-20041209-2.txt" source="CONFIRM">http://www.kde.org/info/security/advisory-20041209-2.txt</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200410-11.xml" source="GENTOO">GLSA-200410-11</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-66-201072-1" source="SUNALERT">201072</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-101677-1" source="SUNALERT">101677</ref>
      <ref url="http://secunia.com/advisories/12818" source="SECUNIA">12818</ref>
      <ref url="http://scary.beasts.org/security/CESA-2004-006.txt" source="MISC">http://scary.beasts.org/security/CESA-2004-006.txt</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:8896" source="OVAL">oval:org.mitre.oval:def:8896</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109778785107450&amp;w=2" source="BUGTRAQ">20041013 CESA-2004-006: libtiff</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/index.php?id=a&amp;anuncio=000888" source="CONECTIVA">CLA-2004:888</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:052" source="MANDRAKE">MDKSA-2005:052</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2004:109" source="MANDRAKE">MDKSA-2004:109</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:100114" source="OVAL" sig="1">oval:org.mitre.oval:def:100114</ref>
    </refs>
    <vuln_soft>
      <prod vendor="libtiff" name="libtiff">
        <vers num="3.4" />
        <vers num="3.5.1" />
        <vers num="3.5.2" />
        <vers num="3.5.3" />
        <vers num="3.5.4" />
        <vers num="3.5.5" />
        <vers num="3.5.7" />
        <vers num="3.6.0" />
        <vers num="3.6.1" />
      </prod>
      <prod vendor="pdflib" name="pdf_library">
        <vers num="5.0.2" />
      </prod>
      <prod vendor="wxgtk2" name="wxgtk2">
        <vers num="2.5_.0" />
      </prod>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.2" />
        <vers num="10.2.1" />
        <vers num="10.2.2" />
        <vers num="10.2.3" />
        <vers num="10.2.4" />
        <vers num="10.2.5" />
        <vers num="10.2.6" />
        <vers num="10.2.7" />
        <vers num="10.2.8" />
        <vers num="10.3" />
        <vers num="10.3.1" />
        <vers num="10.3.2" />
        <vers num="10.3.3" />
        <vers num="10.3.4" />
        <vers num="10.3.5" />
        <vers num="10.3.6" />
      </prod>
      <prod vendor="apple" name="mac_os_x_server">
        <vers num="10.2" />
        <vers num="10.2.1" />
        <vers num="10.2.2" />
        <vers num="10.2.3" />
        <vers num="10.2.4" />
        <vers num="10.2.5" />
        <vers num="10.2.6" />
        <vers num="10.2.7" />
        <vers num="10.2.8" />
        <vers num="10.3" />
        <vers num="10.3.1" />
        <vers num="10.3.2" />
        <vers num="10.3.3" />
        <vers num="10.3.4" />
        <vers num="10.3.5" />
        <vers num="10.3.6" />
      </prod>
      <prod vendor="kde" name="kde">
        <vers num="3.2" />
        <vers num="3.2.1" />
        <vers num="3.2.2" />
        <vers num="3.2.3" />
        <vers num="3.3" />
        <vers num="3.3.1" />
      </prod>
      <prod vendor="mandrakesoft" name="mandrake_linux">
        <vers num="10.0" edition="" />
        <vers num="10.0" edition=":amd64" />
      </prod>
      <prod vendor="redhat" name="enterprise_linux">
        <vers num="2.1" edition="" />
        <vers num="2.1" edition=":workstation_ia64" />
        <vers num="2.1" edition=":advanced_server" />
        <vers num="2.1" edition=":enterprise_server" />
        <vers num="2.1" edition=":advanced_server_ia64" />
        <vers num="2.1" edition=":enterprise_server_ia64" />
        <vers num="2.1" edition=":workstation" />
        <vers num="3.0" edition="" />
        <vers num="3.0" edition=":enterprise_server" />
        <vers num="3.0" edition=":workstation" />
        <vers num="3.0" edition=":advanced_servers" />
      </prod>
      <prod vendor="redhat" name="enterprise_linux_desktop">
        <vers num="3.0" />
      </prod>
      <prod vendor="redhat" name="fedora_core">
        <vers num="core_2.0" />
      </prod>
      <prod vendor="redhat" name="linux_advanced_workstation">
        <vers num="2.1" edition="" />
        <vers num="2.1" edition=":itanium_processor" />
        <vers num="2.1" edition=":ia64" />
      </prod>
      <prod vendor="suse" name="suse_linux">
        <vers num="1.0" edition="" />
        <vers num="1.0" edition=":desktop" />
        <vers num="8" edition="" />
        <vers num="8" edition=":enterprise_server" />
        <vers num="8.1" />
        <vers num="8.2" />
        <vers num="9.0" edition="" />
        <vers num="9.0" edition=":enterprise_server" />
        <vers num="9.1" />
      </prod>
      <prod vendor="trustix" name="secure_linux">
        <vers num="1.5" />
        <vers num="2.0" />
        <vers num="2.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0804" published="2004-11-03" name="CVE-2004-0804" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Vulnerability in tif_dirread.c for libtiff allows remote attackers to cause a denial of service (application crash) via a TIFF image that causes a divide-by-zero error when the number of row bytes is zero, a different vulnerability than CVE-2005-2452.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/555304" source="CERT-VN">VU#555304</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/17755" source="XF" patch="1" adv="1">libtiff-dos(17755)</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-577.html" source="REDHAT" patch="1" adv="1">RHSA-2004:577</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-354.html" source="REDHAT">RHSA-2005:354</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2004_38_libtiff.html" source="SUSE">SUSE-SA:2004:038</ref>
      <ref url="http://www.kde.org/info/security/advisory-20041209-2.txt" source="CONFIRM">http://www.kde.org/info/security/advisory-20041209-2.txt</ref>
      <ref url="http://www.debian.org/security/2004/dsa-567" source="DEBIAN" adv="1">DSA-567</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-66-201072-1" source="SUNALERT">201072</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11711" source="OVAL">oval:org.mitre.oval:def:11711</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/index.php?id=a&amp;anuncio=000888" source="CONECTIVA">CLA-2004:888</ref>
      <ref url="http://bugzilla.remotesensing.org/show_bug.cgi?id=111" source="MISC">http://bugzilla.remotesensing.org/show_bug.cgi?id=111</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-021.html" source="REDHAT">RHSA-2005:021</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:052" source="MANDRAKE">MDKSA-2005:052</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2004:109" source="MANDRAKE">MDKSA-2004:109</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-101677-1" source="SUNALERT">101677</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:100115" source="OVAL" sig="1">oval:org.mitre.oval:def:100115</ref>
    </refs>
    <vuln_soft>
      <prod vendor="libtiff" name="libtiff">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0805" published="2004-12-23" name="CVE-2004-0805" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in layer2.c in mpg123 0.59r and possibly mpg123 0.59s allows remote attackers to execute arbitrary code via a certain (1) mp3 or (2) mp2 file.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/17287" source="XF" patch="1" adv="1">mpg123-layer2c-bo(17287)</ref>
      <ref url="http://www.debian.org/security/2004/dsa-564" source="DEBIAN" patch="1" adv="1">DSA-564</ref>
      <ref url="http://www.securityfocus.com/bid/" source="BID">11121</ref>
      <ref url="http://www.securityfocus.com/archive/1/374433" source="BUGTRAQ">20040916 mpg123 buffer overflow vulnerability</ref>
      <ref url="http://www.mandrakesecure.net/en/advisories/advisory.php?name=MDKSA-2004:100" source="MANDRAKE">MDKSA-2004:100</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200409-20.xml" source="GENTOO">GLSA-200409-20</ref>
      <ref url="http://www.alighieri.org/advisories/advisory-mpg123.txt" source="MISC">http://www.alighieri.org/advisories/advisory-mpg123.txt</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2004-September/026151.html" source="FULLDISC">20040907 mpg123 buffer overflow vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mpg123" name="mpg123">
        <vers num="0.59r" />
        <vers num="0.59s" />
      </prod>
      <prod vendor="mandrakesoft" name="mandrake_linux">
        <vers num="10.0" edition="" />
        <vers num="10.0" edition=":amd64" />
        <vers num="9.2" edition="" />
        <vers num="9.2" edition=":amd64" />
      </prod>
      <prod vendor="mandrakesoft" name="mandrake_linux_corporate_server">
        <vers num="2.1" edition="" />
        <vers num="2.1" edition=":x86_64" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0806" published="2004-12-31" name="CVE-2004-0806" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">cdrecord in the cdrtools package before 2.01, when installed setuid root, does not properly drop privileges before executing a program specified in the RSH environment variable, which allows local users to gain privileges.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/700326" source="CERT-VN" adv="1">VU#700326</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/17303" source="XF" patch="1">cdrecord-rsh-gain-privileges(17303)</ref>
      <ref url="http://www.securityfocus.org/bid/11075" source="BID" patch="1">11075</ref>
      <ref url="https://bugzilla.fedora.us/show_bug.cgi?id=2058" source="FEDORA" adv="1">FLSA:2058</ref>
      <ref url="http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2004-09/0108.html" source="BUGTRAQ">20040910 CAU-EX-2004-0002: cdrecord-suidshell.sh</ref>
      <ref url="http://securitytracker.com/id?1011091" source="SECTRACK">1011091</ref>
      <ref url="http://secunia.com/advisories/12481/" source="SECUNIA" adv="1">12481</ref>
      <ref url="http://seclists.org/lists/bugtraq/2004/Sep/0097.html" source="BUGTRAQ">20040909 Bugtraq: cdrecord local root exploit</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9805" source="OVAL">oval:org.mitre.oval:def:9805</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2004:091" source="MANDRAKE">MDKSA-2004:091</ref>
      <ref url="http://secunia.com/advisories/19532" source="SECUNIA">19532</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/20060401-01-U" source="SGI">20060401-01-U</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cdrtools" name="cdrecord">
        <vers num="1.11" />
        <vers num="2.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0807" published="2004-09-13" name="CVE-2004-0807" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Samba 3.0.6 and earlier allows remote attackers to cause a denial of service (infinite loop and memory exhaustion) via certain malformed requests that cause new processes to be spawned and enter an infinite loop.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.trustix.net/errata/2004/0046/" source="TRUSTIX" patch="1" adv="1">2004-0046</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-467.html" source="REDHAT" patch="1" adv="1">RHSA-2004:467</ref>
      <ref url="http://www.idefense.com/application/poi/display?id=139&amp;type=vulnerabilities" source="IDEFENSE" patch="1" adv="1">20040913 Samba 3.x SMBD Remote Denial of Service Vulnerability</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200409-16.xml" source="GENTOO" patch="1" adv="1">GLSA-200409-16</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109526231623307&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20040915 [OpenPKG-SA-2004.040] OpenPKG Security Advisory (samba)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109509335230495&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20040913 Samba 3.0 DoS Vulberabilities (CAN-2004-0807 &amp; CAN-2004-0808)</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000873" source="CONECTIVA" patch="1" adv="1">CLA-2004:873</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11141" source="OVAL">oval:org.mitre.oval:def:11141</ref>
    </refs>
    <vuln_soft>
      <prod vendor="samba" name="samba">
        <vers num="3.0.0" />
        <vers num="3.0.1" />
        <vers num="3.0.2" />
        <vers num="3.0.2a" />
        <vers num="3.0.3" />
        <vers num="3.0.4" edition="rc1" />
        <vers num="3.0.5" />
        <vers num="3.0.6" />
      </prod>
      <prod vendor="sgi" name="samba">
        <vers num="3.0" edition="" />
        <vers num="3.0" edition=":irix" />
        <vers num="3.0.1" edition="" />
        <vers num="3.0.1" edition=":irix" />
        <vers num="3.0.2" edition="" />
        <vers num="3.0.2" edition=":irix" />
        <vers num="3.0.3" edition="" />
        <vers num="3.0.3" edition=":irix" />
        <vers num="3.0.4" edition="" />
        <vers num="3.0.4" edition=":irix" />
        <vers num="3.0.5" edition="" />
        <vers num="3.0.5" edition=":irix" />
        <vers num="3.0.6" edition="" />
        <vers num="3.0.6" edition=":irix" />
      </prod>
      <prod vendor="conectiva" name="linux">
        <vers num="10.0" />
        <vers num="9.0" />
      </prod>
      <prod vendor="mandrakesoft" name="mandrake_linux">
        <vers num="10.0" edition="" />
        <vers num="10.0" edition=":amd64" />
      </prod>
      <prod vendor="suse" name="suse_linux">
        <vers num="8" edition="" />
        <vers num="8" edition=":enterprise_server" />
        <vers num="8.1" />
        <vers num="8.2" />
        <vers num="9.0" edition="" />
        <vers num="9.0" edition=":enterprise_server" />
        <vers num="9.0" edition=":x86_64" />
        <vers num="9.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0808" published="2004-12-31" name="CVE-2004-0808" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The process_logon_packet function in the nmbd server for Samba 3.0.6 and earlier, when domain logons are enabled, allows remote attackers to cause a denial of service via a SAM_UAS_CHANGE request with a length value that is larger than the number of structures that are provided.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.trustix.net/errata/2004/0046/" source="TRUSTIX" patch="1" adv="1">2004-0046</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-467.html" source="REDHAT" patch="1" adv="1">RHSA-2004:467</ref>
      <ref url="http://www.idefense.com/application/poi/display?id=138&amp;type=vulnerabilities" source="IDEFENSE" patch="1" adv="1">20040913 Samba nmbd Invalid Length Denial of Service Vulnerability</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200409-16.xml" source="GENTOO" patch="1" adv="1">GLSA-200409-16</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109526231623307&amp;w=2" source="BUGTRAQ" patch="1">20040915 [OpenPKG-SA-2004.040] OpenPKG Security Advisory (samba)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109509335230495&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20040913 Samba 3.0 DoS Vulberabilities (CAN-2004-0807 &amp; CAN-2004-0808)</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000873" source="CONECTIVA" patch="1">CLA-2004:873</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10344" source="OVAL">oval:org.mitre.oval:def:10344</ref>
    </refs>
    <vuln_soft>
      <prod vendor="samba" name="samba">
        <vers num="3.0" />
        <vers num="3.0.0" />
        <vers num="3.0.1" />
        <vers num="3.0.2" />
        <vers num="3.0.2a" />
        <vers num="3.0.3" />
        <vers num="3.0.4" edition="rc1" />
        <vers num="3.0.5" />
        <vers num="3.0.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0809" published="2004-09-16" name="CVE-2004-0809" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The mod_dav module in Apache 2.0.50 and earlier allows remote attackers to cause a denial of service (child process crash) via a certain sequence of LOCK requests for a location that allows WebDAV authoring access.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/17366" source="XF" patch="1" adv="1">apache-moddav-lock-dos(17366)</ref>
      <ref url="http://www.trustix.org/errata/2004/0047/" source="TRUSTIX" patch="1" adv="1">2004-0047</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200409-21.xml" source="GENTOO" patch="1" adv="1">GLSA-200409-21</ref>
      <ref url="http://www.debian.org/security/2004/dsa-558" source="DEBIAN" patch="1" adv="1">DSA-558</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-463.html" source="REDHAT" adv="1">RHSA-2004:463</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9588" source="OVAL">oval:org.mitre.oval:def:9588</ref>
      <ref url="http://cvs.apache.org/viewcvs.cgi/httpd-2.0/modules/dav/fs/lock.c?r1=1.32&amp;r2=1.33" source="CONFIRM">http://cvs.apache.org/viewcvs.cgi/httpd-2.0/modules/dav/fs/lock.c?r1=1.32&amp;r2=1.33</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apache" name="http_server">
        <vers num="2.0.47" />
        <vers num="2.0.50" />
      </prod>
      <prod vendor="hp" name="secure_web_server_for_tru64">
        <vers num="4.0_f" />
        <vers num="4.0_g" />
        <vers num="5.0_a" />
        <vers num="5.1" />
        <vers num="5.1_a" />
        <vers num="5.8.1" />
        <vers num="5.8.2" />
        <vers num="5.9.1" />
        <vers num="5.9.2" />
        <vers num="6.3.0" />
      </prod>
      <prod vendor="conectiva" name="linux">
        <vers num="10.0" />
        <vers num="9.0" />
      </prod>
      <prod vendor="gentoo" name="linux">
        <vers num="1.4" />
      </prod>
      <prod vendor="hp" name="hp-ux">
        <vers num="11.00" />
        <vers num="11.11" />
        <vers num="11.22" />
        <vers num="11.23" edition="" />
        <vers num="11.23" edition=":ia64_64-bit" />
      </prod>
      <prod vendor="mandrakesoft" name="mandrake_linux">
        <vers num="10.0" edition="" />
        <vers num="10.0" edition=":amd64" />
        <vers num="9.2" edition="" />
        <vers num="9.2" edition=":amd64" />
      </prod>
      <prod vendor="redhat" name="enterprise_linux">
        <vers num="3.0" edition="" />
        <vers num="3.0" edition=":advanced_server" />
        <vers num="3.0" edition=":workstation_server" />
        <vers num="3.0" edition=":enterprise_server" />
      </prod>
      <prod vendor="redhat" name="enterprise_linux_desktop">
        <vers num="3.0" />
      </prod>
      <prod vendor="trustix" name="secure_linux">
        <vers num="2.0" />
        <vers num="2.1" />
      </prod>
      <prod vendor="turbolinux" name="turbolinux_desktop">
        <vers num="10.0" />
      </prod>
      <prod vendor="turbolinux" name="turbolinux_home">
        <vers num="" />
      </prod>
      <prod vendor="turbolinux" name="turbolinux_server">
        <vers num="10.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0810" published="2004-12-23" name="CVE-2004-0810" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Buffer overflow in Netopia Timbuktu 7.0.3 allows remote attackers to cause a denial of service (server process crash) via a certain data string that is sent to multiple simultaneous client connections to TCP port 407.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/18172" source="XF" adv="1">timbuktu-multiple-connections-dos(18172)</ref>
      <ref url="http://www.uniras.gov.uk/vuls/2004/190204/index.htm" source="MISC">http://www.uniras.gov.uk/vuls/2004/190204/index.htm</ref>
      <ref url="http://www.securityfocus.com/bid/11714" source="BID" adv="1">11714</ref>
      <ref url="http://www.corsaire.com/advisories/c040720-001.txt" source="MISC">http://www.corsaire.com/advisories/c040720-001.txt</ref>
      <ref url="http://secunia.com/advisories/13250/" source="SECUNIA">13250</ref>
      <ref url="http://msgs.securepoint.com/cgi-bin/get/bugtraq0411/218.html" source="BUGTRAQ" adv="1">20041119 Corsaire Security Advisory - Netopia Timbuktu remote buffer overflow issue</ref>
    </refs>
    <vuln_soft>
      <prod vendor="netopia" name="timbuktu_pro_mac">
        <vers num="6.0.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0811" published="2004-12-31" name="CVE-2004-0811" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Unknown vulnerability in Apache 2.0.51 prevents "the merging of the Satisfy directive," which could allow attackers to obtain access to restricted resources contrary to the specified authentication configuration.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <other />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/17473" source="XF" patch="1">apache-satisfy-gain-access(17473)</ref>
      <ref url="http://www.apache.org/dist/httpd/patches/apply_to_2.0.51/CAN-2004-0811.patch" source="CONFIRM" patch="1">http://www.apache.org/dist/httpd/patches/apply_to_2.0.51/CAN-2004-0811.patch</ref>
      <ref url="http://www.apacheweek.com/features/security-20" source="CONFIRM">http://www.apacheweek.com/features/security-20</ref>
      <ref url="http://www.trustix.org/errata/2004/0049" source="TRUSTIX">2004-0049</ref>
      <ref url="http://www.securityfocus.com/bid/11239" source="BID">11239</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200409-33.xml" source="GENTOO">GLSA-200409-33</ref>
      <ref url="http://fedoranews.org/updates/FEDORA-2004-313.shtml" source="FEDORA">FEDORA-2004-313</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apache" name="http_server">
        <vers num="2.0.51" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2004-0812" published="2005-04-14" name="CVE-2004-0812" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">Unknown vulnerability in the Linux kernel before 2.4.23, on the AMD AMD64 and Intel EM64T architectures, associated with "setting up TSS limits," allows local users to cause a denial of service (crash) and possibly execute arbitrary code.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <other />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/11794" source="BID" patch="1" adv="1">11794</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-549.html" source="REDHAT" patch="1" adv="1">RHSA-2004:549</ref>
      <ref url="http://www.ciac.org/ciac/bulletins/p-047.shtml" source="CIAC" patch="1" adv="1">P-047</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/18346" source="XF">linux-tss-gain-privilege(18346)</ref>
      <ref url="http://secunia.com/advisories/13359" source="SECUNIA">13359</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11375" source="OVAL">oval:org.mitre.oval:def:11375</ref>
      <ref url="http://linux.bkbits.net:8080/linux-2.6/cset@3fad673ber4GuU7iWppydzNIyLntEQ" source="CONFIRM">http://linux.bkbits.net:8080/linux-2.6/cset@3fad673ber4GuU7iWppydzNIyLntEQ</ref>
    </refs>
    <vuln_soft>
      <prod vendor="linux" name="linux_kernel">
        <vers num="2.4.0" edition="test1" />
        <vers num="2.4.0" edition="test10" />
        <vers num="2.4.0" edition="test11" />
        <vers num="2.4.0" edition="test12" />
        <vers num="2.4.0" edition="test2" />
        <vers num="2.4.0" edition="test3" />
        <vers num="2.4.0" edition="test4" />
        <vers num="2.4.0" edition="test5" />
        <vers num="2.4.0" edition="test6" />
        <vers num="2.4.0" edition="test7" />
        <vers num="2.4.0" edition="test8" />
        <vers num="2.4.0" edition="test9" />
        <vers num="2.4.1" />
        <vers num="2.4.10" />
        <vers num="2.4.11" />
        <vers num="2.4.12" />
        <vers num="2.4.13" />
        <vers num="2.4.14" />
        <vers num="2.4.15" />
        <vers num="2.4.16" />
        <vers num="2.4.17" />
        <vers num="2.4.18" edition="" />
        <vers num="2.4.18" edition=":x86" />
        <vers num="2.4.18" edition="pre1" />
        <vers num="2.4.18" edition="pre2" />
        <vers num="2.4.18" edition="pre3" />
        <vers num="2.4.18" edition="pre4" />
        <vers num="2.4.18" edition="pre5" />
        <vers num="2.4.18" edition="pre6" />
        <vers num="2.4.18" edition="pre7" />
        <vers num="2.4.18" edition="pre8" />
        <vers num="2.4.19" edition="pre1" />
        <vers num="2.4.19" edition="pre2" />
        <vers num="2.4.19" edition="pre3" />
        <vers num="2.4.19" edition="pre4" />
        <vers num="2.4.19" edition="pre5" />
        <vers num="2.4.19" edition="pre6" />
        <vers num="2.4.2" />
        <vers num="2.4.20" />
        <vers num="2.4.21" edition="pre1" />
        <vers num="2.4.21" edition="pre4" />
        <vers num="2.4.21" edition="pre7" />
        <vers num="2.4.22" />
        <vers num="2.4.3" />
        <vers num="2.4.4" />
        <vers num="2.4.5" />
        <vers num="2.4.6" />
        <vers num="2.4.7" />
        <vers num="2.4.8" />
        <vers num="2.4.9" />
      </prod>
      <prod vendor="redhat" name="enterprise_linux">
        <vers num="3.0" edition="" />
        <vers num="3.0" edition=":enterprise_server" />
        <vers num="3.0" edition=":workstation" />
        <vers num="3.0" edition=":advanced_servers" />
      </prod>
      <prod vendor="redhat" name="enterprise_linux_desktop">
        <vers num="3.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2004-0813" published="2004-12-31" name="CVE-2004-0813" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">Unknown vulnerability in the SG_IO functionality in ide-cd allows local users to bypass read-only access and perform unauthorized write and erase operations.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/17505" source="XF">linux-sgio-gain-privileges(17505)</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/3229" source="VUPEN">ADV-2007-3229</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10011" source="OVAL">oval:org.mitre.oval:def:10011</ref>
      <ref url="http://lkml.org/lkml/2004/7/30/147" source="MISC">http://lkml.org/lkml/2004/7/30/147</ref>
      <ref url="http://www.securityfocus.com/bid/25749" source="BID">25749</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2007-0465.html" source="REDHAT">RHSA-2007:0465</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200711-23.xml" source="GENTOO">GLSA-200711-23</ref>
      <ref url="http://secunia.com/advisories/27706" source="SECUNIA">27706</ref>
      <ref url="http://secunia.com/advisories/26909" source="SECUNIA">26909</ref>
      <ref url="http://secunia.com/advisories/25894" source="SECUNIA">25894</ref>
      <ref url="http://secunia.com/advisories/25631" source="SECUNIA">25631</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2007-September/065902.html" source="FULLDISC">20070920 VMSA-2007-0006 Critical security updates for all supported versions of VMware ESX Server, VMware Server, VMware Workstation, VMware ACE, and VMware Player</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/20070602-01-P.asc" source="SGI">20070602-01-P</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ide-cd" name="ide-cd">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2004-0814" published="2004-12-23" name="CVE-2004-0814" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:H/Au:N/C:N/I:N/A:P)" CVSS_score="1.2" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="1.9" CVSS_base_score="1.2">
    <desc>
      <descript source="cve">Multiple race conditions in the terminal layer in Linux 2.4.x, and 2.6.x before 2.6.9, allow (1) local users to obtain portions of kernel data via a TIOCSETD ioctl call to a terminal interface that is being accessed by another thread, or (2) remote attackers to cause a denial of service (panic) by switching from console to PPP line discipline, then quickly sending data that is received during the switch.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <race />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/17816" source="XF" patch="1" adv="1">linux-tiocsetd-race-condition(17816)</ref>
      <ref url="http://www.securityfocus.com/bid/11492" source="BID" patch="1" adv="1">11492</ref>
      <ref url="http://www.securityfocus.com/bid/11491" source="BID" patch="1" adv="1">11491</ref>
      <ref url="https://bugzilla.fedora.us/show_bug.cgi?id=2336" source="FEDORA">FLSA:2336</ref>
      <ref url="http://www.securityfocus.com/archive/1/379005" source="BUGTRAQ">20041020 CAN-2004-0814: Linux terminal layer races</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10728" source="OVAL">oval:org.mitre.oval:def:10728</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110306397320336&amp;w=2" source="BUGTRAQ" adv="1">20041214 [USN-38-1] Linux kernel vulnerabilities</ref>
      <ref url="http://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=133110" source="CONFIRM">http://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=133110</ref>
      <ref url="http://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=131672" source="CONFIRM">http://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=131672</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-293.html" source="REDHAT">RHSA-2005:293</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:022" source="MANDRAKE">MDKSA-2005:022</ref>
    </refs>
    <vuln_soft>
      <prod vendor="linux" name="linux_kernel">
        <vers num="2.2.0" />
        <vers num="2.2.1" />
        <vers num="2.2.10" />
        <vers num="2.2.11" />
        <vers num="2.2.12" />
        <vers num="2.2.13" />
        <vers num="2.2.14" />
        <vers num="2.2.15" edition="pre16" />
        <vers num="2.2.15_pre20" />
        <vers num="2.2.16" edition="pre6" />
        <vers num="2.2.17" />
        <vers num="2.2.18" />
        <vers num="2.2.19" />
        <vers num="2.2.2" />
        <vers num="2.2.20" />
        <vers num="2.2.21" />
        <vers num="2.2.22" />
        <vers num="2.2.23" />
        <vers num="2.2.24" />
        <vers num="2.2.25" />
        <vers num="2.2.3" />
        <vers num="2.2.7" />
        <vers num="2.2.8" />
        <vers num="2.2.9" />
        <vers num="2.4.0" edition="test1" />
        <vers num="2.4.0" edition="test10" />
        <vers num="2.4.0" edition="test11" />
        <vers num="2.4.0" edition="test12" />
        <vers num="2.4.0" edition="test2" />
        <vers num="2.4.0" edition="test3" />
        <vers num="2.4.0" edition="test4" />
        <vers num="2.4.0" edition="test5" />
        <vers num="2.4.0" edition="test6" />
        <vers num="2.4.0" edition="test7" />
        <vers num="2.4.0" edition="test8" />
        <vers num="2.4.0" edition="test9" />
        <vers num="2.4.1" />
        <vers num="2.4.10" />
        <vers num="2.4.11" />
        <vers num="2.4.12" />
        <vers num="2.4.13" />
        <vers num="2.4.14" />
        <vers num="2.4.15" />
        <vers num="2.4.16" />
        <vers num="2.4.17" />
        <vers num="2.4.18" edition="" />
        <vers num="2.4.18" edition=":x86" />
        <vers num="2.4.18" edition="pre1" />
        <vers num="2.4.18" edition="pre2" />
        <vers num="2.4.18" edition="pre3" />
        <vers num="2.4.18" edition="pre4" />
        <vers num="2.4.18" edition="pre5" />
        <vers num="2.4.18" edition="pre6" />
        <vers num="2.4.18" edition="pre7" />
        <vers num="2.4.18" edition="pre8" />
        <vers num="2.4.19" edition="pre1" />
        <vers num="2.4.19" edition="pre2" />
        <vers num="2.4.19" edition="pre3" />
        <vers num="2.4.19" edition="pre4" />
        <vers num="2.4.19" edition="pre5" />
        <vers num="2.4.19" edition="pre6" />
        <vers num="2.4.2" />
        <vers num="2.4.20" />
        <vers num="2.4.21" edition="pre1" />
        <vers num="2.4.21" edition="pre4" />
        <vers num="2.4.21" edition="pre7" />
        <vers num="2.4.22" />
        <vers num="2.4.23" edition="pre9" />
        <vers num="2.4.23_ow2" />
        <vers num="2.4.24" />
        <vers num="2.4.24_ow1" />
        <vers num="2.4.25" />
        <vers num="2.4.26" />
        <vers num="2.4.27" edition="pre1" />
        <vers num="2.4.27" edition="pre2" />
        <vers num="2.4.27" edition="pre3" />
        <vers num="2.4.27" edition="pre4" />
        <vers num="2.4.27" edition="pre5" />
        <vers num="2.4.3" />
        <vers num="2.4.4" />
        <vers num="2.4.5" />
        <vers num="2.4.6" />
        <vers num="2.4.7" />
        <vers num="2.4.8" />
        <vers num="2.4.9" />
        <vers num="2.6.0" edition="test1" />
        <vers num="2.6.0" edition="test10" />
        <vers num="2.6.0" edition="test11" />
        <vers num="2.6.0" edition="test2" />
        <vers num="2.6.0" edition="test3" />
        <vers num="2.6.0" edition="test4" />
        <vers num="2.6.0" edition="test5" />
        <vers num="2.6.0" edition="test6" />
        <vers num="2.6.0" edition="test7" />
        <vers num="2.6.0" edition="test8" />
        <vers num="2.6.0" edition="test9" />
        <vers num="2.6.1" edition="rc1" />
        <vers num="2.6.1" edition="rc2" />
        <vers num="2.6.2" />
        <vers num="2.6.3" />
        <vers num="2.6.4" />
        <vers num="2.6.5" />
        <vers num="2.6.6" edition="rc1" />
        <vers num="2.6.7" edition="rc1" />
        <vers num="2.6.8" edition="rc1" />
        <vers num="2.6.8" edition="rc2" />
        <vers num="2.6.8" edition="rc3" />
        <vers num="2.6_test9_cvs" />
      </prod>
      <prod vendor="ubuntu" name="ubuntu_linux">
        <vers num="4.1" edition="" />
        <vers num="4.1" edition=":ppc" />
        <vers num="4.1" edition=":ia64" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0815" published="2004-11-03" name="CVE-2004-0815" modified="2010-01-28" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">The unix_clean_name function in Samba 2.2.x through 2.2.11, and 3.0.x before 3.0.2a, trims certain directory names down to absolute paths, which could allow remote attackers to bypass the specified share restrictions and read, write, or list arbitrary files via "/.////" style sequences in pathnames.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <access />
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/11281" source="BID" patch="1" adv="1">11281</ref>
      <ref url="http://www.debian.org/security/2004/dsa-600" source="DEBIAN" patch="1" adv="1">DSA-600</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109655827913457&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20040930 Samba Security Announcement -- Potential Arbitrary File Access</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000873" source="CONECTIVA" patch="1" adv="1">CLA-2004:873</ref>
      <ref url="https://bugzilla.fedora.us/show_bug.cgi?id=2102" source="FEDORA">FLSA:2102</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/17556" source="XF">samba-file-access(17556)</ref>
      <ref url="http://www.trustix.org/errata/2004/0051/" source="TRUSTIX">2004-0051</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2004_35_samba.html" source="SUSE">SUSE-SA:2004:035</ref>
      <ref url="http://www.mandrakesecure.net/en/advisories/advisory.php?name=MDKSA-2004:104" source="MANDRAKE">MDKSA-2004:104</ref>
      <ref url="http://www.idefense.com/application/poi/display?id=146&amp;type=vulnerabilities&amp;flashstatus=true" source="IDEFENSE" adv="1">20040930 Samba Arbitrary File Access Vulnerability</ref>
      <ref url="http://us4.samba.org/samba/news/#security_2.2.12" source="CONFIRM">http://us4.samba.org/samba/news/#security_2.2.12</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-66-200529-1" source="SUNALERT">200529</ref>
      <ref url="http://www.securityfocus.com/archive/1/377618" source="BUGTRAQ">20041005 ERRATA: Potential Arbitrary File Access (CAN-2004-0815)</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-498.html" source="REDHAT">RHSA-2004:498</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-57664-1" source="SUNALERT">57664</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-101584-1" source="SUNALERT">101584</ref>
    </refs>
    <vuln_soft>
      <prod vendor="samba" name="samba">
        <vers num="2.2.0" />
        <vers num="2.2.0a" />
        <vers num="2.2.11" />
        <vers num="2.2.1a" />
        <vers num="2.2.2" />
        <vers num="2.2.3" />
        <vers num="2.2.3a" />
        <vers num="2.2.4" />
        <vers num="2.2.5" />
        <vers num="2.2.6" />
        <vers num="2.2.7" />
        <vers num="2.2.7a" />
        <vers num="2.2.8" />
        <vers num="2.2.8a" />
        <vers num="2.2.9" />
        <vers num="2.2a" />
        <vers num="3.0" />
        <vers num="3.0.0" />
        <vers num="3.0.1" />
        <vers num="3.0.2" />
        <vers num="3.0.2a" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0816" published="2004-12-23" name="CVE-2004-0816" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Integer underflow in the firewall logging rules for iptables in Linux before 2.6.8 allows remote attackers to cause a denial of service (application crash) via a malformed IP packet.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/17800" source="XF" patch="1" adv="1">linux-ip-packet-dos(17800)</ref>
      <ref url="http://www.securityfocus.com/bid/11488" source="BID">11488</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2004_37_kernel.html" source="SUSE">SUSE-SA:2004:037</ref>
      <ref url="http://secunia.com/advisories/11202/" source="SECUNIA">11202</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:022" source="MANDRAKE">MDKSA-2005:022</ref>
    </refs>
    <vuln_soft>
      <prod vendor="linux" name="linux_kernel">
        <vers num="2.6.0" edition="test1" />
        <vers num="2.6.0" edition="test10" />
        <vers num="2.6.0" edition="test11" />
        <vers num="2.6.0" edition="test2" />
        <vers num="2.6.0" edition="test3" />
        <vers num="2.6.0" edition="test4" />
        <vers num="2.6.0" edition="test5" />
        <vers num="2.6.0" edition="test6" />
        <vers num="2.6.0" edition="test7" />
        <vers num="2.6.0" edition="test8" />
        <vers num="2.6.0" edition="test9" />
        <vers num="2.6.1" edition="rc1" />
        <vers num="2.6.1" edition="rc2" />
        <vers num="2.6.2" />
        <vers num="2.6.3" />
        <vers num="2.6.4" />
        <vers num="2.6.5" />
        <vers num="2.6.6" edition="rc1" />
        <vers num="2.6.7" edition="rc1" />
        <vers num="2.6.8" edition="rc1" />
        <vers num="2.6.8" edition="rc2" />
        <vers num="2.6.8" edition="rc3" />
        <vers num="2.6_test9_cvs" />
      </prod>
      <prod vendor="suse" name="suse_linux">
        <vers num="9.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0817" published="2004-12-31" name="CVE-2004-0817" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple heap-based buffer overflows in the imlib BMP image handler allow remote attackers to execute arbitrary code via a crafted BMP file.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/17182" source="XF" patch="1">imlib-bmp-bo(17182)</ref>
      <ref url="http://www.securityfocus.com/bid/11084" source="BID" patch="1">11084</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-465.html" source="REDHAT" patch="1" adv="1">RHSA-2004:465</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200409-12.xml" source="GENTOO" patch="1" adv="1">GLSA-200409-12</ref>
      <ref url="http://www.debian.org/security/2004/dsa-548" source="DEBIAN" patch="1" adv="1">DSA-548</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000870" source="CONECTIVA" patch="1">CLA-2004:870</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-66-201611-1" source="SUNALERT">201611</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:8843" source="OVAL">oval:org.mitre.oval:def:8843</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2004:089" source="MANDRAKE">MDKSA-2004:089</ref>
    </refs>
    <vuln_soft>
      <prod vendor="enlightenment" name="imlib">
        <vers num="1.9" />
        <vers num="1.9.1" />
        <vers num="1.9.10" />
        <vers num="1.9.11" />
        <vers num="1.9.12" />
        <vers num="1.9.13" />
        <vers num="1.9.14" />
        <vers num="1.9.2" />
        <vers num="1.9.3" />
        <vers num="1.9.4" />
        <vers num="1.9.5" />
        <vers num="1.9.6" />
        <vers num="1.9.7" />
        <vers num="1.9.8" />
        <vers num="1.9.9" />
      </prod>
      <prod vendor="enlightenment" name="imlib2">
        <vers num="1.0" />
        <vers num="1.0.1" />
        <vers num="1.0.2" />
        <vers num="1.0.3" />
        <vers num="1.0.4" />
        <vers num="1.0.5" />
        <vers num="1.1" />
        <vers num="1.1.1" />
      </prod>
      <prod vendor="imagemagick" name="imagemagick">
        <vers num="5.3.3" />
        <vers num="5.4.3" />
        <vers num="5.4.4.5" />
        <vers num="5.4.7" />
        <vers num="5.4.8" />
        <vers num="5.4.8.2.1.1.0" />
        <vers num="5.5.3.2.1.2.0" />
        <vers num="5.5.6.0_2003-04-09" />
        <vers num="5.5.7" />
        <vers num="6.0.2" />
      </prod>
      <prod vendor="sun" name="java_desktop_system">
        <vers num="2.0" />
        <vers num="2003" />
      </prod>
      <prod vendor="conectiva" name="linux">
        <vers num="10.0" />
        <vers num="9.0" />
      </prod>
      <prod vendor="mandrakesoft" name="mandrake_linux">
        <vers num="10.0" edition="" />
        <vers num="10.0" edition=":amd64" />
        <vers num="9.2" edition="" />
        <vers num="9.2" edition=":amd64" />
      </prod>
      <prod vendor="mandrakesoft" name="mandrake_linux_corporate_server">
        <vers num="2.1" edition="" />
        <vers num="2.1" edition=":x86_64" />
      </prod>
      <prod vendor="redhat" name="enterprise_linux">
        <vers num="2.1" edition="" />
        <vers num="2.1" edition=":workstation_ia64" />
        <vers num="2.1" edition=":advanced_server" />
        <vers num="2.1" edition=":enterprise_server" />
        <vers num="2.1" edition=":advanced_server_ia64" />
        <vers num="2.1" edition=":enterprise_server_ia64" />
        <vers num="2.1" edition=":workstation" />
        <vers num="3.0" edition="" />
        <vers num="3.0" edition=":enterprise_server" />
        <vers num="3.0" edition=":workstation" />
        <vers num="3.0" edition=":advanced_servers" />
      </prod>
      <prod vendor="redhat" name="enterprise_linux_desktop">
        <vers num="3.0" />
      </prod>
      <prod vendor="redhat" name="fedora_core">
        <vers num="core_1.0" />
        <vers num="core_2.0" />
        <vers num="core_3.0" />
      </prod>
      <prod vendor="redhat" name="linux_advanced_workstation">
        <vers num="2.1" edition="" />
        <vers num="2.1" edition=":itanium_processor" />
        <vers num="2.1" edition=":ia64" />
      </prod>
      <prod vendor="suse" name="suse_linux">
        <vers num="8.0" edition="" />
        <vers num="8.0" edition=":i386" />
        <vers num="8.1" />
        <vers num="8.2" />
        <vers num="9.0" edition="" />
        <vers num="9.0" edition=":x86_64" />
        <vers num="9.1" />
        <vers num="9.2" />
      </prod>
      <prod vendor="turbolinux" name="turbolinux_desktop">
        <vers num="10.0" />
      </prod>
      <prod vendor="turbolinux" name="turbolinux_server">
        <vers num="7.0" />
        <vers num="8.0" />
      </prod>
      <prod vendor="turbolinux" name="turbolinux_workstation">
        <vers num="7.0" />
        <vers num="8.0" />
      </prod>
      <prod vendor="ubuntu" name="ubuntu_linux">
        <vers num="4.1" edition="" />
        <vers num="4.1" edition=":ia64" />
        <vers num="4.1" edition=":ppc" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0819" published="2004-08-25" name="CVE-2004-0819" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The bridge functionality in OpenBSD 3.4 and 3.5, when running a gateway configured as a bridging firewall with the link2 option for IPSec enabled, allows remote attackers to cause a denial of service (crash) via an ICMP echo (ping) packet.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.openbsd.org/errata.html" source="OPENBSD" patch="1" adv="1">20040826 028: RELIABILITY FIX: August 26, 2004</ref>
      <ref url="http://openbsd.org/errata34.html" source="OPENBSD" patch="1" adv="1">20040826 028: RELIABILITY FIX: August 26, 2004</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109345131508824&amp;w=2" source="BUGTRAQ" adv="1">20040825 Vulnerability: OpenBSD 3.5 Kernel Panic.</ref>
    </refs>
    <vuln_soft>
      <prod vendor="openbsd" name="openbsd">
        <vers num="3.2" />
        <vers num="3.3" />
        <vers num="3.4" />
        <vers num="3.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0820" published="2004-08-28" name="CVE-2004-0820" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Winamp before 5.0.4 allows remote attackers to execute arbitrary script in the Local computer zone via script in HTML files that are referenced from XML files contained in a .wsz skin file.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/17124" source="XF" patch="1" adv="1">winamp-wsz-execute-code(17124)</ref>
      <ref url="http://www.frsirt.com/exploits/08252004.skinhead.php" source="MISC" patch="1" adv="1">http://www.frsirt.com/exploits/08252004.skinhead.php</ref>
      <ref url="http://www.auscert.org.au/render.html?it=4338" source="AUSCERT" patch="1" adv="1">ESB-2004.0537</ref>
      <ref url="http://secunia.com/advisories/12381/" source="SECUNIA" patch="1" adv="1">12381</ref>
    </refs>
    <vuln_soft>
      <prod vendor="nullsoft" name="winamp">
        <vers num="2.10" />
        <vers num="2.24" />
        <vers num="2.4" />
        <vers num="2.50" />
        <vers num="2.5e" />
        <vers num="2.60" edition="" />
        <vers num="2.60" edition=":lite" />
        <vers num="2.60" edition=":full" />
        <vers num="2.61" edition="" />
        <vers num="2.61" edition=":full" />
        <vers num="2.62" edition="" />
        <vers num="2.62" edition=":standard" />
        <vers num="2.64" edition="" />
        <vers num="2.64" edition=":standard" />
        <vers num="2.65" />
        <vers num="2.70" edition="" />
        <vers num="2.70" edition=":full" />
        <vers num="2.71" />
        <vers num="2.72" />
        <vers num="2.73" edition="" />
        <vers num="2.73" edition=":full" />
        <vers num="2.74" />
        <vers num="2.75" />
        <vers num="2.76" />
        <vers num="2.77" />
        <vers num="2.78" />
        <vers num="2.79" />
        <vers num="2.80" />
        <vers num="2.81" />
        <vers num="2.91" />
        <vers num="3.0" />
        <vers num="3.1" />
        <vers num="5.01" />
        <vers num="5.02" />
        <vers num="5.03" />
        <vers num="5.04" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0821" published="2004-12-31" name="CVE-2004-0821" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">The CFPlugIn in Core Foundation framework in Mac OS X allows user supplied libraries to be loaded, which could allow local users to gain privileges.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/704110" source="CERT-VN" patch="1" adv="1">VU#704110</ref>
      <ref url="http://www.auscert.org.au/render.html?it=4363" source="AUSCERT" patch="1" adv="1">ESB-2004.0559</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/17291" source="XF" patch="1">macos-corefoundation-gain-privileges(17291)</ref>
      <ref url="http://www.securityfocus.com/bid/11135" source="BID" patch="1">11135</ref>
      <ref url="http://secunia.com/advisories/12491/" source="SECUNIA" patch="1" adv="1">12491</ref>
      <ref url="http://www.ciac.org/ciac/bulletins/o-212.shtml" source="CIAC" adv="1">O-212</ref>
      <ref url="http://www.auscert.org.au/render.html?it=4363" source="APPLE">APPLE-SA-0024-09-07</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.2.8" />
        <vers num="10.3.4" />
        <vers num="10.3.5" />
      </prod>
      <prod vendor="apple" name="mac_os_x_server">
        <vers num="10.2.8" />
        <vers num="10.3.4" />
        <vers num="10.3.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0822" published="2004-09-07" name="CVE-2004-0822" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Buffer overflow in The Core Foundation framework (CoreFoundation.framework) in Mac OS X 10.2.8, 10.3.4, and 10.3.5 allows local users to execute arbitrary code via a certain environment variable.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/545446" source="CERT-VN">VU#545446</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/17295" source="XF">macos-corefoundation-bo(17295)</ref>
      <ref url="http://www.securityfocus.com/bid/11136" source="BID">11136</ref>
      <ref url="http://www.securityfocus.com/advisories/7148" source="APPLE">APPLE-SA-2004-09-07</ref>
      <ref url="http://www.ciac.org/ciac/bulletins/o-212.shtml" source="CIAC">O-212</ref>
      <ref url="http://secunia.com/advisories/12491/" source="SECUNIA">12491</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.2.8" />
        <vers num="10.3.4" />
        <vers num="10.3.5" />
      </prod>
      <prod vendor="apple" name="mac_os_x_server">
        <vers num="10.2.8" />
        <vers num="10.3.4" />
        <vers num="10.3.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0823" published="2004-09-07" name="CVE-2004-0823" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">OpenLDAP 1.0 through 2.1.19, as used in Apple Mac OS 10.3.4 and 10.3.5 and possibly other operating systems, may allow certain authentication schemes to use hashed (crypt) passwords in the userPassword attribute as if they were plaintext passwords, which allows remote attackers to re-use hashed passwords without decrypting them.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/17300" source="XF" patch="1" adv="1">openldap-crypt-gain-access(17300)</ref>
      <ref url="http://www.securityfocus.com/bid/11137" source="BID" patch="1" adv="1">11137</ref>
      <ref url="http://www.securityfocus.com/advisories/7148" source="APPLE" patch="1" adv="1">APPLE-SA-2004-09-07</ref>
      <ref url="http://www.auscert.org.au/render.html?it=4363" source="AUSCERT" patch="1" adv="1">ESB-2004.0559</ref>
      <ref url="http://secunia.com/advisories/12491/" source="SECUNIA" patch="1" adv="1">12491</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10703" source="OVAL">oval:org.mitre.oval:def:10703</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-751.html" source="REDHAT">RHSA-2005:751</ref>
      <ref url="http://support.avaya.com/elmodocs2/security/ASA-2006-157.htm" source="CONFIRM">http://support.avaya.com/elmodocs2/security/ASA-2006-157.htm</ref>
      <ref url="http://secunia.com/advisories/21520" source="SECUNIA">21520</ref>
      <ref url="http://secunia.com/advisories/17233" source="SECUNIA">17233</ref>
    </refs>
    <vuln_soft>
      <prod vendor="openldap" name="openldap">
        <vers num="1.0" />
        <vers num="1.0.1" />
        <vers num="1.0.2" />
        <vers num="1.0.3" />
        <vers num="1.1" />
        <vers num="1.1.1" />
        <vers num="1.1.2" />
        <vers num="1.1.3" />
        <vers num="1.1.4" />
        <vers num="1.2" />
        <vers num="1.2.1" />
        <vers num="1.2.10" />
        <vers num="1.2.11" />
        <vers num="1.2.12" />
        <vers num="1.2.13" />
        <vers num="1.2.2" />
        <vers num="1.2.3" />
        <vers num="1.2.4" />
        <vers num="1.2.5" />
        <vers num="1.2.6" />
        <vers num="1.2.7" />
        <vers num="1.2.8" />
        <vers num="1.2.9" />
        <vers num="2.0" />
        <vers num="2.0.1" />
        <vers num="2.0.10" />
        <vers num="2.0.11" />
        <vers num="2.0.11_11" />
        <vers num="2.0.11_11s" />
        <vers num="2.0.11_9" />
        <vers num="2.0.12" />
        <vers num="2.0.13" />
        <vers num="2.0.14" />
        <vers num="2.0.15" />
        <vers num="2.0.16" />
        <vers num="2.0.17" />
        <vers num="2.0.18" />
        <vers num="2.0.19" />
        <vers num="2.0.2" />
        <vers num="2.0.20" />
        <vers num="2.0.21" />
        <vers num="2.0.22" />
        <vers num="2.0.23" />
        <vers num="2.0.25" />
        <vers num="2.0.27" />
        <vers num="2.0.3" />
        <vers num="2.0.4" />
        <vers num="2.0.5" />
        <vers num="2.0.6" />
        <vers num="2.0.7" />
        <vers num="2.0.8" />
        <vers num="2.0.9" />
        <vers num="2.1.10" />
        <vers num="2.1.11" />
        <vers num="2.1.12" />
        <vers num="2.1.13" />
        <vers num="2.1.14" />
        <vers num="2.1.15" />
        <vers num="2.1.16" />
        <vers num="2.1.17" />
        <vers num="2.1.18" />
        <vers num="2.1.19" />
        <vers num="2.1.4" />
        <vers num="2.1_.20" />
      </prod>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.2.8" />
        <vers num="10.3.4" />
        <vers num="10.3.5" />
      </prod>
      <prod vendor="apple" name="mac_os_x_server">
        <vers num="10.2.8" />
        <vers num="10.3.4" />
        <vers num="10.3.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2004-0824" published="2004-12-31" name="CVE-2004-0824" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">PPPDialer for Mac OS X 10.2.8 through 10.3.5 allows local users to overwrite system files via a symlink attack on PPPDialer log files.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/17298" source="XF" patch="1">macosx-pppdialer-symlink(17298)</ref>
      <ref url="http://www.securityfocus.com/bid/11139" source="BID" patch="1">11139</ref>
      <ref url="http://www.securityfocus.com/advisories/7148" source="APPLE" patch="1" adv="1">APPLE-SA-2004-09-07</ref>
      <ref url="http://www.auscert.org.au/render.html?it=4363" source="AUSCERT" patch="1" adv="1">ESB-2004.0559</ref>
      <ref url="http://securitytracker.com/id?1011175" source="SECTRACK" patch="1">1011175</ref>
      <ref url="http://www.ciac.org/ciac/bulletins/o-212.shtml" source="CIAC" adv="1">O-212</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.2.8" />
        <vers num="10.3" />
        <vers num="10.3.1" />
        <vers num="10.3.2" />
        <vers num="10.3.3" />
        <vers num="10.3.4" />
        <vers num="10.3.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0825" published="2004-12-31" name="CVE-2004-0825" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">QuickTime Streaming Server in Mac OS X Server 10.2.8, 10.3.4, and 10.3.5 allows remote attackers to cause a denial of service (application deadlock) via a certain sequence of operations.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <design />
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/914870" source="CERT-VN" patch="1" adv="1">VU#914870</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/17294" source="XF" patch="1">quicktime-dos(17294)</ref>
      <ref url="http://www.securityfocus.com/bid/11138" source="BID" patch="1">11138</ref>
      <ref url="http://www.securityfocus.com/advisories/7148" source="APPLE" patch="1" adv="1">APPLE-SA-2004-09-07</ref>
      <ref url="http://securitytracker.com/id?1011176" source="SECTRACK" patch="1">1011176</ref>
      <ref url="http://secunia.com/advisories/12491" source="SECUNIA" patch="1" adv="1">12491</ref>
      <ref url="http://www.ciac.org/ciac/bulletins/o-212.shtml" source="CIAC" adv="1">O-212</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109467471617466&amp;w=2" source="BUGTRAQ" adv="1">20040908 Re: Apple, Apple Remote Desktop client [Multiple vulnerabilities]</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x_server">
        <vers num="10.2.8" />
        <vers num="10.3.4" />
        <vers num="10.3.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0826" published="2004-12-31" name="CVE-2004-0826" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Heap-based buffer overflow in Netscape Network Security Services (NSS) library allows remote attackers to execute arbitrary code via a modified record length field in an SSLv2 client hello message.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/16314" source="XF" patch="1">sslv2-client-hello-overflow(16314)</ref>
      <ref url="http://xforce.iss.net/xforce/alerts/id/180" source="ISS" patch="1" adv="1">20040823 Netscape NSS Library Remote Compromise</ref>
      <ref url="http://www.securityfocus.com/bid/11015" source="BID" patch="1">11015</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109351293827731&amp;w=2" source="HP" patch="1" adv="1">SSRT4779</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="network_security_services">
        <vers num="3.2" />
        <vers num="3.2.1" />
        <vers num="3.3" />
        <vers num="3.3.1" />
        <vers num="3.3.2" />
        <vers num="3.4" />
        <vers num="3.4.1" />
        <vers num="3.4.2" />
        <vers num="3.5" />
        <vers num="3.6" />
        <vers num="3.6.1" />
        <vers num="3.7" />
        <vers num="3.7.1" />
        <vers num="3.7.2" />
        <vers num="3.7.3" />
        <vers num="3.7.5" />
        <vers num="3.7.7" />
        <vers num="3.8" />
        <vers num="3.9" />
      </prod>
      <prod vendor="netscape" name="certificate_server">
        <vers num="1.0" edition="patch1" />
        <vers num="4.2" />
      </prod>
      <prod vendor="netscape" name="directory_server">
        <vers num="1.3" edition="patch5" />
        <vers num="3.1" edition="patch1" />
        <vers num="3.12" />
        <vers num="4.1" />
        <vers num="4.11" />
        <vers num="4.13" />
      </prod>
      <prod vendor="netscape" name="enterprise_server">
        <vers num="2.0" />
        <vers num="2.0.1c" />
        <vers num="2.0a" />
        <vers num="3.0" />
        <vers num="3.0.1" />
        <vers num="3.0.1b" />
        <vers num="3.0.7a" edition="" />
        <vers num="3.0.7a" edition=":netware" />
        <vers num="3.0l" />
        <vers num="3.1" />
        <vers num="3.2" />
        <vers num="3.3" />
        <vers num="3.4" />
        <vers num="3.5" edition="" />
        <vers num="3.5" edition=":solaris" />
        <vers num="3.5.1" />
        <vers num="3.6" edition="" />
        <vers num="3.6" edition=":solaris" />
        <vers num="3.6" edition="sp1" />
        <vers num="3.6" edition="sp2" />
        <vers num="3.6" edition="sp3" />
        <vers num="4.0" />
        <vers num="4.1" edition="sp3" />
        <vers num="4.1" edition="sp4" />
        <vers num="4.1" edition="sp5" />
        <vers num="4.1" edition="sp6" />
        <vers num="4.1" edition="sp7" />
        <vers num="4.1" edition="sp8" />
        <vers num="4.1.1" edition="" />
        <vers num="4.1.1" edition=":netware" />
        <vers num="5.0" edition="" />
        <vers num="5.0" edition=":netware" />
      </prod>
      <prod vendor="netscape" name="personalization_engine">
        <vers num="" />
      </prod>
      <prod vendor="sun" name="java_enterprise_system">
        <vers num="2003q4" />
        <vers num="2004q2" />
      </prod>
      <prod vendor="sun" name="java_system_application_server">
        <vers num="7.0" edition="" />
        <vers num="7.0" edition=":enterprise" />
        <vers num="7.0" edition=":platform" />
        <vers num="7.0" edition=":standard" />
        <vers num="7.0" edition="ur4" />
        <vers num="7.1" />
      </prod>
      <prod vendor="sun" name="one_application_server">
        <vers num="6.0" edition="sp1" />
        <vers num="6.0" edition="sp2" />
      </prod>
      <prod vendor="sun" name="one_web_server">
        <vers num="4.1" edition="sp1" />
        <vers num="4.1" edition="sp10" />
        <vers num="4.1" edition="sp11" />
        <vers num="4.1" edition="sp12" />
        <vers num="4.1" edition="sp13" />
        <vers num="4.1" edition="sp14" />
        <vers num="4.1" edition="sp2" />
        <vers num="4.1" edition="sp3" />
        <vers num="4.1" edition="sp4" />
        <vers num="4.1" edition="sp5" />
        <vers num="4.1" edition="sp6" />
        <vers num="4.1" edition="sp7" />
        <vers num="4.1" edition="sp8" />
        <vers num="4.1" edition="sp9" />
        <vers num="6.0" edition="sp3" />
        <vers num="6.0" edition="sp4" />
        <vers num="6.0" edition="sp5" />
        <vers num="6.0" edition="sp7" />
        <vers num="6.0" edition="sp8" />
        <vers num="6.1" edition="sp1" />
        <vers num="6.1" edition="sp2" />
      </prod>
      <prod vendor="hp" name="hp-ux">
        <vers num="11.00" />
        <vers num="11.11" />
        <vers num="11.23" edition="" />
        <vers num="11.23" edition=":ia64_64-bit" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0827" published="2004-09-16" name="CVE-2004-0827" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple buffer overflows in the ImageMagick graphics library 5.x before 5.4.4, and 6.x before 6.0.6.2, allow remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via malformed (1) AVI, (2) BMP, or (3) DIB files.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-494.html" source="REDHAT" patch="1" adv="1">RHSA-2004:494</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-480.html" source="REDHAT" patch="1" adv="1">RHSA-2004:480</ref>
      <ref url="http://www.debian.org/security/2004/dsa-547" source="DEBIAN" patch="1" adv="1">DSA-547</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/17173" source="XF" adv="1">imagemagick-bmp-Bo(17173)</ref>
      <ref url="http://www.vupen.com/english/advisories/2008/0412" source="VUPEN">ADV-2008-0412</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-66-201006-1" source="SUNALERT">201006</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11123" source="OVAL">oval:org.mitre.oval:def:11123</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-231321-1" source="SUNALERT">231321</ref>
      <ref url="http://secunia.com/advisories/28800" source="SECUNIA">28800</ref>
    </refs>
    <vuln_soft>
      <prod vendor="enlightenment" name="imlib">
        <vers num="1.9" />
        <vers num="1.9.1" />
        <vers num="1.9.10" />
        <vers num="1.9.11" />
        <vers num="1.9.12" />
        <vers num="1.9.13" />
        <vers num="1.9.14" />
        <vers num="1.9.2" />
        <vers num="1.9.3" />
        <vers num="1.9.4" />
        <vers num="1.9.5" />
        <vers num="1.9.6" />
        <vers num="1.9.7" />
        <vers num="1.9.8" />
        <vers num="1.9.9" />
      </prod>
      <prod vendor="enlightenment" name="imlib2">
        <vers num="1.0" />
        <vers num="1.0.1" />
        <vers num="1.0.2" />
        <vers num="1.0.3" />
        <vers num="1.0.4" />
        <vers num="1.0.5" />
        <vers num="1.1" />
        <vers num="1.1.1" />
      </prod>
      <prod vendor="imagemagick" name="imagemagick">
        <vers num="5.3.3" />
        <vers num="5.4.3" />
        <vers num="5.4.4.5" />
        <vers num="5.4.7" />
        <vers num="5.4.8" />
        <vers num="5.4.8.2.1.1.0" />
        <vers num="5.5.3.2.1.2.0" />
        <vers num="5.5.6.0_2003-04-09" />
        <vers num="5.5.7" />
        <vers num="6.0.2" />
      </prod>
      <prod vendor="sun" name="java_desktop_system">
        <vers num="2.0" />
        <vers num="2003" />
      </prod>
      <prod vendor="conectiva" name="linux">
        <vers num="10.0" />
        <vers num="9.0" />
      </prod>
      <prod vendor="mandrakesoft" name="mandrake_linux">
        <vers num="10.0" edition="" />
        <vers num="10.0" edition=":amd64" />
        <vers num="9.2" edition="" />
        <vers num="9.2" edition=":amd64" />
      </prod>
      <prod vendor="mandrakesoft" name="mandrake_linux_corporate_server">
        <vers num="2.1" edition="" />
        <vers num="2.1" edition=":x86_64" />
      </prod>
      <prod vendor="redhat" name="enterprise_linux">
        <vers num="2.1" edition="" />
        <vers num="2.1" edition=":workstation_ia64" />
        <vers num="2.1" edition=":advanced_server" />
        <vers num="2.1" edition=":enterprise_server" />
        <vers num="2.1" edition=":advanced_server_ia64" />
        <vers num="2.1" edition=":enterprise_server_ia64" />
        <vers num="2.1" edition=":workstation" />
        <vers num="3.0" edition="" />
        <vers num="3.0" edition=":workstation_server" />
        <vers num="3.0" edition=":enterprise_server" />
        <vers num="3.0" edition=":advanced_server" />
      </prod>
      <prod vendor="redhat" name="enterprise_linux_desktop">
        <vers num="3.0" />
      </prod>
      <prod vendor="redhat" name="fedora_core">
        <vers num="core_1.0" />
        <vers num="core_2.0" />
        <vers num="core_3.0" />
      </prod>
      <prod vendor="redhat" name="linux_advanced_workstation">
        <vers num="2.1" edition="" />
        <vers num="2.1" edition=":itanium_processor" />
        <vers num="2.1" edition=":ia64" />
      </prod>
      <prod vendor="suse" name="suse_linux">
        <vers num="8.0" edition="" />
        <vers num="8.0" edition=":i386" />
        <vers num="8.1" />
        <vers num="8.2" />
        <vers num="9.0" edition="" />
        <vers num="9.0" edition=":x86_64" />
        <vers num="9.1" />
        <vers num="9.2" />
      </prod>
      <prod vendor="turbolinux" name="turbolinux">
        <vers num="desktop_10.0" />
        <vers num="server_7.0" />
        <vers num="server_8.0" />
        <vers num="workstation_7.0" />
        <vers num="workstation_8.0" />
      </prod>
      <prod vendor="ubuntu" name="ubuntu_linux">
        <vers num="4.1" edition="" />
        <vers num="4.1" edition=":ia64" />
        <vers num="4.1" edition=":ppc" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2004-0828" published="2004-11-03" name="CVE-2004-0828" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">The ctstrtcasd program in RSCT 2.3.0.0 and earlier on IBM AIX 5.2 and 5.3 does not properly drop privileges before executing the -f option, which allows local users to modify or create arbitrary files.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/17514" source="XF" patch="1" adv="1">ctstrtcasd-file-overwrite(17514)</ref>
      <ref url="http://www.securityfocus.com/bid/11264" source="BID">11264</ref>
      <ref url="http://securitytracker.com/id?1011429" source="SECTRACK">1011429</ref>
      <ref url="http://secunia.com/advisories/12664/" source="SECUNIA">12664</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="aix">
        <vers num="5.2" />
        <vers num="5.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0829" published="2004-12-31" name="CVE-2004-0829" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">smbd in Samba before 2.2.11 allows remote attackers to cause a denial of service (daemon crash) by sending a FindNextPrintChangeNotify request without a previous FindFirstPrintChangeNotify, as demonstrated by the SMB client in Windows XP SP2.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/17138" source="XF" patch="1">samba-findnextprintchangenotify-dos(17138)</ref>
      <ref url="http://seclists.org/lists/bugtraq/2004/Sep/0003.html" source="BUGTRAQ" patch="1" adv="1">20040831 Samba FindNextPrintChangeNotify() Error Lets Remote Authenticated Users Crash smbd</ref>
      <ref url="http://samba.org/samba/history/samba-2.2.11.html" source="CONFIRM" patch="1">http://samba.org/samba/history/samba-2.2.11.html</ref>
      <ref url="http://www.trustix.org/errata/2004/0043" source="TRUSTIX" adv="1">2004-0043</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200409-14.xml" source="GENTOO" adv="1">GLSA-200409-14</ref>
    </refs>
    <vuln_soft>
      <prod vendor="samba" name="samba">
        <vers num="1.9.17" edition="p1" />
        <vers num="1.9.17" edition="p2" />
        <vers num="1.9.17" edition="p3" />
        <vers num="1.9.17" edition="p4" />
        <vers num="1.9.17" edition="p5" />
        <vers num="1.9.18" edition="p1" />
        <vers num="1.9.18" edition="p10" />
        <vers num="1.9.18" edition="p2" />
        <vers num="1.9.18" edition="p3" />
        <vers num="1.9.18" edition="p4" />
        <vers num="1.9.18" edition="p5" />
        <vers num="1.9.18" edition="p6" />
        <vers num="1.9.18" edition="p7" />
        <vers num="1.9.18" edition="p8" />
        <vers num="2.0.0" />
        <vers num="2.0.1" />
        <vers num="2.0.2" />
        <vers num="2.0.3" />
        <vers num="2.0.4" />
        <vers num="2.0.5" />
        <vers num="2.0.5a" />
        <vers num="2.0.6" />
        <vers num="2.0.7" />
        <vers num="2.2.0" />
        <vers num="2.2.1" />
        <vers num="2.2.10" />
        <vers num="2.2.2" />
        <vers num="2.2.3" />
        <vers num="2.2.3a" />
        <vers num="2.2.4" />
        <vers num="2.2.5" />
        <vers num="2.2.6" />
        <vers num="2.2.7" />
        <vers num="2.2.7a" />
        <vers num="2.2.8" />
        <vers num="2.2.8a" />
        <vers num="2.2.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0830" published="2004-09-09" name="CVE-2004-0830" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The Content Scanner Server in F-Secure Anti-Virus for Microsoft Exchange 6.21 and earlier, F-Secure Anti-Virus for Microsoft Exchange 6.01 and earlier, and F-Secure Internet Gatekeeper 6.32 and earlier allow remote attackers to cause a denial of service (service crash due to unhandled exception) via a certain malformed packet.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/17307" source="XF" patch="1" adv="1">fsecure-content-scanner-dos(17307)</ref>
      <ref url="http://www.securityfocus.com/bid/11145" source="BID" patch="1" adv="1">11145</ref>
      <ref url="http://www.idefense.com/application/poi/display?id=137&amp;type=vulnerabilities" source="IDEFENSE" patch="1" adv="1">20040909 F-Secure Internet Gatekeeper Content Scanning Server Denial of Service Vulnerability</ref>
      <ref url="http://www.f-secure.com/security/fsc-2004-2.shtml" source="CONFIRM" patch="1" adv="1">http://www.f-secure.com/security/fsc-2004-2.shtml</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109483205925698&amp;w=2" source="BUGTRAQ" adv="1">20040910 F-Secure Internet Gatekeeper Content Scanning Server Denial of Service Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="f-secure" name="f-secure_anti-virus">
        <vers num="6.01" edition="" />
        <vers num="6.01" edition=":ms_exchange" />
        <vers num="6.2" edition="" />
        <vers num="6.2" edition=":ms_exchange" />
        <vers num="6.21" edition="" />
        <vers num="6.21" edition=":ms_exchange" />
      </prod>
      <prod vendor="f-secure" name="f-secure_content_scanner_server">
        <vers num="6.31" />
      </prod>
      <prod vendor="f-secure" name="internet_gatekeeper">
        <vers num="6.3" />
        <vers num="6.31" />
        <vers num="6.32" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0831" published="2004-09-14" name="CVE-2004-0831" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">McAfee VirusScan 4.5.1 does not drop SYSTEM privileges before allowing users to browse for files via the "System Scan" properties of the System Tray applet, which could allow local users to gain privileges.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.idefense.com/application/poi/display?id=140&amp;type=vulnerabilities" source="IDEFENSE" patch="1" adv="1">20040914 McAfee VirusScan Privilege Escalation Vulnerability</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/17367" source="XF" adv="1">mcafee-virusscan-gain-privileges(17367)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109526269429728&amp;w=2" source="BUGTRAQ" adv="1">20040915 McAfee VirusScan Privilege Escalation Vulnerability [iDEFENSE]</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mcafee" name="virusscan">
        <vers num="4.5" />
        <vers num="4.5.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0832" published="2004-11-03" name="CVE-2004-0832" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The (1) ntlm_fetch_string and (2) ntlm_get_string functions in Squid 2.5.6 and earlier, with NTLM authentication enabled, allow remote attackers to cause a denial of service (application crash) via an NTLMSSP packet that causes a negative value to be passed to memcpy.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/17218" source="XF" patch="1" adv="1">squid-ntlmssp-dos(17218)</ref>
      <ref url="http://www.trustix.org/errata/2004/0047/" source="TRUSTIX" patch="1" adv="1">2004-0047</ref>
      <ref url="http://www.securityfocus.com/bid/11098" source="BID" patch="1" adv="1">11098</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200409-04.xml" source="GENTOO" patch="1" adv="1">GLSA-200409-04 </ref>
      <ref url="http://www1.uk.squid-cache.org/squid/Versions/v2/2.5/bugs/#squid-2.5.STABLE6-ntlm_fetch_string" source="CONFIRM">http://www1.uk.squid-cache.org/squid/Versions/v2/2.5/bugs/#squid-2.5.STABLE6-ntlm_fetch_string</ref>
      <ref url="http://www.squid-cache.org/bugs/show_bug.cgi?id=1045" source="CONFIRM">http://www.squid-cache.org/bugs/show_bug.cgi?id=1045</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10489" source="OVAL">oval:org.mitre.oval:def:10489</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2004:093" source="MANDRAKE">MDKSA-2004:093</ref>
      <ref url="http://fedoranews.org/updates/FEDORA--.shtml" source="FEDORA">FLSA-2006:152809</ref>
    </refs>
    <vuln_soft>
      <prod vendor="squid" name="squid">
        <vers prev="1" num="2.5.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0833" published="2004-12-23" name="CVE-2004-0833" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Sendmail before 8.12.3 on Debian GNU/Linux, when using sasl and sasl-bin, uses a Sendmail configuration script with a fixed username and password, which could allow remote attackers to use Sendmail as an open mail relay and send spam messages.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/17531" source="XF" patch="1" adv="1">sendmail-mail-relay(17531)</ref>
      <ref url="http://www.securityfocus.com/bid/11262" source="BID" patch="1" adv="1">11262</ref>
      <ref url="http://www.debian.org/security/2004/dsa-554" source="DEBIAN" patch="1" adv="1">DSA-554</ref>
      <ref url="http://secunia.com/advisories/12667" source="SECUNIA">12667</ref>
    </refs>
    <vuln_soft>
      <prod vendor="debian" name="debian_linux">
        <vers num="3.0" edition="" />
        <vers num="3.0" edition=":hppa" />
        <vers num="3.0" edition=":mipsel" />
        <vers num="3.0" edition=":mips" />
        <vers num="3.0" edition=":ia-32" />
        <vers num="3.0" edition=":m68k" />
        <vers num="3.0" edition=":sparc" />
        <vers num="3.0" edition=":s-390" />
        <vers num="3.0" edition=":alpha" />
        <vers num="3.0" edition=":arm" />
        <vers num="3.0" edition=":ia-64" />
        <vers num="3.0" edition=":ppc" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0834" published="2004-12-23" name="CVE-2004-0834" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Format string vulnerability in Speedtouch USB driver before 1.3.1 allows local users to execute arbitrary code via (1) modem_run, (2) pppoa2, or (3) pppoa3.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/17792" source="XF" patch="1" adv="1">speedtouch-format-string(17792)</ref>
      <ref url="http://www.mail-archive.com/speedtouch@ml.free.fr/msg06688.html" source="MISC">http://www.mail-archive.com/speedtouch@ml.free.fr/msg06688.html</ref>
      <ref url="http://speedtouch.sourceforge.net/index.php?/news.en.html" source="CONFIRM" adv="1">http://speedtouch.sourceforge.net/index.php?/news.en.html</ref>
      <ref url="http://sourceforge.net/project/showfiles.php?group_id=32758&amp;package_id=28264&amp;release_id=271734" source="CONFIRM">http://sourceforge.net/project/showfiles.php?group_id=32758&amp;package_id=28264&amp;release_id=271734</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mandrakesoft" name="mandrake_multi_network_firewall">
        <vers num="8.2" />
      </prod>
      <prod vendor="speedtouch" name="speedtouch_usb_driver">
        <vers num="1.0" />
        <vers num="1.1" />
        <vers num="1.2" />
        <vers num="1.2_beta1" />
        <vers num="1.2_beta2" />
        <vers num="1.2_beta3" />
        <vers num="1.3" />
      </prod>
      <prod vendor="gentoo" name="linux">
        <vers num="1.4" />
      </prod>
      <prod vendor="mandrakesoft" name="mandrake_linux">
        <vers num="10.0" edition="" />
        <vers num="10.0" edition=":amd64" />
        <vers num="10.1" edition="" />
        <vers num="10.1" edition=":x86_64" />
        <vers num="8.2" edition="" />
        <vers num="8.2" edition=":ppc" />
        <vers num="9.0" />
        <vers num="9.1" edition="" />
        <vers num="9.1" edition=":ppc" />
        <vers num="9.2" edition="" />
        <vers num="9.2" edition=":amd64" />
      </prod>
      <prod vendor="mandrakesoft" name="mandrake_linux_corporate_server">
        <vers num="2.1" edition="" />
        <vers num="2.1" edition=":x86_64" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0835" published="2004-11-03" name="CVE-2004-0835" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">MySQL 3.x before 3.23.59, 4.x before 4.0.19, 4.1.x before 4.1.2, and 5.x before 5.0.1, checks the CREATE/INSERT rights of the original table instead of the target table in an ALTER TABLE RENAME operation, which could allow attackers to conduct unauthorized activities.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/17666" source="XF" patch="1" adv="1">mysql-alter-restriction-bypass(17666)</ref>
      <ref url="http://www.securityfocus.com/bid/11357" source="BID" patch="1" adv="1">11357</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-611.html" source="REDHAT" patch="1" adv="1">RHSA-2004:611</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-597.html" source="REDHAT" patch="1" adv="1">RHSA-2004:597</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200410-22.xml" source="GENTOO" patch="1" adv="1">GLSA-200410-22</ref>
      <ref url="http://www.debian.org/security/2004/dsa-562" source="DEBIAN" patch="1">DSA-562</ref>
      <ref url="http://secunia.com/advisories/12783/" source="SECUNIA" patch="1" adv="1">12783</ref>
      <ref url="http://www.trustix.org/errata/2004/0054/" source="TRUSTIX" adv="1">2004-0054</ref>
      <ref url="http://www.ciac.org/ciac/bulletins/p-018.shtml" source="CIAC">P-018</ref>
      <ref url="http://securitytracker.com/id?1011606" source="SECTRACK">1011606</ref>
      <ref url="http://lists.mysql.com/internals/13073" source="MISC" adv="1">http://lists.mysql.com/internals/13073</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000892" source="CONECTIVA">CLA-2004:892</ref>
      <ref url="http://bugs.mysql.com/bug.php?id=3270" source="MISC">http://bugs.mysql.com/bug.php?id=3270</ref>
      <ref url="http://www.mysql.org/doc/refman/4.1/en/news-4-1-2.html" source="CONFIRM">http://www.mysql.org/doc/refman/4.1/en/news-4-1-2.html</ref>
      <ref url="http://www.mysql.org/doc/refman/4.1/en/news-4-0-19.html" source="CONFIRM">http://www.mysql.org/doc/refman/4.1/en/news-4-0-19.html</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-101864-1" source="SUNALERT">101864</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mysql" name="mysql">
        <vers prev="1" num="3.23.59" />
        <vers prev="1" num="4.0.21" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0836" published="2004-11-03" name="CVE-2004-0836" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Buffer overflow in the mysql_real_connect function in MySQL 4.x before 4.0.21, and 3.x before 3.23.49, allows remote DNS servers to cause a denial of service and possibly execute arbitrary code via a DNS response with a large address length (h_length).</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/17047" source="XF" patch="1" adv="1">mysql-realconnect-bo(17047)</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-611.html" source="REDHAT" patch="1" adv="1">RHSA-2004:611</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-597.html" source="REDHAT" patch="1" adv="1">RHSA-2004:597</ref>
      <ref url="http://www.debian.org/security/2004/dsa-562" source="DEBIAN" patch="1">DSA-562</ref>
      <ref url="http://www.trustix.org/errata/2004/0054/" source="TRUSTIX" adv="1">2004-0054</ref>
      <ref url="http://www.securityfocus.com/bid/10981" source="BID">10981</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200410-22.xml" source="GENTOO">GLSA-200410-22</ref>
      <ref url="http://www.ciac.org/ciac/bulletins/p-018.shtml" source="CIAC">P-018</ref>
      <ref url="http://secunia.com/advisories/12305/" source="SECUNIA" adv="1">12305</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110140517515735&amp;w=2" source="BUGTRAQ">20041125 [USN-32-1] mysql vulnerabilities</ref>
      <ref url="http://lists.mysql.com/internals/14726" source="MISC">http://lists.mysql.com/internals/14726</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000892" source="CONECTIVA">CLA-2004:892</ref>
      <ref url="http://bugs.mysql.com/bug.php?id=4017" source="MISC">http://bugs.mysql.com/bug.php?id=4017</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mysql" name="mysql">
        <vers prev="1" num="3.23.49" />
        <vers prev="1" num="4.0.21" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2004-0837" published="2004-11-03" name="CVE-2004-0837" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:N/A:P)" CVSS_score="2.6" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="4.9" CVSS_base_score="2.6">
    <desc>
      <descript source="cve">MySQL 4.x before 4.0.21, and 3.x before 3.23.49, allows attackers to cause a denial of service (crash or hang) via multiple threads that simultaneously alter MERGE table UNIONs.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <race />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/17667" source="XF" patch="1" adv="1">mysql-union-dos(17667)</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-597.html" source="REDHAT" patch="1" adv="1">RHSA-2004:597</ref>
      <ref url="http://www.debian.org/security/2004/dsa-562" source="DEBIAN" patch="1">DSA-562</ref>
      <ref url="http://www.trustix.org/errata/2004/0054/" source="TRUSTIX" adv="1">2004-0054</ref>
      <ref url="http://www.securityfocus.com/bid/11357" source="BID">11357</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-611.html" source="REDHAT">RHSA-2004:611</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200410-22.xml" source="GENTOO">GLSA-200410-22</ref>
      <ref url="http://securitytracker.com/id?1011606" source="SECTRACK">1011606</ref>
      <ref url="http://secunia.com/advisories/12783/" source="SECUNIA">12783</ref>
      <ref url="http://mysql.bkbits.net:8080/mysql-3.23/diffs/myisammrg/myrg_open.c@1.15" source="MISC">http://mysql.bkbits.net:8080/mysql-3.23/diffs/myisammrg/myrg_open.c@1.15</ref>
      <ref url="http://lists.mysql.com/internals/16174" source="MISC">http://lists.mysql.com/internals/16174</ref>
      <ref url="http://lists.mysql.com/internals/16173" source="MISC">http://lists.mysql.com/internals/16173</ref>
      <ref url="http://lists.mysql.com/internals/16168" source="MISC">http://lists.mysql.com/internals/16168</ref>
      <ref url="http://bugs.mysql.com/2408" source="MISC">http://bugs.mysql.com/2408</ref>
      <ref url="http://www.ciac.org/ciac/bulletins/p-018.shtml" source="CIAC">P-018</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-101864-1" source="SUNALERT">101864</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110140517515735&amp;w=2" source="BUGTRAQ">20041125 [USN-32-1] mysql vulnerabilities</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000892" source="CONECTIVA">CLA-2004:892</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mysql" name="mysql">
        <vers prev="1" num="3.23.49" />
        <vers prev="1" num="4.0.21" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2004-0838" published="2004-09-13" name="CVE-2004-0838" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">Lexar Safe Guard for JumpDrive Secure 1.0 stores the password insecurely in memory using XOR encryption, which allows local users to read the password directly from the device and access the password protected part of the drive.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/17342" source="XF" adv="1">jumpdrive-safeguard-obtain-password(17342)</ref>
      <ref url="http://www.securityfocus.com/bid/11162" source="BID" adv="1">11162</ref>
      <ref url="http://www.atstake.com/research/advisories/2004/a091304-1.txt" source="ATSTAKE" adv="1">A091304-1</ref>
      <ref url="http://secunia.com/advisories/12522" source="SECUNIA" adv="1">12522</ref>
    </refs>
    <vuln_soft>
      <prod vendor="lexar" name="jumpdrive_secure">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0839" published="2004-08-18" name="CVE-2004-0839" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Internet Explorer in Windows XP SP2, and other versions including 5.01 and 5.5, allows remote attackers to install arbitrary programs via a web page that uses certain styles and the AnchorClick behavior, popup windows, and drag-and-drop capabilities to drop the program in the local startup folder, as demonstrated by "wottapoop.html".</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA04-293A.html" source="CERT" patch="1" adv="1">TA04-293A</ref>
      <ref url="http://www.kb.cert.org/vuls/id/526089" source="CERT-VN" patch="1" adv="1">VU#526089</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/17044" source="XF" patch="1" adv="1">ie-dragdrop-code-execution(17044)</ref>
      <ref url="http://www.securityfocus.com/bid/10973" source="BID" patch="1" adv="1">10973</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms04-038.mspx" source="MS" patch="1" adv="1">MS04-038</ref>
      <ref url="http://seclists.org/lists/fulldisclosure/2004/Aug/0868.html" source="FULLDISC" adv="1">20040818 What A Drag II XP SP2</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109336221826652&amp;w=2" source="BUGTRAQ" adv="1">20040824 What A Drag! -revisited-</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109303291513335&amp;w=2" source="BUGTRAQ" adv="1">20040818 What A Drag II XP SP2</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:7721" source="OVAL" sig="1">oval:org.mitre.oval:def:7721</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6272" source="OVAL" sig="1">oval:org.mitre.oval:def:6272</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:4152" source="OVAL" sig="1">oval:org.mitre.oval:def:4152</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:3773" source="OVAL" sig="1">oval:org.mitre.oval:def:3773</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2073" source="OVAL" sig="1">oval:org.mitre.oval:def:2073</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1563" source="OVAL" sig="1">oval:org.mitre.oval:def:1563</ref>
    </refs>
    <vuln_soft>
      <prod vendor="avaya" name="ip600_media_servers">
        <vers num="" />
      </prod>
      <prod vendor="microsoft" name="ie">
        <vers num="5.0.1" edition="sp1" />
        <vers num="5.0.1" edition="sp2" />
        <vers num="5.0.1" edition="sp3" />
        <vers num="5.0.1" edition="sp4" />
        <vers num="5.5" edition="sp1" />
        <vers num="5.5" edition="sp2" />
        <vers num="6.0" edition="sp1" />
        <vers num="6.0" edition="sp2" />
      </prod>
      <prod vendor="nortel" name="ip_softphone_2050">
        <vers num="" />
      </prod>
      <prod vendor="nortel" name="mobile_voice_client_2050">
        <vers num="" />
      </prod>
      <prod vendor="nortel" name="optivity_telephony_manager">
        <vers num="" />
      </prod>
      <prod vendor="nortel" name="symposium_web_centre_portal">
        <vers num="" />
      </prod>
      <prod vendor="nortel" name="symposium_web_client">
        <vers num="" />
      </prod>
      <prod vendor="avaya" name="definity_one_media_server">
        <vers num="" />
      </prod>
      <prod vendor="avaya" name="s3400">
        <vers num="" />
      </prod>
      <prod vendor="avaya" name="s8100">
        <vers num="" />
      </prod>
      <prod vendor="avaya" name="modular_messaging_message_storage_server">
        <vers num="1.1" />
        <vers num="2.0" />
      </prod>
      <prod vendor="microsoft" name="windows_2000">
        <vers num="" edition=":professional" />
        <vers num="" edition=":server" />
        <vers num="" edition=":advanced_server" />
        <vers num="" edition=":datacenter_server" />
        <vers num="" edition="sp1" />
        <vers num="" edition="sp1:datacenter_server" />
        <vers num="" edition="sp1:professional" />
        <vers num="" edition="sp1:server" />
        <vers num="" edition="sp1:advanced_server" />
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:advanced_server" />
        <vers num="" edition="sp2:professional" />
        <vers num="" edition="sp2:datacenter_server" />
        <vers num="" edition="sp2:server" />
        <vers num="" edition="sp3" />
        <vers num="" edition="sp3:datacenter_server" />
        <vers num="" edition="sp3:server" />
        <vers num="" edition="sp3:professional" />
        <vers num="" edition="sp3:advanced_server" />
        <vers num="" edition="sp4" />
        <vers num="" edition="sp4:datacenter_server" />
        <vers num="" edition="sp4:server" />
        <vers num="" edition="sp4:professional" />
        <vers num="" edition="sp4:advanced_server" />
      </prod>
      <prod vendor="microsoft" name="windows_2003_server">
        <vers num="enterprise" edition="" />
        <vers num="enterprise" edition=":64-bit" />
        <vers num="enterprise_64-bit" />
        <vers num="r2" edition="" />
        <vers num="r2" edition=":datacenter_64-bit" />
        <vers num="r2" edition=":64-bit" />
        <vers num="standard" edition="" />
        <vers num="standard" edition=":64-bit" />
        <vers num="web" />
      </prod>
      <prod vendor="microsoft" name="windows_98">
        <vers num="" edition="gold" />
      </prod>
      <prod vendor="microsoft" name="windows_98se">
        <vers num="" />
      </prod>
      <prod vendor="microsoft" name="windows_me">
        <vers num="" />
      </prod>
      <prod vendor="microsoft" name="windows_xp">
        <vers num="" edition=":home" />
        <vers num="" edition=":64-bit" />
        <vers num="" edition=":media_center" />
        <vers num="" edition="gold" />
        <vers num="" edition="gold:professional" />
        <vers num="" edition="sp1" />
        <vers num="" edition="sp1:home" />
        <vers num="" edition="sp1:media_center" />
        <vers num="" edition="sp1:64-bit" />
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:home" />
        <vers num="" edition="sp2:tablet_pc" />
        <vers num="" edition="sp2:media_center" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0840" published="2004-11-03" name="CVE-2004-0840" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">The SMTP (Simple Mail Transfer Protocol) component of Microsoft Windows XP 64-bit Edition, Windows Server 2003, Windows Server 2003 64-bit Edition, and the Exchange Routing Engine component of Exchange Server 2003, allows remote attackers to execute arbitrary code via a malicious DNS response message containing length values that are not properly validated.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/394792" source="CERT-VN" patch="1" adv="1">VU#394792</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/17660" source="XF" patch="1" adv="1">win-ms04035-patch(17660)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/17621" source="XF" patch="1" adv="1">win2k3-smtp-execute-code(17621)</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms04-035.asp" source="MS" patch="1" adv="1">MS04-035</ref>
      <ref url="http://www.securityfocus.com/bid/11374" source="BID">11374</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5509" source="OVAL" sig="1">oval:org.mitre.oval:def:5509</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:3460" source="OVAL" sig="1">oval:org.mitre.oval:def:3460</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2300" source="OVAL" sig="1">oval:org.mitre.oval:def:2300</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="exchange_server">
        <vers num="2003" />
      </prod>
      <prod vendor="microsoft" name="windows_2003_server">
        <vers num="64-bit" />
        <vers num="r2" />
      </prod>
      <prod vendor="microsoft" name="windows_xp">
        <vers num="" edition=":64-bit" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0841" published="2004-12-23" name="CVE-2004-0841" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Internet Explorer 6.x allows remote attackers to install arbitrary programs via mousedown events that call the Popup.show method and use drag-and-drop actions in a popup window, aka "HijackClick 3" and the "Script in Image Tag File Download Vulnerability."</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA04-293A.html" source="CERT">TA04-293A</ref>
      <ref url="http://www.kb.cert.org/vuls/id/413886" source="CERT-VN">VU#413886</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/16675" source="XF" patch="1" adv="1">ie-popupshow-perform-actions(16675)</ref>
      <ref url="http://www.securityfocus.com/bid/10690" source="BID" patch="1" adv="1">10690</ref>
      <ref url="http://www.securityfocus.com/archive/1/368652" source="BUGTRAQ" patch="1" adv="1">20040711 HijackClick 3</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms04-038.asp" source="MS" patch="1" adv="1">MS04-038</ref>
      <ref url="http://www.securityfocus.com/archive/1/368666" source="BUGTRAQ">20040712 Re: HijackClick 3</ref>
      <ref url="http://archives.neohapsis.com/archives/fulldisclosure/2004-07/0498.html" source="FULLDISC">20040712 Brand New Hole: Internet Explorer: HijackClick 3</ref>
      <ref url="http://www.osvdb.org/7774" source="OSVDB">7774</ref>
      <ref url="http://securitytracker.com/id?1010679" source="SECTRACK">1010679</ref>
      <ref url="http://secunia.com/advisories/12048" source="SECUNIA">12048</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:8077" source="OVAL" sig="1">oval:org.mitre.oval:def:8077</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6048" source="OVAL" sig="1">oval:org.mitre.oval:def:6048</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6031" source="OVAL" sig="1">oval:org.mitre.oval:def:6031</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5620" source="OVAL" sig="1">oval:org.mitre.oval:def:5620</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:4363" source="OVAL" sig="1">oval:org.mitre.oval:def:4363</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2611" source="OVAL" sig="1">oval:org.mitre.oval:def:2611</ref>
    </refs>
    <vuln_soft>
      <prod vendor="avaya" name="ip600_media_servers">
        <vers num="" />
      </prod>
      <prod vendor="microsoft" name="ie">
        <vers num="5.0.1" edition="sp1" />
        <vers num="5.0.1" edition="sp2" />
        <vers num="5.0.1" edition="sp3" />
        <vers num="5.0.1" edition="sp4" />
        <vers num="5.5" edition="sp1" />
        <vers num="5.5" edition="sp2" />
        <vers num="6.0" edition="sp1" />
      </prod>
      <prod vendor="avaya" name="definity_one_media_server">
        <vers num="" />
      </prod>
      <prod vendor="avaya" name="s3400">
        <vers num="" />
      </prod>
      <prod vendor="avaya" name="s8100">
        <vers num="" />
      </prod>
      <prod vendor="avaya" name="modular_messaging_message_storage_server">
        <vers num="1.1" />
        <vers num="2.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0842" published="2004-12-23" name="CVE-2004-0842" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Internet Explorer 6.0 SP1 and earlier, and possibly other versions, allows remote attackers to cause a denial of service (application crash from "memory corruption") via certain malformed Cascading Style Sheet (CSS) elements that trigger heap-based buffer overflows, as demonstrated using the "&lt;STYLE>@;/*" string, possibly due to a missing comment terminator that may cause an invalid length to trigger a large memory copy operation, aka the "CSS Heap Memory Corruption Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA04-293A.html" source="CERT">TA04-293A</ref>
      <ref url="http://www.kb.cert.org/vuls/id/291304" source="CERT-VN">VU#291304</ref>
      <ref url="http://www.securityfocus.com/bid/10816" source="BID" patch="1" adv="1">10816</ref>
      <ref url="http://www.securiteam.com/exploits/5NP042KF5A.html" source="MISC">http://www.securiteam.com/exploits/5NP042KF5A.html</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms04-038.asp" source="MS">MS04-038</ref>
      <ref url="http://www.ecqurity.com/adv/IEstyle.html" source="MISC" adv="1">http://www.ecqurity.com/adv/IEstyle.html</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109107496214572&amp;w=2" source="BUGTRAQ" adv="1">20040728 Re: Crash IE with 11 bytes ;)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/16675" source="XF">ie-popupshow-perform-actions(16675)</ref>
      <ref url="http://www.ciac.org/ciac/bulletins/p-006.shtml" source="CIAC">P-006</ref>
      <ref url="http://secunia.com/advisories/12806" source="SECUNIA">12806</ref>
      <ref url="http://marc.theaimsgroup.com/?l=full-disclosure&amp;m=109102919426844&amp;w=2" source="FULLDISC">20040728 Re: Crash IE with 11 bytes ;)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=full-disclosure&amp;m=109060455614702&amp;w=2" source="FULLDISC">20040723 Crash IE with 11 bytes ;)</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6579" source="OVAL" sig="1">oval:org.mitre.oval:def:6579</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5592" source="OVAL" sig="1">oval:org.mitre.oval:def:5592</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:4169" source="OVAL" sig="1">oval:org.mitre.oval:def:4169</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:3372" source="OVAL" sig="1">oval:org.mitre.oval:def:3372</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2906" source="OVAL" sig="1">oval:org.mitre.oval:def:2906</ref>
    </refs>
    <vuln_soft>
      <prod vendor="avaya" name="ip600_media_servers">
        <vers num="" />
      </prod>
      <prod vendor="microsoft" name="ie">
        <vers num="5.0.1" edition="sp1" />
        <vers num="5.0.1" edition="sp2" />
        <vers num="5.0.1" edition="sp3" />
        <vers num="5.0.1" edition="sp4" />
        <vers num="5.5" edition="sp1" />
        <vers num="5.5" edition="sp2" />
        <vers num="6.0" edition="sp1" />
      </prod>
      <prod vendor="avaya" name="definity_one_media_server">
        <vers num="" />
      </prod>
      <prod vendor="avaya" name="s3400">
        <vers num="" />
      </prod>
      <prod vendor="avaya" name="s8100">
        <vers num="" />
      </prod>
      <prod vendor="avaya" name="modular_messaging_message_storage_server">
        <vers num="1.1" />
        <vers num="2.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0843" published="2004-11-03" name="CVE-2004-0843" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Internet Explorer 5.5 and 6 does not properly handle plug-in navigation, which allows remote attackers to alter displayed address bars and thereby spoof web pages, facilitating phishing attacks, aka the "Plug-in Navigation Address Bar Spoofing Vulnerability."</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA04-293A.html" source="CERT" patch="1" adv="1">TA04-293A</ref>
      <ref url="http://www.kb.cert.org/vuls/id/625616" source="CERT-VN" patch="1" adv="1">VU#625616</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/17655" source="XF" patch="1" adv="1">ie-plugin-address-spoofing(17655)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/17651" source="XF" patch="1" adv="1">ie-ms04038-patch(17651)</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms04-038.mspx" source="MS" patch="1">MS04-038</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:7194" source="OVAL" sig="1">oval:org.mitre.oval:def:7194</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:7095" source="OVAL" sig="1">oval:org.mitre.oval:def:7095</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6313" source="OVAL" sig="1">oval:org.mitre.oval:def:6313</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:3949" source="OVAL" sig="1">oval:org.mitre.oval:def:3949</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2537" source="OVAL" sig="1">oval:org.mitre.oval:def:2537</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2487" source="OVAL" sig="1">oval:org.mitre.oval:def:2487</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="ie">
        <vers num="5.5" />
        <vers num="6" edition="windows_server_2003_sp1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0844" published="2004-11-03" name="CVE-2004-0844" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Internet Explorer 6 on Double Byte Character Set (DBCS) systems allows remote attackers to alter displayed address bars and spoof web pages via a URL containing special characters, facilitating phishing attacks, aka the "Address Bar Spoofing on Double Byte Character Set Systems Vulnerability."</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA04-293A.html" source="CERT" patch="1" adv="1">TA04-293A</ref>
      <ref url="http://www.kb.cert.org/vuls/id/431576" source="CERT-VN" patch="1" adv="1">VU#431576</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/17652" source="XF" patch="1" adv="1">ie-dbcs-obtain-information(17652)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/17651" source="XF" patch="1" adv="1">ie-ms04038-patch(17651)</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms04-038.mspx" source="MS" patch="1">MS04-038</ref>
      <ref url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=110174346717733&amp;w=2" source="NTBUGTRAQ">20041128 Address Bar Spoofing on Double Byte Character Set Locale Vulnerability (CAN-2004-0844) Patched in MS04-038</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110178042025729&amp;w=2" source="BUGTRAQ">20041128 Address Bar Spoofing on Double Byte Character Set Locale Vulnerability (CAN-2004-0844) Patched in MS04-038</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:8127" source="OVAL" sig="1">oval:org.mitre.oval:def:8127</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2448" source="OVAL" sig="1">oval:org.mitre.oval:def:2448</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="ie">
        <vers num="6" edition="windows_server_2003_sp1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0845" published="2004-11-03" name="CVE-2004-0845" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)" CVSS_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_base_score="6.4">
    <desc>
      <descript source="cve">Internet Explorer 5.01, 5.5, and 6 does not properly cache SSL content, which allows remote attackers to obtain information or spoof content via a web site with the same host name as the target web site, whose content is cached and reused when the user visits the target web site.</descript>
    </desc>
    <loss_types>
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA04-293A.html" source="CERT" patch="1" adv="1">TA04-293A</ref>
      <ref url="http://www.kb.cert.org/vuls/id/795720" source="CERT-VN" patch="1" adv="1">VU#795720</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/17654" source="XF" patch="1" adv="1">ie-cache-ssl-obtain-information(17654)</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms04-038.mspx" source="MS" patch="1">MS04-038</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109770364504803&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20041013 ACROS Security: Poisoning Cached HTTPS Documents in Internet Explorer</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/17651" source="XF">ie-ms04038-patch(17651)</ref>
      <ref url="http://www.acrossecurity.com/aspr/ASPR-2004-10-13-1-PUB.txt" source="MISC">http://www.acrossecurity.com/aspr/ASPR-2004-10-13-1-PUB.txt</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:7611" source="OVAL" sig="1">oval:org.mitre.oval:def:7611</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5740" source="OVAL" sig="1">oval:org.mitre.oval:def:5740</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5520" source="OVAL" sig="1">oval:org.mitre.oval:def:5520</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5150" source="OVAL" sig="1">oval:org.mitre.oval:def:5150</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:3872" source="OVAL" sig="1">oval:org.mitre.oval:def:3872</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2219" source="OVAL" sig="1">oval:org.mitre.oval:def:2219</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="ie">
        <vers num="5.01" />
        <vers num="5.5" />
        <vers num="6" edition="windows_server_2003_sp1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0846" published="2004-11-03" name="CVE-2004-0846" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Unknown vulnerability in Microsoft Excel 2000, 2002, 2001 for Mac, and v.X for Mac allows remote attackers to execute arbitrary code via a malicious file containing certain parameters that are not properly validated.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <access />
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/274496" source="CERT-VN" patch="1" adv="1">VU#274496</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/17653" source="XF" patch="1" adv="1">excel-execute-code(17653)</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms04-033.asp" source="MS" patch="1">MS04-033</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/17683" source="XF">excel-ms04033-patch(17683)</ref>
      <ref url="http://www.ciac.org/ciac/bulletins/p-009.shtml" source="CIAC" adv="1">P-009</ref>
      <ref url="http://secunia.com/advisories/12800/" source="SECUNIA">12800</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109779810827096&amp;w=2" source="BUGTRAQ">20041013 Buffer Overflow In Microsoft Excel</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:4226" source="OVAL" sig="1">oval:org.mitre.oval:def:4226</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2673" source="OVAL" sig="1">oval:org.mitre.oval:def:2673</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="excel">
        <vers num="2000" />
        <vers num="2001" />
        <vers num="2002" />
        <vers num="x" />
      </prod>
      <prod vendor="microsoft" name="office">
        <vers num="2000" edition="sp3" />
        <vers num="2001" />
        <vers num="v.x" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0847" published="2004-11-03" name="CVE-2004-0847" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">The Microsoft .NET forms authentication capability for ASP.NET allows remote attackers to bypass authentication for .aspx files in restricted directories via a request containing a (1) "\" (backslash) or (2) "%5C" (encoded backslash), aka "Path Validation Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <access />
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA05-039A.html" source="CERT">TA05-039A</ref>
      <ref url="http://www.kb.cert.org/vuls/id/283646" source="CERT-VN">VU#283646</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/17644" source="XF" patch="1" adv="1">windows-forms-security-bypass(17644)</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms05-004.mspx" source="MS">MS05-004</ref>
      <ref url="http://archives.neohapsis.com/archives/ntbugtraq/2004-q3/0221.html" source="NTBUGTRAQ" adv="1">20040914 Security bug in .NET Forms Authentication</ref>
      <ref url="http://www.securityfocus.com/bid/11342" source="BID">11342</ref>
      <ref url="http://sourceforge.net/mailarchive/forum.php?thread_id=5671607&amp;forum_id=24754" source="MISC">http://sourceforge.net/mailarchive/forum.php?thread_id=5671607&amp;forum_id=24754</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:4987" source="OVAL" sig="1">oval:org.mitre.oval:def:4987</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:3556" source="OVAL" sig="1">oval:org.mitre.oval:def:3556</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="asp.net">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0848" published="2005-02-08" name="CVE-2004-0848" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in Microsoft Office XP allows remote attackers to execute arbitrary code via a link with a URL file location containing long inputs after (1) "%00 (null byte) in .doc filenames or (2) "%0a" (carriage return) in .rtf filenames.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA05-039A.html" source="CERT" patch="1" adv="1">TA05-039A</ref>
      <ref url="http://www.kb.cert.org/vuls/id/416001" source="CERT-VN" patch="1" adv="1">VU#416001</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/19107" source="XF" patch="1" adv="1">ms-url-bo(19107)</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms05-005.mspx" source="MS" patch="1" adv="1">MS05-005</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:4022" source="OVAL" sig="1">oval:org.mitre.oval:def:4022</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2738" source="OVAL" sig="1">oval:org.mitre.oval:def:2738</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2348" source="OVAL" sig="1">oval:org.mitre.oval:def:2348</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="office">
        <vers num="xp" edition="sp1" />
        <vers num="xp" edition="sp2" />
        <vers num="xp" edition="sp3" />
      </prod>
      <prod vendor="microsoft" name="powerpoint">
        <vers num="2002" edition="sp1" />
        <vers num="2002" edition="sp2" />
        <vers num="2002" edition="sp3" />
      </prod>
      <prod vendor="microsoft" name="project">
        <vers num="2002" edition="sp1" />
      </prod>
      <prod vendor="microsoft" name="visio">
        <vers num="2002" edition="sp1" />
        <vers num="2002" edition="sp2" />
        <vers num="2002" edition="sp2:professional" />
        <vers num="2002" edition="sp2:standard" />
      </prod>
      <prod vendor="microsoft" name="word">
        <vers num="2002" edition="sp1" />
        <vers num="2002" edition="sp2" />
        <vers num="2002" edition="sp3" />
      </prod>
      <prod vendor="microsoft" name="works">
        <vers num="2002" />
        <vers num="2003" />
        <vers num="2004" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0849" published="2004-12-23" name="CVE-2004-0849" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Integer overflow in the asn_decode_string() function defined in asn1.c in radiusd for GNU Radius 1.1 and 1.2 before 1.2.94, when compiled with the --enable-snmp option, allows remote attackers to cause a denial of service (daemon crash) via certain SNMP requests.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/17391" source="XF" patch="1" adv="1">radius-asndecodestring-bo(17391)</ref>
      <ref url="http://www.idefense.com/application/poi/display?id=141&amp;type=vulnerabilities" source="IDEFENSE" patch="1" adv="1">20040915 GNU Radius SNMP String Length Integer Overflow Denial of Service Vulnerability</ref>
      <ref url="http://lists.gnu.org/archive/html/info-gnu-radius/2004-09/msg00000.html" source="MLIST" patch="1" adv="1">[Info-gnu-radius] 20040915 GNU Radius 1.2.94.</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gnu" name="radius">
        <vers num="0.92.1" />
        <vers num="0.93" />
        <vers num="0.94" />
        <vers num="0.95" />
        <vers num="0.96" />
        <vers num="1.1" />
        <vers num="1.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0850" published="2004-12-23" name="CVE-2004-0850" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Star before 1.5_alpha46 does not drop the effective user ID (euid) before calling external programs, which could allow local users to gain privileges by modifying the RSH environment variable to reference a malicious program.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/339089" source="CERT-VN" patch="1" adv="1">VU#339089</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/17297" source="XF" patch="1" adv="1">star-ssh-gain-privileges(17297)</ref>
      <ref url="http://www.securityfocus.com/bid/11141" source="BID" patch="1" adv="1">11141</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200409-11.xml" source="GENTOO">GLSA-200409-11</ref>
      <ref url="http://securitytracker.com/id?1011195" source="SECTRACK">1011195</ref>
    </refs>
    <vuln_soft>
      <prod vendor="joerg_schilling" name="star_tape_archiver">
        <vers num="1.5_a45" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2004-0851" published="2004-09-08" name="CVE-2004-0851" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">The (1) write_list and (2) dump_curr_list functions in Net-Acct before 0.71 allows local users to overwrite arbitrary files via a symlink attack on temporary files.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/17283" source="XF" patch="1" adv="1">net-acct-tmp-symlink(17283)</ref>
      <ref url="http://www.securityfocus.com/bid/11125" source="BID" patch="1" adv="1">11125</ref>
      <ref url="http://www.debian.org/security/2004/dsa-559" source="DEBIAN" patch="1" adv="1">DSA-559</ref>
      <ref url="http://secunia.com/advisories/12476" source="SECUNIA" patch="1" adv="1">12476</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109466910232385&amp;w=2" source="BUGTRAQ" adv="1">20040908 Insecure Temporary File Creation Vulnerability in Net-Acct</ref>
      <ref url="http://exorsus.net/projects/net-acct/net-acct-notempfiles.patch" source="CONFIRM" adv="1">http://exorsus.net/projects/net-acct/net-acct-notempfiles.patch</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ulrich_callmeier" name="net-acct">
        <vers num="0.6" />
        <vers num="0.7" />
        <vers num="0.71" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0852" published="2004-12-20" name="CVE-2004-0852" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in htget 0.93 allows remote attackers to execute arbitrary code via a crafted URL.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/18603" source="XF" patch="1" adv="1">htget-bo(18603)</ref>
      <ref url="http://www.debian.org/security/2004/dsa-611" source="DEBIAN" patch="1" adv="1">DSA-611</ref>
      <ref url="http://secunia.com/advisories/13579" source="SECUNIA" adv="1">13579</ref>
    </refs>
    <vuln_soft>
      <prod vendor="htget" name="htget">
        <vers num="0.93" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0866" published="2004-09-16" name="CVE-2004-0866" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Internet Explorer 6.0 allows web sites to set cookies for country-specific top-level domains, such as .ltd.uk, .plc.uk, and .sch.uk, which could allow remote attackers to perform a session fixation attack and hijack a user's HTTP session.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/11186" source="BID" patch="1" adv="1">11186</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/17415" source="XF" adv="1">web-browser-session-hijack(17415)</ref>
      <ref url="http://securitytracker.com/id?1011332" source="SECTRACK" adv="1">1011332</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109536612321898&amp;w=2" source="BUGTRAQ" adv="1">20040916 wp-04-0001: Multiple Browser Cookie Injection Vulnerabilities</ref>
    </refs>
    <vuln_soft>
      <prod vendor="kde" name="konqueror">
        <vers num="2.1.1" />
        <vers num="2.1.2" />
        <vers num="2.2.1" />
        <vers num="2.2.2" />
        <vers num="3.0" />
        <vers num="3.0.1" />
        <vers num="3.0.2" />
        <vers num="3.0.3" />
        <vers num="3.0.5" />
        <vers num="3.0.5b" />
        <vers num="3.1" />
        <vers num="3.1.1" />
        <vers num="3.1.2" />
        <vers num="3.1.3" />
        <vers num="3.1.4" />
        <vers num="3.1.5" />
        <vers num="3.2.1" />
        <vers num="3.2.3" />
      </prod>
      <prod vendor="microsoft" name="ie">
        <vers num="6.0" edition="sp1" />
        <vers num="6.0" edition="sp2" />
      </prod>
      <prod vendor="mozilla" name="firefox">
        <vers num="0.9.2" />
      </prod>
      <prod vendor="suse" name="suse_linux">
        <vers num="1.0" edition="" />
        <vers num="1.0" edition=":desktop" />
        <vers num="8" edition="" />
        <vers num="8" edition=":enterprise_server" />
        <vers num="8.1" />
        <vers num="8.2" />
        <vers num="9.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0867" published="2004-12-23" name="CVE-2004-0867" modified="2008-09-10" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Mozilla Firefox 0.9.2 allows web sites to set cookies for country-specific top-level domains, such as .ltd.uk, .plc.uk, and .sch.uk, which could allow remote attackers to perform a session fixation attack and hijack a user's HTTP session.  NOTE: it was later reported that 2.x is also affected.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=252342" source="CONFIRM">https://bugzilla.mozilla.org/show_bug.cgi?id=252342</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/17415" source="XF" adv="1">web-browser-session-hijack(17415)</ref>
      <ref url="http://www.securityfocus.com/bid/11186" source="BID" adv="1">11186</ref>
      <ref url="http://securitytracker.com/id?1011331" source="SECTRACK">1011331</ref>
      <ref url="http://secunia.com/advisories/12580/" source="SECUNIA">12580</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109536612321898&amp;w=2" source="BUGTRAQ">20040916 wp-04-0001: Multiple Browser Cookie Injection Vulnerabilities</ref>
      <ref url="http://kuza55.blogspot.com/2008/02/understanding-cookie-security.html" source="MISC">http://kuza55.blogspot.com/2008/02/understanding-cookie-security.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="kde" name="konqueror">
        <vers num="2.1.1" />
        <vers num="2.1.2" />
        <vers num="2.2.1" />
        <vers num="2.2.2" />
        <vers num="3.0" />
        <vers num="3.0.1" />
        <vers num="3.0.2" />
        <vers num="3.0.3" />
        <vers num="3.0.5" />
        <vers num="3.0.5b" />
        <vers num="3.1" />
        <vers num="3.1.1" />
        <vers num="3.1.2" />
        <vers num="3.1.3" />
        <vers num="3.1.4" />
        <vers num="3.1.5" />
        <vers num="3.2.1" />
        <vers num="3.2.3" />
      </prod>
      <prod vendor="microsoft" name="ie">
        <vers num="6.0" edition="sp1" />
        <vers num="6.0" edition="sp2" />
      </prod>
      <prod vendor="mozilla" name="firefox">
        <vers num="0.9.2" />
      </prod>
      <prod vendor="suse" name="suse_linux">
        <vers num="1.0" edition="" />
        <vers num="1.0" edition=":desktop" />
        <vers num="8" edition="" />
        <vers num="8" edition=":enterprise_server" />
        <vers num="8.1" />
        <vers num="8.2" />
        <vers num="9.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" seq="2004-0868" reject="1" published="2004-12-23" name="CVE-2004-0868" modified="2008-09-10">
    <desc>
      <descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: CVE-2004-0866.  Reason: This candidate is a duplicate of CVE-2004-0866.  Notes: The description for CVE-2004-0866 was inadvertently attached to this issue instead.  All CVE users should reference CVE-2004-0866 instead of this candidate.  All references and descriptions in this candidate have been removed to prevent accidental usage.</descript>
    </desc>
    <vuln_types>
      <design />
    </vuln_types>
    <refs />
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0869" published="2004-09-16" name="CVE-2004-0869" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Internet Explorer does not prevent cookies that are sent over an insecure channel (HTTP) from also being sent over a secure channel (HTTPS/SSL) in the same domain, which could allow remote attackers to steal cookies and conduct unauthorized activities, aka "Cross Security Boundary Cookie Injection."</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.westpoint.ltd.uk/advisories/wp-04-0001.txt" source="MISC" adv="1">http://www.westpoint.ltd.uk/advisories/wp-04-0001.txt</ref>
      <ref url="http://securityfocus.com/archive/1/375407" source="BUGTRAQ" adv="1">20040916 wp-04-0001: Multiple Browser Cookie Injection Vulnerabilities</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/17417" source="XF">web-browser-cookie-session-hijack(17417)</ref>
      <ref url="http://securitytracker.com/id?1011332" source="SECTRACK">1011332</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="ie">
        <vers num="6" edition="windows_server_2003_sp1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0870" published="2004-09-16" name="CVE-2004-0870" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">KDE Konqueror does not prevent cookies that are sent over an insecure channel (HTTP) from also being sent over a secure channel (HTTPS/SSL) in the same domain, which could allow remote attackers to steal cookies and conduct unauthorized activities, aka "Cross Security Boundary Cookie Injection."</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.westpoint.ltd.uk/advisories/wp-04-0001.txt" source="MISC" adv="1">http://www.westpoint.ltd.uk/advisories/wp-04-0001.txt</ref>
      <ref url="http://securityfocus.com/archive/1/375407" source="BUGTRAQ" adv="1">20040916 wp-04-0001: Multiple Browser Cookie Injection Vulnerabilities</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/17417" source="XF">web-browser-cookie-session-hijack(17417)</ref>
      <ref url="http://securitytracker.com/id?1011330" source="SECTRACK">1011330</ref>
    </refs>
    <vuln_soft>
      <prod vendor="kde" name="konqueror">
        <vers num="2.1.1" />
        <vers num="2.1.2" />
        <vers num="2.2.1" />
        <vers num="2.2.2" />
        <vers num="3.0" />
        <vers num="3.0.1" />
        <vers num="3.0.2" />
        <vers num="3.0.3" />
        <vers num="3.0.5" />
        <vers num="3.0.5b" />
        <vers num="3.1" />
        <vers num="3.1.1" />
        <vers num="3.1.2" />
        <vers num="3.1.3" />
        <vers num="3.1.4" />
        <vers num="3.1.5" />
        <vers num="3.2.1" />
        <vers num="3.2.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0871" published="2004-09-16" name="CVE-2004-0871" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Mozilla does not prevent cookies that are sent over an insecure channel (HTTP) from also being sent over a secure channel (HTTPS/SSL) in the same domain, which could allow remote attackers to steal cookies and conduct unauthorized activities, aka "Cross Security Boundary Cookie Injection."</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.westpoint.ltd.uk/advisories/wp-04-0001.txt" source="MISC" adv="1">http://www.westpoint.ltd.uk/advisories/wp-04-0001.txt</ref>
      <ref url="http://securityfocus.com/archive/1/375407" source="BUGTRAQ" adv="1">20040916 wp-04-0001: Multiple Browser Cookie Injection Vulnerabilities</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/17417" source="XF">web-browser-cookie-session-hijack(17417)</ref>
      <ref url="http://securitytracker.com/id?1011331" source="SECTRACK">1011331</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="mozilla">
        <vers num="0.9.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0872" published="2004-09-16" name="CVE-2004-0872" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Opera does not prevent cookies that are sent over an insecure channel (HTTP) from also being sent over a secure channel (HTTPS/SSL) in the same domain, which could allow remote attackers to steal cookies and conduct unauthorized activities, aka "Cross Security Boundary Cookie Injection."</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.westpoint.ltd.uk/advisories/wp-04-0001.txt" source="MISC" adv="1">http://www.westpoint.ltd.uk/advisories/wp-04-0001.txt</ref>
      <ref url="http://securityfocus.com/archive/1/375407" source="BUGTRAQ" adv="1">20040916 wp-04-0001: Multiple Browser Cookie Injection Vulnerabilities</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/17417" source="XF">web-browser-cookie-session-hijack(17417)</ref>
      <ref url="http://securitytracker.com/id?1011329" source="SECTRACK">1011329</ref>
    </refs>
    <vuln_soft>
      <prod vendor="opera_software" name="opera_web_browser">
        <vers num="7.51" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0873" published="2004-12-23" name="CVE-2004-0873" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Apple iChat AV 2.1, AV 2.0, and 1.0.1 allows remote attackers to execute arbitrary programs via a "link" that references the program.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/17420" source="XF" patch="1" adv="1">ichatav-link-app-execute(17420)</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2004/Sep/msg00001.html" source="APPLE" patch="1" adv="1">APPLE-SA-2004-09-16</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="ichat">
        <vers num="1.0.1" />
      </prod>
      <prod vendor="apple" name="ichat_av">
        <vers num="2.0" />
        <vers num="2.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" seq="2004-0874" reject="1" published="2005-01-10" name="CVE-2004-0874" modified="2008-09-10">
    <desc>
      <descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: CVE-2004-1123.  Reason: This candidate is a reservation duplicate of CVE-2004-1123.  Notes: All CVE users should reference CVE-2004-1123 instead of this candidate.  All references and descriptions in this candidate have been removed to prevent accidental usage.</descript>
    </desc>
    <refs />
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0875" published="2004-12-23" name="CVE-2004-0875" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in Phpgroupware (aka webdistro) 0.9.16.002 and earlier allow remote attackers to insert arbitrary HTML or web script, as demonstrated with a request to the wiki module.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/17289" source="XF" patch="1" adv="1">phpgroupware-xss(17289)</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200409-22.xml" source="GENTOO" patch="1" adv="1">GLSA-200409-22</ref>
      <ref url="http://downloads.phpgroupware.org/changelog" source="CONFIRM">http://downloads.phpgroupware.org/changelog</ref>
    </refs>
    <vuln_soft>
      <prod vendor="phpgroupware" name="phpgroupware">
        <vers num="0.9.12" />
        <vers num="0.9.13" />
        <vers num="0.9.14.003" />
        <vers num="0.9.14.005" />
        <vers num="0.9.14.006" />
        <vers num="0.9.14.007" />
        <vers num="0.9.16.000" />
        <vers num="0.9.16.002" />
        <vers num="0.9.16_rc1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2004-0880" published="2005-01-27" name="CVE-2004-0880" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:H/Au:N/C:N/I:P/A:N)" CVSS_score="1.2" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="1.9" CVSS_base_score="1.2">
    <desc>
      <descript source="cve">getmail 4.x before 4.2.0, when run as root, allows local users to overwrite arbitrary files via a symlink attack on an mbox file.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <config />
      <race />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109571883130372&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20040919 Local root compromise possible with getmail</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/17437" source="XF" adv="1">getmail-mbox-race-condition(17437)</ref>
      <ref url="http://www.qcc.ca/~charlesc/software/getmail-4/CHANGELOG" source="CONFIRM">http://www.qcc.ca/~charlesc/software/getmail-4/CHANGELOG</ref>
      <ref url="http://www.debian.org/security/2004/dsa-553" source="DEBIAN">DSA-553</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200409-32.xml" source="GENTOO">GLSA-200409-32</ref>
    </refs>
    <vuln_soft>
      <prod vendor="getmail" name="getmail">
        <vers num="2.3.7" />
        <vers num="3.x" />
        <vers num="4.0" />
        <vers num="4.0.0_b10" />
        <vers num="4.0.1" />
        <vers num="4.0.10" />
        <vers num="4.0.11" />
        <vers num="4.0.12" />
        <vers num="4.0.13" />
        <vers num="4.0.2" />
        <vers num="4.0.3" />
        <vers num="4.0.4" />
        <vers num="4.0.5" />
        <vers num="4.0.6" />
        <vers num="4.0.7" />
        <vers num="4.0.8" />
        <vers num="4.0.9" />
        <vers num="4.1" />
        <vers num="4.1.1" />
        <vers num="4.1.2" />
        <vers num="4.1.3" />
        <vers num="4.1.4" />
        <vers num="4.1.5" />
      </prod>
      <prod vendor="gentoo" name="linux">
        <vers num="1.4" />
      </prod>
      <prod vendor="slackware" name="slackware_linux">
        <vers num="10.0" />
        <vers num="9.1" />
        <vers num="current" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2004-0881" published="2005-01-27" name="CVE-2004-0881" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">getmail 4.x before 4.2.0, and other versions before 3.2.5, when run as root, allows local users to write files in arbitrary directories via a symlink attack on subdirectories in the maildir.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <design />
      <config />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109571883130372&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20040919 Local root compromise possible with getmail</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/17439" source="XF" adv="1">getmail-maildir-race-condition(17439)</ref>
      <ref url="http://www.qcc.ca/~charlesc/software/getmail-4/CHANGELOG" source="CONFIRM">http://www.qcc.ca/~charlesc/software/getmail-4/CHANGELOG</ref>
      <ref url="http://www.debian.org/security/2004/dsa-553" source="DEBIAN">DSA-553</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200409-32.xml" source="GENTOO">GLSA-200409-32</ref>
    </refs>
    <vuln_soft>
      <prod vendor="getmail" name="getmail">
        <vers num="2.3.7" />
        <vers num="3.x" />
        <vers num="4.0" />
        <vers num="4.0.0_b10" />
        <vers num="4.0.1" />
        <vers num="4.0.10" />
        <vers num="4.0.11" />
        <vers num="4.0.12" />
        <vers num="4.0.13" />
        <vers num="4.0.2" />
        <vers num="4.0.3" />
        <vers num="4.0.4" />
        <vers num="4.0.5" />
        <vers num="4.0.6" />
        <vers num="4.0.7" />
        <vers num="4.0.8" />
        <vers num="4.0.9" />
        <vers num="4.1" />
        <vers num="4.1.1" />
        <vers num="4.1.2" />
        <vers num="4.1.3" />
        <vers num="4.1.4" />
        <vers num="4.1.5" />
      </prod>
      <prod vendor="gentoo" name="linux">
        <vers num="1.4" />
      </prod>
      <prod vendor="slackware" name="slackware_linux">
        <vers num="10.0" />
        <vers num="9.1" />
        <vers num="current" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0882" published="2005-01-27" name="CVE-2004-0882" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Buffer overflow in the QFILEPATHINFO request handler in Samba 3.0.x through 3.0.7 may allow remote attackers to execute arbitrary code via a TRANSACT2_QFILEPATHINFO request with a small "maximum data bytes" value.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/457622" source="CERT-VN">VU#457622</ref>
      <ref url="http://www.trustix.net/errata/2004/0058/" source="TRUSTIX" patch="1" adv="1">2004-0058</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/18070" source="XF" adv="1">samba-qfilepathinfo-bo(18070)</ref>
      <ref url="http://www.osvdb.org/11782" source="OSVDB">11782</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2004_40_samba.html" source="SUSE">SUSE-SA:2004:040</ref>
      <ref url="http://www.ciac.org/ciac/bulletins/p-038.shtml" source="CIAC">P-038</ref>
      <ref url="http://securitytracker.com/id?1012235" source="SECTRACK">1012235</ref>
      <ref url="http://security.e-matters.de/advisories/132004.html" source="MISC">http://security.e-matters.de/advisories/132004.html</ref>
      <ref url="http://secunia.com/advisories/13189" source="SECUNIA">13189</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9969" source="OVAL">oval:org.mitre.oval:def:9969</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2005/Mar/msg00000.html" source="APPLE">APPLE-SA-2005-03-21</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/20041201-01-P" source="SGI">20041201-01-P</ref>
      <ref url="ftp://ftp.sco.com/pub/updates/UnixWare/SCOSA-2005.17/SCOSA-2005.17.txt" source="SCO">SCOSA-2005.17</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110330519803655&amp;w=2" source="BUGTRAQ">20041217 [OpenPKG-SA-2004.054] OpenPKG Security Advisory (samba)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110055646329581&amp;w=2" source="BUGTRAQ">20041115 [SAMBA] CAN-2004-0882: Possiebl Buffer Overrun in smbd</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110054671403755&amp;w=2" source="BUGTRAQ">20041115 Advisory 13/2004: Samba 3.x QFILEPATHINFO unicode filename buffer overflow</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000899" source="CONECTIVA">CLA-2004:899</ref>
    </refs>
    <vuln_soft>
      <prod vendor="samba" name="samba">
        <vers num="3.0" />
        <vers num="3.0.0" />
        <vers num="3.0.1" />
        <vers num="3.0.2" />
        <vers num="3.0.2a" />
        <vers num="3.0.3" />
        <vers num="3.0.4" edition="rc1" />
        <vers num="3.0.5" />
        <vers num="3.0.6" />
        <vers num="3.0.7" />
      </prod>
      <prod vendor="conectiva" name="linux">
        <vers num="10.0" />
      </prod>
      <prod vendor="redhat" name="enterprise_linux">
        <vers num="2.1" edition="" />
        <vers num="2.1" edition=":workstation_ia64" />
        <vers num="2.1" edition=":advanced_server" />
        <vers num="2.1" edition=":enterprise_server" />
        <vers num="2.1" edition=":advanced_server_ia64" />
        <vers num="2.1" edition=":workstation" />
        <vers num="2.1" edition=":enterprise_server_ia64" />
        <vers num="3.0" edition="" />
        <vers num="3.0" edition=":advanced_server" />
        <vers num="3.0" edition=":workstation_server" />
        <vers num="3.0" edition=":enterprise_server" />
      </prod>
      <prod vendor="redhat" name="enterprise_linux_desktop">
        <vers num="3.0" />
      </prod>
      <prod vendor="redhat" name="fedora_core">
        <vers num="core_2.0" />
        <vers num="core_3.0" />
      </prod>
      <prod vendor="redhat" name="linux_advanced_workstation">
        <vers num="2.1" edition="" />
        <vers num="2.1" edition=":itanium_processor" />
        <vers num="2.1" edition=":ia64" />
      </prod>
      <prod vendor="ubuntu" name="ubuntu_linux">
        <vers num="4.1" edition="" />
        <vers num="4.1" edition=":ia64" />
        <vers num="4.1" edition=":ppc" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0883" published="2005-01-10" name="CVE-2004-0883" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:P)" CVSS_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_base_score="6.4">
    <desc>
      <descript source="cve">Multiple vulnerabilities in the samba filesystem (smbfs) in Linux kernel 2.4 and 2.6 allow remote samba servers to cause a denial of service (crash) or gain sensitive information from kernel memory via a samba server (1) returning more data than requested to the smb_proc_read function, (2) returning a data offset from outside the samba packet to the smb_proc_readX function, (3) sending a certain TRANS2 fragmented packet to the smb_receive_trans2 function, (4) sending a samba packet with a certain header size to the smb_proc_readX_data function, or (5) sending a certain packet based offset for the data in a packet to the smb_receive_trans2 function.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
    </loss_types>
    <vuln_types>
      <input />
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/726198" source="CERT-VN">VU#726198</ref>
      <ref url="http://www.securityfocus.com/bid/11695" source="BID" patch="1" adv="1">11695</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-537.html" source="REDHAT" patch="1" adv="1">RHSA-2004:537</ref>
      <ref url="https://bugzilla.fedora.us/show_bug.cgi?id=2336" source="FEDORA">FLSA:2336</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/18136" source="XF">linux-smbreceivetrans2-dos(18136)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/18135" source="XF" adv="1">linux-smbprocreadxdata-dos(18135)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/18134" source="XF">linux-smb-response-dos(18134)</ref>
      <ref url="http://security.e-matters.de/advisories/142004.html" source="MISC">http://security.e-matters.de/advisories/142004.html</ref>
      <ref url="http://secunia.com/advisories/13232/" source="SECUNIA">13232</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10330" source="OVAL">oval:org.mitre.oval:def:10330</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110082989725345&amp;w=2" source="BUGTRAQ">20041118 [USN-30-1] Linux kernel vulnerabilities</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-505.html" source="REDHAT">RHSA-2004:505</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-504.html" source="REDHAT">RHSA-2004:504</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:022" source="MANDRAKE">MDKSA-2005:022</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1082" source="DEBIAN">DSA-1082</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1070" source="DEBIAN">DSA-1070</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1069" source="DEBIAN">DSA-1069</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1067" source="DEBIAN">DSA-1067</ref>
      <ref url="http://secunia.com/advisories/20338" source="SECUNIA">20338</ref>
      <ref url="http://secunia.com/advisories/20202" source="SECUNIA">20202</ref>
      <ref url="http://secunia.com/advisories/20163" source="SECUNIA">20163</ref>
      <ref url="http://secunia.com/advisories/20162" source="SECUNIA">20162</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110072140811965&amp;w=2" source="BUGTRAQ">20041117 Advisory 14/2004: Linux 2.x smbfs multiple remote vulnerabilities</ref>
    </refs>
    <vuln_soft>
      <prod vendor="linux" name="linux_kernel">
        <vers num="2.4.0" edition="test1" />
        <vers num="2.4.0" edition="test10" />
        <vers num="2.4.0" edition="test11" />
        <vers num="2.4.0" edition="test12" />
        <vers num="2.4.0" edition="test2" />
        <vers num="2.4.0" edition="test3" />
        <vers num="2.4.0" edition="test4" />
        <vers num="2.4.0" edition="test5" />
        <vers num="2.4.0" edition="test6" />
        <vers num="2.4.0" edition="test7" />
        <vers num="2.4.0" edition="test8" />
        <vers num="2.4.0" edition="test9" />
        <vers num="2.4.1" />
        <vers num="2.4.10" />
        <vers num="2.4.11" />
        <vers num="2.4.12" />
        <vers num="2.4.13" />
        <vers num="2.4.14" />
        <vers num="2.4.15" />
        <vers num="2.4.16" />
        <vers num="2.4.17" />
        <vers num="2.4.18" edition="" />
        <vers num="2.4.18" edition=":x86" />
        <vers num="2.4.18" edition="pre1" />
        <vers num="2.4.18" edition="pre2" />
        <vers num="2.4.18" edition="pre3" />
        <vers num="2.4.18" edition="pre4" />
        <vers num="2.4.18" edition="pre5" />
        <vers num="2.4.18" edition="pre6" />
        <vers num="2.4.18" edition="pre7" />
        <vers num="2.4.18" edition="pre8" />
        <vers num="2.4.19" edition="pre1" />
        <vers num="2.4.19" edition="pre2" />
        <vers num="2.4.19" edition="pre3" />
        <vers num="2.4.19" edition="pre4" />
        <vers num="2.4.19" edition="pre5" />
        <vers num="2.4.19" edition="pre6" />
        <vers num="2.4.2" />
        <vers num="2.4.20" />
        <vers num="2.4.21" edition="pre1" />
        <vers num="2.4.21" edition="pre4" />
        <vers num="2.4.21" edition="pre7" />
        <vers num="2.4.22" />
        <vers num="2.4.23" edition="pre9" />
        <vers num="2.4.23_ow2" />
        <vers num="2.4.24" />
        <vers num="2.4.24_ow1" />
        <vers num="2.4.25" />
        <vers num="2.4.26" />
        <vers num="2.4.27" edition="pre1" />
        <vers num="2.4.27" edition="pre2" />
        <vers num="2.4.27" edition="pre3" />
        <vers num="2.4.27" edition="pre4" />
        <vers num="2.4.27" edition="pre5" />
        <vers num="2.4.3" />
        <vers num="2.4.4" />
        <vers num="2.4.5" />
        <vers num="2.4.6" />
        <vers num="2.4.7" />
        <vers num="2.4.8" />
        <vers num="2.4.9" />
        <vers num="2.6.0" edition="test1" />
        <vers num="2.6.0" edition="test10" />
        <vers num="2.6.0" edition="test11" />
        <vers num="2.6.0" edition="test2" />
        <vers num="2.6.0" edition="test3" />
        <vers num="2.6.0" edition="test4" />
        <vers num="2.6.0" edition="test5" />
        <vers num="2.6.0" edition="test6" />
        <vers num="2.6.0" edition="test7" />
        <vers num="2.6.0" edition="test8" />
        <vers num="2.6.0" edition="test9" />
        <vers num="2.6.1" edition="rc1" />
        <vers num="2.6.1" edition="rc2" />
        <vers num="2.6.2" />
        <vers num="2.6.3" />
        <vers num="2.6.4" />
        <vers num="2.6.5" />
        <vers num="2.6.6" edition="rc1" />
        <vers num="2.6.7" edition="rc1" />
        <vers num="2.6.8" edition="rc1" />
        <vers num="2.6.8" edition="rc2" />
        <vers num="2.6.8" edition="rc3" />
        <vers num="2.6.9" edition="2.6.20" />
        <vers num="2.6_test9_cvs" />
      </prod>
      <prod vendor="redhat" name="enterprise_linux">
        <vers num="2.1" edition="" />
        <vers num="2.1" edition=":workstation_ia64" />
        <vers num="2.1" edition=":advanced_server" />
        <vers num="2.1" edition=":advanced_server_ia64" />
        <vers num="2.1" edition=":workstation" />
        <vers num="2.1" edition=":enterprise_server" />
        <vers num="2.1" edition=":enterprise_server_ia64" />
        <vers num="3.0" edition="" />
        <vers num="3.0" edition=":workstation_server" />
        <vers num="3.0" edition=":advanced_server" />
        <vers num="3.0" edition=":enterprise_server" />
      </prod>
      <prod vendor="redhat" name="enterprise_linux_desktop">
        <vers num="3.0" />
      </prod>
      <prod vendor="redhat" name="fedora_core">
        <vers num="core_2.0" />
        <vers num="core_3.0" />
      </prod>
      <prod vendor="redhat" name="linux_advanced_workstation">
        <vers num="2.1" edition="" />
        <vers num="2.1" edition=":itanium_processor" />
        <vers num="2.1" edition=":ia64" />
      </prod>
      <prod vendor="suse" name="suse_linux">
        <vers num="1.0" edition="" />
        <vers num="1.0" edition=":desktop" />
        <vers num="8" edition="" />
        <vers num="8" edition=":enterprise_server" />
        <vers num="8.1" />
        <vers num="8.2" />
        <vers num="9.0" edition="" />
        <vers num="9.0" edition=":enterprise_server" />
        <vers num="9.0" edition=":x86_64" />
        <vers num="9.1" />
        <vers num="9.2" />
      </prod>
      <prod vendor="trustix" name="secure_linux">
        <vers num="1.5" />
        <vers num="2.0" />
        <vers num="2.1" />
        <vers num="2.2" />
      </prod>
      <prod vendor="ubuntu" name="ubuntu_linux">
        <vers num="4.1" edition="" />
        <vers num="4.1" edition=":ppc" />
        <vers num="4.1" edition=":ia64" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0884" published="2005-01-27" name="CVE-2004-0884" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">The (1) libsasl and (2) libsasl2 libraries in Cyrus-SASL 2.1.18 and earlier trust the SASL_PATH environment variable to find all available SASL plug-ins, which allows local users to execute arbitrary code by modifying the SASL_PATH to point to malicious programs.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" admin="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/11347" source="BID" patch="1" adv="1">11347</ref>
      <ref url="http://www.debian.org/security/2004/dsa-563" source="DEBIAN" patch="1" adv="1">DSA-563</ref>
      <ref url="https://bugzilla.fedora.us/show_bug.cgi?id=2137" source="FEDORA">FLSA:2137</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/17643" source="XF" adv="1">cyrus-sasl-saslpath(17643)</ref>
      <ref url="http://www.trustix.net/errata/2004/0053/" source="TRUSTIX">2004-0053</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200410-05.xml" source="GENTOO">GLSA-200410-05</ref>
      <ref url="http://www.debian.org/security/2004/dsa-568" source="DEBIAN">DSA-568</ref>
      <ref url="http://www.ciac.org/ciac/bulletins/p-003.shtml" source="CIAC">P-003</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2004-546.html" source="REDHAT">RHSA-2004:546</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11678" source="OVAL">oval:org.mitre.oval:def:11678</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2005/Mar/msg00000.html" source="APPLE">APPLE-SA-2005-03-21</ref>
      <ref url="http://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=134657" source="CONFIRM">http://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=134657</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2004:106" source="MANDRAKE">MDKSA-2004:106</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110693126007214&amp;w=2" source="BUGTRAQ">20050128 [OpenPKG-SA-2005.004] OpenPKG Security Advisory (sasl)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cyrus" name="sasl">
        <vers num="1.5.24" />
        <vers num="1.5.27" />
        <vers num="1.5.28" />
        <vers num="2.1.10" />
        <vers num="2.1.11" />
        <vers num="2.1.12" />
        <vers num="2.1.13" />
        <vers num="2.1.14" />
        <vers num="2.1.15" />
        <vers num="2.1.16" />
        <vers num="2.1.17" />
        <vers num="2.1.18" />
        <vers num="2.1.18_r1" />
        <vers num="2.1.9" />
      </prod>
      <prod vendor="conectiva" name="linux">
        <vers num="10.0" />
        <vers num="9.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0885" published="2004-11-03" name="CVE-2004-0885" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">The mod_ssl module in Apache 2.0.35 through 2.0.52, when using the "SSLCipherSuite" directive in directory or location context, allows remote clients to bypass intended restrictions by using any cipher suite that is allowed by the virtual host configuration.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <config />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/17671" source="XF" patch="1" adv="1">apache-sslciphersuite-restriction-bypass(17671)</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-600.html" source="REDHAT" patch="1" adv="1">RHSA-2004:600</ref>
      <ref url="http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=HPSBUX01123" source="HP">HPSBUX01123</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0789" source="VUPEN">ADV-2006-0789</ref>
      <ref url="http://www.apacheweek.com/features/security-20" source="CONFIRM">http://www.apacheweek.com/features/security-20</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10384" source="OVAL">oval:org.mitre.oval:def:10384</ref>
      <ref url="http://issues.apache.org/bugzilla/show_bug.cgi?id=31505" source="CONFIRM">http://issues.apache.org/bugzilla/show_bug.cgi?id=31505</ref>
      <ref url="http://www.ubuntu.com/usn/usn-177-1" source="UBUNTU">USN-177-1</ref>
      <ref url="http://www.securityfocus.com/bid/11360" source="BID">11360</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2008-0261.html" source="REDHAT">RHSA-2008:0261</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-816.html" source="REDHAT">RHSA-2005:816</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-562.html" source="REDHAT">RHSA-2004:562</ref>
      <ref url="http://support.avaya.com/elmodocs2/security/ASA-2006-081.htm" source="CONFIRM">http://support.avaya.com/elmodocs2/security/ASA-2006-081.htm</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-102198-1" source="SUNALERT">102198</ref>
      <ref url="http://secunia.com/advisories/19072" source="SECUNIA">19072</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109786159119069&amp;w=2" source="BUGTRAQ">20041015 [OpenPKG-SA-2004.044] OpenPKG Security Advisory (modssl)</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2005/Aug/msg00000.html" source="APPLE">APPLE-SA-2005-08-15</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2005//Aug/msg00001.html" source="APPLE">APPLE-SA-2005-08-17</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apache" name="http_server">
        <vers num="2.0.35" />
        <vers num="2.0.36" />
        <vers num="2.0.37" />
        <vers num="2.0.38" />
        <vers num="2.0.39" />
        <vers num="2.0.40" />
        <vers num="2.0.41" />
        <vers num="2.0.42" />
        <vers num="2.0.43" />
        <vers num="2.0.44" />
        <vers num="2.0.45" />
        <vers num="2.0.46" />
        <vers num="2.0.47" />
        <vers num="2.0.48" />
        <vers num="2.0.49" />
        <vers num="2.0.50" />
        <vers num="2.0.51" />
        <vers num="2.0.52" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0886" published="2005-01-27" name="CVE-2004-0886" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Multiple integer overflows in libtiff 3.6.1 and earlier allow remote attackers to cause a denial of service (crash or memory corruption) via TIFF images that lead to incorrect malloc calls.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/687568" source="CERT-VN">VU#687568</ref>
      <ref url="http://www.securityfocus.com/bid/11406" source="BID" patch="1" adv="1">11406</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-577.html" source="REDHAT" patch="1" adv="1">RHSA-2004:577</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/17715" source="XF" adv="1">libtiff-bo(17715)</ref>
      <ref url="http://www.trustix.org/errata/2004/0054/" source="TRUSTIX">2004-0054</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-354.html" source="REDHAT">RHSA-2005:354</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2004_38_libtiff.html" source="SUSE">SUSE-SA:2004:038</ref>
      <ref url="http://www.kde.org/info/security/advisory-20041209-2.txt" source="CONFIRM">http://www.kde.org/info/security/advisory-20041209-2.txt</ref>
      <ref url="http://www.debian.org/security/2004/dsa-567" source="DEBIAN">DSA-567</ref>
      <ref url="http://www.ciac.org/ciac/bulletins/p-015.shtml" source="CIAC">P-015</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-66-201072-1" source="SUNALERT">201072</ref>
      <ref url="http://securitytracker.com/id?1011674" source="SECTRACK">1011674</ref>
      <ref url="http://secunia.com/advisories/12818" source="SECUNIA">12818</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9907" source="OVAL">oval:org.mitre.oval:def:9907</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-021.html" source="REDHAT">RHSA-2005:021</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:052" source="MANDRAKE">MDKSA-2005:052</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2004:109" source="MANDRAKE">MDKSA-2004:109</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-101677-1" source="SUNALERT">101677</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109779465621929&amp;w=2" source="OPENPKG">OpenPKG-SA-2004.043</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/index.php?id=a&amp;anuncio=000888" source="CONECTIVA">CLA-2004:888</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:100116" source="OVAL" sig="1">oval:org.mitre.oval:def:100116</ref>
    </refs>
    <vuln_soft>
      <prod vendor="libtiff" name="libtiff">
        <vers num="3.4" />
        <vers num="3.5.1" />
        <vers num="3.5.2" />
        <vers num="3.5.3" />
        <vers num="3.5.4" />
        <vers num="3.5.5" />
        <vers num="3.5.7" />
        <vers num="3.6.0" />
        <vers num="3.6.1" />
      </prod>
      <prod vendor="pdflib" name="pdf_library">
        <vers num="5.0.2" />
      </prod>
      <prod vendor="wxgtk2" name="wxgtk2">
        <vers num="2.5_.0" />
      </prod>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.2" />
        <vers num="10.2.1" />
        <vers num="10.2.2" />
        <vers num="10.2.3" />
        <vers num="10.2.4" />
        <vers num="10.2.5" />
        <vers num="10.2.6" />
        <vers num="10.2.7" />
        <vers num="10.2.8" />
        <vers num="10.3" />
        <vers num="10.3.1" />
        <vers num="10.3.2" />
        <vers num="10.3.3" />
        <vers num="10.3.4" />
        <vers num="10.3.5" />
        <vers num="10.3.6" />
      </prod>
      <prod vendor="apple" name="mac_os_x_server">
        <vers num="10.2" />
        <vers num="10.2.1" />
        <vers num="10.2.2" />
        <vers num="10.2.3" />
        <vers num="10.2.4" />
        <vers num="10.2.5" />
        <vers num="10.2.6" />
        <vers num="10.2.7" />
        <vers num="10.2.8" />
        <vers num="10.3" />
        <vers num="10.3.1" />
        <vers num="10.3.2" />
        <vers num="10.3.3" />
        <vers num="10.3.4" />
        <vers num="10.3.5" />
        <vers num="10.3.6" />
      </prod>
      <prod vendor="kde" name="kde">
        <vers num="3.2" />
        <vers num="3.2.1" />
        <vers num="3.2.2" />
        <vers num="3.2.3" />
        <vers num="3.3" />
        <vers num="3.3.1" />
      </prod>
      <prod vendor="mandrakesoft" name="mandrake_linux">
        <vers num="10.0" edition="" />
        <vers num="10.0" edition=":amd64" />
      </prod>
      <prod vendor="redhat" name="enterprise_linux">
        <vers num="2.1" edition="" />
        <vers num="2.1" edition=":workstation_ia64" />
        <vers num="2.1" edition=":advanced_server" />
        <vers num="2.1" edition=":enterprise_server" />
        <vers num="2.1" edition=":advanced_server_ia64" />
        <vers num="2.1" edition=":enterprise_server_ia64" />
        <vers num="2.1" edition=":workstation" />
        <vers num="3.0" edition="" />
        <vers num="3.0" edition=":workstation_server" />
        <vers num="3.0" edition=":enterprise_server" />
        <vers num="3.0" edition=":advanced_server" />
      </prod>
      <prod vendor="redhat" name="enterprise_linux_desktop">
        <vers num="3.0" />
      </prod>
      <prod vendor="redhat" name="fedora_core">
        <vers num="core_2.0" />
      </prod>
      <prod vendor="redhat" name="linux_advanced_workstation">
        <vers num="2.1" edition="" />
        <vers num="2.1" edition=":itanium_processor" />
        <vers num="2.1" edition=":ia64" />
      </prod>
      <prod vendor="suse" name="suse_linux">
        <vers num="1.0" edition="" />
        <vers num="1.0" edition=":desktop" />
        <vers num="8" edition="" />
        <vers num="8" edition=":enterprise_server" />
        <vers num="8.1" />
        <vers num="8.2" />
        <vers num="9.0" edition="" />
        <vers num="9.0" edition=":enterprise_server" />
        <vers num="9.1" />
      </prod>
      <prod vendor="trustix" name="secure_linux">
        <vers num="1.5" />
        <vers num="2.0" />
        <vers num="2.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0887" published="2005-01-27" name="CVE-2004-0887" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">SUSE Linux Enterprise Server 9 on the S/390 platform does not properly handle a certain privileged instruction, which allows local users to gain root privileges.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <access />
      <exception />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/11489" source="BID" patch="1" adv="1">11489</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/17801" source="XF" adv="1">linux-instruction-gain-privileges(17801)</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2004_37_kernel.html" source="SUSE">SUSE-SA:2004:037</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1018" source="DEBIAN">DSA-1018</ref>
      <ref url="http://secunia.com/advisories/19369" source="SECUNIA">19369</ref>
    </refs>
    <vuln_soft>
      <prod vendor="linux" name="linux_kernel">
        <vers num="2.6.0" />
        <vers num="2.6.1" edition="rc1" />
        <vers num="2.6.1" edition="rc2" />
        <vers num="2.6.10" edition="rc2" />
        <vers num="2.6.2" />
        <vers num="2.6.3" />
        <vers num="2.6.4" />
        <vers num="2.6.5" />
        <vers num="2.6.6" edition="rc1" />
        <vers num="2.6.7" edition="rc1" />
        <vers num="2.6.8" edition="rc1" />
        <vers num="2.6.8" edition="rc2" />
        <vers num="2.6.8" edition="rc3" />
        <vers num="2.6.9" edition="2.6.20" />
      </prod>
      <prod vendor="suse" name="suse_linux">
        <vers num="9.0" edition="" />
        <vers num="9.0" edition=":enterprise_server" />
        <vers num="9.0" edition=":s_390" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0888" published="2005-01-27" name="CVE-2004-0888" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Multiple integer overflows in xpdf 2.0 and 3.0, and other packages that use xpdf code such as CUPS, gpdf, and kdegraphics, allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code, a different set of vulnerabilities than those identified by CVE-2004-0889.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" admin="1" />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/11501" source="BID" patch="1" adv="1">11501</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-543.html" source="REDHAT" patch="1" adv="1">RHSA-2004:543</ref>
      <ref url="https://bugzilla.fedora.us/show_bug.cgi?id=2353" source="FEDORA">FLSA:2353</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/17818" source="XF" adv="1">xpdf-pdf-bo(17818)</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-354.html" source="REDHAT">RHSA-2005:354</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-066.html" source="REDHAT">RHSA-2005:066</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-592.html" source="REDHAT">RHSA-2004:592</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200410-30.xml" source="GENTOO">GLSA-200410-30</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200410-20.xml" source="GENTOO">GLSA-200410-20</ref>
      <ref url="http://www.debian.org/security/2004/dsa-599" source="DEBIAN">DSA-599</ref>
      <ref url="http://www.debian.org/security/2004/dsa-581" source="DEBIAN">DSA-581</ref>
      <ref url="http://www.debian.org/security/2004/dsa-573" source="DEBIAN">DSA-573</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9714" source="OVAL">oval:org.mitre.oval:def:9714</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2004:116" source="MANDRAKE">MDKSA-2004:116</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2004:115" source="MANDRAKE">MDKSA-2004:115</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2004:114" source="MANDRAKE">MDKSA-2004:114</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2004:113" source="MANDRAKE">MDKSA-2004:113</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110815379627883&amp;w=2" source="FEDORA">FLSA:2352</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109900116408307&amp;w=2" source="UBUNTU">USN-9-1</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109880927526773&amp;w=2" source="SUSE">SUSE-SA:2004:039</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/index.php?id=a&amp;anuncio=000886" source="CONECTIVA">CLA-2004:886</ref>
    </refs>
    <vuln_soft>
      <prod vendor="easy_software_products" name="cups">
        <vers num="1.0.4" />
        <vers num="1.0.4_8" />
        <vers num="1.1.1" />
        <vers num="1.1.10" />
        <vers num="1.1.12" />
        <vers num="1.1.13" />
        <vers num="1.1.14" />
        <vers num="1.1.15" />
        <vers num="1.1.16" />
        <vers num="1.1.17" />
        <vers num="1.1.18" />
        <vers num="1.1.19" />
        <vers num="1.1.19_rc5" />
        <vers num="1.1.20" />
        <vers num="1.1.4" />
        <vers num="1.1.4_2" />
        <vers num="1.1.4_3" />
        <vers num="1.1.4_5" />
        <vers num="1.1.6" />
        <vers num="1.1.7" />
      </prod>
      <prod vendor="gnome" name="gpdf">
        <vers num="0.112" />
        <vers num="0.131" />
      </prod>
      <prod vendor="kde" name="koffice">
        <vers num="1.3" />
        <vers num="1.3.1" />
        <vers num="1.3.2" />
        <vers num="1.3.3" />
        <vers num="1.3_beta1" />
        <vers num="1.3_beta2" />
        <vers num="1.3_beta3" />
      </prod>
      <prod vendor="kde" name="kpdf">
        <vers num="3.2" />
      </prod>
      <prod vendor="pdftohtml" name="pdftohtml">
        <vers num="0.32a" />
        <vers num="0.32b" />
        <vers num="0.33" />
        <vers num="0.33a" />
        <vers num="0.34" />
        <vers num="0.35" />
        <vers num="0.36" />
      </prod>
      <prod vendor="tetex" name="tetex">
        <vers num="1.0.7" />
        <vers num="2.0" />
        <vers num="2.0.1" />
        <vers num="2.0.2" />
      </prod>
      <prod vendor="xpdf" name="xpdf">
        <vers num="0.90" />
        <vers num="0.91" />
        <vers num="0.92" />
        <vers num="0.93" />
        <vers num="1.0" />
        <vers num="1.0a" />
        <vers num="1.1" />
        <vers num="2.0" />
        <vers num="2.1" />
        <vers num="2.3" />
        <vers num="3.0" />
      </prod>
      <prod vendor="debian" name="debian_linux">
        <vers num="3.0" edition="" />
        <vers num="3.0" edition=":mips" />
        <vers num="3.0" edition=":s-390" />
        <vers num="3.0" edition=":alpha" />
        <vers num="3.0" edition=":mipsel" />
        <vers num="3.0" edition=":hppa" />
        <vers num="3.0" edition=":ia-32" />
        <vers num="3.0" edition=":arm" />
        <vers num="3.0" edition=":ppc" />
        <vers num="3.0" edition=":m68k" />
        <vers num="3.0" edition=":ia-64" />
        <vers num="3.0" edition=":sparc" />
      </prod>
      <prod vendor="gentoo" name="linux">
        <vers num="" />
      </prod>
      <prod vendor="kde" name="kde">
        <vers num="3.2" />
        <vers num="3.2.1" />
        <vers num="3.2.2" />
        <vers num="3.2.3" />
        <vers num="3.3" />
        <vers num="3.3.1" />
      </prod>
      <prod vendor="redhat" name="enterprise_linux">
        <vers num="2.1" edition="" />
        <vers num="2.1" edition=":workstation_ia64" />
        <vers num="2.1" edition=":advanced_server" />
        <vers num="2.1" edition=":enterprise_server" />
        <vers num="2.1" edition=":advanced_server_ia64" />
        <vers num="2.1" edition=":enterprise_server_ia64" />
        <vers num="2.1" edition=":workstation" />
        <vers num="3.0" edition="" />
        <vers num="3.0" edition=":workstation_server" />
        <vers num="3.0" edition=":enterprise_server" />
        <vers num="3.0" edition=":advanced_server" />
      </prod>
      <prod vendor="redhat" name="enterprise_linux_desktop">
        <vers num="3.0" />
      </prod>
      <prod vendor="redhat" name="fedora_core">
        <vers num="core_2.0" />
      </prod>
      <prod vendor="redhat" name="linux_advanced_workstation">
        <vers num="2.1" edition="" />
        <vers num="2.1" edition=":itanium_processor" />
        <vers num="2.1" edition=":ia64" />
      </prod>
      <prod vendor="suse" name="suse_linux">
        <vers num="8.0" />
        <vers num="8.1" />
        <vers num="8.2" />
        <vers num="9.0" edition="" />
        <vers num="9.0" edition=":x86_64" />
        <vers num="9.1" />
        <vers num="9.2" />
      </prod>
      <prod vendor="ubuntu" name="ubuntu_linux">
        <vers num="4.1" edition="" />
        <vers num="4.1" edition=":ia64" />
        <vers num="4.1" edition=":ppc" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0889" published="2005-01-27" name="CVE-2004-0889" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Multiple integer overflows in xpdf 3.0, and other packages that use xpdf code such as CUPS, allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code, a different set of vulnerabilities than those identified by CVE-2004-0888.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" admin="1" />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200410-20.xml" source="GENTOO" patch="1" adv="1">GLSA-200410-20</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/17819" source="XF" adv="1">xpdf-pdf-file-bo(17819)</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200410-30.xml" source="GENTOO">GLSA-200410-30</ref>
      <ref url="http://www.securityfocus.com/bid/11501" source="BID">11501</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2004:113" source="MANDRAKE">MDKSA-2004:113</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109880927526773&amp;w=2" source="SUSE">SUSE-SA:2004:039</ref>
    </refs>
    <vuln_soft>
      <prod vendor="easy_software_products" name="cups">
        <vers num="1.0.4" />
        <vers num="1.0.4_8" />
        <vers num="1.1.1" />
        <vers num="1.1.10" />
        <vers num="1.1.12" />
        <vers num="1.1.13" />
        <vers num="1.1.14" />
        <vers num="1.1.15" />
        <vers num="1.1.16" />
        <vers num="1.1.17" />
        <vers num="1.1.18" />
        <vers num="1.1.19" />
        <vers num="1.1.19_rc5" />
        <vers num="1.1.20" />
        <vers num="1.1.4" />
        <vers num="1.1.4_2" />
        <vers num="1.1.4_3" />
        <vers num="1.1.4_5" />
        <vers num="1.1.6" />
        <vers num="1.1.7" />
      </prod>
      <prod vendor="gnome" name="gpdf">
        <vers num="0.112" />
        <vers num="0.131" />
      </prod>
      <prod vendor="kde" name="koffice">
        <vers num="1.3" />
        <vers num="1.3.1" />
        <vers num="1.3.2" />
        <vers num="1.3.3" />
        <vers num="1.3_beta1" />
        <vers num="1.3_beta2" />
        <vers num="1.3_beta3" />
      </prod>
      <prod vendor="kde" name="kpdf">
        <vers num="3.2" />
      </prod>
      <prod vendor="pdftohtml" name="pdftohtml">
        <vers num="0.32a" />
        <vers num="0.32b" />
        <vers num="0.33" />
        <vers num="0.33a" />
        <vers num="0.34" />
        <vers num="0.35" />
        <vers num="0.36" />
      </prod>
      <prod vendor="tetex" name="tetex">
        <vers num="1.0.7" />
        <vers num="2.0" />
        <vers num="2.0.1" />
        <vers num="2.0.2" />
      </prod>
      <prod vendor="xpdf" name="xpdf">
        <vers num="0.90" />
        <vers num="0.91" />
        <vers num="0.92" />
        <vers num="0.93" />
        <vers num="1.0" />
        <vers num="1.0a" />
        <vers num="1.1" />
        <vers num="2.0" />
        <vers num="2.1" />
        <vers num="2.3" />
        <vers num="3.0" />
      </prod>
      <prod vendor="debian" name="debian_linux">
        <vers num="3.0" edition="" />
        <vers num="3.0" edition=":mips" />
        <vers num="3.0" edition=":s-390" />
        <vers num="3.0" edition=":alpha" />
        <vers num="3.0" edition=":mipsel" />
        <vers num="3.0" edition=":hppa" />
        <vers num="3.0" edition=":ia-32" />
        <vers num="3.0" edition=":arm" />
        <vers num="3.0" edition=":ppc" />
        <vers num="3.0" edition=":m68k" />
        <vers num="3.0" edition=":ia-64" />
        <vers num="3.0" edition=":sparc" />
      </prod>
      <prod vendor="gentoo" name="linux">
        <vers num="" />
      </prod>
      <prod vendor="kde" name="kde">
        <vers num="3.2" />
        <vers num="3.2.1" />
        <vers num="3.2.2" />
        <vers num="3.2.3" />
        <vers num="3.3" />
        <vers num="3.3.1" />
      </prod>
      <prod vendor="redhat" name="enterprise_linux">
        <vers num="2.1" edition="" />
        <vers num="2.1" edition=":workstation_ia64" />
        <vers num="2.1" edition=":advanced_server" />
        <vers num="2.1" edition=":enterprise_server" />
        <vers num="2.1" edition=":advanced_server_ia64" />
        <vers num="2.1" edition=":enterprise_server_ia64" />
        <vers num="2.1" edition=":workstation" />
        <vers num="3.0" edition="" />
        <vers num="3.0" edition=":workstation_server" />
        <vers num="3.0" edition=":enterprise_server" />
        <vers num="3.0" edition=":advanced_server" />
      </prod>
      <prod vendor="redhat" name="enterprise_linux_desktop">
        <vers num="3.0" />
      </prod>
      <prod vendor="redhat" name="fedora_core">
        <vers num="core_2.0" />
      </prod>
      <prod vendor="redhat" name="linux_advanced_workstation">
        <vers num="2.1" edition="" />
        <vers num="2.1" edition=":itanium_processor" />
        <vers num="2.1" edition=":ia64" />
      </prod>
      <prod vendor="suse" name="suse_linux">
        <vers num="8.0" />
        <vers num="8.1" />
        <vers num="8.2" />
        <vers num="9.0" edition="" />
        <vers num="9.0" edition=":x86_64" />
        <vers num="9.1" />
        <vers num="9.2" />
      </prod>
      <prod vendor="ubuntu" name="ubuntu_linux">
        <vers num="4.1" edition="" />
        <vers num="4.1" edition=":ia64" />
        <vers num="4.1" edition=":ppc" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" seq="2004-0890" reject="1" published="2005-01-10" name="CVE-2004-0890" modified="2008-09-10">
    <desc>
      <descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: none.  Reasons: This candidate is a reservation duplicate of another candidate.  Notes: All references and descriptions in this candidate have been removed to prevent accidental usage.</descript>
    </desc>
    <refs />
  </entry>
  <entry type="CVE" severity="High" seq="2004-0891" published="2005-01-27" name="CVE-2004-0891" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Buffer overflow in the MSN protocol handler for gaim 0.79 to 1.0.1 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via an "unexpected sequence of MSNSLP messages" that results in an unbounded copy operation that writes to the wrong buffer.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="https://bugzilla.fedora.us/show_bug.cgi?id=2188" source="FEDORA">FLSA:2188</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/17790" source="XF">gaim-file-transfer-dos(17790)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/17787" source="XF">gaim-msn-slp-dos(17787)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/17786" source="XF" adv="1">gaim-msn-slp-bo(17786)</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-604.html" source="REDHAT" adv="1">RHSA-2004:604</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200410-23.xml" source="GENTOO">GLSA-200410-23</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11790" source="OVAL">oval:org.mitre.oval:def:11790</ref>
      <ref url="http://gaim.sourceforge.net/security/?id=9" source="CONFIRM" adv="1">http://gaim.sourceforge.net/security/?id=9</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109900412126643&amp;w=2" source="UBUNTU">USN-8-1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="rob_flynn" name="gaim">
        <vers num="0.10" />
        <vers num="0.10.3" />
        <vers num="0.50" />
        <vers num="0.51" />
        <vers num="0.52" />
        <vers num="0.53" />
        <vers num="0.54" />
        <vers num="0.55" />
        <vers num="0.56" />
        <vers num="0.57" />
        <vers num="0.58" />
        <vers num="0.59" />
        <vers num="0.59.1" />
        <vers num="0.60" />
        <vers num="0.61" />
        <vers num="0.62" />
        <vers num="0.63" />
        <vers num="0.64" />
        <vers num="0.65" />
        <vers num="0.66" />
        <vers num="0.67" />
        <vers num="0.68" />
        <vers num="0.69" />
        <vers num="0.70" />
        <vers num="0.71" />
        <vers num="0.72" />
        <vers num="0.73" />
        <vers num="0.74" />
        <vers num="0.75" />
        <vers num="0.78" />
        <vers num="0.82" />
        <vers num="0.82.1" />
        <vers num="1.0" />
        <vers num="1.0.1" />
      </prod>
      <prod vendor="gentoo" name="linux">
        <vers num="1.4" />
      </prod>
      <prod vendor="slackware" name="slackware_linux">
        <vers num="10.0" />
        <vers num="9.0" />
        <vers num="9.1" />
        <vers num="current" />
      </prod>
      <prod vendor="ubuntu" name="ubuntu_linux">
        <vers num="4.1" edition="" />
        <vers num="4.1" edition=":ia64" />
        <vers num="4.1" edition=":ppc" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0892" published="2005-01-27" name="CVE-2004-0892" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Microsoft Proxy Server 2.0 and Microsoft ISA Server 2000 (which is included in Small Business Server 2000 and Small Business Server 2003 Premium Edition) allows remote attackers to spoof trusted Internet content on a specially crafted webpage via spoofed reverse DNS lookup results.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/11605" source="BID" patch="1" adv="1">11605</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms04-039.asp" source="MS" patch="1" adv="1">MS04-039</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/17906" source="XF" adv="1">isa-cache-reverse-spoof(17906)</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:4859" source="OVAL" sig="1">oval:org.mitre.oval:def:4859</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:4264" source="OVAL" sig="1">oval:org.mitre.oval:def:4264</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="isa_server">
        <vers num="2000" edition="sp1" />
        <vers num="2000" edition="sp2" />
      </prod>
      <prod vendor="microsoft" name="proxy_server">
        <vers num="2.0" edition="sp1" />
      </prod>
      <prod vendor="microsoft" name="windows_2003_server">
        <vers num="2000" edition="" />
        <vers num="2000" edition=":small_business_server" />
        <vers num="2003" edition="" />
        <vers num="2003" edition=":small_business_server" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0893" published="2005-01-10" name="CVE-2004-0893" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">The Local Procedure Call (LPC) interface of the Windows Kernel for Windows NT 4.0, Windows 2000, Windows XP, and Windows Server 2003 does not properly validate the lengths of messages sent to the LPC port, which allows local users to gain privileges, aka "Windows Kernel Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" admin="1" />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms04-044.asp" source="MS" patch="1" adv="1">MS04-044</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/18339" source="XF">win-kernel-lpc-gain-privileges(18339)</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:450" source="OVAL" sig="1">oval:org.mitre.oval:def:450</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:4458" source="OVAL" sig="1">oval:org.mitre.oval:def:4458</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:4021" source="OVAL" sig="1">oval:org.mitre.oval:def:4021</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2008" source="OVAL" sig="1">oval:org.mitre.oval:def:2008</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1886" source="OVAL" sig="1">oval:org.mitre.oval:def:1886</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1581" source="OVAL" sig="1">oval:org.mitre.oval:def:1581</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1561" source="OVAL" sig="1">oval:org.mitre.oval:def:1561</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1321" source="OVAL" sig="1">oval:org.mitre.oval:def:1321</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_2000">
        <vers num="" edition=":professional" />
        <vers num="" edition=":server" />
        <vers num="" edition=":advanced_server" />
        <vers num="" edition=":datacenter_server" />
        <vers num="" edition="sp1" />
        <vers num="" edition="sp1:datacenter_server" />
        <vers num="" edition="sp1:professional" />
        <vers num="" edition="sp1:server" />
        <vers num="" edition="sp1:advanced_server" />
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:advanced_server" />
        <vers num="" edition="sp2:professional" />
        <vers num="" edition="sp2:datacenter_server" />
        <vers num="" edition="sp2:server" />
        <vers num="" edition="sp3" />
        <vers num="" edition="sp3:datacenter_server" />
        <vers num="" edition="sp3:server" />
        <vers num="" edition="sp3:professional" />
        <vers num="" edition="sp3:advanced_server" />
        <vers num="" edition="sp4" />
        <vers num="" edition="sp4:datacenter_server" />
        <vers num="" edition="sp4:server" />
        <vers num="" edition="sp4:professional" />
        <vers num="" edition="sp4:advanced_server" />
      </prod>
      <prod vendor="microsoft" name="windows_2003_server">
        <vers num="datacenter_64-bit" edition="sp1_beta_1" />
        <vers num="enterprise" edition="" />
        <vers num="enterprise" edition=":64-bit" />
        <vers num="enterprise" edition="sp1_beta_1" />
        <vers num="enterprise_64-bit" edition="sp1_beta_1" />
        <vers num="r2" edition="" />
        <vers num="r2" edition=":datacenter_64-bit" />
        <vers num="r2" edition=":64-bit" />
        <vers num="r2" edition="sp1_beta_1" />
        <vers num="standard" edition="" />
        <vers num="standard" edition=":64-bit" />
        <vers num="standard" edition="sp1_beta_1" />
        <vers num="web" edition="sp1_beta_1" />
      </prod>
      <prod vendor="microsoft" name="windows_nt">
        <vers num="4.0" edition="" />
        <vers num="4.0" edition=":server" />
        <vers num="4.0" edition=":enterprise_server" />
        <vers num="4.0" edition=":terminal_server" />
        <vers num="4.0" edition=":workstation" />
        <vers num="4.0" edition="sp1" />
        <vers num="4.0" edition="sp1:server" />
        <vers num="4.0" edition="sp1:workstation" />
        <vers num="4.0" edition="sp1:terminal_server" />
        <vers num="4.0" edition="sp1:enterprise_server" />
        <vers num="4.0" edition="sp2" />
        <vers num="4.0" edition="sp2:enterprise_server" />
        <vers num="4.0" edition="sp2:server" />
        <vers num="4.0" edition="sp2:workstation" />
        <vers num="4.0" edition="sp2:terminal_server" />
        <vers num="4.0" edition="sp3" />
        <vers num="4.0" edition="sp3:workstation" />
        <vers num="4.0" edition="sp3:server" />
        <vers num="4.0" edition="sp3:terminal_server" />
        <vers num="4.0" edition="sp3:enterprise_server" />
        <vers num="4.0" edition="sp4" />
        <vers num="4.0" edition="sp4:workstation" />
        <vers num="4.0" edition="sp4:enterprise_server" />
        <vers num="4.0" edition="sp4:terminal_server" />
        <vers num="4.0" edition="sp4:server" />
        <vers num="4.0" edition="sp5" />
        <vers num="4.0" edition="sp5:workstation" />
        <vers num="4.0" edition="sp5:enterprise_server" />
        <vers num="4.0" edition="sp5:server" />
        <vers num="4.0" edition="sp5:terminal_server" />
        <vers num="4.0" edition="sp6" />
        <vers num="4.0" edition="sp6:terminal_server" />
        <vers num="4.0" edition="sp6:server" />
        <vers num="4.0" edition="sp6:enterprise_server" />
        <vers num="4.0" edition="sp6:workstation" />
        <vers num="4.0" edition="sp6a" />
        <vers num="4.0" edition="sp6a:server" />
        <vers num="4.0" edition="sp6a:enterprise_server" />
        <vers num="4.0" edition="sp6a:workstation" />
      </prod>
      <prod vendor="microsoft" name="windows_xp">
        <vers num="" edition=":home" />
        <vers num="" edition=":64-bit" />
        <vers num="" edition=":media_center" />
        <vers num="" edition="gold" />
        <vers num="" edition="gold:professional" />
        <vers num="" edition="sp1" />
        <vers num="" edition="sp1:home" />
        <vers num="" edition="sp1:media_center" />
        <vers num="" edition="sp1:64-bit" />
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:home" />
        <vers num="" edition="sp2:media_center" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0894" published="2005-01-10" name="CVE-2004-0894" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">LSASS (Local Security Authority Subsystem Service) of Windows 2000 Server and Windows Server 2003 does not properly validate connection information, which allows local users to gain privileges via a specially-designed program.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" admin="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms04-044.asp" source="MS" patch="1" adv="1">MS04-044</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/18340" source="XF">win-lsass-gain-privileges(18340)</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:778" source="OVAL" sig="1">oval:org.mitre.oval:def:778</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:4368" source="OVAL" sig="1">oval:org.mitre.oval:def:4368</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:3325" source="OVAL" sig="1">oval:org.mitre.oval:def:3325</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:3312" source="OVAL" sig="1">oval:org.mitre.oval:def:3312</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2062" source="OVAL" sig="1">oval:org.mitre.oval:def:2062</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1888" source="OVAL" sig="1">oval:org.mitre.oval:def:1888</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_2000">
        <vers num="" edition=":advanced_server" />
        <vers num="" edition=":professional" />
        <vers num="" edition=":datacenter_server" />
        <vers num="" edition=":server" />
        <vers num="" edition="sp1" />
        <vers num="" edition="sp1:datacenter_server" />
        <vers num="" edition="sp1:professional" />
        <vers num="" edition="sp1:server" />
        <vers num="" edition="sp1:advanced_server" />
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:advanced_server" />
        <vers num="" edition="sp2:professional" />
        <vers num="" edition="sp2:datacenter_server" />
        <vers num="" edition="sp2:server" />
        <vers num="" edition="sp3" />
        <vers num="" edition="sp3:datacenter_server" />
        <vers num="" edition="sp3:server" />
        <vers num="" edition="sp3:professional" />
        <vers num="" edition="sp3:advanced_server" />
        <vers num="" edition="sp4" />
        <vers num="" edition="sp4:server" />
        <vers num="" edition="sp4:datacenter_server" />
        <vers num="" edition="sp4:professional" />
        <vers num="" edition="sp4:advanced_server" />
      </prod>
      <prod vendor="microsoft" name="windows_2003_server">
        <vers num="datacenter_64-bit" edition="sp1_beta_1" />
        <vers num="enterprise" edition="" />
        <vers num="enterprise" edition=":64-bit" />
        <vers num="enterprise" edition="sp1_beta_1" />
        <vers num="enterprise_64-bit" edition="sp1_beta_1" />
        <vers num="r2" edition="" />
        <vers num="r2" edition=":64-bit" />
        <vers num="r2" edition=":datacenter_64-bit" />
        <vers num="r2" edition="sp1_beta_1" />
        <vers num="standard" edition="" />
        <vers num="standard" edition=":64-bit" />
        <vers num="standard" edition="sp1_beta_1" />
        <vers num="web" edition="sp1_beta_1" />
      </prod>
      <prod vendor="microsoft" name="windows_xp">
        <vers num="" edition=":media_center" />
        <vers num="" edition=":home" />
        <vers num="" edition=":64-bit" />
        <vers num="" edition="gold" />
        <vers num="" edition="gold:professional" />
        <vers num="" edition="sp1" />
        <vers num="" edition="sp1:64-bit" />
        <vers num="" edition="sp1:home" />
        <vers num="" edition="sp1:media_center" />
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:home" />
        <vers num="" edition="sp2:media_center" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0897" published="2005-01-11" name="CVE-2004-0897" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">The Indexing Service for Microsoft Windows XP and Server 2003 does not properly validate the length of a message, which allows remote attackers to execute arbitrary code via a buffer overflow attack.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/657118" source="CERT-VN" patch="1" adv="1">VU#657118</ref>
      <ref url="http://www.microsoft.com/technet/Security/bulletin/ms05-003.mspx" source="MS" patch="1" adv="1">MS05-003</ref>
      <ref url="http://www.ciac.org/ciac/bulletins/p-095.shtml" source="CIAC" adv="1">P-095</ref>
      <ref url="http://www.securityfocus.com/bid/12228" source="BID">12228</ref>
      <ref url="http://securitytracker.com/id?1012833" source="SECTRACK">1012833</ref>
      <ref url="http://secunia.com/advisories/13802" source="SECUNIA">13802</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2447" source="OVAL" sig="1">oval:org.mitre.oval:def:2447</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2128" source="OVAL" sig="1">oval:org.mitre.oval:def:2128</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_2003_server">
        <vers num="r2" />
      </prod>
      <prod vendor="microsoft" name="windows_xp">
        <vers num="" edition="gold" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0899" published="2005-01-10" name="CVE-2004-0899" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The DHCP Server service for Microsoft Windows NT 4.0 Server and Terminal Server Edition, with DHCP logging enabled, does not properly validate the length of certain messages, which allows remote attackers to cause a denial of service (application crash) via a malformed DHCP message, aka "Logging Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input bound="1" />
      <config />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms04-042.asp" source="MS" patch="1" adv="1">MS04-042</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/18341" source="XF">winnt-dhcp-machinename-dos(18341)</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:4282" source="OVAL" sig="1">oval:org.mitre.oval:def:4282</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2280" source="OVAL" sig="1">oval:org.mitre.oval:def:2280</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_nt">
        <vers num="4.0" edition="" />
        <vers num="4.0" edition=":terminal_server" />
        <vers num="4.0" edition=":server" />
        <vers num="4.0" edition=":enterprise_server" />
        <vers num="4.0" edition=":alpha" />
        <vers num="4.0" edition=":terminal_server_alpha" />
        <vers num="4.0" edition="sp1" />
        <vers num="4.0" edition="sp1:server" />
        <vers num="4.0" edition="sp1:enterprise_server" />
        <vers num="4.0" edition="sp1:alpha" />
        <vers num="4.0" edition="sp1:terminal_server" />
        <vers num="4.0" edition="sp2" />
        <vers num="4.0" edition="sp2:alpha" />
        <vers num="4.0" edition="sp2:enterprise_server" />
        <vers num="4.0" edition="sp2:server" />
        <vers num="4.0" edition="sp2:terminal_server" />
        <vers num="4.0" edition="sp3" />
        <vers num="4.0" edition="sp3:alpha" />
        <vers num="4.0" edition="sp3:enterprise_server" />
        <vers num="4.0" edition="sp3:server" />
        <vers num="4.0" edition="sp3:terminal_server" />
        <vers num="4.0" edition="sp4" />
        <vers num="4.0" edition="sp4:alpha" />
        <vers num="4.0" edition="sp4:enterprise_server" />
        <vers num="4.0" edition="sp4:terminal_server" />
        <vers num="4.0" edition="sp4:server" />
        <vers num="4.0" edition="sp5" />
        <vers num="4.0" edition="sp5:alpha" />
        <vers num="4.0" edition="sp5:enterprise_server" />
        <vers num="4.0" edition="sp5:server" />
        <vers num="4.0" edition="sp5:terminal_server" />
        <vers num="4.0" edition="sp6" />
        <vers num="4.0" edition="sp6:alpha" />
        <vers num="4.0" edition="sp6:enterprise_server" />
        <vers num="4.0" edition="sp6:terminal_server" />
        <vers num="4.0" edition="sp6:server" />
        <vers num="4.0" edition="sp6a" />
        <vers num="4.0" edition="sp6a:enterprise_server" />
        <vers num="4.0" edition="sp6a:server" />
        <vers num="4.0" edition="sp6a:alpha" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0900" published="2005-01-10" name="CVE-2004-0900" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">The DHCP Server service for Microsoft Windows NT 4.0 Server and Terminal Server Edition does not properly validate the length of certain messages, which allows remote attackers to execute arbitrary code via a malformed DHCP message, aka the "DHCP Request Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms04-042.asp" source="MS" patch="1" adv="1">MS04-042</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/18342" source="XF">winnt-dhcp-hardwareaddress-code-execution(18342)</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:4846" source="OVAL" sig="1">oval:org.mitre.oval:def:4846</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:3577" source="OVAL" sig="1">oval:org.mitre.oval:def:3577</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_nt">
        <vers num="4.0" edition="" />
        <vers num="4.0" edition=":terminal_server" />
        <vers num="4.0" edition=":server" />
        <vers num="4.0" edition=":enterprise_server" />
        <vers num="4.0" edition=":alpha" />
        <vers num="4.0" edition=":terminal_server_alpha" />
        <vers num="4.0" edition="sp1" />
        <vers num="4.0" edition="sp1:server" />
        <vers num="4.0" edition="sp1:enterprise_server" />
        <vers num="4.0" edition="sp1:alpha" />
        <vers num="4.0" edition="sp1:terminal_server" />
        <vers num="4.0" edition="sp2" />
        <vers num="4.0" edition="sp2:alpha" />
        <vers num="4.0" edition="sp2:enterprise_server" />
        <vers num="4.0" edition="sp2:server" />
        <vers num="4.0" edition="sp2:terminal_server" />
        <vers num="4.0" edition="sp3" />
        <vers num="4.0" edition="sp3:alpha" />
        <vers num="4.0" edition="sp3:enterprise_server" />
        <vers num="4.0" edition="sp3:server" />
        <vers num="4.0" edition="sp3:terminal_server" />
        <vers num="4.0" edition="sp4" />
        <vers num="4.0" edition="sp4:alpha" />
        <vers num="4.0" edition="sp4:enterprise_server" />
        <vers num="4.0" edition="sp4:terminal_server" />
        <vers num="4.0" edition="sp4:server" />
        <vers num="4.0" edition="sp5" />
        <vers num="4.0" edition="sp5:alpha" />
        <vers num="4.0" edition="sp5:enterprise_server" />
        <vers num="4.0" edition="sp5:server" />
        <vers num="4.0" edition="sp5:terminal_server" />
        <vers num="4.0" edition="sp6" />
        <vers num="4.0" edition="sp6:alpha" />
        <vers num="4.0" edition="sp6:enterprise_server" />
        <vers num="4.0" edition="sp6:terminal_server" />
        <vers num="4.0" edition="sp6:server" />
        <vers num="4.0" edition="sp6a" />
        <vers num="4.0" edition="sp6a:enterprise_server" />
        <vers num="4.0" edition="sp6a:server" />
        <vers num="4.0" edition="sp6a:alpha" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0901" published="2005-01-10" name="CVE-2004-0901" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Microsoft Word for Windows 6.0 Converter (MSWRD632.WPC), as used in WordPad, does not properly validate certain data lengths, which allows remote attackers to execute arbitrary code via a .wri, .rtf, and .doc file sent by email or malicious web site, aka "Font Conversion Vulnerability," a different vulnerability than CVE-2004-0571.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms04-041.asp" source="MS" patch="1" adv="1">MS04-041</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/18338" source="XF">win-converter-font-code-execution(18338)</ref>
      <ref url="http://www.ciac.org/ciac/bulletins/p-055.shtml" source="CIAC">P-055</ref>
      <ref url="http://www.idefense.com/application/poi/display?id=162&amp;type=vulnerabilities&amp;flashstatus=true" source="IDEFENSE">20041214 Microsoft Word 6.0/95 Document Converter Buffer Overflow Vulnerability</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:539" source="OVAL" sig="1">oval:org.mitre.oval:def:539</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:4749" source="OVAL" sig="1">oval:org.mitre.oval:def:4749</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:4576" source="OVAL" sig="1">oval:org.mitre.oval:def:4576</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:4076" source="OVAL" sig="1">oval:org.mitre.oval:def:4076</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:3882" source="OVAL" sig="1">oval:org.mitre.oval:def:3882</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:3310" source="OVAL" sig="1">oval:org.mitre.oval:def:3310</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1655" source="OVAL" sig="1">oval:org.mitre.oval:def:1655</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1241" source="OVAL" sig="1">oval:org.mitre.oval:def:1241</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_2000">
        <vers num="" edition=":professional" />
        <vers num="" edition=":server" />
        <vers num="" edition=":advanced_server" />
        <vers num="" edition=":datacenter_server" />
        <vers num="" edition="sp1" />
        <vers num="" edition="sp1:datacenter_server" />
        <vers num="" edition="sp1:professional" />
        <vers num="" edition="sp1:server" />
        <vers num="" edition="sp1:advanced_server" />
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:advanced_server" />
        <vers num="" edition="sp2:professional" />
        <vers num="" edition="sp2:datacenter_server" />
        <vers num="" edition="sp2:server" />
        <vers num="" edition="sp3" />
        <vers num="" edition="sp3:datacenter_server" />
        <vers num="" edition="sp3:server" />
        <vers num="" edition="sp3:professional" />
        <vers num="" edition="sp3:advanced_server" />
        <vers num="" edition="sp4" />
        <vers num="" edition="sp4:datacenter_server" />
        <vers num="" edition="sp4:server" />
        <vers num="" edition="sp4:professional" />
        <vers num="" edition="sp4:advanced_server" />
      </prod>
      <prod vendor="microsoft" name="windows_2003_server">
        <vers num="enterprise" edition="" />
        <vers num="enterprise" edition=":64-bit" />
        <vers num="enterprise_64-bit" />
        <vers num="r2" edition="" />
        <vers num="r2" edition=":datacenter_64-bit" />
        <vers num="r2" edition=":64-bit" />
        <vers num="standard" edition="" />
        <vers num="standard" edition=":64-bit" />
        <vers num="web" />
      </prod>
      <prod vendor="microsoft" name="windows_98">
        <vers num="" edition="gold" />
      </prod>
      <prod vendor="microsoft" name="windows_98se">
        <vers num="" />
      </prod>
      <prod vendor="microsoft" name="windows_me">
        <vers num="" />
      </prod>
      <prod vendor="microsoft" name="windows_nt">
        <vers num="4.0" edition="" />
        <vers num="4.0" edition=":server" />
        <vers num="4.0" edition=":enterprise_server" />
        <vers num="4.0" edition=":terminal_server" />
        <vers num="4.0" edition=":workstation" />
        <vers num="4.0" edition="sp1" />
        <vers num="4.0" edition="sp1:server" />
        <vers num="4.0" edition="sp1:workstation" />
        <vers num="4.0" edition="sp1:terminal_server" />
        <vers num="4.0" edition="sp1:enterprise_server" />
        <vers num="4.0" edition="sp2" />
        <vers num="4.0" edition="sp2:enterprise_server" />
        <vers num="4.0" edition="sp2:server" />
        <vers num="4.0" edition="sp2:workstation" />
        <vers num="4.0" edition="sp2:terminal_server" />
        <vers num="4.0" edition="sp3" />
        <vers num="4.0" edition="sp3:workstation" />
        <vers num="4.0" edition="sp3:server" />
        <vers num="4.0" edition="sp3:terminal_server" />
        <vers num="4.0" edition="sp3:enterprise_server" />
        <vers num="4.0" edition="sp4" />
        <vers num="4.0" edition="sp4:workstation" />
        <vers num="4.0" edition="sp4:enterprise_server" />
        <vers num="4.0" edition="sp4:terminal_server" />
        <vers num="4.0" edition="sp4:server" />
        <vers num="4.0" edition="sp5" />
        <vers num="4.0" edition="sp5:workstation" />
        <vers num="4.0" edition="sp5:enterprise_server" />
        <vers num="4.0" edition="sp5:server" />
        <vers num="4.0" edition="sp5:terminal_server" />
        <vers num="4.0" edition="sp6" />
        <vers num="4.0" edition="sp6:terminal_server" />
        <vers num="4.0" edition="sp6:server" />
        <vers num="4.0" edition="sp6:enterprise_server" />
        <vers num="4.0" edition="sp6:workstation" />
        <vers num="4.0" edition="sp6a" />
        <vers num="4.0" edition="sp6a:server" />
        <vers num="4.0" edition="sp6a:enterprise_server" />
        <vers num="4.0" edition="sp6a:workstation" />
      </prod>
      <prod vendor="microsoft" name="windows_xp">
        <vers num="" edition=":home" />
        <vers num="" edition=":64-bit" />
        <vers num="" edition="gold" />
        <vers num="" edition="gold:professional" />
        <vers num="" edition="sp1" />
        <vers num="" edition="sp1:home" />
        <vers num="" edition="sp1:64-bit" />
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:home" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0902" published="2005-01-27" name="CVE-2004-0902" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Multiple heap-based buffer overflows in Mozilla Firefox before the Preview Release, Mozilla before 1.7.3, and Thunderbird before 0.8 allow remote attackers to cause a denial of service (application crash) or execute arbitrary code via (1) the "Send page" functionality, (2) certain responses from a malicious POP3 server, or (3) a link containing a non-ASCII hostname.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA04-261A.html" source="CERT" patch="1" adv="1">TA04-261A</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/17379" source="XF" adv="1">mozilla-nspop3protocol-bo(17379)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/17378" source="XF">mozilla-netscape-nonascii-bo(17378)</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2004_36_mozilla.html" source="SUSE">SUSE-SA:2004:036</ref>
      <ref url="http://www.mozilla.org/projects/security/known-vulnerabilities.html#mozilla1.7.3" source="CONFIRM">http://www.mozilla.org/projects/security/known-vulnerabilities.html#mozilla1.7.3</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200409-26.xml" source="GENTOO">GLSA-200409-26</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11201" source="OVAL">oval:org.mitre.oval:def:11201</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109900315219363&amp;w=2" source="FEDORA">FLSA:2089</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109698896104418&amp;w=2" source="HP">SSRT4826</ref>
      <ref url="http://bugzilla.mozilla.org/show_bug.cgi?id=258005" source="CONFIRM">http://bugzilla.mozilla.org/show_bug.cgi?id=258005</ref>
      <ref url="http://bugzilla.mozilla.org/show_bug.cgi?id=256316" source="CONFIRM">http://bugzilla.mozilla.org/show_bug.cgi?id=256316</ref>
      <ref url="http://bugzilla.mozilla.org/show_bug.cgi?id=245066" source="CONFIRM">http://bugzilla.mozilla.org/show_bug.cgi?id=245066</ref>
      <ref url="http://bugzilla.mozilla.org/show_bug.cgi?id=226669" source="CONFIRM">http://bugzilla.mozilla.org/show_bug.cgi?id=226669</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="mozilla">
        <vers num="1.7" />
        <vers num="1.7.1" />
        <vers num="1.7.2" />
      </prod>
      <prod vendor="mozilla" name="thunderbird">
        <vers num="0.7" />
        <vers num="0.7.1" />
        <vers num="0.7.2" />
        <vers num="0.7.3" />
      </prod>
      <prod vendor="conectiva" name="linux">
        <vers num="10.0" />
        <vers num="9.0" />
      </prod>
      <prod vendor="redhat" name="enterprise_linux">
        <vers num="2.1" edition="" />
        <vers num="2.1" edition=":workstation_ia64" />
        <vers num="2.1" edition=":advanced_server" />
        <vers num="2.1" edition=":enterprise_server" />
        <vers num="2.1" edition=":advanced_server_ia64" />
        <vers num="2.1" edition=":workstation" />
        <vers num="2.1" edition=":enterprise_server_ia64" />
        <vers num="3.0" edition="" />
        <vers num="3.0" edition=":advanced_server" />
        <vers num="3.0" edition=":workstation_server" />
        <vers num="3.0" edition=":enterprise_server" />
      </prod>
      <prod vendor="redhat" name="enterprise_linux_desktop">
        <vers num="3.0" />
      </prod>
      <prod vendor="redhat" name="fedora_core">
        <vers num="core_1.0" />
      </prod>
      <prod vendor="redhat" name="linux">
        <vers num="7.3" edition="" />
        <vers num="7.3" edition=":i386" />
        <vers num="7.3" edition=":i686" />
        <vers num="9.0" edition="" />
        <vers num="9.0" edition=":i386" />
      </prod>
      <prod vendor="redhat" name="linux_advanced_workstation">
        <vers num="2.1" edition="" />
        <vers num="2.1" edition=":itanium_processor" />
        <vers num="2.1" edition=":ia64" />
      </prod>
      <prod vendor="suse" name="suse_linux">
        <vers num="1.0" edition="" />
        <vers num="1.0" edition=":desktop" />
        <vers num="8" edition="" />
        <vers num="8" edition=":enterprise_server" />
        <vers num="8.1" />
        <vers num="8.2" />
        <vers num="9.0" edition="" />
        <vers num="9.0" edition=":enterprise_server" />
        <vers num="9.0" edition=":x86_64" />
        <vers num="9.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0903" published="2005-01-27" name="CVE-2004-0903" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Stack-based buffer overflow in the writeGroup function in nsVCardObj.cpp for Mozilla Firefox before the Preview Release, Mozilla before 1.7.3, and Thunderbird before 0.8 allows remote attackers to execute arbitrary code via malformed VCard attachments that are not properly handled when previewing a message.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA04-261A.html" source="CERT">TA04-261A</ref>
      <ref url="http://www.kb.cert.org/vuls/id/414240" source="CERT-VN" adv="1">VU#414240</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/17380" source="XF" adv="1">mozilla-netscape-nsvcardobj-bo(17380)</ref>
      <ref url="http://www.securityfocus.com/bid/11174" source="BID" adv="1">11174</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2004_36_mozilla.html" source="SUSE">SUSE-SA:2004:036</ref>
      <ref url="http://www.mozilla.org/projects/security/known-vulnerabilities.html#mozilla1.7.3" source="CONFIRM">http://www.mozilla.org/projects/security/known-vulnerabilities.html#mozilla1.7.3</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200409-26.xml" source="GENTOO">GLSA-200409-26</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10873" source="OVAL">oval:org.mitre.oval:def:10873</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109900315219363&amp;w=2" source="FEDORA">FLSA:2089</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109698896104418&amp;w=2" source="HP">SSRT4826</ref>
      <ref url="http://bugzilla.mozilla.org/show_bug.cgi?id=257314" source="CONFIRM" adv="1">http://bugzilla.mozilla.org/show_bug.cgi?id=257314</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="mozilla">
        <vers num="1.7" />
        <vers num="1.7.1" />
        <vers num="1.7.2" />
      </prod>
      <prod vendor="mozilla" name="thunderbird">
        <vers num="0.7" />
        <vers num="0.7.1" />
        <vers num="0.7.2" />
        <vers num="0.7.3" />
      </prod>
      <prod vendor="conectiva" name="linux">
        <vers num="10.0" />
        <vers num="9.0" />
      </prod>
      <prod vendor="redhat" name="enterprise_linux">
        <vers num="2.1" edition="" />
        <vers num="2.1" edition=":workstation_ia64" />
        <vers num="2.1" edition=":advanced_server" />
        <vers num="2.1" edition=":enterprise_server" />
        <vers num="2.1" edition=":advanced_server_ia64" />
        <vers num="2.1" edition=":workstation" />
        <vers num="2.1" edition=":enterprise_server_ia64" />
        <vers num="3.0" edition="" />
        <vers num="3.0" edition=":advanced_server" />
        <vers num="3.0" edition=":workstation_server" />
        <vers num="3.0" edition=":enterprise_server" />
      </prod>
      <prod vendor="redhat" name="enterprise_linux_desktop">
        <vers num="3.0" />
      </prod>
      <prod vendor="redhat" name="fedora_core">
        <vers num="core_1.0" />
      </prod>
      <prod vendor="redhat" name="linux">
        <vers num="7.3" edition="" />
        <vers num="7.3" edition=":i386" />
        <vers num="7.3" edition=":i686" />
        <vers num="9.0" edition="" />
        <vers num="9.0" edition=":i386" />
      </prod>
      <prod vendor="redhat" name="linux_advanced_workstation">
        <vers num="2.1" edition="" />
        <vers num="2.1" edition=":itanium_processor" />
        <vers num="2.1" edition=":ia64" />
      </prod>
      <prod vendor="suse" name="suse_linux">
        <vers num="1.0" edition="" />
        <vers num="1.0" edition=":desktop" />
        <vers num="8" edition="" />
        <vers num="8" edition=":enterprise_server" />
        <vers num="8.1" />
        <vers num="8.2" />
        <vers num="9.0" edition="" />
        <vers num="9.0" edition=":enterprise_server" />
        <vers num="9.0" edition=":x86_64" />
        <vers num="9.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0904" published="2004-12-31" name="CVE-2004-0904" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Integer overflow in the bitmap (BMP) decoder for Mozilla Firefox before the Preview Release, Mozilla before 1.7.3, and Thunderbird before 0.8 allow remote attackers to execute arbitrary code via wide bitmap files that trigger heap-based buffer overflows.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA04-261A.html" source="CERT">TA04-261A</ref>
      <ref url="http://www.kb.cert.org/vuls/id/847200" source="CERT-VN" adv="1">VU#847200</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/17381" source="XF" adv="1">mozilla-netscape-bmp-bo(17381)</ref>
      <ref url="http://www.securityfocus.com/bid/11171" source="BID" adv="1">11171</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2004_36_mozilla.html" source="SUSE">SUSE-SA:2004:036</ref>
      <ref url="http://www.mozilla.org/projects/security/known-vulnerabilities.html#mozilla1.7.3" source="CONFIRM">http://www.mozilla.org/projects/security/known-vulnerabilities.html#mozilla1.7.3</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200409-26.xml" source="GENTOO">GLSA-200409-26</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10952" source="OVAL">oval:org.mitre.oval:def:10952</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109900315219363&amp;w=2" source="FEDORA">FLSA:2089</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109698896104418&amp;w=2" source="HP">SSRT4826</ref>
      <ref url="http://bugzilla.mozilla.org/show_bug.cgi?id=255067" source="CONFIRM" adv="1">http://bugzilla.mozilla.org/show_bug.cgi?id=255067</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="firefox">
        <vers num="0.8" />
        <vers num="0.9" edition="rc" />
        <vers num="0.9.1" />
        <vers num="0.9.2" />
        <vers num="0.9.3" />
      </prod>
      <prod vendor="mozilla" name="mozilla">
        <vers num="1.7" edition="rc3" />
        <vers num="1.7.1" />
        <vers num="1.7.2" />
      </prod>
      <prod vendor="mozilla" name="thunderbird">
        <vers num="0.6" />
        <vers num="0.7" />
        <vers num="0.7.1" />
        <vers num="0.7.2" />
        <vers num="0.7.3" />
      </prod>
      <prod vendor="netscape" name="navigator">
        <vers num="7.0" />
        <vers num="7.0.2" />
        <vers num="7.1" />
        <vers num="7.2" />
      </prod>
      <prod vendor="conectiva" name="linux">
        <vers num="10.0" />
        <vers num="9.0" />
      </prod>
      <prod vendor="redhat" name="enterprise_linux">
        <vers num="2.1" edition="" />
        <vers num="2.1" edition=":workstation_ia64" />
        <vers num="2.1" edition=":advanced_server" />
        <vers num="2.1" edition=":enterprise_server" />
        <vers num="2.1" edition=":advanced_server_ia64" />
        <vers num="2.1" edition=":workstation" />
        <vers num="2.1" edition=":enterprise_server_ia64" />
        <vers num="3.0" edition="" />
        <vers num="3.0" edition=":advanced_server" />
        <vers num="3.0" edition=":workstation_server" />
        <vers num="3.0" edition=":enterprise_server" />
      </prod>
      <prod vendor="redhat" name="enterprise_linux_desktop">
        <vers num="3.0" />
      </prod>
      <prod vendor="redhat" name="fedora_core">
        <vers num="core_1.0" />
      </prod>
      <prod vendor="redhat" name="linux">
        <vers num="7.3" edition="" />
        <vers num="7.3" edition=":i386" />
        <vers num="7.3" edition=":i686" />
        <vers num="9.0" edition="" />
        <vers num="9.0" edition=":i386" />
      </prod>
      <prod vendor="redhat" name="linux_advanced_workstation">
        <vers num="2.1" edition="" />
        <vers num="2.1" edition=":itanium_processor" />
        <vers num="2.1" edition=":ia64" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0905" published="2004-09-14" name="CVE-2004-0905" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Mozilla Firefox before the Preview Release, Mozilla before 1.7.3, and Thunderbird before 0.8 allows remote attackers to perform cross-domain scripting and possibly execute arbitrary code by convincing a user to drag and drop javascript: links to a frame or page in another domain.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <local />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA04-261A.html" source="CERT" patch="1" adv="1">TA04-261A</ref>
      <ref url="http://www.kb.cert.org/vuls/id/651928" source="CERT-VN" patch="1" adv="1">VU#651928</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/17374" source="XF" patch="1" adv="1">mozilla-netscape-sameorigin-bypass(17374)</ref>
      <ref url="http://www.securityfocus.com/bid/11177" source="BID" patch="1" adv="1">11177</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2004_36_mozilla.html" source="SUSE" patch="1" adv="1">SUSE-SA:2004:036</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200409-26.xml" source="GENTOO" patch="1" adv="1">GLSA-200409-26</ref>
      <ref url="http://bugzilla.mozilla.org/show_bug.cgi?id=250862" source="CONFIRM" patch="1" adv="1">http://bugzilla.mozilla.org/show_bug.cgi?id=250862</ref>
      <ref url="http://www.mozilla.org/projects/security/known-vulnerabilities.html#mozilla1.7.3" source="CONFIRM" adv="1">http://www.mozilla.org/projects/security/known-vulnerabilities.html#mozilla1.7.3</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10378" source="OVAL">oval:org.mitre.oval:def:10378</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109900315219363&amp;w=2" source="FEDORA" adv="1">FLSA:2089</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109698896104418&amp;w=2" source="HP" adv="1">SSRT4826</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="firefox">
        <vers num="0.8" />
        <vers num="0.9" edition="rc" />
        <vers num="0.9.1" />
        <vers num="0.9.2" />
        <vers num="0.9.3" />
      </prod>
      <prod vendor="mozilla" name="mozilla">
        <vers num="1.0" edition="rc1" />
        <vers num="1.0" edition="rc2" />
        <vers num="1.0.1" />
        <vers num="1.0.2" />
        <vers num="1.1" edition="alpha" />
        <vers num="1.1" edition="beta" />
        <vers num="1.2" edition="alpha" />
        <vers num="1.2" edition="beta" />
        <vers num="1.2.1" />
        <vers num="1.3" />
        <vers num="1.3.1" />
        <vers num="1.4" edition="alpha" />
        <vers num="1.4" edition="beta" />
        <vers num="1.4.1" />
        <vers num="1.4.2" />
        <vers num="1.5" />
        <vers num="1.6" />
        <vers num="1.7" edition="rc3" />
        <vers num="1.7.1" />
        <vers num="1.7.2" />
      </prod>
      <prod vendor="netscape" name="navigator">
        <vers num="7.0" />
        <vers num="7.0.2" />
        <vers num="7.1" />
        <vers num="7.2" />
      </prod>
      <prod vendor="conectiva" name="linux">
        <vers num="10.0" />
        <vers num="9.0" />
      </prod>
      <prod vendor="redhat" name="enterprise_linux">
        <vers num="2.1" edition="" />
        <vers num="2.1" edition=":workstation_ia64" />
        <vers num="2.1" edition=":advanced_server" />
        <vers num="2.1" edition=":enterprise_server" />
        <vers num="2.1" edition=":advanced_server_ia64" />
        <vers num="2.1" edition=":enterprise_server_ia64" />
        <vers num="2.1" edition=":workstation" />
        <vers num="3.0" edition="" />
        <vers num="3.0" edition=":workstation_server" />
        <vers num="3.0" edition=":enterprise_server" />
        <vers num="3.0" edition=":advanced_server" />
      </prod>
      <prod vendor="redhat" name="enterprise_linux_desktop">
        <vers num="3.0" />
      </prod>
      <prod vendor="redhat" name="fedora_core">
        <vers num="core_1.0" />
      </prod>
      <prod vendor="redhat" name="linux">
        <vers num="7.3" edition="" />
        <vers num="7.3" edition=":i386" />
        <vers num="7.3" edition=":i686" />
        <vers num="9.0" edition="" />
        <vers num="9.0" edition=":i386" />
      </prod>
      <prod vendor="redhat" name="linux_advanced_workstation">
        <vers num="2.1" edition="" />
        <vers num="2.1" edition=":itanium_processor" />
        <vers num="2.1" edition=":ia64" />
      </prod>
      <prod vendor="suse" name="suse_linux">
        <vers num="1.0" edition="" />
        <vers num="1.0" edition=":desktop" />
        <vers num="8" edition="" />
        <vers num="8" edition=":enterprise_server" />
        <vers num="8.1" />
        <vers num="8.2" />
        <vers num="9.0" edition="" />
        <vers num="9.0" edition=":enterprise_server" />
        <vers num="9.0" edition=":x86_64" />
        <vers num="9.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0906" published="2004-12-31" name="CVE-2004-0906" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">The XPInstall installer in Mozilla Firefox before the Preview Release, Mozilla before 1.7.3, and Thunderbird before 0.8 sets insecure permissions for certain installed files within xpi packages, which could allow local users to overwrite arbitrary files or execute arbitrary code.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/653160" source="CERT-VN" adv="1">VU#653160</ref>
      <ref url="http://bugzilla.mozilla.org/show_bug.cgi?id=235781" source="CONFIRM" patch="1">http://bugzilla.mozilla.org/show_bug.cgi?id=235781</ref>
      <ref url="http://bugzilla.mozilla.org/show_bug.cgi?id=231083" source="CONFIRM" patch="1">http://bugzilla.mozilla.org/show_bug.cgi?id=231083</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/17375" source="XF">mozilla-insecure-file-permissions(17375)</ref>
      <ref url="http://www.securityfocus.com/bid/11192" source="BID">11192</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-323.html" source="REDHAT">RHSA-2005:323</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2004_36_mozilla.html" source="SUSE" adv="1">SUSE-SA:2004:036</ref>
      <ref url="http://www.mozilla.org/projects/security/known-vulnerabilities.html#mozilla1.7.3" source="CONFIRM">http://www.mozilla.org/projects/security/known-vulnerabilities.html#mozilla1.7.3</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200409-26.xml" source="GENTOO">GLSA-200409-26</ref>
      <ref url="http://secunia.com/advisories/12526/" source="SECUNIA">12526</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11668" source="OVAL">oval:org.mitre.oval:def:11668</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="mozilla">
        <vers num="0.8" />
        <vers num="0.9.2" />
        <vers num="0.9.2.1" />
        <vers num="0.9.3" />
        <vers num="0.9.35" />
        <vers num="0.9.4" />
        <vers num="0.9.4.1" />
        <vers num="0.9.48" />
        <vers num="0.9.5" />
        <vers num="0.9.6" />
        <vers num="0.9.7" />
        <vers num="0.9.8" />
        <vers num="0.9.9" />
        <vers num="1.0" edition="rc1" />
        <vers num="1.0" edition="rc2" />
        <vers num="1.0.1" />
        <vers num="1.0.2" />
        <vers num="1.1" edition="alpha" />
        <vers num="1.1" edition="beta" />
        <vers num="1.2" edition="alpha" />
        <vers num="1.2" edition="beta" />
        <vers num="1.2.1" />
        <vers num="1.3" />
        <vers num="1.3.1" />
        <vers num="1.4" edition="alpha" />
        <vers num="1.4" edition="beta" />
        <vers num="1.4.1" />
        <vers num="1.4.2" />
        <vers num="1.4.4" />
        <vers num="1.5" />
        <vers num="1.5.1" />
        <vers num="1.6" />
        <vers num="1.7" edition="alpha" />
        <vers num="1.7" edition="beta" />
        <vers num="1.7" edition="rc1" />
        <vers num="1.7" edition="rc2" />
        <vers num="1.7" edition="rc3" />
        <vers num="1.7.1" />
        <vers num="1.7.2" />
      </prod>
      <prod vendor="mozilla" name="thunderbird">
        <vers num="0.1" />
        <vers num="0.2" />
        <vers num="0.3" />
        <vers num="0.4" />
        <vers num="0.5" />
        <vers num="0.6" />
        <vers num="0.7" />
        <vers num="0.7.1" />
        <vers num="0.7.2" />
        <vers num="0.7.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0907" published="2004-12-31" name="CVE-2004-0907" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">The Linux install .tar.gz archives for Mozilla Firefox before the Preview Release, Mozilla before 1.7.3, and Thunderbird before 0.8, create certain files with insecure permissions, which could allow local users to overwrite those files and execute arbitrary code.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://bugzilla.mozilla.org/show_bug.cgi?id=254303" source="CONFIRM" patch="1">http://bugzilla.mozilla.org/show_bug.cgi?id=254303</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/17373" source="XF">mozilla-tar-insecure-permissions(17373)</ref>
      <ref url="http://www.mozilla.org/projects/security/known-vulnerabilities.html#mozilla1.7.3" source="CONFIRM">http://www.mozilla.org/projects/security/known-vulnerabilities.html#mozilla1.7.3</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200409-26.xml" source="GENTOO">GLSA-200409-26</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="mozilla">
        <vers num="0.8" />
        <vers num="0.9.2" />
        <vers num="0.9.2.1" />
        <vers num="0.9.3" />
        <vers num="0.9.35" />
        <vers num="0.9.4" />
        <vers num="0.9.4.1" />
        <vers num="0.9.48" />
        <vers num="0.9.5" />
        <vers num="0.9.6" />
        <vers num="0.9.7" />
        <vers num="0.9.8" />
        <vers num="0.9.9" />
        <vers num="1.0" edition="rc1" />
        <vers num="1.0" edition="rc2" />
        <vers num="1.0.1" />
        <vers num="1.0.2" />
        <vers num="1.1" edition="alpha" />
        <vers num="1.1" edition="beta" />
        <vers num="1.2" edition="alpha" />
        <vers num="1.2" edition="beta" />
        <vers num="1.2.1" />
        <vers num="1.3" />
        <vers num="1.3.1" />
        <vers num="1.4" edition="alpha" />
        <vers num="1.4" edition="beta" />
        <vers num="1.4.1" />
        <vers num="1.4.2" />
        <vers num="1.4.4" />
        <vers num="1.5" />
        <vers num="1.5.1" />
        <vers num="1.6" />
        <vers num="1.7" edition="alpha" />
        <vers num="1.7" edition="beta" />
        <vers num="1.7" edition="rc1" />
        <vers num="1.7" edition="rc2" />
        <vers num="1.7" edition="rc3" />
        <vers num="1.7.1" />
        <vers num="1.7.2" />
      </prod>
      <prod vendor="mozilla" name="thunderbird">
        <vers num="0.1" />
        <vers num="0.2" />
        <vers num="0.3" />
        <vers num="0.4" />
        <vers num="0.5" />
        <vers num="0.6" />
        <vers num="0.7" />
        <vers num="0.7.1" />
        <vers num="0.7.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0908" published="2004-12-31" name="CVE-2004-0908" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:N)" CVSS_score="4.0" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="4.9" CVSS_base_score="4.0">
    <desc>
      <descript source="cve">Mozilla Firefox before the Preview Release, Mozilla before 1.7.3, and Thunderbird before 0.8 allows untrusted Javascript code to read and write to the clipboard, and possibly obtain sensitive information, via script-generated events such as Ctrl-Ins.</descript>
    </desc>
    <loss_types>
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/460528" source="CERT-VN">VU#460528</ref>
      <ref url="http://www.securityfocus.com/bid/11179" source="BID" patch="1">11179</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2004_36_mozilla.html" source="SUSE" patch="1">SUSE-SA:2004:036</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109900315219363&amp;w=2" source="FEDORA" patch="1">FLSA:2089</ref>
      <ref url="http://bugzilla.mozilla.org/show_bug.cgi?id=257523" source="CONFIRM" patch="1">http://bugzilla.mozilla.org/show_bug.cgi?id=257523</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/17376" source="XF">mozilla-shortcut-clipboard-access(17376)</ref>
      <ref url="http://www.mozilla.org/projects/security/known-vulnerabilities.html#mozilla1.7.3" source="CONFIRM">http://www.mozilla.org/projects/security/known-vulnerabilities.html#mozilla1.7.3</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200409-26.xml" source="GENTOO">GLSA-200409-26</ref>
      <ref url="http://secunia.com/advisories/12526" source="SECUNIA">12526</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9745" source="OVAL">oval:org.mitre.oval:def:9745</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109698896104418&amp;w=2" source="HP">SSRT4826</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="mozilla">
        <vers num="0.8" />
        <vers num="0.9.2" />
        <vers num="0.9.2.1" />
        <vers num="0.9.3" />
        <vers num="0.9.35" />
        <vers num="0.9.4" />
        <vers num="0.9.4.1" />
        <vers num="0.9.48" />
        <vers num="0.9.5" />
        <vers num="0.9.6" />
        <vers num="0.9.7" />
        <vers num="0.9.8" />
        <vers num="0.9.9" />
        <vers num="1.0" edition="rc1" />
        <vers num="1.0" edition="rc2" />
        <vers num="1.0.1" />
        <vers num="1.0.2" />
        <vers num="1.1" edition="alpha" />
        <vers num="1.1" edition="beta" />
        <vers num="1.2" edition="alpha" />
        <vers num="1.2" edition="beta" />
        <vers num="1.2.1" />
        <vers num="1.3" />
        <vers num="1.3.1" />
        <vers num="1.4" edition="alpha" />
        <vers num="1.4" edition="beta" />
        <vers num="1.4.1" />
        <vers num="1.4.2" />
        <vers num="1.4.4" />
        <vers num="1.5" />
        <vers num="1.5.1" />
        <vers num="1.6" />
        <vers num="1.7" edition="alpha" />
        <vers num="1.7" edition="beta" />
        <vers num="1.7" edition="rc1" />
        <vers num="1.7" edition="rc2" />
        <vers num="1.7" edition="rc3" />
        <vers num="1.7.1" />
        <vers num="1.7.2" />
      </prod>
      <prod vendor="mozilla" name="thunderbird">
        <vers num="0.1" />
        <vers num="0.2" />
        <vers num="0.3" />
        <vers num="0.4" />
        <vers num="0.5" />
        <vers num="0.6" />
        <vers num="0.7" />
        <vers num="0.7.1" />
        <vers num="0.7.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0909" published="2004-12-31" name="CVE-2004-0909" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_score="5.1" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="4.9" CVSS_base_score="5.1">
    <desc>
      <descript source="cve">Mozilla Firefox before the Preview Release, Mozilla before 1.7.3, and Thunderbird before 0.8 may allow remote attackers to trick users into performing unexpected actions, including installing software, via signed scripts that request enhanced abilities using the enablePrivilege parameter, then modify the meaning of certain security-relevant dialog messages.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/113192" source="CERT-VN" adv="1">VU#113192</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/17377" source="XF">mozilla-enableprivilege-modify-dialog(17377)</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2004_36_mozilla.html" source="SUSE" adv="1">SUSE-SA:2004:036</ref>
      <ref url="http://www.mozilla.org/projects/security/known-vulnerabilities.html#mozilla1.7.3" source="CONFIRM">http://www.mozilla.org/projects/security/known-vulnerabilities.html#mozilla1.7.3</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200409-26.xml" source="GENTOO">GLSA-200409-26</ref>
      <ref url="http://secunia.com/advisories/12526" source="SECUNIA">12526</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109698896104418&amp;w=2" source="HP">SSRT4826</ref>
      <ref url="http://bugzilla.mozilla.org/show_bug.cgi?id=253942" source="CONFIRM">http://bugzilla.mozilla.org/show_bug.cgi?id=253942</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="mozilla">
        <vers num="0.8" />
        <vers num="0.9.2" />
        <vers num="0.9.2.1" />
        <vers num="0.9.3" />
        <vers num="0.9.35" />
        <vers num="0.9.4" />
        <vers num="0.9.4.1" />
        <vers num="0.9.48" />
        <vers num="0.9.5" />
        <vers num="0.9.6" />
        <vers num="0.9.7" />
        <vers num="0.9.8" />
        <vers num="0.9.9" />
        <vers num="1.0" edition="rc1" />
        <vers num="1.0" edition="rc2" />
        <vers num="1.0.1" />
        <vers num="1.0.2" />
        <vers num="1.1" edition="alpha" />
        <vers num="1.1" edition="beta" />
        <vers num="1.2" edition="alpha" />
        <vers num="1.2" edition="beta" />
        <vers num="1.2.1" />
        <vers num="1.3" />
        <vers num="1.3.1" />
        <vers num="1.4" edition="alpha" />
        <vers num="1.4" edition="beta" />
        <vers num="1.4.1" />
        <vers num="1.4.2" />
        <vers num="1.4.4" />
        <vers num="1.5" />
        <vers num="1.5.1" />
        <vers num="1.6" />
        <vers num="1.7" edition="alpha" />
        <vers num="1.7" edition="beta" />
        <vers num="1.7" edition="rc1" />
        <vers num="1.7" edition="rc2" />
        <vers num="1.7" edition="rc3" />
        <vers num="1.7.1" />
        <vers num="1.7.2" />
      </prod>
      <prod vendor="mozilla" name="thunderbird">
        <vers num="0.1" />
        <vers num="0.2" />
        <vers num="0.3" />
        <vers num="0.4" />
        <vers num="0.5" />
        <vers num="0.6" />
        <vers num="0.7" />
        <vers num="0.7.1" />
        <vers num="0.7.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" seq="2004-0910" reject="1" published="2004-11-03" name="CVE-2004-0910" modified="2008-09-10">
    <desc>
      <descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: CVE-2004-0815.  Reason: This candidate is a reservation duplicate of CVE-2004-0815.  Notes: All CVE users should reference CVE-2004-0815 instead of this candidate.  All references and descriptions in this candidate have been removed to prevent accidental usage.</descript>
    </desc>
    <refs />
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0911" published="2004-11-03" name="CVE-2004-0911" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">telnetd for netkit 0.17 and earlier, and possibly other versions, on Debian GNU/Linux allows remote attackers to cause a denial of service (free of an invalid pointer), a different vulnerability than CVE-2001-0554.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/17540" source="XF" patch="1" adv="1">telnetd-netkit-bo(17540)</ref>
      <ref url="http://www.securityfocus.com/archive/1/375743" source="BUGTRAQ" patch="1" adv="1">20040918 Debian netkit telnetd vulnerability</ref>
      <ref url="http://www.debian.org/security/2004/dsa-556" source="DEBIAN" patch="1" adv="1">DSA-556</ref>
      <ref url="http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=273694" source="CONFIRM">http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=273694</ref>
    </refs>
    <vuln_soft>
      <prod vendor="debian" name="netkit">
        <vers prev="1" num="0.17" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0913" published="2004-12-31" name="CVE-2004-0913" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Unknown vulnerability in ecartis 0.x before 0.129a+1.0.0-snap20020514-1.3 and 1.x before 1.0.0+cvs.20030911-8 allows attackers in the same domain to gain administrator privileges and modify configuration.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <other />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/11487" source="BID" patch="1">11487</ref>
      <ref url="http://www.debian.org/security/2004/dsa-572" source="DEBIAN" patch="1">DSA-572</ref>
      <ref url="http://www.auscert.org.au/render.html?it=4491" source="AUSCERT" patch="1">ESB-2004.0669</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/17809" source="XF">ecartis-gain-privileges(17809)</ref>
      <ref url="http://secunia.com/advisories/12918/" source="SECUNIA">12918</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ecartis" name="ecartis">
        <vers num="0.129a" />
        <vers num="1.0.0_snapshot_2002-01-21" />
        <vers num="1.0.0_snapshot_2002-01-25" />
        <vers num="1.0.0_snapshot_2002-04-27" />
        <vers num="1.0.0_snapshot_2002-05-14" />
        <vers num="1.0.0_snapshot_2002-10-13" />
        <vers num="1.0.0_snapshot_2003-02-27" />
        <vers num="1.0.0_snapshot_2003-03-03" />
        <vers num="1.0.0_snapshot_2003-03-09" />
        <vers num="1.0.0_snapshot_2003-03-12" />
        <vers num="1.0.0_snapshot_2003-03-18" />
        <vers num="1.0.0_snapshot_2003-04-16" />
        <vers num="1.0.0_snapshot_2003-04-17" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0914" published="2005-01-10" name="CVE-2004-0914" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Multiple vulnerabilities in libXpm for 6.8.1 and earlier, as used in XFree86 and other packages, include (1) multiple integer overflows, (2) out-of-bounds memory accesses, (3) directory traversal, (4) shell metacharacter, (5) endless loops, and (6) memory leaks, which could allow remote attackers to obtain sensitive information, cause a denial of service (application crash), or execute arbitrary code via a certain XPM image file. NOTE: it is highly likely that this candidate will be SPLIT into other candidates in the future, per CVE's content decisions.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" admin="1" />
    </loss_types>
    <vuln_types>
      <input bound="1" />
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/11694" source="BID" patch="1" adv="1">11694</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200411-28.xml" source="GENTOO" patch="1" adv="1">GLSA-200411-28</ref>
      <ref url="http://www.debian.org/security/2004/dsa-607" source="DEBIAN" patch="1" adv="1">DSA-607</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/18147" source="XF" adv="1">libxpm-dos(18147)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/18146" source="XF">libxpm-directory-traversal(18146):</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/18145" source="XF">libxpm-command-execution(18145):</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/18144" source="XF">libxpm-improper-memory-access(18144):</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/18142" source="XF">libxpm-image-bo(18142):</ref>
      <ref url="http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=HPSBTU01228" source="HP">HPSBTU01228</ref>
      <ref url="http://www.x.org/pub/X11R6.8.1/patches/README.xorg-681-CAN-2004-0914.patch" source="CONFIRM">http://www.x.org/pub/X11R6.8.1/patches/README.xorg-681-CAN-2004-0914.patch</ref>
      <ref url="http://www.ubuntu.com/usn/usn-83-2" source="UBUNTU">USN-83-2</ref>
      <ref url="http://www.ubuntu.com/usn/usn-83-1" source="UBUNTU">USN-83-1</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-004.html" source="REDHAT">RHSA-2005:004</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-610.html" source="REDHAT">RHSA-2004:610</ref>
      <ref url="http://www.redhat.com/archives/fedora-legacy-announce/2006-January/msg00001.html" source="FEDORA">FLSA-2006:152803</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2004:137" source="MANDRAKE">MDKSA-2004:137</ref>
      <ref url="http://www.linuxsecurity.com/content/view/106877/102/" source="FEDORA">FEDORA-2004-433</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200502-07.xml" source="GENTOO">GLSA-200502-07</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200502-06.xml" source="GENTOO">GLSA-200502-06</ref>
      <ref url="http://secunia.com/advisories/13224/" source="SECUNIA" adv="1">13224</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2004-537.html" source="REDHAT">RHSA-2004:537</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9943" source="OVAL">oval:org.mitre.oval:def:9943</ref>
    </refs>
    <vuln_soft>
      <prod vendor="lesstif" name="lesstif">
        <vers num="0.93" />
        <vers num="0.93.12" />
        <vers num="0.93.18" />
        <vers num="0.93.34" />
        <vers num="0.93.36" />
        <vers num="0.93.40" />
        <vers num="0.93.91" />
        <vers num="0.93.94" />
        <vers num="0.93.96" />
      </prod>
      <prod vendor="x.org" name="x11r6">
        <vers num="6.7.0" />
        <vers num="6.8" />
        <vers num="6.8.1" />
      </prod>
      <prod vendor="xfree86_project" name="x11r6">
        <vers num="3.3" />
        <vers num="3.3.2" />
        <vers num="3.3.3" />
        <vers num="3.3.4" />
        <vers num="3.3.5" />
        <vers num="3.3.6" />
        <vers num="4.0" />
        <vers num="4.0.1" />
        <vers num="4.0.2.11" />
        <vers num="4.0.3" />
        <vers num="4.1.0" />
        <vers num="4.1.11" />
        <vers num="4.1.12" />
        <vers num="4.2.0" />
        <vers num="4.2.1" edition="" />
        <vers num="4.2.1" edition=":errata" />
        <vers num="4.3.0" />
      </prod>
      <prod vendor="gentoo" name="linux">
        <vers num="" />
      </prod>
      <prod vendor="redhat" name="fedora_core">
        <vers num="core_2.0" />
        <vers num="core_3.0" />
      </prod>
      <prod vendor="suse" name="suse_linux">
        <vers num="1.0" edition="" />
        <vers num="1.0" edition=":desktop" />
        <vers num="8" edition="" />
        <vers num="8" edition=":enterprise_server" />
        <vers num="8.1" />
        <vers num="8.2" />
        <vers num="9.0" edition="" />
        <vers num="9.0" edition=":enterprise_server" />
        <vers num="9.1" />
        <vers num="9.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0915" published="2005-01-10" name="CVE-2004-0915" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Multiple unknown vulnerabilities in viewcvs before 0.9.2, when exporting a repository as a tar archive, does not properly implement the hide_cvsroot and forbidden settings, which could allow remote attackers to gain sensitive information.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
      <config />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.debian.org/security/2004/dsa-605" source="DEBIAN" patch="1" adv="1">DSA-605</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/18369" source="XF" adv="1">viewcvs-repository-weak-security(18369)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="viewcvs" name="viewcvs">
        <vers num="0.9.2" />
      </prod>
      <prod vendor="debian" name="debian_linux">
        <vers num="3.0" edition="" />
        <vers num="3.0" edition=":hppa" />
        <vers num="3.0" edition=":mips" />
        <vers num="3.0" edition=":ia-32" />
        <vers num="3.0" edition=":m68k" />
        <vers num="3.0" edition=":s-390" />
        <vers num="3.0" edition=":alpha" />
        <vers num="3.0" edition=":arm" />
        <vers num="3.0" edition=":ia-64" />
        <vers num="3.0" edition=":mipsel" />
        <vers num="3.0" edition=":sparc" />
        <vers num="3.0" edition=":ppc" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0916" published="2005-01-27" name="CVE-2004-0916" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in cabextract before 1.1 allows remote attackers to overwrite arbitrary files via a cabinet file containing .. (dot dot) sequences in a filename.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.debian.org/security/2004/dsa-574" source="DEBIAN" patch="1" adv="1">DSA-574</ref>
      <ref url="http://secunia.com/advisories/12882/" source="SECUNIA" patch="1" adv="1">12882</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/17766" source="XF" adv="1">cabextract-directory-traversal(17766)</ref>
      <ref url="http://www.securityfocus.com/bid/11460" source="BID" adv="1">11460</ref>
      <ref url="http://www.kyz.uklinux.net/cabextract.php#changes" source="CONFIRM">http://www.kyz.uklinux.net/cabextract.php#changes</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cabextract" name="cabextract">
        <vers num="0.2" />
        <vers num="0.6" />
        <vers num="1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0917" published="2005-01-27" name="CVE-2004-0917" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The default installation of Vignette Application Portal installs the diagnostic utility without authentication requirements, which allows remote attackers to gain sensitive information, such as server and OS version, and conduct unauthorized activities via an HTTP request to /diag.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/17530" source="XF" adv="1">vignette-diagnostic-obtain-info(17530)</ref>
      <ref url="http://www.securityfocus.com/bid/11267" source="BID" adv="1">11267</ref>
      <ref url="http://www.atstake.com/research/advisories/2004/a092804-1.txt" source="ATSTAKE" adv="1">A092804-1</ref>
      <ref url="http://securitytracker.com/id?1011447" source="SECTRACK">1011447</ref>
    </refs>
    <vuln_soft>
      <prod vendor="vignette" name="application_portal">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0918" published="2005-01-27" name="CVE-2004-0918" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The asn_parse_header function (asn1.c) in the SNMP module for Squid Web Proxy Cache before 2.4.STABLE7 allows remote attackers to cause a denial of service (server restart) via certain SNMP packets with negative length fields that trigger a memory allocation error.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/11385" source="BID" patch="1" adv="1">11385</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-591.html" source="REDHAT" patch="1" adv="1">RHSA-2004:591</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2008-July/msg00122.html" source="FEDORA">FEDORA-2008-6045</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/17688" source="XF" adv="1">squid-snmp-asnparseheader-dos(17688)</ref>
      <ref url="http://www.vupen.com/english/advisories/2008/1969/references" source="VUPEN" adv="1">ADV-2008-1969</ref>
      <ref url="http://www.squid-cache.org/Advisories/SQUID-2008_1.txt" source="CONFIRM">http://www.squid-cache.org/Advisories/SQUID-2008_1.txt</ref>
      <ref url="http://www.squid-cache.org/Advisories/SQUID-2004_3.txt" source="CONFIRM">http://www.squid-cache.org/Advisories/SQUID-2004_3.txt</ref>
      <ref url="http://www.idefense.com/application/poi/display?id=152&amp;type=vulnerabilities&amp;flashstatus=false" source="IDEFENSE">20041011 Squid Web Proxy Cache Remote Denial of Service Vulnerability</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200410-15.xml" source="GENTOO">GLSA-200410-15</ref>
      <ref url="http://secunia.com/advisories/30967" source="SECUNIA" adv="1">30967</ref>
      <ref url="http://secunia.com/advisories/30914" source="SECUNIA" adv="1">30914</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10931" source="OVAL">oval:org.mitre.oval:def:10931</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109913064629327&amp;w=2" source="OPENPKG">OpenPKG-SA-2004.048</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2008-07/msg00001.html" source="SUSE">SUSE-SR:2008:014</ref>
      <ref url="ftp://ftp.sco.com/pub/updates/UnixWare/SCOSA-2005.16/SCOSA-2005.16.txt" source="SCO">SCOSA-2005.16</ref>
    </refs>
    <vuln_soft>
      <prod vendor="openpkg" name="openpkg">
        <vers num="2.1" />
        <vers num="2.2" />
        <vers num="current" />
      </prod>
      <prod vendor="squid" name="squid">
        <vers num="2.0_patch2" />
        <vers num="2.1_patch2" />
        <vers num="2.3_.stable4" />
        <vers num="2.3_.stable5" />
        <vers num="2.4" />
        <vers num="2.4_.stable2" />
        <vers num="2.4_.stable6" />
        <vers num="2.4_.stable7" />
        <vers num="2.5_.stable1" />
        <vers num="2.5_.stable3" />
        <vers num="2.5_.stable4" />
        <vers num="2.5_.stable5" />
        <vers num="2.5_.stable6" />
        <vers num="3.0_pre1" />
        <vers num="3.0_pre2" />
        <vers num="3.0_pre3" />
      </prod>
      <prod vendor="gentoo" name="linux">
        <vers num="" />
      </prod>
      <prod vendor="redhat" name="fedora_core">
        <vers num="core_2.0" />
      </prod>
      <prod vendor="trustix" name="secure_linux">
        <vers num="1.5" />
        <vers num="2.0" />
        <vers num="2.1" />
      </prod>
      <prod vendor="ubuntu" name="ubuntu_linux">
        <vers num="4.1" edition="" />
        <vers num="4.1" edition=":ia64" />
        <vers num="4.1" edition=":ppc" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0919" published="2004-12-31" name="CVE-2004-0919" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">The syscons CONS_SCRSHOT ioctl in FreeBSD 5.x allows local users to read arbitrary kernel memory via (1) negative coordinates or (2) large coordinates.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/969078" source="CERT-VN" adv="1">VU#969078</ref>
      <ref url="http://www.securityfocus.com/bid/11321" source="BID" patch="1">11321</ref>
      <ref url="http://secunia.com/advisories/12722" source="SECUNIA" patch="1">12722</ref>
      <ref url="ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-04:15.syscons.asc" source="FREEBSD" patch="1">FreeBSD-SA-04:15</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/17584" source="XF">syscons-consscrshot-info-disclosure(17584)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="freebsd" name="freebsd">
        <vers num="5.0" edition="alpha" />
        <vers num="5.0" edition="release_p14" />
        <vers num="5.0" edition="releng" />
        <vers num="5.1" edition="alpha" />
        <vers num="5.1" edition="release" />
        <vers num="5.1" edition="release_p5" />
        <vers num="5.1" edition="releng" />
        <vers num="5.2" />
        <vers num="5.2.1" edition="release" />
        <vers num="5.2.1" edition="releng" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0920" published="2004-11-03" name="CVE-2004-0920" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Symantec Norton AntiVirus 2004, and earlier versions, allows a virus or other malicious code to avoid detection or cause a denial of service (application crash) using a filename containing an MS-DOS device name.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/17603" source="XF" patch="1" adv="1">nav-antivirus-security-bypass(17603)</ref>
      <ref url="http://www.seifried.org/security/advisories/kssa-010.html" source="MISC">http://www.seifried.org/security/advisories/kssa-010.html</ref>
      <ref url="http://www.idefense.com/application/poi/display?id=147&amp;type=vulnerabilities" source="IDEFENSE">20041005 Symantec Norton AntiVirus Reserved Device Name Handling Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="symantec" name="norton_antivirus">
        <vers prev="1" num="2.1" edition="" />
        <vers prev="1" num="2.1" edition=":ms_exchange" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0921" published="2005-01-27" name="CVE-2004-0921" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">AFP Server on Mac OS X 10.3.x to 10.3.5, when a guest has mounted an AFP volume, allows the guest to "terminate authenticated user mounts" via modified SessionDestroy packets.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/11322" source="BID" patch="1" adv="1">11322</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2004/Oct/msg00000.html" source="APPLE" patch="1" adv="1">APPLE-SA-2004-09-30</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="quicktime">
        <vers num="5.0.2" />
        <vers num="6.0" />
        <vers num="6.1" />
        <vers num="6.5" />
        <vers num="6.5.1" />
      </prod>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.2" />
        <vers num="10.2.1" />
        <vers num="10.2.2" />
        <vers num="10.2.3" />
        <vers num="10.2.4" />
        <vers num="10.2.5" />
        <vers num="10.2.6" />
        <vers num="10.2.7" />
        <vers num="10.2.8" />
        <vers num="10.3" />
        <vers num="10.3.1" />
        <vers num="10.3.2" />
        <vers num="10.3.3" />
        <vers num="10.3.4" />
        <vers num="10.3.5" />
      </prod>
      <prod vendor="apple" name="mac_os_x_server">
        <vers num="10.2" />
        <vers num="10.2.1" />
        <vers num="10.2.2" />
        <vers num="10.2.3" />
        <vers num="10.2.4" />
        <vers num="10.2.5" />
        <vers num="10.2.6" />
        <vers num="10.2.7" />
        <vers num="10.2.8" />
        <vers num="10.3" />
        <vers num="10.3.1" />
        <vers num="10.3.2" />
        <vers num="10.3.3" />
        <vers num="10.3.4" />
        <vers num="10.3.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0922" published="2005-01-27" name="CVE-2004-0922" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">AFP Server on Mac OS X 10.3.x to 10.3.5, under certain conditions, does not properly set the guest group ID, which causes AFP to change a write-only AFP Drop Box to be read-write when the Drop Box is on a share that is mounted by a guest, which allows attackers to read the Drop Box.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/11322" source="BID" patch="1" adv="1">11322</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2004/Oct/msg00000.html" source="APPLE" patch="1" adv="1">APPLE-SA-2004-09-30</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="quicktime">
        <vers num="5.0.2" />
        <vers num="6.0" />
        <vers num="6.1" />
        <vers num="6.5" />
        <vers num="6.5.1" />
      </prod>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.2" />
        <vers num="10.2.1" />
        <vers num="10.2.2" />
        <vers num="10.2.3" />
        <vers num="10.2.4" />
        <vers num="10.2.5" />
        <vers num="10.2.6" />
        <vers num="10.2.7" />
        <vers num="10.2.8" />
        <vers num="10.3" />
        <vers num="10.3.1" />
        <vers num="10.3.2" />
        <vers num="10.3.3" />
        <vers num="10.3.4" />
        <vers num="10.3.5" />
      </prod>
      <prod vendor="apple" name="mac_os_x_server">
        <vers num="10.2" />
        <vers num="10.2.1" />
        <vers num="10.2.2" />
        <vers num="10.2.3" />
        <vers num="10.2.4" />
        <vers num="10.2.5" />
        <vers num="10.2.6" />
        <vers num="10.2.7" />
        <vers num="10.2.8" />
        <vers num="10.3" />
        <vers num="10.3.1" />
        <vers num="10.3.2" />
        <vers num="10.3.3" />
        <vers num="10.3.4" />
        <vers num="10.3.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2004-0923" published="2005-01-27" name="CVE-2004-0923" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">CUPS 1.1.20 and earlier records authentication information for a device URI in the error_log file, which allows local users to obtain user names and passwords.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/557062" source="CERT-VN" adv="1">VU#557062</ref>
      <ref url="http://www.securityfocus.com/bid/11324" source="BID" patch="1" adv="1">11324</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-543.html" source="REDHAT" patch="1" adv="1">RHSA-2004:543</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/17593" source="XF" adv="1">cups-password-disclosure(17593)</ref>
      <ref url="http://www.debian.org/security/2004/dsa-566" source="DEBIAN">DSA-566</ref>
      <ref url="http://www.ciac.org/ciac/bulletins/p-002.shtml" source="CIAC">P-002</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10710" source="OVAL">oval:org.mitre.oval:def:10710</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2004/Oct/msg00000.html" source="APPLE">APPLE-SA-2004-09-30</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2004:116" source="MANDRAKE">MDKSA-2004:116</ref>
    </refs>
    <vuln_soft>
      <prod vendor="easy_software_products" name="cups">
        <vers num="1.0.4" />
        <vers num="1.0.4_8" />
        <vers num="1.1.1" />
        <vers num="1.1.10" />
        <vers num="1.1.12" />
        <vers num="1.1.13" />
        <vers num="1.1.14" />
        <vers num="1.1.15" />
        <vers num="1.1.16" />
        <vers num="1.1.17" />
        <vers num="1.1.18" />
        <vers num="1.1.19" />
        <vers num="1.1.19_rc5" />
        <vers num="1.1.20" />
        <vers num="1.1.21" />
        <vers num="1.1.4" />
        <vers num="1.1.4_2" />
        <vers num="1.1.4_3" />
        <vers num="1.1.4_5" />
        <vers num="1.1.6" />
        <vers num="1.1.7" />
      </prod>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.2" />
        <vers num="10.2.1" />
        <vers num="10.2.2" />
        <vers num="10.2.3" />
        <vers num="10.2.4" />
        <vers num="10.2.5" />
        <vers num="10.2.6" />
        <vers num="10.2.7" />
        <vers num="10.2.8" />
        <vers num="10.3" />
        <vers num="10.3.1" />
        <vers num="10.3.2" />
        <vers num="10.3.3" />
        <vers num="10.3.4" />
        <vers num="10.3.5" />
      </prod>
      <prod vendor="apple" name="mac_os_x_server">
        <vers num="10.2" />
        <vers num="10.2.1" />
        <vers num="10.2.2" />
        <vers num="10.2.3" />
        <vers num="10.2.4" />
        <vers num="10.2.5" />
        <vers num="10.2.6" />
        <vers num="10.2.7" />
        <vers num="10.2.8" />
        <vers num="10.3" />
        <vers num="10.3.1" />
        <vers num="10.3.2" />
        <vers num="10.3.3" />
        <vers num="10.3.4" />
        <vers num="10.3.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0924" published="2005-01-27" name="CVE-2004-0924" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">NetInfo Manager on Mac OS X 10.3.x through 10.3.5, after an initial root login, reports the root account as being disabled, even when it has not.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://lists.apple.com/archives/security-announce/2004/Oct/msg00000.html" source="APPLE" patch="1" adv="1">APPLE-SA-2004-09-30</ref>
      <ref url="http://www.securityfocus.com/bid/11322" source="BID" adv="1">11322</ref>
    </refs>
    <vuln_soft>
      <prod vendor="easy_software_products" name="cups">
        <vers num="1.0.4" />
        <vers num="1.0.4_8" />
        <vers num="1.1.1" />
        <vers num="1.1.10" />
        <vers num="1.1.12" />
        <vers num="1.1.13" />
        <vers num="1.1.14" />
        <vers num="1.1.15" />
        <vers num="1.1.16" />
        <vers num="1.1.17" />
        <vers num="1.1.18" />
        <vers num="1.1.19" />
        <vers num="1.1.19_rc5" />
        <vers num="1.1.20" />
        <vers num="1.1.21" />
        <vers num="1.1.4" />
        <vers num="1.1.4_2" />
        <vers num="1.1.4_3" />
        <vers num="1.1.4_5" />
        <vers num="1.1.6" />
        <vers num="1.1.7" />
      </prod>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.2" />
        <vers num="10.2.1" />
        <vers num="10.2.2" />
        <vers num="10.2.3" />
        <vers num="10.2.4" />
        <vers num="10.2.5" />
        <vers num="10.2.6" />
        <vers num="10.2.7" />
        <vers num="10.2.8" />
        <vers num="10.3" />
        <vers num="10.3.1" />
        <vers num="10.3.2" />
        <vers num="10.3.3" />
        <vers num="10.3.4" />
        <vers num="10.3.5" />
      </prod>
      <prod vendor="apple" name="mac_os_x_server">
        <vers num="10.2" />
        <vers num="10.2.1" />
        <vers num="10.2.2" />
        <vers num="10.2.3" />
        <vers num="10.2.4" />
        <vers num="10.2.5" />
        <vers num="10.2.6" />
        <vers num="10.2.7" />
        <vers num="10.2.8" />
        <vers num="10.3" />
        <vers num="10.3.1" />
        <vers num="10.3.2" />
        <vers num="10.3.3" />
        <vers num="10.3.4" />
        <vers num="10.3.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0925" published="2005-01-27" name="CVE-2004-0925" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Postfix on Mac OS X 10.3.x through 10.3.5, with SMTPD AUTH enabled, does not properly clear the username between authentication attempts, which allows users with the longest username to prevent other valid users from being able to authenticate.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <design />
      <exception />
      <config />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://lists.apple.com/archives/security-announce/2004/Oct/msg00000.html" source="APPLE" patch="1" adv="1">APPLE-SA-2004-09-30</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.3" />
        <vers num="10.3.1" />
        <vers num="10.3.2" />
        <vers num="10.3.3" />
        <vers num="10.3.4" />
        <vers num="10.3.5" />
      </prod>
      <prod vendor="apple" name="mac_os_x_server">
        <vers num="10.3" />
        <vers num="10.3.1" />
        <vers num="10.3.2" />
        <vers num="10.3.3" />
        <vers num="10.3.4" />
        <vers num="10.3.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0926" published="2005-01-27" name="CVE-2004-0926" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Heap-based buffer overflow in Apple QuickTime on Mac OS 10.2.8 through 10.3.5 may allow remote attackers to execute arbitrary code via a certain BMP image.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/11322" source="BID" patch="1" adv="1">11322</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2004/Oct/msg00000.html" source="APPLE" patch="1" adv="1">APPLE-SA-2004-09-30</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2004/Oct/msg00001.html" source="APPLE">APPLE-SA-2004-10-27</ref>
    </refs>
    <vuln_soft>
      <prod vendor="easy_software_products" name="cups">
        <vers num="1.0.4" />
        <vers num="1.0.4_8" />
        <vers num="1.1.1" />
        <vers num="1.1.10" />
        <vers num="1.1.12" />
        <vers num="1.1.13" />
        <vers num="1.1.14" />
        <vers num="1.1.15" />
        <vers num="1.1.16" />
        <vers num="1.1.17" />
        <vers num="1.1.18" />
        <vers num="1.1.19" />
        <vers num="1.1.19_rc5" />
        <vers num="1.1.20" />
        <vers num="1.1.21" />
        <vers num="1.1.4" />
        <vers num="1.1.4_2" />
        <vers num="1.1.4_3" />
        <vers num="1.1.4_5" />
        <vers num="1.1.6" />
        <vers num="1.1.7" />
      </prod>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.2" />
        <vers num="10.2.1" />
        <vers num="10.2.2" />
        <vers num="10.2.3" />
        <vers num="10.2.4" />
        <vers num="10.2.5" />
        <vers num="10.2.6" />
        <vers num="10.2.7" />
        <vers num="10.2.8" />
        <vers num="10.3" />
        <vers num="10.3.1" />
        <vers num="10.3.2" />
        <vers num="10.3.3" />
        <vers num="10.3.4" />
        <vers num="10.3.5" />
      </prod>
      <prod vendor="apple" name="mac_os_x_server">
        <vers num="10.2" />
        <vers num="10.2.1" />
        <vers num="10.2.2" />
        <vers num="10.2.3" />
        <vers num="10.2.4" />
        <vers num="10.2.5" />
        <vers num="10.2.6" />
        <vers num="10.2.7" />
        <vers num="10.2.8" />
        <vers num="10.3" />
        <vers num="10.3.1" />
        <vers num="10.3.2" />
        <vers num="10.3.3" />
        <vers num="10.3.4" />
        <vers num="10.3.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0927" published="2005-01-27" name="CVE-2004-0927" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">ServerAdmin in Mac OS X 10.2.8 through 10.3.5 uses the same example self-signed certificate on each system, which allows remote attackers to decrypt sessions.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://lists.apple.com/archives/security-announce/2004/Oct/msg00000.html" source="APPLE" patch="1" adv="1">APPLE-SA-2004-09-30</ref>
      <ref url="http://www.securityfocus.com/bid/11322" source="BID">11322</ref>
    </refs>
    <vuln_soft>
      <prod vendor="easy_software_products" name="cups">
        <vers num="1.0.4" />
        <vers num="1.0.4_8" />
        <vers num="1.1.1" />
        <vers num="1.1.10" />
        <vers num="1.1.12" />
        <vers num="1.1.13" />
        <vers num="1.1.14" />
        <vers num="1.1.15" />
        <vers num="1.1.16" />
        <vers num="1.1.17" />
        <vers num="1.1.18" />
        <vers num="1.1.19" />
        <vers num="1.1.19_rc5" />
        <vers num="1.1.20" />
        <vers num="1.1.21" />
        <vers num="1.1.4" />
        <vers num="1.1.4_2" />
        <vers num="1.1.4_3" />
        <vers num="1.1.4_5" />
        <vers num="1.1.6" />
        <vers num="1.1.7" />
      </prod>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.2" />
        <vers num="10.2.1" />
        <vers num="10.2.2" />
        <vers num="10.2.3" />
        <vers num="10.2.4" />
        <vers num="10.2.5" />
        <vers num="10.2.6" />
        <vers num="10.2.7" />
        <vers num="10.2.8" />
        <vers num="10.3" />
        <vers num="10.3.1" />
        <vers num="10.3.2" />
        <vers num="10.3.3" />
        <vers num="10.3.4" />
        <vers num="10.3.5" />
      </prod>
      <prod vendor="apple" name="mac_os_x_server">
        <vers num="10.2" />
        <vers num="10.2.1" />
        <vers num="10.2.2" />
        <vers num="10.2.3" />
        <vers num="10.2.4" />
        <vers num="10.2.5" />
        <vers num="10.2.6" />
        <vers num="10.2.7" />
        <vers num="10.2.8" />
        <vers num="10.3" />
        <vers num="10.3.1" />
        <vers num="10.3.2" />
        <vers num="10.3.3" />
        <vers num="10.3.4" />
        <vers num="10.3.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0928" published="2004-10-05" name="CVE-2004-0928" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The Microsoft IIS Connector in JRun 4.0 and Macromedia ColdFusion MX 6.0, 6.1, and 6.1 J2EE allows remote attackers to bypass authentication and view source files, such as .asp, .pl, and .php files, via an HTTP request that ends in ";.cfm".</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/977440" source="CERT-VN" patch="1" adv="1">VU#977440</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/17484" source="XF" patch="1" adv="1">coldfusion-jrun-restriction-bypass(17484)</ref>
      <ref url="http://www.securityfocus.com/bid/11245" source="BID" patch="1" adv="1">11245</ref>
      <ref url="http://www.macromedia.com/devnet/security/security_zone/mpsb04-09.html" source="CONFIRM" patch="1" adv="1">http://www.macromedia.com/devnet/security/security_zone/mpsb04-09.html</ref>
      <ref url="http://www.macromedia.com/devnet/security/security_zone/mpsb04-08.html" source="CONFIRM" patch="1" adv="1">http://www.macromedia.com/devnet/security/security_zone/mpsb04-08.html</ref>
      <ref url="http://www.idefense.com/application/poi/display?id=148&amp;type=vulnerabilities" source="IDEFENSE" patch="1" adv="1">20041005 ColdFusion MX 6.1 on IIS File Contents Disclosure</ref>
      <ref url="http://secunia.com/advisories/12647/" source="SECUNIA" patch="1" adv="1">12647</ref>
      <ref url="http://secunia.com/advisories/12638/" source="SECUNIA" patch="1" adv="1">12638</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109621995623823&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20040923 New Macromedia Security Zone Bulletins Posted</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hitachi" name="cosminexus_enterprise">
        <vers num="01_01_1" edition="" />
        <vers num="01_01_1" edition=":enterprise" />
        <vers num="01_01_1" edition=":standard" />
        <vers num="01_02_2" edition="" />
        <vers num="01_02_2" edition=":standard" />
        <vers num="01_02_2" edition=":enterprise" />
      </prod>
      <prod vendor="hitachi" name="cosminexus_server">
        <vers num="web_01-01_1" />
        <vers num="web_01-01_2" />
      </prod>
      <prod vendor="macromedia" name="coldfusion">
        <vers num="6.0" />
        <vers num="6.1" />
      </prod>
      <prod vendor="macromedia" name="jrun">
        <vers num="3.0" />
        <vers num="3.1" />
        <vers num="4.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0929" published="2005-01-27" name="CVE-2004-0929" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Heap-based buffer overflow in the OJPEGVSetField function in tif_ojpeg.c for libtiff 3.6.1 and earlier, when compiled with the OJPEG_SUPPORT (old JPEG support) option, allows remote attackers to execute arbitrary code via a malformed TIFF image.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/129910" source="CERT-VN">VU#129910</ref>
      <ref url="http://www.idefense.com/application/poi/display?id=154&amp;type=vulnerabilities" source="IDEFENSE" patch="1" adv="1">20041022 Novell SuSe Linux LibTIFF Heap Overflow Vulnerability</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/17843" source="XF" adv="1">libtiff-ojpegvsetfield-bo(17843)</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2004_38_libtiff.html" source="SUSE">SUSE-SA:2004:038</ref>
    </refs>
    <vuln_soft>
      <prod vendor="libtiff" name="libtiff">
        <vers num="3.6.1" />
      </prod>
      <prod vendor="suse" name="suse_linux">
        <vers num="1.0" edition="" />
        <vers num="1.0" edition=":desktop" />
        <vers num="8" edition="" />
        <vers num="8" edition=":enterprise_server" />
        <vers num="8.1" />
        <vers num="8.2" />
        <vers num="9.0" edition="" />
        <vers num="9.0" edition=":enterprise_server" />
        <vers num="9.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0930" published="2005-01-27" name="CVE-2004-0930" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The ms_fnmatch function in Samba 3.0.4 and 3.0.7 and possibly other versions allows remote authenticated users to cause a denial of service (CPU consumption) via a SAMBA request that contains multiple * (wildcard) characters.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/11624" source="BID" patch="1" adv="1">11624</ref>
      <ref url="http://www.idefense.com/application/poi/display?id=156&amp;type=vulnerabilities&amp;flashstatus=false" source="IDEFENSE" patch="1" adv="1">20041108 Samba SMBD Remote Denial of Service Vulnerability</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/17987" source="XF" adv="1">samba-msfnmatch-dos(17987)</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2004_40_samba.html" source="SUSE">SUSE-SA:2004:040</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200411-21.xml" source="GENTOO">GLSA 200411-21</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10936" source="OVAL">oval:org.mitre.oval:def:10936</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2005/Mar/msg00000.html" source="APPLE">APPLE-SA-2005-03-21</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/20041201-01-P" source="SGI">20041201-01-P</ref>
      <ref url="ftp://ftp.sco.com/pub/updates/UnixWare/SCOSA-2005.17/SCOSA-2005.17.txt" source="SCO">SCOSA-2005.17</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2004:131" source="MANDRAKE">MDKSA-2004:131</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-101783-1" source="SUNALERT">101783</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110330519803655&amp;w=2" source="OPENPKG">OpenPKG-SA-2004.054</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110022719024619&amp;w=2" source="UBUNTU">USN-22-1</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109993720717957&amp;w=2" source="BUGTRAQ">20041108 [SECURITY] CAN-2004-0930: Potential Remote Denial of Service Vulnerability</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000899" source="CONECTIVA">CLA-2004:899</ref>
    </refs>
    <vuln_soft>
      <prod vendor="samba" name="samba">
        <vers num="3.0.0" />
        <vers num="3.0.3" />
        <vers num="3.0.4" />
        <vers num="3.0.5" />
        <vers num="3.0.6" />
        <vers num="3.0.7" />
      </prod>
      <prod vendor="sgi" name="samba">
        <vers num="3.0" edition="" />
        <vers num="3.0" edition=":irix" />
        <vers num="3.0.1" edition="" />
        <vers num="3.0.1" edition=":irix" />
        <vers num="3.0.2" edition="" />
        <vers num="3.0.2" edition=":irix" />
        <vers num="3.0.3" edition="" />
        <vers num="3.0.3" edition=":irix" />
        <vers num="3.0.4" edition="" />
        <vers num="3.0.4" edition=":irix" />
        <vers num="3.0.5" edition="" />
        <vers num="3.0.5" edition=":irix" />
        <vers num="3.0.6" edition="" />
        <vers num="3.0.6" edition=":irix" />
        <vers num="3.0.7" edition="" />
        <vers num="3.0.7" edition=":irix" />
      </prod>
      <prod vendor="conectiva" name="linux">
        <vers num="10.0" />
      </prod>
      <prod vendor="gentoo" name="linux">
        <vers num="" />
      </prod>
      <prod vendor="redhat" name="enterprise_linux">
        <vers num="2.1" edition="" />
        <vers num="2.1" edition=":workstation_ia64" />
        <vers num="2.1" edition=":advanced_server" />
        <vers num="2.1" edition=":enterprise_server" />
        <vers num="2.1" edition=":advanced_server_ia64" />
        <vers num="2.1" edition=":workstation" />
        <vers num="2.1" edition=":enterprise_server_ia64" />
        <vers num="3.0" edition="" />
        <vers num="3.0" edition=":advanced_server" />
        <vers num="3.0" edition=":workstation_server" />
        <vers num="3.0" edition=":enterprise_server" />
      </prod>
      <prod vendor="redhat" name="enterprise_linux_desktop">
        <vers num="3.0" />
      </prod>
      <prod vendor="redhat" name="fedora_core">
        <vers num="core_2.0" />
        <vers num="core_3.0" />
      </prod>
      <prod vendor="redhat" name="linux_advanced_workstation">
        <vers num="2.1" edition="" />
        <vers num="2.1" edition=":itanium_processor" />
        <vers num="2.1" edition=":ia64" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0931" published="2004-12-31" name="CVE-2004-0931" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">MySQL MaxDB before 7.5.00.18 allows remote attackers to cause a denial of service (crash) via an HTTP request to webdbm with high ASCII values in the Server field, which triggers an assert error in the IsAscii7 function.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/11346" source="BID" patch="1">11346</ref>
      <ref url="http://www.secunia.com/advisories/12756" source="SECUNIA" patch="1">12756</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/17633" source="XF">maxdb-isascii7dos(17633)</ref>
      <ref url="http://www.osvdb.org/10532" source="OSVDB">10532</ref>
      <ref url="http://www.idefense.com/application/poi/display?id=150&amp;type=vulnerabilities&amp;flashstatus=false" source="IDEFENSE">20041006 MySQL MaxDB Web Agent WebDBMServer Name Denial of Service Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mysql" name="maxdb">
        <vers num="7.5.00.08" />
        <vers num="7.5.00.11" />
        <vers num="7.5.00.12" />
        <vers num="7.5.00.14" />
        <vers num="7.5.00.15" />
        <vers num="7.5.00.16" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0932" published="2005-01-27" name="CVE-2004-0932" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">McAfee Anti-Virus Engine DATS drivers before 4398 released on Oct 13th 2004 and DATS Driver before 4397 October 6th 2004 allows remote attackers to bypass antivirus protection via a compressed file with both local and global headers set to zero, which does not prevent the compressed file from being opened on a target system.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <design />
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/11448" source="BID" patch="1" adv="1">11448</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/17761" source="XF" adv="1">antivirus-zip-protection-bypass(17761)</ref>
      <ref url="http://www.idefense.com/application/poi/display?id=153&amp;type=vulnerabilities&amp;flashstatus=true" source="IDEFENSE">20041018 Multiple Vendor Anti-Virus Software Detection Evasion Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="archive_zip" name="archive_zip">
        <vers num="1.13" />
      </prod>
      <prod vendor="ca" name="brightstor_arcserve_backup">
        <vers num="11.1" />
      </prod>
      <prod vendor="ca" name="etrust_antivirus">
        <vers num="7.0" />
        <vers num="7.0_sp2" />
        <vers num="7.1" />
      </prod>
      <prod vendor="ca" name="etrust_antivirus_gateway">
        <vers num="7.0" />
        <vers num="7.1" />
      </prod>
      <prod vendor="ca" name="etrust_ez_antivirus">
        <vers num="6.1" />
        <vers num="6.2" />
        <vers num="6.3" />
      </prod>
      <prod vendor="ca" name="etrust_ez_armor">
        <vers num="2.0" />
        <vers num="2.3" />
        <vers num="2.4" />
      </prod>
      <prod vendor="ca" name="etrust_intrusion_detection">
        <vers num="1.4.1.13" />
        <vers num="1.4.5" />
        <vers num="1.5" />
      </prod>
      <prod vendor="ca" name="etrust_secure_content_manager">
        <vers num="1.0" edition="sp1" />
        <vers num="1.1" />
      </prod>
      <prod vendor="ca" name="inoculateit">
        <vers num="6.0" />
      </prod>
      <prod vendor="eset_software" name="nod32_antivirus">
        <vers num="1.0.11" />
        <vers num="1.0.12" />
        <vers num="1.0.13" />
      </prod>
      <prod vendor="kaspersky_lab" name="kaspersky_anti-virus">
        <vers num="3.0" />
        <vers num="4.0" />
        <vers num="5.0" />
      </prod>
      <prod vendor="mcafee" name="antivirus_engine">
        <vers num="4.3.20" />
      </prod>
      <prod vendor="rav_antivirus" name="rav_antivirus_desktop">
        <vers num="8.6" />
      </prod>
      <prod vendor="rav_antivirus" name="rav_antivirus_for_file_servers">
        <vers num="1.0" />
      </prod>
      <prod vendor="rav_antivirus" name="rav_antivirus_for_mail_servers">
        <vers num="8.4.2" />
      </prod>
      <prod vendor="sophos" name="sophos_anti-virus">
        <vers num="3.4.6" />
        <vers num="3.78" />
        <vers num="3.78d" />
        <vers num="3.79" />
        <vers num="3.80" />
        <vers num="3.81" />
        <vers num="3.82" />
        <vers num="3.83" />
        <vers num="3.84" />
        <vers num="3.85" />
        <vers num="3.86" />
      </prod>
      <prod vendor="sophos" name="sophos_puremessage_anti-virus">
        <vers num="4.6" />
      </prod>
      <prod vendor="sophos" name="sophos_small_business_suite">
        <vers num="1.0" />
      </prod>
      <prod vendor="gentoo" name="linux">
        <vers num="1.4" />
      </prod>
      <prod vendor="mandrakesoft" name="mandrake_linux">
        <vers num="10.1" edition="" />
        <vers num="10.1" edition=":x86_64" />
      </prod>
      <prod vendor="suse" name="suse_linux">
        <vers num="9.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0933" published="2005-01-27" name="CVE-2004-0933" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Computer Associates (CA) InoculateIT 6.0, eTrust Antivirus r6.0 through r7.1, eTrust Antivirus for the Gateway r7.0 and r7.1, eTrust Secure Content Manager, eTrust Intrusion Detection, EZ-Armor 2.0 through 2.4, and EZ-Antivirus 6.1 through 6.3 allow remote attackers to bypass antivirus protection via a compressed file with both local and global headers set to zero, which does not prevent the compressed file from being opened on a target system.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <design />
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/11448" source="BID" patch="1" adv="1">11448</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/17761" source="XF" adv="1">antivirus-zip-protection-bypass(17761)</ref>
      <ref url="http://www.idefense.com/application/poi/display?id=153&amp;type=vulnerabilities&amp;flashstatus=true" source="IDEFENSE">20041018 Multiple Vendor Anti-Virus Software Detection Evasion Vulnerability</ref>
      <ref url="http://supportconnectw.ca.com/public/ca_common_docs/arclib_vuln.asp" source="CONFIRM">http://supportconnectw.ca.com/public/ca_common_docs/arclib_vuln.asp</ref>
    </refs>
    <vuln_soft>
      <prod vendor="archive_zip" name="archive_zip">
        <vers num="1.13" />
      </prod>
      <prod vendor="ca" name="brightstor_arcserve_backup">
        <vers num="11.1" />
      </prod>
      <prod vendor="ca" name="etrust_antivirus">
        <vers num="7.0" />
        <vers num="7.0_sp2" />
        <vers num="7.1" />
      </prod>
      <prod vendor="ca" name="etrust_antivirus_gateway">
        <vers num="7.0" />
        <vers num="7.1" />
      </prod>
      <prod vendor="ca" name="etrust_ez_antivirus">
        <vers num="6.1" />
        <vers num="6.2" />
        <vers num="6.3" />
      </prod>
      <prod vendor="ca" name="etrust_ez_armor">
        <vers num="2.0" />
        <vers num="2.3" />
        <vers num="2.4" />
      </prod>
      <prod vendor="ca" name="etrust_intrusion_detection">
        <vers num="1.4.1.13" />
        <vers num="1.4.5" />
        <vers num="1.5" />
      </prod>
      <prod vendor="ca" name="etrust_secure_content_manager">
        <vers num="1.0" edition="sp1" />
        <vers num="1.1" />
      </prod>
      <prod vendor="ca" name="inoculateit">
        <vers num="6.0" />
      </prod>
      <prod vendor="eset_software" name="nod32_antivirus">
        <vers num="1.0.11" />
        <vers num="1.0.12" />
        <vers num="1.0.13" />
      </prod>
      <prod vendor="kaspersky_lab" name="kaspersky_anti-virus">
        <vers num="3.0" />
        <vers num="4.0" />
        <vers num="5.0" />
      </prod>
      <prod vendor="mcafee" name="antivirus_engine">
        <vers num="4.3.20" />
      </prod>
      <prod vendor="rav_antivirus" name="rav_antivirus_desktop">
        <vers num="8.6" />
      </prod>
      <prod vendor="rav_antivirus" name="rav_antivirus_for_file_servers">
        <vers num="1.0" />
      </prod>
      <prod vendor="rav_antivirus" name="rav_antivirus_for_mail_servers">
        <vers num="8.4.2" />
      </prod>
      <prod vendor="sophos" name="sophos_anti-virus">
        <vers num="3.4.6" />
        <vers num="3.78" />
        <vers num="3.78d" />
        <vers num="3.79" />
        <vers num="3.80" />
        <vers num="3.81" />
        <vers num="3.82" />
        <vers num="3.83" />
        <vers num="3.84" />
        <vers num="3.85" />
        <vers num="3.86" />
      </prod>
      <prod vendor="sophos" name="sophos_puremessage_anti-virus">
        <vers num="4.6" />
      </prod>
      <prod vendor="sophos" name="sophos_small_business_suite">
        <vers num="1.0" />
      </prod>
      <prod vendor="gentoo" name="linux">
        <vers num="1.4" />
      </prod>
      <prod vendor="mandrakesoft" name="mandrake_linux">
        <vers num="10.1" edition="" />
        <vers num="10.1" edition=":x86_64" />
      </prod>
      <prod vendor="suse" name="suse_linux">
        <vers num="9.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0934" published="2005-01-27" name="CVE-2004-0934" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Kaspersky 3.x to 4.x allows remote attackers to bypass antivirus protection via a compressed file with both local and global headers set to zero, which does not prevent the compressed file from being opened on a target system.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <design />
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/968818" source="CERT-VN">VU#968818</ref>
      <ref url="http://www.securityfocus.com/bid/11448" source="BID" patch="1" adv="1">11448</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/17761" source="XF" adv="1">antivirus-zip-protection-bypass(17761)</ref>
      <ref url="http://www.idefense.com/application/poi/display?id=153&amp;type=vulnerabilities&amp;flashstatus=true" source="IDEFENSE">20041018 Multiple Vendor Anti-Virus Software Detection Evasion Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="archive_zip" name="archive_zip">
        <vers num="1.13" />
      </prod>
      <prod vendor="ca" name="brightstor_arcserve_backup">
        <vers num="11.1" />
      </prod>
      <prod vendor="ca" name="etrust_antivirus">
        <vers num="7.0" />
        <vers num="7.0_sp2" />
        <vers num="7.1" />
      </prod>
      <prod vendor="ca" name="etrust_antivirus_gateway">
        <vers num="7.0" />
        <vers num="7.1" />
      </prod>
      <prod vendor="ca" name="etrust_ez_antivirus">
        <vers num="6.1" />
        <vers num="6.2" />
        <vers num="6.3" />
      </prod>
      <prod vendor="ca" name="etrust_ez_armor">
        <vers num="2.0" />
        <vers num="2.3" />
        <vers num="2.4" />
      </prod>
      <prod vendor="ca" name="etrust_intrusion_detection">
        <vers num="1.4.1.13" />
        <vers num="1.4.5" />
        <vers num="1.5" />
      </prod>
      <prod vendor="ca" name="etrust_secure_content_manager">
        <vers num="1.0" edition="sp1" />
        <vers num="1.1" />
      </prod>
      <prod vendor="ca" name="inoculateit">
        <vers num="6.0" />
      </prod>
      <prod vendor="eset_software" name="nod32_antivirus">
        <vers num="1.0.11" />
        <vers num="1.0.12" />
        <vers num="1.0.13" />
      </prod>
      <prod vendor="kaspersky_lab" name="kaspersky_anti-virus">
        <vers num="3.0" />
        <vers num="4.0" />
        <vers num="5.0" />
      </prod>
      <prod vendor="mcafee" name="antivirus_engine">
        <vers num="4.3.20" />
      </prod>
      <prod vendor="rav_antivirus" name="rav_antivirus_desktop">
        <vers num="8.6" />
      </prod>
      <prod vendor="rav_antivirus" name="rav_antivirus_for_file_servers">
        <vers num="1.0" />
      </prod>
      <prod vendor="rav_antivirus" name="rav_antivirus_for_mail_servers">
        <vers num="8.4.2" />
      </prod>
      <prod vendor="sophos" name="sophos_anti-virus">
        <vers num="3.4.6" />
        <vers num="3.78" />
        <vers num="3.78d" />
        <vers num="3.79" />
        <vers num="3.80" />
        <vers num="3.81" />
        <vers num="3.82" />
        <vers num="3.83" />
        <vers num="3.84" />
        <vers num="3.85" />
        <vers num="3.86" />
      </prod>
      <prod vendor="sophos" name="sophos_puremessage_anti-virus">
        <vers num="4.6" />
      </prod>
      <prod vendor="sophos" name="sophos_small_business_suite">
        <vers num="1.0" />
      </prod>
      <prod vendor="gentoo" name="linux">
        <vers num="1.4" />
      </prod>
      <prod vendor="mandrakesoft" name="mandrake_linux">
        <vers num="10.1" edition="" />
        <vers num="10.1" edition=":x86_64" />
      </prod>
      <prod vendor="suse" name="suse_linux">
        <vers num="9.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0935" published="2005-01-27" name="CVE-2004-0935" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Eset Anti-Virus before 1.020 (16th September 2004) allows remote attackers to bypass antivirus protection via a compressed file with both local and global headers set to zero, which does not prevent the compressed file from being opened on a target system.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <design />
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/968818" source="CERT-VN">VU#968818</ref>
      <ref url="http://www.securityfocus.com/bid/11448" source="BID" patch="1" adv="1">11448</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/17761" source="XF" adv="1">antivirus-zip-protection-bypass(17761)</ref>
      <ref url="http://www.idefense.com/application/poi/display?id=153&amp;type=vulnerabilities&amp;flashstatus=true" source="IDEFENSE">20041018 Multiple Vendor Anti-Virus Software Detection Evasion Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="archive_zip" name="archive_zip">
        <vers num="1.13" />
      </prod>
      <prod vendor="ca" name="brightstor_arcserve_backup">
        <vers num="11.1" />
      </prod>
      <prod vendor="ca" name="etrust_antivirus">
        <vers num="7.0" />
        <vers num="7.0_sp2" />
        <vers num="7.1" />
      </prod>
      <prod vendor="ca" name="etrust_antivirus_gateway">
        <vers num="7.0" />
        <vers num="7.1" />
      </prod>
      <prod vendor="ca" name="etrust_ez_antivirus">
        <vers num="6.1" />
        <vers num="6.2" />
        <vers num="6.3" />
      </prod>
      <prod vendor="ca" name="etrust_ez_armor">
        <vers num="2.0" />
        <vers num="2.3" />
        <vers num="2.4" />
      </prod>
      <prod vendor="ca" name="etrust_intrusion_detection">
        <vers num="1.4.1.13" />
        <vers num="1.4.5" />
        <vers num="1.5" />
      </prod>
      <prod vendor="ca" name="etrust_secure_content_manager">
        <vers num="1.0" edition="sp1" />
        <vers num="1.1" />
      </prod>
      <prod vendor="ca" name="inoculateit">
        <vers num="6.0" />
      </prod>
      <prod vendor="eset_software" name="nod32_antivirus">
        <vers num="1.0.11" />
        <vers num="1.0.12" />
        <vers num="1.0.13" />
      </prod>
      <prod vendor="kaspersky_lab" name="kaspersky_anti-virus">
        <vers num="3.0" />
        <vers num="4.0" />
        <vers num="5.0" />
      </prod>
      <prod vendor="mcafee" name="antivirus_engine">
        <vers num="4.3.20" />
      </prod>
      <prod vendor="rav_antivirus" name="rav_antivirus_desktop">
        <vers num="8.6" />
      </prod>
      <prod vendor="rav_antivirus" name="rav_antivirus_for_file_servers">
        <vers num="1.0" />
      </prod>
      <prod vendor="rav_antivirus" name="rav_antivirus_for_mail_servers">
        <vers num="8.4.2" />
      </prod>
      <prod vendor="sophos" name="sophos_anti-virus">
        <vers num="3.4.6" />
        <vers num="3.78" />
        <vers num="3.78d" />
        <vers num="3.79" />
        <vers num="3.80" />
        <vers num="3.81" />
        <vers num="3.82" />
        <vers num="3.83" />
        <vers num="3.84" />
        <vers num="3.85" />
        <vers num="3.86" />
      </prod>
      <prod vendor="sophos" name="sophos_puremessage_anti-virus">
        <vers num="4.6" />
      </prod>
      <prod vendor="sophos" name="sophos_small_business_suite">
        <vers num="1.0" />
      </prod>
      <prod vendor="gentoo" name="linux">
        <vers num="1.4" />
      </prod>
      <prod vendor="mandrakesoft" name="mandrake_linux">
        <vers num="10.1" edition="" />
        <vers num="10.1" edition=":x86_64" />
      </prod>
      <prod vendor="suse" name="suse_linux">
        <vers num="9.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0936" published="2005-01-27" name="CVE-2004-0936" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">RAV antivirus allows remote attackers to bypass antivirus protection via a compressed file with both local and global headers set to zero, which does not prevent the compressed file from being opened on a target system.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <design />
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/968818" source="CERT-VN">VU#968818</ref>
      <ref url="http://www.securityfocus.com/bid/11448" source="BID" patch="1" adv="1">11448</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/17761" source="XF" adv="1">antivirus-zip-protection-bypass(17761)</ref>
      <ref url="http://www.idefense.com/application/poi/display?id=153&amp;type=vulnerabilities&amp;flashstatus=true" source="IDEFENSE">20041018 Multiple Vendor Anti-Virus Software Detection Evasion Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="archive_zip" name="archive_zip">
        <vers num="1.13" />
      </prod>
      <prod vendor="ca" name="brightstor_arcserve_backup">
        <vers num="11.1" />
      </prod>
      <prod vendor="ca" name="etrust_antivirus">
        <vers num="7.0" />
        <vers num="7.0_sp2" />
        <vers num="7.1" />
      </prod>
      <prod vendor="ca" name="etrust_antivirus_gateway">
        <vers num="7.0" />
        <vers num="7.1" />
      </prod>
      <prod vendor="ca" name="etrust_ez_antivirus">
        <vers num="6.1" />
        <vers num="6.2" />
        <vers num="6.3" />
      </prod>
      <prod vendor="ca" name="etrust_ez_armor">
        <vers num="2.0" />
        <vers num="2.3" />
        <vers num="2.4" />
      </prod>
      <prod vendor="ca" name="etrust_intrusion_detection">
        <vers num="1.4.1.13" />
        <vers num="1.4.5" />
        <vers num="1.5" />
      </prod>
      <prod vendor="ca" name="etrust_secure_content_manager">
        <vers num="1.0" edition="sp1" />
        <vers num="1.1" />
      </prod>
      <prod vendor="ca" name="inoculateit">
        <vers num="6.0" />
      </prod>
      <prod vendor="eset_software" name="nod32_antivirus">
        <vers num="1.0.11" />
        <vers num="1.0.12" />
        <vers num="1.0.13" />
      </prod>
      <prod vendor="kaspersky_lab" name="kaspersky_anti-virus">
        <vers num="3.0" />
        <vers num="4.0" />
        <vers num="5.0" />
      </prod>
      <prod vendor="mcafee" name="antivirus_engine">
        <vers num="4.3.20" />
      </prod>
      <prod vendor="rav_antivirus" name="rav_antivirus_desktop">
        <vers num="8.6" />
      </prod>
      <prod vendor="rav_antivirus" name="rav_antivirus_for_file_servers">
        <vers num="1.0" />
      </prod>
      <prod vendor="rav_antivirus" name="rav_antivirus_for_mail_servers">
        <vers num="8.4.2" />
      </prod>
      <prod vendor="sophos" name="sophos_anti-virus">
        <vers num="3.4.6" />
        <vers num="3.78" />
        <vers num="3.78d" />
        <vers num="3.79" />
        <vers num="3.80" />
        <vers num="3.81" />
        <vers num="3.82" />
        <vers num="3.83" />
        <vers num="3.84" />
        <vers num="3.85" />
        <vers num="3.86" />
      </prod>
      <prod vendor="sophos" name="sophos_puremessage_anti-virus">
        <vers num="4.6" />
      </prod>
      <prod vendor="sophos" name="sophos_small_business_suite">
        <vers num="1.0" />
      </prod>
      <prod vendor="gentoo" name="linux">
        <vers num="1.4" />
      </prod>
      <prod vendor="mandrakesoft" name="mandrake_linux">
        <vers num="10.1" edition="" />
        <vers num="10.1" edition=":x86_64" />
      </prod>
      <prod vendor="suse" name="suse_linux">
        <vers num="9.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0937" published="2005-02-09" name="CVE-2004-0937" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Sophos Anti-Virus before 3.87.0, and Sophos Anti-Virus for Windows 95, 98, and Me before 3.88.0, allows remote attackers to bypass antivirus protection via a compressed file with both local and global headers set to zero, which does not prevent the compressed file from being opened on a target system.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <design />
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/968818" source="CERT-VN">VU#968818</ref>
      <ref url="http://www.securityfocus.com/bid/11448" source="BID" patch="1" adv="1">11448</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/17761" source="XF" adv="1">antivirus-zip-protection-bypass(17761)</ref>
      <ref url="http://www.idefense.com/application/poi/display?id=153&amp;type=vulnerabilities&amp;flashstatus=true" source="IDEFENSE">20041018 Multiple Vendor Anti-Virus Software Detection Evasion Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="archive_zip" name="archive_zip">
        <vers num="1.13" />
      </prod>
      <prod vendor="ca" name="brightstor_arcserve_backup">
        <vers num="11.1" />
      </prod>
      <prod vendor="ca" name="etrust_antivirus">
        <vers num="7.0" />
        <vers num="7.0_sp2" />
        <vers num="7.1" />
      </prod>
      <prod vendor="ca" name="etrust_antivirus_gateway">
        <vers num="7.0" />
        <vers num="7.1" />
      </prod>
      <prod vendor="ca" name="etrust_ez_antivirus">
        <vers num="6.1" />
        <vers num="6.2" />
        <vers num="6.3" />
      </prod>
      <prod vendor="ca" name="etrust_ez_armor">
        <vers num="2.0" />
        <vers num="2.3" />
        <vers num="2.4" />
      </prod>
      <prod vendor="ca" name="etrust_intrusion_detection">
        <vers num="1.4.1.13" />
        <vers num="1.4.5" />
        <vers num="1.5" />
      </prod>
      <prod vendor="ca" name="etrust_secure_content_manager">
        <vers num="1.0" edition="sp1" />
        <vers num="1.1" />
      </prod>
      <prod vendor="ca" name="inoculateit">
        <vers num="6.0" />
      </prod>
      <prod vendor="eset_software" name="nod32_antivirus">
        <vers num="1.0.11" />
        <vers num="1.0.12" />
        <vers num="1.0.13" />
      </prod>
      <prod vendor="kaspersky_lab" name="kaspersky_anti-virus">
        <vers num="3.0" />
        <vers num="4.0" />
        <vers num="5.0" />
      </prod>
      <prod vendor="mcafee" name="antivirus_engine">
        <vers num="4.3.20" />
      </prod>
      <prod vendor="rav_antivirus" name="rav_antivirus_desktop">
        <vers num="8.6" />
      </prod>
      <prod vendor="rav_antivirus" name="rav_antivirus_for_file_servers">
        <vers num="1.0" />
      </prod>
      <prod vendor="rav_antivirus" name="rav_antivirus_for_mail_servers">
        <vers num="8.4.2" />
      </prod>
      <prod vendor="sophos" name="sophos_anti-virus">
        <vers num="3.4.6" />
        <vers num="3.78" />
        <vers num="3.78d" />
        <vers num="3.79" />
        <vers num="3.80" />
        <vers num="3.81" />
        <vers num="3.82" />
        <vers num="3.83" />
        <vers num="3.84" />
        <vers num="3.85" />
        <vers num="3.86" />
      </prod>
      <prod vendor="sophos" name="sophos_puremessage_anti-virus">
        <vers num="4.6" />
      </prod>
      <prod vendor="sophos" name="sophos_small_business_suite">
        <vers num="1.0" />
      </prod>
      <prod vendor="gentoo" name="linux">
        <vers num="1.4" />
      </prod>
      <prod vendor="mandrakesoft" name="mandrake_linux">
        <vers num="10.1" edition="" />
        <vers num="10.1" edition=":x86_64" />
      </prod>
      <prod vendor="suse" name="suse_linux">
        <vers num="9.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0938" published="2004-11-03" name="CVE-2004-0938" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">FreeRADIUS before 1.0.1 allows remote attackers to cause a denial of service (server crash) by sending an Ascend-Send-Secret attribute without the required leading packet.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/541574" source="CERT-VN" patch="1" adv="1">VU#541574</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/17440" source="XF" patch="1" adv="1">freeradius-dos(17440)</ref>
      <ref url="http://www.securityfocus.com/bid/11222" source="BID" patch="1" adv="1">11222</ref>
      <ref url="http://www.osvdb.org/10178" source="OSVDB" patch="1" adv="1">10178</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200409-29.xml" source="GENTOO" patch="1" adv="1">GLSA-200409-29</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10837" source="OVAL">oval:org.mitre.oval:def:10837</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1347" source="OVAL" sig="1">oval:org.mitre.oval:def:1347</ref>
    </refs>
    <vuln_soft>
      <prod vendor="freeradius" name="freeradius">
        <vers prev="1" num="1.0.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0939" published="2005-02-09" name="CVE-2004-0939" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">changepassword.cgi in Neoteris Instant Virtual Extranet (IVE) 3.x and 4.x, with LDAP authentication or NT domain authentication enabled, does not limit the number of times a bad password can be entered, which allows remote attackers to guess passwords via a brute force attack.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109709990708794&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20041006 [GoSecure Advisory] Neoteris IVE Vulnerability</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/17629" source="XF" adv="1">juniper-netscreen-password-bruteforce(17629)</ref>
      <ref url="http://www.gosecure.ca/SecInfo/gosecure-2004-10.txt" source="MISC">http://www.gosecure.ca/SecInfo/gosecure-2004-10.txt</ref>
      <ref url="http://securitytracker.com/id?1011552" source="SECTRACK">1011552</ref>
      <ref url="http://www.osvdb.org/8365" source="OSVDB">8365</ref>
      <ref url="http://secunia.com/advisories/12752" source="SECUNIA">12752</ref>
    </refs>
    <vuln_soft>
      <prod vendor="neoteris" name="instant_virtual_extranet">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0940" published="2005-02-09" name="CVE-2004-0940" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:L/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="6.9" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.4" CVSS_base_score="6.9">
    <desc>
      <descript source="cve">Buffer overflow in the get_tag function in mod_include for Apache 1.3.x to 1.3.32 allows local users who can create SSI documents to execute arbitrary code as the apache user via SSI (XSSI) documents that trigger a length calculation error.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/11471" source="BID" patch="1" adv="1">11471</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109906660225051&amp;w=2" source="OPENPKG" patch="1" adv="1">OpenPKG-SA-2004.047</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/17785" source="XF" adv="1">apache-modinclude-bo(17785)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0789" source="VUPEN">ADV-2006-0789</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-816.html" source="REDHAT">RHSA-2005:816</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-600.html" source="REDHAT">RHSA-2004:600</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2004:134" source="MANDRAKE">MDKSA-2004:134</ref>
      <ref url="http://www.debian.org/security/2004/dsa-594" source="DEBIAN">DSA-594</ref>
      <ref url="http://www.apacheweek.com/features/security-13" source="CONFIRM">http://www.apacheweek.com/features/security-13</ref>
      <ref url="http://support.avaya.com/elmodocs2/security/ASA-2006-081.htm" source="CONFIRM">http://support.avaya.com/elmodocs2/security/ASA-2006-081.htm</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-102197-1" source="SUNALERT">102197</ref>
      <ref url="http://securitytracker.com/id?1011783" source="SECTRACK">1011783</ref>
      <ref url="http://secunia.com/advisories/19073" source="SECUNIA">19073</ref>
      <ref url="http://secunia.com/advisories/12898/" source="SECUNIA">12898</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apache" name="http_server">
        <vers num="1.3" />
        <vers num="1.3.1" />
        <vers num="1.3.11" />
        <vers num="1.3.12" />
        <vers num="1.3.14" />
        <vers num="1.3.17" />
        <vers num="1.3.18" />
        <vers num="1.3.19" />
        <vers num="1.3.20" />
        <vers num="1.3.22" />
        <vers num="1.3.23" />
        <vers num="1.3.24" />
        <vers num="1.3.25" />
        <vers num="1.3.26" />
        <vers num="1.3.27" />
        <vers num="1.3.28" />
        <vers num="1.3.29" />
        <vers num="1.3.3" />
        <vers num="1.3.31" />
        <vers num="1.3.32" />
        <vers num="1.3.4" />
        <vers num="1.3.6" />
        <vers num="1.3.7" edition="" />
        <vers num="1.3.7" edition=":dev" />
        <vers num="1.3.9" />
      </prod>
      <prod vendor="openpkg" name="openpkg">
        <vers num="2.0" />
        <vers num="2.1" />
        <vers num="2.2" />
        <vers num="current" />
      </prod>
      <prod vendor="hp" name="hp-ux">
        <vers num="11.00" />
        <vers num="11.11" />
        <vers num="11.20" />
        <vers num="11.22" />
      </prod>
      <prod vendor="slackware" name="slackware_linux">
        <vers num="10.0" />
        <vers num="8.0" />
        <vers num="8.1" />
        <vers num="9.0" />
        <vers num="9.1" />
        <vers num="current" />
      </prod>
      <prod vendor="suse" name="suse_linux">
        <vers num="8.0" />
        <vers num="8.1" />
        <vers num="8.2" />
        <vers num="9.0" edition="" />
        <vers num="9.0" edition=":x86_64" />
        <vers num="9.1" />
        <vers num="9.2" />
      </prod>
      <prod vendor="trustix" name="secure_linux">
        <vers num="1.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0941" published="2005-02-09" name="CVE-2004-0941" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Multiple buffer overflows in the gd graphics library (libgd) 2.0.21 and earlier may allow remote attackers to execute arbitrary code via malformed image files that trigger the overflows due to improper calls to the gdMalloc function, a different set of vulnerabilities than CVE-2004-0990.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.trustix.org/errata/2004/0058" source="TRUSTIX" patch="1" adv="1">2004-0058</ref>
      <ref url="http://www.securityfocus.com/bid/11663" source="BID" patch="1" adv="1">11663</ref>
      <ref url="http://secunia.com/advisories/13179/" source="SECUNIA">13179</ref>
      <ref url="http://seclists.org/lists/bugtraq/2004/Nov/0203.html" source="UBUNTU">USN-25-1</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11176" source="OVAL">oval:org.mitre.oval:def:11176</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/18048" source="XF">gd-graphics-gdmalloc-bo(18048)</ref>
      <ref url="http://www.ubuntulinux.org/support/documentation/usn/usn-33-1" source="UBUNTU">USN-33-1</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2006-0194.html" source="REDHAT">RHSA-2006:0194</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-638.html" source="REDHAT">RHSA-2004:638</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:122" source="MANDRIVA">MDKSA-2006:122</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:114" source="MANDRIVA">MDKSA-2006:114</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:113" source="MANDRIVA">MDKSA-2006:113</ref>
      <ref url="http://www.debian.org/security/2004/dsa-601" source="DEBIAN">DSA-601</ref>
      <ref url="http://www.ciac.org/ciac/bulletins/p-071.shtml" source="CIAC">P-071</ref>
      <ref url="http://secunia.com/advisories/21050" source="SECUNIA">21050</ref>
      <ref url="http://secunia.com/advisories/20824" source="SECUNIA">20824</ref>
      <ref url="http://secunia.com/advisories/18686" source="SECUNIA">18686</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1195" source="OVAL" sig="1">oval:org.mitre.oval:def:1195</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gd_graphics_library" name="gdlib">
        <vers num="1.8.4" />
        <vers num="2.0.1" />
        <vers num="2.0.20" />
        <vers num="2.0.21" />
        <vers num="2.0.22" />
        <vers num="2.0.23" />
        <vers num="2.0.26" />
        <vers num="2.0.27" />
        <vers num="2.0.28" />
        <vers num="2.0.33" />
      </prod>
      <prod vendor="trustix" name="secure_linux">
        <vers num="1.5" />
        <vers num="2.0" />
        <vers num="2.1" />
        <vers num="2.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0942" published="2005-02-09" name="CVE-2004-0942" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Apache webserver 2.0.52 and earlier allows remote attackers to cause a denial of service (CPU consumption) via an HTTP GET request with a MIME header containing multiple lines with a large number of space characters.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/17930" source="XF" adv="1">apache-http-get-dos(17930)</ref>
      <ref url="http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=HPSBUX01123" source="HP">HPSBUX01123</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0789" source="VUPEN">ADV-2006-0789</ref>
      <ref url="http://www.trustix.org/errata/2004/0061/" source="TRUSTIX">2004-0061</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10962" source="OVAL">oval:org.mitre.oval:def:10962</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110384374213596&amp;w=2" source="HP">SSRT4876</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2004-November/028248.html" source="FULLDISC">20041101 DoS in Apache 2.0.52 ?</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-562.html" source="REDHAT">RHSA-2004:562</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2004:135" source="MANDRAKE">MDKSA-2004:135</ref>
      <ref url="http://support.avaya.com/elmodocs2/security/ASA-2006-081.htm" source="CONFIRM">http://support.avaya.com/elmodocs2/security/ASA-2006-081.htm</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-102198-1" source="SUNALERT">102198</ref>
      <ref url="http://secunia.com/advisories/19072" source="SECUNIA">19072</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2005/Aug/msg00000.html" source="APPLE">APPLE-SA-2005-08-15</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2005//Aug/msg00001.html" source="APPLE">APPLE-SA-2005-08-17</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apache" name="http_server">
        <vers prev="1" num="2.0.52" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" seq="2004-0943" reject="1" published="2004-12-31" name="CVE-2004-0943" modified="2008-09-10">
    <desc>
      <descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: none.  Reason: This candidate was withdrawn by its CNA.  Further investigation showed that it was not a security issue.  Notes: none.</descript>
    </desc>
    <refs />
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0944" published="2004-02-28" name="CVE-2004-0944" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The web management interface for Mitel 3300 Integrated Communications Platform (ICP) before 4.2.2.11 generates easily predictable web session IDs, which allows remote attackers to hijack other sessions via the parentsessionid cookie.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.niscc.gov.uk/niscc/docs/re-20050228-00178.pdf?lang=en" source="MISC" patch="1" adv="1">http://www.niscc.gov.uk/niscc/docs/re-20050228-00178.pdf?lang=en</ref>
      <ref url="http://www.mitel.com/DocController?documentId=14223" source="CONFIRM" patch="1" adv="1">http://www.mitel.com/DocController?documentId=14223</ref>
      <ref url="http://www.corsaire.com/advisories/c040817-002.txt" source="MISC" adv="1">http://www.corsaire.com/advisories/c040817-002.txt</ref>
    </refs>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0945" published="2005-02-28" name="CVE-2004-0945" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The web management interface for Mitel 3300 Integrated Communications Platform (ICP) before 4.2.2.11 allows remote authenticated users to cause a denial of service (resource exhaustion) via a large number of active sessions, which exceeds ICP's maximum.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.niscc.gov.uk/niscc/docs/re-20050228-00178.pdf?lang=en" source="MISC" adv="1">http://www.niscc.gov.uk/niscc/docs/re-20050228-00178.pdf?lang=en</ref>
      <ref url="http://www.mitel.com/DocController?documentId=14223" source="CONFIRM" adv="1">http://www.mitel.com/DocController?documentId=14223</ref>
      <ref url="http://www.corsaire.com/advisories/c040817-003.txt" source="MISC" adv="1">http://www.corsaire.com/advisories/c040817-003.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mitel" name="mitel_3300_integrated_communication_platform">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0946" published="2005-01-10" name="CVE-2004-0946" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">rquotad in nfs-utils (rquota_server.c) before 1.0.6-r6 on 64-bit architectures does not properly perform an integer conversion, which leads to a stack-based buffer overflow and allows remote attackers to execute arbitrary code via a crafted NFS request.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/698302" source="CERT-VN">VU#698302</ref>
      <ref url="http://www.securityfocus.com/bid/11911" source="BID" patch="1" adv="1">11911</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-583.html" source="REDHAT" patch="1" adv="1">RHSA-2004:583</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200412-08.xml" source="GENTOO" patch="1" adv="1">GLSA-200412-08</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/18455" source="XF" adv="1">nfsutils-getquotainfo-bo(18455)</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-014.html" source="REDHAT">RHSA-2005:014</ref>
      <ref url="http://secunia.com/advisories/13440/" source="SECUNIA">13440</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10464" source="OVAL">oval:org.mitre.oval:def:10464</ref>
      <ref url="http://bugs.gentoo.org/show_bug.cgi?id=72113" source="MISC">http://bugs.gentoo.org/show_bug.cgi?id=72113</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/426072/30/6740/threaded" source="FEDORA">FLSA-2006:138098</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:005" source="MANDRAKE">MDKSA-2005:005</ref>
    </refs>
    <vuln_soft>
      <prod vendor="nfs" name="nfs-utils">
        <vers num="1.0" />
        <vers num="1.0.1" />
        <vers num="1.0.2" />
        <vers num="1.0.3" />
        <vers num="1.0.4" />
        <vers num="1.0.6" />
      </prod>
      <prod vendor="redhat" name="enterprise_linux">
        <vers num="3.0" edition="" />
        <vers num="3.0" edition=":enterprise_server" />
        <vers num="3.0" edition=":advanced_server" />
        <vers num="3.0" edition=":workstation_server" />
      </prod>
      <prod vendor="redhat" name="enterprise_linux_desktop">
        <vers num="3.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0947" published="2005-02-09" name="CVE-2004-0947" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Buffer overflow in unarj before 2.63a-r2 allows remote attackers to execute arbitrary code via an arj archive that contains long filenames.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/11665" source="BID" patch="1" adv="1">11665</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200411-29.xml" source="GENTOO" patch="1" adv="1">GLSA-200411-29</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/18044" source="XF" adv="1">unarj-longfilename-bo(18044)</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-007.html" source="REDHAT">RHSA-2005:007</ref>
      <ref url="http://www.debian.org/security/2005/dsa-652" source="DEBIAN">DSA-652</ref>
      <ref url="http://lwn.net/Articles/121827/" source="FEDORA">FLSA:2272</ref>
    </refs>
    <vuln_soft>
      <prod vendor="arj_software_inc." name="unarj">
        <vers num="2.62" />
        <vers num="2.63_a" />
        <vers num="2.64" />
        <vers num="2.65" />
      </prod>
      <prod vendor="gentoo" name="linux">
        <vers num="" />
      </prod>
      <prod vendor="suse" name="suse_linux">
        <vers num="9.0" />
        <vers num="9.1" />
        <vers num="9.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" seq="2004-0948" reject="1" published="2004-12-31" name="CVE-2004-0948" modified="2008-09-10">
    <desc>
      <descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: none.  Reason: This candidate was withdrawn by its CNA.  It was a duplicate assignment before public disclosure.  Notes: none.</descript>
    </desc>
    <refs />
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0949" published="2005-01-10" name="CVE-2004-0949" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)" CVSS_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_base_score="6.4">
    <desc>
      <descript source="cve">The smb_recv_trans2 function call in the samba filesystem (smbfs) in Linux kernel 2.4 and 2.6 does not properly handle the re-assembly of fragmented packets correctly, which could allow remote samba servers to (1) read arbitrary kernel information or (2) raise a counter value to an arbitrary number by sending the first part of the fragmented packet multiple times.</descript>
    </desc>
    <loss_types>
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/11695" source="BID" patch="1" adv="1">11695</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-537.html" source="REDHAT" patch="1" adv="1">RHSA-2004:537</ref>
      <ref url="https://bugzilla.fedora.us/show_bug.cgi?id=2336" source="FEDORA">FLSA:2336</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/18137" source="XF" adv="1">linux-smbrecvtrans2-memory-leak(18137)</ref>
      <ref url="http://www.trustix.org/errata/2004/0061/" source="TRUSTIX">2004-0061</ref>
      <ref url="http://security.e-matters.de/advisories/142004.html" source="MISC">http://security.e-matters.de/advisories/142004.html</ref>
      <ref url="http://secunia.com/advisories/13232/" source="SECUNIA">13232</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10360" source="OVAL">oval:org.mitre.oval:def:10360</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110072140811965&amp;w=2" source="BUGTRAQ" adv="1">20041117 Advisory 14/2004: Linux 2.x smbfs multiple remote vulnerabilities</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-505.html" source="REDHAT">RHSA-2004:505</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-504.html" source="REDHAT">RHSA-2004:504</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:022" source="MANDRAKE">MDKSA-2005:022</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1082" source="DEBIAN">DSA-1082</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1070" source="DEBIAN">DSA-1070</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1069" source="DEBIAN">DSA-1069</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1067" source="DEBIAN">DSA-1067</ref>
      <ref url="http://secunia.com/advisories/20338" source="SECUNIA">20338</ref>
      <ref url="http://secunia.com/advisories/20202" source="SECUNIA">20202</ref>
      <ref url="http://secunia.com/advisories/20163" source="SECUNIA">20163</ref>
      <ref url="http://secunia.com/advisories/20162" source="SECUNIA">20162</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110082989725345&amp;w=2" source="UBUNTU">USN-30-1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="linux" name="linux_kernel">
        <vers num="2.4.0" edition="test1" />
        <vers num="2.4.0" edition="test10" />
        <vers num="2.4.0" edition="test11" />
        <vers num="2.4.0" edition="test12" />
        <vers num="2.4.0" edition="test2" />
        <vers num="2.4.0" edition="test3" />
        <vers num="2.4.0" edition="test4" />
        <vers num="2.4.0" edition="test5" />
        <vers num="2.4.0" edition="test6" />
        <vers num="2.4.0" edition="test7" />
        <vers num="2.4.0" edition="test8" />
        <vers num="2.4.0" edition="test9" />
        <vers num="2.4.1" />
        <vers num="2.4.10" />
        <vers num="2.4.11" />
        <vers num="2.4.12" />
        <vers num="2.4.13" />
        <vers num="2.4.14" />
        <vers num="2.4.15" />
        <vers num="2.4.16" />
        <vers num="2.4.17" />
        <vers num="2.4.18" edition="" />
        <vers num="2.4.18" edition=":x86" />
        <vers num="2.4.18" edition="pre1" />
        <vers num="2.4.18" edition="pre2" />
        <vers num="2.4.18" edition="pre3" />
        <vers num="2.4.18" edition="pre4" />
        <vers num="2.4.18" edition="pre5" />
        <vers num="2.4.18" edition="pre6" />
        <vers num="2.4.18" edition="pre7" />
        <vers num="2.4.18" edition="pre8" />
        <vers num="2.4.19" edition="pre1" />
        <vers num="2.4.19" edition="pre2" />
        <vers num="2.4.19" edition="pre3" />
        <vers num="2.4.19" edition="pre4" />
        <vers num="2.4.19" edition="pre5" />
        <vers num="2.4.19" edition="pre6" />
        <vers num="2.4.2" />
        <vers num="2.4.20" />
        <vers num="2.4.21" edition="pre1" />
        <vers num="2.4.21" edition="pre4" />
        <vers num="2.4.21" edition="pre7" />
        <vers num="2.4.22" />
        <vers num="2.4.23" edition="pre9" />
        <vers num="2.4.23_ow2" />
        <vers num="2.4.24" />
        <vers num="2.4.24_ow1" />
        <vers num="2.4.25" />
        <vers num="2.4.26" />
        <vers num="2.4.27" edition="pre1" />
        <vers num="2.4.27" edition="pre2" />
        <vers num="2.4.27" edition="pre3" />
        <vers num="2.4.27" edition="pre4" />
        <vers num="2.4.27" edition="pre5" />
        <vers num="2.4.3" />
        <vers num="2.4.4" />
        <vers num="2.4.5" />
        <vers num="2.4.6" />
        <vers num="2.4.7" />
        <vers num="2.4.8" />
        <vers num="2.4.9" />
        <vers num="2.6.0" edition="test1" />
        <vers num="2.6.0" edition="test10" />
        <vers num="2.6.0" edition="test11" />
        <vers num="2.6.0" edition="test2" />
        <vers num="2.6.0" edition="test3" />
        <vers num="2.6.0" edition="test4" />
        <vers num="2.6.0" edition="test5" />
        <vers num="2.6.0" edition="test6" />
        <vers num="2.6.0" edition="test7" />
        <vers num="2.6.0" edition="test8" />
        <vers num="2.6.0" edition="test9" />
        <vers num="2.6.1" edition="rc1" />
        <vers num="2.6.1" edition="rc2" />
        <vers num="2.6.2" />
        <vers num="2.6.3" />
        <vers num="2.6.4" />
        <vers num="2.6.5" />
        <vers num="2.6.6" edition="rc1" />
        <vers num="2.6.7" edition="rc1" />
        <vers num="2.6.8" edition="rc1" />
        <vers num="2.6.8" edition="rc2" />
        <vers num="2.6.8" edition="rc3" />
        <vers num="2.6.9" edition="2.6.20" />
        <vers num="2.6_test9_cvs" />
      </prod>
      <prod vendor="redhat" name="enterprise_linux">
        <vers num="2.1" edition="" />
        <vers num="2.1" edition=":workstation_ia64" />
        <vers num="2.1" edition=":advanced_server" />
        <vers num="2.1" edition=":advanced_server_ia64" />
        <vers num="2.1" edition=":workstation" />
        <vers num="2.1" edition=":enterprise_server" />
        <vers num="2.1" edition=":enterprise_server_ia64" />
        <vers num="3.0" edition="" />
        <vers num="3.0" edition=":workstation" />
        <vers num="3.0" edition=":advanced_servers" />
        <vers num="3.0" edition=":enterprise_server" />
      </prod>
      <prod vendor="redhat" name="enterprise_linux_desktop">
        <vers num="3.0" />
      </prod>
      <prod vendor="redhat" name="fedora_core">
        <vers num="core_2.0" />
        <vers num="core_3.0" />
      </prod>
      <prod vendor="redhat" name="linux_advanced_workstation">
        <vers num="2.1" edition="" />
        <vers num="2.1" edition=":itanium_processor" />
        <vers num="2.1" edition=":ia64" />
      </prod>
      <prod vendor="suse" name="suse_linux">
        <vers num="1.0" edition="" />
        <vers num="1.0" edition=":desktop" />
        <vers num="8" edition="" />
        <vers num="8" edition=":enterprise_server" />
        <vers num="8.1" />
        <vers num="8.2" />
        <vers num="9.0" edition="" />
        <vers num="9.0" edition=":enterprise_server" />
        <vers num="9.0" edition=":x86_64" />
        <vers num="9.1" />
        <vers num="9.2" />
      </prod>
      <prod vendor="trustix" name="secure_linux">
        <vers num="1.5" />
        <vers num="2.0" />
        <vers num="2.1" />
        <vers num="2.2" />
      </prod>
      <prod vendor="ubuntu" name="ubuntu_linux">
        <vers num="4.1" edition="" />
        <vers num="4.1" edition=":ppc" />
        <vers num="4.1" edition=":ia64" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0950" published="2005-02-09" name="CVE-2004-0950" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">NetOp Host before 7.65 build 2004278 allows remote attackers to obtain sensitive hostname, username and local IP address information via (1) a NetOp HELO request, or (2) when responses are disabled, a "custom" HELO request.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <access />
      <config />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/11710" source="BID" patch="1" adv="1">11710</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/18171" source="XF">danware-helo-obtain-information(18171)</ref>
      <ref url="http://www.corsaire.com/advisories/c040619-001.txt" source="MISC" adv="1">http://www.corsaire.com/advisories/c040619-001.txt</ref>
      <ref url="http://msgs.securepoint.com/cgi-bin/get/bugtraq0411/213.html" source="BUGTRAQ">20041119 Corsaire Security Advisory - Danware NetOp Host multiple information disclosure issues</ref>
    </refs>
    <vuln_soft>
      <prod vendor="danware_data" name="netop">
        <vers num="6.0" />
        <vers num="6.50" />
        <vers num="7.0.1_build2002-01-29" />
        <vers num="7.50_build2003-08-04" />
        <vers num="7.60_build2003-06-24" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0951" published="2004-12-31" name="CVE-2004-0951" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">The make_recovery command for the TFTP server in HP Ignite-UX before C.6.2.241 makes a copy of the password file in the TFTP directory tree, which allows remote attackers to obtain sensitive information.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/21858" source="XF" patch="1">hpigniteux-makerecovery-bypass-security(21858)</ref>
      <ref url="http://www.corsaire.com/advisories/c041123-001.txt" source="MISC" patch="1" adv="1">http://www.corsaire.com/advisories/c041123-001.txt</ref>
      <ref url="http://secunia.com/advisories/16456/" source="SECUNIA" patch="1" adv="1">16456</ref>
      <ref url="http://www.securityfocus.com/bid/14568" source="BID">14568</ref>
      <ref url="http://securitytracker.com/id?1014711" source="SECTRACK">1014711</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hp" name="ignite-ux">
        <vers num="c.6.2.241" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0952" published="2004-12-31" name="CVE-2004-0952" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:P)" CVSS_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_base_score="6.4">
    <desc>
      <descript source="cve">HP-UX B.11.00 through B.11.23, when running Ignite-UX and using the add_new_client command, causes the TFTP server to set world-writable permissions on part of the directory tree, which allows remote attackers to modify data or cause disk consumption.</descript>
    </desc>
    <loss_types>
      <avail />
      <int />
    </loss_types>
    <vuln_types>
      <config />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/21857" source="XF" patch="1">hpigniteux-addnewclient-gain-access(21857)</ref>
      <ref url="http://secunia.com/advisories/16456/" source="SECUNIA" patch="1" adv="1">16456</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112422597529112&amp;w=2" source="HP" patch="1" adv="1">HPSBUX01219</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5775" source="OVAL">oval:org.mitre.oval:def:5775</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112422597529112&amp;w=2" source="HP">HPSBUX01219</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112420609211136&amp;w=2" source="BUGTRAQ" adv="1">20050816 Corsaire Security Advisory: HP Ignite-UX filesystem permissions issue</ref>
      <ref url="http://securitytracker.com/id?1014711" source="SECTRACK">1014711</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hp" name="hp-ux">
        <vers num="11.00" />
        <vers num="11.11" />
        <vers num="11.22" />
        <vers num="11.23" edition="" />
        <vers num="11.23" edition=":ia64_64-bit" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0953" published="2005-01-10" name="CVE-2004-0953" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Buffer overflow in the C2S module in the open source Jabber 2.x server (Jabberd) allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a long username.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/11741" source="BID" patch="1" adv="1">11741</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/18238" source="XF" adv="1">jabberd2-c2s-bo(18238)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110144303826709&amp;w=2" source="BUGTRAQ" adv="1">20041124 Jabberd2.x remote BuffJabberd2.x remote Buffer Overflowser Overflows</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2004-November/029346.html" source="FULLDISC">20041124 Jabberd2.x remote BuffJabberd2.x remote Buffer Overflowser Overflows</ref>
    </refs>
    <vuln_soft>
      <prod vendor="jabber_software_foundation" name="jabber_server">
        <vers num="2.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" seq="2004-0954" reject="1" published="2004-12-23" name="CVE-2004-0954" modified="2008-09-10">
    <desc>
      <descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: CVE-2004-0597.  Reason: This candidate is a reservation duplicate of CVE-2004-0597.  Notes: All CVE users should reference CVE-2004-0597 instead of this candidate.  All references and descriptions in this candidate have been removed to prevent accidental usage.</descript>
    </desc>
    <refs />
  </entry>
  <entry type="CVE" seq="2004-0955" reject="1" published="2004-12-23" name="CVE-2004-0955" modified="2008-09-10">
    <desc>
      <descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: CVE-2004-0599.  Reason: This candidate is a reservation duplicate of CVE-2004-0599 (the first item listed in that candidate).  Notes: All CVE users should reference CVE-2004-0599 instead of this candidate.  All references and descriptions have been removed from this candidate to prevent accidental usage.</descript>
    </desc>
    <refs />
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0956" published="2005-01-10" name="CVE-2004-0956" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">MySQL before 4.0.20 allows remote attackers to cause a denial of service (application crash) via a MATCH AGAINST query with an opening double quote but no closing double quote.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200410-22.xml" source="GENTOO" patch="1" adv="1">GLSA-200410-22 </ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/17768" source="XF" adv="1">mysql-match-against-dos(17768)</ref>
      <ref url="http://www.trustix.net/errata/2004/0054/" source="TRUSTIX">2004-0054</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2004_01_sr.html" source="SUSE">SUSE-SR:2004:001</ref>
      <ref url="http://lists.mysql.com/packagers/202" source="CONFIRM">http://lists.mysql.com/packagers/202</ref>
      <ref url="http://bugs.mysql.com/bug.php?id=3870" source="CONFIRM">http://bugs.mysql.com/bug.php?id=3870</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mysql" name="mysql">
        <vers num="4.0.0" />
        <vers num="4.0.1" />
        <vers num="4.0.10" />
        <vers num="4.0.11" edition="gamma" />
        <vers num="4.0.12" />
        <vers num="4.0.13" />
        <vers num="4.0.14" />
        <vers num="4.0.15" />
        <vers num="4.0.18" />
        <vers num="4.0.2" />
        <vers num="4.0.20" />
        <vers num="4.0.3" />
        <vers num="4.0.4" />
        <vers num="4.0.5" />
        <vers num="4.0.5a" />
        <vers num="4.0.6" />
        <vers num="4.0.7" edition="gamma" />
        <vers num="4.0.8" edition="gamma" />
        <vers num="4.0.9" edition="gamma" />
      </prod>
      <prod vendor="suse" name="suse_linux">
        <vers num="8.0" />
        <vers num="8.1" />
        <vers num="8.2" />
        <vers num="9.0" edition="" />
        <vers num="9.0" edition=":x86_64" />
        <vers num="9.1" />
        <vers num="9.2" />
      </prod>
      <prod vendor="ubuntu" name="ubuntu_linux">
        <vers num="4.1" edition="" />
        <vers num="4.1" edition=":ia64" />
        <vers num="4.1" edition=":ppc" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0957" published="2005-02-09" name="CVE-2004-0957" modified="2008-09-10" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Unknown vulnerability in MySQL 3.23.58 and earlier, when a local user has privileges for a database whose name includes a "_" (underscore), grants privileges to other databases that have similar names, which can allow the user to conduct unauthorized activities.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/17783" source="XF" adv="1">mysql-underscore-gain-priv(17783)</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-611.html" source="REDHAT">RHSA-2004:611</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-597.html" source="REDHAT">RHSA-2004:597</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:070" source="MANDRAKE">MDKSA-2005:070</ref>
      <ref url="http://www.debian.org/security/2005/dsa-707" source="DEBIAN">DSA-707</ref>
      <ref url="http://www.ciac.org/ciac/bulletins/p-018.shtml" source="CIAC">P-018</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110140517515735&amp;w=2" source="UBUNTU">USN-32-1</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000947" source="CONECTIVA">CLA-2005:947</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mysql" name="mysql">
        <vers num="3.20" />
        <vers num="3.20.32a" />
        <vers num="3.21" />
        <vers num="3.22" />
        <vers num="3.22.26" />
        <vers num="3.22.27" />
        <vers num="3.22.28" />
        <vers num="3.22.29" />
        <vers num="3.22.30" />
        <vers num="3.22.32" />
        <vers num="3.23" />
        <vers num="3.23.10" />
        <vers num="3.23.2" />
        <vers num="3.23.22" />
        <vers num="3.23.23" />
        <vers num="3.23.24" />
        <vers num="3.23.25" />
        <vers num="3.23.26" />
        <vers num="3.23.27" />
        <vers num="3.23.28" edition="gamma" />
        <vers num="3.23.29" />
        <vers num="3.23.3" />
        <vers num="3.23.30" />
        <vers num="3.23.31" />
        <vers num="3.23.32" />
        <vers num="3.23.33" />
        <vers num="3.23.34" />
        <vers num="3.23.36" />
        <vers num="3.23.37" />
        <vers num="3.23.38" />
        <vers num="3.23.39" />
        <vers num="3.23.4" />
        <vers num="3.23.40" />
        <vers num="3.23.41" />
        <vers num="3.23.42" />
        <vers num="3.23.43" />
        <vers num="3.23.44" />
        <vers num="3.23.45" />
        <vers num="3.23.46" />
        <vers num="3.23.47" />
        <vers num="3.23.48" />
        <vers num="3.23.49" />
        <vers num="3.23.5" />
        <vers num="3.23.50" />
        <vers num="3.23.51" />
        <vers num="3.23.52" />
        <vers num="3.23.53" />
        <vers num="3.23.53a" />
        <vers num="3.23.54" />
        <vers num="3.23.54a" />
        <vers num="3.23.55" />
        <vers num="3.23.56" />
        <vers num="3.23.58" />
        <vers num="3.23.59" />
        <vers num="3.23.8" />
        <vers num="3.23.9" />
        <vers num="4.0.0" />
        <vers num="4.0.1" />
        <vers num="4.0.10" />
        <vers num="4.0.11" edition="gamma" />
        <vers num="4.0.12" />
        <vers num="4.0.13" />
        <vers num="4.0.14" />
        <vers num="4.0.15" />
        <vers num="4.0.18" />
        <vers num="4.0.2" />
        <vers num="4.0.20" />
        <vers num="4.0.3" />
        <vers num="4.0.4" />
        <vers num="4.0.5" />
        <vers num="4.0.5a" />
        <vers num="4.0.6" />
        <vers num="4.0.7" edition="gamma" />
        <vers num="4.0.8" edition="gamma" />
        <vers num="4.0.9" edition="gamma" />
      </prod>
      <prod vendor="openpkg" name="openpkg">
        <vers num="2.1" />
        <vers num="2.2" />
        <vers num="current" />
      </prod>
      <prod vendor="redhat" name="enterprise_linux">
        <vers num="3.0" edition="" />
        <vers num="3.0" edition=":workstation_server" />
        <vers num="3.0" edition=":advanced_server" />
        <vers num="3.0" edition=":enterprise_server" />
      </prod>
      <prod vendor="redhat" name="enterprise_linux_desktop">
        <vers num="3.0" />
      </prod>
      <prod vendor="suse" name="suse_linux">
        <vers num="8.0" />
        <vers num="8.1" />
        <vers num="8.2" />
        <vers num="9.0" edition="" />
        <vers num="9.0" edition=":x86_64" />
        <vers num="9.1" />
        <vers num="9.2" />
      </prod>
      <prod vendor="trustix" name="secure_linux">
        <vers num="1.5" />
        <vers num="2.0" />
        <vers num="2.1" />
      </prod>
      <prod vendor="ubuntu" name="ubuntu_linux">
        <vers num="4.1" edition="" />
        <vers num="4.1" edition=":ppc" />
        <vers num="4.1" edition=":ia64" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0958" published="2004-11-03" name="CVE-2004-0958" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">php_variables.c in PHP before 5.0.2 allows remote attackers to read sensitive memory contents via (1) GET, (2) POST, or (3) COOKIE GPC variables that end in an open bracket character, which causes PHP to calculate an incorrect string length.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/17393" source="XF" patch="1" adv="1">php-phpinfo-disclose-memory(17393)</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-687.html" source="REDHAT" patch="1" adv="1">RHSA-2004:687</ref>
      <ref url="https://bugzilla.fedora.us/show_bug.cgi?id=2344" source="FEDORA">FLSA:2344</ref>
      <ref url="http://securitytracker.com/id?1011279" source="SECTRACK">1011279</ref>
      <ref url="http://secunia.com/advisories/12560/" source="SECUNIA">12560</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10863" source="OVAL">oval:org.mitre.oval:def:10863</ref>
      <ref url="http://archives.neohapsis.com/archives/vulnwatch/2004-q3/0053.html" source="VULNWATCH">20040915 [VulnWatch] PHP Vulnerability N. 1</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109527531130492&amp;w=2" source="BUGTRAQ">20040915 PHP Vulnerability N. 1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="php" name="php">
        <vers prev="1" num="5.0.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2004-0959" published="2004-11-03" name="CVE-2004-0959" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">rfc1867.c in PHP before 5.0.2 allows local users to upload files to arbitrary locations via a PHP script with a certain MIME header that causes the "$_FILES" array to be modified.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/17392" source="XF" patch="1" adv="1">php-mime-array-execute-code(17392)</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-687.html" source="REDHAT" patch="1" adv="1">RHSA-2004:687</ref>
      <ref url="https://bugzilla.fedora.us/show_bug.cgi?id=2344" source="FEDORA">FLSA:2344</ref>
      <ref url="http://securitytracker.com/id?1011307" source="SECTRACK">1011307</ref>
      <ref url="http://secunia.com/advisories/12560/" source="SECUNIA">12560</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10961" source="OVAL">oval:org.mitre.oval:def:10961</ref>
      <ref url="http://archives.neohapsis.com/archives/vulnwatch/2004-q3/0054.html" source="VULNWATCH">20040915 Php Vulnerability N. 2</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109534848430404&amp;w=2" source="BUGTRAQ">20040915 Php Vulnerability N. 2</ref>
    </refs>
    <vuln_soft>
      <prod vendor="php" name="php">
        <vers prev="1" num="5.0.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0960" published="2005-02-09" name="CVE-2004-0960" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">FreeRADIUS before 1.0.1 allows remote attackers to cause a denial of service (core dump) via malformed USR vendor-specific attributes (VSA) that cause a memcpy operation with a -1 argument.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/541574" source="CERT-VN" adv="1">VU#541574</ref>
      <ref url="http://www.securityfocus.com/bid/11222" source="BID" patch="1" adv="1">11222</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/17440" source="XF" adv="1">freeradius-dos(17440)</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200409-29.xml" source="GENTOO">GLSA-200409-29</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11023" source="OVAL">oval:org.mitre.oval:def:11023</ref>
    </refs>
    <vuln_soft>
      <prod vendor="freeradius" name="freeradius">
        <vers num="0.2" />
        <vers num="0.3" />
        <vers num="0.4" />
        <vers num="0.5" />
        <vers num="0.8" />
        <vers num="0.8.1" />
        <vers num="0.9" />
        <vers num="0.9.1" />
        <vers num="0.9.2" />
        <vers num="0.9.3" />
        <vers num="1.0.0" />
      </prod>
      <prod vendor="redhat" name="enterprise_linux">
        <vers num="3.0" edition="" />
        <vers num="3.0" edition=":advanced_server" />
        <vers num="3.0" edition=":enterprise_server" />
      </prod>
      <prod vendor="redhat" name="fedora_core">
        <vers num="core_2.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0961" published="2005-02-09" name="CVE-2004-0961" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Memory leak in FreeRADIUS before 1.0.1 allows remote attackers to cause a denial of service (memory exhaustion) via a series of Access-Request packets with (1) Ascend-Send-Secret, (2) Ascend-Recv-Secret, or (3) Tunnel-Password attributes.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/541574" source="CERT-VN" adv="1">VU#541574</ref>
      <ref url="http://www.securityfocus.com/bid/11222" source="BID" patch="1" adv="1">11222</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/17440" source="XF" adv="1">freeradius-dos(17440)</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200409-29.xml" source="GENTOO">GLSA-200409-29</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10024" source="OVAL">oval:org.mitre.oval:def:10024</ref>
    </refs>
    <vuln_soft>
      <prod vendor="freeradius" name="freeradius">
        <vers num="0.2" />
        <vers num="0.3" />
        <vers num="0.4" />
        <vers num="0.5" />
        <vers num="0.8" />
        <vers num="0.8.1" />
        <vers num="0.9" />
        <vers num="0.9.1" />
        <vers num="0.9.2" />
        <vers num="0.9.3" />
        <vers num="1.0.0" />
      </prod>
      <prod vendor="redhat" name="enterprise_linux">
        <vers num="3.0" edition="" />
        <vers num="3.0" edition=":advanced_server" />
        <vers num="3.0" edition=":enterprise_server" />
      </prod>
      <prod vendor="redhat" name="fedora_core">
        <vers num="core_2.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0962" published="2005-02-09" name="CVE-2004-0962" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Apple Remote Desktop Client 1.2.4 executes a GUI application as root when it is started by an Apple Remote Desktop Administrator application, which allows remote authenticated users to execute arbitrary code when loginwindow is active via Fast User Switching.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" admin="1" />
    </loss_types>
    <vuln_types>
      <design />
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://lists.apple.com/archives/security-announce/2004/Oct/msg00002.html" source="APPLE">APPLE-SA-2004-10-27</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="remote_desktop">
        <vers num="2.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0963" published="2005-02-09" name="CVE-2004-0963" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Buffer overflow in Microsoft Word 2002 (10.6612.6714) SP3, and possibly other versions, allows remote attackers to cause a denial of service (application exception) and possibly execute arbitrary code in winword.exe via certain unexpected values in a .doc file, including (1) an offset that triggers an out-of-bounds memory access, (2) a certain value that causes a large memory copy as triggered by an integer conversion error, and other values.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/17635" source="XF" adv="1">word-file-parsing-bo(17635)</ref>
      <ref url="http://www.microsoft.com/technet/Security/bulletin/ms05-023.mspx" source="MS">MS05-023</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109716247230733&amp;w=2" source="BUGTRAQ" adv="1">20041006 [HV-HIGH] MS Word multiple exceptions, at least one exploitable</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:420" source="OVAL" sig="1">oval:org.mitre.oval:def:420</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2216" source="OVAL" sig="1">oval:org.mitre.oval:def:2216</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2105" source="OVAL" sig="1">oval:org.mitre.oval:def:2105</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1795" source="OVAL" sig="1">oval:org.mitre.oval:def:1795</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="word">
        <vers num="2002" edition="sp3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0964" published="2005-02-09" name="CVE-2004-0964" modified="2011-09-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Buffer overflow in Zinf 2.2.1 on Windows, and other older versions for Linux, allows remote attackers or local users to execute arbitrary code via certain values in a .pls file.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/11248" source="BID" patch="1" adv="1">11248</ref>
      <ref url="http://www.debian.org/security/2004/dsa-587" source="DEBIAN" patch="1" adv="1">DSA-587</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/17491" source="XF" adv="1">zinf-pls-bo(17491)</ref>
      <ref url="http://securityreason.com/securityalert/8341" source="SREASON">8341</ref>
      <ref url="http://secunia.com/advisories/12656" source="SECUNIA">12656</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109638486728548&amp;w=2" source="BUGTRAQ" adv="1">20040927 Re: Buffer overflow in Zinf 2.2.1 for Win32+exploit</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109608092609200&amp;w=2" source="BUGTRAQ">20040924 Buffer overflow in Zinf 2.2.1 for Win32</ref>
    </refs>
    <vuln_soft>
      <prod vendor="zinf" name="zinf">
        <vers num="2.2.1" />
      </prod>
      <prod vendor="debian" name="debian_linux">
        <vers num="3.0" edition="" />
        <vers num="3.0" edition=":hppa" />
        <vers num="3.0" edition=":mipsel" />
        <vers num="3.0" edition=":mips" />
        <vers num="3.0" edition=":ia-32" />
        <vers num="3.0" edition=":m68k" />
        <vers num="3.0" edition=":sparc" />
        <vers num="3.0" edition=":s-390" />
        <vers num="3.0" edition=":alpha" />
        <vers num="3.0" edition=":arm" />
        <vers num="3.0" edition=":ia-64" />
        <vers num="3.0" edition=":ppc" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0965" published="2005-02-09" name="CVE-2004-0965" modified="2009-03-04" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">stmkfont in HP-UX B.11.00 through B.11.23 relies on the user-specified PATH when executing certain commands, which allows local users to execute arbitrary code by modifying the PATH environment variable to point to malicious programs.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" admin="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/11493" source="BID" patch="1" adv="1">11493</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/17813" source="XF" adv="1">hpux-stmkfont-gain-privileges(17813)</ref>
      <ref url="http://www.securityfocus.com/advisories/7351" source="HP">SSRT4807</ref>
      <ref url="http://www.nsfocus.com/english/homepage/research/0402.htm" source="MISC">http://www.nsfocus.com/english/homepage/research/0402.htm</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5538" source="OVAL">oval:org.mitre.oval:def:5538</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109837243713696&amp;w=2" source="BUGTRAQ">20041021 NSFOCUS SA2004-02 : HP-UX stmkfont Local Privilege Escalation Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hp" name="hp-ux">
        <vers num="11.00" />
        <vers num="11.11" />
        <vers num="11.22" />
        <vers num="11.23" edition="" />
        <vers num="11.23" edition=":ia64_64-bit" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2004-0966" published="2005-02-09" name="CVE-2004-0966" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">The (1) autopoint and (2) gettextize scripts in the GNU gettext package 1.14 and later versions, as used in Trustix Secure Linux 1.5 through 2.1 and other operating systems, allows local users to overwrite files via a symlink attack on temporary files.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/11282" source="BID" patch="1" adv="1">11282</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/17583" source="XF" adv="1">script-temporary-file-overwrite(17583)</ref>
      <ref url="http://www.trustix.org/errata/2004/0050" source="TRUSTIX">2004-0050</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200410-10.xml" source="GENTOO">GLSA-200410-10</ref>
      <ref url="http://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=136323" source="CONFIRM">http://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=136323</ref>
      <ref url="http://wwwnew.mandriva.com/security/advisories?name=MDKSA-2006:051" source="MANDRIVA">MDKSA-2006:051</ref>
      <ref url="http://www.redhat.com/archives/fedora-legacy-announce/2006-January/msg00000.html" source="FEDORA">FLSA:136323</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110382652226638&amp;w=2" source="OPENPKG">OpenPKG-SA-2004.055</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109899973325734&amp;w=2" source="UBUNTU">USN-5-1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gnu" name="gettext">
        <vers num="0.14.1" />
      </prod>
      <prod vendor="ubuntu" name="ubuntu_linux">
        <vers num="4.1" edition="" />
        <vers num="4.1" edition=":ia64" />
        <vers num="4.1" edition=":ppc" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0967" published="2005-02-09" name="CVE-2004-0967" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">The (1) pj-gs.sh, (2) ps2epsi, (3) pv.sh, and (4) sysvlp.sh scripts in the ESP Ghostscript (espgs) package in Trustix Secure Linux 1.5 through 2.1, and other operating systems, allow local users to overwrite files via a symlink attack on temporary files.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/11285" source="BID" patch="1" adv="1">11285</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/17583" source="XF" adv="1">script-temporary-file-overwrite(17583)</ref>
      <ref url="http://www.trustix.org/errata/2004/0050" source="TRUSTIX">2004-0050</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-081.html" source="REDHAT">RHSA-2005:081</ref>
      <ref url="http://secunia.com/advisories/20056" source="SECUNIA" adv="1">20056</ref>
      <ref url="http://secunia.com/advisories/19799" source="SECUNIA" adv="1">19799</ref>
      <ref url="http://secunia.com/advisories/17135" source="SECUNIA" adv="1">17135</ref>
      <ref url="http://secunia.com/advisories/16997" source="SECUNIA" adv="1">16997</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10284" source="OVAL">oval:org.mitre.oval:def:10284</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109900135814990&amp;w=2" source="UBUNTU">USN-3-1</ref>
      <ref url="http://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=136321" source="CONFIRM">http://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=136321</ref>
      <ref url="ftp://ftp.sco.com/pub/updates/UnixWare/SCOSA-2006.23/SCOSA-2006.23.txt" source="SCO">SCOSA-2006.23</ref>
      <ref url="ftp://ftp.sco.com/pub/updates/OpenServer/SCOSA-2006.19/SCOSA-2006.19.txt" source="SCO">SCOSA-2006.19</ref>
    </refs>
    <vuln_soft>
      <prod vendor="aladdin_enterprises" name="ghostscript">
        <vers num="4.3" />
        <vers num="4.3.2" />
        <vers num="5.10.10" edition="" />
        <vers num="5.10.10" edition=":mdk" />
        <vers num="5.10.10_1" edition="" />
        <vers num="5.10.10_1" edition=":mdk" />
        <vers num="5.10.12cl" />
        <vers num="5.10.15" />
        <vers num="5.10.16" />
        <vers num="5.10cl" />
        <vers num="5.50" />
        <vers num="5.50.8" />
        <vers num="5.50.8_7" />
        <vers num="6.51" />
        <vers num="6.52" />
        <vers num="6.53" />
        <vers num="7.0.4" />
        <vers num="7.0.5" />
        <vers num="7.0.6" />
        <vers num="7.0.7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2004-0968" published="2005-02-09" name="CVE-2004-0968" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">The catchsegv script in glibc 2.3.2 and earlier allows local users to overwrite files via a symlink attack on temporary files.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/11286" source="BID" patch="1" adv="1">11286</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/17583" source="XF" adv="1">script-temporary-file-overwrite(17583)</ref>
      <ref url="http://www.trustix.org/errata/2004/0050" source="TRUSTIX">2004-0050</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-261.html" source="REDHAT">RHSA-2005:261</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-586.html" source="REDHAT">RHSA-2004:586</ref>
      <ref url="http://www.debian.org/security/2005/dsa-636" source="DEBIAN">DSA-636</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200410-19.xml" source="GENTOO">GLSA-200410-19</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9523" source="OVAL">oval:org.mitre.oval:def:9523</ref>
      <ref url="http://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=136318" source="CONFIRM">http://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=136318</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109899903129801&amp;w=2" source="UBUNTU">USN-4-1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gnu" name="glibc">
        <vers num="2.0" />
        <vers num="2.0.1" />
        <vers num="2.0.2" />
        <vers num="2.0.3" />
        <vers num="2.0.4" />
        <vers num="2.0.5" />
        <vers num="2.0.6" />
        <vers num="2.1" />
        <vers num="2.1.1" />
        <vers num="2.1.1.6" />
        <vers num="2.1.2" />
        <vers num="2.1.3" />
        <vers num="2.1.3.10" />
        <vers num="2.1.9" />
        <vers num="2.2" />
        <vers num="2.2.1" />
        <vers num="2.2.2" />
        <vers num="2.2.3" />
        <vers num="2.2.4" />
        <vers num="2.2.5" />
        <vers num="2.3" />
        <vers num="2.3.1" />
        <vers num="2.3.10" />
        <vers num="2.3.2" />
        <vers num="2.3.3" />
        <vers num="2.3.4" />
      </prod>
      <prod vendor="redhat" name="enterprise_linux">
        <vers num="3.0" edition="" />
        <vers num="3.0" edition=":advanced_server" />
        <vers num="3.0" edition=":workstation_server" />
        <vers num="3.0" edition=":enterprise_server" />
      </prod>
      <prod vendor="redhat" name="enterprise_linux_desktop">
        <vers num="3.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2004-0969" published="2005-02-09" name="CVE-2004-0969" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">The groffer script in the Groff package 1.18 and later versions, as used in Trustix Secure Linux 1.5 through 2.1, and possibly other operating systems, allows local users to overwrite files via a symlink attack on temporary files.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/11287" source="BID" patch="1" adv="1">11287</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200411-15.xml" source="GENTOO" patch="1" adv="1">GLSA-200411-15</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/17583" source="XF" adv="1">script-temporary-file-overwrite(17583)</ref>
      <ref url="http://www.trustix.org/errata/2004/0050" source="TRUSTIX">2004-0050</ref>
      <ref url="http://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=136313" source="CONFIRM">http://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=136313</ref>
      <ref url="http://wwwnew.mandriva.com/security/advisories?name=MDKSA-2006:038" source="MANDRIVA">MDKSA-2006:038</ref>
      <ref url="http://secunia.com/advisories/18764" source="SECUNIA">18764</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gnu" name="groff">
        <vers num="1.19" />
      </prod>
      <prod vendor="gentoo" name="linux">
        <vers num="" />
      </prod>
      <prod vendor="ubuntu" name="ubuntu_linux">
        <vers num="4.1" edition="" />
        <vers num="4.1" edition=":ia64" />
        <vers num="4.1" edition=":ppc" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2004-0970" published="2005-02-09" name="CVE-2004-0970" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">The (1) gzexe, (2) zdiff, and (3) znew scripts in the gzip package, as used by other packages such as ncompress, allows local users to overwrite files via a symlink attack on temporary files.  NOTE: the znew vulnerability may overlap CVE-2003-0367.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/11288" source="BID" patch="1" adv="1">11288</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/17583" source="XF" adv="1">script-temporary-file-overwrite(17583)</ref>
      <ref url="http://www.trustix.org/errata/2004/0050" source="TRUSTIX">2004-0050</ref>
      <ref url="http://www.debian.org/security/2004/dsa-588" source="DEBIAN" adv="1">DSA-588</ref>
      <ref url="http://www.zataz.net/adviso/ncompress-09052005.txt" source="MISC">http://www.zataz.net/adviso/ncompress-09052005.txt</ref>
      <ref url="http://secunia.com/advisories/13131" source="SECUNIA">13131</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gnu" name="gzip">
        <vers num="1.2.4a" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2004-0971" published="2005-02-09" name="CVE-2004-0971" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">The krb5-send-pr script in the kerberos5 (krb5) package in Trustix Secure Linux 1.5 through 2.1, and possibly other operating systems, allows local users to overwrite files via a symlink attack on temporary files.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/11289" source="BID" patch="1" adv="1">11289</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200410-24.xml" source="GENTOO" patch="1" adv="1">GLSA-200410-24</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/17583" source="XF" adv="1">script-temporary-file-overwrite(17583)</ref>
      <ref url="http://www.trustix.org/errata/2004/0050" source="TRUSTIX">2004-0050</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-012.html" source="REDHAT">RHSA-2005:012</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10497" source="OVAL">oval:org.mitre.oval:def:10497</ref>
      <ref url="http://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=136304" source="CONFIRM">http://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=136304</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mit" name="kerberos">
        <vers num="5-1.3.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2004-0972" published="2005-02-09" name="CVE-2004-0972" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">The lvmcreate_initrd script in the lvm package in Trustix Secure Linux 1.5 through 2.1, and possibly other operating systems, allows local users to overwrite files via a symlink attack on temporary files.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.trustix.org/errata/2004/0050" source="TRUSTIX" patch="1" adv="1">2004-0050</ref>
      <ref url="http://www.securityfocus.com/bid/11290" source="BID" patch="1" adv="1">11290</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/17583" source="XF" adv="1">script-temporary-file-overwrite(17583)</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10632" source="OVAL">oval:org.mitre.oval:def:10632</ref>
      <ref url="http://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=136308" source="CONFIRM">http://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=136308</ref>
      <ref url="http://rhn.redhat.com/errata/RHBA-2004-232.html" source="REDHAT">RHBA-2004:232</ref>
    </refs>
    <vuln_soft>
      <prod vendor="lvm" name="logical_volume_management_utilities">
        <vers num="1.0.1" />
        <vers num="1.0.4" />
        <vers num="1.0.7" />
        <vers num="1.0.8" />
      </prod>
      <prod vendor="gentoo" name="linux">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" seq="2004-0973" reject="1" published="2004-12-23" name="CVE-2004-0973" modified="2008-09-10">
    <desc>
      <descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: CVE-2004-0457.  Reason: This candidate is a reservation duplicate of CVE-2004-0457.  Notes: All CVE users should reference CVE-2004-0457 instead of this candidate.  All references and descriptions in this candidate have been removed to prevent accidental usage.</descript>
    </desc>
    <refs />
  </entry>
  <entry type="CVE" severity="Low" seq="2004-0974" published="2005-02-09" name="CVE-2004-0974" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">The netatalk package in Trustix Secure Linux 1.5 through 2.1, and possibly other operating systems, allows local users to overwrite files via a symlink attack on temporary files.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200410-25.xml" source="GENTOO" patch="1" adv="1">GLSA-200410-25</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/17583" source="XF" adv="1">script-temporary-file-overwrite(17583)</ref>
      <ref url="http://www.trustix.org/errata/2004/0050" source="TRUSTIX">2004-0050</ref>
    </refs>
    <vuln_soft>
      <prod vendor="netatalk" name="open_source_apple_file_share_protocol_suite">
        <vers num="1.5_pre6" />
        <vers num="1.6.1" />
        <vers num="1.6.4" />
      </prod>
      <prod vendor="mandrakesoft" name="mandrake_linux">
        <vers num="10.0" edition="" />
        <vers num="10.0" edition=":amd64" />
        <vers num="10.1" edition="" />
        <vers num="10.1" edition=":x86_64" />
        <vers num="9.2" edition="" />
        <vers num="9.2" edition=":amd64" />
      </prod>
      <prod vendor="mandrakesoft" name="mandrake_linux_corporate_server">
        <vers num="2.1" edition="" />
        <vers num="2.1" edition=":x86_64" />
      </prod>
      <prod vendor="redhat" name="fedora_core">
        <vers num="core_2.0" />
        <vers num="core_3.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2004-0975" published="2005-02-09" name="CVE-2004-0975" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">The der_chop script in the openssl package in Trustix Secure Linux 1.5 through 2.1 and other operating systems allows local users to overwrite files via a symlink attack on temporary files.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/11293" source="BID" patch="1" adv="1">11293</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/17583" source="XF" adv="1">script-temporary-file-overwrite(17583)</ref>
      <ref url="http://www.trustix.org/errata/2004/0050" source="TRUSTIX">2004-0050</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200411-15.xml" source="GENTOO">GLSA-200411-15</ref>
      <ref url="http://www.debian.org/security/2004/dsa-603" source="DEBIAN">DSA-603</ref>
      <ref url="http://secunia.com/advisories/12973" source="SECUNIA">12973</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10621" source="OVAL">oval:org.mitre.oval:def:10621</ref>
      <ref url="http://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=136302" source="CONFIRM">http://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=136302</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-476.html" source="REDHAT">RHSA-2005:476</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:164" source="OVAL" sig="1">oval:org.mitre.oval:def:164</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mandrakesoft" name="mandrake_multi_network_firewall">
        <vers num="8.2" />
      </prod>
      <prod vendor="openssl" name="openssl">
        <vers num="0.9.6" />
        <vers num="0.9.6a" />
        <vers num="0.9.6b" />
        <vers num="0.9.6c" />
        <vers num="0.9.6d" />
        <vers num="0.9.6e" />
        <vers num="0.9.6f" />
        <vers num="0.9.6g" />
        <vers num="0.9.6h" />
        <vers num="0.9.6i" />
        <vers num="0.9.6j" />
        <vers num="0.9.6k" />
        <vers num="0.9.6l" />
        <vers num="0.9.6m" />
        <vers num="0.9.7c" />
        <vers num="0.9.7d" />
      </prod>
      <prod vendor="gentoo" name="linux">
        <vers num="" />
      </prod>
      <prod vendor="mandrakesoft" name="mandrake_linux">
        <vers num="10.0" edition="" />
        <vers num="10.0" edition=":amd64" />
        <vers num="10.1" edition="" />
        <vers num="10.1" edition=":x86_64" />
        <vers num="9.2" edition="" />
        <vers num="9.2" edition=":amd64" />
      </prod>
      <prod vendor="mandrakesoft" name="mandrake_linux_corporate_server">
        <vers num="2.1" edition="" />
        <vers num="2.1" edition=":x86_64" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2004-0976" published="2005-02-09" name="CVE-2004-0976" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">Multiple scripts in the perl package in Trustix Secure Linux 1.5 through 2.1 and other operating systems allows local users to overwrite files via a symlink attack on temporary files.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/11294" source="BID" patch="1" adv="1">11294</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/17583" source="XF" adv="1">script-temporary-file-overwrite(17583)</ref>
      <ref url="http://www.trustix.org/errata/2004/0050" source="TRUSTIX">2004-0050</ref>
      <ref url="http://www.debian.org/security/2004/dsa-620" source="DEBIAN">DSA-620</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9752" source="OVAL">oval:org.mitre.oval:def:9752</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-881.html" source="REDHAT">RHSA-2005:881</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:031" source="MANDRAKE">MDKSA-2005:031</ref>
      <ref url="http://secunia.com/advisories/18075" source="SECUNIA">18075</ref>
      <ref url="http://secunia.com/advisories/17661" source="SECUNIA">17661</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110547693019788&amp;w=2" source="OPENPKG">OpenPKG-SA-2005.001</ref>
      <ref url="http://fedoranews.org/updates/FEDORA--.shtml" source="FEDORA">FLSA-2006:152845</ref>
    </refs>
    <vuln_soft>
      <prod vendor="larry_wall" name="perl">
        <vers num="5.6" />
        <vers num="5.6.1" />
        <vers num="5.8.0" />
        <vers num="5.8.1" />
        <vers num="5.8.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2004-0977" published="2005-02-09" name="CVE-2004-0977" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">The make_oidjoins_check script in PostgreSQL 7.4.5 and earlier allows local users to overwrite files via a symlink attack on temporary files.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/11295" source="BID" patch="1" adv="1">11295</ref>
      <ref url="http://www.debian.org/security/2004/dsa-577" source="DEBIAN" patch="1" adv="1">DSA-577</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/17583" source="XF" adv="1">script-temporary-file-overwrite(17583)</ref>
      <ref url="http://www.trustix.org/errata/2004/0050" source="TRUSTIX">2004-0050</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-489.html" source="REDHAT">RHSA-2004:489</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200410-16.xml" source="GENTOO">GLSA-200410-16</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11360" source="OVAL">oval:org.mitre.oval:def:11360</ref>
      <ref url="http://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=136300" source="CONFIRM">http://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=136300</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2004:149" source="MANDRAKE">MDKSA-2004:149</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109910073808903&amp;w=2" source="OPENPKG">OpenPKG-SA-2004.046</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109902101714725&amp;w=2" source="UBUNTU">USN-6-1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="postgresql" name="postgresql">
        <vers num="7.2.1" />
        <vers num="7.4.3" />
        <vers num="7.4.5" />
      </prod>
      <prod vendor="mandrakesoft" name="mandrake_linux">
        <vers num="10.0" edition="" />
        <vers num="10.0" edition=":amd64" />
        <vers num="10.1" edition="" />
        <vers num="10.1" edition=":x86_64" />
        <vers num="9.2" edition="" />
        <vers num="9.2" edition=":amd64" />
      </prod>
      <prod vendor="mandrakesoft" name="mandrake_linux_corporate_server">
        <vers num="2.1" edition="" />
        <vers num="2.1" edition=":x86_64" />
      </prod>
      <prod vendor="redhat" name="enterprise_linux">
        <vers num="3.0" edition="" />
        <vers num="3.0" edition=":advanced_server" />
        <vers num="3.0" edition=":workstation_server" />
        <vers num="3.0" edition=":enterprise_server" />
      </prod>
      <prod vendor="redhat" name="enterprise_linux_desktop">
        <vers num="3.0" />
      </prod>
      <prod vendor="trustix" name="secure_linux">
        <vers num="2.0" />
        <vers num="2.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0978" published="2005-02-09" name="CVE-2004-0978" modified="2005-10-20" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Heap-based buffer overflow in the Hrtbeat.ocx (Heartbeat) ActiveX control for Internet Explorer 5.01 through 6, when users who visit online gaming sites that are associated with MSN, allows remote attackers to execute arbitrary code via the SetupData parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <other />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/673134" source="CERT-VN" adv="1">VU#673134</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/17714" source="XF" adv="1">heartbeat-activex(17714)</ref>
      <ref url="http://www.securityfocus.com/bid/11367" source="BID">11367</ref>
      <ref url="http://www.ngssoftware.com/advisories/heartbeatfull.txt" source="MISC">http://www.ngssoftware.com/advisories/heartbeatfull.txt</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms04-038.mspx" source="MS">MS04-038</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110616221411579&amp;w=2" source="BUGTRAQ">20050119 MSN Heartbeat Control Buffer Overflow</ref>
    </refs>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0979" published="2004-12-31" name="CVE-2004-0979" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Internet Explorer on Windows XP does not properly modify the "Drag and Drop or copy and paste files" setting when the user sets it to "Disable" or "Prompt," which may enable security-sensitive operations that are inconsistent with the user's intended configuration.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA04-293A.html" source="CERT">TA04-293A</ref>
      <ref url="http://www.kb.cert.org/vuls/id/630720" source="CERT-VN" adv="1">VU#630720</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/17820" source="XF" adv="1">ie-dragdrop-security-bypass(17820)</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms04-038.mspx" source="MS">MS04-038</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="ie">
        <vers num="6.0" edition="sp1" />
        <vers num="6.0" edition="sp2" />
      </prod>
      <prod vendor="microsoft" name="windows_xp">
        <vers num="" edition=":media_center" />
        <vers num="" edition=":home" />
        <vers num="" edition=":64-bit" />
        <vers num="" edition=":embedded" />
        <vers num="" edition="gold" />
        <vers num="" edition="gold:professional" />
        <vers num="" edition="sp1" />
        <vers num="" edition="sp1:embedded" />
        <vers num="" edition="sp1:64-bit" />
        <vers num="" edition="sp1:home" />
        <vers num="" edition="sp1:media_center" />
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:home" />
        <vers num="" edition="sp2:media_center" />
        <vers num="" edition="sp2:tablet_pc" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0980" published="2005-02-09" name="CVE-2004-0980" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Format string vulnerability in ez-ipupdate.c for ez-ipupdate 3.0.10 through 3.0.11b8, when running in daemon mode with certain service types in use, allows remote servers to execute arbitrary code.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" admin="1" />
    </loss_types>
    <vuln_types>
      <input />
      <config />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/11657" source="BID" patch="1" adv="1">11657</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200411-20.xml" source="GENTOO" patch="1" adv="1">GLSA-200411-20</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/18032" source="XF" adv="1">eziupdate-showmessage-format-string(18032)</ref>
      <ref url="http://www.debian.org/security/2004/dsa-592" source="DEBIAN">DSA-592</ref>
      <ref url="http://secunia.com/advisories/13167/" source="SECUNIA">13167</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2004-November/028590.html" source="FULLDISC">20041111 ez-ipupdate format string bug</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2004:129" source="MANDRAKE">MDKSA-2004:129</ref>
    </refs>
    <vuln_soft>
      <prod vendor="angus_mackay" name="ez-ipupdate">
        <vers num="3.0.11b5" />
        <vers num="3.0.11b8" />
      </prod>
      <prod vendor="debian" name="debian_linux">
        <vers num="3.0" edition="" />
        <vers num="3.0" edition=":hppa" />
        <vers num="3.0" edition=":mips" />
        <vers num="3.0" edition=":ia-32" />
        <vers num="3.0" edition=":m68k" />
        <vers num="3.0" edition=":s-390" />
        <vers num="3.0" edition=":alpha" />
        <vers num="3.0" edition=":arm" />
        <vers num="3.0" edition=":ia-64" />
        <vers num="3.0" edition=":mipsel" />
        <vers num="3.0" edition=":sparc" />
        <vers num="3.0" edition=":ppc" />
      </prod>
      <prod vendor="gentoo" name="linux">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0981" published="2005-02-09" name="CVE-2004-0981" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Buffer overflow in the EXIF parsing routine in ImageMagick before 6.1.0 allows remote attackers to execute arbitrary code via a certain image file.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/17903" source="XF" adv="1">imagemagick-exif-image-bo(17903)</ref>
      <ref url="http://www.securityfocus.org/bid/11548" source="BID">11548</ref>
      <ref url="http://www.imagemagick.org/www/Changelog.html" source="CONFIRM">http://www.imagemagick.org/www/Changelog.html</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200411-11.xml" source="GENTOO">GLSA-200411-11</ref>
      <ref url="http://secunia.com/advisories/12995/" source="SECUNIA">12995</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10472" source="OVAL">oval:org.mitre.oval:def:10472</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109900325831136&amp;w=2" source="UBUNTU" adv="1">USN-7-1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="imagemagick" name="imagemagick">
        <vers num="5.3.3" />
        <vers num="5.4.3" />
        <vers num="5.4.4.5" />
        <vers num="5.4.7" />
        <vers num="5.4.8" />
        <vers num="5.4.8.2.1.1.0" />
        <vers num="5.5.3.2.1.2.0" />
        <vers num="5.5.6.0_2003-04-09" />
        <vers num="5.5.7" />
        <vers num="6.0" />
        <vers num="6.0.1" />
        <vers num="6.0.3" />
        <vers num="6.0.4" />
        <vers num="6.0.5" />
        <vers num="6.0.6" />
        <vers num="6.0.7" />
        <vers num="6.0.8" />
      </prod>
      <prod vendor="debian" name="debian_linux">
        <vers num="3.0" edition="" />
        <vers num="3.0" edition=":mips" />
        <vers num="3.0" edition=":ia-32" />
        <vers num="3.0" edition=":s-390" />
        <vers num="3.0" edition=":alpha" />
        <vers num="3.0" edition=":arm" />
        <vers num="3.0" edition=":mipsel" />
        <vers num="3.0" edition=":ppc" />
        <vers num="3.0" edition=":hppa" />
        <vers num="3.0" edition=":m68k" />
        <vers num="3.0" edition=":ia-64" />
        <vers num="3.0" edition=":sparc" />
      </prod>
      <prod vendor="gentoo" name="linux">
        <vers num="" />
      </prod>
      <prod vendor="suse" name="suse_linux">
        <vers num="8.0" />
        <vers num="8.1" />
        <vers num="8.2" />
        <vers num="9.0" edition="" />
        <vers num="9.0" edition=":x86_64" />
        <vers num="9.1" />
        <vers num="9.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0982" published="2005-02-09" name="CVE-2004-0982" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Buffer overflow in the getauthfromURL function in httpget.c in mpg123 pre0.59s and mpg123 0.59r could allow remote attackers or local users to execute arbitrary code via an mp3 file that contains a long string before the @ (at sign) in a URL.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/11468" source="BID" patch="1" adv="1">11468</ref>
      <ref url="http://www.debian.org/security/2004/dsa-578" source="DEBIAN" patch="1" adv="1">DSA-578</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/17574" source="XF" adv="1">mpg123-getauthfromurl-bo(17574)</ref>
      <ref url="http://www.osvdb.org/11023" source="OSVDB">11023</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200410-27.xml" source="GENTOO">GLSA-200410-27</ref>
      <ref url="http://www.barrossecurity.com/advisories/mpg123_getauthfromurl_bof_advisory.txt" source="MISC">http://www.barrossecurity.com/advisories/mpg123_getauthfromurl_bof_advisory.txt</ref>
      <ref url="http://securitytracker.com/id?1011832" source="SECTRACK">1011832</ref>
      <ref url="http://secunia.com/advisories/12908" source="SECUNIA">12908</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109834486312407&amp;w=2" source="BUGTRAQ">20041019 mpg123 "getauthfromurl" buffer overflow</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mpg123" name="mpg123">
        <vers num="0.59r" />
        <vers num="pre0.59s" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0983" published="2005-03-01" name="CVE-2004-0983" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The CGI module in Ruby 1.6 before 1.6.8, and 1.8 before 1.8.2, allows remote attackers to cause a denial of service (infinite loop and CPU consumption) via a certain HTTP request.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/11618" source="BID" patch="1" adv="1">11618</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/17985" source="XF" adv="1">ruby-cgi-dos(17985)</ref>
      <ref url="http://www.ubuntulinux.org/support/documentation/usn/usn-20-1" source="UBUNTU">USN-20-1</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-635.html" source="REDHAT">RHSA-2004:635</ref>
      <ref url="http://www.debian.org/security/2004/dsa-586" source="DEBIAN">DSA-586</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10268" source="OVAL">oval:org.mitre.oval:def:10268</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2004:128" source="MANDRAKE">MDKSA-2004:128</ref>
    </refs>
    <vuln_soft>
      <prod vendor="yukihiro_matsumoto" name="ruby">
        <vers num="1.6" />
        <vers num="1.6.7" />
        <vers num="1.8" />
        <vers num="1.8.1" />
        <vers num="1.8.2_pre1" />
        <vers num="1.8.2_pre2" />
      </prod>
      <prod vendor="gentoo" name="linux">
        <vers num="" />
      </prod>
      <prod vendor="mandrakesoft" name="mandrake_linux">
        <vers num="10.0" edition="" />
        <vers num="10.0" edition=":amd64" />
        <vers num="10.1" edition="" />
        <vers num="10.1" edition=":x86_64" />
        <vers num="9.2" edition="" />
        <vers num="9.2" edition=":amd64" />
      </prod>
      <prod vendor="mandrakesoft" name="mandrake_linux_corporate_server">
        <vers num="2.1" edition="" />
        <vers num="2.1" edition=":x86_64" />
      </prod>
      <prod vendor="ubuntu" name="ubuntu_linux">
        <vers num="4.1" edition="" />
        <vers num="4.1" edition=":ia64" />
        <vers num="4.1" edition=":ppc" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0984" published="2004-12-31" name="CVE-2004-0984" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Unknown vulnerability in the dotlock implementation in mailutils before 1:0.5-4 on Debian GNU/Linux allows attackers to gain privileges.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <other />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://packages.debian.org/changelogs/pool/main/m/mailutils/mailutils_0.6-2/changelog" source="CONFIRM">http://packages.debian.org/changelogs/pool/main/m/mailutils/mailutils_0.6-2/changelog</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gnu" name="mailutils">
        <vers prev="1" num="1.0.5.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0985" published="2004-12-31" name="CVE-2004-0985" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Internet Explorer 6.x on Windows XP SP2 allows remote attackers to execute arbitrary code, as demonstrated using a document with a draggable file type such as .xml, .doc, .py, .cdf, .css, .pdf, or .ppt, and using ADODB.Connection and ADODB.recordset to write to a .hta file that is interpreted in the Local Zone by HTML Help.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" admin="1" />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/17824" source="XF" adv="1">ie-anchorclick-command-execution(17824)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=109828076802478&amp;w=2" source="NTBUGTRAQ" adv="1">20041020 How to Break Windows XP SP2 + Internet Explorer 6 SP2</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109830296130857&amp;w=2" source="BUGTRAQ">20041020 How to Break Windows XP SP2 + Internet Explorer 6 SP2</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109829111200055&amp;w=2" source="BUGTRAQ">20041020 Re: How to Break Windows XP SP2 + Internet Explorer 6 SP2</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="ie">
        <vers num="6.0" edition="sp2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0986" published="2005-03-01" name="CVE-2004-0986" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Iptables before 1.2.11, under certain conditions, does not properly load the required modules at system startup, which causes the firewall rules to fail to load and protect the system from remote attackers.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/11570" source="BID" patch="1" adv="1">11570</ref>
      <ref url="https://bugzilla.fedora.us/show_bug.cgi?id=2252" source="FEDORA">FLSA:2252</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/17928" source="XF" adv="1">iptables-module-dos(17928)</ref>
      <ref url="http://www.debian.org/security/2004/dsa-580" source="DEBIAN">DSA-580</ref>
      <ref url="http://www.ciac.org/ciac/bulletins/p-026.shtml" source="CIAC">P-026</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2004:125" source="MANDRAKE">MDKSA-2004:125</ref>
      <ref url="http://rpmfind.net/linux/RPM/suse/updates/9.2/i386/rpm/i586/iptables-1.2.11-4.2.i586.html" source="CONFIRM">http://rpmfind.net/linux/RPM/suse/updates/9.2/i386/rpm/i586/iptables-1.2.11-4.2.i586.html</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110815247703862&amp;w=2" source="UBUNTU">USN-81-1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="suse" name="suse_iptables">
        <vers num="1.2.11" />
      </prod>
      <prod vendor="debian" name="debian_linux">
        <vers num="3.0" edition="" />
        <vers num="3.0" edition=":mips" />
        <vers num="3.0" edition=":s-390" />
        <vers num="3.0" edition=":alpha" />
        <vers num="3.0" edition=":mipsel" />
        <vers num="3.0" edition=":hppa" />
        <vers num="3.0" edition=":ia-32" />
        <vers num="3.0" edition=":arm" />
        <vers num="3.0" edition=":ppc" />
        <vers num="3.0" edition=":m68k" />
        <vers num="3.0" edition=":ia-64" />
        <vers num="3.0" edition=":sparc" />
      </prod>
      <prod vendor="linux" name="linux_kernel">
        <vers num="2.0.2" />
        <vers num="2.4.0" />
        <vers num="2.4.1" />
        <vers num="2.4.10" />
        <vers num="2.4.11" />
        <vers num="2.4.12" />
        <vers num="2.4.13" />
        <vers num="2.4.14" />
        <vers num="2.4.15" />
        <vers num="2.4.16" />
        <vers num="2.4.17" />
        <vers num="2.4.18" />
        <vers num="2.4.19" />
        <vers num="2.4.2" />
        <vers num="2.4.20" />
        <vers num="2.4.21" />
        <vers num="2.4.22" />
        <vers num="2.4.23" />
        <vers num="2.4.24" />
        <vers num="2.4.25" />
        <vers num="2.4.26" />
        <vers num="2.4.3" />
        <vers num="2.4.4" />
        <vers num="2.4.5" />
        <vers num="2.4.6" />
        <vers num="2.4.7" />
        <vers num="2.4.8" />
        <vers num="2.4.9" />
        <vers num="2.6.0" />
        <vers num="2.6.1" />
        <vers num="2.6.2" />
        <vers num="2.6.3" />
        <vers num="2.6.4" />
        <vers num="2.6.5" />
        <vers num="2.6.6" />
        <vers num="2.6.7" />
        <vers num="2.6.8" />
        <vers num="2.6.9" edition="2.6.20" />
      </prod>
      <prod vendor="redhat" name="fedora_core">
        <vers num="core_3.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0987" published="2005-01-10" name="CVE-2004-0987" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Buffer overflow in the process_menu function in yardradius 1.0.20 allows remote attackers to execute arbitrary code.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/11753" source="BID" patch="1" adv="1">11753</ref>
      <ref url="http://www.debian.org/security/2004/dsa-598" source="DEBIAN" patch="1" adv="1">DSA-598</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/18270" source="XF" adv="1">yardradius-processmenu-bo(18270)</ref>
      <ref url="http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=278384" source="MISC">http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=278384</ref>
    </refs>
    <vuln_soft>
      <prod vendor="yard_radius" name="yard_radius">
        <vers num="1.0.16" />
        <vers num="1.0.17" />
        <vers num="1.0.18" />
        <vers num="1.0.19" />
        <vers num="1.0.20" />
        <vers num="1.0_pre13" />
        <vers num="1.0_pre14" />
        <vers num="1.0_pre15" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0988" published="2005-03-01" name="CVE-2004-0988" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Integer overflow on Apple QuickTime before 6.5.2, when running on Windows systems, allows remote attackers to cause a denial of service (memory consumption) via certain inputs that cause a large memory operation.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://lists.apple.com/archives/security-announce/2004/Oct/msg00001.html" source="APPLE">APPLE-SA-2004-10-27</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="quicktime">
        <vers num="5.0.2" />
        <vers num="6.0" />
        <vers num="6.1" />
        <vers num="6.5" />
        <vers num="6.5.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0989" published="2005-03-01" name="CVE-2004-0989" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Multiple buffer overflows in libXML 2.6.12 and 2.6.13 (libxml2), and possibly other versions, may allow remote attackers to execute arbitrary code via (1) a long FTP URL that is not properly handled by the xmlNanoFTPScanURL function, (2) a long proxy URL containing FTP data that is not properly handled by the xmlNanoFTPScanProxy function, and other overflows related to manipulation of DNS length values, including (3) xmlNanoFTPConnect, (4) xmlNanoHTTPConnectHost, and (5) xmlNanoHTTPConnectHost.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/11526" source="BID" patch="1" adv="1">11526</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/17875" source="XF" adv="1">libxml2-xmlnanoftpscanproxy-bo(17875)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/17870" source="XF" adv="1">libxml2-xmlnanoftpscanurl-bo(17870)</ref>
      <ref url="http://www.debian.org/security/2004/dsa-582" source="DEBIAN">DSA-582</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10505" source="OVAL">oval:org.mitre.oval:def:10505</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2005/Jan/msg00001.html" source="APPLE">APPLE-SA-2005-01-25</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/17876" source="XF">libxml2-nanohttp-file-bo(17876)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/17872" source="XF">libxml2-nanoftp-file-bo(17872)</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-650.html" source="REDHAT">RHSA-2004:650</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-615.html" source="REDHAT">RHSA-2004:615</ref>
      <ref url="http://www.osvdb.org/11324" source="OSVDB">11324</ref>
      <ref url="http://www.osvdb.org/11180" source="OSVDB">11180</ref>
      <ref url="http://www.osvdb.org/11179" source="OSVDB">11179</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2005_01_sr.html" source="SUSE">SUSE-SR:2005:001</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200411-05.xml" source="GENTOO">GLSA-200411-05</ref>
      <ref url="http://www.ciac.org/ciac/bulletins/p-029.shtml" source="CIAC">P-029</ref>
      <ref url="http://securitytracker.com/id?1011941" source="SECTRACK">1011941</ref>
      <ref url="http://secunia.com/advisories/13000" source="SECUNIA">13000</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110972110516151&amp;w=2" source="UBUNTU">USN-89-1</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109880813013482&amp;w=2" source="BUGTRAQ">20041026 libxml2 remote buffer overflows (not in xml parsing code though)</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000890" source="CONECTIVA">CLA-2004:890</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1173" source="OVAL" sig="1">oval:org.mitre.oval:def:1173</ref>
    </refs>
    <vuln_soft>
      <prod vendor="xmlsoft" name="libxml">
        <vers num="1.8.17" />
      </prod>
      <prod vendor="xmlsoft" name="libxml2">
        <vers num="2.5.11" />
        <vers num="2.6.11" />
        <vers num="2.6.12" />
        <vers num="2.6.13" />
        <vers num="2.6.14" />
        <vers num="2.6.6" />
        <vers num="2.6.7" />
        <vers num="2.6.8" />
        <vers num="2.6.9" />
      </prod>
      <prod vendor="xmlstarlet" name="command_line_xml_toolkit">
        <vers num="0.9.1" />
      </prod>
      <prod vendor="redhat" name="fedora_core">
        <vers num="core_2.0" />
      </prod>
      <prod vendor="trustix" name="secure_linux">
        <vers num="2.0" />
        <vers num="2.1" />
      </prod>
      <prod vendor="ubuntu" name="ubuntu_linux">
        <vers num="4.1" edition="" />
        <vers num="4.1" edition=":ia64" />
        <vers num="4.1" edition=":ppc" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0990" published="2005-03-01" name="CVE-2004-0990" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Integer overflow in GD Graphics Library libgd 2.0.28 (libgd2), and possibly other versions, allows remote attackers to cause a denial of service and possibly execute arbitrary code via PNG image files with large image rows values that lead to a heap-based buffer overflow in the gdImageCreateFromPngCtx function, a different set of vulnerabilities than CVE-2004-0941.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" admin="1" />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/11523" source="BID" patch="1" adv="1">11523</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/17866" source="XF" adv="1">gd-png-bo(17866)</ref>
      <ref url="http://www.trustix.org/errata/2004/0058" source="TRUSTIX">2004-0058</ref>
      <ref url="http://www.osvdb.org/11190" source="OSVDB">11190</ref>
      <ref url="http://www.debian.org/security/2004/dsa-602" source="DEBIAN">DSA-602</ref>
      <ref url="http://www.debian.org/security/2004/dsa-601" source="DEBIAN">DSA-601</ref>
      <ref url="http://www.debian.org/security/2004/dsa-591" source="DEBIAN">DSA-591</ref>
      <ref url="http://www.debian.org/security/2004/dsa-589" source="DEBIAN">DSA-589</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9952" source="OVAL">oval:org.mitre.oval:def:9952</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109882489302099&amp;w=2" source="BUGTRAQ" adv="1">20041026 libgd integer overflow</ref>
      <ref url="https://issues.rpath.com/browse/RPL-939" source="CONFIRM">https://issues.rpath.com/browse/RPL-939</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-638.html" source="REDHAT">RHSA-2004:638</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:122" source="MANDRIVA">MDKSA-2006:122</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:114" source="MANDRIVA">MDKSA-2006:114</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:113" source="MANDRIVA">MDKSA-2006:113</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2004:132" source="MANDRAKE">MDKSA-2004:132</ref>
      <ref url="http://www.ciac.org/ciac/bulletins/p-071.shtml" source="CIAC">P-071</ref>
      <ref url="http://secunia.com/advisories/23783" source="SECUNIA">23783</ref>
      <ref url="http://secunia.com/advisories/21050" source="SECUNIA">21050</ref>
      <ref url="http://secunia.com/advisories/20866" source="SECUNIA">20866</ref>
      <ref url="http://secunia.com/advisories/20824" source="SECUNIA">20824</ref>
      <ref url="http://secunia.com/advisories/18717" source="SECUNIA">18717</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110055781015402&amp;w=2" source="UBUNTU">USN-25-1</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109907605501428&amp;w=2" source="UBUNTU">USN-11-1</ref>
      <ref url="http://lists.suse.com/archive/suse-security-announce/2006-Feb/0001.html" source="SUSE">SUSE-SR:2006:003</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1260" source="OVAL" sig="1">oval:org.mitre.oval:def:1260</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gd_graphics_library" name="gdlib">
        <vers num="1.8.4" />
        <vers num="2.0.1" />
        <vers num="2.0.15" />
        <vers num="2.0.20" />
        <vers num="2.0.21" />
        <vers num="2.0.22" />
        <vers num="2.0.23" />
        <vers num="2.0.26" />
        <vers num="2.0.27" />
        <vers num="2.0.28" />
      </prod>
      <prod vendor="openpkg" name="openpkg">
        <vers num="2.1" />
        <vers num="2.2" />
        <vers num="current" />
      </prod>
      <prod vendor="gentoo" name="linux">
        <vers num="" />
      </prod>
      <prod vendor="suse" name="suse_linux">
        <vers num="8.0" />
        <vers num="8.1" />
        <vers num="8.2" />
        <vers num="9.0" edition="" />
        <vers num="9.0" edition=":x86_64" />
        <vers num="9.1" />
        <vers num="9.2" />
      </prod>
      <prod vendor="trustix" name="secure_linux">
        <vers num="1.5" />
        <vers num="2.0" />
        <vers num="2.1" />
        <vers num="2.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0991" published="2005-01-11" name="CVE-2004-0991" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in mpg123 before 0.59s-r9 allows remote attackers to execute arbitrary code via frame headers in MP2 or MP3 files.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://security.gentoo.org/glsa/glsa-200501-14.xml" source="GENTOO" patch="1" adv="1">GLSA-200501-14</ref>
      <ref url="http://secunia.com/advisories/13779" source="SECUNIA" adv="1">13779</ref>
      <ref url="http://www.securityfocus.com/bid/12218" source="BID">12218</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:009" source="MANDRAKE">MDKSA-2005:009</ref>
      <ref url="http://secunia.com/advisories/13899" source="SECUNIA">13899</ref>
      <ref url="http://secunia.com/advisories/13788" source="SECUNIA">13788</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mpg123" name="mpg123">
        <vers num="0.59m" />
        <vers num="0.59n" />
        <vers num="0.59o" />
        <vers num="0.59p" />
        <vers num="0.59q" />
        <vers num="0.59r" />
        <vers num="0.59s" />
      </prod>
      <prod vendor="suse" name="suse_linux">
        <vers num="8.0" edition="" />
        <vers num="8.0" edition=":i386" />
        <vers num="8.1" />
        <vers num="8.2" />
        <vers num="9.0" edition="" />
        <vers num="9.0" edition=":x86_64" />
        <vers num="9.1" />
        <vers num="9.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0992" published="2005-03-01" name="CVE-2004-0992" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Format string vulnerability in the -a option (daemon mode) in Proxytunnel before 1.2.3 allows remote attackers to execute arbitrary code via format string specifiers in an invalid proxy answer.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" admin="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/11592" source="BID" patch="1" adv="1">11592</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200411-07.xml" source="GENTOO" patch="1" adv="1">GLSA-200411-07</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/17945" source="XF" adv="1">proxytunnel-message-format-string(17945)</ref>
      <ref url="http://proxytunnel.sourceforge.net/news.html" source="CONFIRM">http://proxytunnel.sourceforge.net/news.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="proxytunnel" name="proxytunnel">
        <vers num="1.0.6" />
        <vers num="1.1.3" />
        <vers num="1.2.2" />
        <vers num="1.2_.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0993" published="2005-01-10" name="CVE-2004-0993" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Buffer overflow in hpsockd before 0.6 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.debian.org/security/2004/dsa-604" source="DEBIAN" patch="1" adv="1">DSA-604</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/18359" source="XF" adv="1">hpsockd-bo(18359)</ref>
      <ref url="http://www.securityfocus.com/bid/11800" source="BID" adv="1">11800</ref>
      <ref url="http://secunia.com/advisories/13371/" source="SECUNIA">13371</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hp" name="sockd">
        <vers num="0.4" />
        <vers num="0.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0994" published="2005-01-10" name="CVE-2004-0994" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Multiple integer overflows in xzgv 0.8 and earlier allow remote attackers to execute arbitrary code via images with large width and height values, which trigger a heap-based buffer overflow, as demonstrated in the read_prf_file function in readprf.c.  NOTE: CVE-2004-0994 and CVE-2004-1095 identify sets of bugs that only partially overlap, despite having the same developer.  Therefore, they should be regarded as distinct.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" admin="1" />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/18454" source="XF">xzgv-readprffile-bo(18454)</ref>
      <ref url="http://www.debian.org/security/2004/dsa-614" source="DEBIAN">DSA-614</ref>
      <ref url="http://rus.members.beeb.net/xzgv-0.8-integer-overflow-fix.diff" source="CONFIRM">http://rus.members.beeb.net/xzgv-0.8-integer-overflow-fix.diff</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110297198402077&amp;w=2" source="IDEFENSE" adv="1">20041213 Multiple Vendor xzgv PRF Parsing Integer Overflow Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="zgv" name="xzgv_image_viewer">
        <vers num="0.6" />
        <vers num="0.7" />
        <vers num="0.8" />
      </prod>
      <prod vendor="zgv" name="zgv_image_viewer">
        <vers num="5.5" />
        <vers num="5.6" />
        <vers num="5.7" />
        <vers num="5.8" />
      </prod>
      <prod vendor="debian" name="debian_linux">
        <vers num="3.0" edition="" />
        <vers num="3.0" edition=":hppa" />
        <vers num="3.0" edition=":mips" />
        <vers num="3.0" edition=":ia-32" />
        <vers num="3.0" edition=":m68k" />
        <vers num="3.0" edition=":s-390" />
        <vers num="3.0" edition=":alpha" />
        <vers num="3.0" edition=":arm" />
        <vers num="3.0" edition=":ia-64" />
        <vers num="3.0" edition=":mipsel" />
        <vers num="3.0" edition=":sparc" />
        <vers num="3.0" edition=":ppc" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2004-0996" published="2005-01-10" name="CVE-2004-0996" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">main.c in cscope 15-4 and 15-5 creates temporary files with predictable filenames, which allows local users to overwrite arbitrary files via a symlink attack.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/11697" source="BID" patch="1" adv="1">11697</ref>
      <ref url="http://www.debian.org/security/2004/dsa-610" source="DEBIAN" patch="1" adv="1">DSA-610</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/18125" source="XF" adv="1">cscope-tmp-race-condition(18125)</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/2732" source="VUPEN">ADV-2007-2732</ref>
      <ref url="http://www.securityfocus.com/archive/1/381611" source="BUGTRAQ">20041118 Re: RX171104 Cscope v15.5 and minors - symlink vulnerability - advisory, exploit and patch.</ref>
      <ref url="http://www.securityfocus.com/archive/1/381506" source="BUGTRAQ">20041118 Re: RX171104 Cscope v15.5 and minors - symlink vulnerability - advisory, exploit and patch.</ref>
      <ref url="http://www.securityfocus.com/archive/1/381443" source="BUGTRAQ">20041117 RX171104 Cscope v15.5 and minors - symlink vulnerability - advisory, exploit and patch.</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200412-11.xml" source="GENTOO">GLSA-200412-11</ref>
      <ref url="http://www.securityfocus.com/bid/25159" source="BID">25159</ref>
      <ref url="http://secunia.com/advisories/26235" source="SECUNIA">26235</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110133485519690&amp;w=2" source="BUGTRAQ">20041124 STG Security Advisory: [SSA-20041122-09] cscope insecure temp file creation vulnerability</ref>
      <ref url="http://lists.apple.com/archives/security-announce//2007/Jul/msg00004.html" source="APPLE">APPLE-SA-2007-07-31</ref>
      <ref url="http://docs.info.apple.com/article.html?artnum=306172" source="CONFIRM">http://docs.info.apple.com/article.html?artnum=306172</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cscope" name="cscope">
        <vers num="13.0" />
        <vers num="15.1" />
        <vers num="15.3" />
        <vers num="15.4" />
        <vers num="15.5" />
      </prod>
      <prod vendor="debian" name="debian_linux">
        <vers num="3.0" edition="" />
        <vers num="3.0" edition=":hppa" />
        <vers num="3.0" edition=":mips" />
        <vers num="3.0" edition=":ia-32" />
        <vers num="3.0" edition=":m68k" />
        <vers num="3.0" edition=":s-390" />
        <vers num="3.0" edition=":alpha" />
        <vers num="3.0" edition=":arm" />
        <vers num="3.0" edition=":ia-64" />
        <vers num="3.0" edition=":mipsel" />
        <vers num="3.0" edition=":sparc" />
        <vers num="3.0" edition=":ppc" />
      </prod>
      <prod vendor="gentoo" name="linux">
        <vers num="" />
      </prod>
      <prod vendor="sco" name="unixware">
        <vers num="7.1.1" />
        <vers num="7.1.3" />
        <vers num="7.1.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0997" published="2004-12-31" name="CVE-2004-0997" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Unspecified vulnerability in the ptrace MIPS assembly code in Linux kernel 2.4 before 2.4.17 allows local users to gain privileges via unknown vectors.</descript>
    </desc>
    <sols>
      <sol source="nvd">This vulnerability is addressed in the following product release:
Linux, Linux kernel, 2.4.17</sol>
    </sols>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.debian.org/security/2006/dsa-1082" source="DEBIAN" patch="1" adv="1">DSA-1082</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1070" source="DEBIAN" patch="1" adv="1">DSA-1070</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1069" source="DEBIAN" patch="1" adv="1">DSA-1069</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1067" source="DEBIAN" patch="1" adv="1">DSA-1067</ref>
      <ref url="http://secunia.com/advisories/20202" source="SECUNIA" patch="1" adv="1">20202</ref>
      <ref url="http://secunia.com/advisories/20163" source="SECUNIA" patch="1" adv="1">20163</ref>
      <ref url="http://secunia.com/advisories/20162" source="SECUNIA" patch="1" adv="1">20162</ref>
      <ref url="http://kernel.debian.net/debian/pool/main/kernel-source-2.4.17/kernel-source-2.4.17_2.4.17-1woody4_ia64.changes" source="CONFIRM" patch="1">http://kernel.debian.net/debian/pool/main/kernel-source-2.4.17/kernel-source-2.4.17_2.4.17-1woody4_ia64.changes</ref>
      <ref url="http://www.securityfocus.com/bid/18176" source="BID">18176</ref>
      <ref url="http://svn.debian.org/wsvn/kernel/patch-tracking/CVE-2004-0997?op=file&amp;rev=0&amp;sc=0" source="MISC">http://svn.debian.org/wsvn/kernel/patch-tracking/CVE-2004-0997?op=file&amp;rev=0&amp;sc=0</ref>
      <ref url="http://secunia.com/advisories/20338" source="SECUNIA">20338</ref>
    </refs>
    <vuln_soft>
      <prod vendor="linux" name="linux_kernel">
        <vers num="2.4.0" edition="test1" />
        <vers num="2.4.0" edition="test10" />
        <vers num="2.4.0" edition="test11" />
        <vers num="2.4.0" edition="test12" />
        <vers num="2.4.0" edition="test2" />
        <vers num="2.4.0" edition="test3" />
        <vers num="2.4.0" edition="test4" />
        <vers num="2.4.0" edition="test5" />
        <vers num="2.4.0" edition="test6" />
        <vers num="2.4.0" edition="test7" />
        <vers num="2.4.0" edition="test8" />
        <vers num="2.4.0" edition="test9" />
        <vers num="2.4.1" />
        <vers num="2.4.10" />
        <vers num="2.4.11" />
        <vers num="2.4.12" />
        <vers num="2.4.13" />
        <vers num="2.4.14" />
        <vers num="2.4.15" />
        <vers num="2.4.16" />
        <vers num="2.4.2" />
        <vers num="2.4.3" />
        <vers num="2.4.4" />
        <vers num="2.4.5" />
        <vers num="2.4.6" />
        <vers num="2.4.7" />
        <vers num="2.4.8" />
        <vers num="2.4.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0998" published="2004-12-23" name="CVE-2004-0998" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Format string vulnerability in telnetd-ssl 0.17 and earlier allows remote attackers to execute arbitrary code.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/995038" source="CERT-VN" patch="1" adv="1">VU#995038</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/18654" source="XF" patch="1" adv="1">netkit-telnetssl-format-string(18654)</ref>
      <ref url="http://www.debian.org/security/2004/dsa-616" source="DEBIAN" patch="1" adv="1">DSA-616</ref>
      <ref url="http://secunia.com/advisories/13663" source="SECUNIA" patch="1" adv="1">13663</ref>
    </refs>
    <vuln_soft>
      <prod vendor="telnetd" name="telnetd">
        <vers num="0.17.18" />
        <vers num="0.17.25" />
      </prod>
      <prod vendor="telnetd" name="telnetd-ssl">
        <vers num="0.17.17_0.1.1" />
        <vers num="0.17.17_0.1.2" edition="" />
        <vers num="0.17.17_0.1.2" edition=":woody1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2004-0999" published="2004-12-31" name="CVE-2004-0999" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:N/A:P)" CVSS_score="2.6" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="4.9" CVSS_base_score="2.6">
    <desc>
      <descript source="cve">zgv 5.5.3 allows remote attackers to cause a denial of service (application crash via segmentation fault) via crafted multiple-image (animated) GIF images.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.debian.org/security/2004/dsa-608" source="DEBIAN" patch="1">DSA-608</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/18480" source="XF">zgv-multiple-image-dos(18480)</ref>
      <ref url="http://www.securityfocus.com/bid/11915" source="BID">11915</ref>
    </refs>
    <vuln_soft>
      <prod vendor="zgv" name="zgv_image_viewer">
        <vers num="5.5.3" />
        <vers num="5.6" />
        <vers num="5.7" />
        <vers num="5.8" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2004-1000" published="2004-01-10" name="CVE-2004-1000" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">lintian 1.23 and earlier removes the working directory even if it was not created by lintian, which may allow local users to delete arbitrary files or directories via a symlink attack.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/18808" source="XF" patch="1" adv="1">lintian-symlink(18808)</ref>
      <ref url="http://secunia.com/advisories/13771" source="SECUNIA">13771</ref>
    </refs>
    <vuln_soft>
      <prod vendor="debian" name="lintian">
        <vers num="1.2_0.17.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1001" published="2005-03-01" name="CVE-2004-1001" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Unknown vulnerability in the passwd_check function in Shadow 4.0.4.1, and possibly other versions before 4.0.5, allows local users to conduct unauthorized activities when an error from a pam_chauthtok function call is not properly handled.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <other />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/17902" source="XF" adv="1">shadow-pwdcheck-modify-account(17902)</ref>
      <ref url="http://www.debian.org/security/2004/dsa-585" source="DEBIAN">DSA-585</ref>
      <ref url="http://secunia.com/advisories/13028" source="SECUNIA">13028</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000894" source="CONECTIVA">CLA-2004:894</ref>
    </refs>
    <vuln_soft>
      <prod vendor="debian" name="shadow-utils">
        <vers num="4.0.4.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1002" published="2005-03-01" name="CVE-2004-1002" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Integer underflow in pppd in cbcp.c for ppp 2.4.1 allows remote attackers to cause a denial of service (daemon crash) via a CBCP packet with an invalid length value that causes pppd to access an incorrect memory location.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/17874" source="XF" adv="1">ppp-ccp-headers-dos(17874)</ref>
      <ref url="http://www.securityfocus.com/archive/1/379450" source="BUGTRAQ">20041026 pppd out of bounds memory access, possible DOS</ref>
      <ref url="http://lists.ubuntu.com/archives/ubuntu-security-announce/2004-October/000012.html" source="UBUNTU">USN-12-1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="samba" name="ppp">
        <vers num="2.4.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1003" published="2005-03-01" name="CVE-2004-1003" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Trend ScanMail allows remote attackers to obtain potentially sensitive information or disable the anti-virus capability via the smency.nsf file.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/17962" source="XF" adv="1">scanmail-file-access(17962)</ref>
      <ref url="http://cgi.nessus.org/plugins/dump.php3?id=14312" source="MISC">http://cgi.nessus.org/plugins/dump.php3?id=14312</ref>
    </refs>
    <vuln_soft>
      <prod vendor="trend_micro" name="scanmail_domino">
        <vers num="2.51" />
        <vers num="2.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-1004" published="2005-04-14" name="CVE-2004-1004" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple format string vulnerabilities in Midnight Commander (mc) 4.5.55 and earlier allow remote attackers to have an unknown impact.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-217.html" source="REDHAT" patch="1" adv="1">RHSA-2005:217</ref>
      <ref url="http://secunia.com/advisories/13863/" source="SECUNIA" patch="1" adv="1">13863</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/18902" source="XF" adv="1">midnightcommander-format-string(18902)</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200502-24.xml" source="GENTOO">GLSA-200502-24</ref>
      <ref url="http://www.debian.org/security/2005/dsa-639" source="DEBIAN">DSA-639</ref>
    </refs>
    <vuln_soft>
      <prod vendor="midnight_commander" name="midnight_commander">
        <vers num="4.5.40" />
        <vers num="4.5.41" />
        <vers num="4.5.42" />
        <vers num="4.5.43" />
        <vers num="4.5.44" />
        <vers num="4.5.45" />
        <vers num="4.5.46" />
        <vers num="4.5.47" />
        <vers num="4.5.48" />
        <vers num="4.5.49" />
        <vers num="4.5.50" />
        <vers num="4.5.51" />
        <vers num="4.5.52" />
        <vers num="4.5.54" />
        <vers num="4.5.55" />
        <vers num="4.6" />
      </prod>
      <prod vendor="debian" name="debian_linux">
        <vers num="3.0" edition="" />
        <vers num="3.0" edition=":mips" />
        <vers num="3.0" edition=":ia-32" />
        <vers num="3.0" edition=":s-390" />
        <vers num="3.0" edition=":alpha" />
        <vers num="3.0" edition=":arm" />
        <vers num="3.0" edition=":mipsel" />
        <vers num="3.0" edition=":ppc" />
        <vers num="3.0" edition=":hppa" />
        <vers num="3.0" edition=":m68k" />
        <vers num="3.0" edition=":ia-64" />
        <vers num="3.0" edition=":sparc" />
      </prod>
      <prod vendor="gentoo" name="linux">
        <vers num="" />
      </prod>
      <prod vendor="redhat" name="enterprise_linux">
        <vers num="2.1" edition="" />
        <vers num="2.1" edition=":workstation_ia64" />
        <vers num="2.1" edition=":advanced_server" />
        <vers num="2.1" edition=":advanced_server_ia64" />
        <vers num="2.1" edition=":workstation" />
      </prod>
      <prod vendor="redhat" name="linux_advanced_workstation">
        <vers num="2.1" edition="" />
        <vers num="2.1" edition=":itanium_processor" />
        <vers num="2.1" edition=":ia64" />
      </prod>
      <prod vendor="suse" name="suse_linux">
        <vers num="8.0" edition="" />
        <vers num="8.0" edition=":i386" />
        <vers num="8.1" />
        <vers num="8.2" />
        <vers num="9.0" edition="" />
        <vers num="9.0" edition=":x86_64" />
        <vers num="9.1" />
        <vers num="9.2" />
      </prod>
      <prod vendor="turbolinux" name="turbolinux_server">
        <vers num="7.0" />
        <vers num="8.0" />
      </prod>
      <prod vendor="turbolinux" name="turbolinux_workstation">
        <vers num="7.0" />
        <vers num="8.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-1005" published="2005-04-14" name="CVE-2004-1005" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple buffer overflows in Midnight Commander (mc) 4.5.55 and earlier allow remote attackers to have an unknown impact.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-217.html" source="REDHAT" patch="1" adv="1">RHSA-2005:217</ref>
      <ref url="http://secunia.com/advisories/13863/" source="SECUNIA" patch="1" adv="1">13863</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/18898" source="XF">midnight-commander-bo(18898)</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200502-24.xml" source="GENTOO">GLSA-200502-24</ref>
      <ref url="http://www.debian.org/security/2005/dsa-639" source="DEBIAN">DSA-639</ref>
    </refs>
    <vuln_soft>
      <prod vendor="midnight_commander" name="midnight_commander">
        <vers num="4.5.40" />
        <vers num="4.5.41" />
        <vers num="4.5.42" />
        <vers num="4.5.43" />
        <vers num="4.5.44" />
        <vers num="4.5.45" />
        <vers num="4.5.46" />
        <vers num="4.5.47" />
        <vers num="4.5.48" />
        <vers num="4.5.49" />
        <vers num="4.5.50" />
        <vers num="4.5.51" />
        <vers num="4.5.52" />
        <vers num="4.5.54" />
        <vers num="4.5.55" />
        <vers num="4.6" />
      </prod>
      <prod vendor="debian" name="debian_linux">
        <vers num="3.0" edition="" />
        <vers num="3.0" edition=":mips" />
        <vers num="3.0" edition=":ia-32" />
        <vers num="3.0" edition=":s-390" />
        <vers num="3.0" edition=":alpha" />
        <vers num="3.0" edition=":arm" />
        <vers num="3.0" edition=":mipsel" />
        <vers num="3.0" edition=":ppc" />
        <vers num="3.0" edition=":hppa" />
        <vers num="3.0" edition=":m68k" />
        <vers num="3.0" edition=":ia-64" />
        <vers num="3.0" edition=":sparc" />
      </prod>
      <prod vendor="gentoo" name="linux">
        <vers num="" />
      </prod>
      <prod vendor="redhat" name="enterprise_linux">
        <vers num="2.1" edition="" />
        <vers num="2.1" edition=":workstation_ia64" />
        <vers num="2.1" edition=":advanced_server" />
        <vers num="2.1" edition=":advanced_server_ia64" />
        <vers num="2.1" edition=":workstation" />
      </prod>
      <prod vendor="redhat" name="linux_advanced_workstation">
        <vers num="2.1" edition="" />
        <vers num="2.1" edition=":itanium_processor" />
        <vers num="2.1" edition=":ia64" />
      </prod>
      <prod vendor="suse" name="suse_linux">
        <vers num="8.0" edition="" />
        <vers num="8.0" edition=":i386" />
        <vers num="8.1" />
        <vers num="8.2" />
        <vers num="9.0" edition="" />
        <vers num="9.0" edition=":x86_64" />
        <vers num="9.1" />
        <vers num="9.2" />
      </prod>
      <prod vendor="turbolinux" name="turbolinux_server">
        <vers num="7.0" />
        <vers num="8.0" />
      </prod>
      <prod vendor="turbolinux" name="turbolinux_workstation">
        <vers num="7.0" />
        <vers num="8.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-1006" published="2005-03-01" name="CVE-2004-1006" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Format string vulnerability in the log functions in dhcpd for dhcp 2.x allows remote DNS servers to execute arbitrary code via certain DNS messages, a different vulnerability than CVE-2002-0702.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" admin="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/448384" source="CERT-VN">VU#448384</ref>
      <ref url="http://www.securityfocus.com/bid/11591" source="BID" patch="1" adv="1">11591</ref>
      <ref url="http://www.debian.org/security/2004/dsa-584" source="DEBIAN" patch="1" adv="1">DSA-584</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/17963" source="XF" adv="1">dhcp-log-format-string(17963)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109968710822449&amp;w=2" source="BUGTRAQ" adv="1">20041105 Re: debian dhcpd, old format string bug</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2004-11/0037.html" source="BUGTRAQ">20041102 Re: debian dhcpd, old format string bug</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2004-10/0287.html" source="BUGTRAQ">20041025 debian dhcpd, old format string bug</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-212.html" source="REDHAT">RHSA-2005:212</ref>
    </refs>
    <vuln_soft>
      <prod vendor="isc" name="dhcpd">
        <vers num="2.0.pl5" />
        <vers num="3.0" edition="rc12" />
        <vers num="3.0" edition="rc4" />
        <vers num="3.0.1" edition="rc1" />
        <vers num="3.0.1" edition="rc10" />
        <vers num="3.0.1" edition="rc11" />
        <vers num="3.0.1" edition="rc12" />
        <vers num="3.0.1" edition="rc13" />
        <vers num="3.0.1" edition="rc14" />
        <vers num="3.0.1" edition="rc2" />
        <vers num="3.0.1" edition="rc3" />
        <vers num="3.0.1" edition="rc4" />
        <vers num="3.0.1" edition="rc5" />
        <vers num="3.0.1" edition="rc6" />
        <vers num="3.0.1" edition="rc7" />
        <vers num="3.0.1" edition="rc8" />
        <vers num="3.0.1" edition="rc9" />
        <vers num="3.0_b2pl23" />
        <vers num="3.0_b2pl9" />
        <vers num="3.0_pl1" />
        <vers num="3.0_pl2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1007" published="2005-03-01" name="CVE-2004-1007" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The quoted-printable decoder in bogofilter 0.17.4 to 0.92.7 allows remote attackers to cause a denial of service (application crash) via mail headers that cause a line feed (LF) to be replaced by a null byte that is written to an incorrect memory address.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/17916" source="XF" adv="1">bogofilter-dos(17916)</ref>
      <ref url="http://bogofilter.sourceforge.net/security/bogofilter-SA-2004-01" source="CONFIRM">http://bogofilter.sourceforge.net/security/bogofilter-SA-2004-01</ref>
    </refs>
    <vuln_soft>
      <prod vendor="bogofilter" name="email_filter">
        <vers num="0.9.0.3" />
        <vers num="0.9.0.4" />
        <vers num="0.9.0.5" />
        <vers num="0.92" />
        <vers num="0.92.4" />
        <vers num="0.92.6" />
        <vers num="0.92.7" />
      </prod>
      <prod vendor="ubuntu" name="ubuntu_linux">
        <vers num="4.1" edition="" />
        <vers num="4.1" edition=":ia64" />
        <vers num="4.1" edition=":ppc" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-1008" published="2005-01-10" name="CVE-2004-1008" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Integer signedness error in the ssh2_rdpkt function in PuTTY before 0.56 allows remote attackers to execute arbitrary code via a SSH2_MSG_DEBUG packet with a modified stringlen parameter, which leads to a buffer overflow.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/11549" source="BID" patch="1" adv="1">11549</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200410-29.xml" source="GENTOO" patch="1" adv="1">GLSA-200410-29</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/17886" source="XF" adv="1">putty-ssh2msgdebug-bo(17886)</ref>
      <ref url="http://www.chiark.greenend.org.uk/~sgtatham/putty/" source="CONFIRM">http://www.chiark.greenend.org.uk/~sgtatham/putty/</ref>
      <ref url="http://secunia.com/advisories/13012/" source="SECUNIA">13012</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109889312917613&amp;w=2" source="BUGTRAQ" adv="1">20041027 PuTTY SSH client vulnerability</ref>
      <ref url="http://www.idefense.com/application/poi/display?id=155&amp;type=vulnerabilities&amp;flashstatus=true" source="IDEFENSE">20041027 PuTTY SSH2_MSG_DEBUG Buffer Overflow Vulnerability </ref>
      <ref url="http://www-1.ibm.com/support/docview.wss?uid=ssg1S1002416" source="CONFIRM">http://www-1.ibm.com/support/docview.wss?uid=ssg1S1002416</ref>
      <ref url="http://www-1.ibm.com/support/docview.wss?uid=ssg1S1002414" source="CONFIRM">http://www-1.ibm.com/support/docview.wss?uid=ssg1S1002414</ref>
      <ref url="http://secunia.com/advisories/17214" source="SECUNIA">17214</ref>
      <ref url="http://secunia.com/advisories/12987/" source="SECUNIA">12987</ref>
    </refs>
    <vuln_soft>
      <prod vendor="putty" name="putty">
        <vers num="0.48" />
        <vers num="0.49" />
        <vers num="0.50" />
        <vers num="0.51" />
        <vers num="0.52" />
        <vers num="0.53" />
        <vers num="0.53b" />
        <vers num="0.54" />
        <vers num="0.55" />
      </prod>
      <prod vendor="tortoisecvs" name="tortoisecvs">
        <vers num="1.8" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1009" published="2005-04-14" name="CVE-2004-1009" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Midnight commander (mc) 4.5.55 and earlier allows remote attackers to cause a denial of service (infinite loop) via unknown attack vectors.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <other />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.debian.org/security/2005/dsa-639" source="DEBIAN" patch="1" adv="1">DSA-639</ref>
      <ref url="http://secunia.com/advisories/13863/" source="SECUNIA" patch="1" adv="1">13863</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/18903" source="XF">midnight-commander-dos(18903)</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-512.html" source="REDHAT">RHSA-2005:512</ref>
    </refs>
    <vuln_soft>
      <prod vendor="midnight_commander" name="midnight_commander">
        <vers num="4.5.40" />
        <vers num="4.5.41" />
        <vers num="4.5.42" />
        <vers num="4.5.43" />
        <vers num="4.5.44" />
        <vers num="4.5.45" />
        <vers num="4.5.46" />
        <vers num="4.5.47" />
        <vers num="4.5.48" />
        <vers num="4.5.49" />
        <vers num="4.5.50" />
        <vers num="4.5.51" />
        <vers num="4.5.52" />
        <vers num="4.5.54" />
        <vers num="4.5.55" />
        <vers num="4.6" />
      </prod>
      <prod vendor="debian" name="debian_linux">
        <vers num="3.0" edition="" />
        <vers num="3.0" edition=":mips" />
        <vers num="3.0" edition=":ia-32" />
        <vers num="3.0" edition=":s-390" />
        <vers num="3.0" edition=":alpha" />
        <vers num="3.0" edition=":arm" />
        <vers num="3.0" edition=":mipsel" />
        <vers num="3.0" edition=":ppc" />
        <vers num="3.0" edition=":hppa" />
        <vers num="3.0" edition=":m68k" />
        <vers num="3.0" edition=":ia-64" />
        <vers num="3.0" edition=":sparc" />
      </prod>
      <prod vendor="gentoo" name="linux">
        <vers num="" />
      </prod>
      <prod vendor="redhat" name="enterprise_linux">
        <vers num="2.1" edition="" />
        <vers num="2.1" edition=":workstation_ia64" />
        <vers num="2.1" edition=":advanced_server" />
        <vers num="2.1" edition=":advanced_server_ia64" />
        <vers num="2.1" edition=":workstation" />
      </prod>
      <prod vendor="redhat" name="linux_advanced_workstation">
        <vers num="2.1" edition="" />
        <vers num="2.1" edition=":itanium_processor" />
        <vers num="2.1" edition=":ia64" />
      </prod>
      <prod vendor="suse" name="suse_linux">
        <vers num="8.0" edition="" />
        <vers num="8.0" edition=":i386" />
        <vers num="8.1" />
        <vers num="8.2" />
        <vers num="9.0" edition="" />
        <vers num="9.0" edition=":x86_64" />
        <vers num="9.1" />
        <vers num="9.2" />
      </prod>
      <prod vendor="turbolinux" name="turbolinux_server">
        <vers num="7.0" />
        <vers num="8.0" />
      </prod>
      <prod vendor="turbolinux" name="turbolinux_workstation">
        <vers num="7.0" />
        <vers num="8.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-1010" published="2005-03-01" name="CVE-2004-1010" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Buffer overflow in Info-Zip 2.3 and possibly earlier versions, when using recursive folder compression, allows remote attackers to execute arbitrary code via a ZIP file containing a long pathname.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/11603" source="BID" patch="1" adv="1">11603</ref>
      <ref url="https://bugzilla.fedora.us/show_bug.cgi?id=2255" source="FEDORA">FLSA:2255</ref>
      <ref url="http://www.hexview.com/docs/20041103-1.txt" source="MISC">http://www.hexview.com/docs/20041103-1.txt</ref>
      <ref url="http://www.debian.org/security/2005/dsa-624" source="DEBIAN">DSA-624</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9848" source="OVAL">oval:org.mitre.oval:def:9848</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2004-November/028379.html" source="FULLDISC">20041103 [HV-MED] Zip/Linux long path buffer overflow</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/17956" source="XF">infozip-compressed-folder-bo(17956)</ref>
      <ref url="http://www.ubuntulinux.org/support/documentation/usn/usn-18-1" source="UBUNTU">USN-18-1</ref>
      <ref url="http://www.turbolinux.com/security/2005/TLSA-2005-18.txt" source="TURBO">TLSA-2005-18</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-634.html" source="REDHAT">RHSA-2004:634</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2004:141" source="MANDRAKE">MDKSA-2004:141</ref>
      <ref url="http://www.ciac.org/ciac/bulletins/p-072.shtml" source="CIAC">P-072</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200411-16.xml" source="GENTOO">GLSA-200411-16</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109958840611053&amp;w=2" source="BUGTRAQ">20041103 [HV-MED] Zip/Linux long path buffer overflow</ref>
    </refs>
    <vuln_soft>
      <prod vendor="info-zip" name="zip">
        <vers num="2.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-1011" published="2005-01-10" name="CVE-2004-1011" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Stack-based buffer overflow in Cyrus IMAP Server 2.2.4 through 2.2.8, with the imapmagicplus option enabled, allows remote attackers to execute arbitrary code via a long (1) PROXY or (2) LOGIN command, a different vulnerability than CVE-2004-1015.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
      <config />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/18198" source="XF" adv="1">cyrus-imap-username-bo(18198)</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200411-34.xml" source="GENTOO">GLSA-200411-34</ref>
      <ref url="http://security.e-matters.de/advisories/152004.html" source="MISC">http://security.e-matters.de/advisories/152004.html</ref>
      <ref url="http://secunia.com/advisories/13274/" source="SECUNIA">13274</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110123023521619&amp;w=2" source="BUGTRAQ" adv="1">20041122 Advisory 15/2004: Cyrus IMAP Server multiple remote vulnerabilities</ref>
      <ref url="http://asg.web.cmu.edu/cyrus/download/imapd/changes.html" source="CONFIRM">http://asg.web.cmu.edu/cyrus/download/imapd/changes.html</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2004:139" source="MANDRAKE">MDKSA-2004:139</ref>
      <ref url="http://asg.web.cmu.edu/archive/message.php?mailbox=archive.cyrus-announce&amp;msg=143" source="MLIST">[cyrus-announce] 20041122 Cyrus IMAPd 2.2.9 Released</ref>
    </refs>
    <vuln_soft>
      <prod vendor="carnegie_mellon_university" name="cyrus_imap_server">
        <vers num="2.1.10" />
        <vers num="2.1.16" />
        <vers num="2.1.7" />
        <vers num="2.1.9" />
        <vers num="2.2.0_alpha" />
        <vers num="2.2.1_beta" />
        <vers num="2.2.2_beta" />
        <vers num="2.2.3" />
        <vers num="2.2.4" />
        <vers num="2.2.5" />
        <vers num="2.2.6" />
        <vers num="2.2.7" />
        <vers num="2.2.8" />
      </prod>
      <prod vendor="openpkg" name="openpkg">
        <vers num="current" />
      </prod>
      <prod vendor="conectiva" name="linux">
        <vers num="10.0" />
        <vers num="9.0" />
      </prod>
      <prod vendor="redhat" name="fedora_core">
        <vers num="core_2.0" />
        <vers num="core_3.0" />
      </prod>
      <prod vendor="trustix" name="secure_linux">
        <vers num="2.0" />
        <vers num="2.1" />
        <vers num="2.2" />
      </prod>
      <prod vendor="ubuntu" name="ubuntu_linux">
        <vers num="4.1" edition="" />
        <vers num="4.1" edition=":ia64" />
        <vers num="4.1" edition=":ppc" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-1012" published="2005-01-10" name="CVE-2004-1012" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">The argument parser of the PARTIAL command in Cyrus IMAP Server 2.2.6 and earlier allows remote authenticated users to execute arbitrary code via a certain command ("body[p") that is treated as a different command ("body.peek") and causes an index increment error that leads to an out-of-bounds memory corruption.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" admin="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/18199" source="XF" adv="1">cyrus-imap-commands-execute-code(18199)</ref>
      <ref url="http://www.debian.org/security/2004/dsa-597" source="DEBIAN">DSA-597</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200411-34.xml" source="GENTOO">GLSA-200411-34</ref>
      <ref url="http://security.e-matters.de/advisories/152004.html" source="MISC">http://security.e-matters.de/advisories/152004.html</ref>
      <ref url="http://secunia.com/advisories/13274/" source="SECUNIA">13274</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110123023521619&amp;w=2" source="BUGTRAQ" adv="1">20041122 Advisory 15/2004: Cyrus IMAP Server multiple remote vulnerabilities</ref>
      <ref url="http://asg.web.cmu.edu/cyrus/download/imapd/changes.html" source="CONFIRM">http://asg.web.cmu.edu/cyrus/download/imapd/changes.html</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2004:139" source="MANDRAKE">MDKSA-2004:139</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110134117423743&amp;w=2" source="UBUNTU">USN-31-1</ref>
      <ref url="http://asg.web.cmu.edu/archive/message.php?mailbox=archive.cyrus-announce&amp;msg=143" source="MLIST">[cyrus-announce] 20041122 Cyrus IMAPd 2.2.9 Released</ref>
    </refs>
    <vuln_soft>
      <prod vendor="carnegie_mellon_university" name="cyrus_imap_server">
        <vers num="2.1.10" />
        <vers num="2.1.16" />
        <vers num="2.1.7" />
        <vers num="2.1.9" />
        <vers num="2.2.0_alpha" />
        <vers num="2.2.1_beta" />
        <vers num="2.2.2_beta" />
        <vers num="2.2.3" />
        <vers num="2.2.4" />
        <vers num="2.2.5" />
        <vers num="2.2.6" />
        <vers num="2.2.7" />
        <vers num="2.2.8" />
      </prod>
      <prod vendor="openpkg" name="openpkg">
        <vers num="current" />
      </prod>
      <prod vendor="conectiva" name="linux">
        <vers num="10.0" />
        <vers num="9.0" />
      </prod>
      <prod vendor="redhat" name="fedora_core">
        <vers num="core_2.0" />
        <vers num="core_3.0" />
      </prod>
      <prod vendor="trustix" name="secure_linux">
        <vers num="2.0" />
        <vers num="2.1" />
        <vers num="2.2" />
      </prod>
      <prod vendor="ubuntu" name="ubuntu_linux">
        <vers num="4.1" edition="" />
        <vers num="4.1" edition=":ia64" />
        <vers num="4.1" edition=":ppc" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-1013" published="2005-01-10" name="CVE-2004-1013" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">The argument parser of the FETCH command in Cyrus IMAP Server 2.2.x through 2.2.8 allows remote authenticated users to execute arbitrary code via certain commands such as (1) "body[p", (2) "binary[p", or (3) "binary[p") that cause an index increment error that leads to an out-of-bounds memory corruption.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" admin="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.debian.org/security/2004/dsa-597" source="DEBIAN" patch="1" adv="1">DSA-597</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200411-34.xml" source="GENTOO">GLSA-200411-34</ref>
      <ref url="http://security.e-matters.de/advisories/152004.html" source="MISC">http://security.e-matters.de/advisories/152004.html</ref>
      <ref url="http://secunia.com/advisories/13274/" source="SECUNIA">13274</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110123023521619&amp;w=2" source="BUGTRAQ" adv="1">20041122 Advisory 15/2004: Cyrus IMAP Server multiple remote vulnerabilities</ref>
      <ref url="http://asg.web.cmu.edu/cyrus/download/imapd/changes.html" source="CONFIRM">http://asg.web.cmu.edu/cyrus/download/imapd/changes.html</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2004:139" source="MANDRAKE">MDKSA-2004:139</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110134117423743&amp;w=2" source="UBUNTU">USN-31-1</ref>
      <ref url="http://asg.web.cmu.edu/archive/message.php?mailbox=archive.cyrus-announce&amp;msg=143" source="MLIST">[cyrus-announce] 20041122 Cyrus IMAPd 2.2.9 Released</ref>
    </refs>
    <vuln_soft>
      <prod vendor="carnegie_mellon_university" name="cyrus_imap_server">
        <vers num="2.1.10" />
        <vers num="2.1.16" />
        <vers num="2.1.7" />
        <vers num="2.1.9" />
        <vers num="2.2.0_alpha" />
        <vers num="2.2.1_beta" />
        <vers num="2.2.2_beta" />
        <vers num="2.2.3" />
        <vers num="2.2.4" />
        <vers num="2.2.5" />
        <vers num="2.2.6" />
        <vers num="2.2.7" />
        <vers num="2.2.8" />
      </prod>
      <prod vendor="openpkg" name="openpkg">
        <vers num="current" />
      </prod>
      <prod vendor="conectiva" name="linux">
        <vers num="10.0" />
        <vers num="9.0" />
      </prod>
      <prod vendor="redhat" name="fedora_core">
        <vers num="core_2.0" />
        <vers num="core_3.0" />
      </prod>
      <prod vendor="trustix" name="secure_linux">
        <vers num="2.0" />
        <vers num="2.1" />
        <vers num="2.2" />
      </prod>
      <prod vendor="ubuntu" name="ubuntu_linux">
        <vers num="4.1" edition="" />
        <vers num="4.1" edition=":ia64" />
        <vers num="4.1" edition=":ppc" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1014" published="2005-01-10" name="CVE-2004-1014" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">statd in nfs-utils 1.257 and earlier does not ignore the SIGPIPE signal, which allows remote attackers to cause a denial of service (server process crash) via a TCP connection that is prematurely terminated.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/11785" source="BID" patch="1" adv="1">11785</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/18332" source="XF" adv="1">nfs-utils-statd-dos(18332)</ref>
      <ref url="http://www.trustix.org/errata/2004/0065/" source="TRUSTIX">2004-0065</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-014.html" source="REDHAT">RHSA-2005:014</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-583.html" source="REDHAT">RHSA-2004:583</ref>
      <ref url="http://www.debian.org/security/2004/dsa-606" source="DEBIAN">DSA-606</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10899" source="OVAL">oval:org.mitre.oval:def:10899</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110194853709629&amp;w=2" source="UBUNTU" adv="1">USN-36-1</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/426072/30/6740/threaded" source="FEDORA">FLSA-2006:138098</ref>
      <ref url="http://cvs.sourceforge.net/viewcvs.py/nfs/nfs-utils/ChangeLog?rev=1.258&amp;view=markup" source="CONFIRM">http://cvs.sourceforge.net/viewcvs.py/nfs/nfs-utils/ChangeLog?rev=1.258&amp;view=markup</ref>
    </refs>
    <vuln_soft>
      <prod vendor="nfs" name="nfs-utils">
        <vers num="1.0.6" />
      </prod>
      <prod vendor="debian" name="debian_linux">
        <vers num="3.0" edition="" />
        <vers num="3.0" edition=":mips" />
        <vers num="3.0" edition=":ia-32" />
        <vers num="3.0" edition=":s-390" />
        <vers num="3.0" edition=":alpha" />
        <vers num="3.0" edition=":arm" />
        <vers num="3.0" edition=":mipsel" />
        <vers num="3.0" edition=":ppc" />
        <vers num="3.0" edition=":hppa" />
        <vers num="3.0" edition=":m68k" />
        <vers num="3.0" edition=":ia-64" />
        <vers num="3.0" edition=":sparc" />
      </prod>
      <prod vendor="mandrakesoft" name="mandrake_linux">
        <vers num="10.0" edition="" />
        <vers num="10.0" edition=":amd64" />
        <vers num="10.1" edition="" />
        <vers num="10.1" edition=":x86_64" />
        <vers num="9.2" edition="" />
        <vers num="9.2" edition=":amd64" />
      </prod>
      <prod vendor="mandrakesoft" name="mandrake_linux_corporate_server">
        <vers num="2.1" edition="" />
        <vers num="2.1" edition=":x86_64" />
      </prod>
      <prod vendor="redhat" name="enterprise_linux">
        <vers num="3.0" edition="" />
        <vers num="3.0" edition=":advanced_server" />
        <vers num="3.0" edition=":workstation_server" />
        <vers num="3.0" edition=":enterprise_server" />
      </prod>
      <prod vendor="redhat" name="enterprise_linux_desktop">
        <vers num="3.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-1015" published="2005-01-10" name="CVE-2004-1015" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Buffer overflow in proxyd for Cyrus IMAP Server 2.2.9 and earlier, with the imapmagicplus option enabled, may allow remote attackers to execute arbitrary code, a different vulnerability than CVE-2004-1011.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
      <config />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://security.gentoo.org/glsa/glsa-200411-34.xml" source="GENTOO" patch="1" adv="1">GLSA-200411-34</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/18274" source="XF" adv="1">cyrus-magic-plus-bo(18274)</ref>
      <ref url="http://asg.web.cmu.edu/cyrus/download/imapd/changes.html" source="CONFIRM">http://asg.web.cmu.edu/cyrus/download/imapd/changes.html</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2004:139" source="MANDRAKE">MDKSA-2004:139</ref>
      <ref url="http://asg.web.cmu.edu/archive/message.php?mailbox=archive.cyrus-announce&amp;msg=145" source="MLIST">[cyrus-announce] 20041123 Cyrus IMAPd 2.2.10 Released</ref>
    </refs>
    <vuln_soft>
      <prod vendor="carnegie_mellon_university" name="cyrus_imap_server">
        <vers num="1.4" />
        <vers num="1.5.19" />
        <vers num="2.0.12" />
        <vers num="2.0.16" />
        <vers num="2.1.10" />
        <vers num="2.1.16" />
        <vers num="2.1.7" />
        <vers num="2.1.9" />
        <vers num="2.2.0_alpha" />
        <vers num="2.2.1_beta" />
        <vers num="2.2.2_beta" />
        <vers num="2.2.3" />
        <vers num="2.2.4" />
        <vers num="2.2.5" />
        <vers num="2.2.6" />
        <vers num="2.2.7" />
        <vers num="2.2.8" />
        <vers num="2.2.9" />
      </prod>
      <prod vendor="redhat" name="fedora_core">
        <vers num="core_2.0" />
        <vers num="core_3.0" />
      </prod>
      <prod vendor="ubuntu" name="ubuntu_linux">
        <vers num="4.1" edition="" />
        <vers num="4.1" edition=":ia64" />
        <vers num="4.1" edition=":ppc" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2004-1016" published="2005-01-10" name="CVE-2004-1016" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">The scm_send function in the scm layer for Linux kernel 2.4.x up to 2.4.28, and 2.6.x up to 2.6.9, allows local users to cause a denial of service (system hang) via crafted auxiliary messages that are passed to the sendmsg function, which causes a deadlock condition.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/11921" source="BID" patch="1" adv="1">11921</ref>
      <ref url="https://bugzilla.fedora.us/show_bug.cgi?id=2336" source="FEDORA">FLSA:2336</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/18483" source="XF">linux-scmsend-dos(18483)</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-689.html" source="REDHAT">RHSA-2004:689</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11816" source="OVAL">oval:org.mitre.oval:def:11816</ref>
      <ref url="http://isec.pl/vulnerabilities/isec-0019-scm.txt" source="MISC">http://isec.pl/vulnerabilities/isec-0019-scm.txt</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-017.html" source="REDHAT">RHSA-2005:017</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-016.html" source="REDHAT">RHSA-2005:016</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2004_44_kernel.html" source="SUSE">SUSE-SA:2004:044</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:022" source="MANDRAKE">MDKSA-2005:022</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1082" source="DEBIAN">DSA-1082</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1070" source="DEBIAN">DSA-1070</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1069" source="DEBIAN">DSA-1069</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1067" source="DEBIAN">DSA-1067</ref>
      <ref url="http://secunia.com/advisories/20338" source="SECUNIA">20338</ref>
      <ref url="http://secunia.com/advisories/20202" source="SECUNIA">20202</ref>
      <ref url="http://secunia.com/advisories/20163" source="SECUNIA">20163</ref>
      <ref url="http://secunia.com/advisories/20162" source="SECUNIA">20162</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110306397320336&amp;w=2" source="UBUNTU">USN-38-1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="linux" name="linux_kernel">
        <vers num="2.4.0" edition="test1" />
        <vers num="2.4.0" edition="test10" />
        <vers num="2.4.0" edition="test11" />
        <vers num="2.4.0" edition="test12" />
        <vers num="2.4.0" edition="test2" />
        <vers num="2.4.0" edition="test3" />
        <vers num="2.4.0" edition="test4" />
        <vers num="2.4.0" edition="test5" />
        <vers num="2.4.0" edition="test6" />
        <vers num="2.4.0" edition="test7" />
        <vers num="2.4.0" edition="test8" />
        <vers num="2.4.0" edition="test9" />
        <vers num="2.4.1" />
        <vers num="2.4.10" />
        <vers num="2.4.11" />
        <vers num="2.4.12" />
        <vers num="2.4.13" />
        <vers num="2.4.14" />
        <vers num="2.4.15" />
        <vers num="2.4.16" />
        <vers num="2.4.17" />
        <vers num="2.4.18" edition="" />
        <vers num="2.4.18" edition=":x86" />
        <vers num="2.4.18" edition="pre1" />
        <vers num="2.4.18" edition="pre2" />
        <vers num="2.4.18" edition="pre3" />
        <vers num="2.4.18" edition="pre4" />
        <vers num="2.4.18" edition="pre5" />
        <vers num="2.4.18" edition="pre6" />
        <vers num="2.4.18" edition="pre7" />
        <vers num="2.4.18" edition="pre8" />
        <vers num="2.4.19" edition="pre1" />
        <vers num="2.4.19" edition="pre2" />
        <vers num="2.4.19" edition="pre3" />
        <vers num="2.4.19" edition="pre4" />
        <vers num="2.4.19" edition="pre5" />
        <vers num="2.4.19" edition="pre6" />
        <vers num="2.4.2" />
        <vers num="2.4.20" />
        <vers num="2.4.21" edition="pre1" />
        <vers num="2.4.21" edition="pre4" />
        <vers num="2.4.21" edition="pre7" />
        <vers num="2.4.22" />
        <vers num="2.4.23" edition="pre9" />
        <vers num="2.4.23_ow2" />
        <vers num="2.4.24" />
        <vers num="2.4.24_ow1" />
        <vers num="2.4.25" />
        <vers num="2.4.26" />
        <vers num="2.4.27" edition="pre1" />
        <vers num="2.4.27" edition="pre2" />
        <vers num="2.4.27" edition="pre3" />
        <vers num="2.4.27" edition="pre4" />
        <vers num="2.4.27" edition="pre5" />
        <vers num="2.4.28" />
        <vers num="2.4.3" />
        <vers num="2.4.4" />
        <vers num="2.4.5" />
        <vers num="2.4.6" />
        <vers num="2.4.7" />
        <vers num="2.4.8" />
        <vers num="2.4.9" />
        <vers num="2.6.0" edition="test1" />
        <vers num="2.6.0" edition="test10" />
        <vers num="2.6.0" edition="test11" />
        <vers num="2.6.0" edition="test2" />
        <vers num="2.6.0" edition="test3" />
        <vers num="2.6.0" edition="test4" />
        <vers num="2.6.0" edition="test5" />
        <vers num="2.6.0" edition="test6" />
        <vers num="2.6.0" edition="test7" />
        <vers num="2.6.0" edition="test8" />
        <vers num="2.6.0" edition="test9" />
        <vers num="2.6.1" edition="rc1" />
        <vers num="2.6.1" edition="rc2" />
        <vers num="2.6.2" />
        <vers num="2.6.3" />
        <vers num="2.6.4" />
        <vers num="2.6.5" />
        <vers num="2.6.6" edition="rc1" />
        <vers num="2.6.7" edition="rc1" />
        <vers num="2.6.8" edition="rc1" />
        <vers num="2.6.8" edition="rc2" />
        <vers num="2.6.8" edition="rc3" />
        <vers num="2.6.9" edition="2.6.20" />
        <vers num="2.6_test9_cvs" />
      </prod>
      <prod vendor="ubuntu" name="ubuntu_linux">
        <vers num="4.1" edition="" />
        <vers num="4.1" edition=":ppc" />
        <vers num="4.1" edition=":ia64" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-1017" published="2004-12-31" name="CVE-2004-1017" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Multiple "overflows" in the io_edgeport driver for Linux kernel 2.4.x have unknown impact and unknown attack vectors.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="https://bugzilla.fedora.us/show_bug.cgi?id=2336" source="FEDORA" patch="1">FLSA:2336</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/18433" source="XF">linux-ioedgeport-bo(18433)</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-689.html" source="REDHAT">RHSA-2004:689</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9786" source="OVAL">oval:org.mitre.oval:def:9786</ref>
      <ref url="http://www.securityfocus.com/bid/12102" source="BID">12102</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-017.html" source="REDHAT">RHSA-2005:017</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-016.html" source="REDHAT">RHSA-2005:016</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1082" source="DEBIAN">DSA-1082</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1070" source="DEBIAN">DSA-1070</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1069" source="DEBIAN">DSA-1069</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1067" source="DEBIAN">DSA-1067</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1017" source="DEBIAN">DSA-1017</ref>
      <ref url="http://secunia.com/advisories/20338" source="SECUNIA">20338</ref>
      <ref url="http://secunia.com/advisories/20202" source="SECUNIA">20202</ref>
      <ref url="http://secunia.com/advisories/20163" source="SECUNIA">20163</ref>
      <ref url="http://secunia.com/advisories/20162" source="SECUNIA">20162</ref>
      <ref url="http://secunia.com/advisories/19374" source="SECUNIA">19374</ref>
    </refs>
    <vuln_soft>
      <prod vendor="linux" name="linux_kernel">
        <vers num="2.4.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-1018" published="2005-01-10" name="CVE-2004-1018" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Multiple integer handling errors in PHP before 4.3.10 allow attackers to bypass safe mode restrictions, cause a denial of service, or execute arbitrary code via (1) a negative offset value to the shmop_write function, (2) an "integer overflow/underflow" in the pack function, or (3) an "integer overflow/underflow" in the unpack function.  NOTE: this issue was originally REJECTed by its CNA before publication, but that decision is in active dispute.  This candidate may change significantly in the future as a result of further discussion.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="https://bugzilla.fedora.us/show_bug.cgi?id=2344" source="FEDORA">FLSA:2344</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/18515" source="XF">php-shmopwrite-outofbounds-memory(18515)</ref>
      <ref url="http://www.securityfocus.com/bid/12045" source="BID">12045</ref>
      <ref url="http://www.securityfocus.com/archive/1/384920" source="BUGTRAQ">20041219 PHP shmop.c module permits write of arbitrary memory.</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-032.html" source="REDHAT">RHSA-2005:032</ref>
      <ref url="http://www.php.net/release_4_3_10.php" source="CONFIRM">http://www.php.net/release_4_3_10.php</ref>
      <ref url="http://www.hardened-php.net/advisories/012004.txt" source="MISC">http://www.hardened-php.net/advisories/012004.txt</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10949" source="OVAL">oval:org.mitre.oval:def:10949</ref>
      <ref url="http://www.securityfocus.com/advisories/9028" source="HP">HPSBMA01212</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-816.html" source="REDHAT">RHSA-2005:816</ref>
      <ref url="http://www.osvdb.org/12411" source="OSVDB">12411</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:072" source="MANDRAKE">MDKSA-2005:072</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2004:151" source="MANDRAKE">MDKSA-2004:151</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111117104809638&amp;w=2" source="UBUNTU">USN-99-1</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110314318531298&amp;w=2" source="BUGTRAQ">20041215 Advisory 01/2004: Multiple vulnerabilities in PHP 4/5</ref>
    </refs>
  </entry>
  <entry type="CVE" severity="High" seq="2004-1019" published="2005-01-10" name="CVE-2004-1019" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">The deserialization code in PHP before 4.3.10 and PHP 5.x up to 5.0.2 allows remote attackers to cause a denial of service and execute arbitrary code via untrusted data to the unserialize function that may trigger "information disclosure, double-free and negative reference index array underflow" results.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" admin="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-687.html" source="REDHAT" patch="1" adv="1">RHSA-2004:687</ref>
      <ref url="https://bugzilla.fedora.us/show_bug.cgi?id=2344" source="FEDORA">FLSA:2344</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/18514" source="XF">php-unserialize-code-execution(18514)</ref>
      <ref url="http://www.securityfocus.com/advisories/9028" source="HP">HPSBMA01212</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-816.html" source="REDHAT">RHSA-2005:816</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-032.html" source="REDHAT">RHSA-2005:032</ref>
      <ref url="http://www.php.net/release_4_3_10.php" source="CONFIRM">http://www.php.net/release_4_3_10.php</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2005_02_php4_mod_php4.html" source="SUSE">SUSE-SA:2005:002</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2004:151" source="MANDRAKE">MDKSA-2004:151</ref>
      <ref url="http://www.hardened-php.net/advisories/012004.txt" source="MISC">http://www.hardened-php.net/advisories/012004.txt</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10511" source="OVAL">oval:org.mitre.oval:def:10511</ref>
      <ref url="http://msgs.securepoint.com/cgi-bin/get/bugtraq0412/157.html" source="OPENPKG">OpenPKG-SA-2004.053</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110314318531298&amp;w=2" source="BUGTRAQ">20041215 Advisory 01/2004: Multiple vulnerabilities in PHP 4/5</ref>
    </refs>
    <vuln_soft>
      <prod vendor="openpkg" name="openpkg">
        <vers num="2.1" />
        <vers num="2.2" />
        <vers num="current" />
      </prod>
      <prod vendor="php" name="php">
        <vers num="3.0" />
        <vers num="3.0.1" />
        <vers num="3.0.10" />
        <vers num="3.0.11" />
        <vers num="3.0.12" />
        <vers num="3.0.13" />
        <vers num="3.0.14" />
        <vers num="3.0.15" />
        <vers num="3.0.16" />
        <vers num="3.0.17" />
        <vers num="3.0.18" />
        <vers num="3.0.2" />
        <vers num="3.0.3" />
        <vers num="3.0.4" />
        <vers num="3.0.5" />
        <vers num="3.0.6" />
        <vers num="3.0.7" />
        <vers num="3.0.8" />
        <vers num="3.0.9" />
        <vers num="4.0" />
        <vers num="4.0.1" edition="patch1" />
        <vers num="4.0.1" edition="patch2" />
        <vers num="4.0.2" />
        <vers num="4.0.3" edition="patch1" />
        <vers num="4.0.4" />
        <vers num="4.0.5" />
        <vers num="4.0.6" />
        <vers num="4.0.7" edition="rc1" />
        <vers num="4.0.7" edition="rc2" />
        <vers num="4.0.7" edition="rc3" />
        <vers num="4.1.0" />
        <vers num="4.1.1" />
        <vers num="4.1.2" />
        <vers num="4.2" edition="" />
        <vers num="4.2" edition=":dev" />
        <vers num="4.2.0" />
        <vers num="4.2.1" />
        <vers num="4.2.2" />
        <vers num="4.2.3" />
        <vers num="4.3" />
        <vers num="4.3.1" />
        <vers num="4.3.2" />
        <vers num="4.3.3" />
        <vers num="4.3.4" />
        <vers num="4.3.5" />
        <vers num="4.3.6" />
        <vers num="4.3.7" />
        <vers num="4.3.8" />
        <vers num="4.3.9" />
        <vers num="5.0" edition="rc1" />
        <vers num="5.0" edition="rc2" />
        <vers num="5.0" edition="rc3" />
        <vers num="5.0.0" />
        <vers num="5.0.1" />
        <vers num="5.0.2" />
      </prod>
      <prod vendor="trustix" name="secure_linux">
        <vers num="2.0" />
        <vers num="2.1" />
        <vers num="2.2" />
      </prod>
      <prod vendor="ubuntu" name="ubuntu_linux">
        <vers num="4.1" edition="" />
        <vers num="4.1" edition=":ia64" />
        <vers num="4.1" edition=":ppc" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1020" published="2005-01-10" name="CVE-2004-1020" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The addslashes function in PHP 4.3.9 does not properly escape a NULL (/0) character, which may allow remote attackers to read arbitrary files in PHP applications that contain a directory traversal vulnerability in require or include statements, but are otherwise protected by the magic_quotes_gpc mechanism.  NOTE: this issue was originally REJECTed by its CNA before publication, but that decision is in active dispute.  This candidate may change significantly in the future as a result of further discussion.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/11981" source="BID" patch="1">11981</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/18516" source="XF">php-addslashes-view-files(18516)</ref>
      <ref url="http://www.securityfocus.com/archive/1/384663" source="BUGTRAQ" adv="1">20041216 PHP Input Validation Vulnerabilities</ref>
      <ref url="http://www.securityfocus.com/advisories/9028" source="HP">HPSBMA01212</ref>
      <ref url="http://www.php.net/release_4_3_10.php" source="CONFIRM" adv="1">http://www.php.net/release_4_3_10.php</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200412-14.xml" source="GENTOO" adv="1">GLSA-200412-14</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000915" source="CONECTIVA">CLA-2005:915</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2004:151" source="MANDRAKE">MDKSA-2004:151</ref>
    </refs>
    <vuln_soft>
      <prod vendor="php" name="php">
        <vers num="4.3.6" />
        <vers num="4.3.7" />
        <vers num="4.3.8" />
        <vers num="4.3.9" />
        <vers num="5.0" edition="rc1" />
        <vers num="5.0" edition="rc2" />
        <vers num="5.0" edition="rc3" />
        <vers num="5.0.0" />
        <vers num="5.0.1" />
        <vers num="5.0.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-1021" published="2005-03-01" name="CVE-2004-1021" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">iCal before 1.5.4 on Mac OS X 10.2.3, and other later versions, does not alert the user when handling calendars that use alarms, which allows attackers to execute programs and send e-mail via alarms.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/18209" source="XF">ical-calendar-authorization-bypass(18209)</ref>
      <ref url="http://lists.apple.com/archives/security-announce//2004/Nov/msg00000.html" source="APPLE">APPLE-SA-2004-11-22</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="ical">
        <vers num="1.5.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2004-1022" published="2005-01-10" name="CVE-2004-1022" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">Kerio Winroute Firewall before 6.0.7, ServerFirewall before 1.0.1, and MailServer before 6.0.5 use symmetric encryption for user passwords, which allows attackers to decrypt the user database and obtain the passwords by extracting the secret key from within the software.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/18470" source="XF">kerio-weak-encryption(18470)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110304957607578&amp;w=2" source="BUGTRAQ" adv="1">20041214 [CAN-2004-1022] Insecure Credential Storage on Kerio Software</ref>
    </refs>
    <vuln_soft>
      <prod vendor="kerio" name="kerio_mailserver">
        <vers num="5.0" />
        <vers num="5.1" />
        <vers num="5.1.1" />
        <vers num="5.6.3" />
        <vers num="5.6.4" />
        <vers num="5.6.5" />
        <vers num="5.7.0" />
        <vers num="5.7.1" />
        <vers num="5.7.10" />
        <vers num="5.7.2" />
        <vers num="5.7.3" />
        <vers num="5.7.4" />
        <vers num="5.7.5" />
        <vers num="5.7.6" />
        <vers num="5.7.7" />
        <vers num="5.7.8" />
        <vers num="5.7.9" />
        <vers num="6.0" />
        <vers num="6.0.1" />
        <vers num="6.0.2" />
        <vers num="6.0.3" />
        <vers num="6.0.4" />
      </prod>
      <prod vendor="kerio" name="serverfirewall">
        <vers num="1.0" />
      </prod>
      <prod vendor="kerio" name="winroute_firewall">
        <vers num="5.0.1" />
        <vers num="5.0.2" />
        <vers num="5.0.3" />
        <vers num="5.0.4" />
        <vers num="5.0.5" />
        <vers num="5.0.6" />
        <vers num="5.0.7" />
        <vers num="5.0.8" />
        <vers num="5.0.9" />
        <vers num="5.1" />
        <vers num="5.1.1" />
        <vers num="5.1.10" />
        <vers num="5.1.2" />
        <vers num="5.1.3" />
        <vers num="5.1.4" />
        <vers num="5.1.5" />
        <vers num="5.1.6" />
        <vers num="5.1.7" />
        <vers num="5.1.8" />
        <vers num="5.1.9" />
        <vers num="5.10" />
        <vers num="6.0" />
        <vers num="6.0.1" />
        <vers num="6.0.2" />
        <vers num="6.0.3" />
        <vers num="6.0.4" />
        <vers num="6.0.5" />
        <vers num="6.0.6" />
        <vers num="6.0.7" />
        <vers num="6.0.8" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2004-1023" published="2005-01-10" name="CVE-2004-1023" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">Kerio Winroute Firewall before 6.0.9, ServerFirewall before 1.0.1, and MailServer before 6.0.5, when installed on Windows based systems, do not modify the ACLs for critical files, which allows local users with Power Users privileges to modify programs, install malicious DLLs in the plug-ins folder, and modify XML files related to configuration.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/18471" source="XF">kerio-insecure-permissions(18471)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110305387813002&amp;w=2" source="BUGTRAQ">20041214 [CAN-2004-1023] Insecure default file system permissions on Microsoft versions of Kerio Software</ref>
    </refs>
    <vuln_soft>
      <prod vendor="kerio" name="kerio_mailserver">
        <vers num="6.0.0" />
        <vers num="6.0.1" />
        <vers num="6.0.2" />
        <vers num="6.0.3" />
        <vers num="6.0.4" />
      </prod>
      <prod vendor="kerio" name="serverfirewall">
        <vers num="1.0.0" />
      </prod>
      <prod vendor="kerio" name="winroute_firewall">
        <vers num="6.0.0" />
        <vers num="6.0.1" />
        <vers num="6.0.2" />
        <vers num="6.0.3" />
        <vers num="6.0.4" />
        <vers num="6.0.5" />
        <vers num="6.0.6" />
        <vers num="6.0.7" />
        <vers num="6.0.8" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-1025" published="2005-01-10" name="CVE-2004-1025" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Multiple heap-based buffer overflows in imlib 1.9.14 and earlier, which is used by gkrellm and several window managers, allow remote attackers to cause a denial of service (application crash) and execute arbitrary code via certain image files.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-651.html" source="REDHAT" patch="1" adv="1">RHSA-2004:651</ref>
      <ref url="http://www.securityfocus.com/bid/11830" source="BID" adv="1">11830</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10786" source="OVAL">oval:org.mitre.oval:def:10786</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:007" source="MANDRAKE">MDKSA-2005:007</ref>
    </refs>
    <vuln_soft>
      <prod vendor="enlightenment" name="imlib">
        <vers num="1.9.13" />
        <vers num="1.9.14" />
      </prod>
      <prod vendor="gentoo" name="linux">
        <vers num="" />
      </prod>
      <prod vendor="redhat" name="linux">
        <vers num="7.3" edition="" />
        <vers num="7.3" edition=":i386" />
        <vers num="7.3" edition=":i686" />
        <vers num="9.0" edition="" />
        <vers num="9.0" edition=":i386" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-1026" published="2005-01-10" name="CVE-2004-1026" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Multiple integer overflows in the image handler for imlib 1.9.14 and earlier, which is used by gkrellm and several window managers, allow remote attackers to cause a denial of service (application crash) and execute arbitrary code via certain image files.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" admin="1" />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-651.html" source="REDHAT" patch="1" adv="1">RHSA-2004:651</ref>
      <ref url="http://www.securityfocus.com/bid/11830" source="BID" adv="1">11830</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200412-03.xml" source="GENTOO">GLSA-200412-03</ref>
      <ref url="http://www.debian.org/security/2005/dsa-628" source="DEBIAN">DSA-628</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10771" source="OVAL">oval:org.mitre.oval:def:10771</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:007" source="MANDRAKE">MDKSA-2005:007</ref>
    </refs>
    <vuln_soft>
      <prod vendor="enlightenment" name="imlib">
        <vers num="1.9.13" />
        <vers num="1.9.14" />
      </prod>
      <prod vendor="gentoo" name="linux">
        <vers num="" />
      </prod>
      <prod vendor="redhat" name="linux">
        <vers num="7.3" edition="" />
        <vers num="7.3" edition=":i386" />
        <vers num="7.3" edition=":i686" />
        <vers num="9.0" edition="" />
        <vers num="9.0" edition=":i386" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1027" published="2005-03-01" name="CVE-2004-1027" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in the -x (extract) command line option in unarj allows remote attackers to overwrite arbitrary files via an arj archive with filenames that contain .. (dot dot) sequences.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/11436" source="BID" patch="1" adv="1">11436</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/17684" source="XF" adv="1">unarj-directory-traversal(17684)</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-007.html" source="REDHAT">RHSA-2005:007</ref>
      <ref url="http://www.debian.org/security/2005/dsa-652" source="DEBIAN">DSA-652</ref>
      <ref url="http://www.debian.org/security/2005/dsa-628" source="DEBIAN">DSA-628</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200411-29.xml" source="GENTOO">GLSA-200411-29</ref>
      <ref url="http://lwn.net/Articles/121827/" source="FEDORA">FLSA:2272</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2004-October/027348.html" source="FULLDISC">20041010 unarj dir-transversal bug (../../../..)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="arj_software_inc." name="unarj">
        <vers num="2.62" />
        <vers num="2.63_a" />
        <vers num="2.64" />
        <vers num="2.65" />
      </prod>
      <prod vendor="gentoo" name="linux">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-1028" published="2005-01-10" name="CVE-2004-1028" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Untrusted execution path vulnerability in chcod on AIX IBM 5.1.0, 5.2.0, and 5.3.0 allows local users to execute arbitrary programs by modifying the PATH environment variable to point to a malicious "grep" program, which is executed from chcod.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" admin="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/18625" source="XF">aix-chcod-gain-privileges(18625)</ref>
      <ref url="http://www.idefense.com/application/poi/display?id=170&amp;type=vulnerabilities" source="IDEFENSE" adv="1">20041220 IBM AIX chcod Local Privilege Escalation Vulnerability</ref>
      <ref url="http://www-1.ibm.com/support/search.wss?rs=0&amp;q=IY64356&amp;apar=only" source="AIXAPAR">IY64356</ref>
      <ref url="http://www-1.ibm.com/support/search.wss?rs=0&amp;q=IY64355&amp;apar=only" source="AIXAPAR">IY64355</ref>
      <ref url="http://www-1.ibm.com/support/search.wss?rs=0&amp;q=IY64354&amp;apar=only" source="AIXAPAR">IY64354</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="aix">
        <vers num="5.1" />
        <vers num="5.1l" />
        <vers num="5.2" />
        <vers num="5.2.2" />
        <vers num="5.2_l" />
        <vers num="5.3" />
        <vers num="5.3_l" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-1029" published="2005-03-01" name="CVE-2004-1029" modified="2011-06-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">The Sun Java Plugin capability in Java 2 Runtime Environment (JRE) 1.4.2_01, 1.4.2_04, and possibly earlier versions, does not properly restrict access between Javascript and Java applets during data transfer, which allows remote attackers to load unsafe classes and execute arbitrary code by using the reflection API to access private Java packages.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/760344" source="CERT-VN">VU#760344</ref>
      <ref url="http://www.securityfocus.com/bid/12317" source="BID" patch="1">12317</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-57591-1" source="SUNALERT" patch="1" adv="1">57591</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-101523-1" source="SUNALERT" patch="1" adv="1">101523</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/18188" source="XF">sdk-jre-applet-restriction-bypass(18188)</ref>
      <ref url="http://www.vupen.com/english/advisories/2008/0599" source="VUPEN" adv="1">ADV-2008-0599</ref>
      <ref url="http://www.idefense.com/application/poi/display?id=158&amp;type=vulnerabilities" source="IDEFENSE">20041122 Sun Java Plugin Arbitrary Package Access Vulnerability</ref>
      <ref url="http://www-1.ibm.com/support/docview.wss?uid=swg21257249" source="CONFIRM">http://www-1.ibm.com/support/docview.wss?uid=swg21257249</ref>
      <ref url="http://securityreason.com/securityalert/61" source="SREASON">61</ref>
      <ref url="http://secunia.com/advisories/29035" source="SECUNIA" adv="1">29035</ref>
      <ref url="http://secunia.com/advisories/13271" source="SECUNIA" adv="1">13271</ref>
      <ref url="http://rpmfind.net/linux/RPM/suse/updates/9.3/i386/rpm/i586/java-1_4_2-sun-src-1.4.2.08-0.1.i586.html" source="CONFIRM">http://rpmfind.net/linux/RPM/suse/updates/9.3/i386/rpm/i586/java-1_4_2-sun-src-1.4.2.08-0.1.i586.html</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5674" source="OVAL">oval:org.mitre.oval:def:5674</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2005/Feb/msg00000.html" source="APPLE">APPLE-SA-2005-02-22</ref>
      <ref url="http://jouko.iki.fi/adv/javaplugin.html" source="MISC">http://jouko.iki.fi/adv/javaplugin.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hp" name="java_sdk-rte">
        <vers num="1.3" edition="" />
        <vers num="1.3" edition=":hp-ux_pa-risc" />
        <vers num="1.4" edition="" />
        <vers num="1.4" edition=":hp-ux_pa-risc" />
      </prod>
      <prod vendor="sun" name="jdk">
        <vers num="1.3.1_01" edition="" />
        <vers num="1.3.1_01" edition=":linux" />
        <vers num="1.3.1_01" edition=":solaris" />
        <vers num="1.3.1_01a" edition="" />
        <vers num="1.3.1_01a" edition=":windows" />
        <vers num="1.3.1_02" edition="" />
        <vers num="1.3.1_02" edition=":windows" />
        <vers num="1.3.1_02" edition=":linux" />
        <vers num="1.3.1_02" edition=":solaris" />
        <vers num="1.3.1_03" edition="" />
        <vers num="1.3.1_03" edition=":solaris" />
        <vers num="1.3.1_03" edition=":windows" />
        <vers num="1.3.1_03" edition=":linux" />
        <vers num="1.3.1_04" edition="" />
        <vers num="1.3.1_04" edition=":windows" />
        <vers num="1.3.1_05" edition="" />
        <vers num="1.3.1_05" edition=":linux" />
        <vers num="1.3.1_05" edition=":windows" />
        <vers num="1.3.1_05" edition=":solaris" />
        <vers num="1.3.1_06" edition="" />
        <vers num="1.3.1_06" edition=":windows" />
        <vers num="1.3.1_06" edition=":solaris" />
        <vers num="1.3.1_06" edition=":linux" />
        <vers num="1.3.1_07" edition="" />
        <vers num="1.3.1_07" edition=":windows" />
        <vers num="1.3.1_07" edition=":solaris" />
        <vers num="1.3.1_07" edition=":linux" />
        <vers num="1.4" edition="" />
        <vers num="1.4" edition=":linux" />
        <vers num="1.4" edition=":windows" />
        <vers num="1.4" edition=":solaris" />
        <vers num="1.4.0_01" edition="" />
        <vers num="1.4.0_01" edition=":windows" />
        <vers num="1.4.0_02" edition="" />
        <vers num="1.4.0_02" edition=":linux" />
        <vers num="1.4.0_02" edition=":solaris" />
        <vers num="1.4.0_02" edition=":windows" />
        <vers num="1.4.0_03" edition="" />
        <vers num="1.4.0_03" edition=":linux" />
        <vers num="1.4.0_03" edition=":solaris" />
        <vers num="1.4.0_03" edition=":windows" />
        <vers num="1.4.0_4" edition="" />
        <vers num="1.4.0_4" edition=":solaris" />
        <vers num="1.4.0_4" edition=":windows" />
        <vers num="1.4.0_4" edition=":linux" />
        <vers num="1.4.1" edition="" />
        <vers num="1.4.1" edition=":windows" />
        <vers num="1.4.1" edition=":solaris" />
        <vers num="1.4.1" edition=":linux" />
        <vers num="1.4.1_01" edition="" />
        <vers num="1.4.1_01" edition=":linux" />
        <vers num="1.4.1_01" edition=":solaris" />
        <vers num="1.4.1_01" edition=":windows" />
        <vers num="1.4.1_02" edition="" />
        <vers num="1.4.1_02" edition=":windows" />
        <vers num="1.4.1_02" edition=":linux" />
        <vers num="1.4.1_02" edition=":solaris" />
        <vers num="1.4.1_03" edition="" />
        <vers num="1.4.1_03" edition=":solaris" />
        <vers num="1.4.1_03" edition=":windows" />
        <vers num="1.4.1_03" edition=":linux" />
        <vers num="1.4.2" edition="" />
        <vers num="1.4.2" edition=":solaris" />
        <vers num="1.4.2" edition=":windows" />
        <vers num="1.4.2" edition=":linux" />
        <vers num="1.4.2_01" edition="" />
        <vers num="1.4.2_01" edition=":linux" />
        <vers num="1.4.2_02" edition="" />
        <vers num="1.4.2_02" edition=":linux" />
        <vers num="1.4.2_03" edition="" />
        <vers num="1.4.2_03" edition=":windows" />
        <vers num="1.4.2_03" edition=":linux" />
        <vers num="1.4.2_03" edition=":solaris" />
        <vers num="1.4.2_04" edition="" />
        <vers num="1.4.2_04" edition=":linux" />
        <vers num="1.4.2_04" edition=":solaris" />
        <vers num="1.4.2_04" edition=":windows" />
        <vers num="1.4.2_05" edition="" />
        <vers num="1.4.2_05" edition=":windows" />
        <vers num="1.4.2_05" edition=":linux" />
        <vers num="1.4.2_05" edition=":solaris" />
      </prod>
      <prod vendor="sun" name="jre">
        <vers num="1.3.0" edition="" />
        <vers num="1.3.0" edition=":windows" />
        <vers num="1.3.0" edition=":linux" />
        <vers num="1.3.0" edition=":solaris" />
        <vers num="1.3.0" edition="update1" />
        <vers num="1.3.0" edition="update1:linux" />
        <vers num="1.3.0" edition="update2" />
        <vers num="1.3.0" edition="update2:solaris" />
        <vers num="1.3.0" edition="update2:linux" />
        <vers num="1.3.0" edition="update2:windows" />
        <vers num="1.3.0" edition="update3" />
        <vers num="1.3.0" edition="update3:linux" />
        <vers num="1.3.0" edition="update4" />
        <vers num="1.3.0" edition="update4:windows" />
        <vers num="1.3.0" edition="update4:linux" />
        <vers num="1.3.0" edition="update5" />
        <vers num="1.3.0" edition="update5:linux" />
        <vers num="1.3.0" edition="update5:solaris" />
        <vers num="1.3.0" edition="update5:windows" />
        <vers num="1.3.1" edition="" />
        <vers num="1.3.1" edition=":linux" />
        <vers num="1.3.1" edition="update1" />
        <vers num="1.3.1" edition="update1:linux" />
        <vers num="1.3.1" edition="update1:windows" />
        <vers num="1.3.1" edition="update1:solaris" />
        <vers num="1.3.1" edition="update1a" />
        <vers num="1.3.1" edition="update1a:windows" />
        <vers num="1.3.1" edition="update4" />
        <vers num="1.3.1" edition="update4:windows" />
        <vers num="1.3.1" edition="update4:solaris" />
        <vers num="1.3.1" edition="update8" />
        <vers num="1.3.1" edition="update8:solaris" />
        <vers num="1.3.1" edition="update8:windows" />
        <vers num="1.3.1" edition="update8:linux" />
        <vers num="1.3.1_02" edition="" />
        <vers num="1.3.1_02" edition=":solaris" />
        <vers num="1.3.1_02" edition=":windows" />
        <vers num="1.3.1_02" edition=":linux" />
        <vers num="1.3.1_03" edition="" />
        <vers num="1.3.1_03" edition=":windows" />
        <vers num="1.3.1_03" edition=":solaris" />
        <vers num="1.3.1_03" edition=":linux" />
        <vers num="1.3.1_05" edition="" />
        <vers num="1.3.1_05" edition=":linux" />
        <vers num="1.3.1_05" edition=":windows" />
        <vers num="1.3.1_05" edition=":solaris" />
        <vers num="1.3.1_06" edition="" />
        <vers num="1.3.1_06" edition=":solaris" />
        <vers num="1.3.1_06" edition=":linux" />
        <vers num="1.3.1_06" edition=":windows" />
        <vers num="1.3.1_07" edition="" />
        <vers num="1.3.1_07" edition=":solaris" />
        <vers num="1.3.1_07" edition=":linux" />
        <vers num="1.3.1_07" edition=":windows" />
        <vers num="1.3.1_09" edition="" />
        <vers num="1.3.1_09" edition=":linux" />
        <vers num="1.3.1_09" edition=":solaris" />
        <vers num="1.3.1_09" edition=":windows" />
        <vers num="1.4" edition="" />
        <vers num="1.4" edition=":linux" />
        <vers num="1.4" edition=":solaris" />
        <vers num="1.4" edition=":windows" />
        <vers num="1.4.0_01" edition="" />
        <vers num="1.4.0_01" edition=":solaris" />
        <vers num="1.4.0_01" edition=":windows" />
        <vers num="1.4.0_02" edition="" />
        <vers num="1.4.0_02" edition=":linux" />
        <vers num="1.4.0_02" edition=":windows" />
        <vers num="1.4.0_02" edition=":solaris" />
        <vers num="1.4.0_03" edition="" />
        <vers num="1.4.0_03" edition=":solaris" />
        <vers num="1.4.0_03" edition=":linux" />
        <vers num="1.4.0_03" edition=":windows" />
        <vers num="1.4.0_04" edition="" />
        <vers num="1.4.0_04" edition=":solaris" />
        <vers num="1.4.0_04" edition=":windows" />
        <vers num="1.4.0_04" edition=":linux" />
        <vers num="1.4.1" edition="" />
        <vers num="1.4.1" edition=":linux" />
        <vers num="1.4.1" edition=":windows" />
        <vers num="1.4.1" edition=":solaris" />
        <vers num="1.4.1" edition="update3" />
        <vers num="1.4.1" edition="update3:linux" />
        <vers num="1.4.1" edition="update3:solaris" />
        <vers num="1.4.1" edition="update3:windows" />
        <vers num="1.4.1_01" edition="" />
        <vers num="1.4.1_01" edition=":solaris" />
        <vers num="1.4.1_01" edition=":windows" />
        <vers num="1.4.1_01" edition=":linux" />
        <vers num="1.4.1_02" edition="" />
        <vers num="1.4.1_02" edition=":solaris" />
        <vers num="1.4.1_02" edition=":linux" />
        <vers num="1.4.1_02" edition=":windows" />
        <vers num="1.4.1_07" edition="" />
        <vers num="1.4.1_07" edition=":windows" />
        <vers num="1.4.2" edition="" />
        <vers num="1.4.2" edition=":solaris" />
        <vers num="1.4.2" edition=":linux" />
        <vers num="1.4.2" edition=":windows" />
        <vers num="1.4.2" edition="update1" />
        <vers num="1.4.2" edition="update1:solaris" />
        <vers num="1.4.2" edition="update1:linux" />
        <vers num="1.4.2" edition="update1:windows" />
        <vers num="1.4.2" edition="update2" />
        <vers num="1.4.2" edition="update2:linux" />
        <vers num="1.4.2" edition="update2:solaris" />
        <vers num="1.4.2" edition="update2:windows" />
        <vers num="1.4.2" edition="update3" />
        <vers num="1.4.2" edition="update3:windows" />
        <vers num="1.4.2" edition="update3:linux" />
        <vers num="1.4.2" edition="update3:solaris" />
        <vers num="1.4.2" edition="update4" />
        <vers num="1.4.2" edition="update4:linux" />
        <vers num="1.4.2" edition="update4:solaris" />
        <vers num="1.4.2" edition="update4:windows" />
        <vers num="1.4.2" edition="update5" />
        <vers num="1.4.2" edition="update5:windows" />
        <vers num="1.4.2" edition="update5:linux" />
        <vers num="1.4.2" edition="update5:solaris" />
      </prod>
      <prod vendor="symantec" name="enterprise_firewall">
        <vers num="8.0" edition="" />
        <vers num="8.0" edition=":windows_2000_nt" />
        <vers num="8.0" edition=":solaris" />
      </prod>
      <prod vendor="symantec" name="gateway_security_5400">
        <vers num="2.0" />
        <vers num="2.0.1" />
      </prod>
      <prod vendor="conectiva" name="linux">
        <vers num="10.0" />
      </prod>
      <prod vendor="gentoo" name="linux">
        <vers num="" />
      </prod>
      <prod vendor="hp" name="hp-ux">
        <vers num="11.00" />
        <vers num="11.11" />
        <vers num="11.22" />
        <vers num="11.23" edition="" />
        <vers num="11.23" edition=":ia64_64-bit" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2004-1030" published="2005-03-01" name="CVE-2004-1030" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">fcronsighup in Fcron 2.0.1, 2.9.4, and possibly earlier versions allows local users to gain sensitive information by calling fcronsighup with an arbitrary file, which reveals the contents of the file that can not be parsed in an error message.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/11684" source="BID" patch="1" adv="1">11684</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/18075" source="XF" adv="1">fcron-fcronsighup-obtain-info(18075)</ref>
      <ref url="http://www.idefense.com/application/poi/display?id=157&amp;type=vulnerabilities&amp;flashstatus=false" source="IDEFENSE">20041115 Multiple Security Vulnerabilities in Fcron</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200411-27.xml" source="GENTOO">GLSA-200411-27</ref>
    </refs>
    <vuln_soft>
      <prod vendor="thibault_godouet" name="fcron">
        <vers num="2.0.1" />
        <vers num="2.9.4" />
      </prod>
      <prod vendor="gentoo" name="linux">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-1031" published="2005-03-01" name="CVE-2004-1031" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">fcronsighup in Fcron 2.0.1, 2.9.4, and possibly earlier versions allows local users to bypass access restrictions and load an arbitrary configuration file by starting an suid process and pointing the fcronsighup configuration file to a /proc entry that is owned by root but modifiable by the user, such as /proc/self/cmdline or /proc/self/environ.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/11684" source="BID" patch="1" adv="1">11684</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/18076" source="XF" adv="1">fcron-fcronsighup-restrictions-bypass(18076)</ref>
      <ref url="http://www.idefense.com/application/poi/display?id=157&amp;type=vulnerabilities&amp;flashstatus=false" source="IDEFENSE">20041115 Multiple Security Vulnerabilities in Fcron</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200411-27.xml" source="GENTOO">GLSA-200411-27</ref>
    </refs>
    <vuln_soft>
      <prod vendor="thibault_godouet" name="fcron">
        <vers num="2.0.1" />
        <vers num="2.9.4" />
      </prod>
      <prod vendor="gentoo" name="linux">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2004-1032" published="2005-03-01" name="CVE-2004-1032" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">fcronsighup in Fcron 2.0.1, 2.9.4, and possibly earlier versions allows local users to delete arbitrary files or create arbitrary empty files via a target filename with a large number of leading slash (/) characters such that fcronsighup does not properly append the intended fcrontab.sig to the resulting string.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://security.gentoo.org/glsa/glsa-200411-27.xml" source="GENTOO" patch="1" adv="1">GLSA-200411-27</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/18077" source="XF">fcron-fcronsighup-create-files(18077)</ref>
      <ref url="http://www.idefense.com/application/poi/display?id=157&amp;type=vulnerabilities&amp;flashstatus=false" source="IDEFENSE">20041115 Multiple Security Vulnerabilities in Fcron</ref>
    </refs>
    <vuln_soft>
      <prod vendor="thibault_godouet" name="fcron">
        <vers num="2.0.1" />
        <vers num="2.9.4" />
      </prod>
      <prod vendor="gentoo" name="linux">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2004-1033" published="2005-03-01" name="CVE-2004-1033" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">Fcron 2.0.1, 2.9.4, and possibly earlier versions leak file descriptors of open files, which allows local users to bypass access restrictions and read fcron.allow and fcron.deny via the EDITOR environment variable.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/11684" source="BID" patch="1" adv="1">11684</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/18078" source="XF" adv="1">fcron-fcrontab-obtain-info(18078)</ref>
      <ref url="http://www.idefense.com/application/poi/display?id=157&amp;type=vulnerabilities&amp;flashstatus=false" source="IDEFENSE">20041115 Multiple Security Vulnerabilities in Fcron</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200411-27.xml" source="GENTOO">GLSA-200411-27</ref>
    </refs>
    <vuln_soft>
      <prod vendor="thibault_godouet" name="fcron">
        <vers num="2.0.1" />
        <vers num="2.9.4" />
      </prod>
      <prod vendor="gentoo" name="linux">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-1034" published="2005-03-01" name="CVE-2004-1034" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Buffer overflow in the http_open function in Kaffeine before 0.5, whose code is also used in gxine before 0.3.3, allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a long Content-Type header for a Real Audio Media (.ram) playlist file.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/11528" source="BID" patch="1" adv="1">11528</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/17849" source="XF" adv="1">kaffeine-ram-bo(17849)</ref>
      <ref url="http://sourceforge.net/tracker/index.php?func=detail&amp;aid=1060299&amp;group_id=9655&amp;atid=109655" source="CONFIRM">http://sourceforge.net/tracker/index.php?func=detail&amp;aid=1060299&amp;group_id=9655&amp;atid=109655</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200411-14.xml" source="GENTOO">GLSA-200411-14</ref>
      <ref url="http://secunia.com/advisories/13117/" source="SECUNIA">13117</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2004-October/028061.html" source="FULLDISC">20041025 Kaffeine Media Player Conteny Type overflow</ref>
    </refs>
    <vuln_soft>
      <prod vendor="kaffeine" name="kaffeine_player">
        <vers num="0.4.2" />
        <vers num="0.4.3" />
        <vers num="0.4.3b" />
        <vers num="0.5_rc1" />
      </prod>
      <prod vendor="xine" name="gxine">
        <vers num="0.3" />
      </prod>
      <prod vendor="gentoo" name="linux">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1035" published="2005-03-01" name="CVE-2004-1035" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:P)" CVSS_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_base_score="6.4">
    <desc>
      <descript source="cve">Multiple integer signedness errors in (1) imapcommon.c, (2) main.c, (3) request.c, and (4) select.c for up-imapproxy IMAP proxy 1.2.2 allow remote attackers to cause a denial of service (server crash) and possibly leak sensitive information via certain literal values that are not properly handled when using the IMAP_Line_Read function.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/17999" source="XF" adv="1">upimapproxy-dos(17999)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109995749510773&amp;w=2" source="BUGTRAQ">20041107 up-imapproxy DoS vulnerabilities</ref>
    </refs>
    <vuln_soft>
      <prod vendor="imap_proxy" name="imap_proxy">
        <vers num="1.2.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1036" published="2005-03-01" name="CVE-2004-1036" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in the decoding of encoded text in certain headers in mime.php for SquirrelMail 1.4.3a and earlier, and 1.5.1-cvs before 23rd October 2004, allows remote attackers to execute arbitrary web script or HTML.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200411-25.xml" source="GENTOO" patch="1" adv="1">GLSA-200411-25</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110012133608004&amp;w=2" source="BUGTRAQ" patch="1">20041110 [SquirrelMail Security Advisory] Cross Site Scripting in encoded text</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/18031" source="XF">squirrelmail-mime-xss(18031)</ref>
      <ref url="http://www.squirrelmail.org/" source="CONFIRM">http://www.squirrelmail.org/</ref>
      <ref url="http://voxel.dl.sourceforge.net/sourceforge/squirrelmail/sm143a-xss.diff" source="CONFIRM">http://voxel.dl.sourceforge.net/sourceforge/squirrelmail/sm143a-xss.diff</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9592" source="OVAL">oval:org.mitre.oval:def:9592</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2005/Mar/msg00000.html" source="APPLE" adv="1">APPLE-SA-2005-03-21</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2005/Jan/msg00001.html" source="APPLE" adv="1">APPLE-SA-2005-01-25</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000905" source="CONECTIVA">CLA-2004:905</ref>
    </refs>
    <vuln_soft>
      <prod vendor="squirrelmail" name="squirrelmail">
        <vers num="1.0.4" />
        <vers num="1.0.5" />
        <vers num="1.2" />
        <vers num="1.2.1" />
        <vers num="1.2.10" />
        <vers num="1.2.11" />
        <vers num="1.2.2" />
        <vers num="1.2.3" />
        <vers num="1.2.4" />
        <vers num="1.2.5" />
        <vers num="1.2.6" />
        <vers num="1.2.7" />
        <vers num="1.2.8" />
        <vers num="1.2.9" />
        <vers num="1.4" />
        <vers num="1.4.1" />
        <vers num="1.4.2" />
        <vers num="1.4.3" />
        <vers num="1.4.3_rc1" />
        <vers num="1.4.3a" />
        <vers num="1.5_dev" />
      </prod>
      <prod vendor="gentoo" name="linux">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-1037" published="2005-03-01" name="CVE-2004-1037" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">The search function in TWiki 20030201 allows remote attackers to execute arbitrary commands via shell metacharacters in a search string.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" admin="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/11674" source="BID" patch="1" adv="1">11674</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/18062" source="XF" adv="1">twik-search-command-execution(18062)</ref>
      <ref url="http://www.ciac.org/ciac/bulletins/p-039.shtml" source="CIAC">P-039</ref>
      <ref url="http://twiki.org/cgi-bin/view/Codev/SecurityAlertExecuteCommandsWithSearch" source="CONFIRM">http://twiki.org/cgi-bin/view/Codev/SecurityAlertExecuteCommandsWithSearch</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200411-33.xml" source="GENTOO">GLSA-200411-33</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2004-11/0201.html" source="FULLDISC">20041116 Re: [Full-Disclosure] TWiki search function allows arbitrary shell command execution</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110037207516456&amp;w=2" source="BUGTRAQ">20041112 TWiki search function allows arbitrary shell command execution</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000918" source="CONECTIVA">CLA-2005:918</ref>
    </refs>
    <vuln_soft>
      <prod vendor="twiki" name="twiki">
        <vers num="2003-02-01" />
      </prod>
      <prod vendor="gentoo" name="linux">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-1038" published="2005-03-01" name="CVE-2004-1038" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">A design error in the IEEE1394 specification allows attackers with physical access to a device to read and write to sensitive memory using a modified FireWire/IEEE 1394 client, thus bypassing intended restrictions that would normally require greater degrees of physical access to exploit.  NOTE: this was reported in 2008 to affect Windows Vista, but some Linux-based operating systems have protection mechanisms against this attack.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" admin="1" />
    </loss_types>
    <vuln_types>
      <access />
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/18041" source="XF">firewire-ieee1394-interface-installed(18041)</ref>
      <ref url="http://www.theage.com.au/news/security/hack-into-a-windows-pc-no-password-needed/2008/03/04/1204402423638.html" source="MISC">http://www.theage.com.au/news/security/hack-into-a-windows-pc-no-password-needed/2008/03/04/1204402423638.html</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/489342/100/0/threaded" source="BUGTRAQ">20080310 Re: [Full-disclosure] Firewire Attack on Windows Vista</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/489335/100/0/threaded" source="BUGTRAQ">20080309 Re: Firewire Attack on Windows Vista</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/489330/100/0/threaded" source="BUGTRAQ">20080310 RE: [Full-disclosure] Firewire Attack on Windows Vista</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/489322/100/0/threaded" source="BUGTRAQ">20080309 Re: [Full-disclosure] Firewire Attack on Windows Vista</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/489189/100/0/threaded" source="BUGTRAQ">20080305 RE: Firewire Attack on Windows Vista</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/489175/100/0/threaded" source="BUGTRAQ">20080305 Re: Firewire Attack on Windows Vista</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/489163/100/0/threaded" source="BUGTRAQ">20080305 Firewire Attack on Windows Vista</ref>
      <ref url="http://www.sec-consult.com/fileadmin/Whitepapers/Vista_Physical_Attacks.pdf" source="MISC">http://www.sec-consult.com/fileadmin/Whitepapers/Vista_Physical_Attacks.pdf</ref>
      <ref url="http://storm.net.nz/static/files/ab_firewire_rux2k6-final.pdf" source="MISC">http://storm.net.nz/static/files/ab_firewire_rux2k6-final.pdf</ref>
      <ref url="http://storm.net.nz/projects/16" source="MISC">http://storm.net.nz/projects/16</ref>
      <ref url="http://pacsec.jp/advisories.html" source="MISC">http://pacsec.jp/advisories.html</ref>
      <ref url="http://md.hudora.de/presentations/firewire/2005-firewire-cansecwest.pdf" source="MISC">http://md.hudora.de/presentations/firewire/2005-firewire-cansecwest.pdf</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109881362530790&amp;w=2" source="BUGTRAQ">20041026 pacsec.jp advisory: Firewire/IEEE 1394 Considered Harmful to Physical Security</ref>
      <ref url="http://it.slashdot.org/article.pl?sid=08/03/04/1258210" source="MISC">http://it.slashdot.org/article.pl?sid=08/03/04/1258210</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/489296/100/0/threaded" source="BUGTRAQ">20080308 RE: [Full-disclosure] Firewire Attack on Windows Vista</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/489295/100/0/threaded" source="BUGTRAQ">20080308 Re: [Full-disclosure] Firewire Attack on Windows Vista</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/489269/100/0/threaded" source="BUGTRAQ">20080307 Re: Firewire Attack on Windows Vista</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/489257/100/0/threaded" source="BUGTRAQ">20080306 RE: Firewire Attack on Windows Vista</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/489212/100/0/threaded" source="BUGTRAQ">20080306 Re: Firewire Attack on Windows Vista</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ieee" name="firewire_ieee">
        <vers num="1394" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1039" published="2005-01-11" name="CVE-2004-1039" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The NFS mountd service on SCO UnixWare 7.1.1, 7.1.3, 7.1.4, and 7.0.1, and possibly other versions, when run from inetd, allows remote attackers to cause a denial of service (memory exhaustion) via a series of requests, which causes inetd to launch a separate process for each request.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/386814" source="BUGTRAQ" patch="1" adv="1">20050111 [NILESA-20050101]: Denial of Service vulnerability due to the mountd bug</ref>
      <ref url="ftp://ftp.sco.com/pub/updates/UnixWare/SCOSA-2005.1/SCOSA-2005.1.txt" source="SCO" patch="1" adv="1">SCOSA-2005.1</ref>
      <ref url="http://www.securityfocus.com/bid/12225" source="BID">12225</ref>
      <ref url="http://secunia.com/advisories/13805" source="SECUNIA">13805</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sco" name="openserver">
        <vers num="5.0.6" />
        <vers num="5.0.7" />
      </prod>
      <prod vendor="sco" name="unixware">
        <vers num="7.1.1" />
        <vers num="7.1.3" />
        <vers num="7.1.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1043" published="2004-12-31" name="CVE-2004-1043" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Internet Explorer 6.0 on Windows XP SP2 allows remote attackers to execute arbitrary code by using the "Related Topics" command in the Help ActiveX Control (hhctrl.ocx) to open a Help popup window containing the PCHealth tools.htm file in the local zone and injecting Javascript to be executed, as demonstrated using "writehta.txt" and the ADODB recordset, which saves a .HTA file to the local system, aka the "HTML Help ActiveX control Cross Domain Vulnerability."</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA05-012B.html" source="CERT" adv="1">TA05-012B</ref>
      <ref url="http://www.kb.cert.org/vuls/id/972415" source="CERT-VN" adv="1">VU#972415</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/18311" source="XF">ie-helpactivexcontrol-save-file(18311)</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms05-001.mspx" source="MS" adv="1">MS05-001</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2004-12/0426.html" source="BUGTRAQ">20041225 Microsoft Internet Explorer SP2 Fully Automated Remote Compromise</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:3496" source="OVAL" sig="1">oval:org.mitre.oval:def:3496</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2830" source="OVAL" sig="1">oval:org.mitre.oval:def:2830</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1963" source="OVAL" sig="1">oval:org.mitre.oval:def:1963</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1349" source="OVAL" sig="1">oval:org.mitre.oval:def:1349</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="ie">
        <vers num="6.0" />
      </prod>
      <prod vendor="microsoft" name="windows_xp">
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:tablet_pc" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1049" published="2004-12-31" name="CVE-2004-1049" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_score="5.1" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="4.9" CVSS_base_score="5.1">
    <desc>
      <descript source="cve">Integer overflow in the LoadImage API of the USER32 Lib for Microsoft Windows allows remote attackers to execute arbitrary code via a .bmp, .cur, .ico or .ani file with a large image size field, which leads to a buffer overflow, aka the "Cursor and Icon Format Handling Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA05-012A.html" source="CERT" adv="1">TA05-012A</ref>
      <ref url="http://www.kb.cert.org/vuls/id/625856" source="CERT-VN" adv="1">VU#625856</ref>
      <ref url="http://www.xfocus.net/flashsky/icoExp/index.html" source="MISC">http://www.xfocus.net/flashsky/icoExp/index.html</ref>
      <ref url="http://www.microsoft.com/technet/Security/bulletin/ms05-002.mspx" source="MS" adv="1">MS05-002</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110382891718076&amp;w=2" source="BUGTRAQ">20041223 Microsoft Windows LoadImage API Integer Buffer overflow </ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/18668" source="XF">win-loadimage-bo(18668)</ref>
      <ref url="http://www.securityfocus.com/bid/12095" source="BID">12095</ref>
      <ref url="http://www.osvdb.org/12623" source="OSVDB">12623</ref>
      <ref url="http://www.ciac.org/ciac/bulletins/p-094.shtml" source="CIAC">P-094</ref>
      <ref url="http://securitytracker.com/id?1012684" source="SECTRACK">1012684</ref>
      <ref url="http://secunia.com/advisories/13645" source="SECUNIA">13645</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:4671" source="OVAL" sig="1">oval:org.mitre.oval:def:4671</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:3355" source="OVAL" sig="1">oval:org.mitre.oval:def:3355</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:3220" source="OVAL" sig="1">oval:org.mitre.oval:def:3220</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:3097" source="OVAL" sig="1">oval:org.mitre.oval:def:3097</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2956" source="OVAL" sig="1">oval:org.mitre.oval:def:2956</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_2000">
        <vers num="" edition="sp1" />
        <vers num="" edition="sp2" />
        <vers num="" edition="sp3" />
        <vers num="" edition="sp4" />
        <vers num="" edition="sp4:" />
        <vers num="" edition="sp4::fr" />
      </prod>
      <prod vendor="microsoft" name="windows_2003_server">
        <vers num="r2" />
      </prod>
      <prod vendor="microsoft" name="windows_nt">
        <vers num="" />
      </prod>
      <prod vendor="microsoft" name="windows_xp">
        <vers num="" edition="gold" />
        <vers num="" edition="sp1" />
        <vers num="" edition="sp1:tablet_pc" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-1050" published="2004-12-31" name="CVE-2004-1050" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Heap-based buffer overflow in Internet Explorer 6 allows remote attackers to execute arbitrary code via long (1) SRC or (2) NAME attributes in IFRAME, FRAME, and EMBED elements, as originally discovered using the mangleme utility, aka "the IFRAME vulnerability" or the "HTML Elements Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA04-336A.html" source="CERT">TA04-336A</ref>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA04-315A.html" source="CERT">TA04-315A</ref>
      <ref url="http://www.kb.cert.org/vuls/id/842160" source="CERT-VN" adv="1">VU#842160</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/17889" source="XF" adv="1">ie-iframe-src-name-bo(17889)</ref>
      <ref url="http://www.securityfocus.com/bid/11515" source="BID">11515</ref>
      <ref url="http://www.securityfocus.com/archive/1/379261" source="BUGTRAQ">20041024 python does mangleme (with IE bugs!)</ref>
      <ref url="http://www.microsoft.com/technet/security/Bulletin/MS04-040.mspx" source="MS">MS04-040</ref>
      <ref url="http://secunia.com/advisories/12959/" source="SECUNIA">12959</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109942758911846&amp;w=2" source="BUGTRAQ">20041102 MSIE &lt;IFRAME> and &lt;FRAME> tag NAME property bufferoverflow PoC</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2004-October/028035.html" source="FULLDISC">20041025 python does mangleme (with IE bugs!)</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2004-October/028009.html" source="FULLDISC">20041023 python does mangleme (with IE bugs!)</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1294" source="OVAL" sig="1">oval:org.mitre.oval:def:1294</ref>
    </refs>
    <vuln_soft>
      <prod vendor="avaya" name="ip600_media_servers">
        <vers num="r10" />
        <vers num="r11" />
        <vers num="r12" />
        <vers num="r6" />
        <vers num="r7" />
        <vers num="r8" />
        <vers num="r9" />
      </prod>
      <prod vendor="microsoft" name="ie">
        <vers num="6.0" edition="sp1" />
      </prod>
      <prod vendor="avaya" name="definity_one_media_server">
        <vers num="r10" />
        <vers num="r11" />
        <vers num="r12" />
        <vers num="r6" />
        <vers num="r7" />
        <vers num="r8" />
        <vers num="r9" />
      </prod>
      <prod vendor="avaya" name="s3400">
        <vers num="" />
      </prod>
      <prod vendor="avaya" name="s8100">
        <vers num="r10" />
        <vers num="r11" />
        <vers num="r12" />
        <vers num="r6" />
        <vers num="r7" />
        <vers num="r8" />
        <vers num="r9" />
      </prod>
      <prod vendor="avaya" name="modular_messaging_message_storage_server">
        <vers num="s3400" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-1051" published="2005-03-01" name="CVE-2004-1051" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">sudo before 1.6.8p2 allows local users to execute arbitrary commands by using "()" style environment variables to create functions that have the same name as any program within the bash script that is called without using the program's full pathname.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" admin="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/11668" source="BID" patch="1" adv="1">11668</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/18055" source="XF" adv="1">sudo-bash-command-execution(18055)</ref>
      <ref url="http://www.trustix.org/errata/2004/0061/" source="TRUSTIX">2004-0061</ref>
      <ref url="http://www.sudo.ws/sudo/alerts/bash_functions.html" source="CONFIRM">http://www.sudo.ws/sudo/alerts/bash_functions.html</ref>
      <ref url="http://www.debian.org/security/2004/dsa-596" source="DEBIAN">DSA-596</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2005/May/msg00001.html" source="APPLE">APPLE-SA-2005-05-03</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2004:133" source="MANDRAKE">MDKSA-2004:133</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110598298225675&amp;w=2" source="OPENPKG">OpenPKG-SA-2005.002</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110073149111410&amp;w=2" source="UBUNTU">USN-28-1</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110028877431192&amp;w=2" source="BUGTRAQ">20041112 Sudo version 1.6.8p2 now available (fwd)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mandrakesoft" name="mandrake_multi_network_firewall">
        <vers num="8.2" />
      </prod>
      <prod vendor="todd_miller" name="sudo">
        <vers num="1.5.6" />
        <vers num="1.5.7" />
        <vers num="1.5.8" />
        <vers num="1.5.9" />
        <vers num="1.6" />
        <vers num="1.6.1" />
        <vers num="1.6.2" />
        <vers num="1.6.3" />
        <vers num="1.6.3_p1" />
        <vers num="1.6.3_p2" />
        <vers num="1.6.3_p3" />
        <vers num="1.6.3_p4" />
        <vers num="1.6.3_p5" />
        <vers num="1.6.3_p6" />
        <vers num="1.6.3_p7" />
        <vers num="1.6.4" />
        <vers num="1.6.4_p1" />
        <vers num="1.6.4_p2" />
        <vers num="1.6.5" />
        <vers num="1.6.5_p1" />
        <vers num="1.6.5_p2" />
        <vers num="1.6.6" />
        <vers num="1.6.7" />
        <vers num="1.6.8" />
        <vers num="1.6.8_p1" />
      </prod>
      <prod vendor="debian" name="debian_linux">
        <vers num="3.0" edition="" />
        <vers num="3.0" edition=":mips" />
        <vers num="3.0" edition=":s-390" />
        <vers num="3.0" edition=":alpha" />
        <vers num="3.0" edition=":mipsel" />
        <vers num="3.0" edition=":hppa" />
        <vers num="3.0" edition=":ia-32" />
        <vers num="3.0" edition=":arm" />
        <vers num="3.0" edition=":ppc" />
        <vers num="3.0" edition=":m68k" />
        <vers num="3.0" edition=":ia-64" />
        <vers num="3.0" edition=":sparc" />
      </prod>
      <prod vendor="mandrakesoft" name="mandrake_linux">
        <vers num="10.0" edition="" />
        <vers num="10.0" edition=":amd64" />
        <vers num="10.1" edition="" />
        <vers num="10.1" edition=":x86_64" />
        <vers num="9.2" edition="" />
        <vers num="9.2" edition=":amd64" />
      </prod>
      <prod vendor="mandrakesoft" name="mandrake_linux_corporate_server">
        <vers num="2.1" edition="" />
        <vers num="2.1" edition=":x86_64" />
      </prod>
      <prod vendor="trustix" name="secure_linux">
        <vers num="1.5" />
        <vers num="2.0" />
        <vers num="2.1" />
        <vers num="2.2" />
      </prod>
      <prod vendor="ubuntu" name="ubuntu_linux">
        <vers num="4.1" edition="" />
        <vers num="4.1" edition=":ia64" />
        <vers num="4.1" edition=":ppc" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-1052" published="2005-03-01" name="CVE-2004-1052" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Buffer overflow in the getnickuserhost function in BNC 2.8.9, and possibly other versions, allows remote IRC servers to execute arbitrary code via an IRC server response that contains many (1) ! (exclamation) or (2) @ (at sign) characters.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/11647" source="BID" patch="1" adv="1">11647</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/18013" source="XF" adv="1">bnc-irc-getnickuserhost-bo(18013)</ref>
      <ref url="http://www.debian.org/security/2004/dsa-595" source="DEBIAN">DSA-595</ref>
      <ref url="http://secunia.com/advisories/13149/" source="SECUNIA">13149</ref>
      <ref url="http://security.lss.hr/en/index.php?page=details&amp;ID=LSS-2004-11-03" source="MISC">http://security.lss.hr/en/index.php?page=details&amp;ID=LSS-2004-11-03</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110011817627839&amp;w=2" source="BUGTRAQ">20041110 BNC 2.8.9 remote buffer overflow</ref>
    </refs>
    <vuln_soft>
      <prod vendor="bnc" name="bnc">
        <vers num="2.2.4" />
        <vers num="2.4.6" />
        <vers num="2.4.8" />
        <vers num="2.6" />
        <vers num="2.6.2" />
        <vers num="2.6.4" />
        <vers num="2.8.8" />
        <vers num="2.8.9" />
      </prod>
      <prod vendor="debian" name="debian_linux">
        <vers num="3.0" edition="" />
        <vers num="3.0" edition=":hppa" />
        <vers num="3.0" edition=":mips" />
        <vers num="3.0" edition=":ia-32" />
        <vers num="3.0" edition=":m68k" />
        <vers num="3.0" edition=":s-390" />
        <vers num="3.0" edition=":alpha" />
        <vers num="3.0" edition=":arm" />
        <vers num="3.0" edition=":ia-64" />
        <vers num="3.0" edition=":mipsel" />
        <vers num="3.0" edition=":sparc" />
        <vers num="3.0" edition=":ppc" />
      </prod>
      <prod vendor="gentoo" name="linux">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-1053" published="2005-03-01" name="CVE-2004-1053" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Integer overflow in fetch on FreeBSD 4.1 through 5.3 allows remote malicious servers to execute arbitrary code via certain HTTP headers in an HTTP response, which lead to a buffer overflow.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/11702" source="BID" patch="1" adv="1">11702</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/18160" source="XF" adv="1">fetch-http-header-bo(18160)</ref>
      <ref url="ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-04:16.fetch.asc" source="FREEBSD">FreeBSD-SA-04:16</ref>
    </refs>
    <vuln_soft>
      <prod vendor="freebsd" name="fetch">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-1054" published="2005-01-10" name="CVE-2004-1054" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Untrusted execution path vulnerability in invscout in IBM AIX 5.1.0, 5.2.0, and 5.3.0 allows local users to gain privileges by modifying the PATH environment variable to point to a malicious "uname" program, which is executed from lsvpd after lsvpd has been invoked by invscout.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" admin="1" />
    </loss_types>
    <vuln_types>
      <access />
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/18619" source="XF">aix-invscout-gain-privileges(18619)</ref>
      <ref url="http://www.idefense.com/application/poi/display?id=171&amp;type=vulnerabilities" source="IDEFENSE" adv="1">20041220 IBM AIX invscout Local Command Execution Vulnerability</ref>
      <ref url="http://www-1.ibm.com/support/search.wss?rs=0&amp;q=IY64976&amp;apar=only" source="AIXAPAR">IY64976</ref>
      <ref url="http://www-1.ibm.com/support/search.wss?rs=0&amp;q=IY64852&amp;apar=only" source="AIXAPAR">IY64852</ref>
      <ref url="http://www-1.ibm.com/support/search.wss?rs=0&amp;q=IY64820&amp;apar=only" source="AIXAPAR">IY64820</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="aix">
        <vers num="5.1" />
        <vers num="5.1l" />
        <vers num="5.2" />
        <vers num="5.2.2" />
        <vers num="5.2_l" />
        <vers num="5.3" />
        <vers num="5.3_l" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1055" published="2005-03-01" name="CVE-2004-1055" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin 2.6.0-pl2 and earlier allow remote attackers to inject arbitrary web script or HTML via (1) the PmaAbsoluteUri parameter, (2) the zero_rows parameter in read_dump.php, (3) the confirm form, or (4) an error message generated by the internal phpMyAdmin parser.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/18158" source="XF">phpmyadmin-multiple-xss(18158)</ref>
      <ref url="http://www.phpmyadmin.net/home_page/security.php?issue=PMASA-2004-3" source="CONFIRM">http://www.phpmyadmin.net/home_page/security.php?issue=PMASA-2004-3</ref>
      <ref url="http://www.netvigilance.com/html/advisory0005.htm" source="MISC" adv="1">http://www.netvigilance.com/html/advisory0005.htm</ref>
    </refs>
    <vuln_soft>
      <prod vendor="phpmyadmin" name="phpmyadmin">
        <vers num="2.5.0" />
        <vers num="2.5.1" />
        <vers num="2.5.2" />
        <vers num="2.5.4" />
        <vers num="2.5.5" />
        <vers num="2.5.5_pl1" />
        <vers num="2.5.5_rc1" />
        <vers num="2.5.5_rc2" />
        <vers num="2.5.6_rc1" />
        <vers num="2.5.7" />
        <vers num="2.5.7_pl1" />
        <vers num="2.6.0_pl1" />
        <vers num="2.6.0_pl2" />
      </prod>
      <prod vendor="gentoo" name="linux">
        <vers num="1.4" edition="rc1" />
        <vers num="1.4" edition="rc2" />
        <vers num="1.4" edition="rc3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1056" published="2005-01-10" name="CVE-2004-1056" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:P)" CVSS_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_base_score="6.4">
    <desc>
      <descript source="cve">Direct Rendering Manager (DRM) driver in Linux kernel 2.6 does not properly check the DMA lock, which could allow remote attackers or local users to cause a denial of service (X Server crash) and possibly modify the video output.</descript>
    </desc>
    <loss_types>
      <avail />
      <int />
    </loss_types>
    <vuln_types>
      <access />
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="https://bugzilla.fedora.us/show_bug.cgi?id=2336" source="FEDORA">FLSA:2336</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15972" source="XF">linux-i810-dma-dos(15972)</ref>
      <ref url="http://www.vupen.com/english/advisories/2005/1878" source="VUPEN">ADV-2005-1878</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-092.html" source="REDHAT">RHSA-2005:092</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9795" source="OVAL">oval:org.mitre.oval:def:9795</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110306397320336&amp;w=2" source="UBUNTU" adv="1">USN-38-1</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-663.html" source="REDHAT">RHSA-2005:663</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-551.html" source="REDHAT">RHSA-2005:551</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-529.html" source="REDHAT">RHSA-2005:529</ref>
      <ref url="http://secunia.com/advisories/17002" source="SECUNIA">17002</ref>
    </refs>
    <vuln_soft>
      <prod vendor="linux" name="linux_kernel">
        <vers num="2.6.0" edition="test1" />
        <vers num="2.6.0" edition="test10" />
        <vers num="2.6.0" edition="test11" />
        <vers num="2.6.0" edition="test2" />
        <vers num="2.6.0" edition="test3" />
        <vers num="2.6.0" edition="test4" />
        <vers num="2.6.0" edition="test5" />
        <vers num="2.6.0" edition="test6" />
        <vers num="2.6.0" edition="test7" />
        <vers num="2.6.0" edition="test8" />
        <vers num="2.6.0" edition="test9" />
        <vers num="2.6.1" edition="rc1" />
        <vers num="2.6.1" edition="rc2" />
        <vers num="2.6.10" edition="rc2" />
        <vers num="2.6.2" />
        <vers num="2.6.3" />
        <vers num="2.6.4" />
        <vers num="2.6.5" />
        <vers num="2.6.6" edition="rc1" />
        <vers num="2.6.7" edition="rc1" />
        <vers num="2.6.8" edition="rc1" />
        <vers num="2.6.8" edition="rc2" />
        <vers num="2.6.8" edition="rc3" />
        <vers num="2.6.9" edition="2.6.20" />
        <vers num="2.6_test9_cvs" />
      </prod>
      <prod vendor="ubuntu" name="ubuntu_linux">
        <vers num="4.1" edition="" />
        <vers num="4.1" edition=":ia64" />
        <vers num="4.1" edition=":ppc" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-1057" published="2005-01-21" name="CVE-2004-1057" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Multiple drivers in Linux kernel 2.4.19 and earlier do not properly mark memory with the VM_IO flag, which causes incorrect reference counts and may lead to a denial of service (kernel panic) when accessing freed kernel pages.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <design />
      <env />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=137821" source="CONFIRM" patch="1" adv="1">https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=137821</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/19275" source="XF" patch="1" adv="1">linux-kernel-vmio-dos(19275)</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-016.html" source="REDHAT" patch="1" adv="1">RHSA-2005:016</ref>
      <ref url="http://www.securityfocus.com/bid/12338" source="BID">12338</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2006-0140.html" source="REDHAT">RHSA-2006:0140</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-017.html" source="REDHAT">RHSA-2005:017</ref>
      <ref url="http://www.kernel.org/pub/linux/kernel/people/andrea/kernels/v2.4/2.4.23aa3/00_VM_IO-4" source="MISC">http://www.kernel.org/pub/linux/kernel/people/andrea/kernels/v2.4/2.4.23aa3/00_VM_IO-4</ref>
      <ref url="http://secunia.com/advisories/18562" source="SECUNIA">18562</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11474" source="OVAL">oval:org.mitre.oval:def:11474</ref>
    </refs>
    <vuln_soft>
      <prod vendor="linux" name="linux_kernel">
        <vers num="2.0" />
        <vers num="2.0.1" />
        <vers num="2.0.10" />
        <vers num="2.0.11" />
        <vers num="2.0.12" />
        <vers num="2.0.13" />
        <vers num="2.0.14" />
        <vers num="2.0.15" />
        <vers num="2.0.16" />
        <vers num="2.0.17" />
        <vers num="2.0.18" />
        <vers num="2.0.19" />
        <vers num="2.0.2" />
        <vers num="2.0.20" />
        <vers num="2.0.21" />
        <vers num="2.0.22" />
        <vers num="2.0.23" />
        <vers num="2.0.24" />
        <vers num="2.0.25" />
        <vers num="2.0.26" />
        <vers num="2.0.27" />
        <vers num="2.0.28" />
        <vers num="2.0.29" />
        <vers num="2.0.3" />
        <vers num="2.0.30" />
        <vers num="2.0.31" />
        <vers num="2.0.32" />
        <vers num="2.0.33" />
        <vers num="2.0.34" />
        <vers num="2.0.35" />
        <vers num="2.0.36" />
        <vers num="2.0.37" />
        <vers num="2.0.38" />
        <vers num="2.0.39" />
        <vers num="2.0.4" />
        <vers num="2.0.5" />
        <vers num="2.0.6" />
        <vers num="2.0.7" />
        <vers num="2.0.8" />
        <vers num="2.0.9" />
        <vers num="2.0.9.9" />
        <vers num="2.1" />
        <vers num="2.1.89" />
        <vers num="2.2.0" />
        <vers num="2.2.1" />
        <vers num="2.2.10" />
        <vers num="2.2.11" />
        <vers num="2.2.12" />
        <vers num="2.2.13" />
        <vers num="2.2.14" />
        <vers num="2.2.15" edition="pre16" />
        <vers num="2.2.15_pre20" />
        <vers num="2.2.16" edition="pre6" />
        <vers num="2.2.17" />
        <vers num="2.2.18" />
        <vers num="2.2.19" />
        <vers num="2.2.2" />
        <vers num="2.2.20" />
        <vers num="2.2.21" />
        <vers num="2.2.22" />
        <vers num="2.2.23" />
        <vers num="2.2.24" />
        <vers num="2.2.25" />
        <vers num="2.2.27" edition="rc2" />
        <vers num="2.2.3" />
        <vers num="2.2.4" />
        <vers num="2.2.5" />
        <vers num="2.2.6" />
        <vers num="2.2.7" />
        <vers num="2.2.8" />
        <vers num="2.2.9" />
        <vers num="2.3.0" />
        <vers num="2.3.99" edition="pre1" />
        <vers num="2.3.99" edition="pre2" />
        <vers num="2.3.99" edition="pre3" />
        <vers num="2.3.99" edition="pre4" />
        <vers num="2.3.99" edition="pre5" />
        <vers num="2.3.99" edition="pre6" />
        <vers num="2.3.99" edition="pre7" />
        <vers num="2.4.0" edition="test1" />
        <vers num="2.4.0" edition="test10" />
        <vers num="2.4.0" edition="test11" />
        <vers num="2.4.0" edition="test12" />
        <vers num="2.4.0" edition="test2" />
        <vers num="2.4.0" edition="test3" />
        <vers num="2.4.0" edition="test4" />
        <vers num="2.4.0" edition="test5" />
        <vers num="2.4.0" edition="test6" />
        <vers num="2.4.0" edition="test7" />
        <vers num="2.4.0" edition="test8" />
        <vers num="2.4.0" edition="test9" />
        <vers num="2.4.1" />
        <vers num="2.4.10" />
        <vers num="2.4.11" />
        <vers num="2.4.12" />
        <vers num="2.4.13" />
        <vers num="2.4.14" />
        <vers num="2.4.15" />
        <vers num="2.4.16" />
        <vers num="2.4.17" />
        <vers num="2.4.18" edition="" />
        <vers num="2.4.18" edition=":x86" />
        <vers num="2.4.18" edition="pre1" />
        <vers num="2.4.18" edition="pre2" />
        <vers num="2.4.18" edition="pre3" />
        <vers num="2.4.18" edition="pre4" />
        <vers num="2.4.18" edition="pre5" />
        <vers num="2.4.18" edition="pre6" />
        <vers num="2.4.18" edition="pre7" />
        <vers num="2.4.18" edition="pre8" />
        <vers prev="1" num="2.4.19" edition="pre1" />
        <vers prev="1" num="2.4.19" edition="pre2" />
        <vers prev="1" num="2.4.19" edition="pre3" />
        <vers prev="1" num="2.4.19" edition="pre4" />
        <vers prev="1" num="2.4.19" edition="pre5" />
        <vers prev="1" num="2.4.19" edition="pre6" />
        <vers num="2.6.20.1" />
      </prod>
      <prod vendor="redhat" name="enterprise_linux">
        <vers num="2.1" edition="" />
        <vers num="2.1" edition=":workstation_ia64" />
        <vers num="2.1" edition=":advanced_server" />
        <vers num="2.1" edition=":advanced_server_ia64" />
        <vers num="2.1" edition=":workstation" />
        <vers num="2.1" edition=":enterprise_server" />
        <vers num="2.1" edition=":enterprise_server_ia64" />
        <vers num="3.0" edition="" />
        <vers num="3.0" edition=":workstation" />
        <vers num="3.0" edition=":advanced_servers" />
        <vers num="3.0" edition=":enterprise_server" />
        <vers num="4.0" edition="" />
        <vers num="4.0" edition=":workstation" />
        <vers num="4.0" edition=":enterprise_server" />
        <vers num="4.0" edition=":advanced_server" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2004-1058" published="2005-01-10" name="CVE-2004-1058" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:H/Au:N/C:P/I:N/A:N)" CVSS_score="1.2" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="1.9" CVSS_base_score="1.2">
    <desc>
      <descript source="cve">Race condition in Linux kernel 2.6 allows local users to read the environment variables of another process that is still spawning via /proc/.../cmdline.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <race />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/11937" source="BID" patch="1" adv="1">11937</ref>
      <ref url="https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=152532" source="FEDORA">FLSA:152532</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/17151" source="XF">linux-spawning-race-condition(17151)</ref>
      <ref url="http://www.ubuntulinux.org/support/documentation/usn/usn-38-1" source="UBUNTU">USN-38-1</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200408-24.xml" source="GENTOO">GLSA-200408-24</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10427" source="OVAL">oval:org.mitre.oval:def:10427</ref>
      <ref url="http://www.securityfocus.com/bid/11052" source="BID">11052</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2006-0191.html" source="REDHAT">RHSA-2006:0191</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2006-0190.html" source="REDHAT">RHSA-2006:0190</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-293.html" source="REDHAT">RHSA-2005:293</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:022" source="MANDRAKE">MDKSA-2005:022</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1018" source="DEBIAN">DSA-1018</ref>
      <ref url="http://secunia.com/advisories/21476" source="SECUNIA">21476</ref>
      <ref url="http://secunia.com/advisories/19607" source="SECUNIA">19607</ref>
      <ref url="http://secunia.com/advisories/19369" source="SECUNIA">19369</ref>
      <ref url="http://secunia.com/advisories/19038" source="SECUNIA">19038</ref>
      <ref url="http://secunia.com/advisories/18684" source="SECUNIA">18684</ref>
      <ref url="http://lists.suse.de/archive/suse-security-announce/2006-Feb/0010.html" source="SUSE">SUSE-SA:2006:012</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/20060402-01-U" source="SGI">20060402-01-U</ref>
    </refs>
    <vuln_soft>
      <prod vendor="linux" name="linux_kernel">
        <vers num="2.6.0" edition="test1" />
        <vers num="2.6.0" edition="test10" />
        <vers num="2.6.0" edition="test11" />
        <vers num="2.6.0" edition="test2" />
        <vers num="2.6.0" edition="test3" />
        <vers num="2.6.0" edition="test4" />
        <vers num="2.6.0" edition="test5" />
        <vers num="2.6.0" edition="test6" />
        <vers num="2.6.0" edition="test7" />
        <vers num="2.6.0" edition="test8" />
        <vers num="2.6.0" edition="test9" />
        <vers num="2.6.1" edition="rc1" />
        <vers num="2.6.1" edition="rc2" />
        <vers num="2.6.10" edition="rc2" />
        <vers num="2.6.2" />
        <vers num="2.6.3" />
        <vers num="2.6.4" />
        <vers num="2.6.5" />
        <vers num="2.6.6" edition="rc1" />
        <vers num="2.6.7" edition="rc1" />
        <vers num="2.6.8" edition="rc1" />
        <vers num="2.6.8" edition="rc2" />
        <vers num="2.6.8" edition="rc3" />
        <vers num="2.6.9" edition="2.6.20" />
        <vers num="2.6_test9_cvs" />
      </prod>
      <prod vendor="ubuntu" name="ubuntu_linux">
        <vers num="4.1" edition="" />
        <vers num="4.1" edition=":ia64" />
        <vers num="4.1" edition=":ppc" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1059" published="2004-12-10" name="CVE-2004-1059" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in mnoGoSearch 3.2.26 and earlier allow remote attackers to inject arbitrary HTML and web script via the (1) next and (2) prev result search pages, and the (3) extended and (4) simple search forms.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/18434" source="XF" patch="1" adv="1">mnogosearch-search-xss(18434)</ref>
      <ref url="http://www.securityfocus.com/bid/11895" source="BID" patch="1" adv="1">11895</ref>
      <ref url="http://www.mnogosearch.org/history.html" source="CONFIRM" patch="1" adv="1">http://www.mnogosearch.org/history.html</ref>
      <ref url="http://www.mikx.de/index.php?p=6" source="MISC" patch="1" adv="1">http://www.mikx.de/index.php?p=6</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2004-December/030222.html" source="FULLDISC" patch="1" adv="1">20041223 Cross-Site Scripting - an industry-wide problem</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mnogosearch" name="mnogosearch">
        <vers num="3.1.19" />
        <vers num="3.1.20" />
        <vers num="3.2.10" />
        <vers num="3.2.13" />
        <vers num="3.2.14" />
        <vers num="3.2.15" />
        <vers num="3.2.16" />
        <vers num="3.2.17" />
        <vers num="3.2.18" />
        <vers num="3.2.19" />
        <vers num="3.2.20" />
        <vers num="3.2.21" />
        <vers num="3.2.22" />
        <vers num="3.2.23" />
        <vers num="3.2.24" />
        <vers num="3.2.25" />
        <vers num="3.2.26" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1060" published="2004-04-12" name="CVE-2004-1060" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Multiple TCP/IP and ICMP implementations, when using Path MTU (PMTU) discovery (PMTUD), allow remote attackers to cause a denial of service (network throughput reduction for TCP connections) via forged ICMP ("Fragmentation Needed and Don't Fragment was Set") packets with a low next-hop MTU value, aka the "Path MTU discovery attack."  NOTE: CVE-2004-0790, CVE-2004-0791, and CVE-2004-1060 have been SPLIT based on different attacks; CVE-2005-0065, CVE-2005-0066, CVE-2005-0067, and CVE-2005-0068 are related identifiers that are SPLIT based on the underlying vulnerability.  While CVE normally SPLITs based on vulnerability, the attack-based identifiers exist due to the variety and number of affected implementations and solutions that address the attacks instead of the underlying vulnerabilities.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms05-019.mspx" source="MS" patch="1" adv="1">MS05-019</ref>
      <ref url="http://www.uniras.gov.uk/niscc/docs/al-20050412-00308.html?lang=en" source="MISC" adv="1">http://www.uniras.gov.uk/niscc/docs/al-20050412-00308.html?lang=en</ref>
      <ref url="http://www.gont.com.ar/drafts/icmp-attacks-against-tcp.html" source="MISC" adv="1">http://www.gont.com.ar/drafts/icmp-attacks-against-tcp.html</ref>
      <ref url="http://www.cisco.com/warp/public/707/cisco-sa-20050412-icmp.shtml" source="CISCO" adv="1">20050412 Crafted ICMP Messages Can Cause Denial of Service</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5386" source="OVAL">oval:org.mitre.oval:def:5386</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112861397904255&amp;w=2" source="HP">SSRT4884</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112861397904255&amp;w=2" source="HP">SSRT4743</ref>
      <ref url="http://www.securityfocus.com/bid/13124" source="BID">13124</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/418882/100/0/threaded" source="HP">HPSBUX01164</ref>
      <ref url="http://securityreason.com/securityalert/57" source="SREASON">57</ref>
      <ref url="http://securityreason.com/securityalert/19" source="SREASON">19</ref>
      <ref url="http://secunia.com/advisories/18317" source="SECUNIA">18317</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112861397904255&amp;w=2" source="HP">HPSBTU01210</ref>
      <ref url="ftp://ftp.sco.com/pub/updates/OpenServer/SCOSA-2006.4/SCOSA-2006.4.txt" source="SCO">SCOSA-2006.4</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:899" source="OVAL" sig="1">oval:org.mitre.oval:def:899</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:780" source="OVAL" sig="1">oval:org.mitre.oval:def:780</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:651" source="OVAL" sig="1">oval:org.mitre.oval:def:651</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:405" source="OVAL" sig="1">oval:org.mitre.oval:def:405</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:3826" source="OVAL" sig="1">oval:org.mitre.oval:def:3826</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2188" source="OVAL" sig="1">oval:org.mitre.oval:def:2188</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:196" source="OVAL" sig="1">oval:org.mitre.oval:def:196</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:181" source="OVAL" sig="1">oval:org.mitre.oval:def:181</ref>
    </refs>
    <vuln_soft>
      <prod vendor="icmp" name="icmp">
        <vers num="" />
      </prod>
      <prod vendor="tcp" name="tcp">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1061" published="2005-01-04" name="CVE-2004-1061" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in Bugzilla before 2.18, including 2.16.x before 2.16.11, allows remote attackers to inject arbitrary HTML and web script via forced error messages, as demonstrated using the action parameter.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/18728" source="XF" patch="1" adv="1">bugzilla-xss(18728)</ref>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=272620" source="CONFIRM">https://bugzilla.mozilla.org/show_bug.cgi?id=272620</ref>
      <ref url="http://www.securityfocus.com/bid/12154" source="BID">12154</ref>
      <ref url="http://www.mikx.de/index.php?p=6" source="MISC" adv="1">http://www.mikx.de/index.php?p=6</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2004-December/030222.html" source="FULLDISC" adv="1">20041223 Cross-Site Scripting - an industry-wide problem</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/index.php?id=a&amp;anuncio=001040" source="CONECTIVA">CLSA-2005:1040</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="bugzilla">
        <vers num="2.16.1" />
        <vers num="2.16.10" />
        <vers num="2.16.11" />
        <vers num="2.16.2" />
        <vers num="2.16.3" />
        <vers num="2.16.4" />
        <vers num="2.16.5" />
        <vers num="2.16.6" />
        <vers num="2.16.7" />
        <vers num="2.16.8" />
        <vers num="2.16.9" />
        <vers num="2.17" />
        <vers num="2.17.1" />
        <vers num="2.17.3" />
        <vers num="2.17.4" />
        <vers num="2.17.5" />
        <vers num="2.17.6" />
        <vers num="2.17.7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1062" published="2004-12-28" name="CVE-2004-1062" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in ViewCVS 0.9.2 allow remote attackers to inject arbitrary HTML and web script via certain error messages.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/18718" source="XF" patch="1" adv="1">viewcvs-xss(18718)</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200412-26.xml" source="GENTOO" patch="1" adv="1">GLSA-200412-26</ref>
      <ref url="http://www.mikx.de/index.php?p=6" source="MISC" adv="1">http://www.mikx.de/index.php?p=6</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2004-December/030222.html" source="FULLDISC" adv="1">20041223 Cross-Site Scripting - an industry-wide problem</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2005_01_sr.html" source="SUSE">SUSE-SR:2005:001</ref>
    </refs>
    <vuln_soft>
      <prod vendor="viewcvs" name="viewcvs">
        <vers num="0.9.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-1063" published="2005-01-10" name="CVE-2004-1063" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">PHP 4.x to 4.3.9, and PHP 5.x to 5.0.2, when running in safe mode on a multithreaded Unix webserver, allows local users to bypass safe_mode_exec_dir restrictions and execute commands outside of the intended safe_mode_exec_dir via shell metacharacters in the current directory name.  NOTE: this issue was originally REJECTed by its CNA before publication, but that decision is in active dispute.  This candidate may change significantly in the future as a result of further discussion.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/18511" source="XF">php-safemodeexecdir-restriction-bypass(18511)</ref>
      <ref url="http://www.securityfocus.com/bid/11964" source="BID">11964</ref>
      <ref url="http://www.securityfocus.com/archive/1/384545" source="BUGTRAQ">20041215 Advisory 01/2004: Multiple vulnerabilities in PHP 4/5</ref>
      <ref url="http://www.php.net/release_4_3_10.php" source="CONFIRM">http://www.php.net/release_4_3_10.php</ref>
      <ref url="http://www.hardened-php.net/advisories/012004.txt" source="MISC">http://www.hardened-php.net/advisories/012004.txt</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200412-14.xml" source="GENTOO">GLSA-200412-14</ref>
      <ref url="http://www.securityfocus.com/advisories/9028" source="HP">HPSBMA01212</ref>
      <ref url="http://www.osvdb.org/12412" source="OSVDB">12412</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:072" source="MANDRAKE">MDKSA-2005:072</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2004:151" source="MANDRAKE">MDKSA-2004:151</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111117104809638&amp;w=2" source="UBUNTU">USN-99-1</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000915" source="CONECTIVA">CLA-2005:915</ref>
    </refs>
  </entry>
  <entry type="CVE" severity="High" seq="2004-1064" published="2005-01-10" name="CVE-2004-1064" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">The safe mode checks in PHP 4.x to 4.3.9 and PHP 5.x to 5.0.2 truncate the file path before passing the data to the realpath function, which could allow attackers to bypass safe mode.  NOTE: this issue was originally REJECTed by its CNA before publication, but that decision is in active dispute.  This candidate may change significantly in the future as a result of further discussion.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/18512" source="XF">php-realpath-safemode-bypass(18512)</ref>
      <ref url="http://www.securityfocus.com/bid/11964" source="BID">11964</ref>
      <ref url="http://www.securityfocus.com/archive/1/384545" source="BUGTRAQ">20041215 Advisory 01/2004: Multiple vulnerabilities in PHP 4/5</ref>
      <ref url="http://www.php.net/release_4_3_10.php" source="CONFIRM">http://www.php.net/release_4_3_10.php</ref>
      <ref url="http://www.hardened-php.net/advisories/012004.txt" source="MISC">http://www.hardened-php.net/advisories/012004.txt</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200412-14.xml" source="GENTOO">GLSA-200412-14</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111170851228358&amp;w=2" source="UBUNTU">USN-99-2</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111117104809638&amp;w=2" source="UBUNTU">USN-99-1</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000915" source="CONECTIVA">CLA-2005:915</ref>
      <ref url="http://www.securityfocus.com/advisories/9028" source="HP">HPSBMA01212</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:072" source="MANDRAKE">MDKSA-2005:072</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2004:151" source="MANDRAKE">MDKSA-2004:151</ref>
    </refs>
  </entry>
  <entry type="CVE" severity="High" seq="2004-1065" published="2005-01-10" name="CVE-2004-1065" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Buffer overflow in the exif_read_data function in PHP before 4.3.10 and PHP 5.x up to 5.0.2 allows remote attackers to execute arbitrary code via a long section name in an image file.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-687.html" source="REDHAT" patch="1" adv="1">RHSA-2004:687</ref>
      <ref url="https://bugzilla.fedora.us/show_bug.cgi?id=2344" source="FEDORA">FLSA:2344</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/18517" source="XF">php-exifreaddata-bo(18517)</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-032.html" source="REDHAT">RHSA-2005:032</ref>
      <ref url="http://www.php.net/release_4_3_10.php" source="CONFIRM">http://www.php.net/release_4_3_10.php</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2005_02_php4_mod_php4.html" source="SUSE">SUSE-SA:2005:002</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10877" source="OVAL">oval:org.mitre.oval:def:10877</ref>
      <ref url="http://msgs.securepoint.com/cgi-bin/get/bugtraq0412/157.html" source="OPENPKG">OpenPKG-SA-2004.053</ref>
      <ref url="http://www.securityfocus.com/advisories/9028" source="HP">HPSBMA01212</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2004:151" source="MANDRAKE">MDKSA-2004:151</ref>
    </refs>
    <vuln_soft>
      <prod vendor="openpkg" name="openpkg">
        <vers num="2.1" />
        <vers num="2.2" />
        <vers num="current" />
      </prod>
      <prod vendor="php" name="php">
        <vers num="3.0" />
        <vers num="3.0.1" />
        <vers num="3.0.10" />
        <vers num="3.0.11" />
        <vers num="3.0.12" />
        <vers num="3.0.13" />
        <vers num="3.0.14" />
        <vers num="3.0.15" />
        <vers num="3.0.16" />
        <vers num="3.0.17" />
        <vers num="3.0.18" />
        <vers num="3.0.2" />
        <vers num="3.0.3" />
        <vers num="3.0.4" />
        <vers num="3.0.5" />
        <vers num="3.0.6" />
        <vers num="3.0.7" />
        <vers num="3.0.8" />
        <vers num="3.0.9" />
        <vers num="4.0" />
        <vers num="4.0.1" edition="patch1" />
        <vers num="4.0.1" edition="patch2" />
        <vers num="4.0.2" />
        <vers num="4.0.3" edition="patch1" />
        <vers num="4.0.4" />
        <vers num="4.0.5" />
        <vers num="4.0.6" />
        <vers num="4.0.7" edition="rc1" />
        <vers num="4.0.7" edition="rc2" />
        <vers num="4.0.7" edition="rc3" />
        <vers num="4.1.0" />
        <vers num="4.1.1" />
        <vers num="4.1.2" />
        <vers num="4.2" edition="" />
        <vers num="4.2" edition=":dev" />
        <vers num="4.2.0" />
        <vers num="4.2.1" />
        <vers num="4.2.2" />
        <vers num="4.2.3" />
        <vers num="4.3" />
        <vers num="4.3.1" />
        <vers num="4.3.2" />
        <vers num="4.3.3" />
        <vers num="4.3.4" />
        <vers num="4.3.5" />
        <vers num="4.3.6" />
        <vers num="4.3.7" />
        <vers num="4.3.8" />
        <vers num="4.3.9" />
        <vers num="5.0" edition="rc1" />
        <vers num="5.0" edition="rc2" />
        <vers num="5.0" edition="rc3" />
        <vers num="5.0.0" />
        <vers num="5.0.1" />
        <vers num="5.0.2" />
      </prod>
      <prod vendor="trustix" name="secure_linux">
        <vers num="2.0" />
        <vers num="2.1" />
        <vers num="2.2" />
      </prod>
      <prod vendor="ubuntu" name="ubuntu_linux">
        <vers num="4.1" edition="" />
        <vers num="4.1" edition=":ia64" />
        <vers num="4.1" edition=":ppc" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2004-1066" published="2005-01-10" name="CVE-2004-1066" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:P)" CVSS_score="3.6" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="3.9" CVSS_base_score="3.6">
    <desc>
      <descript source="cve">The cmdline pseudofiles in (1) procfs on FreeBSD 4.8 through 5.3, and (2) linprocfs on FreeBSD 5.x through 5.3, do not properly validate a process argument vector, which allows local users to cause a denial of service (panic) or read portions of kernel memory.  NOTE: this candidate might be SPLIT into 2 separate items in the future.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
    </loss_types>
    <vuln_types>
      <input />
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/18321" source="XF" adv="1">freebsd-profs-linprocfs-info-disclosure(18321)</ref>
      <ref url="ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-04:17.procfs.asc" source="FREEBSD">FreeBSD-SA-04:17</ref>
    </refs>
    <vuln_soft>
      <prod vendor="freebsd" name="freebsd">
        <vers num="4.0" />
        <vers num="4.1" />
        <vers num="4.1.1" />
        <vers num="4.10" edition="release" />
        <vers num="4.10" edition="releng" />
        <vers num="4.2" />
        <vers num="4.3" />
        <vers num="4.4" />
        <vers num="4.5" />
        <vers num="4.6" />
        <vers num="4.7" />
        <vers num="4.8" edition="releng" />
        <vers num="4.9" />
        <vers num="5.0" />
        <vers num="5.1" />
        <vers num="5.2" />
        <vers num="5.2.1" edition="release" />
        <vers num="5.2.1" edition="releng" />
        <vers num="5.3" edition="release" />
        <vers num="5.3" edition="stable" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-1067" published="2005-01-10" name="CVE-2004-1067" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Off-by-one error in the mysasl_canon_user function in Cyrus IMAP Server 2.2.9 and earlier leads to a buffer overflow, which may allow remote attackers to execute arbitrary code via the username.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/11738" source="BID" patch="1" adv="1">11738</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/18333" source="XF" adv="1">cyrus-mysaslcanonuser-offbyone-bo(18333)</ref>
      <ref url="http://asg.web.cmu.edu/cyrus/download/imapd/changes.html" source="CONFIRM">http://asg.web.cmu.edu/cyrus/download/imapd/changes.html</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110202757008916&amp;w=2" source="UBUNTU">USN-37-1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="carnegie_mellon_university" name="cyrus_imap_server">
        <vers num="1.4" />
        <vers num="1.5.19" />
        <vers num="2.0.12" />
        <vers num="2.0.16" />
        <vers num="2.1.10" />
        <vers num="2.1.16" />
        <vers num="2.1.7" />
        <vers num="2.1.9" />
        <vers num="2.2.0_alpha" />
        <vers num="2.2.1_beta" />
        <vers num="2.2.2_beta" />
        <vers num="2.2.3" />
        <vers num="2.2.4" />
        <vers num="2.2.5" />
        <vers num="2.2.6" />
        <vers num="2.2.7" />
        <vers num="2.2.8" />
        <vers num="2.2.9" />
      </prod>
      <prod vendor="redhat" name="fedora_core">
        <vers num="core_2.0" />
        <vers num="core_3.0" />
      </prod>
      <prod vendor="ubuntu" name="ubuntu_linux">
        <vers num="4.1" edition="" />
        <vers num="4.1" edition=":ia64" />
        <vers num="4.1" edition=":ppc" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1068" published="2005-01-10" name="CVE-2004-1068" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:H/Au:N/C:C/I:C/A:C)" CVSS_score="6.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="1.9" CVSS_base_score="6.2">
    <desc>
      <descript source="cve">A "missing serialization" error in the unix_dgram_recvmsg function in Linux 2.4.27 and earlier, and 2.6.x up to 2.6.9, allows local users to gain privileges via a race condition.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" admin="1" />
    </loss_types>
    <vuln_types>
      <race />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/11715" source="BID" patch="1" adv="1">11715</ref>
      <ref url="https://bugzilla.fedora.us/show_bug.cgi?id=2336" source="FEDORA">FLSA:2336</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/18230" source="XF" adv="1">linux-afunix-race-condition(18230)</ref>
      <ref url="http://www.securityfocus.com/archive/1/381689" source="BUGTRAQ">20041119 Addendum, recent Linux &lt;= 2.4.27 vulnerabilities</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-537.html" source="REDHAT">RHSA-2004:537</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11384" source="OVAL">oval:org.mitre.oval:def:11384</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-505.html" source="REDHAT">RHSA-2004:505</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-504.html" source="REDHAT">RHSA-2004:504</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2004_44_kernel.html" source="SUSE">SUSE-SA:2004:044</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:022" source="MANDRAKE">MDKSA-2005:022</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1082" source="DEBIAN">DSA-1082</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1070" source="DEBIAN">DSA-1070</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1069" source="DEBIAN">DSA-1069</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1067" source="DEBIAN">DSA-1067</ref>
      <ref url="http://secunia.com/advisories/20338" source="SECUNIA">20338</ref>
      <ref url="http://secunia.com/advisories/20202" source="SECUNIA">20202</ref>
      <ref url="http://secunia.com/advisories/20163" source="SECUNIA">20163</ref>
      <ref url="http://secunia.com/advisories/20162" source="SECUNIA">20162</ref>
      <ref url="http://secunia.com/advisories/19607" source="SECUNIA">19607</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110306397320336&amp;w=2" source="BUGTRAQ">20041214 [USN-38-1] Linux kernel vulnerabilities</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/20060402-01-U" source="SGI">20060402-01-U</ref>
    </refs>
    <vuln_soft>
      <prod vendor="linux" name="linux_kernel">
        <vers num="2.4.0" edition="test1" />
        <vers num="2.4.0" edition="test10" />
        <vers num="2.4.0" edition="test11" />
        <vers num="2.4.0" edition="test12" />
        <vers num="2.4.0" edition="test2" />
        <vers num="2.4.0" edition="test3" />
        <vers num="2.4.0" edition="test4" />
        <vers num="2.4.0" edition="test5" />
        <vers num="2.4.0" edition="test6" />
        <vers num="2.4.0" edition="test7" />
        <vers num="2.4.0" edition="test8" />
        <vers num="2.4.0" edition="test9" />
        <vers num="2.4.1" />
        <vers num="2.4.10" />
        <vers num="2.4.12" />
        <vers num="2.4.13" />
        <vers num="2.4.14" />
        <vers num="2.4.15" />
        <vers num="2.4.16" />
        <vers num="2.4.17" />
        <vers num="2.4.18" edition="" />
        <vers num="2.4.18" edition=":x86" />
        <vers num="2.4.18" edition="pre1" />
        <vers num="2.4.18" edition="pre2" />
        <vers num="2.4.18" edition="pre3" />
        <vers num="2.4.18" edition="pre4" />
        <vers num="2.4.18" edition="pre5" />
        <vers num="2.4.18" edition="pre6" />
        <vers num="2.4.18" edition="pre7" />
        <vers num="2.4.18" edition="pre8" />
        <vers num="2.4.19" edition="pre1" />
        <vers num="2.4.19" edition="pre2" />
        <vers num="2.4.19" edition="pre3" />
        <vers num="2.4.19" edition="pre4" />
        <vers num="2.4.19" edition="pre5" />
        <vers num="2.4.19" edition="pre6" />
        <vers num="2.4.2" />
        <vers num="2.4.20" />
        <vers num="2.4.21" edition="pre1" />
        <vers num="2.4.21" edition="pre4" />
        <vers num="2.4.21" edition="pre7" />
        <vers num="2.4.22" />
        <vers num="2.4.23" edition="pre9" />
        <vers num="2.4.23_ow2" />
        <vers num="2.4.24" />
        <vers num="2.4.24_ow1" />
        <vers num="2.4.25" />
        <vers num="2.4.26" />
        <vers num="2.4.27" edition="pre1" />
        <vers num="2.4.27" edition="pre2" />
        <vers num="2.4.27" edition="pre3" />
        <vers num="2.4.27" edition="pre4" />
        <vers num="2.4.27" edition="pre5" />
        <vers num="2.4.3" />
        <vers num="2.4.4" />
        <vers num="2.4.5" />
        <vers num="2.4.6" />
        <vers num="2.4.7" />
        <vers num="2.4.8" />
        <vers num="2.4.9" />
      </prod>
      <prod vendor="redhat" name="enterprise_linux">
        <vers num="2.1" edition="" />
        <vers num="2.1" edition=":workstation_ia64" />
        <vers num="2.1" edition=":advanced_server" />
        <vers num="2.1" edition=":enterprise_server" />
        <vers num="2.1" edition=":advanced_server_ia64" />
        <vers num="2.1" edition=":enterprise_server_ia64" />
        <vers num="2.1" edition=":workstation" />
        <vers num="3.0" edition="" />
        <vers num="3.0" edition=":workstation_server" />
        <vers num="3.0" edition=":enterprise_server" />
        <vers num="3.0" edition=":advanced_server" />
      </prod>
      <prod vendor="redhat" name="enterprise_linux_desktop">
        <vers num="3.0" />
      </prod>
      <prod vendor="redhat" name="linux_advanced_workstation">
        <vers num="2.1" edition="" />
        <vers num="2.1" edition=":itanium_processor" />
        <vers num="2.1" edition=":ia64" />
      </prod>
      <prod vendor="ubuntu" name="ubuntu_linux">
        <vers num="4.1" edition="" />
        <vers num="4.1" edition=":ia64" />
        <vers num="4.1" edition=":ppc" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2004-1069" published="2005-01-10" name="CVE-2004-1069" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:H/Au:N/C:N/I:N/A:P)" CVSS_score="1.2" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="1.9" CVSS_base_score="1.2">
    <desc>
      <descript source="cve">Race condition in SELinux 2.6.x through 2.6.9 allows local users to cause a denial of service (kernel crash) via SOCK_SEQPACKET unix domain sockets, which are not properly handled in the sock_dgram_sendmsg function.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
      <race />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/18312" source="XF" adv="1">linux-sockdgramsendmsg-race-condition(18312)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=linux-kernel&amp;m=110045613004761" source="MLIST" adv="1">[linux-kernel] 20041114 [PATCH] linux 2.9.10-rc1: Fix oops in unix_dgram_sendmsg when using</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110306397320336&amp;w=2" source="BUGTRAQ" adv="1">20041214 [USN-38-1] Linux kernel vulnerabilities</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:022" source="MANDRAKE">MDKSA-2005:022</ref>
    </refs>
    <vuln_soft>
      <prod vendor="linux" name="linux_kernel">
        <vers num="2.6.0" edition="test1" />
        <vers num="2.6.0" edition="test10" />
        <vers num="2.6.0" edition="test11" />
        <vers num="2.6.0" edition="test2" />
        <vers num="2.6.0" edition="test3" />
        <vers num="2.6.0" edition="test4" />
        <vers num="2.6.0" edition="test5" />
        <vers num="2.6.0" edition="test6" />
        <vers num="2.6.0" edition="test7" />
        <vers num="2.6.0" edition="test8" />
        <vers num="2.6.0" edition="test9" />
        <vers num="2.6.1" edition="rc1" />
        <vers num="2.6.1" edition="rc2" />
        <vers num="2.6.10" edition="rc2" />
        <vers num="2.6.2" />
        <vers num="2.6.3" />
        <vers num="2.6.4" />
        <vers num="2.6.5" />
        <vers num="2.6.6" edition="rc1" />
        <vers num="2.6.7" edition="rc1" />
        <vers num="2.6.8" edition="rc1" />
        <vers num="2.6.8" edition="rc2" />
        <vers num="2.6.8" edition="rc3" />
        <vers num="2.6.9" edition="2.6.20" />
        <vers num="2.6_test9_cvs" />
      </prod>
      <prod vendor="ubuntu" name="ubuntu_linux">
        <vers num="4.1" edition="" />
        <vers num="4.1" edition=":ia64" />
        <vers num="4.1" edition=":ppc" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-1070" published="2005-01-10" name="CVE-2004-1070" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">The load_elf_binary function in the binfmt_elf loader (binfmt_elf.c) in Linux kernel 2.4.x up to 2.4.27, and 2.6.x up to 2.6.8, does not properly check return values from calls to the kernel_read function, which may allow local users to modify sensitive memory in a setuid program and execute arbitrary code.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" admin="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="https://bugzilla.fedora.us/show_bug.cgi?id=2336" source="FEDORA">FLSA:2336</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/18025" source="XF" adv="1">linux-elf-setuid-gain-privileges(18025)</ref>
      <ref url="http://www.securityfocus.com/bid/11646" source="BID">11646</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-549.html" source="REDHAT">RHSA-2004:549</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-505.html" source="REDHAT">RHSA-2004:505</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-504.html" source="REDHAT">RHSA-2004:504</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:022" source="MANDRAKE">MDKSA-2005:022</ref>
      <ref url="http://www.isec.pl/vulnerabilities/isec-0017-binfmt_elf.txt" source="MISC">http://www.isec.pl/vulnerabilities/isec-0017-binfmt_elf.txt</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1082" source="DEBIAN">DSA-1082</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1070" source="DEBIAN">DSA-1070</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1069" source="DEBIAN">DSA-1069</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1067" source="DEBIAN">DSA-1067</ref>
      <ref url="http://secunia.com/advisories/20338" source="SECUNIA" adv="1">20338</ref>
      <ref url="http://secunia.com/advisories/20202" source="SECUNIA" adv="1">20202</ref>
      <ref url="http://secunia.com/advisories/20163" source="SECUNIA" adv="1">20163</ref>
      <ref url="http://secunia.com/advisories/20162" source="SECUNIA" adv="1">20162</ref>
      <ref url="http://secunia.com/advisories/19607" source="SECUNIA" adv="1">19607</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9450" source="OVAL">oval:org.mitre.oval:def:9450</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/20060402-01-U" source="SGI">20060402-01-U</ref>
    </refs>
    <vuln_soft>
      <prod vendor="linux" name="linux_kernel">
        <vers num="2.4.0" edition="test1" />
        <vers num="2.4.0" edition="test10" />
        <vers num="2.4.0" edition="test11" />
        <vers num="2.4.0" edition="test12" />
        <vers num="2.4.0" edition="test2" />
        <vers num="2.4.0" edition="test3" />
        <vers num="2.4.0" edition="test4" />
        <vers num="2.4.0" edition="test5" />
        <vers num="2.4.0" edition="test6" />
        <vers num="2.4.0" edition="test7" />
        <vers num="2.4.0" edition="test8" />
        <vers num="2.4.0" edition="test9" />
        <vers num="2.4.1" />
        <vers num="2.4.10" />
        <vers num="2.4.11" />
        <vers num="2.4.12" />
        <vers num="2.4.13" />
        <vers num="2.4.14" />
        <vers num="2.4.15" />
        <vers num="2.4.16" />
        <vers num="2.4.17" />
        <vers num="2.4.18" edition="" />
        <vers num="2.4.18" edition=":x86" />
        <vers num="2.4.18" edition="pre1" />
        <vers num="2.4.18" edition="pre2" />
        <vers num="2.4.18" edition="pre3" />
        <vers num="2.4.18" edition="pre4" />
        <vers num="2.4.18" edition="pre5" />
        <vers num="2.4.18" edition="pre6" />
        <vers num="2.4.18" edition="pre7" />
        <vers num="2.4.18" edition="pre8" />
        <vers num="2.4.19" edition="pre1" />
        <vers num="2.4.19" edition="pre2" />
        <vers num="2.4.19" edition="pre3" />
        <vers num="2.4.19" edition="pre4" />
        <vers num="2.4.19" edition="pre5" />
        <vers num="2.4.19" edition="pre6" />
        <vers num="2.4.2" />
        <vers num="2.4.20" />
        <vers num="2.4.21" edition="pre1" />
        <vers num="2.4.21" edition="pre4" />
        <vers num="2.4.21" edition="pre7" />
        <vers num="2.4.22" />
        <vers num="2.4.23" edition="pre9" />
        <vers num="2.4.23_ow2" />
        <vers num="2.4.24" />
        <vers num="2.4.24_ow1" />
        <vers num="2.4.25" />
        <vers num="2.4.26" />
        <vers num="2.4.27" edition="pre1" />
        <vers num="2.4.27" edition="pre2" />
        <vers num="2.4.27" edition="pre3" />
        <vers num="2.4.27" edition="pre4" />
        <vers num="2.4.27" edition="pre5" />
        <vers num="2.4.3" />
        <vers num="2.4.4" />
        <vers num="2.4.5" />
        <vers num="2.4.6" />
        <vers num="2.4.7" />
        <vers num="2.4.8" />
        <vers num="2.4.9" />
        <vers num="2.6.0" edition="test1" />
        <vers num="2.6.0" edition="test10" />
        <vers num="2.6.0" edition="test11" />
        <vers num="2.6.0" edition="test2" />
        <vers num="2.6.0" edition="test3" />
        <vers num="2.6.0" edition="test4" />
        <vers num="2.6.0" edition="test5" />
        <vers num="2.6.0" edition="test6" />
        <vers num="2.6.0" edition="test7" />
        <vers num="2.6.0" edition="test8" />
        <vers num="2.6.0" edition="test9" />
        <vers num="2.6.1" edition="rc1" />
        <vers num="2.6.1" edition="rc2" />
        <vers num="2.6.2" />
        <vers num="2.6.3" />
        <vers num="2.6.4" />
        <vers num="2.6.5" />
        <vers num="2.6.6" edition="rc1" />
        <vers num="2.6.7" edition="rc1" />
        <vers num="2.6.8" edition="rc1" />
        <vers num="2.6.8" edition="rc2" />
        <vers num="2.6.8" edition="rc3" />
        <vers num="2.6.9" edition="2.6.20" />
        <vers num="2.6_test9_cvs" />
      </prod>
      <prod vendor="redhat" name="enterprise_linux">
        <vers num="2.1" edition="" />
        <vers num="2.1" edition=":workstation_ia64" />
        <vers num="2.1" edition=":advanced_server" />
        <vers num="2.1" edition=":advanced_server_ia64" />
        <vers num="2.1" edition=":workstation" />
        <vers num="2.1" edition=":enterprise_server" />
        <vers num="2.1" edition=":enterprise_server_ia64" />
        <vers num="3.0" edition="" />
        <vers num="3.0" edition=":workstation_server" />
        <vers num="3.0" edition=":advanced_server" />
        <vers num="3.0" edition=":enterprise_server" />
      </prod>
      <prod vendor="redhat" name="enterprise_linux_desktop">
        <vers num="3.0" />
      </prod>
      <prod vendor="redhat" name="fedora_core">
        <vers num="core_2.0" />
        <vers num="core_3.0" />
      </prod>
      <prod vendor="redhat" name="linux_advanced_workstation">
        <vers num="2.1" edition="" />
        <vers num="2.1" edition=":itanium_processor" />
        <vers num="2.1" edition=":ia64" />
      </prod>
      <prod vendor="suse" name="suse_linux">
        <vers num="1.0" edition="" />
        <vers num="1.0" edition=":desktop" />
        <vers num="8" edition="" />
        <vers num="8" edition=":enterprise_server" />
        <vers num="8.1" />
        <vers num="8.2" />
        <vers num="9.0" edition="" />
        <vers num="9.0" edition=":enterprise_server" />
        <vers num="9.0" edition=":x86_64" />
        <vers num="9.1" />
        <vers num="9.2" />
      </prod>
      <prod vendor="trustix" name="secure_linux">
        <vers num="1.5" />
        <vers num="2.0" />
        <vers num="2.1" />
        <vers num="2.2" />
      </prod>
      <prod vendor="turbolinux" name="turbolinux_server">
        <vers num="10.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-1071" published="2005-01-10" name="CVE-2004-1071" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">The binfmt_elf loader (binfmt_elf.c) in Linux kernel 2.4.x up to 2.4.27, and 2.6.x up to 2.6.8, does not properly handle a failed call to the mmap function, which causes an incorrect mapped image and may allow local users to execute arbitrary code.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" admin="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-537.html" source="REDHAT" patch="1" adv="1">RHSA-2004:537</ref>
      <ref url="https://bugzilla.fedora.us/show_bug.cgi?id=2336" source="FEDORA">FLSA:2336</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/18025" source="XF" adv="1">linux-elf-setuid-gain-privileges(18025)</ref>
      <ref url="http://www.isec.pl/vulnerabilities/isec-0017-binfmt_elf.txt" source="MISC">http://www.isec.pl/vulnerabilities/isec-0017-binfmt_elf.txt</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9917" source="OVAL">oval:org.mitre.oval:def:9917</ref>
      <ref url="http://www.securityfocus.com/bid/11646" source="BID">11646</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-505.html" source="REDHAT">RHSA-2004:505</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-504.html" source="REDHAT">RHSA-2004:504</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:022" source="MANDRAKE">MDKSA-2005:022</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1082" source="DEBIAN">DSA-1082</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1070" source="DEBIAN">DSA-1070</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1069" source="DEBIAN">DSA-1069</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1067" source="DEBIAN">DSA-1067</ref>
      <ref url="http://secunia.com/advisories/20338" source="SECUNIA">20338</ref>
      <ref url="http://secunia.com/advisories/20202" source="SECUNIA">20202</ref>
      <ref url="http://secunia.com/advisories/20163" source="SECUNIA">20163</ref>
      <ref url="http://secunia.com/advisories/20162" source="SECUNIA">20162</ref>
      <ref url="http://secunia.com/advisories/19607" source="SECUNIA">19607</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/20060402-01-U" source="SGI">20060402-01-U</ref>
    </refs>
    <vuln_soft>
      <prod vendor="linux" name="linux_kernel">
        <vers num="2.4.0" edition="test1" />
        <vers num="2.4.0" edition="test10" />
        <vers num="2.4.0" edition="test11" />
        <vers num="2.4.0" edition="test12" />
        <vers num="2.4.0" edition="test2" />
        <vers num="2.4.0" edition="test3" />
        <vers num="2.4.0" edition="test4" />
        <vers num="2.4.0" edition="test5" />
        <vers num="2.4.0" edition="test6" />
        <vers num="2.4.0" edition="test7" />
        <vers num="2.4.0" edition="test8" />
        <vers num="2.4.0" edition="test9" />
        <vers num="2.4.1" />
        <vers num="2.4.10" />
        <vers num="2.4.11" />
        <vers num="2.4.12" />
        <vers num="2.4.13" />
        <vers num="2.4.14" />
        <vers num="2.4.15" />
        <vers num="2.4.16" />
        <vers num="2.4.17" />
        <vers num="2.4.18" edition="" />
        <vers num="2.4.18" edition=":x86" />
        <vers num="2.4.18" edition="pre1" />
        <vers num="2.4.18" edition="pre2" />
        <vers num="2.4.18" edition="pre3" />
        <vers num="2.4.18" edition="pre4" />
        <vers num="2.4.18" edition="pre5" />
        <vers num="2.4.18" edition="pre6" />
        <vers num="2.4.18" edition="pre7" />
        <vers num="2.4.18" edition="pre8" />
        <vers num="2.4.19" edition="pre1" />
        <vers num="2.4.19" edition="pre2" />
        <vers num="2.4.19" edition="pre3" />
        <vers num="2.4.19" edition="pre4" />
        <vers num="2.4.19" edition="pre5" />
        <vers num="2.4.19" edition="pre6" />
        <vers num="2.4.2" />
        <vers num="2.4.20" />
        <vers num="2.4.21" edition="pre1" />
        <vers num="2.4.21" edition="pre4" />
        <vers num="2.4.21" edition="pre7" />
        <vers num="2.4.22" />
        <vers num="2.4.23" edition="pre9" />
        <vers num="2.4.23_ow2" />
        <vers num="2.4.24" />
        <vers num="2.4.24_ow1" />
        <vers num="2.4.25" />
        <vers num="2.4.26" />
        <vers num="2.4.27" edition="pre1" />
        <vers num="2.4.27" edition="pre2" />
        <vers num="2.4.27" edition="pre3" />
        <vers num="2.4.27" edition="pre4" />
        <vers num="2.4.27" edition="pre5" />
        <vers num="2.4.3" />
        <vers num="2.4.4" />
        <vers num="2.4.5" />
        <vers num="2.4.6" />
        <vers num="2.4.7" />
        <vers num="2.4.8" />
        <vers num="2.4.9" />
        <vers num="2.6.0" edition="test1" />
        <vers num="2.6.0" edition="test10" />
        <vers num="2.6.0" edition="test11" />
        <vers num="2.6.0" edition="test2" />
        <vers num="2.6.0" edition="test3" />
        <vers num="2.6.0" edition="test4" />
        <vers num="2.6.0" edition="test5" />
        <vers num="2.6.0" edition="test6" />
        <vers num="2.6.0" edition="test7" />
        <vers num="2.6.0" edition="test8" />
        <vers num="2.6.0" edition="test9" />
        <vers num="2.6.1" edition="rc1" />
        <vers num="2.6.1" edition="rc2" />
        <vers num="2.6.2" />
        <vers num="2.6.3" />
        <vers num="2.6.4" />
        <vers num="2.6.5" />
        <vers num="2.6.6" edition="rc1" />
        <vers num="2.6.7" edition="rc1" />
        <vers num="2.6.8" edition="rc1" />
        <vers num="2.6.8" edition="rc2" />
        <vers num="2.6.8" edition="rc3" />
        <vers num="2.6.9" edition="2.6.20" />
        <vers num="2.6_test9_cvs" />
      </prod>
      <prod vendor="redhat" name="enterprise_linux">
        <vers num="2.1" edition="" />
        <vers num="2.1" edition=":workstation_ia64" />
        <vers num="2.1" edition=":advanced_server" />
        <vers num="2.1" edition=":advanced_server_ia64" />
        <vers num="2.1" edition=":workstation" />
        <vers num="2.1" edition=":enterprise_server" />
        <vers num="2.1" edition=":enterprise_server_ia64" />
        <vers num="3.0" edition="" />
        <vers num="3.0" edition=":workstation_server" />
        <vers num="3.0" edition=":advanced_server" />
        <vers num="3.0" edition=":enterprise_server" />
      </prod>
      <prod vendor="redhat" name="enterprise_linux_desktop">
        <vers num="3.0" />
      </prod>
      <prod vendor="redhat" name="fedora_core">
        <vers num="core_2.0" />
        <vers num="core_3.0" />
      </prod>
      <prod vendor="redhat" name="linux_advanced_workstation">
        <vers num="2.1" edition="" />
        <vers num="2.1" edition=":itanium_processor" />
        <vers num="2.1" edition=":ia64" />
      </prod>
      <prod vendor="suse" name="suse_linux">
        <vers num="1.0" edition="" />
        <vers num="1.0" edition=":desktop" />
        <vers num="8" edition="" />
        <vers num="8" edition=":enterprise_server" />
        <vers num="8.1" />
        <vers num="8.2" />
        <vers num="9.0" edition="" />
        <vers num="9.0" edition=":enterprise_server" />
        <vers num="9.0" edition=":x86_64" />
        <vers num="9.1" />
        <vers num="9.2" />
      </prod>
      <prod vendor="trustix" name="secure_linux">
        <vers num="1.5" />
        <vers num="2.0" />
        <vers num="2.1" />
        <vers num="2.2" />
      </prod>
      <prod vendor="turbolinux" name="turbolinux_server">
        <vers num="10.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-1072" published="2005-01-10" name="CVE-2004-1072" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">The binfmt_elf loader (binfmt_elf.c) in Linux kernel 2.4.x up to 2.4.27, and 2.6.x up to 2.6.8, may create an interpreter name string that is not NULL terminated, which could cause strings longer than PATH_MAX to be used, leading to buffer overflows that allow local users to cause a denial of service (hang) and possibly execute arbitrary code.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-537.html" source="REDHAT" patch="1" adv="1">RHSA-2004:537</ref>
      <ref url="https://bugzilla.fedora.us/show_bug.cgi?id=2336" source="FEDORA">FLSA:2336</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/18025" source="XF" adv="1">linux-elf-setuid-gain-privileges(18025)</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-275.html" source="REDHAT">RHSA-2005:275</ref>
      <ref url="http://www.isec.pl/vulnerabilities/isec-0017-binfmt_elf.txt" source="MISC">http://www.isec.pl/vulnerabilities/isec-0017-binfmt_elf.txt</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11195" source="OVAL">oval:org.mitre.oval:def:11195</ref>
      <ref url="http://www.securityfocus.com/bid/11646" source="BID">11646</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-505.html" source="REDHAT">RHSA-2004:505</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-504.html" source="REDHAT">RHSA-2004:504</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:022" source="MANDRAKE">MDKSA-2005:022</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1082" source="DEBIAN">DSA-1082</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1070" source="DEBIAN">DSA-1070</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1069" source="DEBIAN">DSA-1069</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1067" source="DEBIAN">DSA-1067</ref>
      <ref url="http://secunia.com/advisories/20338" source="SECUNIA">20338</ref>
      <ref url="http://secunia.com/advisories/20202" source="SECUNIA">20202</ref>
      <ref url="http://secunia.com/advisories/20163" source="SECUNIA">20163</ref>
      <ref url="http://secunia.com/advisories/20162" source="SECUNIA">20162</ref>
      <ref url="http://secunia.com/advisories/19607" source="SECUNIA">19607</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/20060402-01-U" source="SGI">20060402-01-U</ref>
    </refs>
    <vuln_soft>
      <prod vendor="linux" name="linux_kernel">
        <vers num="2.4.0" edition="test1" />
        <vers num="2.4.0" edition="test10" />
        <vers num="2.4.0" edition="test11" />
        <vers num="2.4.0" edition="test12" />
        <vers num="2.4.0" edition="test2" />
        <vers num="2.4.0" edition="test3" />
        <vers num="2.4.0" edition="test4" />
        <vers num="2.4.0" edition="test5" />
        <vers num="2.4.0" edition="test6" />
        <vers num="2.4.0" edition="test7" />
        <vers num="2.4.0" edition="test8" />
        <vers num="2.4.0" edition="test9" />
        <vers num="2.4.1" />
        <vers num="2.4.10" />
        <vers num="2.4.11" />
        <vers num="2.4.12" />
        <vers num="2.4.13" />
        <vers num="2.4.14" />
        <vers num="2.4.15" />
        <vers num="2.4.16" />
        <vers num="2.4.17" />
        <vers num="2.4.18" edition="" />
        <vers num="2.4.18" edition=":x86" />
        <vers num="2.4.18" edition="pre1" />
        <vers num="2.4.18" edition="pre2" />
        <vers num="2.4.18" edition="pre3" />
        <vers num="2.4.18" edition="pre4" />
        <vers num="2.4.18" edition="pre5" />
        <vers num="2.4.18" edition="pre6" />
        <vers num="2.4.18" edition="pre7" />
        <vers num="2.4.18" edition="pre8" />
        <vers num="2.4.19" edition="pre1" />
        <vers num="2.4.19" edition="pre2" />
        <vers num="2.4.19" edition="pre3" />
        <vers num="2.4.19" edition="pre4" />
        <vers num="2.4.19" edition="pre5" />
        <vers num="2.4.19" edition="pre6" />
        <vers num="2.4.2" />
        <vers num="2.4.20" />
        <vers num="2.4.21" edition="pre1" />
        <vers num="2.4.21" edition="pre4" />
        <vers num="2.4.21" edition="pre7" />
        <vers num="2.4.22" />
        <vers num="2.4.23" edition="pre9" />
        <vers num="2.4.23_ow2" />
        <vers num="2.4.24" />
        <vers num="2.4.24_ow1" />
        <vers num="2.4.25" />
        <vers num="2.4.26" />
        <vers num="2.4.27" edition="pre1" />
        <vers num="2.4.27" edition="pre2" />
        <vers num="2.4.27" edition="pre3" />
        <vers num="2.4.27" edition="pre4" />
        <vers num="2.4.27" edition="pre5" />
        <vers num="2.4.3" />
        <vers num="2.4.4" />
        <vers num="2.4.5" />
        <vers num="2.4.6" />
        <vers num="2.4.7" />
        <vers num="2.4.8" />
        <vers num="2.4.9" />
        <vers num="2.6.0" edition="test1" />
        <vers num="2.6.0" edition="test10" />
        <vers num="2.6.0" edition="test11" />
        <vers num="2.6.0" edition="test2" />
        <vers num="2.6.0" edition="test3" />
        <vers num="2.6.0" edition="test4" />
        <vers num="2.6.0" edition="test5" />
        <vers num="2.6.0" edition="test6" />
        <vers num="2.6.0" edition="test7" />
        <vers num="2.6.0" edition="test8" />
        <vers num="2.6.0" edition="test9" />
        <vers num="2.6.1" edition="rc1" />
        <vers num="2.6.1" edition="rc2" />
        <vers num="2.6.2" />
        <vers num="2.6.3" />
        <vers num="2.6.4" />
        <vers num="2.6.5" />
        <vers num="2.6.6" edition="rc1" />
        <vers num="2.6.7" edition="rc1" />
        <vers num="2.6.8" edition="rc1" />
        <vers num="2.6.8" edition="rc2" />
        <vers num="2.6.8" edition="rc3" />
        <vers num="2.6.9" edition="2.6.20" />
        <vers num="2.6_test9_cvs" />
      </prod>
      <prod vendor="redhat" name="enterprise_linux">
        <vers num="2.1" edition="" />
        <vers num="2.1" edition=":workstation_ia64" />
        <vers num="2.1" edition=":advanced_server" />
        <vers num="2.1" edition=":advanced_server_ia64" />
        <vers num="2.1" edition=":workstation" />
        <vers num="2.1" edition=":enterprise_server" />
        <vers num="2.1" edition=":enterprise_server_ia64" />
        <vers num="3.0" edition="" />
        <vers num="3.0" edition=":workstation_server" />
        <vers num="3.0" edition=":advanced_server" />
        <vers num="3.0" edition=":enterprise_server" />
      </prod>
      <prod vendor="redhat" name="enterprise_linux_desktop">
        <vers num="3.0" />
      </prod>
      <prod vendor="redhat" name="fedora_core">
        <vers num="core_2.0" />
        <vers num="core_3.0" />
      </prod>
      <prod vendor="redhat" name="linux_advanced_workstation">
        <vers num="2.1" edition="" />
        <vers num="2.1" edition=":itanium_processor" />
        <vers num="2.1" edition=":ia64" />
      </prod>
      <prod vendor="suse" name="suse_linux">
        <vers num="1.0" edition="" />
        <vers num="1.0" edition=":desktop" />
        <vers num="8" edition="" />
        <vers num="8" edition=":enterprise_server" />
        <vers num="8.1" />
        <vers num="8.2" />
        <vers num="9.0" edition="" />
        <vers num="9.0" edition=":enterprise_server" />
        <vers num="9.0" edition=":x86_64" />
        <vers num="9.1" />
        <vers num="9.2" />
      </prod>
      <prod vendor="trustix" name="secure_linux">
        <vers num="1.5" />
        <vers num="2.0" />
        <vers num="2.1" />
        <vers num="2.2" />
      </prod>
      <prod vendor="turbolinux" name="turbolinux_server">
        <vers num="10.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2004-1073" published="2005-01-10" name="CVE-2004-1073" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">The open_exec function in the execve functionality (exec.c) in Linux kernel 2.4.x up to 2.4.27, and 2.6.x up to 2.6.8, allows local users to read non-readable ELF binaries by using the interpreter (PT_INTERP) functionality.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-549.html" source="REDHAT" patch="1" adv="1">RHSA-2004:549</ref>
      <ref url="https://bugzilla.fedora.us/show_bug.cgi?id=2336" source="FEDORA">FLSA:2336</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/18025" source="XF" adv="1">linux-elf-setuid-gain-privileges(18025)</ref>
      <ref url="http://www.isec.pl/vulnerabilities/isec-0017-binfmt_elf.txt" source="MISC">http://www.isec.pl/vulnerabilities/isec-0017-binfmt_elf.txt</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11503" source="OVAL">oval:org.mitre.oval:def:11503</ref>
      <ref url="http://www.securityfocus.com/bid/11646" source="BID">11646</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2006-0191.html" source="REDHAT">RHSA-2006:0191</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2006-0190.html" source="REDHAT">RHSA-2006:0190</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-293.html" source="REDHAT">RHSA-2005:293</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-505.html" source="REDHAT">RHSA-2004:505</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-504.html" source="REDHAT">RHSA-2004:504</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:022" source="MANDRAKE">MDKSA-2005:022</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1082" source="DEBIAN">DSA-1082</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1070" source="DEBIAN">DSA-1070</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1069" source="DEBIAN">DSA-1069</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1067" source="DEBIAN">DSA-1067</ref>
      <ref url="http://secunia.com/advisories/20338" source="SECUNIA">20338</ref>
      <ref url="http://secunia.com/advisories/20202" source="SECUNIA">20202</ref>
      <ref url="http://secunia.com/advisories/20163" source="SECUNIA">20163</ref>
      <ref url="http://secunia.com/advisories/20162" source="SECUNIA">20162</ref>
      <ref url="http://secunia.com/advisories/18684" source="SECUNIA">18684</ref>
    </refs>
    <vuln_soft>
      <prod vendor="linux" name="linux_kernel">
        <vers num="2.4.0" edition="test1" />
        <vers num="2.4.0" edition="test10" />
        <vers num="2.4.0" edition="test11" />
        <vers num="2.4.0" edition="test12" />
        <vers num="2.4.0" edition="test2" />
        <vers num="2.4.0" edition="test3" />
        <vers num="2.4.0" edition="test4" />
        <vers num="2.4.0" edition="test5" />
        <vers num="2.4.0" edition="test6" />
        <vers num="2.4.0" edition="test7" />
        <vers num="2.4.0" edition="test8" />
        <vers num="2.4.0" edition="test9" />
        <vers num="2.4.1" />
        <vers num="2.4.10" />
        <vers num="2.4.11" />
        <vers num="2.4.12" />
        <vers num="2.4.13" />
        <vers num="2.4.14" />
        <vers num="2.4.15" />
        <vers num="2.4.16" />
        <vers num="2.4.17" />
        <vers num="2.4.18" edition="" />
        <vers num="2.4.18" edition=":x86" />
        <vers num="2.4.18" edition="pre1" />
        <vers num="2.4.18" edition="pre2" />
        <vers num="2.4.18" edition="pre3" />
        <vers num="2.4.18" edition="pre4" />
        <vers num="2.4.18" edition="pre5" />
        <vers num="2.4.18" edition="pre6" />
        <vers num="2.4.18" edition="pre7" />
        <vers num="2.4.18" edition="pre8" />
        <vers num="2.4.19" edition="pre1" />
        <vers num="2.4.19" edition="pre2" />
        <vers num="2.4.19" edition="pre3" />
        <vers num="2.4.19" edition="pre4" />
        <vers num="2.4.19" edition="pre5" />
        <vers num="2.4.19" edition="pre6" />
        <vers num="2.4.2" />
        <vers num="2.4.20" />
        <vers num="2.4.21" edition="pre1" />
        <vers num="2.4.21" edition="pre4" />
        <vers num="2.4.21" edition="pre7" />
        <vers num="2.4.22" />
        <vers num="2.4.23" edition="pre9" />
        <vers num="2.4.23_ow2" />
        <vers num="2.4.24" />
        <vers num="2.4.24_ow1" />
        <vers num="2.4.25" />
        <vers num="2.4.26" />
        <vers num="2.4.27" edition="pre1" />
        <vers num="2.4.27" edition="pre2" />
        <vers num="2.4.27" edition="pre3" />
        <vers num="2.4.27" edition="pre4" />
        <vers num="2.4.27" edition="pre5" />
        <vers num="2.4.3" />
        <vers num="2.4.4" />
        <vers num="2.4.5" />
        <vers num="2.4.6" />
        <vers num="2.4.7" />
        <vers num="2.4.8" />
        <vers num="2.4.9" />
        <vers num="2.6.0" edition="test1" />
        <vers num="2.6.0" edition="test10" />
        <vers num="2.6.0" edition="test11" />
        <vers num="2.6.0" edition="test2" />
        <vers num="2.6.0" edition="test3" />
        <vers num="2.6.0" edition="test4" />
        <vers num="2.6.0" edition="test5" />
        <vers num="2.6.0" edition="test6" />
        <vers num="2.6.0" edition="test7" />
        <vers num="2.6.0" edition="test8" />
        <vers num="2.6.0" edition="test9" />
        <vers num="2.6.1" edition="rc1" />
        <vers num="2.6.1" edition="rc2" />
        <vers num="2.6.2" />
        <vers num="2.6.3" />
        <vers num="2.6.4" />
        <vers num="2.6.5" />
        <vers num="2.6.6" edition="rc1" />
        <vers num="2.6.7" edition="rc1" />
        <vers num="2.6.8" edition="rc1" />
        <vers num="2.6.8" edition="rc2" />
        <vers num="2.6.8" edition="rc3" />
        <vers num="2.6.9" edition="2.6.20" />
        <vers num="2.6_test9_cvs" />
      </prod>
      <prod vendor="redhat" name="enterprise_linux">
        <vers num="2.1" edition="" />
        <vers num="2.1" edition=":workstation_ia64" />
        <vers num="2.1" edition=":advanced_server" />
        <vers num="2.1" edition=":advanced_server_ia64" />
        <vers num="2.1" edition=":workstation" />
        <vers num="2.1" edition=":enterprise_server" />
        <vers num="2.1" edition=":enterprise_server_ia64" />
        <vers num="3.0" edition="" />
        <vers num="3.0" edition=":workstation_server" />
        <vers num="3.0" edition=":advanced_server" />
        <vers num="3.0" edition=":enterprise_server" />
      </prod>
      <prod vendor="redhat" name="enterprise_linux_desktop">
        <vers num="3.0" />
      </prod>
      <prod vendor="redhat" name="fedora_core">
        <vers num="core_2.0" />
        <vers num="core_3.0" />
      </prod>
      <prod vendor="redhat" name="linux_advanced_workstation">
        <vers num="2.1" edition="" />
        <vers num="2.1" edition=":itanium_processor" />
        <vers num="2.1" edition=":ia64" />
      </prod>
      <prod vendor="suse" name="suse_linux">
        <vers num="1.0" edition="" />
        <vers num="1.0" edition=":desktop" />
        <vers num="8" edition="" />
        <vers num="8" edition=":enterprise_server" />
        <vers num="8.1" />
        <vers num="8.2" />
        <vers num="9.0" edition="" />
        <vers num="9.0" edition=":enterprise_server" />
        <vers num="9.0" edition=":x86_64" />
        <vers num="9.1" />
        <vers num="9.2" />
      </prod>
      <prod vendor="trustix" name="secure_linux">
        <vers num="1.5" />
        <vers num="2.0" />
        <vers num="2.1" />
        <vers num="2.2" />
      </prod>
      <prod vendor="turbolinux" name="turbolinux_server">
        <vers num="10.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2004-1074" published="2005-01-10" name="CVE-2004-1074" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">The binfmt functionality in the Linux kernel, when "memory overcommit" is enabled, allows local users to cause a denial of service (kernel oops) via a malformed a.out binary.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/11754" source="BID" patch="1" adv="1">11754</ref>
      <ref url="https://bugzilla.fedora.us/show_bug.cgi?id=2336" source="FEDORA">FLSA:2336</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/18290" source="XF" adv="1">linux-aout-binary-dos(18290)</ref>
      <ref url="http://www.trustix.org/errata/2005/0001/" source="TRUSTIX">2005-0001</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9751" source="OVAL">oval:org.mitre.oval:def:9751</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110322596918807&amp;w=2" source="BUGTRAQ">20041216 [USN-39-1] Linux amd64 kernel vulnerability</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/index.php?id=a&amp;anuncio=000930" source="CONECTIVA">CLA-2005:930</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:022" source="MANDRAKE">MDKSA-2005:022</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1082" source="DEBIAN">DSA-1082</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1070" source="DEBIAN">DSA-1070</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1069" source="DEBIAN">DSA-1069</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1067" source="DEBIAN">DSA-1067</ref>
      <ref url="http://secunia.com/advisories/20338" source="SECUNIA">20338</ref>
      <ref url="http://secunia.com/advisories/20202" source="SECUNIA">20202</ref>
      <ref url="http://secunia.com/advisories/20163" source="SECUNIA">20163</ref>
      <ref url="http://secunia.com/advisories/20162" source="SECUNIA">20162</ref>
      <ref url="http://marc.theaimsgroup.com/?l=linux-kernel&amp;m=110021173607372&amp;w=2" source="MLIST">[linux-kernel] 20041111 a.out issue</ref>
    </refs>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1075" published="2005-01-10" name="CVE-2004-1075" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in standard_error_message.dtml for Zwiki after 0.10.0rc1 to 0.36.2 allows remote attackers to inject arbitrary HTML and web script via a malformed URL, which is not properly cleansed when generating an error message.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/11745" source="BID" patch="1">11745</ref>
      <ref url="http://zwiki.org/925ZwikiXSSVulnerability" source="CONFIRM">http://zwiki.org/925ZwikiXSSVulnerability</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/18237" source="XF">zwiki-link-xss(18237)</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200412-23.xml" source="GENTOO">GLSA-200412-23</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110149122529761&amp;w=2" source="BUGTRAQ">20041126 Re: STG Security Advisory: [SSA-20041122-12] Zwiki XSS vulnerability</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110138568212036&amp;w=2" source="BUGTRAQ" adv="1">20041124 STG Security Advisory: [SSA-20041122-12] Zwiki XSS vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="zwiki" name="zwiki">
        <vers num="0.10_rc1" />
        <vers num="0.36.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-1076" published="2005-01-10" name="CVE-2004-1076" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Multiple buffer overflows in the RtConfigLoad function in rt-config.c for Atari800 before 1.3.4 allow local users to execute arbitrary code via large values in the configuration file.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/11756" source="BID" patch="1" adv="1">11756</ref>
      <ref url="http://www.debian.org/security/2004/dsa-609" source="DEBIAN">DSA-609</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110149441815270&amp;w=2" source="BUGTRAQ" adv="1">20041126 Re: Atari800 - local root. (fwd)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110142899319841&amp;w=2" source="BUGTRAQ" adv="1">20041125 Atari800 - local root.</ref>
      <ref url="http://www.osvdb.org/12610" source="OSVDB">12610</ref>
      <ref url="http://secunia.com/advisories/13670/" source="SECUNIA">13670</ref>
      <ref url="http://cvs.sourceforge.net/viewcvs.py/atari800/atari800/DOC/ChangeLog?view=markup" source="CONFIRM">http://cvs.sourceforge.net/viewcvs.py/atari800/atari800/DOC/ChangeLog?view=markup</ref>
    </refs>
    <vuln_soft>
      <prod vendor="atari800" name="atari800">
        <vers num="0.5.4" />
        <vers num="0.6" />
        <vers num="0.6.2" />
        <vers num="0.7" />
        <vers num="0.8.1" />
        <vers num="0.8.2" />
        <vers num="0.8.6" />
        <vers num="0.8.7" />
        <vers num="0.8.8" />
        <vers num="0.8.9" />
        <vers num="0.9" />
        <vers num="0.9.1" />
        <vers num="0.9.2" />
        <vers num="0.9.3" />
        <vers num="0.9.4" />
        <vers num="0.9.5" />
        <vers num="0.9.6" />
        <vers num="0.9.7" />
        <vers num="0.9.8" />
        <vers num="0.9.9" />
        <vers num="0.9.9a" />
        <vers num="0.9.9b" />
        <vers num="0.9.9c" />
        <vers num="0.9.9d" />
        <vers num="0.9.9e" />
        <vers num="0.9.9f" />
        <vers num="0.9.9g" />
        <vers num="0.9.9h" />
        <vers num="0.9.9i" />
        <vers num="0.9.9j" />
        <vers num="1.0" />
        <vers num="1.0.1" />
        <vers num="1.0.2" />
        <vers num="1.0.3" />
        <vers num="1.0.4" />
        <vers num="1.0.5" />
        <vers num="1.0.6" />
        <vers num="1.0.7" />
        <vers num="1.2" />
        <vers num="1.2.1" />
        <vers num="1.2.1_pre0" />
        <vers num="1.2.2" />
        <vers num="1.2.3" />
        <vers num="1.2.4" />
        <vers num="1.2.5" />
        <vers num="1.2_pre0" />
        <vers num="1.3" />
      </prod>
      <prod vendor="debian" name="debian_linux">
        <vers num="3.0" edition="" />
        <vers num="3.0" edition=":mips" />
        <vers num="3.0" edition=":s-390" />
        <vers num="3.0" edition=":alpha" />
        <vers num="3.0" edition=":mipsel" />
        <vers num="3.0" edition=":hppa" />
        <vers num="3.0" edition=":ia-32" />
        <vers num="3.0" edition=":arm" />
        <vers num="3.0" edition=":ppc" />
        <vers num="3.0" edition=":m68k" />
        <vers num="3.0" edition=":ia-64" />
        <vers num="3.0" edition=":sparc" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1077" published="2004-04-26" name="CVE-2004-1077" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Citrix Program Neighborhood Agent for Win32 8.00.24737 and earlier and MetaFrame Presentation Server client for WinCE before 8.33 allows remote servers to create arbitrary shortcuts on the client via a full UNC path in the AppInStartmenu directive.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.idefense.com/application/poi/display?id=237&amp;type=vulnerabilities" source="IDEFENSE" patch="1" adv="1">20050426 Citrix Program Neighborhood Agent Arbitrary Shortcut Creation Vulnerability</ref>
      <ref url="http://secunia.com/advisories/15108" source="SECUNIA" patch="1" adv="1">15108</ref>
      <ref url="http://support.citrix.com/kb/entry.jspa?externalID=CTX105650" source="CONFIRM" adv="1">http://support.citrix.com/kb/entry.jspa?externalID=CTX105650</ref>
    </refs>
    <vuln_soft>
      <prod vendor="citrix" name="metaframe_client">
        <vers num="8.0" edition="" />
        <vers num="8.0" edition=":win-ce" />
      </prod>
      <prod vendor="citrix" name="program_neighborhood_agent">
        <vers num="8.0" edition="" />
        <vers num="8.0" edition=":win32" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-1078" published="2004-04-26" name="CVE-2004-1078" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Stack-based buffer overflow in the client for Citrix Program Neighborhood Agent for Win32 8.00.24737 and earlier and Citrix MetaFrame Presentation Server client for WinCE before 8.33 allows remote attackers to execute arbitrary code via a long cached icon filename in the InName XML element.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.idefense.com/application/poi/display?id=238&amp;type=vulnerabilities" source="IDEFENSE" patch="1" adv="1">20050426 Citrix Program Neighborhood Agent Buffer Overflow</ref>
      <ref url="http://support.citrix.com/kb/entry.jspa?externalID=CTX105650" source="CONFIRM" patch="1" adv="1">http://support.citrix.com/kb/entry.jspa?externalID=CTX105650</ref>
      <ref url="http://secunia.com/advisories/15108" source="SECUNIA" patch="1" adv="1">15108</ref>
    </refs>
    <vuln_soft>
      <prod vendor="citrix" name="metaframe_client">
        <vers num="8.0" edition="" />
        <vers num="8.0" edition=":win-ce" />
      </prod>
      <prod vendor="citrix" name="program_neighborhood_agent">
        <vers num="8.0" edition="" />
        <vers num="8.0" edition=":win32" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-1079" published="2005-01-10" name="CVE-2004-1079" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Buffer overflow in (1) ncplogin and (2) ncpmap in nwclient.c for ncpfs 2.2.4, and possibly other versions, may allow local users to gain privileges via a long -T option.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/11945" source="BID" patch="1" adv="1">11945</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/18283" source="XF" adv="1">ncpfs-nwclientc-bo(18283)</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200412-09.xml" source="GENTOO">GLSA-200412-09</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2004-November/029563.html" source="FULLDISC">20041129 ncpfs buffer overflow</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/433927/100/0/threaded" source="FEDORA">FLSA:152904</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:028" source="MANDRAKE">MDKSA-2005:028</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110175523207437&amp;w=2" source="BUGTRAQ">20041129 ncpfs buffer overflow</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ncpfs" name="ncpfs">
        <vers num="2.2.1" />
        <vers num="2.2.2" />
        <vers num="2.2.3" />
        <vers num="2.2.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-1080" published="2005-01-10" name="CVE-2004-1080" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">The WINS service (wins.exe) on Microsoft Windows NT Server 4.0, Windows 2000 Server, and Windows Server 2003 allows remote attackers to write to arbitrary memory locations and possibly execute arbitrary code via a modified memory pointer in a WINS replication packet to TCP port 42, aka the "Association Context Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" admin="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/145134" source="CERT-VN" patch="1" adv="1">VU#145134</ref>
      <ref url="http://www.securityfocus.com/bid/11763" source="BID" patch="1" adv="1">11763</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/18259" source="XF" adv="1">wins-memory-pointer-hijack(18259)</ref>
      <ref url="http://xforce.iss.net/xforce/alerts/id/184" source="ISS">20041129 Microsoft WINS Server Vulnerability</ref>
      <ref url="http://www.osvdb.org/12378" source="OSVDB">12378</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/MS04-045.mspx" source="MS">MS04-045</ref>
      <ref url="http://www.immunitysec.com/downloads/instantanea.pdf" source="MISC">http://www.immunitysec.com/downloads/instantanea.pdf</ref>
      <ref url="http://www.ciac.org/ciac/bulletins/p-054.shtml" source="CIAC">P-054</ref>
      <ref url="http://support.microsoft.com/kb/890710" source="MSKB">890710</ref>
      <ref url="http://securitytracker.com/id?1012516" source="SECTRACK">1012516</ref>
      <ref url="http://secunia.com/advisories/13328/" source="SECUNIA">13328</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110150370506704&amp;w=2" source="BUGTRAQ" adv="1">20041126 Immunity, Inc Advisor</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:4831" source="OVAL" sig="1">oval:org.mitre.oval:def:4831</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:4372" source="OVAL" sig="1">oval:org.mitre.oval:def:4372</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:3677" source="OVAL" sig="1">oval:org.mitre.oval:def:3677</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2734" source="OVAL" sig="1">oval:org.mitre.oval:def:2734</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2541" source="OVAL" sig="1">oval:org.mitre.oval:def:2541</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1549" source="OVAL" sig="1">oval:org.mitre.oval:def:1549</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_2000">
        <vers num="" edition=":advanced_server" />
        <vers num="" edition=":datacenter_server" />
        <vers num="" edition=":server" />
        <vers num="" edition="sp1" />
        <vers num="" edition="sp1:datacenter_server" />
        <vers num="" edition="sp1:server" />
        <vers num="" edition="sp1:advanced_server" />
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:advanced_server" />
        <vers num="" edition="sp2:datacenter_server" />
        <vers num="" edition="sp2:server" />
        <vers num="" edition="sp3" />
        <vers num="" edition="sp3:datacenter_server" />
        <vers num="" edition="sp3:server" />
        <vers num="" edition="sp3:advanced_server" />
        <vers num="" edition="sp4" />
        <vers num="" edition="sp4:server" />
        <vers num="" edition="sp4:datacenter_server" />
        <vers num="" edition="sp4:advanced_server" />
      </prod>
      <prod vendor="microsoft" name="windows_2003_server">
        <vers num="2000" edition="" />
        <vers num="2000" edition=":small_business_server" />
        <vers num="2003" edition="" />
        <vers num="2003" edition=":small_business_server" />
        <vers num="enterprise" edition="" />
        <vers num="enterprise" edition=":64-bit" />
        <vers num="enterprise_64-bit" />
        <vers num="r2" edition="" />
        <vers num="r2" edition=":64-bit" />
        <vers num="r2" edition=":datacenter_64-bit" />
        <vers num="standard" edition="" />
        <vers num="standard" edition=":64-bit" />
        <vers num="web" />
      </prod>
      <prod vendor="microsoft" name="windows_nt">
        <vers num="4.0" edition="" />
        <vers num="4.0" edition=":terminal_server" />
        <vers num="4.0" edition=":server" />
        <vers num="4.0" edition=":enterprise_server" />
        <vers num="4.0" edition="sp1" />
        <vers num="4.0" edition="sp1:server" />
        <vers num="4.0" edition="sp1:enterprise_server" />
        <vers num="4.0" edition="sp1:terminal_server" />
        <vers num="4.0" edition="sp2" />
        <vers num="4.0" edition="sp2:enterprise_server" />
        <vers num="4.0" edition="sp2:server" />
        <vers num="4.0" edition="sp2:terminal_server" />
        <vers num="4.0" edition="sp3" />
        <vers num="4.0" edition="sp3:enterprise_server" />
        <vers num="4.0" edition="sp3:server" />
        <vers num="4.0" edition="sp3:terminal_server" />
        <vers num="4.0" edition="sp4" />
        <vers num="4.0" edition="sp4:enterprise_server" />
        <vers num="4.0" edition="sp4:terminal_server" />
        <vers num="4.0" edition="sp4:server" />
        <vers num="4.0" edition="sp5" />
        <vers num="4.0" edition="sp5:enterprise_server" />
        <vers num="4.0" edition="sp5:server" />
        <vers num="4.0" edition="sp5:terminal_server" />
        <vers num="4.0" edition="sp6" />
        <vers num="4.0" edition="sp6:enterprise_server" />
        <vers num="4.0" edition="sp6:terminal_server" />
        <vers num="4.0" edition="sp6:server" />
        <vers num="4.0" edition="sp6a" />
        <vers num="4.0" edition="sp6a:enterprise_server" />
        <vers num="4.0" edition="sp6a:terminal_server" />
        <vers num="4.0" edition="sp6a:server" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2004-1081" published="2004-12-02" name="CVE-2004-1081" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">The Application Framework (AppKit) for Apple Mac OS X 10.2.8 and 10.3.6 does not properly restrict access to a secure text input field, which allows local users to read keyboard input from other applications within the same window session.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <access />
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/11802" source="BID" patch="1" adv="1">11802</ref>
      <ref url="http://www.ciac.org/ciac/bulletins/p-049.shtml" source="CIAC" patch="1" adv="1">P-049</ref>
      <ref url="http://secunia.com/advisories/13362/" source="SECUNIA" patch="1" adv="1">13362</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2004/Dec/msg00000.html" source="APPLE" patch="1" adv="1">APPLE-SA-2004-12-02</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/18350" source="XF" adv="1">macos-appkit-obtain-info(18350)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="darwin_streaming_server">
        <vers num="4.1.3" />
        <vers num="5.0.1" />
      </prod>
      <prod vendor="apple" name="quicktime_streaming_server">
        <vers num="4.1.1" />
      </prod>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.2" />
        <vers num="10.2.1" />
        <vers num="10.2.2" />
        <vers num="10.2.3" />
        <vers num="10.2.4" />
        <vers num="10.2.5" />
        <vers num="10.2.6" />
        <vers num="10.2.7" />
        <vers num="10.2.8" />
        <vers num="10.3" />
        <vers num="10.3.1" />
        <vers num="10.3.2" />
        <vers num="10.3.3" />
        <vers num="10.3.4" />
        <vers num="10.3.5" />
        <vers num="10.3.6" />
      </prod>
      <prod vendor="apple" name="mac_os_x_server">
        <vers num="10.2" />
        <vers num="10.2.1" />
        <vers num="10.2.2" />
        <vers num="10.2.3" />
        <vers num="10.2.4" />
        <vers num="10.2.5" />
        <vers num="10.2.6" />
        <vers num="10.2.7" />
        <vers num="10.2.8" />
        <vers num="10.3" />
        <vers num="10.3.1" />
        <vers num="10.3.2" />
        <vers num="10.3.3" />
        <vers num="10.3.4" />
        <vers num="10.3.5" />
        <vers num="10.3.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-1082" published="2004-02-03" name="CVE-2004-1082" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">mod_digest_apple for Apache 1.3.31 and 1.3.32 on Mac OS X Server does not properly verify the nonce of a client response, which allows remote attackers to replay credentials.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/18347" source="XF" patch="1" adv="1">macos-moddigest-response-replay(18347)</ref>
      <ref url="http://www.securitytracker.com/alerts/2004/Dec/1012414.html" source="SECTRACK" patch="1" adv="1">1012414</ref>
      <ref url="http://www.securityfocus.com/bid/9571" source="BID" patch="1" adv="1">9571</ref>
      <ref url="http://www.ciac.org/ciac/bulletins/p-049.shtml" source="CIAC" patch="1" adv="1">P-049</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2004/Dec/msg00000.html" source="APPLE" patch="1" adv="1">APPLE-SA-2004-12-02</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apache" name="http_server">
        <vers num="1.3" />
        <vers num="1.3.1" />
        <vers num="1.3.11" />
        <vers num="1.3.12" />
        <vers num="1.3.14" />
        <vers num="1.3.17" />
        <vers num="1.3.18" />
        <vers num="1.3.19" />
        <vers num="1.3.20" />
        <vers num="1.3.22" />
        <vers num="1.3.23" />
        <vers num="1.3.24" />
        <vers num="1.3.25" />
        <vers num="1.3.26" />
        <vers num="1.3.27" />
        <vers num="1.3.28" />
        <vers num="1.3.29" />
        <vers num="1.3.3" />
        <vers num="1.3.4" />
        <vers num="1.3.6" />
        <vers num="1.3.7" edition="" />
        <vers num="1.3.7" edition=":dev" />
        <vers num="1.3.9" />
      </prod>
      <prod vendor="apple" name="apache_mod_digest_apple">
        <vers num="" />
      </prod>
      <prod vendor="avaya" name="communication_manager">
        <vers num="1.1" />
        <vers num="1.3.1" />
        <vers num="2.0" />
        <vers num="2.0.1" />
      </prod>
      <prod vendor="avaya" name="intuity_audix_lx">
        <vers num="" />
      </prod>
      <prod vendor="avaya" name="mn100">
        <vers num="" />
      </prod>
      <prod vendor="avaya" name="network_routing">
        <vers num="" />
      </prod>
      <prod vendor="hp" name="virtualvault">
        <vers num="4.5" />
        <vers num="4.6" />
        <vers num="4.7" />
      </prod>
      <prod vendor="hp" name="webproxy">
        <vers num="a.02.00" />
        <vers num="a.02.10" />
      </prod>
      <prod vendor="ibm" name="http_server">
        <vers num="1.3.19" />
      </prod>
      <prod vendor="avaya" name="modular_messaging_message_storage_server">
        <vers num="1.1" />
        <vers num="2.0" />
      </prod>
      <prod vendor="openbsd" name="openbsd">
        <vers num="3.4" />
        <vers num="3.5" />
        <vers num="current" />
      </prod>
      <prod vendor="sco" name="openserver">
        <vers num="5.0.6" />
        <vers num="5.0.7" />
      </prod>
      <prod vendor="sun" name="solaris">
        <vers num="8.0" edition="" />
        <vers num="8.0" edition=":x86" />
        <vers num="9.0" edition="" />
        <vers num="9.0" edition=":sparc" />
        <vers num="9.0" edition=":x86" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1083" published="2004-12-03" name="CVE-2004-1083" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Apache for Apple Mac OS X 10.2.8 and 10.3.6 restricts access to files in a case sensitive manner, but the Apple HFS+ filesystem accesses files in a case insensitive manner, which allows remote attackers to read .DS_Store files and files beginning with ".ht" using alternate capitalization.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/18348" source="XF" patch="1" adv="1">apache-hfs-file-disclosure(18348)</ref>
      <ref url="http://www.ciac.org/ciac/bulletins/p-049.shtml" source="CIAC" patch="1" adv="1">P-049</ref>
      <ref url="http://secunia.com/advisories/13362/" source="SECUNIA" patch="1" adv="1">13362</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2004/Dec/msg00000.html" source="APPLE" patch="1" adv="1">APPLE-SA-2004-12-02</ref>
      <ref url="http://www.securityfocus.com/bid/11802" source="BID">11802</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2005/Aug/msg00000.html" source="APPLE">APPLE-SA-2005-08-15</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2005//Aug/msg00001.html" source="APPLE">APPLE-SA-2005-08-17</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="darwin_streaming_server">
        <vers num="4.1.3" />
        <vers num="5.0.1" />
      </prod>
      <prod vendor="apple" name="quicktime_streaming_server">
        <vers num="4.1.1" />
      </prod>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.2" />
        <vers num="10.2.1" />
        <vers num="10.2.2" />
        <vers num="10.2.3" />
        <vers num="10.2.4" />
        <vers num="10.2.5" />
        <vers num="10.2.6" />
        <vers num="10.2.7" />
        <vers num="10.2.8" />
        <vers num="10.3" />
        <vers num="10.3.1" />
        <vers num="10.3.2" />
        <vers num="10.3.3" />
        <vers num="10.3.4" />
        <vers num="10.3.5" />
        <vers num="10.3.6" />
      </prod>
      <prod vendor="apple" name="mac_os_x_server">
        <vers num="10.2" />
        <vers num="10.2.1" />
        <vers num="10.2.2" />
        <vers num="10.2.3" />
        <vers num="10.2.4" />
        <vers num="10.2.5" />
        <vers num="10.2.6" />
        <vers num="10.2.7" />
        <vers num="10.2.8" />
        <vers num="10.3" />
        <vers num="10.3.1" />
        <vers num="10.3.2" />
        <vers num="10.3.3" />
        <vers num="10.3.4" />
        <vers num="10.3.5" />
        <vers num="10.3.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1084" published="2004-12-02" name="CVE-2004-1084" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Apache for Apple Mac OS X 10.2.8 and 10.3.6 allows remote attackers to read files and resource fork content via HTTP requests to certain special file names related to multiple data streams in HFS+, which bypass Apache file handles.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/18349" source="XF" patch="1" adv="1">apache-hfs-obtain-info(18349)</ref>
      <ref url="http://www.ciac.org/ciac/bulletins/p-049.shtml" source="CIAC" patch="1" adv="1">P-049</ref>
      <ref url="http://secunia.com/advisories/13362/" source="SECUNIA" patch="1" adv="1">13362</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2004/Dec/msg00000.html" source="APPLE" patch="1" adv="1">APPLE-SA-2004-12-02</ref>
      <ref url="http://www.securityfocus.com/bid/11802" source="BID">11802</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2005/Aug/msg00000.html" source="APPLE">APPLE-SA-2005-08-15</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2005//Aug/msg00001.html" source="APPLE">APPLE-SA-2005-08-17</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="darwin_streaming_server">
        <vers num="4.1.3" />
        <vers num="5.0.1" />
      </prod>
      <prod vendor="apple" name="quicktime_streaming_server">
        <vers num="4.1.1" />
      </prod>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.2" />
        <vers num="10.2.1" />
        <vers num="10.2.2" />
        <vers num="10.2.3" />
        <vers num="10.2.4" />
        <vers num="10.2.5" />
        <vers num="10.2.6" />
        <vers num="10.2.7" />
        <vers num="10.2.8" />
        <vers num="10.3" />
        <vers num="10.3.1" />
        <vers num="10.3.2" />
        <vers num="10.3.3" />
        <vers num="10.3.4" />
        <vers num="10.3.5" />
        <vers num="10.3.6" />
      </prod>
      <prod vendor="apple" name="mac_os_x_server">
        <vers num="10.2" />
        <vers num="10.2.1" />
        <vers num="10.2.2" />
        <vers num="10.2.3" />
        <vers num="10.2.4" />
        <vers num="10.2.5" />
        <vers num="10.2.6" />
        <vers num="10.2.7" />
        <vers num="10.2.8" />
        <vers num="10.3" />
        <vers num="10.3.1" />
        <vers num="10.3.2" />
        <vers num="10.3.3" />
        <vers num="10.3.4" />
        <vers num="10.3.5" />
        <vers num="10.3.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2004-1085" published="2004-12-02" name="CVE-2004-1085" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">Human Interface Toolbox (HIToolBox) for Apple Mac 0S X 10.3.6 allows local users to exit applications via the force-quit key combination, even when the system is running in kiosk mode.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/18352" source="XF" patch="1" adv="1">macos-hitoolbox-kiosk-dos(18352)</ref>
      <ref url="http://www.ciac.org/ciac/bulletins/p-049.shtml" source="CIAC" patch="1" adv="1">P-049</ref>
      <ref url="http://secunia.com/advisories/13362/" source="SECUNIA" patch="1" adv="1">13362</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2004/Dec/msg00000.html" source="APPLE" patch="1" adv="1">APPLE-SA-2004-12-02</ref>
      <ref url="http://www.securityfocus.com/bid/11802" source="BID">11802</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="darwin_streaming_server">
        <vers num="4.1.3" />
        <vers num="5.0.1" />
      </prod>
      <prod vendor="apple" name="quicktime_streaming_server">
        <vers num="4.1.1" />
      </prod>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.2" />
        <vers num="10.2.1" />
        <vers num="10.2.2" />
        <vers num="10.2.3" />
        <vers num="10.2.4" />
        <vers num="10.2.5" />
        <vers num="10.2.6" />
        <vers num="10.2.7" />
        <vers num="10.2.8" />
        <vers num="10.3" />
        <vers num="10.3.1" />
        <vers num="10.3.2" />
        <vers num="10.3.3" />
        <vers num="10.3.4" />
        <vers num="10.3.5" />
        <vers num="10.3.6" />
      </prod>
      <prod vendor="apple" name="mac_os_x_server">
        <vers num="10.2" />
        <vers num="10.2.1" />
        <vers num="10.2.2" />
        <vers num="10.2.3" />
        <vers num="10.2.4" />
        <vers num="10.2.5" />
        <vers num="10.2.6" />
        <vers num="10.2.7" />
        <vers num="10.2.8" />
        <vers num="10.3" />
        <vers num="10.3.1" />
        <vers num="10.3.2" />
        <vers num="10.3.3" />
        <vers num="10.3.4" />
        <vers num="10.3.5" />
        <vers num="10.3.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-1086" published="2004-12-02" name="CVE-2004-1086" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in PSNormalizer for Apple Mac OS X 10.3.6 allows remote attackers to execute arbitrary code via a crafted PostScript input file.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/18354" source="XF" patch="1" adv="1">macos-psnormalizer-bo(18354)</ref>
      <ref url="http://www.ciac.org/ciac/bulletins/p-049.shtml" source="CIAC" patch="1" adv="1">P-049</ref>
      <ref url="http://secunia.com/advisories/13362/" source="SECUNIA" patch="1" adv="1">13362</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2004/Dec/msg00000.html" source="APPLE" patch="1" adv="1">APPLE-SA-2004-12-02</ref>
      <ref url="http://www.securityfocus.com/bid/11802" source="BID">11802</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="darwin_streaming_server">
        <vers num="4.1.3" />
        <vers num="5.0.1" />
      </prod>
      <prod vendor="apple" name="quicktime_streaming_server">
        <vers num="4.1.1" />
      </prod>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.2" />
        <vers num="10.2.1" />
        <vers num="10.2.2" />
        <vers num="10.2.3" />
        <vers num="10.2.4" />
        <vers num="10.2.5" />
        <vers num="10.2.6" />
        <vers num="10.2.7" />
        <vers num="10.2.8" />
        <vers num="10.3" />
        <vers num="10.3.1" />
        <vers num="10.3.2" />
        <vers num="10.3.3" />
        <vers num="10.3.4" />
        <vers num="10.3.5" />
        <vers num="10.3.6" />
      </prod>
      <prod vendor="apple" name="mac_os_x_server">
        <vers num="10.2" />
        <vers num="10.2.1" />
        <vers num="10.2.2" />
        <vers num="10.2.3" />
        <vers num="10.2.4" />
        <vers num="10.2.5" />
        <vers num="10.2.6" />
        <vers num="10.2.7" />
        <vers num="10.2.8" />
        <vers num="10.3" />
        <vers num="10.3.1" />
        <vers num="10.3.2" />
        <vers num="10.3.3" />
        <vers num="10.3.4" />
        <vers num="10.3.5" />
        <vers num="10.3.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2004-1087" published="2004-12-02" name="CVE-2004-1087" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">Terminal for Apple Mac OS X 10.3.6 may indicate that "Secure Keyboard Entry" is enabled even when it is not, which could result in a false sense of security for the user.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/18355" source="XF" patch="1" adv="1">macos-terminal-secure-improper(18355)</ref>
      <ref url="http://www.ciac.org/ciac/bulletins/p-049.shtml" source="CIAC" patch="1" adv="1">P-049</ref>
      <ref url="http://secunia.com/advisories/13362/" source="SECUNIA" patch="1" adv="1">13362</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2004/Dec/msg00000.html" source="APPLE" patch="1" adv="1">APPLE-SA-2004-12-02</ref>
      <ref url="http://www.securityfocus.com/bid/11802" source="BID">11802</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="darwin_streaming_server">
        <vers num="4.1.3" />
        <vers num="5.0.1" />
      </prod>
      <prod vendor="apple" name="quicktime_streaming_server">
        <vers num="4.1.1" />
      </prod>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.2" />
        <vers num="10.2.1" />
        <vers num="10.2.2" />
        <vers num="10.2.3" />
        <vers num="10.2.4" />
        <vers num="10.2.5" />
        <vers num="10.2.6" />
        <vers num="10.2.7" />
        <vers num="10.2.8" />
        <vers num="10.3" />
        <vers num="10.3.1" />
        <vers num="10.3.2" />
        <vers num="10.3.3" />
        <vers num="10.3.4" />
        <vers num="10.3.5" />
        <vers num="10.3.6" />
      </prod>
      <prod vendor="apple" name="mac_os_x_server">
        <vers num="10.2" />
        <vers num="10.2.1" />
        <vers num="10.2.2" />
        <vers num="10.2.3" />
        <vers num="10.2.4" />
        <vers num="10.2.5" />
        <vers num="10.2.6" />
        <vers num="10.2.7" />
        <vers num="10.2.8" />
        <vers num="10.3" />
        <vers num="10.3.1" />
        <vers num="10.3.2" />
        <vers num="10.3.3" />
        <vers num="10.3.4" />
        <vers num="10.3.5" />
        <vers num="10.3.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-1088" published="2004-12-02" name="CVE-2004-1088" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Postfix server for Apple Mac OS X 10.3.6, when using CRAM-MD5, allows remote attackers to send mail without authentication by replaying authentication information.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/18353" source="XF" patch="1" adv="1">postfix-crammd5-auth-replay(18353)</ref>
      <ref url="http://www.ciac.org/ciac/bulletins/p-049.shtml" source="CIAC" patch="1" adv="1">P-049</ref>
      <ref url="http://secunia.com/advisories/13362/" source="SECUNIA" patch="1" adv="1">13362</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2004/Dec/msg00000.html" source="APPLE" patch="1" adv="1">APPLE-SA-2004-12-02</ref>
      <ref url="http://www.securityfocus.com/bid/11802" source="BID">11802</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="darwin_streaming_server">
        <vers num="4.1.3" />
        <vers num="5.0.1" />
      </prod>
      <prod vendor="apple" name="quicktime_streaming_server">
        <vers num="4.1.1" />
      </prod>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.2" />
        <vers num="10.2.1" />
        <vers num="10.2.2" />
        <vers num="10.2.3" />
        <vers num="10.2.4" />
        <vers num="10.2.5" />
        <vers num="10.2.6" />
        <vers num="10.2.7" />
        <vers num="10.2.8" />
        <vers num="10.3" />
        <vers num="10.3.1" />
        <vers num="10.3.2" />
        <vers num="10.3.3" />
        <vers num="10.3.4" />
        <vers num="10.3.5" />
        <vers num="10.3.6" />
      </prod>
      <prod vendor="apple" name="mac_os_x_server">
        <vers num="10.2" />
        <vers num="10.2.1" />
        <vers num="10.2.2" />
        <vers num="10.2.3" />
        <vers num="10.2.4" />
        <vers num="10.2.5" />
        <vers num="10.2.6" />
        <vers num="10.2.7" />
        <vers num="10.2.8" />
        <vers num="10.3" />
        <vers num="10.3.1" />
        <vers num="10.3.2" />
        <vers num="10.3.3" />
        <vers num="10.3.4" />
        <vers num="10.3.5" />
        <vers num="10.3.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1089" published="2004-12-02" name="CVE-2004-1089" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Unknown vulnerability in Apple Mac OS X 10.3.6 server, when using Kerberos authentication and Cyrus IMAP allows local users to access mailboxes of other users.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/18351" source="XF" patch="1" adv="1">cyrus-kerberos-gain-access(18351)</ref>
      <ref url="http://www.ciac.org/ciac/bulletins/p-049.shtml" source="CIAC" patch="1" adv="1">P-049</ref>
      <ref url="http://secunia.com/advisories/13362/" source="SECUNIA" patch="1" adv="1">13362</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2004/Dec/msg00000.html" source="APPLE" patch="1" adv="1">APPLE-SA-2004-12-02</ref>
      <ref url="http://www.securityfocus.com/bid/11802" source="BID">11802</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="darwin_streaming_server">
        <vers num="4.1.3" />
        <vers num="5.0.1" />
      </prod>
      <prod vendor="apple" name="quicktime_streaming_server">
        <vers num="4.1.1" />
      </prod>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.2" />
        <vers num="10.2.1" />
        <vers num="10.2.2" />
        <vers num="10.2.3" />
        <vers num="10.2.4" />
        <vers num="10.2.5" />
        <vers num="10.2.6" />
        <vers num="10.2.7" />
        <vers num="10.2.8" />
        <vers num="10.3" />
        <vers num="10.3.1" />
        <vers num="10.3.2" />
        <vers num="10.3.3" />
        <vers num="10.3.4" />
        <vers num="10.3.5" />
        <vers num="10.3.6" />
      </prod>
      <prod vendor="apple" name="mac_os_x_server">
        <vers num="10.2" />
        <vers num="10.2.1" />
        <vers num="10.2.2" />
        <vers num="10.2.3" />
        <vers num="10.2.4" />
        <vers num="10.2.5" />
        <vers num="10.2.6" />
        <vers num="10.2.7" />
        <vers num="10.2.8" />
        <vers num="10.3" />
        <vers num="10.3.1" />
        <vers num="10.3.2" />
        <vers num="10.3.3" />
        <vers num="10.3.4" />
        <vers num="10.3.5" />
        <vers num="10.3.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1090" published="2005-04-14" name="CVE-2004-1090" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Midnight commander (mc) 4.5.55 and earlier allows remote attackers to cause a denial of service via "a corrupt section header."</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <other />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.debian.org/security/2005/dsa-639" source="DEBIAN" patch="1" adv="1">DSA-639</ref>
      <ref url="http://secunia.com/advisories/13863/" source="SECUNIA" patch="1" adv="1">13863</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/18907" source="XF">midnight-commander-section-dos(18907)</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-512.html" source="REDHAT">RHSA-2005:512</ref>
    </refs>
    <vuln_soft>
      <prod vendor="midnight_commander" name="midnight_commander">
        <vers num="4.5.40" />
        <vers num="4.5.41" />
        <vers num="4.5.42" />
        <vers num="4.5.43" />
        <vers num="4.5.44" />
        <vers num="4.5.45" />
        <vers num="4.5.46" />
        <vers num="4.5.47" />
        <vers num="4.5.48" />
        <vers num="4.5.49" />
        <vers num="4.5.50" />
        <vers num="4.5.51" />
        <vers num="4.5.52" />
        <vers num="4.5.54" />
        <vers num="4.5.55" />
        <vers num="4.6" />
      </prod>
      <prod vendor="debian" name="debian_linux">
        <vers num="3.0" edition="" />
        <vers num="3.0" edition=":mips" />
        <vers num="3.0" edition=":ia-32" />
        <vers num="3.0" edition=":s-390" />
        <vers num="3.0" edition=":alpha" />
        <vers num="3.0" edition=":arm" />
        <vers num="3.0" edition=":mipsel" />
        <vers num="3.0" edition=":ppc" />
        <vers num="3.0" edition=":hppa" />
        <vers num="3.0" edition=":m68k" />
        <vers num="3.0" edition=":ia-64" />
        <vers num="3.0" edition=":sparc" />
      </prod>
      <prod vendor="gentoo" name="linux">
        <vers num="" />
      </prod>
      <prod vendor="redhat" name="enterprise_linux">
        <vers num="2.1" edition="" />
        <vers num="2.1" edition=":workstation_ia64" />
        <vers num="2.1" edition=":advanced_server" />
        <vers num="2.1" edition=":advanced_server_ia64" />
        <vers num="2.1" edition=":workstation" />
      </prod>
      <prod vendor="redhat" name="linux_advanced_workstation">
        <vers num="2.1" edition="" />
        <vers num="2.1" edition=":itanium_processor" />
        <vers num="2.1" edition=":ia64" />
      </prod>
      <prod vendor="suse" name="suse_linux">
        <vers num="8.0" edition="" />
        <vers num="8.0" edition=":i386" />
        <vers num="8.1" />
        <vers num="8.2" />
        <vers num="9.0" edition="" />
        <vers num="9.0" edition=":x86_64" />
        <vers num="9.1" />
        <vers num="9.2" />
      </prod>
      <prod vendor="turbolinux" name="turbolinux_server">
        <vers num="7.0" />
        <vers num="8.0" />
      </prod>
      <prod vendor="turbolinux" name="turbolinux_workstation">
        <vers num="7.0" />
        <vers num="8.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1091" published="2005-04-14" name="CVE-2004-1091" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Midnight commander (mc) 4.5.55 and earlier allows remote attackers to cause a denial of service by triggering a null dereference.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <other />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.debian.org/security/2005/dsa-639" source="DEBIAN" patch="1" adv="1">DSA-639</ref>
      <ref url="http://secunia.com/advisories/13863" source="SECUNIA" patch="1" adv="1">13863</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/18908" source="XF">midnight-commander-find-dos(18908)</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-512.html" source="REDHAT">RHSA-2005:512</ref>
    </refs>
    <vuln_soft>
      <prod vendor="midnight_commander" name="midnight_commander">
        <vers num="4.5.40" />
        <vers num="4.5.41" />
        <vers num="4.5.42" />
        <vers num="4.5.43" />
        <vers num="4.5.44" />
        <vers num="4.5.45" />
        <vers num="4.5.46" />
        <vers num="4.5.47" />
        <vers num="4.5.48" />
        <vers num="4.5.49" />
        <vers num="4.5.50" />
        <vers num="4.5.51" />
        <vers num="4.5.52" />
        <vers num="4.5.54" />
        <vers num="4.5.55" />
        <vers num="4.6" />
      </prod>
      <prod vendor="debian" name="debian_linux">
        <vers num="3.0" edition="" />
        <vers num="3.0" edition=":mips" />
        <vers num="3.0" edition=":ia-32" />
        <vers num="3.0" edition=":s-390" />
        <vers num="3.0" edition=":alpha" />
        <vers num="3.0" edition=":arm" />
        <vers num="3.0" edition=":mipsel" />
        <vers num="3.0" edition=":ppc" />
        <vers num="3.0" edition=":hppa" />
        <vers num="3.0" edition=":m68k" />
        <vers num="3.0" edition=":ia-64" />
        <vers num="3.0" edition=":sparc" />
      </prod>
      <prod vendor="gentoo" name="linux">
        <vers num="" />
      </prod>
      <prod vendor="redhat" name="enterprise_linux">
        <vers num="2.1" edition="" />
        <vers num="2.1" edition=":workstation_ia64" />
        <vers num="2.1" edition=":advanced_server" />
        <vers num="2.1" edition=":advanced_server_ia64" />
        <vers num="2.1" edition=":workstation" />
      </prod>
      <prod vendor="redhat" name="linux_advanced_workstation">
        <vers num="2.1" edition="" />
        <vers num="2.1" edition=":itanium_processor" />
        <vers num="2.1" edition=":ia64" />
      </prod>
      <prod vendor="suse" name="suse_linux">
        <vers num="8.0" edition="" />
        <vers num="8.0" edition=":i386" />
        <vers num="8.1" />
        <vers num="8.2" />
        <vers num="9.0" edition="" />
        <vers num="9.0" edition=":x86_64" />
        <vers num="9.1" />
        <vers num="9.2" />
      </prod>
      <prod vendor="turbolinux" name="turbolinux_server">
        <vers num="7.0" />
        <vers num="8.0" />
      </prod>
      <prod vendor="turbolinux" name="turbolinux_workstation">
        <vers num="7.0" />
        <vers num="8.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1092" published="2005-04-14" name="CVE-2004-1092" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Midnight commander (mc) 4.5.55 and earlier allows remote attackers to cause a denial of service by causing mc to free unallocated memory.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <other />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.debian.org/security/2005/dsa-639" source="DEBIAN" patch="1" adv="1">DSA-639</ref>
      <ref url="http://secunia.com/advisories/13863/" source="SECUNIA" patch="1" adv="1">13863</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/18904" source="XF">midnight-commander-memory-allocation(18904)</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200502-24.xml" source="GENTOO">GLSA-200502-24</ref>
    </refs>
    <vuln_soft>
      <prod vendor="midnight_commander" name="midnight_commander">
        <vers num="4.5.40" />
        <vers num="4.5.41" />
        <vers num="4.5.42" />
        <vers num="4.5.43" />
        <vers num="4.5.44" />
        <vers num="4.5.45" />
        <vers num="4.5.46" />
        <vers num="4.5.47" />
        <vers num="4.5.48" />
        <vers num="4.5.49" />
        <vers num="4.5.50" />
        <vers num="4.5.51" />
        <vers num="4.5.52" />
        <vers num="4.5.54" />
        <vers num="4.5.55" />
        <vers num="4.6" />
      </prod>
      <prod vendor="debian" name="debian_linux">
        <vers num="3.0" edition="" />
        <vers num="3.0" edition=":mips" />
        <vers num="3.0" edition=":ia-32" />
        <vers num="3.0" edition=":s-390" />
        <vers num="3.0" edition=":alpha" />
        <vers num="3.0" edition=":arm" />
        <vers num="3.0" edition=":mipsel" />
        <vers num="3.0" edition=":ppc" />
        <vers num="3.0" edition=":hppa" />
        <vers num="3.0" edition=":m68k" />
        <vers num="3.0" edition=":ia-64" />
        <vers num="3.0" edition=":sparc" />
      </prod>
      <prod vendor="gentoo" name="linux">
        <vers num="" />
      </prod>
      <prod vendor="redhat" name="enterprise_linux">
        <vers num="2.1" edition="" />
        <vers num="2.1" edition=":workstation_ia64" />
        <vers num="2.1" edition=":advanced_server" />
        <vers num="2.1" edition=":advanced_server_ia64" />
        <vers num="2.1" edition=":workstation" />
      </prod>
      <prod vendor="redhat" name="linux_advanced_workstation">
        <vers num="2.1" edition="" />
        <vers num="2.1" edition=":itanium_processor" />
        <vers num="2.1" edition=":ia64" />
      </prod>
      <prod vendor="suse" name="suse_linux">
        <vers num="8.0" edition="" />
        <vers num="8.0" edition=":i386" />
        <vers num="8.1" />
        <vers num="8.2" />
        <vers num="9.0" edition="" />
        <vers num="9.0" edition=":x86_64" />
        <vers num="9.1" />
        <vers num="9.2" />
      </prod>
      <prod vendor="turbolinux" name="turbolinux_server">
        <vers num="7.0" />
        <vers num="8.0" />
      </prod>
      <prod vendor="turbolinux" name="turbolinux_workstation">
        <vers num="7.0" />
        <vers num="8.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1093" published="2005-04-14" name="CVE-2004-1093" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Midnight commander (mc) 4.5.55 and earlier allows remote attackers to cause a denial of service via "use of already freed memory."</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <other />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.debian.org/security/2005/dsa-639" source="DEBIAN" patch="1" adv="1">DSA-639</ref>
      <ref url="http://secunia.com/advisories/13863/" source="SECUNIA" patch="1" adv="1">13863</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/18905" source="XF">midnight-commander-key-dos(18905)</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-512.html" source="REDHAT">RHSA-2005:512</ref>
    </refs>
    <vuln_soft>
      <prod vendor="midnight_commander" name="midnight_commander">
        <vers num="4.5.40" />
        <vers num="4.5.41" />
        <vers num="4.5.42" />
        <vers num="4.5.43" />
        <vers num="4.5.44" />
        <vers num="4.5.45" />
        <vers num="4.5.46" />
        <vers num="4.5.47" />
        <vers num="4.5.48" />
        <vers num="4.5.49" />
        <vers num="4.5.50" />
        <vers num="4.5.51" />
        <vers num="4.5.52" />
        <vers num="4.5.54" />
        <vers num="4.5.55" />
        <vers num="4.6" />
      </prod>
      <prod vendor="debian" name="debian_linux">
        <vers num="3.0" edition="" />
        <vers num="3.0" edition=":mips" />
        <vers num="3.0" edition=":ia-32" />
        <vers num="3.0" edition=":s-390" />
        <vers num="3.0" edition=":alpha" />
        <vers num="3.0" edition=":arm" />
        <vers num="3.0" edition=":mipsel" />
        <vers num="3.0" edition=":ppc" />
        <vers num="3.0" edition=":hppa" />
        <vers num="3.0" edition=":m68k" />
        <vers num="3.0" edition=":ia-64" />
        <vers num="3.0" edition=":sparc" />
      </prod>
      <prod vendor="gentoo" name="linux">
        <vers num="" />
      </prod>
      <prod vendor="redhat" name="enterprise_linux">
        <vers num="2.1" edition="" />
        <vers num="2.1" edition=":workstation_ia64" />
        <vers num="2.1" edition=":advanced_server" />
        <vers num="2.1" edition=":advanced_server_ia64" />
        <vers num="2.1" edition=":workstation" />
      </prod>
      <prod vendor="redhat" name="linux_advanced_workstation">
        <vers num="2.1" edition="" />
        <vers num="2.1" edition=":itanium_processor" />
        <vers num="2.1" edition=":ia64" />
      </prod>
      <prod vendor="suse" name="suse_linux">
        <vers num="8.0" edition="" />
        <vers num="8.0" edition=":i386" />
        <vers num="8.1" />
        <vers num="8.2" />
        <vers num="9.0" edition="" />
        <vers num="9.0" edition=":x86_64" />
        <vers num="9.1" />
        <vers num="9.2" />
      </prod>
      <prod vendor="turbolinux" name="turbolinux_server">
        <vers num="7.0" />
        <vers num="8.0" />
      </prod>
      <prod vendor="turbolinux" name="turbolinux_workstation">
        <vers num="7.0" />
        <vers num="8.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-1094" published="2005-01-10" name="CVE-2004-1094" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Buffer overflow in InnerMedia DynaZip DUNZIP32.dll file version 5.00.03 and earlier allows remote attackers to execute arbitrary code via a ZIP file containing a file with a long filename, as demonstrated using (1) a .rjs (skin) file in RealPlayer 10 through RealPlayer 10.5 (6.0.12.1053), RealOne Player 1 and 2, (2) the Restore Backup function in CheckMark Software Payroll 2004/2005 3.9.6 and earlier, (3) CheckMark MultiLedger before 7.0.2, (4) dtSearch 6.x and 7.x, (5) mcupdmgr.exe and mghtml.exe in McAfee VirusScan 10 Build 10.0.21 and earlier, (6) IBM Lotus Notes before 6.5.5, and other products.  NOTE: it is unclear whether this is the same vulnerability as CVE-2004-0575, although the data manipulations are the same.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/582498" source="CERT-VN" adv="1">VU#582498</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109894226007607&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20041027 High Risk Vulnerability in RealPlayer</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/22737" source="XF">payroll-dunzip32-bo(22737)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/17879" source="XF" adv="1">realplayer-dunzip32-bo(17879)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1176" source="VUPEN">ADV-2006-1176</ref>
      <ref url="http://www.vupen.com/english/advisories/2005/2057" source="VUPEN">ADV-2005-2057</ref>
      <ref url="http://www.securityfocus.com/bid/11555" source="BID" adv="1">11555</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/445369/100/0/threaded" source="BUGTRAQ">20060906 IBM Lotus Notes DUNZIP32.dll Buffer Overflow Vulnerability</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/429361/100/0/threaded" source="BUGTRAQ">20060330 McAfee VirusScan DUNZIP32.dll Buffer Overflow Vulnerability</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/420274/100/0/threaded" source="BUGTRAQ">20051223 dtSearch DUNZIP32.dll Buffer Overflow Vulnerability</ref>
      <ref url="http://www.securiteam.com/windowsntfocus/6Z00W00EAM.html" source="MISC">http://www.securiteam.com/windowsntfocus/6Z00W00EAM.html</ref>
      <ref url="http://www.osvdb.org/19906" source="OSVDB">19906</ref>
      <ref url="http://www.networksecurity.fi/advisories/payroll.html" source="MISC">http://www.networksecurity.fi/advisories/payroll.html</ref>
      <ref url="http://www.networksecurity.fi/advisories/multiledger.html" source="MISC">http://www.networksecurity.fi/advisories/multiledger.html</ref>
      <ref url="http://www.networksecurity.fi/advisories/mcafee-virusscan.html" source="MISC">http://www.networksecurity.fi/advisories/mcafee-virusscan.html</ref>
      <ref url="http://www.networksecurity.fi/advisories/lotus-notes.html" source="MISC">http://www.networksecurity.fi/advisories/lotus-notes.html</ref>
      <ref url="http://www.networksecurity.fi/advisories/dtsearch.html" source="MISC" adv="1">http://www.networksecurity.fi/advisories/dtsearch.html</ref>
      <ref url="http://service.real.com/help/faq/security/041026_player/EN/" source="CONFIRM">http://service.real.com/help/faq/security/041026_player/EN/</ref>
      <ref url="http://securitytracker.com/id?1016817" source="SECTRACK">1016817</ref>
      <ref url="http://securitytracker.com/id?1012297" source="SECTRACK">1012297</ref>
      <ref url="http://securitytracker.com/id?1011944" source="SECTRACK">1011944</ref>
      <ref url="http://secunia.com/advisories/19451" source="SECUNIA">19451</ref>
      <ref url="http://secunia.com/advisories/18194" source="SECUNIA" adv="1">18194</ref>
      <ref url="http://secunia.com/advisories/17394" source="SECUNIA" adv="1">17394</ref>
      <ref url="http://secunia.com/advisories/17096" source="SECUNIA" adv="1">17096</ref>
      <ref url="http://archives.neohapsis.com/archives/fulldisclosure/2004-10/1044.html" source="BUGTRAQ">20041027 EEYE: RealPlayer Zipped Skin File Buffer Overflow</ref>
      <ref url="http://securityreason.com/securityalert/653" source="SREASON">653</ref>
      <ref url="http://securityreason.com/securityalert/296" source="SREASON">296</ref>
    </refs>
    <vuln_soft>
      <prod vendor="checkmark" name="checkmark_payroll">
        <vers num="3.7.5" />
        <vers num="3.9.1" />
        <vers num="3.9.2" />
        <vers num="3.9.3" />
        <vers num="3.9.4" />
        <vers num="3.9.5" />
        <vers prev="1" num="3.9.6" />
      </prod>
      <prod vendor="checkmark" name="multiledger">
        <vers num="6.0.3" />
        <vers num="6.0.5" />
        <vers num="7.0.0" />
        <vers prev="1" num="7.0.1" />
      </prod>
      <prod vendor="innermedia" name="dynazip_library">
        <vers num="5.00.00" />
        <vers num="5.00.01" />
        <vers num="5.00.02" />
        <vers num="5.00.03" />
      </prod>
      <prod vendor="realnetworks" name="realone_player">
        <vers num="1.0" />
        <vers num="2.0" />
      </prod>
      <prod vendor="realnetworks" name="realplayer">
        <vers num="10.0" />
        <vers num="10.0_6.0.12.690" />
        <vers num="10.0_beta" />
        <vers num="10.5" />
        <vers num="10.5_6.0.12.1016_beta" />
        <vers num="10.5_6.0.12.1040" />
        <vers num="10.5_6.0.12.1053" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-1095" published="2005-01-10" name="CVE-2004-1095" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Multiple integer overflows in (1) readbmp.c, (2) readgif.c, (3) readgif.c, (4) readmrf.c, (5) readpcx.c, (6) readpng.c,(7) readpnm.c, (8) readprf.c, (9) readtiff.c, (10) readxbm.c, (11) readxpm.c in zgv 5.8 allow remote attackers to execute arbitrary code via certain image headers that cause calculations to be overflowed and small buffers to be allocated, leading to buffer overflows.  NOTE: CVE-2004-0994 and CVE-2004-1095 identify sets of bugs that only partially overlap, despite having the same developer.  Therefore, they should be regarded as distinct.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/11556" source="BID" patch="1" adv="1">11556</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/17871" source="XF" adv="1">zgv-image-header-bo(17871)</ref>
      <ref url="http://www.svgalib.org/rus/zgv/zgv-5.8-integer-overflow-fix.diff" source="CONFIRM">http://www.svgalib.org/rus/zgv/zgv-5.8-integer-overflow-fix.diff</ref>
      <ref url="http://www.svgalib.org/rus/zgv/" source="CONFIRM">http://www.svgalib.org/rus/zgv/</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200411-12.xml" source="GENTOO">GLSA-200411-12</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109898111915661&amp;w=2" source="BUGTRAQ" adv="1">20041028 Re: zgv image viewing heap overflows</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109886210702781&amp;w=2" source="BUGTRAQ" adv="1">20041026 zgv image viewing heap overflows</ref>
    </refs>
    <vuln_soft>
      <prod vendor="zgv" name="xzgv_image_viewer">
        <vers num="0.6" />
        <vers num="0.7" />
        <vers num="0.8" />
      </prod>
      <prod vendor="zgv" name="zgv_image_viewer">
        <vers num="5.5" />
        <vers num="5.6" />
        <vers num="5.7" />
        <vers num="5.8" />
      </prod>
      <prod vendor="debian" name="debian_linux">
        <vers num="3.0" edition="" />
        <vers num="3.0" edition=":hppa" />
        <vers num="3.0" edition=":mips" />
        <vers num="3.0" edition=":ia-32" />
        <vers num="3.0" edition=":m68k" />
        <vers num="3.0" edition=":s-390" />
        <vers num="3.0" edition=":alpha" />
        <vers num="3.0" edition=":arm" />
        <vers num="3.0" edition=":ia-64" />
        <vers num="3.0" edition=":mipsel" />
        <vers num="3.0" edition=":sparc" />
        <vers num="3.0" edition=":ppc" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-1096" published="2005-01-10" name="CVE-2004-1096" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Archive::Zip Perl module before 1.14, when used by antivirus programs such as amavisd-new, allows remote attackers to bypass antivirus protection via a compressed file with both local and global headers set to zero, which does not prevent the compressed file from being opened on a target system.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <design />
      <config />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/492545" source="CERT-VN">VU#492545</ref>
      <ref url="http://www.securityfocus.com/bid/11448" source="BID" patch="1" adv="1">11448</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200410-31.xml" source="GENTOO" patch="1" adv="1">GLSA-200410-31</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/17761" source="XF" adv="1">antivirus-zip-protection-bypass(17761)</ref>
      <ref url="http://www.idefense.com/application/poi/display?id=153&amp;type=vulnerabilities&amp;flashstatus=true" source="IDEFENSE" adv="1">20041018 Multiple Vendor Anti-Virus Software Detection Evasion Vulnerability</ref>
      <ref url="http://secunia.com/advisories/13038/" source="SECUNIA">13038</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2004:118" source="MANDRAKE">MDKSA-2004:118</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ca" name="brightstor_arcserve_backup">
        <vers num="11.1" />
      </prod>
      <prod vendor="ca" name="etrust_antivirus">
        <vers num="7.0" />
        <vers num="7.0_sp2" />
        <vers num="7.1" />
      </prod>
      <prod vendor="ca" name="etrust_antivirus_gateway">
        <vers num="7.0" />
        <vers num="7.1" />
      </prod>
      <prod vendor="ca" name="etrust_ez_antivirus">
        <vers num="6.1" />
        <vers num="6.2" />
        <vers num="6.3" />
      </prod>
      <prod vendor="ca" name="etrust_ez_armor">
        <vers num="2.0" />
        <vers num="2.3" />
        <vers num="2.4" />
      </prod>
      <prod vendor="ca" name="etrust_intrusion_detection">
        <vers num="1.4.1.13" />
        <vers num="1.4.5" />
        <vers num="1.5" />
      </prod>
      <prod vendor="ca" name="etrust_secure_content_manager">
        <vers num="1.0" edition="sp1" />
        <vers num="1.1" />
      </prod>
      <prod vendor="ca" name="inoculateit">
        <vers num="6.0" />
      </prod>
      <prod vendor="eset_software" name="nod32_antivirus">
        <vers num="1.0.11" />
        <vers num="1.0.12" />
        <vers num="1.0.13" />
      </prod>
      <prod vendor="kaspersky_lab" name="kaspersky_anti-virus">
        <vers num="3.0" />
        <vers num="4.0" />
        <vers num="5.0" />
      </prod>
      <prod vendor="mcafee" name="antivirus_engine">
        <vers num="4.3.20" />
      </prod>
      <prod vendor="rav_antivirus" name="rav_antivirus_desktop">
        <vers num="8.6" />
      </prod>
      <prod vendor="rav_antivirus" name="rav_antivirus_for_file_servers">
        <vers num="1.0" />
      </prod>
      <prod vendor="rav_antivirus" name="rav_antivirus_for_mail_servers">
        <vers num="8.4.2" />
      </prod>
      <prod vendor="sophos" name="sophos_anti-virus">
        <vers num="3.4.6" />
        <vers num="3.78" />
        <vers num="3.78d" />
        <vers num="3.79" />
        <vers num="3.80" />
        <vers num="3.81" />
        <vers num="3.82" />
        <vers num="3.83" />
        <vers num="3.84" />
        <vers num="3.85" />
        <vers num="3.86" />
      </prod>
      <prod vendor="sophos" name="sophos_puremessage_anti-virus">
        <vers num="4.6" />
      </prod>
      <prod vendor="sophos" name="sophos_small_business_suite">
        <vers num="1.0" />
      </prod>
      <prod vendor="gentoo" name="linux">
        <vers num="1.4" />
      </prod>
      <prod vendor="mandrakesoft" name="mandrake_linux">
        <vers num="10.1" edition="" />
        <vers num="10.1" edition=":x86_64" />
      </prod>
      <prod vendor="suse" name="suse_linux">
        <vers num="9.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-1097" published="2005-01-10" name="CVE-2004-1097" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Format string vulnerability in the cherokee_logger_ncsa_write_string function in Cherokee 0.4.17 and earlier, when authenticating via auth_pam, allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via format string specifiers in the URL.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" admin="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/11574" source="BID" patch="1" adv="1">11574</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200411-02.xml" source="GENTOO" patch="1" adv="1">GLSA-200411-02</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/17934" source="XF" adv="1">cherokee-format-string(17934)</ref>
      <ref url="http://bugs.gentoo.org/show_bug.cgi?id=67667" source="MISC">http://bugs.gentoo.org/show_bug.cgi?id=67667</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cherokee" name="cherokee_httpd">
        <vers num="0.1" />
        <vers num="0.1.5" />
        <vers num="0.1.6" />
        <vers num="0.2" />
        <vers num="0.2.5" />
        <vers num="0.2.6" />
        <vers num="0.2.7" />
        <vers num="0.4.17" />
        <vers num="0.4.6" />
        <vers num="0.4.7" />
        <vers num="0.4.8" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-1098" published="2005-01-10" name="CVE-2004-1098" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">MIMEDefang in MIME-tools 5.414 allows remote attackers to bypass virus scanning capabilities via an e-mail attachment with a virus that contains an empty boundary string in the Content-Type header.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/11563" source="BID" patch="1" adv="1">11563</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200411-06.xml" source="GENTOO" patch="1" adv="1">GLSA-200411-06</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/17940" source="XF" adv="1">mimetools-boundary-virus-bypass(17940)</ref>
      <ref url="http://lists.roaringpenguin.com/pipermail/mimedefang/2004-October/024959.html" source="MLIST">20041026 [Mimedefang] SECURITY: Patch for MIME-tools</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2004:123" source="MANDRAKE">MDKSA-2004:123</ref>
    </refs>
    <vuln_soft>
      <prod vendor="roaring_penguin" name="mimedefang">
        <vers num="2.14" />
        <vers num="2.20" />
        <vers num="2.21" />
        <vers num="2.38" />
        <vers num="2.39" />
        <vers num="2.4" />
        <vers num="2.41" />
        <vers num="2.42" />
        <vers num="2.43" />
        <vers num="2.44" />
        <vers num="2.45" />
        <vers num="4.46" />
        <vers num="4.47" />
      </prod>
      <prod vendor="mandrakesoft" name="mandrake_linux">
        <vers num="10.0" edition="" />
        <vers num="10.0" edition=":amd64" />
        <vers num="10.1" edition="" />
        <vers num="10.1" edition=":x86_64" />
        <vers num="9.2" edition="" />
        <vers num="9.2" edition=":amd64" />
      </prod>
      <prod vendor="mandrakesoft" name="mandrake_linux_corporate_server">
        <vers num="2.1" edition="" />
        <vers num="2.1" edition=":x86_64" />
      </prod>
      <prod vendor="suse" name="suse_linux">
        <vers num="8.0" />
        <vers num="8.1" />
        <vers num="8.2" />
        <vers num="9.0" edition="" />
        <vers num="9.0" edition=":x86_64" />
        <vers num="9.1" />
        <vers num="9.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-1099" published="2005-01-10" name="CVE-2004-1099" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Cisco Secure Access Control Server for Windows (ACS Windows) and Cisco Secure Access Control Server Solution Engine (ACS Solution Engine) 3.3.1, when the EAP-TLS protocol is enabled, does not properly handle expired or untrusted certificates, which allows remote attackers to bypass authentication and gain unauthorized access via a "cryptographically correct" certificate with valid fields such as the username.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" admin="1" />
    </loss_types>
    <vuln_types>
      <access />
      <config />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/11577" source="BID" patch="1" adv="1">11577</ref>
      <ref url="http://www.ciac.org/ciac/bulletins/p-028.shtml" source="CIAC" patch="1" adv="1">P-028</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/17936" source="XF" adv="1">ciscosecure-eaptls-auth-bypass(17936)</ref>
      <ref url="http://www.cisco.com/warp/public/707/cisco-sa-20041102-acs-eap-tls.shtml" source="CISCO" adv="1">20041102 Vulnerability in Cisco Secure Access Control Server EAP-TLS Authentication</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="secure_access_control_server">
        <vers num="3.3(1)" />
        <vers num="3.3.1" />
      </prod>
      <prod vendor="cisco" name="secure_access_control_server_solution_engine">
        <vers num="3.3.1" />
      </prod>
      <prod vendor="cisco" name="secure_acs_solution_engine">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1100" published="2005-01-10" name="CVE-2004-1100" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in mailpost.exe in MailPost 5.1.1sv, and possibly earlier versions, when debug mode is enabled, allows remote attackers to execute arbitrary web script or HTML via the append parameter.</descript>
    </desc>
    <sols>
      <sol source="nvd">Successful exploitation requires that debug mode is enabled.</sol>
    </sols>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/107998" source="CERT-VN">VU#107998</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/17953" source="XF">mailpost-append-xss(17953)</ref>
      <ref url="http://www.securityfocus.com/bid/11596" source="BID">11596</ref>
      <ref url="http://www.procheckup.com/security_info/vuln_pr0410.html" source="MISC">http://www.procheckup.com/security_info/vuln_pr0410.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="tips" name="mailpost">
        <vers num="5.1.1sv" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1101" published="2005-01-10" name="CVE-2004-1101" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:N/A:P)" CVSS_score="5.8" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="8.6" CVSS_base_score="5.8">
    <desc>
      <descript source="cve">mailpost.exe in MailPost 5.1.1sv, and possibly earlier versions, allows remote attackers to cause a denial of service (server crash), leak sensitive pathname information in the resulting error message, and execute a cross-site scripting (XSS) attack via an HTTP request that contains a / (backslash) and arbitrary webscript before the requested file, which leaks the pathname and does not quote the script in the resulting Visual Basic error message.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/596046" source="CERT-VN" adv="1">VU#596046</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/17951" source="XF" adv="1">mailpost-slash-xss(17951)</ref>
      <ref url="http://www.securityfocus.com/bid/11598" source="BID" adv="1">11598</ref>
      <ref url="http://www.procheckup.com/security_info/vuln_pr0411.html" source="MISC">http://www.procheckup.com/security_info/vuln_pr0411.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="tips" name="mailpost">
        <vers num="5.1.1_sv" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1102" published="2005-01-10" name="CVE-2004-1102" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">MailPost 5.1.1sv, and possibly earlier versions, displays a different error message depending on whether the requested file exists or not, which allows remote attackers to gain sensitive information.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/306086" source="CERT-VN" adv="1">VU#306086</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/17954" source="XF" adv="1">mailpost-get-info-disclosure(17954)</ref>
      <ref url="http://www.securityfocus.com/bid/11599" source="BID" adv="1">11599</ref>
      <ref url="http://www.procheckup.com/security_info/vuln_pr0408.html" source="MISC">http://www.procheckup.com/security_info/vuln_pr0408.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="tips" name="mailpost">
        <vers num="5.1.1_sv" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1103" published="2005-01-10" name="CVE-2004-1103" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">MailPost 5.1.1sv, and possibly earlier versions, when debug mode is enabled, allows remote attackers to gain sensitive information via the debug parameter, which reveals information such as the path to the web root and the web server version.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
      <config />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/858726" source="CERT-VN" adv="1">VU#858726</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/17952" source="XF" adv="1">mailpost-information-disclosure(17952)</ref>
      <ref url="http://www.securityfocus.com/bid/11595" source="BID" adv="1">11595</ref>
      <ref url="http://www.procheckup.com/security_info/vuln_pr0409.html" source="MISC">http://www.procheckup.com/security_info/vuln_pr0409.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="tips" name="mailpost">
        <vers num="5.1.1_sv" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-1104" published="2004-12-31" name="CVE-2004-1104" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Microsoft Internet Explorer 6.0 SP2 allows remote attackers to spoof a legitimate URL in the status bar and conduct a phishing attack via a web page that contains a BASE element that points to the legitimate site, followed by an anchor (a) element with an empty "href" attribute, and a FORM whose action points to a malicious URL, and an INPUT submit element that is modified to look like a legitimate URL.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/702086" source="CERT-VN" adv="1">VU#702086</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/17938" source="XF" adv="1">ie-ahref-status-spoofing(17938)</ref>
      <ref url="http://www.securityfocus.com/bid/11565" source="BID" adv="1">11565</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/425883/100/0/threaded" source="BUGTRAQ">20060223 Re: Internet Explorer Phishing mouseover issue</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/425386/100/0/threaded" source="BUGTRAQ">20060218 Re: Internet Explorer Phishing mouseover issue</ref>
      <ref url="http://www.securityfocus.com/archive/1/379903" source="BUGTRAQ">20041030 Re: New URL spoofing bug in Microsoft Internet Explorer</ref>
      <ref url="http://secunia.com/advisories/11273" source="SECUNIA">11273</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="ie">
        <vers num="6.0" edition="sp2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1105" published="2005-01-10" name="CVE-2004-1105" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Nortel Networks Contivity VPN Client displays a different error message depending on whether the username is valid or invalid, which could allow remote attackers to gain sensitive information.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/CRDY-626N7F" source="CONFIRM">http://www.kb.cert.org/vuls/id/CRDY-626N7F</ref>
      <ref url="http://www.kb.cert.org/vuls/id/830214" source="CERT-VN" adv="1">VU#830214</ref>
      <ref url="http://www.securityfocus.com/bid/11623" source="BID" patch="1" adv="1">11623</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/17988" source="XF" adv="1">nortel-contivity-info-disclosure(17988)</ref>
      <ref url="http://www.nii.co.in/vuln/contivity.html" source="MISC">http://www.nii.co.in/vuln/contivity.html</ref>
      <ref url="http://archives.neohapsis.com/archives/fulldisclosure/2004-11/0291.html" source="FULLDISC" adv="1">20041110 Nortel Networks Contivity VPN Client information leakage vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="nortel" name="contivity">
        <vers num="4.91" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1106" published="2005-01-10" name="CVE-2004-1106" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in Gallery 1.4.4-pl3 and earlier allows remote attackers to execute arbitrary web script or HTML via "specially formed URLs," possibly via the include parameter in index.php.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/17948" source="XF" patch="1">gallery-script-xss(17948)</ref>
      <ref url="http://www.securityfocus.com/bid/11602" source="BID" patch="1" adv="1">11602</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200411-10.xml" source="GENTOO" patch="1" adv="1">GLSA-200411-10</ref>
      <ref url="http://www.debian.org/security/2005/dsa-642" source="DEBIAN" patch="1">DSA-642</ref>
      <ref url="http://gallery.menalto.com/modules.php?op=modload&amp;name=News&amp;file=article&amp;sid=142&amp;mode=thread&amp;order=0&amp;thold=0" source="CONFIRM">http://gallery.menalto.com/modules.php?op=modload&amp;name=News&amp;file=article&amp;sid=142&amp;mode=thread&amp;order=0&amp;thold=0</ref>
      <ref url="http://g3cko.info/gallery2-4.patch" source="MISC">http://g3cko.info/gallery2-4.patch</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gallery_project" name="gallery">
        <vers num="1.4" />
        <vers num="1.4.1" />
        <vers num="1.4.2" />
        <vers num="1.4.3_pl1" />
        <vers num="1.4.3_pl2" />
        <vers num="1.4_pl1" />
        <vers num="1.4_pl2" />
      </prod>
      <prod vendor="gentoo" name="linux">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2004-1107" published="2005-01-10" name="CVE-2004-1107" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">dispatch-conf in Portage 2.0.51-r2 and earlier allows local users to overwrite arbitrary files via a symlink attack on temporary files.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/11616" source="BID" patch="1" adv="1">11616</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200411-13.xml" source="GENTOO" patch="1" adv="1">GLSA-200411-13</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/17986" source="XF" adv="1">portage-dispatchconf-symlink(17986)</ref>
      <ref url="http://secunia.com/advisories/13108/" source="SECUNIA">13108</ref>
      <ref url="http://bugs.gentoo.org/show_bug.cgi?id=69147" source="CONFIRM">http://bugs.gentoo.org/show_bug.cgi?id=69147</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gentoo" name="linux">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2004-1108" published="2005-01-10" name="CVE-2004-1108" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">qpkg in Gentoolkit 0.2.0_pre10 and earlier allows local users to overwrite arbitrary files via a symlink attack on a temporary directory.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <access />
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/11617" source="BID" patch="1" adv="1">11617</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200411-13.xml" source="GENTOO" patch="1" adv="1">GLSA-200411-13</ref>
      <ref url="http://secunia.com/advisories/13108/" source="SECUNIA" patch="1" adv="1">13108</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/17968" source="XF" adv="1">gentoolkit-symlink(17968)</ref>
      <ref url="http://bugs.gentoo.org/show_bug.cgi?id=68846" source="CONFIRM">http://bugs.gentoo.org/show_bug.cgi?id=68846</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gentoo" name="linux">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1109" published="2005-01-10" name="CVE-2004-1109" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The FWDRV.SYS driver in Kerio Personal Firewall 4.1.1 and earlier allows remote attackers to cause a denial of service (CPU consumption and system freeze from infinite loop) via a (1) TCP, (2) UDP, or (3) ICMP packet with a zero length IP Option field.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/11639" source="BID" patch="1" adv="1">11639</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/17992" source="XF" adv="1">kerio-pf-packet-dos(17992)</ref>
      <ref url="http://www.kerio.com/security_advisory.html" source="CONFIRM" adv="1">http://www.kerio.com/security_advisory.html</ref>
      <ref url="http://www.eeye.com/html/research/advisories/AD20041109.html" source="EEYE">AD20041109</ref>
    </refs>
    <vuln_soft>
      <prod vendor="kerio" name="personal_firewall">
        <vers num="4.0.10" />
        <vers num="4.0.16" />
        <vers num="4.0.6" />
        <vers num="4.0.7" />
        <vers num="4.0.8" />
        <vers num="4.0.9" />
        <vers num="4.1" />
        <vers num="4.1.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2004-1110" published="2005-01-10" name="CVE-2004-1110" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">The mtink status monitor before 1.0.5 for Epson printers allows local users to overwrite arbitrary files via a symlink attack on the epson temporary file.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/11640" source="BID" patch="1" adv="1">11640</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200411-17.xml" source="GENTOO" patch="1" adv="1">GLSA-200411-17</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/18011" source="XF" adv="1">mtink-tmp-file-symlink(18011)</ref>
      <ref url="http://bugs.gentoo.org/show_bug.cgi?id=70310" source="CONFIRM">http://bugs.gentoo.org/show_bug.cgi?id=70310</ref>
    </refs>
    <vuln_soft>
      <prod vendor="jean-jacques_sarton" name="mtink">
        <vers num="0.9.32" />
        <vers num="0.9.33" />
        <vers num="0.9.52" />
        <vers num="0.9.53" />
        <vers num="1.0.4" />
      </prod>
      <prod vendor="gentoo" name="linux">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1111" published="2005-01-10" name="CVE-2004-1111" modified="2009-03-04" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Cisco IOS 2.2(18)EW, 12.2(18)EWA, 12.2(14)SZ, 12.2(18)S, 12.2(18)SE, 12.2(18)SV, 12.2(18)SW, and other versions without the "no service dhcp" command, keep undeliverable DHCP packets in the queue instead of dropping them, which allows remote attackers to cause a denial of service (dropped traffic) via multiple undeliverable DHCP packets that exceed the input queue size.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input bound="1" />
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/630104" source="CERT-VN" adv="1">VU#630104</ref>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA04-316A.html" source="CERT">TA04-316A</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/18021" source="XF" adv="1">cisco-ios-dhcp-dos(18021)</ref>
      <ref url="http://www.cisco.com/warp/public/707/cisco-sa-20041110-dhcp.shtml" source="CISCO">20041110 Cisco Security Advisory: Cisco IOS DHCP Blocked Interface Denial-of-Service</ref>
      <ref url="http://www.ciac.org/ciac/bulletins/p-034.shtml" source="CIAC">P-034</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5632" source="OVAL">oval:org.mitre.oval:def:5632</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="7200_router">
        <vers num="" />
      </prod>
      <prod vendor="cisco" name="7300_router">
        <vers num="" />
      </prod>
      <prod vendor="cisco" name="7500_router">
        <vers num="" />
      </prod>
      <prod vendor="cisco" name="7600_router">
        <vers num="" />
      </prod>
      <prod vendor="cisco" name="catalyst_7600">
        <vers num="" edition=":sup720_msfc3" />
      </prod>
      <prod vendor="cisco" name="multiservice_platform_2650">
        <vers num="" />
      </prod>
      <prod vendor="cisco" name="multiservice_platform_2650xm">
        <vers num="" />
      </prod>
      <prod vendor="cisco" name="multiservice_platform_2651">
        <vers num="" />
      </prod>
      <prod vendor="cisco" name="multiservice_platform_2651xm">
        <vers num="" />
      </prod>
      <prod vendor="cisco" name="ios">
        <vers num="12.2(14)sz" />
        <vers num="12.2(18)ew" />
        <vers num="12.2(18)ewa" />
        <vers num="12.2(18)s" />
        <vers num="12.2(18)se" />
        <vers num="12.2(18)sv" />
        <vers num="12.2(18)sw" />
        <vers num="12.2(20)ew" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1112" published="2005-01-10" name="CVE-2004-1112" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_score="5.1" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="4.9" CVSS_base_score="5.1">
    <desc>
      <descript source="cve">The buffer overflow trigger in Cisco Security Agent (CSA) before 4.0.3 build 728 waits five minutes for a user response before terminating the process, which could allow remote attackers to bypass the buffer overflow protection by sending additional buffer overflow attacks within the five minute timeout period.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
      <race />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/18037" source="XF" adv="1">csa-buffer-protection-bypass(18037)</ref>
      <ref url="http://www.securityfocus.com/bid/11659" source="BID" adv="1">11659</ref>
      <ref url="http://www.cisco.com/warp/public/707/cisco-sa-20041111-csa.shtml" source="CISCO" adv="1">20041111 Crafted Timed Attack Evades Cisco Security Agent Protections</ref>
      <ref url="http://www.ciac.org/ciac/bulletins/p-036.shtml" source="CIAC" adv="1">P-036</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="security_agent">
        <vers num="3" />
        <vers num="4.0" />
        <vers num="4.0.1" />
        <vers num="4.0.2" />
        <vers num="4.0.3" />
      </prod>
      <prod vendor="okena" name="stormwatch">
        <vers num="3.x" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-1113" published="2005-01-10" name="CVE-2004-1113" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">SQL injection vulnerability in SQLgrey Postfix greylisting service before 1.2.0 allows remote attackers to execute arbitrary SQL commands via the (1) sender or (2) recipient e-mail addresses.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" admin="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.trustix.org/errata/2004/0058/" source="TRUSTIX" patch="1" adv="1">2004-0058</ref>
      <ref url="http://www.securityfocus.com/bid/11633" source="BID" patch="1" adv="1">11633</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/17998" source="XF" adv="1">sqlgrey-postfix-sql-injection(17998)</ref>
      <ref url="http://sourceforge.net/project/shownotes.php?release_id=281256" source="CONFIRM">http://sourceforge.net/project/shownotes.php?release_id=281256</ref>
      <ref url="http://secunia.com/advisories/13135/" source="SECUNIA">13135</ref>
    </refs>
  </entry>
  <entry type="CVE" severity="High" seq="2004-1114" published="2005-01-10" name="CVE-2004-1114" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Buffer overflow in the handling of command line arguments in Skype 1.0.x.94 through 1.0.x.98 allows remote attackers to execute arbitrary code via a callto:// URL with a long non-existent username, a different vulnerability than CVE-2004-1777.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/11682" source="BID" patch="1" adv="1">11682</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/18063" source="XF" adv="1">skype-callto-uri-bo(18063)</ref>
      <ref url="http://www.skype.com/security/ssa-2004-02.html" source="CONFIRM">http://www.skype.com/security/ssa-2004-02.html</ref>
      <ref url="http://www.skype.com/products/skype/windows/changelog.html" source="CONFIRM">http://www.skype.com/products/skype/windows/changelog.html</ref>
      <ref url="http://www.osvdb.org/11786" source="OSVDB">11786</ref>
      <ref url="http://secunia.com/advisories/13191" source="SECUNIA">13191</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110067029422696&amp;w=2" source="BUGTRAQ">20041115 Re: Skype callto:// BoF technical details</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110062240706017&amp;w=2" source="BUGTRAQ" adv="1">20041116 Skype callto:// BoF technical details</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2004-November/028852.html" source="FULLDISC">20041116 Skype callto:// BoF technical details</ref>
    </refs>
    <vuln_soft>
      <prod vendor="skype_technologies" name="skype">
        <vers num="1.0.0.10" />
        <vers num="1.0.0.18" />
        <vers num="1.0.0.29" />
        <vers num="1.0.0.9" />
        <vers num="1.0.0.94" />
        <vers num="1.0.0.97" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-1115" published="2005-01-10" name="CVE-2004-1115" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">The init scripts in Search for Extraterrestrial Intelligence (SETI) project 3.08-r3 and earlier execute user-owned programs with root privileges, which allows local users to gain privileges by modifying the programs.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200411-26.xml" source="GENTOO" patch="1" adv="1">GLSA-200411-26</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/18149" source="XF" adv="1">seti@home-gain-privileges(18149)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gentoo" name="linux">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-1116" published="2005-01-10" name="CVE-2004-1116" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">The init scripts in Great Internet Mersenne Prime Search (GIMPS) 23.9 and earlier execute user-owned programs with root privileges, which allows local users to gain privileges by modifying the programs.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <design />
      <config />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200411-26.xml" source="GENTOO" patch="1" adv="1">GLSA-200411-26</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/18149" source="XF" adv="1">seti@home-gain-privileges(18149)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gentoo" name="linux">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-1117" published="2005-01-10" name="CVE-2004-1117" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">The init scripts in ChessBrain 20407 and earlier execute user-owned programs with root privileges, which allows local users to gain privileges by modifying the programs.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <design />
      <config />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200411-26.xml" source="GENTOO" patch="1" adv="1">GLSA-200411-26</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/18149" source="XF" adv="1">seti@home-gain-privileges(18149)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gentoo" name="linux">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-1118" published="2005-01-10" name="CVE-2004-1118" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Buffer overflow in the WodFtpDLX.ocx (WeOnlyDo!) ActiveX component before 2.3.2.97, as used by CoffeeCup Direct FTP 6.2.0.62 and CoffeeCup Free FTP 3.0.0.10, and possibly other applications, allows remote attackers to execute arbitrary code via a long filename.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/18190" source="XF" adv="1">wodftpdlx-long-filename-bo(18190)</ref>
      <ref url="http://www.securityfocus.com/bid/11721" source="BID" adv="1">11721</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110114233323417&amp;w=2" source="BUGTRAQ" adv="1">20041122 WeOnlyDo! COM Ftp DELUXE ActiveX Control Buffer Overflow Vulnerability</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2004-November/029244.html" source="FULLDISC">20041122 CoffeeCup FTP Clients Buffer Overflow Vulnerability</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2004-November/029243.html" source="FULLDISC">20041122 WeOnlyDo! COM Ftp DELUXE ActiveX Control Buffer Overflow Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="weonlydo" name="wodftpdlx_activex_component">
        <vers num="2.1.1_8" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-1119" published="2005-01-10" name="CVE-2004-1119" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Stack-based buffer overflow in IN_CDDA.dll in Winamp 5.05, and possibly other versions including 5.06, allows remote attackers to execute arbitrary code via a certain .m3u playlist file.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/986504" source="CERT-VN">VU#986504</ref>
      <ref url="http://www.securityfocus.com/bid/11730" source="BID" patch="1" adv="1">11730</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/18197" source="XF" adv="1">winamp-incddadll-bo(18197)</ref>
      <ref url="http://www.security-assessment.com/Papers/Winamp_IN_CDDA_Buffer_Overflow.pdf" source="MISC">http://www.security-assessment.com/Papers/Winamp_IN_CDDA_Buffer_Overflow.pdf</ref>
      <ref url="http://secunia.com/advisories/13269/" source="SECUNIA">13269</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110123330404482&amp;w=2" source="BUGTRAQ" adv="1">20041123 Winamp - Buffer Overflow In IN_CDDA.dll</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2004-11/0369.html" source="BUGTRAQ">20041126 Re: Winamp - Buffer Overflow In IN_CDDA.dll [Unpatched</ref>
      <ref url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=110135574326217&amp;w=2" source="NTBUGTRAQ">20041124 Winamp - Buffer Overflow In IN_CDDA.dll [Unpatched]</ref>
      <ref url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=110126352412395&amp;w=2" source="NTBUGTRAQ">20041123 Winamp - Buffer Overflow In IN_CDDA.dll</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110146036300803&amp;w=2" source="BUGTRAQ">20041124 Winamp - Buffer Overflow In IN_CDDA.dll [Unpatched]</ref>
    </refs>
    <vuln_soft>
      <prod vendor="nullsoft" name="winamp">
        <vers num="5.01" />
        <vers num="5.02" />
        <vers num="5.03" />
        <vers num="5.04" />
        <vers num="5.05" />
        <vers num="5.06" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-1120" published="2005-01-10" name="CVE-2004-1120" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Mulitple buffer overflows in (1) http.c, (2) http-retr.c, (3) main.c and other code that handles network protocols in ProZilla 1.3.6-r2 and earlier allow remote servers to execute arbitrary code via a long Location header.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/18210" source="XF" adv="1">prozilla-bo(18210)</ref>
      <ref url="http://www.securityfocus.com/bid/11734" source="BID" adv="1">11734</ref>
      <ref url="http://www.securityfocus.com/archive/1/382219" source="BUGTRAQ">20041124 Prozilla Remote Exploit</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200411-31.xml" source="GENTOO" adv="1">GLSA-200411-31</ref>
      <ref url="http://www.debian.org/security/2005/dsa-663" source="DEBIAN">DSA-663</ref>
      <ref url="http://bugs.gentoo.org/show_bug.cgi?id=70090" source="CONFIRM">http://bugs.gentoo.org/show_bug.cgi?id=70090</ref>
    </refs>
    <vuln_soft>
      <prod vendor="prozilla" name="prozilla_download_accelerator">
        <vers num="1.0.0" />
        <vers num="1.3.0" />
        <vers num="1.3.1" />
        <vers num="1.3.2" />
        <vers num="1.3.3" />
        <vers num="1.3.4" />
        <vers num="1.3.5" />
        <vers num="1.3.5.1" />
        <vers num="1.3.5.2" />
        <vers num="1.3.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1121" published="2004-11-01" name="CVE-2004-1121" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Apple Safari 1.0 through 1.2.3 allows remote attackers to spoof the URL displayed in the status bar via TABLE tags.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/925430" source="CERT-VN" patch="1" adv="1">VU#925430</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/17909" source="XF" patch="1" adv="1">ie-table-status-spoofing(17909)</ref>
      <ref url="http://www.securityfocus.com/bid/11573" source="BID" patch="1" adv="1">11573</ref>
      <ref url="http://secunia.com/advisories/13047/" source="SECUNIA" patch="1" adv="1">13047</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2004/Dec/msg00000.html" source="APPLE" patch="1" adv="1">APPLE-SA-2004-12-02</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="safari">
        <vers num="1.0" />
        <vers num="1.1" />
        <vers num="1.2" />
        <vers num="1.2.1" />
        <vers num="1.2.2" />
        <vers num="1.2.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-1122" published="2005-01-10" name="CVE-2004-1122" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Safari 1.x to 1.2.4, and possibly other versions, allows inactive windows to launch dialog boxes, which can allow remote attackers to spoof the dialog boxes from web sites in other windows, aka the "Dialog Box Spoofing Vulnerability," a different vulnerability than CVE-2004-1314.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://secunia.com/secunia_research/2004-10/" source="MISC">http://secunia.com/secunia_research/2004-10/</ref>
      <ref url="http://secunia.com/multiple_browsers_dialog_box_spoofing_test/" source="MISC" adv="1">http://secunia.com/multiple_browsers_dialog_box_spoofing_test/</ref>
      <ref url="http://secunia.com/advisories/12892" source="SECUNIA">12892</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2004/Dec/msg00000.html" source="APPLE">APPLE-SA-2004-12-02</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="safari">
        <vers num="1.2.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1123" published="2005-01-10" name="CVE-2004-1123" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Darwin Streaming Server 5.0.1, and possibly earlier versions, allows remote attackers to cause a denial of service (server crash) via a DESCRIBE request with a location that contains a null byte.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.idefense.com/application/poi/display?id=159&amp;type=vulnerabilities" source="IDEFENSE" patch="1" adv="1">20041203 Apple Darwin Streaming Server DESCRIBE Null Byte Denial of Service Vulnerability</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/18357" source="XF">darwin-describe-dos(18357)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="darwin_streaming_server">
        <vers num="4.1.3" />
        <vers num="5.0.1" />
      </prod>
      <prod vendor="apple" name="quicktime_streaming_server">
        <vers num="4.1.1" />
      </prod>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.2" />
        <vers num="10.2.1" />
        <vers num="10.2.2" />
        <vers num="10.2.3" />
        <vers num="10.2.4" />
        <vers num="10.2.5" />
        <vers num="10.2.6" />
        <vers num="10.2.7" />
        <vers num="10.2.8" />
        <vers num="10.3" />
        <vers num="10.3.1" />
        <vers num="10.3.2" />
        <vers num="10.3.3" />
        <vers num="10.3.4" />
        <vers num="10.3.5" />
        <vers num="10.3.6" />
      </prod>
      <prod vendor="apple" name="mac_os_x_server">
        <vers num="10.2" />
        <vers num="10.2.1" />
        <vers num="10.2.2" />
        <vers num="10.2.3" />
        <vers num="10.2.4" />
        <vers num="10.2.5" />
        <vers num="10.2.6" />
        <vers num="10.2.7" />
        <vers num="10.2.8" />
        <vers num="10.3" />
        <vers num="10.3.1" />
        <vers num="10.3.2" />
        <vers num="10.3.3" />
        <vers num="10.3.4" />
        <vers num="10.3.5" />
        <vers num="10.3.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1124" published="2004-01-14" name="CVE-2004-1124" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Unknown vulnerability in chroot on SCO UnixWare 7.1.1 through 7.1.4 allows local users to escape the chroot jail and conduct unauthorized activities.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/18970" source="XF" patch="1" adv="1">chroot-jail-security-bypass(18970)</ref>
      <ref url="ftp://ftp.sco.com/pub/updates/UnixWare/SCOSA-2005.2/SCOSA-2005.2.txt" source="SCO" patch="1" adv="1">SCOSA-2005.2</ref>
      <ref url="http://www.securityfocus.com/bid/12300" source="BID">12300</ref>
      <ref url="http://secunia.com/advisories/15339" source="SECUNIA">15339</ref>
      <ref url="http://secunia.com/advisories/13915" source="SECUNIA">13915</ref>
      <ref url="ftp://ftp.sco.com/pub/updates/OpenServer/SCOSA-2005.22/SCOSA-2005.22.txt" source="SCO">SCOSA-2005.22</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sco" name="openserver">
        <vers num="5.0.6" />
        <vers num="5.0.7" />
      </prod>
      <prod vendor="sco" name="unixware">
        <vers num="7.1.1" />
        <vers num="7.1.3" />
        <vers num="7.1.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-1125" published="2005-01-10" name="CVE-2004-1125" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Buffer overflow in the Gfx::doImage function in Gfx.cc for xpdf 3.00, and other products that share code such as tetex-bin and kpdf in KDE 3.2.x to 3.2.3 and 3.3.x to 3.3.2, allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a crafted PDF file that causes the boundaries of a maskColors array to be exceeded.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/12070" source="BID" patch="1" adv="1">12070</ref>
      <ref url="https://bugzilla.fedora.us/show_bug.cgi?id=2353" source="FEDORA">FLSA:2353</ref>
      <ref url="https://bugzilla.fedora.us/show_bug.cgi?id=2352" source="FEDORA">FLSA:2352</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/18641" source="XF">xpdf-gfx-doimage-bo(18641)</ref>
      <ref url="http://www.ubuntulinux.org/support/documentation/usn/usn-50-1" source="UBUNTU">USN-50-1</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-354.html" source="REDHAT">RHSA-2005:354</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-066.html" source="REDHAT">RHSA-2005:066</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-057.html" source="REDHAT">RHSA-2005:057</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-053.html" source="REDHAT">RHSA-2005:053</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-034.html" source="REDHAT">RHSA-2005:034</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-026.html" source="REDHAT">RHSA-2005:026</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-018.html" source="REDHAT">RHSA-2005:018</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-013.html" source="REDHAT">RHSA-2005:013</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2005_01_sr.html" source="SUSE">SUSE-SR:2005:001</ref>
      <ref url="http://www.kde.org/info/security/advisory-20041223-1.txt" source="CONFIRM">http://www.kde.org/info/security/advisory-20041223-1.txt</ref>
      <ref url="http://www.idefense.com/application/poi/display?id=172&amp;type=vulnerabilities" source="IDEFENSE">20041221 Multiple Vendor xpdf PDF Viewer Buffer Overflow Vulnerability</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200501-17.xml" source="GENTOO">GLSA-200501-17</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200501-13.xml" source="GENTOO">GLSA-200501-13</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200412-25.xml" source="GENTOO">GLSA-200412-25</ref>
      <ref url="http://securitytracker.com/id?1012646" source="SECTRACK">1012646</ref>
      <ref url="http://secunia.com/advisories/17277" source="SECUNIA">17277</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10830" source="OVAL">oval:org.mitre.oval:def:10830</ref>
      <ref url="http://marc.theaimsgroup.com/?t=110378596500001&amp;r=1&amp;w=2" source="BUGTRAQ">20041228 KDE Security Advisory: kpdf Buffer Overflow Vulnerability</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2004-December/030241.html" source="FULLDISC">20041223 [USN-48-1] xpdf, tetex-bin vulnerabilities</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000921" source="CONECTIVA">CLA-2005:921</ref>
      <ref url="ftp://ftp.sco.com/pub/updates/OpenServer/SCOSA-2005.42/SCOSA-2005.42.txt" source="SCO">SCOSA-2005.42</ref>
      <ref url="ftp://ftp.foolabs.com/pub/xpdf/xpdf-3.00pl2.patch" source="CONFIRM">ftp://ftp.foolabs.com/pub/xpdf/xpdf-3.00pl2.patch</ref>
    </refs>
    <vuln_soft>
      <prod vendor="easy_software_products" name="cups">
        <vers num="1.1.20" />
      </prod>
      <prod vendor="xpdf" name="xpdf">
        <vers num="3.0" />
      </prod>
      <prod vendor="kde" name="kde">
        <vers num="3.2.3" />
        <vers num="3.3.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-1127" published="2005-01-10" name="CVE-2004-1127" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Buffer overflow in Open Dc Hub 0.7.14 allows remote attackers, with administrator privileges, to execute arbitrary code via a long RedirectAll command.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/11747" source="BID" patch="1" adv="1">11747</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110144606411674&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20041124 Buffer Overflow in Open Dc Hub 0.7.14</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/18254" source="XF" adv="1">open-hub-redirectall-bo(18254)</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200411-37.xml" source="GENTOO">GLSA-200411-37</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2004-November/029383.html" source="FULLDISC">20041124 Buffer Overflow in Open Dc Hub 0.7.14</ref>
    </refs>
    <vuln_soft>
      <prod vendor="open_dc_hub" name="direct_connect_peer-to-peer_client">
        <vers num="0.7.14" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-1128" published="2005-01-10" name="CVE-2004-1128" modified="2009-04-03" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Buffer overflow in CMailCOM.dll in CMailServer 5.2 allows remote attackers to execute arbitrary code via an attachment with a long filename.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/18276" source="XF" adv="1">cmailserver-cmailcomdll-bo(18276)</ref>
      <ref url="http://www.securityfocus.com/bid/11742" source="BID" adv="1">11742</ref>
      <ref url="http://www.security.org.sg/vuln/cmailserver52.html" source="MISC">http://www.security.org.sg/vuln/cmailserver52.html</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110137313329955&amp;w=2" source="BUGTRAQ" adv="1">20041124 [SIG^2 G-TEC] CMailServer WebMail v5.2 Multiple Vulnerabilities</ref>
    </refs>
  </entry>
  <entry type="CVE" severity="High" seq="2004-1129" published="2005-01-10" name="CVE-2004-1129" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">SQL injection vulnerability in (1) fdelmail.asp, (2) addressc.asp, and possibly (3) postmail.asp and (4) fmvmail.asp in CMailServer 5.2 allow remote attackers to inject arbitrary SQL commands and delete mail metadata or e-mail addresses of contacts via the indexOfMail parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" admin="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/18281" source="XF" adv="1">cmailserver-fdelmail-addressc-sql-injection(18281)</ref>
      <ref url="http://www.securityfocus.com/bid/11742" source="BID" adv="1">11742</ref>
      <ref url="http://www.security.org.sg/vuln/cmailserver52.html" source="MISC">http://www.security.org.sg/vuln/cmailserver52.html</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110137313329955&amp;w=2" source="BUGTRAQ" adv="1">20041124 [SIG^2 G-TEC] CMailServer WebMail v5.2 Multiple Vulnerabilities</ref>
    </refs>
    <vuln_soft>
      <prod vendor="youngzsoft" name="cmailserver">
        <vers num="5.2.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1130" published="2005-01-10" name="CVE-2004-1130" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in admin.asp in CMailServer 5.2 allows remote attackers to execute arbitrary web script or HTML via personal information fields, such as (1) username, (2) name, or (3) comments.</descript>
    </desc>
    <sols>
      <sol source="nvd">This vulnerability is addressed in the following product release:
YoungZSoft, CMailServer, 5.2.1</sol>
    </sols>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/18280" source="XF" patch="1">cmailserver-adminasp-xss(18280)</ref>
      <ref url="http://www.securityfocus.com/bid/11742" source="BID" patch="1">11742</ref>
      <ref url="http://www.security.org.sg/vuln/cmailserver52.html" source="MISC" patch="1">http://www.security.org.sg/vuln/cmailserver52.html</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110137313329955&amp;w=2" source="BUGTRAQ" patch="1">20041124 [SIG^2 G-TEC] CMailServer WebMail v5.2 Multiple Vulnerabilities</ref>
    </refs>
    <vuln_soft>
      <prod vendor="youngzsoft" name="cmailserver">
        <vers num="5.2.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-1131" published="2005-02-07" name="CVE-2004-1131" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Multiple buffer overflows in the enable command for SCO OpenServer 5.0.6 and 5.0.7 allow local users to execute arbitrary code via long command line arguments.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="ftp://ftp.sco.com/pub/updates/OpenServer/SCOSA-2005.13/SCOSA-2005.13.txt" source="SCO" patch="1" adv="1">SCOSA-2005.13</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/19243" source="XF">openserver-enable-bo(19243)</ref>
      <ref url="http://www.securityfocus.com/bid/12474" source="BID">12474</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sco" name="openserver">
        <vers num="5.0.6" />
        <vers num="5.0.7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1133" published="2005-01-10" name="CVE-2004-1133" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in Microsoft W3Who ISAPI (w3who.dll) allow remote attackers to inject arbitrary HTML and web script via (1) HTTP headers such as "Connection" or (2) invalid parameters whose values are echoed in the resulting error message.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/18375" source="XF">w3who-http-error-xss(18375)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=full-disclosure&amp;m=110234486823233&amp;w=2" source="FULLDISC">20041206 Multiple vulnerabilities in w3who ISAPI DLL</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="w3who.dll">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-1134" published="2005-01-10" name="CVE-2004-1134" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Buffer overflow in the Microsoft W3Who ISAPI (w3who.dll) allows remote attackers to cause a denial of service and possibly execute arbitrary code via a long query string.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/18377" source="XF" adv="1">w3who-bo(18377)</ref>
      <ref url="http://www.exaprobe.com/labs/advisories/esa-2004-1206.html" source="MISC">http://www.exaprobe.com/labs/advisories/esa-2004-1206.html</ref>
      <ref url="http://marc.theaimsgroup.com/?l=full-disclosure&amp;m=110234486823233&amp;w=2" source="FULLDISC">20041206 Multiple vulnerabilities in w3who ISAPI DLL</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="w3who.dll">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1135" published="2005-01-10" name="CVE-2004-1135" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Multiple buffer overflows in WS_FTP Server 5.03 2004.10.14 allow remote attackers to cause a denial of service (service crash) via long (1) SITE, (2) XMKD, (3) MKD, and (4) RNFR commands.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/18296" source="XF" adv="1">wsftp-ftp-commands-bo(18296)</ref>
      <ref url="http://www.securiteam.com/exploits/6D00L2KBPG.html" source="MISC">http://www.securiteam.com/exploits/6D00L2KBPG.html</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110177654524819&amp;w=2" source="BUGTRAQ" adv="1">20041129 Multiple buffer overlows in WS_FTP Server Version 5.03, 2004.10.14.</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2004-November/029600.html" source="FULLDISC">20041129 Multiple buffer overlows in WS_FTP Server Version 5.03, 2004.10.14.</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ipswitch" name="ws_ftp_server">
        <vers num="5.03" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1136" published="2005-01-10" name="CVE-2004-1136" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Buffer overflow in CuteFTP Professional 6.0, and possibly other versions, allows remote FTP servers to cause a denial of service (application crash) via large replies to FTP commands.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/18309" source="XF" adv="1">cuteftp-reply-bo(18309)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110182983622642&amp;w=2" source="BUGTRAQ">20041129 CuteFTP 6.0 Professional Remote Buffer Overflow Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="globalscape" name="cuteftp">
        <vers num="6.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-1137" published="2005-01-10" name="CVE-2004-1137" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Multiple vulnerabilities in the IGMP functionality for Linux kernel 2.4.22 to 2.4.28, and 2.6.x to 2.6.9, allow local and remote attackers to cause a denial of service or execute arbitrary code via (1) the ip_mc_source function, which decrements a counter to -1, or (2) the igmp_marksources function, which does not properly validate IGMP message parameters and performs an out-of-bounds read.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" admin="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="https://bugzilla.fedora.us/show_bug.cgi?id=2336" source="FEDORA">FLSA:2336</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/18482" source="XF">linux-igmpmarksources-dos(18482)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/18481" source="XF">linux-ipmcsource-code-execution(18481)</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-092.html" source="REDHAT">RHSA-2005:092</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11144" source="OVAL">oval:org.mitre.oval:def:11144</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110306397320336&amp;w=2" source="BUGTRAQ" adv="1">20041214 [USN-38-1] Linux kernel vulnerabilities</ref>
      <ref url="http://isec.pl/vulnerabilities/isec-0018-igmp.txt" source="MISC">http://isec.pl/vulnerabilities/isec-0018-igmp.txt</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2004_44_kernel.html" source="SUSE">SUSE-SA:2004:044</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:022" source="MANDRAKE">MDKSA-2005:022</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/index.php?id=a&amp;anuncio=000930" source="CONECTIVA">CLA-2005:930</ref>
    </refs>
    <vuln_soft>
      <prod vendor="linux" name="linux_kernel">
        <vers num="2.4.0" edition="test1" />
        <vers num="2.4.0" edition="test10" />
        <vers num="2.4.0" edition="test11" />
        <vers num="2.4.0" edition="test12" />
        <vers num="2.4.0" edition="test2" />
        <vers num="2.4.0" edition="test3" />
        <vers num="2.4.0" edition="test4" />
        <vers num="2.4.0" edition="test5" />
        <vers num="2.4.0" edition="test6" />
        <vers num="2.4.0" edition="test7" />
        <vers num="2.4.0" edition="test8" />
        <vers num="2.4.0" edition="test9" />
        <vers num="2.4.1" />
        <vers num="2.4.10" />
        <vers num="2.4.11" />
        <vers num="2.4.12" />
        <vers num="2.4.13" />
        <vers num="2.4.14" />
        <vers num="2.4.15" />
        <vers num="2.4.16" />
        <vers num="2.4.17" />
        <vers num="2.4.18" edition="" />
        <vers num="2.4.18" edition=":x86" />
        <vers num="2.4.18" edition="pre1" />
        <vers num="2.4.18" edition="pre2" />
        <vers num="2.4.18" edition="pre3" />
        <vers num="2.4.18" edition="pre4" />
        <vers num="2.4.18" edition="pre5" />
        <vers num="2.4.18" edition="pre6" />
        <vers num="2.4.18" edition="pre7" />
        <vers num="2.4.18" edition="pre8" />
        <vers num="2.4.19" edition="pre1" />
        <vers num="2.4.19" edition="pre2" />
        <vers num="2.4.19" edition="pre3" />
        <vers num="2.4.19" edition="pre4" />
        <vers num="2.4.19" edition="pre5" />
        <vers num="2.4.19" edition="pre6" />
        <vers num="2.4.2" />
        <vers num="2.4.20" />
        <vers num="2.4.21" edition="pre1" />
        <vers num="2.4.21" edition="pre4" />
        <vers num="2.4.21" edition="pre7" />
        <vers num="2.4.22" />
        <vers num="2.4.23" edition="pre9" />
        <vers num="2.4.23_ow2" />
        <vers num="2.4.24" />
        <vers num="2.4.24_ow1" />
        <vers num="2.4.25" />
        <vers num="2.4.26" />
        <vers num="2.4.27" edition="pre1" />
        <vers num="2.4.27" edition="pre2" />
        <vers num="2.4.27" edition="pre3" />
        <vers num="2.4.27" edition="pre4" />
        <vers num="2.4.27" edition="pre5" />
        <vers num="2.4.28" />
        <vers num="2.4.3" />
        <vers num="2.4.4" />
        <vers num="2.4.5" />
        <vers num="2.4.6" />
        <vers num="2.4.7" />
        <vers num="2.4.8" />
        <vers num="2.4.9" />
        <vers num="2.6.0" edition="test1" />
        <vers num="2.6.0" edition="test10" />
        <vers num="2.6.0" edition="test11" />
        <vers num="2.6.0" edition="test2" />
        <vers num="2.6.0" edition="test3" />
        <vers num="2.6.0" edition="test4" />
        <vers num="2.6.0" edition="test5" />
        <vers num="2.6.0" edition="test6" />
        <vers num="2.6.0" edition="test7" />
        <vers num="2.6.0" edition="test8" />
        <vers num="2.6.0" edition="test9" />
        <vers num="2.6.1" edition="rc1" />
        <vers num="2.6.1" edition="rc2" />
        <vers num="2.6.2" />
        <vers num="2.6.3" />
        <vers num="2.6.4" />
        <vers num="2.6.5" />
        <vers num="2.6.6" edition="rc1" />
        <vers num="2.6.7" edition="rc1" />
        <vers num="2.6.8" edition="rc1" />
        <vers num="2.6.8" edition="rc2" />
        <vers num="2.6.8" edition="rc3" />
        <vers num="2.6.9" edition="2.6.20" />
        <vers num="2.6_test9_cvs" />
      </prod>
      <prod vendor="ubuntu" name="ubuntu_linux">
        <vers num="4.1" edition="" />
        <vers num="4.1" edition=":ppc" />
        <vers num="4.1" edition=":ia64" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-1138" published="2005-01-10" name="CVE-2004-1138" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">VIM before 6.3 and gVim before 6.3 allow local users to execute arbitrary commands via a file containing a crafted modeline that is executed when the file is viewed using options such as (1) termcap, (2) printdevice, (3) titleold, (4) filetype, (5) syntax, (6) backupext, (7) keymap, (8) patchmode, or (9) langmenu.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" admin="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200412-10.xml" source="GENTOO" patch="1" adv="1">GLSA-200412-10</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110313588125609&amp;w=2" source="OPENPKG" patch="1" adv="1">OpenPKG-SA-2004.052</ref>
      <ref url="https://bugzilla.fedora.us/show_bug.cgi?id=2343" source="FEDORA">FLSA:2343</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/18503" source="XF">vim-modeline-gain-privileges(18503)</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-036.html" source="REDHAT">RHSA-2005:036</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-010.html" source="REDHAT">RHSA-2005:010</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9571" source="OVAL">oval:org.mitre.oval:def:9571</ref>
    </refs>
    <vuln_soft>
      <prod vendor="vim_development_group" name="vim">
        <vers num="5.0" />
        <vers num="5.1" />
        <vers num="5.2" />
        <vers num="5.3" />
        <vers num="5.4" />
        <vers num="5.5" />
        <vers num="5.6" />
        <vers num="5.7" />
        <vers num="5.8" />
        <vers num="6.0" />
        <vers num="6.1" />
        <vers num="6.2" />
        <vers num="6.3.011" />
        <vers num="6.3.025" />
        <vers num="6.3.030" />
        <vers num="6.3.044" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1139" published="2004-12-15" name="CVE-2004-1139" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Unknown vulnerability in the DICOM dissector in Ethereal 0.10.4 through 0.10.7 allows remote attackers to cause a denial of service (application crash).</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/18484" source="XF" patch="1" adv="1">ethereal-dicom-dos(18484)</ref>
      <ref url="http://www.securityfocus.com/bid/11943" source="BID" patch="1" adv="1">11943</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-037.html" source="REDHAT" patch="1" adv="1">RHSA-2005:037</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200412-15.xml" source="GENTOO" patch="1" adv="1">GLSA-200412-15</ref>
      <ref url="http://www.ethereal.com/appnotes/enpa-sa-00016.html" source="CONFIRM" patch="1" adv="1">http://www.ethereal.com/appnotes/enpa-sa-00016.html</ref>
      <ref url="http://www.ciac.org/ciac/bulletins/p-061.shtml" source="CIAC" patch="1" adv="1">P-061</ref>
      <ref url="http://secunia.com/advisories/13468/" source="SECUNIA" patch="1" adv="1">13468</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11319" source="OVAL">oval:org.mitre.oval:def:11319</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000916" source="CONECTIVA" adv="1">CLA-2005:916</ref>
      <ref url="http://www.redhat.com/archives/fedora-legacy-announce/2006-January/msg00003.html" source="FEDORA">FLSA-2006:152922</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2004:152" source="MANDRAKE">MDKSA-2004:152</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ethereal_group" name="ethereal">
        <vers num="0.10" />
        <vers num="0.10.1" />
        <vers num="0.10.2" />
        <vers num="0.10.3" />
        <vers num="0.10.4" />
        <vers num="0.10.5" />
        <vers num="0.10.6" />
        <vers num="0.10.7" />
        <vers num="0.9" />
        <vers num="0.9.1" />
        <vers num="0.9.10" />
        <vers num="0.9.11" />
        <vers num="0.9.12" />
        <vers num="0.9.13" />
        <vers num="0.9.14" />
        <vers num="0.9.15" />
        <vers num="0.9.16" />
        <vers num="0.9.2" />
        <vers num="0.9.3" />
        <vers num="0.9.4" />
        <vers num="0.9.5" />
        <vers num="0.9.6" />
        <vers num="0.9.7" />
        <vers num="0.9.8" />
        <vers num="0.9.9" />
      </prod>
      <prod vendor="sgi" name="propack">
        <vers num="3.0" />
      </prod>
      <prod vendor="altlinux" name="alt_linux">
        <vers num="2.3" edition="" />
        <vers num="2.3" edition=":junior" />
        <vers num="2.3" edition=":compact" />
      </prod>
      <prod vendor="conectiva" name="linux">
        <vers num="10.0" />
        <vers num="9.0" />
      </prod>
      <prod vendor="debian" name="debian_linux">
        <vers num="3.0" edition="" />
        <vers num="3.0" edition=":mips" />
        <vers num="3.0" edition=":s-390" />
        <vers num="3.0" edition=":alpha" />
        <vers num="3.0" edition=":mipsel" />
        <vers num="3.0" edition=":hppa" />
        <vers num="3.0" edition=":ia-32" />
        <vers num="3.0" edition=":arm" />
        <vers num="3.0" edition=":ppc" />
        <vers num="3.0" edition=":m68k" />
        <vers num="3.0" edition=":ia-64" />
        <vers num="3.0" edition=":sparc" />
      </prod>
      <prod vendor="redhat" name="enterprise_linux">
        <vers num="2.1" edition="" />
        <vers num="2.1" edition=":workstation_ia64" />
        <vers num="2.1" edition=":advanced_server" />
        <vers num="2.1" edition=":enterprise_server" />
        <vers num="2.1" edition=":advanced_server_ia64" />
        <vers num="2.1" edition=":enterprise_server_ia64" />
        <vers num="2.1" edition=":workstation" />
        <vers num="3.0" edition="" />
        <vers num="3.0" edition=":workstation_server" />
        <vers num="3.0" edition=":enterprise_server" />
        <vers num="3.0" edition=":advanced_server" />
      </prod>
      <prod vendor="redhat" name="enterprise_linux_desktop">
        <vers num="3.0" />
      </prod>
      <prod vendor="redhat" name="linux_advanced_workstation">
        <vers num="2.1" edition="" />
        <vers num="2.1" edition=":itanium_processor" />
        <vers num="2.1" edition=":ia64" />
      </prod>
      <prod vendor="suse" name="suse_linux">
        <vers num="8.0" edition="" />
        <vers num="8.0" edition=":i386" />
        <vers num="8.1" />
        <vers num="8.2" />
        <vers num="9.0" edition="" />
        <vers num="9.0" edition=":x86_64" />
        <vers num="9.1" />
        <vers num="9.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1140" published="2004-12-31" name="CVE-2004-1140" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Ethereal 0.9.0 through 0.10.7 allows remote attackers to cause a denial of service (application hang) and possibly fill available disk space via an invalid RTP timestamp.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/11943" source="BID" patch="1">11943</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200412-15.xml" source="GENTOO" patch="1">GLSA-200412-15</ref>
      <ref url="http://secunia.com/advisories/13468/" source="SECUNIA" patch="1">13468</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/18485" source="XF">Ethereal-rtp-dos(18485)</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-037.html" source="REDHAT">RHSA-2005:037</ref>
      <ref url="http://www.ethereal.com/appnotes/enpa-sa-00016.html" source="CONFIRM" adv="1">http://www.ethereal.com/appnotes/enpa-sa-00016.html</ref>
      <ref url="http://www.ciac.org/ciac/bulletins/p-061.shtml" source="CIAC" adv="1">P-061</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10484" source="OVAL">oval:org.mitre.oval:def:10484</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000916" source="CONECTIVA">CLA-2005:916</ref>
      <ref url="http://www.redhat.com/archives/fedora-legacy-announce/2006-January/msg00003.html" source="FEDORA">FLSA-2006:152922</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2004:152" source="MANDRAKE">MDKSA-2004:152</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ethereal_group" name="ethereal">
        <vers num="0.10.0" />
        <vers num="0.10.0a" />
        <vers num="0.10.1" />
        <vers num="0.10.2" />
        <vers num="0.10.3" />
        <vers num="0.10.4" />
        <vers num="0.10.5" />
        <vers num="0.10.6" />
        <vers num="0.10.7" />
        <vers num="0.9.0" />
        <vers num="0.9.1" />
        <vers num="0.9.10" />
        <vers num="0.9.11" />
        <vers num="0.9.12" />
        <vers num="0.9.13" />
        <vers num="0.9.14" />
        <vers num="0.9.15" />
        <vers num="0.9.16" />
        <vers num="0.9.2" />
        <vers num="0.9.3" />
        <vers num="0.9.4" />
        <vers num="0.9.5" />
        <vers num="0.9.6" />
        <vers num="0.9.7" />
        <vers num="0.9.8" />
        <vers num="0.9.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1141" published="2004-12-31" name="CVE-2004-1141" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The HTTP dissector in Ethereal 0.10.1 through 0.10.7 allows remote attackers to cause a denial of service (application crash) via a certain packet that causes the dissector to access previously-freed memory.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/11943" source="BID" patch="1">11943</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200412-15.xml" source="GENTOO" patch="1">GLSA-200412-15</ref>
      <ref url="http://secunia.com/advisories/13468/" source="SECUNIA" patch="1">13468</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/18487" source="XF">ethereal-http-dissector-dos(18487)</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-037.html" source="REDHAT">RHSA-2005:037</ref>
      <ref url="http://www.ethereal.com/appnotes/enpa-sa-00016.html" source="CONFIRM" adv="1">http://www.ethereal.com/appnotes/enpa-sa-00016.html</ref>
      <ref url="http://www.ciac.org/ciac/bulletins/p-061.shtml" source="CIAC" adv="1">P-061</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9473" source="OVAL">oval:org.mitre.oval:def:9473</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000916" source="CONECTIVA">CLA-2005:916</ref>
      <ref url="http://www.redhat.com/archives/fedora-legacy-announce/2006-January/msg00003.html" source="FEDORA">FLSA-2006:152922</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2004:152" source="MANDRAKE">MDKSA-2004:152</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ethereal_group" name="ethereal">
        <vers num="0.10.1" />
        <vers num="0.10.2" />
        <vers num="0.10.3" />
        <vers num="0.10.4" />
        <vers num="0.10.5" />
        <vers num="0.10.6" />
        <vers num="0.10.7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1142" published="2004-12-15" name="CVE-2004-1142" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Ethereal 0.9.0 through 0.10.7 allows remote attackers to cause a denial of service (CPU consumption) via a certain malformed SMB packet.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/18488" source="XF" patch="1" adv="1">ethereal-smb-dos(18488)</ref>
      <ref url="http://www.securityfocus.com/bid/11943" source="BID" patch="1" adv="1">11943</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-037.html" source="REDHAT" patch="1" adv="1">RHSA-2005:037</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200412-15.xml" source="GENTOO" patch="1" adv="1">GLSA-200412-15</ref>
      <ref url="http://www.ethereal.com/appnotes/enpa-sa-00016.html" source="CONFIRM" patch="1" adv="1">http://www.ethereal.com/appnotes/enpa-sa-00016.html</ref>
      <ref url="http://www.debian.org/security/2004/dsa-613" source="DEBIAN" patch="1" adv="1">DSA-613</ref>
      <ref url="http://www.ciac.org/ciac/bulletins/p-061.shtml" source="CIAC" patch="1" adv="1">P-061</ref>
      <ref url="http://secunia.com/advisories/13468/" source="SECUNIA" patch="1" adv="1">13468</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11278" source="OVAL">oval:org.mitre.oval:def:11278</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000916" source="CONECTIVA" adv="1">CLA-2005:916</ref>
      <ref url="http://www.redhat.com/archives/fedora-legacy-announce/2006-January/msg00003.html" source="FEDORA">FLSA-2006:152922</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2004:152" source="MANDRAKE">MDKSA-2004:152</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ethereal_group" name="ethereal">
        <vers num="0.10" />
        <vers num="0.10.1" />
        <vers num="0.10.2" />
        <vers num="0.10.3" />
        <vers num="0.10.4" />
        <vers num="0.10.5" />
        <vers num="0.10.6" />
        <vers num="0.10.7" />
        <vers num="0.9" />
        <vers num="0.9.1" />
        <vers num="0.9.10" />
        <vers num="0.9.11" />
        <vers num="0.9.12" />
        <vers num="0.9.13" />
        <vers num="0.9.14" />
        <vers num="0.9.15" />
        <vers num="0.9.16" />
        <vers num="0.9.2" />
        <vers num="0.9.3" />
        <vers num="0.9.4" />
        <vers num="0.9.5" />
        <vers num="0.9.6" />
        <vers num="0.9.7" />
        <vers num="0.9.8" />
        <vers num="0.9.9" />
      </prod>
      <prod vendor="sgi" name="propack">
        <vers num="3.0" />
      </prod>
      <prod vendor="altlinux" name="alt_linux">
        <vers num="2.3" edition="" />
        <vers num="2.3" edition=":junior" />
        <vers num="2.3" edition=":compact" />
      </prod>
      <prod vendor="conectiva" name="linux">
        <vers num="10.0" />
        <vers num="9.0" />
      </prod>
      <prod vendor="debian" name="debian_linux">
        <vers num="3.0" edition="" />
        <vers num="3.0" edition=":mips" />
        <vers num="3.0" edition=":s-390" />
        <vers num="3.0" edition=":alpha" />
        <vers num="3.0" edition=":mipsel" />
        <vers num="3.0" edition=":hppa" />
        <vers num="3.0" edition=":ia-32" />
        <vers num="3.0" edition=":arm" />
        <vers num="3.0" edition=":ppc" />
        <vers num="3.0" edition=":m68k" />
        <vers num="3.0" edition=":ia-64" />
        <vers num="3.0" edition=":sparc" />
      </prod>
      <prod vendor="redhat" name="enterprise_linux">
        <vers num="2.1" edition="" />
        <vers num="2.1" edition=":workstation_ia64" />
        <vers num="2.1" edition=":advanced_server" />
        <vers num="2.1" edition=":enterprise_server" />
        <vers num="2.1" edition=":advanced_server_ia64" />
        <vers num="2.1" edition=":enterprise_server_ia64" />
        <vers num="2.1" edition=":workstation" />
        <vers num="3.0" edition="" />
        <vers num="3.0" edition=":workstation_server" />
        <vers num="3.0" edition=":enterprise_server" />
        <vers num="3.0" edition=":advanced_server" />
      </prod>
      <prod vendor="redhat" name="enterprise_linux_desktop">
        <vers num="3.0" />
      </prod>
      <prod vendor="redhat" name="linux_advanced_workstation">
        <vers num="2.1" edition="" />
        <vers num="2.1" edition=":itanium_processor" />
        <vers num="2.1" edition=":ia64" />
      </prod>
      <prod vendor="suse" name="suse_linux">
        <vers num="8.0" edition="" />
        <vers num="8.0" edition=":i386" />
        <vers num="8.1" />
        <vers num="8.2" />
        <vers num="9.0" edition="" />
        <vers num="9.0" edition=":x86_64" />
        <vers num="9.1" />
        <vers num="9.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-1143" published="2004-12-31" name="CVE-2004-1143" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">The password generation in mailman before 2.1.5 generates only 5 million unique passwords, which makes it easier for remote attackers to guess passwords via a brute force attack.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=286796" source="CONFIRM" patch="1">http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=286796</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/18857" source="XF">mailman-weak-encryption(18857)</ref>
      <ref url="http://secunia.com/advisories/13603/" source="SECUNIA">13603</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110549296126351&amp;w=2" source="BUGTRAQ">20050110 [USN-59-1] mailman vulnerabilities</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2005_07_mailman.html" source="SUSE">SUSE-SA:2005:007</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gnu" name="mailman">
        <vers num="1.0" />
        <vers num="1.1" />
        <vers num="2.0" edition="beta3" />
        <vers num="2.0" edition="beta4" />
        <vers num="2.0" edition="beta5" />
        <vers num="2.0.1" />
        <vers num="2.0.10" />
        <vers num="2.0.11" />
        <vers num="2.0.12" />
        <vers num="2.0.13" />
        <vers num="2.0.2" />
        <vers num="2.0.3" />
        <vers num="2.0.4" />
        <vers num="2.0.5" />
        <vers num="2.0.6" />
        <vers num="2.0.7" />
        <vers num="2.0.8" />
        <vers num="2.0.9" />
        <vers num="2.1" />
        <vers num="2.1.1" />
        <vers num="2.1.2" />
        <vers num="2.1.3" />
        <vers num="2.1.4" />
        <vers num="2.1b1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-1144" published="2004-12-31" name="CVE-2004-1144" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Unknown vulnerability in the 32bit emulation code in Linux 2.4 on AMD64 systems allows local users to gain privileges.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <env />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110376890429798&amp;w=2" source="SUSE" patch="1">SUSE-SA:2004:046</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/18686" source="XF">linux-32bit-emulation-gain-privileges(18686)</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-689.html" source="REDHAT">RHSA-2004:689</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10439" source="OVAL">oval:org.mitre.oval:def:10439</ref>
    </refs>
    <vuln_soft>
      <prod vendor="linux" name="linux_kernel">
        <vers num="2.4.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1145" published="2004-12-15" name="CVE-2004-1145" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Multiple vulnerabilities in Konqueror in KDE 3.3.1 and earlier (1) allow access to restricted Java classes via JavaScript and (2) do not properly restrict access to certain Java classes from the Java applet, which allows remote attackers to bypass sandbox restrictions and read or write arbitrary files.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/420222" source="CERT-VN" patch="1" adv="1">VU#420222</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/18596" source="XF" patch="1" adv="1">konqueror-sandbox-restriction-bypass(18596)</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-065.html" source="REDHAT" patch="1" adv="1">RHSA-2005:065</ref>
      <ref url="http://www.kde.org/info/security/advisory-20041220-1.txt" source="CONFIRM" patch="1" adv="1">http://www.kde.org/info/security/advisory-20041220-1.txt</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200501-16.xml" source="GENTOO" patch="1" adv="1">GLSA-200501-16</ref>
      <ref url="http://secunia.com/advisories/13586" source="SECUNIA" patch="1" adv="1">13586</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110356286722875&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20041220 KDE Security Advisory: Konqueror Java Vulnerability</ref>
      <ref url="http://www.heise.de/security/dienste/browsercheck/tests/java.shtml" source="MISC" adv="1">http://www.heise.de/security/dienste/browsercheck/tests/java.shtml</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10173" source="OVAL">oval:org.mitre.oval:def:10173</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2004:154" source="MANDRAKE">MDKSA-2004:154</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ethereal_group" name="ethereal">
        <vers num="0.10" />
        <vers num="0.10.1" />
        <vers num="0.10.2" />
        <vers num="0.10.3" />
        <vers num="0.10.4" />
        <vers num="0.10.5" />
        <vers num="0.10.6" />
        <vers num="0.10.7" />
        <vers num="0.9" />
        <vers num="0.9.1" />
        <vers num="0.9.10" />
        <vers num="0.9.11" />
        <vers num="0.9.12" />
        <vers num="0.9.13" />
        <vers num="0.9.14" />
        <vers num="0.9.15" />
        <vers num="0.9.16" />
        <vers num="0.9.2" />
        <vers num="0.9.3" />
        <vers num="0.9.4" />
        <vers num="0.9.5" />
        <vers num="0.9.6" />
        <vers num="0.9.7" />
        <vers num="0.9.8" />
        <vers num="0.9.9" />
      </prod>
      <prod vendor="sgi" name="propack">
        <vers num="3.0" />
      </prod>
      <prod vendor="altlinux" name="alt_linux">
        <vers num="2.3" edition="" />
        <vers num="2.3" edition=":junior" />
        <vers num="2.3" edition=":compact" />
      </prod>
      <prod vendor="conectiva" name="linux">
        <vers num="10.0" />
        <vers num="9.0" />
      </prod>
      <prod vendor="debian" name="debian_linux">
        <vers num="3.0" edition="" />
        <vers num="3.0" edition=":mips" />
        <vers num="3.0" edition=":s-390" />
        <vers num="3.0" edition=":alpha" />
        <vers num="3.0" edition=":mipsel" />
        <vers num="3.0" edition=":hppa" />
        <vers num="3.0" edition=":ia-32" />
        <vers num="3.0" edition=":arm" />
        <vers num="3.0" edition=":ppc" />
        <vers num="3.0" edition=":m68k" />
        <vers num="3.0" edition=":ia-64" />
        <vers num="3.0" edition=":sparc" />
      </prod>
      <prod vendor="redhat" name="enterprise_linux">
        <vers num="2.1" edition="" />
        <vers num="2.1" edition=":workstation_ia64" />
        <vers num="2.1" edition=":advanced_server" />
        <vers num="2.1" edition=":enterprise_server" />
        <vers num="2.1" edition=":advanced_server_ia64" />
        <vers num="2.1" edition=":enterprise_server_ia64" />
        <vers num="2.1" edition=":workstation" />
        <vers num="3.0" edition="" />
        <vers num="3.0" edition=":workstation_server" />
        <vers num="3.0" edition=":enterprise_server" />
        <vers num="3.0" edition=":advanced_server" />
      </prod>
      <prod vendor="redhat" name="enterprise_linux_desktop">
        <vers num="3.0" />
      </prod>
      <prod vendor="redhat" name="linux_advanced_workstation">
        <vers num="2.1" edition="" />
        <vers num="2.1" edition=":itanium_processor" />
        <vers num="2.1" edition=":ia64" />
      </prod>
      <prod vendor="suse" name="suse_linux">
        <vers num="8.0" edition="" />
        <vers num="8.0" edition=":i386" />
        <vers num="8.1" />
        <vers num="8.2" />
        <vers num="9.0" edition="" />
        <vers num="9.0" edition=":x86_64" />
        <vers num="9.1" />
        <vers num="9.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1146" published="2004-12-31" name="CVE-2004-1146" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in (1) main.c and (2) login.c for CVSTrac before 1.1.5 allow remote attackers to inject arbitrary HTML and web script.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/12017" source="BID" patch="1">12017</ref>
      <ref url="http://www.cvstrac.org/cvstrac/chngview?cn=321" source="CONFIRM" patch="1">http://www.cvstrac.org/cvstrac/chngview?cn=321</ref>
      <ref url="http://www.cvstrac.org/cvstrac/chngview?cn=320" source="CONFIRM" patch="1">http://www.cvstrac.org/cvstrac/chngview?cn=320</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110332469631253&amp;w=2" source="OPENPKG" patch="1">OpenPKG-SA-2004.056</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/18726" source="XF">cvstrac-main-login-xss(18726)</ref>
      <ref url="http://www.mikx.de/index.php?p=6" source="MISC">http://www.mikx.de/index.php?p=6</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2004-December/030222.html" source="FULLDISC">20041223 Cross-Site Scripting - an industry-wide problem</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cvstrac" name="cvstrac">
        <vers num="1.1" />
        <vers num="1.1.1" />
        <vers num="1.1.2" />
        <vers num="1.1.3" />
        <vers num="1.1.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-1147" published="2005-01-10" name="CVE-2004-1147" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">phpMyAdmin 2.6.0-pl2, and other versions before 2.6.1, with external transformations enabled, allows remote attackers to execute arbitrary commands via shell metacharacters.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" admin="1" />
    </loss_types>
    <vuln_types>
      <design />
      <config />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/18441" source="XF">phpmyadmin-command-execute(18441)</ref>
      <ref url="http://www.exaprobe.com/labs/advisories/esa-2004-1213.html" source="MISC">http://www.exaprobe.com/labs/advisories/esa-2004-1213.html</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110295781828323&amp;w=2" source="BUGTRAQ" adv="1">20041213 Multiple vulnerabilities in phpMyAdmin</ref>
    </refs>
    <vuln_soft>
      <prod vendor="phpmyadmin" name="phpmyadmin">
        <vers num="2.4.0" />
        <vers num="2.5.0" />
        <vers num="2.5.1" />
        <vers num="2.5.2" />
        <vers num="2.5.4" />
        <vers num="2.5.5" />
        <vers num="2.5.5_pl1" />
        <vers num="2.5.5_rc1" />
        <vers num="2.5.5_rc2" />
        <vers num="2.5.6_rc1" />
        <vers num="2.5.7" />
        <vers num="2.5.7_pl1" />
        <vers num="2.6.0_pl1" />
        <vers num="2.6.0_pl2" />
        <vers num="2.6.0_pl3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1148" published="2005-01-10" name="CVE-2004-1148" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">phpMyAdmin before 2.6.1, when configured with UploadDir functionality, allows remote attackers to read arbitrary files via the sql_localfile parameter.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
      <config />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/18441" source="XF">phpmyadmin-command-execute(18441)</ref>
      <ref url="http://www.exaprobe.com/labs/advisories/esa-2004-1213.html" source="MISC">http://www.exaprobe.com/labs/advisories/esa-2004-1213.html</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110295781828323&amp;w=2" source="BUGTRAQ" adv="1">20041213 Multiple vulnerabilities in phpMyAdmin</ref>
    </refs>
    <vuln_soft>
      <prod vendor="phpmyadmin" name="phpmyadmin">
        <vers num="2.4.0" />
        <vers num="2.5.0" />
        <vers num="2.5.1" />
        <vers num="2.5.2" />
        <vers num="2.5.4" />
        <vers num="2.5.5" />
        <vers num="2.5.5_pl1" />
        <vers num="2.5.5_rc1" />
        <vers num="2.5.5_rc2" />
        <vers num="2.5.6_rc1" />
        <vers num="2.5.7" />
        <vers num="2.5.7_pl1" />
        <vers num="2.6.0_pl1" />
        <vers num="2.6.0_pl2" />
        <vers num="2.6.0_pl3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-1149" published="2005-01-10" name="CVE-2004-1149" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Computer Associates eTrust EZ Antivirus 7.0.0 to 7.0.4, including 7.0.1.4, installs its files with insecure permissions (ACLs), which allows local users to gain privileges by replacing critical programs with malicious ones, as demonstrated using VetMsg.exe.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" admin="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/18502" source="XF">etrust-antivirus-insecure-permissions(18502)</ref>
      <ref url="http://www.idefense.com/application/poi/display?id=164" source="IDEFENSE">20041215 Computer Associates eTrust EZ Antivirus Insecure File Permission Vulnerability</ref>
      <ref url="http://crm.my-etrust.com/login.asp?username=guest&amp;target=DOCUMENT&amp;openparameter" source="CONFIRM">http://crm.my-etrust.com/login.asp?username=guest&amp;target=DOCUMENT&amp;openparameter</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ca" name="etrust_ez_antivirus">
        <vers num="7.0" />
        <vers num="7.0.1" />
        <vers num="7.0.1.1" />
        <vers num="7.0.1.2" />
        <vers num="7.0.1.3" />
        <vers num="7.0.1.4" />
        <vers num="7.0.2" />
        <vers num="7.0.2.1" />
        <vers num="7.0.3" />
        <vers num="7.0.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1150" published="2004-12-31" name="CVE-2004-1150" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_score="5.1" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="4.9" CVSS_base_score="5.1">
    <desc>
      <descript source="cve">Stack-based buffer overflow in the in_cdda.dll plugin for Winamp 5.0 through 5.08c allows attackers to execute arbitrary code via a cda:// URL with a long (1) device name or (2) sound track number, as demonstrated with a .m3u or .pls playlist file.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/18840" source="XF">winamp-incdda-bo(18840)</ref>
      <ref url="http://www.winamp.com/player/version_history.php" source="CONFIRM">http://www.winamp.com/player/version_history.php</ref>
      <ref url="http://www.nsfocus.com/english/homepage/research/0501.htm" source="MISC">http://www.nsfocus.com/english/homepage/research/0501.htm</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110684140108614&amp;w=2" source="BUGTRAQ">20050127 NSFOCUS SA2005-01 : Buffer Overflow in WinAMP in_cdda.dll CDA Device Name</ref>
      <ref url="http://www.securityfocus.com/bid/12381" source="BID">12381</ref>
      <ref url="http://secunia.com/advisories/13781" source="SECUNIA">13781</ref>
    </refs>
    <vuln_soft>
      <prod vendor="nullsoft" name="winamp">
        <vers num="5.0" />
        <vers num="5.01" />
        <vers num="5.02" />
        <vers num="5.03" />
        <vers num="5.04" />
        <vers num="5.05" />
        <vers num="5.06" />
        <vers num="5.07" />
        <vers num="5.08c" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-1151" published="2005-01-10" name="CVE-2004-1151" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Multiple buffer overflows in the (1) sys32_ni_syscall and (2) sys32_vm86_warning functions in sys_ia32.c for Linux 2.6.x may allow local attackers to modify kernel memory and gain privileges.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.ussg.iu.edu/hypermail/linux/kernel/0411.3/1467.html" source="MLIST">[linux-kernel] 20041130 Buffer overrun in arch/x86_64/sys_ia32.c:sys32_ni_syscall()</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110306397320336&amp;w=2" source="BUGTRAQ" adv="1">20041214 [USN-38-1] Linux kernel vulnerabilities</ref>
      <ref url="http://linux.bkbits.net:8080/linux-2.6/gnupatch@41ae6af1cR3mJYlW6D8EHxCKSxuJiQ" source="MISC">http://linux.bkbits.net:8080/linux-2.6/gnupatch@41ae6af1cR3mJYlW6D8EHxCKSxuJiQ</ref>
      <ref url="http://linux.bkbits.net:8080/linux-2.6/cset@1.2079" source="MISC">http://linux.bkbits.net:8080/linux-2.6/cset@1.2079</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2004_44_kernel.html" source="SUSE">SUSE-SA:2004:044</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:022" source="MANDRAKE">MDKSA-2005:022</ref>
    </refs>
    <vuln_soft>
      <prod vendor="linux" name="linux_kernel">
        <vers num="2.6.0" edition="test1" />
        <vers num="2.6.0" edition="test10" />
        <vers num="2.6.0" edition="test11" />
        <vers num="2.6.0" edition="test2" />
        <vers num="2.6.0" edition="test3" />
        <vers num="2.6.0" edition="test4" />
        <vers num="2.6.0" edition="test5" />
        <vers num="2.6.0" edition="test6" />
        <vers num="2.6.0" edition="test7" />
        <vers num="2.6.0" edition="test8" />
        <vers num="2.6.0" edition="test9" />
        <vers num="2.6.1" edition="rc1" />
        <vers num="2.6.1" edition="rc2" />
        <vers num="2.6.10" edition="rc2" />
        <vers num="2.6.2" />
        <vers num="2.6.3" />
        <vers num="2.6.4" />
        <vers num="2.6.5" />
        <vers num="2.6.6" edition="rc1" />
        <vers num="2.6.7" edition="rc1" />
        <vers num="2.6.8" edition="rc1" />
        <vers num="2.6.8" edition="rc2" />
        <vers num="2.6.8" edition="rc3" />
        <vers num="2.6.9" edition="2.6.20" />
        <vers num="2.6_test9_cvs" />
      </prod>
      <prod vendor="ubuntu" name="ubuntu_linux">
        <vers num="4.1" edition="" />
        <vers num="4.1" edition=":ia64" />
        <vers num="4.1" edition=":ppc" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-1152" published="2005-01-10" name="CVE-2004-1152" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Buffer overflow in the mailListIsPdf function in Adobe Acrobat Reader 5.09 for Unix allows remote attackers to execute arbitrary code via an e-mail message with a crafted PDF attachment.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/253024" source="CERT-VN">VU#253024</ref>
      <ref url="http://www.idefense.com/application/poi/display?id=161&amp;type=vulnerabilities&amp;flashstatus=false" source="IDEFENSE" patch="1" adv="1">20041214 Adobe Acrobat Reader 5.0.9 mailListIsPdf() Buffer Overflow Vulnerability</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/18477" source="XF">adobe-acrobat-maillistlspdf-bo(18477)</ref>
      <ref url="http://www.adobe.com/support/techdocs/331153.html" source="CONFIRM">http://www.adobe.com/support/techdocs/331153.html</ref>
      <ref url="http://secunia.com/advisories/13474" source="SECUNIA">13474</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2005_01_sr.html" source="SUSE">SUSE-SR:2005:001</ref>
    </refs>
    <vuln_soft>
      <prod vendor="adobe" name="acrobat_reader">
        <vers num="5.0.9" edition="" />
        <vers num="5.0.9" edition=":unix" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-1153" published="2005-01-10" name="CVE-2004-1153" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Format string vulnerability in Adobe Acrobat Reader 6.0.0 through 6.0.2 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via an .ETD document containing format string specifiers in (1) title or (2) baseurl fields.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" admin="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.idefense.com/application/poi/display?id=163&amp;type=vulnerabilities" source="IDEFENSE" patch="1" adv="1">20041214 Adobe Reader 6.0 .ETD File Format String Vulnerability</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/18478" source="XF">adobe-acrobat-etd-format-string(18478)</ref>
      <ref url="http://www.adobe.com/support/downloads/detail.jsp?ftpID=2679" source="CONFIRM">http://www.adobe.com/support/downloads/detail.jsp?ftpID=2679</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2919" source="OVAL" sig="1">oval:org.mitre.oval:def:2919</ref>
    </refs>
    <vuln_soft>
      <prod vendor="adobe" name="acrobat_reader">
        <vers num="6.0" />
        <vers num="6.0.2" />
        <vers num="8.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-1154" published="2005-01-10" name="CVE-2004-1154" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Integer overflow in the Samba daemon (smbd) in Samba 2.x and 3.0.x through 3.0.9 allows remote authenticated users to cause a denial of service (application crash) and possibly execute arbitrary code via a Samba request with a large number of security descriptors that triggers a heap-based buffer overflow.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/226184" source="CERT-VN" adv="1">VU#226184</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/18519" source="XF" adv="1">samba-msrpc-heap-corruption(18519)</ref>
      <ref url="http://www.samba.org/samba/security/CAN-2004-1154.html" source="CONFIRM">http://www.samba.org/samba/security/CAN-2004-1154.html</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-020.html" source="REDHAT">RHSA-2005:020</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2004_45_samba.html" source="SUSE">SUSE-SA:2004:045</ref>
      <ref url="http://www.debian.org/security/2005/dsa-701" source="DEBIAN">DSA-701</ref>
      <ref url="http://secunia.com/advisories/13453/" source="SECUNIA">13453</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10236" source="OVAL">oval:org.mitre.oval:def:10236</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2005/Mar/msg00000.html" source="APPLE">APPLE-SA-2005-03-21</ref>
      <ref url="ftp://ftp.sco.com/pub/updates/UnixWare/SCOSA-2005.17/SCOSA-2005.17.txt" source="SCO">SCOSA-2005.17</ref>
      <ref url="http://www.securityfocus.com/bid/11973" source="BID">11973</ref>
      <ref url="http://www.idefense.com/application/poi/display?id=165&amp;type=vulnerabilities" source="IDEFENSE">20041216 Samba smbd Security Descriptor Integer Overflow Vulnerability</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-57730-1" source="SUNALERT">57730</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-101643-1" source="SUNALERT">101643</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:642" source="OVAL" sig="1">oval:org.mitre.oval:def:642</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1459" source="OVAL" sig="1">oval:org.mitre.oval:def:1459</ref>
    </refs>
    <vuln_soft>
      <prod vendor="samba" name="samba">
        <vers num="2.0.0" />
        <vers num="2.0.1" />
        <vers num="2.0.10" />
        <vers num="2.0.2" />
        <vers num="2.0.3" />
        <vers num="2.0.4" />
        <vers num="2.0.5" />
        <vers num="2.0.6" />
        <vers num="2.0.7" />
        <vers num="2.0.8" />
        <vers num="2.0.9" />
        <vers num="2.2.0" />
        <vers num="2.2.0a" />
        <vers num="2.2.11" />
        <vers num="2.2.12" />
        <vers num="2.2.1a" />
        <vers num="2.2.2" />
        <vers num="2.2.3" />
        <vers num="2.2.3a" />
        <vers num="2.2.4" />
        <vers num="2.2.5" />
        <vers num="2.2.6" />
        <vers num="2.2.7" />
        <vers num="2.2.7a" />
        <vers num="2.2.8" />
        <vers num="2.2.8a" />
        <vers num="2.2.9" />
        <vers num="2.2a" />
        <vers num="3.0" />
        <vers num="3.0.0" />
        <vers num="3.0.1" />
        <vers num="3.0.2" />
        <vers num="3.0.2a" />
        <vers num="3.0.3" />
        <vers num="3.0.4" edition="rc1" />
        <vers num="3.0.5" />
        <vers num="3.0.6" />
        <vers num="3.0.7" />
        <vers num="3.0.8" />
        <vers num="3.0.9" />
      </prod>
      <prod vendor="redhat" name="fedora_core">
        <vers num="core_2.0" />
        <vers num="core_3.0" />
      </prod>
      <prod vendor="suse" name="suse_linux">
        <vers num="1.0" edition="" />
        <vers num="1.0" edition=":desktop" />
        <vers num="8.1" />
        <vers num="8.2" />
        <vers num="9.0" edition="" />
        <vers num="9.0" edition=":enterprise_server" />
        <vers num="9.0" edition=":x86_64" />
        <vers num="9.1" />
        <vers num="9.2" />
      </prod>
      <prod vendor="trustix" name="secure_linux">
        <vers num="2.0" />
        <vers num="2.1" />
        <vers num="2.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-1155" published="2004-12-31" name="CVE-2004-1155" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Internet Explorer 5.01 through 6 allows remote attackers to spoof arbitrary web sites by injecting content from one window into another window whose name is known but resides in a different domain, as demonstrated using a pop-up window on a trusted web site, aka the "window injection" vulnerability.  NOTE: later research shows that Internet Explorer 7 on Windows XP SP2 is also vulnerable.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/11855" source="BID" adv="1">11855</ref>
      <ref url="http://secunia.com/secunia_research/2004-13/advisory/" source="MISC">http://secunia.com/secunia_research/2004-13/advisory/</ref>
      <ref url="http://secunia.com/multiple_browsers_window_injection_vulnerability_test/" source="MISC" adv="1">http://secunia.com/multiple_browsers_window_injection_vulnerability_test/</ref>
      <ref url="http://secunia.com/advisories/22628" source="SECUNIA">22628</ref>
      <ref url="http://secunia.com/advisories/13251/" source="SECUNIA">13251</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/449917/100/0/threaded" source="BUGTRAQ">20061025 IE7 status: 8 days after release, 3 unfixed issues</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="ie">
        <vers num="5.0.1" edition="" />
        <vers num="5.0.1" edition=":windows_95" />
        <vers num="5.0.1" edition=":windows_nt_4.0" />
        <vers num="5.0.1" edition=":windows_2000" />
        <vers num="5.0.1" edition=":windows_98" />
        <vers num="5.0.1" edition="sp1" />
        <vers num="5.0.1" edition="sp2" />
        <vers num="5.0.1" edition="sp3" />
        <vers num="5.0.1" edition="sp4" />
        <vers num="5.2.3" edition="" />
        <vers num="5.2.3" edition=":macintosh" />
        <vers num="5.5" edition="preview" />
        <vers num="5.5" edition="sp1" />
        <vers num="5.5" edition="sp2" />
        <vers num="6.0" edition="sp1" />
        <vers num="6.0" edition="sp2" />
        <vers num="7.0" edition="windows_xp_sp2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1156" published="2004-12-31" name="CVE-2004-1156" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Mozilla before 1.7.6, and Firefox before 1.0.1, allows remote attackers to spoof arbitrary web sites by injecting content from one window into a target window whose name is known but resides in a different domain, as demonstrated using a pop-up window on a trusted web site, aka the "window injection" vulnerability.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
      <design />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-384.html" source="REDHAT">RHSA-2005:384</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-176.html" source="REDHAT">RHSA-2005:176</ref>
      <ref url="http://www.mozilla.org/security/announce/mfsa2005-13.html" source="CONFIRM">http://www.mozilla.org/security/announce/mfsa2005-13.html</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200503-30.xml" source="GENTOO">GLSA-200503-30</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200503-10.xml" source="GENTOO">GLSA-200503-10</ref>
      <ref url="http://secunia.com/secunia_research/2004-13/advisory/" source="MISC" adv="1">http://secunia.com/secunia_research/2004-13/advisory/</ref>
      <ref url="http://secunia.com/multiple_browsers_window_injection_vulnerability_test/" source="MISC">http://secunia.com/multiple_browsers_window_injection_vulnerability_test/</ref>
      <ref url="http://secunia.com/advisories/13129/" source="SECUNIA" adv="1">13129</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10117" source="OVAL">oval:org.mitre.oval:def:10117</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:100045" source="OVAL" sig="1">oval:org.mitre.oval:def:100045</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="firefox">
        <vers num="0.10" />
        <vers num="0.10.1" />
        <vers num="0.8" />
        <vers num="0.9" edition="rc" />
        <vers num="0.9.1" />
        <vers num="0.9.2" />
        <vers num="0.9.3" />
        <vers num="1.0" />
      </prod>
      <prod vendor="mozilla" name="mozilla">
        <vers num="0.8" />
        <vers num="0.9.2" />
        <vers num="0.9.2.1" />
        <vers num="0.9.3" />
        <vers num="0.9.35" />
        <vers num="0.9.4" />
        <vers num="0.9.4.1" />
        <vers num="0.9.48" />
        <vers num="0.9.5" />
        <vers num="0.9.6" />
        <vers num="0.9.7" />
        <vers num="0.9.8" />
        <vers num="0.9.9" />
        <vers num="1.0" edition="rc1" />
        <vers num="1.0" edition="rc2" />
        <vers num="1.0.1" />
        <vers num="1.0.2" />
        <vers num="1.1" edition="alpha" />
        <vers num="1.1" edition="beta" />
        <vers num="1.2" edition="alpha" />
        <vers num="1.2" edition="beta" />
        <vers num="1.2.1" />
        <vers num="1.3" />
        <vers num="1.3.1" />
        <vers num="1.4" edition="alpha" />
        <vers num="1.4" edition="beta" />
        <vers num="1.4.1" />
        <vers num="1.4.2" />
        <vers num="1.5" />
        <vers num="1.5.1" />
        <vers num="1.6" />
        <vers num="1.7" edition="alpha" />
        <vers num="1.7" edition="beta" />
        <vers num="1.7" edition="rc1" />
        <vers num="1.7" edition="rc2" />
        <vers num="1.7" edition="rc3" />
        <vers num="1.7.1" />
        <vers num="1.7.2" />
        <vers num="1.7.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-1157" published="2005-01-10" name="CVE-2004-1157" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Opera 7.x up to 7.54, and possibly other versions, allows remote attackers to spoof arbitrary web sites by injecting content from one window into a target window whose name is known but resides in a different domain, as demonstrated using a pop-up window on a trusted web site, aka the "window injection" vulnerability.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <access />
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200502-17.xml" source="GENTOO">GLSA-200502-17</ref>
      <ref url="http://secunia.com/secunia_research/2004-13/advisory/" source="MISC">http://secunia.com/secunia_research/2004-13/advisory/</ref>
      <ref url="http://secunia.com/multiple_browsers_window_injection_vulnerability_test/" source="MISC">http://secunia.com/multiple_browsers_window_injection_vulnerability_test/</ref>
      <ref url="http://secunia.com/advisories/13253/" source="SECUNIA" adv="1">13253</ref>
    </refs>
    <vuln_soft>
      <prod vendor="opera_software" name="opera_web_browser">
        <vers num="7.54" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-1158" published="2005-01-10" name="CVE-2004-1158" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Konqueror 3.x up to 3.2.2-6, and possibly other versions, allows remote attackers to spoof arbitrary web sites by injecting content from one window into a target window or tab whose name is known but resides in a different domain, as demonstrated using a pop-up window on a trusted web site, aka the "window injection" vulnerability.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <access />
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/11853" source="BID" patch="1" adv="1">11853</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110296048613575&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20041213 KDE Security Advisory: Konqueror Window Injection Vulnerability</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-009.html" source="REDHAT">RHSA-2005:009</ref>
      <ref url="http://www.kde.org/info/security/advisory-20041213-1.txt" source="CONFIRM">http://www.kde.org/info/security/advisory-20041213-1.txt</ref>
      <ref url="http://secunia.com/secunia_research/2004-13/advisory/" source="MISC">http://secunia.com/secunia_research/2004-13/advisory/</ref>
      <ref url="http://secunia.com/multiple_browsers_window_injection_vulnerability_test/" source="MISC" adv="1">http://secunia.com/multiple_browsers_window_injection_vulnerability_test/</ref>
      <ref url="http://secunia.com/advisories/13254/" source="SECUNIA">13254</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11056" source="OVAL">oval:org.mitre.oval:def:11056</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2005_01_sr.html" source="SUSE">SUSE-SR:2005:001</ref>
      <ref url="http://secunia.com/advisories/13560" source="SECUNIA">13560</ref>
      <ref url="http://secunia.com/advisories/13486" source="SECUNIA">13486</ref>
      <ref url="http://secunia.com/advisories/13477" source="SECUNIA">13477</ref>
      <ref url="http://secunia.com/advisories/13254" source="SECUNIA">13254</ref>
    </refs>
    <vuln_soft>
      <prod vendor="kde" name="konqueror">
        <vers num="2.1.1" />
        <vers num="2.1.2" />
        <vers num="2.2.1" />
        <vers num="2.2.2" />
        <vers num="3.0" />
        <vers num="3.0.1" />
        <vers num="3.0.2" />
        <vers num="3.0.3" />
        <vers num="3.0.5" />
        <vers num="3.0.5b" />
        <vers num="3.1" />
        <vers num="3.1.1" />
        <vers num="3.1.2" />
        <vers num="3.1.3" />
        <vers num="3.1.4" />
        <vers num="3.1.5" />
        <vers num="3.2.1" />
        <vers num="3.2.2.6" />
        <vers num="3.2.3" />
        <vers num="3.3" />
        <vers num="3.3.1" />
        <vers num="3.3.2" />
      </prod>
      <prod vendor="mandrakesoft" name="mandrake_linux">
        <vers num="10.0" edition="" />
        <vers num="10.0" edition=":amd64" />
        <vers num="10.1" edition="" />
        <vers num="10.1" edition=":x86_64" />
      </prod>
      <prod vendor="redhat" name="fedora_core">
        <vers num="core_2.0" />
        <vers num="core_3.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" seq="2004-1159" reject="1" published="2005-01-10" name="CVE-2004-1159" modified="2008-09-10">
    <desc>
      <descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: CVE-2004-1122, CVE-2004-1314.  Reason: this was an out-of-band assignment duplicate intended for one issue, but the description and references inadvertently combined multiple issues.  Notes: All CVE users should consult CVE-2004-1122 and CVE-2004-1314 to determine which ID is appropriate.  All references and descriptions in this candidate have been removed to prevent accidental usage.</descript>
    </desc>
    <refs />
  </entry>
  <entry type="CVE" severity="High" seq="2004-1160" published="2005-01-10" name="CVE-2004-1160" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Netscape 7.x to 7.2, and possibly other versions, allows remote attackers to spoof arbitrary web sites by injecting content from one window into a target window whose name is known but resides in a different domain, as demonstrated using a pop-up window on a trusted web site, aka the "window injection" vulnerability.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <access />
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/11852" source="BID" adv="1">11852</ref>
      <ref url="http://secunia.com/secunia_research/2004-13/advisory/" source="MISC">http://secunia.com/secunia_research/2004-13/advisory/</ref>
      <ref url="http://secunia.com/multiple_browsers_window_injection_vulnerability_test/" source="MISC" adv="1">http://secunia.com/multiple_browsers_window_injection_vulnerability_test/</ref>
      <ref url="http://secunia.com/advisories/13402/" source="SECUNIA">13402</ref>
    </refs>
    <vuln_soft>
      <prod vendor="netscape" name="navigator">
        <vers num="7.0" />
        <vers num="7.0.2" />
        <vers num="7.1" />
        <vers num="7.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-1161" published="2005-01-10" name="CVE-2004-1161" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">rssh 2.2.2 and earlier does not properly restrict programs that can be run, which could allow remote authenticated users to bypass intended access restrictions and execute arbitrary programs via (1) rdist -P, (2) rsync, or (3) scp -S.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <access />
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200412-01.xml" source="GENTOO" patch="1" adv="1">GLSA-200412-01</ref>
      <ref url="http://www.securityfocus.com/bid/11792" source="BID" adv="1">11792</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110202047507273&amp;w=2" source="BUGTRAQ" adv="1">20041202 rssh and scponly arbitrary command execution</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110581113814623&amp;w=2" source="BUGTRAQ">20050115 Re: rssh and scponly arbitrary command execution</ref>
    </refs>
    <vuln_soft>
      <prod vendor="rssh" name="rssh">
        <vers num="2.0" />
        <vers num="2.1" />
        <vers num="2.2" />
        <vers num="2.2.1" />
        <vers num="2.2.2" />
      </prod>
      <prod vendor="gentoo" name="linux">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-1162" published="2005-01-10" name="CVE-2004-1162" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">The unison command in scponly before 4.0 does not properly restrict programs that can be run, which could allow remote authenticated users to bypass intended access restrictions and execute arbitrary programs via the (1) -rshcmd or (2) -sshcmd flags.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/11791" source="BID" patch="1" adv="1">11791</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/18362" source="XF" adv="1">scponly-commandline-command-execution(18362)</ref>
      <ref url="http://www.sublimation.org/scponly/#relnotes" source="CONFIRM">http://www.sublimation.org/scponly/#relnotes</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200412-01.xml" source="GENTOO">GLSA-200412-01</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110581113814623&amp;w=2" source="BUGTRAQ">20050115 Re: rssh and scponly arbitrary command execution</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110202047507273&amp;w=2" source="BUGTRAQ">20041202 rssh and scponly arbitrary command execution</ref>
    </refs>
    <vuln_soft>
      <prod vendor="scponly" name="scponly">
        <vers num="2.0" />
        <vers num="2.1" />
        <vers num="2.3" />
        <vers num="2.4" />
        <vers num="3.0" />
        <vers num="3.11" />
        <vers num="3.5" />
        <vers num="3.8" />
        <vers num="3.9" />
      </prod>
      <prod vendor="gentoo" name="linux">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1163" published="2005-01-10" name="CVE-2004-1163" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Cisco CNS Network Registrar Central Configuration Management (CCM) server 6.0 through 6.1.1.3 allows remote attackers to cause a denial of service (CPU consumption) by ending a connection after sending a certain sequence of packets.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/18327" source="XF" adv="1">cisco-cns-ccm-dos(18327)</ref>
      <ref url="http://www.cisco.com/en/US/products/products_security_advisory09186a008036786d.shtml" source="CISCO">20041202 Cisco Network Registrar Denial of Service Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="cns_network_registrar">
        <vers num="6.0" />
        <vers num="6.0.1" />
        <vers num="6.0.2" />
        <vers num="6.0.3" />
        <vers num="6.0.4" />
        <vers num="6.0.5" />
        <vers num="6.0.5.2" />
        <vers num="6.0.5.3" />
        <vers num="6.0.5.4" />
        <vers num="6.1" />
        <vers num="6.1.1" />
        <vers num="6.1.1.1" />
        <vers num="6.1.1.2" />
        <vers num="6.1.1.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1164" published="2005-01-10" name="CVE-2004-1164" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The lock manager in Cisco CNS Network Registrar 6.0 through 6.1.1.3 allows remote attackers to cause a denial of service (process crash) via a certain "unexpected packet sequence."</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/18328" source="XF" adv="1">cisco-cns-lock-dos(18328)</ref>
      <ref url="http://www.securityfocus.com/bid/11793" source="BID" adv="1">11793</ref>
      <ref url="http://www.cisco.com/en/US/products/products_security_advisory09186a008036786d.shtml" source="CISCO">20041202 Cisco Network Registrar Denial of Service Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="cns_network_registrar">
        <vers num="6.0" />
        <vers num="6.0.1" />
        <vers num="6.0.2" />
        <vers num="6.0.3" />
        <vers num="6.0.4" />
        <vers num="6.0.5" />
        <vers num="6.0.5.2" />
        <vers num="6.0.5.3" />
        <vers num="6.0.5.4" />
        <vers num="6.1" />
        <vers num="6.1.1" />
        <vers num="6.1.1.1" />
        <vers num="6.1.1.2" />
        <vers num="6.1.1.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-1165" published="2005-01-10" name="CVE-2004-1165" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Konqueror 3.3.1 allows remote attackers to execute arbitrary FTP commands via an ftp:// URL that contains a URL-encoded newline ("%0a") before the FTP command, which causes the commands to be inserted into the resulting FTP session, as demonstrated using a PORT command.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/18384" source="XF" adv="1">web-browser-ftp-command-execution(18384)</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-065.html" source="REDHAT">RHSA-2005:065</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-009.html" source="REDHAT">RHSA-2005:009</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200501-18.xml" source="GENTOO">GLSA-200501-18</ref>
      <ref url="http://www.debian.org/security/2005/dsa-631" source="DEBIAN">DSA-631</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9645" source="OVAL">oval:org.mitre.oval:def:9645</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:045" source="MANDRAKE">MDKSA-2005:045</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110245752232681&amp;w=2" source="BUGTRAQ">20041205 7a69Adv#16 - Konqueror FTP command injection</ref>
    </refs>
    <vuln_soft>
      <prod vendor="kde" name="kdelibs">
        <vers num="3.1" />
        <vers num="3.1.1" />
        <vers num="3.1.2" />
        <vers num="3.1.3" />
        <vers num="3.1.4" />
        <vers num="3.1.5" />
        <vers num="3.2" />
        <vers num="3.2.1" />
        <vers num="3.2.2" />
      </prod>
      <prod vendor="kde" name="konqueror">
        <vers num="3.3.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-1166" published="2004-12-31" name="CVE-2004-1166" modified="2011-09-27" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">CRLF injection vulnerability in Microsoft Internet Explorer 6.0.2800.1106 and earlier allows remote attackers to execute arbitrary FTP commands via an ftp:// URL that contains a URL-encoded newline ("%0a") before the FTP command, which causes the commands to be inserted into the resulting FTP session, as demonstrated using a PORT command.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/18384" source="XF" adv="1">web-browser-ftp-command-execution(18384)</ref>
      <ref url="http://www.vupen.com/english/advisories/2008/0870" source="VUPEN" adv="1">ADV-2008-0870</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/3212" source="VUPEN" adv="1">ADV-2006-3212</ref>
      <ref url="http://www.securityfocus.com/bid/28208" source="BID">28208</ref>
      <ref url="http://www.securityfocus.com/bid/11826" source="BID" adv="1">11826</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/489500/100/0/threaded" source="BUGTRAQ">20080313 Rapid7 Advisory R7-0032: Microsoft Internet Explorer FTP Command Injection Vulnerability</ref>
      <ref url="http://www.rapid7.com/advisories/R7-0032.jsp" source="MISC">http://www.rapid7.com/advisories/R7-0032.jsp</ref>
      <ref url="http://www.osvdb.org/12299" source="OSVDB">12299</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms06-042.mspx" source="MS">MS06-042</ref>
      <ref url="http://securitytracker.com/id?1012444" source="SECTRACK">1012444</ref>
      <ref url="http://secunia.com/advisories/29346" source="SECUNIA" adv="1">29346</ref>
      <ref url="http://secunia.com/advisories/13404" source="SECUNIA" adv="1">13404</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110253463305359&amp;w=2" source="BUGTRAQ">20041207 7a69Adv#15 - Internet Explorer FTP command injection</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:462" source="OVAL" sig="1">oval:org.mitre.oval:def:462</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="ie">
        <vers num="6.0" edition="sp1" />
        <vers num="6.0" edition="sp2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1167" published="2005-01-10" name="CVE-2004-1167" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">mirrorselect before 0.89 creates temporary files in a world-writable location with predictable file names, which allows remote attackers to overwrite arbitrary files via a symlink attack.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200412-05.xml" source="GENTOO" patch="1" adv="1">GLSA-200412-05</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/18382" source="XF" adv="1">mirrorselect-symlink(18382)</ref>
      <ref url="http://secunia.com/advisories/13392/" source="SECUNIA">13392</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gentoo" name="mirrorselect">
        <vers num="0.80" />
        <vers num="0.81" />
        <vers num="0.82" />
        <vers num="0.83" />
        <vers num="0.84" />
        <vers num="0.85" />
        <vers num="0.86" />
        <vers num="0.87" />
        <vers num="0.88" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-1168" published="2005-01-10" name="CVE-2004-1168" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Stack-based buffer overflow in the WebDav handler in MaxDB WebTools 7.5.00.18 and earlier allows remote attackers to execute arbitrary code via a long Overwrite header.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110244542000340&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20041207 MaxDB WebTools &lt;= 7.5.00.18 buffer overflow and Denial of Service</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/18386" source="XF" adv="1">maxdb-webdav-bo(18386)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mysql" name="maxdb">
        <vers num="7.5.00.08" />
        <vers num="7.5.00.11" />
        <vers num="7.5.00.12" />
        <vers num="7.5.00.14" />
        <vers num="7.5.00.15" />
        <vers num="7.5.00.16" />
        <vers num="7.5.00.18" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1169" published="2005-01-10" name="CVE-2004-1169" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">MaxDB WebTools 7.5.00.18 and earlier allows remote attackers to cause a denial of service (application crash) via an HTTP GET request for a file that does not exist, followed by two carriage returns, which causes a NULL dereference.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110244542000340&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20041207 MaxDB WebTools &lt;= 7.5.00.18 buffer overflow and Denial of Service</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/18387" source="XF" adv="1">maxdb-dos(18387)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mysql" name="maxdb">
        <vers num="7.5.00.08" />
        <vers num="7.5.00.11" />
        <vers num="7.5.00.12" />
        <vers num="7.5.00.14" />
        <vers num="7.5.00.15" />
        <vers num="7.5.00.16" />
        <vers num="7.5.00.18" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-1170" published="2005-01-10" name="CVE-2004-1170" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">a2ps 4.13 allows remote attackers to execute arbitrary commands via shell metacharacters in the filename.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" admin="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/11025" source="BID" patch="1" adv="1">11025</ref>
      <ref url="http://archives.neohapsis.com/archives/fulldisclosure/2004-08/1026.html" source="FULLDISC" patch="1" adv="1">20040824 a2ps executing shell commands from file name</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/17127" source="XF" adv="1">gnu-a2ps-gain-privileges(17127)</ref>
      <ref url="http://www.securiteam.com/unixfocus/5MP0N2KDPA.html" source="MISC">http://www.securiteam.com/unixfocus/5MP0N2KDPA.html</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2004_34_xfree86_libs_xshared.html" source="SUSE">SUSE-SA:2004:034</ref>
      <ref url="http://secunia.com/advisories/12375" source="SECUNIA">12375</ref>
      <ref url="http://bugs.debian.org/283134" source="CONFIRM">http://bugs.debian.org/283134</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/419765/100/0/threaded" source="FEDORA">FLSA:152870</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2004:140" source="MANDRAKE">MDKSA-2004:140</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-57649-1&amp;searchclause=" source="SUNALERT">57649</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110598355226660&amp;w=2" source="OPENPKG">OpenPKG-SA-2005.003</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gnu" name="a2ps">
        <vers num="4.13" />
        <vers num="4.13b" />
      </prod>
      <prod vendor="sun" name="java_desktop_system">
        <vers num="2.0" />
        <vers num="2003" />
      </prod>
      <prod vendor="suse" name="suse_linux">
        <vers num="8" edition="" />
        <vers num="8" edition=":enterprise_server" />
        <vers num="8.1" />
        <vers num="8.2" />
        <vers num="9.0" edition="" />
        <vers num="9.0" edition=":enterprise_server" />
        <vers num="9.0" edition=":x86_64" />
        <vers num="9.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2004-1171" published="2005-01-10" name="CVE-2004-1171" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">KDE 3.2.x and 3.3.0 through 3.3.2, when saving credentials that are (1) manually entered by the user or (2) created by the SMB protocol handler, stores those credentials for plaintext in the user's .desktop file, which may be created with world-readable permissions, which could allow local users to obtain usernames and passwords for remote resources such as SMB shares.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
      <exception />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/305294" source="CERT-VN" adv="1">VU#305294</ref>
      <ref url="http://www.securityfocus.com/bid/11866" source="BID" patch="1" adv="1">11866</ref>
      <ref url="http://www.sec-consult.com/index.php?id=118" source="MISC">http://www.sec-consult.com/index.php?id=118</ref>
      <ref url="http://www.kde.org/info/security/advisory-20041209-1.txt" source="CONFIRM">http://www.kde.org/info/security/advisory-20041209-1.txt</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110178786809694&amp;w=2" source="BUGTRAQ" adv="1">20041129 Password Disclosure for SMB Shares in KDE's Konqueror</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/18267" source="XF">kde-smb-password-plaintext(18267)</ref>
      <ref url="http://www.osvdb.org/12248" source="OSVDB">12248</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2004:150" source="MANDRAKE">MDKSA-2004:150</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200412-16.xml" source="GENTOO">GLSA-200412-16</ref>
      <ref url="http://www.ciac.org/ciac/bulletins/p-051.shtml" source="CIAC">P-051</ref>
      <ref url="http://securitytracker.com/id?1012471" source="SECTRACK">1012471</ref>
      <ref url="http://secunia.com/advisories/13560" source="SECUNIA">13560</ref>
      <ref url="http://secunia.com/advisories/13486" source="SECUNIA">13486</ref>
      <ref url="http://secunia.com/advisories/13477" source="SECUNIA">13477</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110261063201488&amp;w=2" source="BUGTRAQ">20041209 KDE Security Advisory: plain text password exposure</ref>
      <ref url="http://archives.neohapsis.com/archives/fulldisclosure/2004-11/1292.html" source="FULLDISC">20041129 Password Disclosure for SMB Shares in KDE's Konqueror</ref>
    </refs>
    <vuln_soft>
      <prod vendor="kde" name="kde">
        <vers num="3.2" />
        <vers num="3.2.1" />
        <vers num="3.2.2" />
        <vers num="3.2.3" />
        <vers num="3.3" />
        <vers num="3.3.1" />
        <vers num="3.3.2" />
      </prod>
      <prod vendor="mandrakesoft" name="mandrake_linux">
        <vers num="10.0" edition="" />
        <vers num="10.0" edition=":amd64" />
        <vers num="10.1" edition="" />
        <vers num="10.1" edition=":x86_64" />
      </prod>
      <prod vendor="redhat" name="fedora_core">
        <vers num="core_2.0" />
        <vers num="core_3.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-1172" published="2005-01-10" name="CVE-2004-1172" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Stack-based buffer overflow in the Agent Browser in Veritas Backup Exec 8.x before 8.60.3878 Hotfix 68, and 9.x before 9.1.4691 Hotfix 40, allows remote attackers to execute arbitrary code via a registration request with a long hostname.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/907729" source="CERT-VN">VU#907729</ref>
      <ref url="http://www.securityfocus.com/bid/11974" source="BID" patch="1" adv="1">11974</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/18506" source="XF">netbackup-agent-browser-bo(18506)</ref>
      <ref url="http://www.idefense.com/application/poi/display?id=169" source="IDEFENSE">20041216 Veritas Backup Exec Agent Browser Registration Request Buffer Overflow Vulnerability</ref>
      <ref url="http://www.frsirt.com/exploits/20050111.101_BXEC.cpp.php" source="MISC">http://www.frsirt.com/exploits/20050111.101_BXEC.cpp.php</ref>
      <ref url="http://seer.support.veritas.com/docs/273850.htm" source="CONFIRM">http://seer.support.veritas.com/docs/273850.htm</ref>
      <ref url="http://seer.support.veritas.com/docs/273422.htm" source="CONFIRM">http://seer.support.veritas.com/docs/273422.htm</ref>
      <ref url="http://seer.support.veritas.com/docs/273420.htm" source="CONFIRM">http://seer.support.veritas.com/docs/273420.htm</ref>
      <ref url="http://seer.support.veritas.com/docs/273419.htm" source="CONFIRM">http://seer.support.veritas.com/docs/273419.htm</ref>
      <ref url="http://secunia.com/advisories/13495/" source="SECUNIA">13495</ref>
    </refs>
    <vuln_soft>
      <prod vendor="symantec_veritas" name="backup_exec">
        <vers num="8.0" />
        <vers num="8.5" />
        <vers num="8.6" />
        <vers num="9.0" />
        <vers num="9.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-1173" published="2004-12-31" name="CVE-2004-1173" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Internet Explorer 6 allows remote attackers to bypass the popup blocker via the document object model (DOM) methods in the DHTML Dynamic HTML (DHTML) Editing Component (DEC) and Javascript that calls showModalDialog.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/18444" source="XF">ie-popup-blocking-bypass(18444)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=110271016129952&amp;w=2" source="NTBUGTRAQ">20041210 HOW TO BREAK XP SP2 POPUP BLOCKER: kick it in the nut !</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110271114525795&amp;w=2" source="BUGTRAQ" adv="1">20041210 HOW TO BREAK XP SP2 POPUP BLOCKER: kick it in the nut !</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="ie">
        <vers num="6.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1174" published="2005-04-14" name="CVE-2004-1174" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">direntry.c in Midnight Commander (mc) 4.5.55 and earlier allows attackers to cause a denial of service by "manipulating non-existing file handles."</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <other />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.debian.org/security/2005/dsa-639" source="DEBIAN" patch="1" adv="1">DSA-639</ref>
      <ref url="http://secunia.com/advisories/13863/" source="SECUNIA" patch="1" adv="1">13863</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/18909" source="XF">midnight-commander-direntry-dos(18909)</ref>
      <ref url="http://securitytracker.com/id?1012903" source="SECTRACK">1012903</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-512.html" source="REDHAT">RHSA-2005:512</ref>
    </refs>
    <vuln_soft>
      <prod vendor="midnight_commander" name="midnight_commander">
        <vers num="4.5.40" />
        <vers num="4.5.41" />
        <vers num="4.5.42" />
        <vers num="4.5.43" />
        <vers num="4.5.44" />
        <vers num="4.5.45" />
        <vers num="4.5.46" />
        <vers num="4.5.47" />
        <vers num="4.5.48" />
        <vers num="4.5.49" />
        <vers num="4.5.50" />
        <vers num="4.5.51" />
        <vers num="4.5.52" />
        <vers num="4.5.54" />
        <vers num="4.5.55" />
        <vers num="4.6" />
      </prod>
      <prod vendor="debian" name="debian_linux">
        <vers num="3.0" edition="" />
        <vers num="3.0" edition=":mips" />
        <vers num="3.0" edition=":ia-32" />
        <vers num="3.0" edition=":s-390" />
        <vers num="3.0" edition=":alpha" />
        <vers num="3.0" edition=":arm" />
        <vers num="3.0" edition=":mipsel" />
        <vers num="3.0" edition=":ppc" />
        <vers num="3.0" edition=":hppa" />
        <vers num="3.0" edition=":m68k" />
        <vers num="3.0" edition=":ia-64" />
        <vers num="3.0" edition=":sparc" />
      </prod>
      <prod vendor="gentoo" name="linux">
        <vers num="" />
      </prod>
      <prod vendor="redhat" name="enterprise_linux">
        <vers num="2.1" edition="" />
        <vers num="2.1" edition=":workstation_ia64" />
        <vers num="2.1" edition=":advanced_server" />
        <vers num="2.1" edition=":advanced_server_ia64" />
        <vers num="2.1" edition=":workstation" />
      </prod>
      <prod vendor="redhat" name="linux_advanced_workstation">
        <vers num="2.1" edition="" />
        <vers num="2.1" edition=":itanium_processor" />
        <vers num="2.1" edition=":ia64" />
      </prod>
      <prod vendor="suse" name="suse_linux">
        <vers num="8.0" edition="" />
        <vers num="8.0" edition=":i386" />
        <vers num="8.1" />
        <vers num="8.2" />
        <vers num="9.0" edition="" />
        <vers num="9.0" edition=":x86_64" />
        <vers num="9.1" />
        <vers num="9.2" />
      </prod>
      <prod vendor="turbolinux" name="turbolinux_server">
        <vers num="7.0" />
        <vers num="8.0" />
      </prod>
      <prod vendor="turbolinux" name="turbolinux_workstation">
        <vers num="7.0" />
        <vers num="8.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-1175" published="2005-04-14" name="CVE-2004-1175" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">fish.c in midnight commander allows remote attackers execute arbitrary programs via "insecure filename quoting," possibly using shell metacharacters.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <other />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.debian.org/security/2005/dsa-639" source="DEBIAN" patch="1" adv="1">DSA-639</ref>
      <ref url="http://secunia.com/advisories/13863/" source="SECUNIA" patch="1" adv="1">13863</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/18906" source="XF" adv="1">midnight-commander-command-execution(18906)</ref>
      <ref url="http://securitytracker.com/id?1012903" source="SECTRACK">1012903</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-512.html" source="REDHAT">RHSA-2005:512</ref>
    </refs>
    <vuln_soft>
      <prod vendor="midnight_commander" name="midnight_commander">
        <vers num="4.5.40" />
        <vers num="4.5.41" />
        <vers num="4.5.42" />
        <vers num="4.5.43" />
        <vers num="4.5.44" />
        <vers num="4.5.45" />
        <vers num="4.5.46" />
        <vers num="4.5.47" />
        <vers num="4.5.48" />
        <vers num="4.5.49" />
        <vers num="4.5.50" />
        <vers num="4.5.51" />
        <vers num="4.5.52" />
        <vers num="4.5.54" />
        <vers num="4.5.55" />
        <vers num="4.6" />
      </prod>
      <prod vendor="debian" name="debian_linux">
        <vers num="3.0" edition="" />
        <vers num="3.0" edition=":mips" />
        <vers num="3.0" edition=":ia-32" />
        <vers num="3.0" edition=":s-390" />
        <vers num="3.0" edition=":alpha" />
        <vers num="3.0" edition=":arm" />
        <vers num="3.0" edition=":mipsel" />
        <vers num="3.0" edition=":ppc" />
        <vers num="3.0" edition=":hppa" />
        <vers num="3.0" edition=":m68k" />
        <vers num="3.0" edition=":ia-64" />
        <vers num="3.0" edition=":sparc" />
      </prod>
      <prod vendor="gentoo" name="linux">
        <vers num="" />
      </prod>
      <prod vendor="redhat" name="enterprise_linux">
        <vers num="2.1" edition="" />
        <vers num="2.1" edition=":workstation_ia64" />
        <vers num="2.1" edition=":advanced_server" />
        <vers num="2.1" edition=":advanced_server_ia64" />
        <vers num="2.1" edition=":workstation" />
      </prod>
      <prod vendor="redhat" name="linux_advanced_workstation">
        <vers num="2.1" edition="" />
        <vers num="2.1" edition=":itanium_processor" />
        <vers num="2.1" edition=":ia64" />
      </prod>
      <prod vendor="suse" name="suse_linux">
        <vers num="8.0" edition="" />
        <vers num="8.0" edition=":i386" />
        <vers num="8.1" />
        <vers num="8.2" />
        <vers num="9.0" edition="" />
        <vers num="9.0" edition=":x86_64" />
        <vers num="9.1" />
        <vers num="9.2" />
      </prod>
      <prod vendor="turbolinux" name="turbolinux_server">
        <vers num="7.0" />
        <vers num="8.0" />
      </prod>
      <prod vendor="turbolinux" name="turbolinux_workstation">
        <vers num="7.0" />
        <vers num="8.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-1176" published="2005-04-14" name="CVE-2004-1176" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer underflow in extfs.c in Midnight Commander (mc) 4.5.55 and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary code.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.debian.org/security/2005/dsa-639" source="DEBIAN" patch="1" adv="1">DSA-639</ref>
      <ref url="http://secunia.com/advisories/13863" source="SECUNIA" patch="1" adv="1">13863</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/18911" source="XF">midnight-commander-extfs-dos(18911)</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-217.html" source="REDHAT">RHSA-2005:217</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200502-24.xml" source="GENTOO">GLSA-200502-24</ref>
      <ref url="http://securitytracker.com/id?1012903" source="SECTRACK">1012903</ref>
    </refs>
    <vuln_soft>
      <prod vendor="midnight_commander" name="midnight_commander">
        <vers num="4.5.40" />
        <vers num="4.5.41" />
        <vers num="4.5.42" />
        <vers num="4.5.43" />
        <vers num="4.5.44" />
        <vers num="4.5.45" />
        <vers num="4.5.46" />
        <vers num="4.5.47" />
        <vers num="4.5.48" />
        <vers num="4.5.49" />
        <vers num="4.5.50" />
        <vers num="4.5.51" />
        <vers num="4.5.52" />
        <vers num="4.5.54" />
        <vers num="4.5.55" />
        <vers num="4.6" />
      </prod>
      <prod vendor="debian" name="debian_linux">
        <vers num="3.0" edition="" />
        <vers num="3.0" edition=":mips" />
        <vers num="3.0" edition=":ia-32" />
        <vers num="3.0" edition=":s-390" />
        <vers num="3.0" edition=":alpha" />
        <vers num="3.0" edition=":arm" />
        <vers num="3.0" edition=":mipsel" />
        <vers num="3.0" edition=":ppc" />
        <vers num="3.0" edition=":hppa" />
        <vers num="3.0" edition=":m68k" />
        <vers num="3.0" edition=":ia-64" />
        <vers num="3.0" edition=":sparc" />
      </prod>
      <prod vendor="gentoo" name="linux">
        <vers num="" />
      </prod>
      <prod vendor="redhat" name="enterprise_linux">
        <vers num="2.1" edition="" />
        <vers num="2.1" edition=":workstation_ia64" />
        <vers num="2.1" edition=":advanced_server" />
        <vers num="2.1" edition=":advanced_server_ia64" />
        <vers num="2.1" edition=":workstation" />
      </prod>
      <prod vendor="redhat" name="linux_advanced_workstation">
        <vers num="2.1" edition="" />
        <vers num="2.1" edition=":itanium_processor" />
        <vers num="2.1" edition=":ia64" />
      </prod>
      <prod vendor="suse" name="suse_linux">
        <vers num="8.0" edition="" />
        <vers num="8.0" edition=":i386" />
        <vers num="8.1" />
        <vers num="8.2" />
        <vers num="9.0" edition="" />
        <vers num="9.0" edition=":x86_64" />
        <vers num="9.1" />
        <vers num="9.2" />
      </prod>
      <prod vendor="turbolinux" name="turbolinux_server">
        <vers num="7.0" />
        <vers num="8.0" />
      </prod>
      <prod vendor="turbolinux" name="turbolinux_workstation">
        <vers num="7.0" />
        <vers num="8.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1177" published="2005-01-10" name="CVE-2004-1177" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in the driver script in mailman before 2.1.5 allows remote attackers to inject arbitrary web script or HTML via a URL, which is not properly escaped in the resulting error page.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.debian.org/security/2005/dsa-674" source="DEBIAN" patch="1" adv="1">DSA-674</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110549296126351&amp;w=2" source="BUGTRAQ" patch="1">20050110 [USN-59-1] mailman vulnerabilities</ref>
      <ref url="http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=287555" source="CONFIRM" patch="1">http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=287555</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/18854" source="XF">mailman-script-driver-xss(18854)</ref>
      <ref url="http://secunia.com/advisories/13603" source="SECUNIA">13603</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11113" source="OVAL">oval:org.mitre.oval:def:11113</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-235.html" source="REDHAT">RHSA-2005:235</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2005_07_mailman.html" source="SUSE">SUSE-SA:2005:007</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:015" source="MANDRAKE">MDKSA-2005:015</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gnu" name="mailman">
        <vers num="1.0" />
        <vers num="1.1" />
        <vers num="2.0" edition="beta3" />
        <vers num="2.0" edition="beta4" />
        <vers num="2.0" edition="beta5" />
        <vers num="2.0.1" />
        <vers num="2.0.10" />
        <vers num="2.0.11" />
        <vers num="2.0.12" />
        <vers num="2.0.13" />
        <vers num="2.0.2" />
        <vers num="2.0.3" />
        <vers num="2.0.4" />
        <vers num="2.0.5" />
        <vers num="2.0.6" />
        <vers num="2.0.7" />
        <vers num="2.0.8" />
        <vers num="2.0.9" />
        <vers num="2.1" />
        <vers num="2.1.1" />
        <vers num="2.1.2" />
        <vers num="2.1.3" />
        <vers num="2.1.4" />
        <vers num="2.1b1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2004-1179" published="2004-12-31" name="CVE-2004-1179" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">The debstd script in debmake 3.6.x before 3.6.10 and 3.7.x before 3.7.7 allows local users to overwrite arbitrary files via a symlink attack on temporary directories.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
      <env />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/12078" source="BID" patch="1">12078</ref>
      <ref url="http://www.derkeiler.com/Mailing-Lists/Full-Disclosure/2004-12/0645.html" source="FULLDISC" patch="1">20041223 [USN-49-1] debmake vulnerability</ref>
      <ref url="http://www.debian.org/security/2004/dsa-615" source="DEBIAN" patch="1" adv="1">DSA-615</ref>
      <ref url="http://secunia.com/advisories/13633/" source="SECUNIA" patch="1">13633</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/18646" source="XF">debmake-debstd-symlink(18646)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="debian" name="debmake">
        <vers num="3.6" />
        <vers prev="1" num="3.6.9" />
        <vers num="3.7" />
        <vers prev="1" num="3.7.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1180" published="2004-02-16" name="CVE-2004-1180" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Unknown vulnerability in the rwho daemon (rwhod) before 0.17, on little endian architectures, allows remote attackers to cause a denial of service (application crash).</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <other />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.debian.org/security/2005/dsa-678" source="DEBIAN" patch="1" adv="1">DSA-678</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:039" source="MANDRAKE">MDKSA-2005:039</ref>
      <ref url="http://secunia.com/advisories/14309" source="SECUNIA">14309</ref>
    </refs>
    <vuln_soft>
      <prod vendor="debian" name="debian_linux">
        <vers num="3.0" edition="" />
        <vers num="3.0" edition=":woody" />
      </prod>
      <prod vendor="mandrakesoft" name="mandrake_linux">
        <vers num="10.0" edition="" />
        <vers num="10.0" edition=":amd64" />
        <vers num="10.1" edition="" />
        <vers num="10.1" edition=":x86_64" />
      </prod>
      <prod vendor="mandrakesoft" name="mandrake_linux_corporate_server">
        <vers num="2.1" edition="" />
        <vers num="2.1" edition=":x86_64" />
      </prod>
      <prod vendor="sun" name="solaris">
        <vers num="9.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1181" published="2005-04-14" name="CVE-2004-1181" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">htmlheadline before 21.8 allows local users to overwrite arbitrary files via a symlink attack on temporary files.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <other />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/12147" source="BID" patch="1" adv="1">12147</ref>
      <ref url="http://www.debian.org/security/2005/dsa-622" source="DEBIAN" patch="1" adv="1">DSA-622</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/18737" source="XF" adv="1">htmlheadline-symlink(18737)</ref>
      <ref url="http://securitytracker.com/id?1012756" source="SECTRACK">1012756</ref>
      <ref url="http://secunia.com/advisories/13715" source="SECUNIA">13715</ref>
    </refs>
    <vuln_soft>
      <prod vendor="toshiaki_kanosue" name="htmlheadline">
        <vers num="21.8" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-1182" published="2004-12-31" name="CVE-2004-1182" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">hfaxd in HylaFAX before 4.2.1, when installed with a "weak" hosts.hfaxd file, allows remote attackers to authenticate and bypass intended access restrictions via a crafted (1) username or (2) hostname that satisfies a regular expression that is matched against a hosts.hfaxd entry without a password.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://security.gentoo.org/glsa/glsa-200501-21.xml" source="GENTOO" patch="1">GLSA-200501-21</ref>
      <ref url="http://marc.theaimsgroup.com/?l=hylafax&amp;m=110545119911558&amp;w=2" source="MLIST" patch="1">[hylafax-announce] 20050111 **ANOUNCE** hylafax-4.2.1 released</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110546971307585&amp;w=2" source="BUGTRAQ" patch="1">20050111 HylaFAX hfaxd unauthorized login vulnerability</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:006" source="MANDRAKE">MDKSA-2005:006</ref>
      <ref url="http://secunia.com/advisories/13812" source="SECUNIA">13812</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hylafax" name="hylafax">
        <vers num="4.1.1" />
        <vers num="4.1.2" />
        <vers num="4.1.3" />
        <vers num="4.1.5" />
        <vers num="4.1.6" />
        <vers num="4.1.7" />
        <vers num="4.1.8" />
        <vers num="4.1_beta1" />
        <vers num="4.1_beta2" />
        <vers num="4.1_beta3" />
        <vers num="4.2.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1183" published="2005-01-06" name="CVE-2004-1183" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_score="5.1" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="4.9" CVSS_base_score="5.1">
    <desc>
      <descript source="cve">Integer overflow in the tiffdump utility for libtiff 3.7.1 and earlier allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a crafted TIFF file.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input />
      <exception />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.novell.com/linux/security/advisories/2005_01_libtiff_tiff.html" source="SUSE" patch="1">SUSE-SA:2005:001</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200501-06.xml" source="GENTOO" patch="1">GLSA-200501-06</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110503635113419&amp;w=2" source="BUGTRAQ" patch="1">20050106 [USN-54-1] TIFF library tool vulnerability</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/18782" source="XF">libtiff-tiffdump-bo(18782)</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-035.html" source="REDHAT">RHSA-2005:035</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-019.html" source="REDHAT">RHSA-2005:019</ref>
      <ref url="http://secunia.com/advisories/13728/" source="SECUNIA">13728</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9743" source="OVAL">oval:org.mitre.oval:def:9743</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000920" source="CONECTIVA">CLA-2005:920</ref>
      <ref url="http://www.securityfocus.com/bid/12173" source="BID">12173</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:052" source="MANDRAKE">MDKSA-2005:052</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:002" source="MANDRAKE">MDKSA-2005:002</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:001" source="MANDRAKE">MDKSA-2005:001</ref>
      <ref url="http://secunia.com/advisories/13776" source="SECUNIA">13776</ref>
    </refs>
    <vuln_soft>
      <prod vendor="libtiff" name="libtiff">
        <vers num="3.4" />
        <vers num="3.5.1" />
        <vers num="3.5.2" />
        <vers num="3.5.3" />
        <vers num="3.5.4" />
        <vers num="3.5.5" />
        <vers num="3.5.6" />
        <vers num="3.5.7" />
        <vers num="3.6.0" />
        <vers num="3.6.1" />
        <vers num="3.7.0" />
        <vers num="3.7.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1184" published="2005-01-21" name="CVE-2004-1184" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">The EPSF pipe support in enscript 1.6.3 allows remote attackers or local users to execute arbitrary commands via shell metacharacters.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA09-133A.html" source="CERT">TA09-133A</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/19012" source="XF" patch="1" adv="1">enscript-epsf-command-ececution(19012)</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-040.html" source="REDHAT" patch="1" adv="1">RHSA-2005:040</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200502-03.xml" source="GENTOO" patch="1" adv="1">GLSA-200502-03</ref>
      <ref url="http://www.debian.org/security/2005/dsa-654" source="DEBIAN" patch="1" adv="1">DSA-654</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1297" source="VUPEN">ADV-2009-1297</ref>
      <ref url="http://support.apple.com/kb/HT3549" source="CONFIRM">http://support.apple.com/kb/HT3549</ref>
      <ref url="http://secunia.com/advisories/35074" source="SECUNIA">35074</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9658" source="OVAL">oval:org.mitre.oval:def:9658</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2009/May/msg00002.html" source="APPLE">APPLE-SA-2009-05-12</ref>
      <ref url="http://www.ubuntulinux.org/support/documentation/usn/usn-68-1" source="UBUNTU">USN-68-1</ref>
      <ref url="http://www.securityfocus.com/bid/12329" source="BID">12329</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/435199/100/0/threaded" source="BUGTRAQ">20060526 rPSA-2006-0083-1 enscript</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/419768/100/0/threaded" source="FEDORA">FLSA:152892</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:033" source="MANDRAKE">MDKSA-2005:033</ref>
      <ref url="http://securitytracker.com/id?1012965" source="SECTRACK">1012965</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gnu" name="enscript">
        <vers num="1.4" />
        <vers num="1.5" />
        <vers num="1.6" />
        <vers num="1.6.1" />
        <vers num="1.6.2" />
        <vers num="1.6.3" />
        <vers num="1.6.4" />
      </prod>
      <prod vendor="sgi" name="propack">
        <vers num="3.0" />
      </prod>
      <prod vendor="redhat" name="fedora_core">
        <vers num="core_2.0" />
        <vers num="core_3.0" />
      </prod>
      <prod vendor="suse" name="suse_linux">
        <vers num="1.0" />
        <vers num="2.0" />
        <vers num="3.0" />
        <vers num="4.0" />
        <vers num="4.2" />
        <vers num="4.3" />
        <vers num="4.4" />
        <vers num="4.4.1" />
        <vers num="5.0" />
        <vers num="5.1" />
        <vers num="5.2" />
        <vers num="5.3" />
        <vers num="6.0" />
        <vers num="6.1" edition="alpha" />
        <vers num="6.2" />
        <vers num="6.3" edition="" />
        <vers num="6.3" edition=":ppc" />
        <vers num="6.3" edition="alpha" />
        <vers num="6.4" edition="" />
        <vers num="6.4" edition=":i386" />
        <vers num="6.4" edition=":ppc" />
        <vers num="6.4" edition="alpha" />
        <vers num="7.0" edition="" />
        <vers num="7.0" edition=":sparc" />
        <vers num="7.0" edition=":i386" />
        <vers num="7.0" edition=":ppc" />
        <vers num="7.0" edition="alpha" />
        <vers num="7.1" edition="" />
        <vers num="7.1" edition=":spa" />
        <vers num="7.1" edition=":sparc" />
        <vers num="7.1" edition=":x86" />
        <vers num="7.1" edition="alpha" />
        <vers num="7.2" edition="" />
        <vers num="7.2" edition=":i386" />
        <vers num="7.3" edition="" />
        <vers num="7.3" edition=":ppc" />
        <vers num="7.3" edition=":i386" />
        <vers num="7.3" edition=":sparc" />
        <vers num="8.0" edition="" />
        <vers num="8.0" edition=":i386" />
        <vers num="8.1" />
        <vers num="8.2" />
        <vers num="9.0" edition="" />
        <vers num="9.0" edition=":x86_64" />
        <vers num="9.1" edition="" />
        <vers num="9.1" edition=":x86_64" />
        <vers num="9.2" edition="" />
        <vers num="9.2" edition=":x86_64" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-1185" published="2005-01-21" name="CVE-2004-1185" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Enscript 1.6.3 does not sanitize filenames, which allows remote attackers or local users to execute arbitrary commands via crafted filenames.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA09-133A.html" source="CERT">TA09-133A</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200502-03.xml" source="GENTOO" patch="1">GLSA-200502-03</ref>
      <ref url="http://www.debian.org/security/2005/dsa-654" source="DEBIAN" patch="1" adv="1">DSA-654</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/19029" source="XF">enscript-filename-command-execution(19029)</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1297" source="VUPEN">ADV-2009-1297</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-040.html" source="REDHAT">RHSA-2005:040</ref>
      <ref url="http://support.apple.com/kb/HT3549" source="CONFIRM">http://support.apple.com/kb/HT3549</ref>
      <ref url="http://secunia.com/advisories/35074" source="SECUNIA">35074</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10808" source="OVAL">oval:org.mitre.oval:def:10808</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2009/May/msg00002.html" source="APPLE">APPLE-SA-2009-05-12</ref>
      <ref url="http://www.ubuntulinux.org/support/documentation/usn/usn-68-1" source="UBUNTU">USN-68-1</ref>
      <ref url="http://www.securityfocus.com/bid/12329" source="BID">12329</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/435199/100/0/threaded" source="BUGTRAQ">20060526 rPSA-2006-0083-1 enscript</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/419768/100/0/threaded" source="FEDORA">FLSA:152892</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:033" source="MANDRAKE">MDKSA-2005:033</ref>
      <ref url="http://securitytracker.com/id?1012965" source="SECTRACK">1012965</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gnu" name="enscript">
        <vers num="1.3.0" />
        <vers num="1.4.0" />
        <vers num="1.5.0" />
        <vers num="1.6.0" />
        <vers num="1.6.1" />
        <vers num="1.6.2" />
        <vers num="1.6.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1186" published="2004-12-31" name="CVE-2004-1186" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Multiple buffer overflows in enscript 1.6.3 allow remote attackers or local users to cause a denial of service (application crash).</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA09-133A.html" source="CERT">TA09-133A</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200502-03.xml" source="GENTOO" patch="1">GLSA-200502-03</ref>
      <ref url="http://www.debian.org/security/2005/dsa-654" source="DEBIAN" patch="1" adv="1">DSA-654</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/19033" source="XF">enscript-multiple-bo(19033)</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1297" source="VUPEN">ADV-2009-1297</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-040.html" source="REDHAT">RHSA-2005:040</ref>
      <ref url="http://support.apple.com/kb/HT3549" source="CONFIRM">http://support.apple.com/kb/HT3549</ref>
      <ref url="http://secunia.com/advisories/35074" source="SECUNIA">35074</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11134" source="OVAL">oval:org.mitre.oval:def:11134</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2009/May/msg00002.html" source="APPLE">APPLE-SA-2009-05-12</ref>
      <ref url="http://www.ubuntulinux.org/support/documentation/usn/usn-68-1" source="UBUNTU">USN-68-1</ref>
      <ref url="http://www.securityfocus.com/bid/12329" source="BID">12329</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/435199/100/0/threaded" source="BUGTRAQ">20060526 rPSA-2006-0083-1 enscript</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/419768/100/0/threaded" source="FEDORA">FLSA:152892</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:033" source="MANDRAKE">MDKSA-2005:033</ref>
      <ref url="http://securitytracker.com/id?1012965" source="SECTRACK">1012965</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gnu" name="enscript">
        <vers num="1.6.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-1187" published="2005-01-10" name="CVE-2004-1187" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Heap-based buffer overflow in the pnm_get_chunk function for xine 0.99.2, and other packages such as MPlayer that use the same code, allows remote attackers to execute arbitrary code via long PNA_TAG values, a different vulnerability than CVE-2004-1188.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.idefense.com/application/poi/display?id=176&amp;type=vulnerabilities" source="IDEFENSE" patch="1" adv="1">20041221 Multiple Vendor Xine version 0.99.2 PNM Handler PNA_TAG Heap Overflow Vulnerability</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/18640" source="XF">xine-pnatag-bo(18640)</ref>
      <ref url="http://www.mplayerhq.hu/MPlayer/patches/pnm_fix_20041215.diff" source="CONFIRM">http://www.mplayerhq.hu/MPlayer/patches/pnm_fix_20041215.diff</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:011" source="MANDRAKE">MDKSA-2005:011</ref>
      <ref url="http://cvs.sourceforge.net/viewcvs.py/xine/xine-lib/src/input/pnm.c?r1=1.20&amp;r2=1.21" source="CONFIRM">http://cvs.sourceforge.net/viewcvs.py/xine/xine-lib/src/input/pnm.c?r1=1.20&amp;r2=1.21</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mplayer" name="mplayer">
        <vers num="0.90" />
        <vers num="0.90_pre" />
        <vers num="0.90_rc" />
        <vers num="0.90_rc4" />
        <vers num="0.91" />
        <vers num="0.92" />
        <vers num="0.92.1" />
        <vers num="0.92_cvs" />
        <vers num="1.0_pre1" />
        <vers num="1.0_pre2" />
        <vers num="1.0_pre3" />
        <vers num="1.0_pre3try2" />
        <vers num="1.0_pre4" />
        <vers num="1.0_pre5" />
        <vers num="1.0_pre5try1" />
        <vers num="1.0_pre5try2" />
        <vers num="head_cvs" />
      </prod>
      <prod vendor="xine" name="xine">
        <vers num="0.9.13" />
        <vers num="0.9.18" />
        <vers num="0.9.8" />
        <vers num="1_alpha" />
        <vers num="1_beta1" />
        <vers num="1_beta10" />
        <vers num="1_beta11" />
        <vers num="1_beta12" />
        <vers num="1_beta2" />
        <vers num="1_beta3" />
        <vers num="1_beta4" />
        <vers num="1_beta5" />
        <vers num="1_beta6" />
        <vers num="1_beta7" />
        <vers num="1_beta8" />
        <vers num="1_beta9" />
        <vers num="1_rc0" />
        <vers num="1_rc0a" />
        <vers num="1_rc1" />
        <vers num="1_rc2" />
        <vers num="1_rc3" />
        <vers num="1_rc3a" />
        <vers num="1_rc3b" />
        <vers num="1_rc4" />
        <vers num="1_rc5" />
        <vers num="1_rc6" />
        <vers num="1_rc6a" />
        <vers num="1_rc7" />
        <vers num="1_rc8" />
      </prod>
      <prod vendor="xine" name="xine-lib">
        <vers num="0.9.13" />
        <vers num="0.9.8" />
        <vers num="0.99" />
        <vers num="1_alpha" />
        <vers num="1_beta1" />
        <vers num="1_beta10" />
        <vers num="1_beta11" />
        <vers num="1_beta12" />
        <vers num="1_beta2" />
        <vers num="1_beta3" />
        <vers num="1_beta4" />
        <vers num="1_beta5" />
        <vers num="1_beta6" />
        <vers num="1_beta7" />
        <vers num="1_beta8" />
        <vers num="1_beta9" />
        <vers num="1_rc0" />
        <vers num="1_rc1" />
        <vers num="1_rc2" />
        <vers num="1_rc3" />
        <vers num="1_rc3a" />
        <vers num="1_rc3b" />
        <vers num="1_rc3c" />
        <vers num="1_rc4" />
        <vers num="1_rc5" />
        <vers num="1_rc6" />
        <vers num="1_rc6a" />
        <vers num="1_rc7" />
      </prod>
      <prod vendor="mandrakesoft" name="mandrake_linux">
        <vers num="10.0" edition="" />
        <vers num="10.0" edition=":amd64" />
        <vers num="10.1" edition="" />
        <vers num="10.1" edition=":x86_64" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-1188" published="2005-01-10" name="CVE-2004-1188" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">The pnm_get_chunk function in xine 0.99.2 and earlier, and other packages such as MPlayer that use the same code, does not properly verify that the chunk size is less than the PREAMBLE_SIZE, which causes a read operation with a negative length that leads to a buffer overflow via (1) RMF_TAG, (2) DATA_TAG, (3) PROP_TAG, (4) MDPR_TAG, and (5) CONT_TAG values, a different vulnerability than CVE-2004-1187.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.idefense.com/application/poi/display?id=177&amp;type=vulnerabilities" source="IDEFENSE" patch="1" adv="1">20041221 Multiple Vendor Xine version 0.99.2 PNM Handler Negative Read Length Heap Overflow Vulnerability</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/18638" source="XF">xine-pnmgetchunk-bo(18638)</ref>
      <ref url="http://www.mplayerhq.hu/MPlayer/patches/pnm_fix_20041215.diff" source="CONFIRM">http://www.mplayerhq.hu/MPlayer/patches/pnm_fix_20041215.diff</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:011" source="MANDRAKE">MDKSA-2005:011</ref>
      <ref url="http://cvs.sourceforge.net/viewcvs.py/xine/xine-lib/src/input/pnm.c?r1=1.20&amp;r2=1.21" source="CONFIRM">http://cvs.sourceforge.net/viewcvs.py/xine/xine-lib/src/input/pnm.c?r1=1.20&amp;r2=1.21</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mplayer" name="mplayer">
        <vers num="0.90" />
        <vers num="0.90_pre" />
        <vers num="0.90_rc" />
        <vers num="0.90_rc4" />
        <vers num="0.91" />
        <vers num="0.92" />
        <vers num="0.92.1" />
        <vers num="0.92_cvs" />
        <vers num="1.0_pre1" />
        <vers num="1.0_pre2" />
        <vers num="1.0_pre3" />
        <vers num="1.0_pre3try2" />
        <vers num="1.0_pre4" />
        <vers num="1.0_pre5" />
        <vers num="1.0_pre5try1" />
        <vers num="1.0_pre5try2" />
        <vers num="head_cvs" />
      </prod>
      <prod vendor="xine" name="xine">
        <vers num="0.9.13" />
        <vers num="0.9.18" />
        <vers num="0.9.8" />
        <vers num="1_alpha" />
        <vers num="1_beta1" />
        <vers num="1_beta10" />
        <vers num="1_beta11" />
        <vers num="1_beta12" />
        <vers num="1_beta2" />
        <vers num="1_beta3" />
        <vers num="1_beta4" />
        <vers num="1_beta5" />
        <vers num="1_beta6" />
        <vers num="1_beta7" />
        <vers num="1_beta8" />
        <vers num="1_beta9" />
        <vers num="1_rc0" />
        <vers num="1_rc0a" />
        <vers num="1_rc1" />
        <vers num="1_rc2" />
        <vers num="1_rc3" />
        <vers num="1_rc3a" />
        <vers num="1_rc3b" />
        <vers num="1_rc4" />
        <vers num="1_rc5" />
        <vers num="1_rc6" />
        <vers num="1_rc6a" />
        <vers num="1_rc7" />
        <vers num="1_rc8" />
      </prod>
      <prod vendor="xine" name="xine-lib">
        <vers num="0.9.13" />
        <vers num="0.9.8" />
        <vers num="0.99" />
        <vers num="1_alpha" />
        <vers num="1_beta1" />
        <vers num="1_beta10" />
        <vers num="1_beta11" />
        <vers num="1_beta12" />
        <vers num="1_beta2" />
        <vers num="1_beta3" />
        <vers num="1_beta4" />
        <vers num="1_beta5" />
        <vers num="1_beta6" />
        <vers num="1_beta7" />
        <vers num="1_beta8" />
        <vers num="1_beta9" />
        <vers num="1_rc0" />
        <vers num="1_rc1" />
        <vers num="1_rc2" />
        <vers num="1_rc3" />
        <vers num="1_rc3a" />
        <vers num="1_rc3b" />
        <vers num="1_rc3c" />
        <vers num="1_rc4" />
        <vers num="1_rc5" />
        <vers num="1_rc6" />
        <vers num="1_rc6a" />
        <vers num="1_rc7" />
      </prod>
      <prod vendor="mandrakesoft" name="mandrake_linux">
        <vers num="10.0" edition="" />
        <vers num="10.0" edition=":amd64" />
        <vers num="10.1" edition="" />
        <vers num="10.1" edition=":x86_64" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-1189" published="2004-12-31" name="CVE-2004-1189" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">The add_to_history function in svr_principal.c in libkadm5srv for MIT Kerberos 5 (krb5) up to 1.3.5, when performing a password change, does not properly track the password policy's history count and the maximum number of keys, which can cause an array index out-of-bounds error and may allow authenticated users to execute arbitrary code via a heap-based buffer overflow.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://web.mit.edu/kerberos/advisories/MITKRB5-SA-2004-004-pwhist.txt" source="CONFIRM" patch="1" adv="1">http://web.mit.edu/kerberos/advisories/MITKRB5-SA-2004-004-pwhist.txt</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110358420909358&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20041220 MITKRB5-SA-2004-004: heap overflow in libkadm5srv</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/18621" source="XF">kerberos-libkadm5srv-bo(18621)</ref>
      <ref url="http://www.trustix.org/errata/2004/0069" source="TRUSTIX">2004-0069</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-045.html" source="REDHAT">RHSA-2005:045</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-012.html" source="REDHAT">RHSA-2005:012</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11911" source="OVAL">oval:org.mitre.oval:def:11911</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110548298407590&amp;w=2" source="BUGTRAQ">20050110 [USN-58-1] MIT Kerberos server vulnerability</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000917" source="CONECTIVA">CLA-2005:917</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2004:156" source="MANDRAKE">MDKSA-2004:156</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2005/Aug/msg00000.html" source="APPLE">APPLE-SA-2005-08-15</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2005//Aug/msg00001.html" source="APPLE">APPLE-SA-2005-08-17</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mit" name="kerberos">
        <vers num="5-1.2" />
        <vers num="5-1.3.1" />
        <vers prev="1" num="5-1.3.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2004-1190" published="2005-01-10" name="CVE-2004-1190" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">SUSE Linux before 9.1 and SUSE Linux Enterprise Server before 9 do not properly check commands sent to CD devices that have been opened read-only, which could allow local users to conduct unauthorized write activities to modify the firmware of associated SCSI devices.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.novell.com/linux/security/advisories/2004_42_kernel.html" source="SUSE" patch="1" adv="1">SUSE-SA:2004:042</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/18370" source="XF">suse-scsi-firmware-overwrite(18370)</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9369" source="OVAL">oval:org.mitre.oval:def:9369</ref>
      <ref url="http://www.securityfocus.com/bid/11784" source="BID">11784</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2006-0101.html" source="REDHAT">RHSA-2006:0101</ref>
      <ref url="http://secunia.com/advisories/18510" source="SECUNIA">18510</ref>
    </refs>
    <vuln_soft>
      <prod vendor="suse" name="suse_linux">
        <vers num="8.1" edition="" />
        <vers num="8.1" edition=":enterprise_server" />
        <vers num="8.2" edition="" />
        <vers num="8.2" edition=":enterprise_server" />
        <vers num="9.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2004-1191" published="2005-01-10" name="CVE-2004-1191" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:H/Au:N/C:P/I:N/A:N)" CVSS_score="1.2" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="1.9" CVSS_base_score="1.2">
    <desc>
      <descript source="cve">Race condition in SuSE Linux 8.1 through 9.2, when run on SMP systems that have more than 4GB of memory, could allow local users to read unauthorized memory from "foreign memory pages."</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <race />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/18137" source="XF">linux-smbrecvtrans2-memory-leak(18137)</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2004_42_kernel.html" source="SUSE">SUSE-SA:2004:042</ref>
    </refs>
    <vuln_soft>
      <prod vendor="suse" name="suse_linux">
        <vers num="8.1" />
        <vers num="9.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-1192" published="2005-01-10" name="CVE-2004-1192" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Format string vulnerability in the lprintf function in Citadel/UX 6.27 and earlier allows remote attackers to execute arbitrary code via format string specifiers sent to the server.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" admin="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/18429" source="XF">citadel-format-string(18429)</ref>
      <ref url="http://www.nosystem.com.ar/advisories/advisory-09.txt" source="MISC">http://www.nosystem.com.ar/advisories/advisory-09.txt</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110304986223400&amp;w=2" source="BUGTRAQ">20041214 Re: Citadel/UX &lt;= v6.27 Remote Format String Vulnerability</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110295469430696&amp;w=2" source="BUGTRAQ">20041213 Citadel/UX &lt;= v6.27 Remote Format String Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="citadel" name="ux">
        <vers num="6.07" />
        <vers num="6.08" />
        <vers num="6.23" />
        <vers num="6.24" />
        <vers num="6.26" />
        <vers num="6.27" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1193" published="2005-01-10" name="CVE-2004-1193" modified="2009-04-03" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:C/A:C)" CVSS_score="6.6" CVSS_impact_subscore="9.2" CVSS_exploit_subscore="3.9" CVSS_base_score="6.6">
    <desc>
      <descript source="cve">Prevx Home 1.0 allows local users with administrator privileges to bypass the intrusion prevention features by directly writing to \device\physicalmemory, which restores the running kernel's original SDT ServiceTable.</descript>
    </desc>
    <loss_types>
      <avail />
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/18195" source="XF">prevx-home-settings-disable(18195)</ref>
      <ref url="http://securitytracker.com/id?1012294" source="SECTRACK">1012294</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110138413816367&amp;w=2" source="BUGTRAQ">20041124 Re: [SIG^2 G-TEC] Prevx Home v1.0 Instrusion Prevention Features Can Be Disabled by Direct Service Table Restoration </ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110118902823639&amp;w=2" source="BUGTRAQ">20041122 [SIG^2 G-TEC] Prevx Home v1.0 Instrusion Prevention Features Can Be Disabled by Direct Service Table Restoration</ref>
    </refs>
    <vuln_soft>
      <prod vendor="prevx" name="prevx_home">
        <vers num="1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1194" published="2005-01-10" name="CVE-2004-1194" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Buffer overflow in Star Wars Battlefront 1.11 and earlier allows remote attackers to cause a denial of service (application crash) via a long nickname.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/18256" source="XF" adv="1">star-wars-nickname-bo(18256)</ref>
      <ref url="http://www.securityfocus.com/bid/11750" source="BID" adv="1">11750</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110132227932050&amp;w=2" source="BUGTRAQ">20041124 Limited buffer-overflow and arbitrary memory access in Star Wars</ref>
    </refs>
    <vuln_soft>
      <prod vendor="lucasarts" name="star_wars_battlefront">
        <vers num="1.11" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1195" published="2005-01-10" name="CVE-2004-1195" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Star Wars Battlefront 1.11 and earlier allows remote attackers to cause a denial of service (application crash) via a join request that contains a memory address that causes the server to read arbitrary memory.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/18257" source="XF" adv="1">star-wars-packet-dos(18257)</ref>
      <ref url="http://www.securityfocus.com/bid/11750" source="BID" adv="1">11750</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110132227932050&amp;w=2" source="BUGTRAQ">20041124 Limited buffer-overflow and arbitrary memory access in Star Wars Battlefront 1.1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="lucasarts" name="star_wars_battlefront">
        <vers num="1.11" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1196" published="2005-01-10" name="CVE-2004-1196" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in inmail.pl in Insite Inmail allows remote attackers to inject arbitrary web script or HTML via the acao parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/18268" source="XF">insite-inmail-inshop-xss(18268)</ref>
      <ref url="http://www.securityfocus.com/bid/11758" source="BID">11758</ref>
      <ref url="http://secunia.com/advisories/13188/" source="SECUNIA" adv="1">13188</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110140029419018&amp;w=2" source="BUGTRAQ">20041124 XSS in Brazilian Insite products</ref>
    </refs>
    <vuln_soft>
      <prod vendor="insite" name="inmail">
        <vers num="" />
      </prod>
      <prod vendor="insite" name="inshop">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1197" published="2005-01-10" name="CVE-2004-1197" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in inshop.pl in Insite inShop allows remote attackers to inject arbitrary web script or HTML via the screen parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/18268" source="XF" adv="1">insite-inmail-inshop-xss(18268)</ref>
      <ref url="http://www.securityfocus.com/bid/11758" source="BID" adv="1">11758</ref>
      <ref url="http://secunia.com/advisories/13188/" source="SECUNIA" adv="1">13188</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110140029419018&amp;w=2" source="BUGTRAQ">20041124 XSS in Brazilian Insite products</ref>
    </refs>
    <vuln_soft>
      <prod vendor="insite" name="inmail">
        <vers num="" />
      </prod>
      <prod vendor="insite" name="inshop">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1198" published="2004-12-31" name="CVE-2004-1198" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Microsoft Internet Explorer allows remote attackers to cause a denial of service (application crash from memory consumption), as demonstrated using Javascript code that continuously creates nested arrays and then sorts the newly created arrays.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <design />
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/18282" source="XF" adv="1">web-browser-array-dos(18282)</ref>
      <ref url="http://www.securityfocus.com/bid/11751" source="BID" adv="1">11751</ref>
      <ref url="http://www.securityfocus.com/archive/1/382257" source="BUGTRAQ">20041125 MSIE flaws: nested array sort() loop Stack overflow exception</ref>
      <ref url="http://archives.neohapsis.com/archives/fulldisclosure/2004-11/1221.html" source="FULLDISC" adv="1">20041125 MSIE &amp; FIREFOX flaws: "detailed" advisory and comments that you probably don't want to read anyway</ref>
    </refs>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1199" published="2005-01-10" name="CVE-2004-1199" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Safari 1.2.4 on Mac OS X 10.3.6 allows remote attackers to cause a denial of service (application crash from memory exhaustion), as demonstrated using Javascript code that continuously creates nested arrays and then sorts the newly created arrays.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/18282" source="XF" adv="1">web-browser-array-dos(18282)</ref>
      <ref url="http://www.securityfocus.com/bid/11759" source="BID" adv="1">11759</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2004-November/029458.html" source="FULLDISC">20041125 More Browser flaws on MACOSX: nested array sort() loop Stack overflow exception</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="safari">
        <vers num="1.0" />
        <vers num="1.1" />
        <vers num="1.2" />
        <vers num="1.2.1" />
        <vers num="1.2.2" />
        <vers num="1.2.3" />
        <vers num="beta2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1200" published="2004-12-31" name="CVE-2004-1200" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Firefox and Mozilla allow remote attackers to cause a denial of service (application crash from memory consumption), as demonstrated using Javascript code that continuously creates nested arrays and then sorts the newly created arrays.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/18282" source="XF" adv="1">web-browser-array-dos(18282)</ref>
      <ref url="http://www.securityfocus.com/bid/11760" source="BID">11760</ref>
      <ref url="http://www.securityfocus.com/bid/11752" source="BID" adv="1">11752</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2004-November/029491.html" source="FULLDISC">20041125 MSIE &amp; FIREFOX flaws: "detailed" advisory and comments that you probably don't want to read anyway</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2004-November/029434.html" source="FULLDISC">20041125 FIREFOX flaws: nested array sort() loop Stack overflow exception</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="firefox">
        <vers num="0.10" />
        <vers num="0.10.1" />
        <vers num="0.8" />
        <vers num="0.9" edition="rc" />
        <vers num="0.9.1" />
        <vers num="0.9.2" />
        <vers num="0.9.3" />
        <vers num="preview_release" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1201" published="2005-01-10" name="CVE-2004-1201" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Opera 7.54 allows remote attackers to cause a denial of service (application crash from memory exhaustion), as demonstrated using Javascript code that continuously creates nested arrays and then sorts the newly created arrays.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/18282" source="XF" adv="1">web-browser-array-dos(18282)</ref>
      <ref url="http://www.securityfocus.com/bid/11762" source="BID" adv="1">11762</ref>
      <ref url="http://marc.theaimsgroup.com/?l=full-disclosure&amp;m=110141347502530&amp;w=2" source="FULLDISC">20041125 Re: MSIE flaws: nested array sort() loop Stack overflow exception</ref>
      <ref url="http://marc.theaimsgroup.com/?l=full-disclosure&amp;m=110144136213993&amp;w=2" source="FULLDISC">20041125 Re: Opera flaws: nested array sort() loop Stack overflow exception</ref>
    </refs>
    <vuln_soft>
      <prod vendor="opera_software" name="opera_web_browser">
        <vers num="5.0" edition="" />
        <vers num="5.0" edition=":linux" />
        <vers num="5.0" edition=":mac" />
        <vers num="5.0.2" edition="" />
        <vers num="5.0.2" edition=":win32" />
        <vers num="5.1.0" edition="" />
        <vers num="5.1.0" edition=":win32" />
        <vers num="5.1.1" edition="" />
        <vers num="5.1.1" edition=":win32" />
        <vers num="5.12" edition="" />
        <vers num="5.12" edition=":win32" />
        <vers num="6.0" edition="" />
        <vers num="6.0" edition=":win32" />
        <vers num="6.0.1" edition="" />
        <vers num="6.0.1" edition=":win32" />
        <vers num="6.0.1" edition=":linux" />
        <vers num="6.0.2" edition="" />
        <vers num="6.0.2" edition=":linux" />
        <vers num="6.0.2" edition=":win32" />
        <vers num="6.0.3" edition="" />
        <vers num="6.0.3" edition=":linux" />
        <vers num="6.0.3" edition=":win32" />
        <vers num="6.0.4" edition="" />
        <vers num="6.0.4" edition=":win32" />
        <vers num="6.0.5" edition="" />
        <vers num="6.0.5" edition=":win32" />
        <vers num="6.0.6" edition="" />
        <vers num="6.0.6" edition=":win32" />
        <vers num="6.10" edition="" />
        <vers num="6.10" edition=":linux" />
        <vers num="7.0" edition="" />
        <vers num="7.0" edition=":win32" />
        <vers num="7.0.1" edition="" />
        <vers num="7.0.1" edition=":win32" />
        <vers num="7.0.2" edition="" />
        <vers num="7.0.2" edition=":win32" />
        <vers num="7.0.3" edition="" />
        <vers num="7.0.3" edition=":win32" />
        <vers num="7.0_beta1" edition="" />
        <vers num="7.0_beta1" edition=":win32" />
        <vers num="7.0_beta2" edition="" />
        <vers num="7.0_beta2" edition=":win32" />
        <vers num="7.10" />
        <vers num="7.11" />
        <vers num="7.11b" />
        <vers num="7.11j" />
        <vers num="7.20" />
        <vers num="7.20_beta1_build2981" />
        <vers num="7.21" />
        <vers num="7.22" />
        <vers num="7.23" />
        <vers num="7.50" />
        <vers num="7.51" />
        <vers num="7.52" />
        <vers num="7.53" />
        <vers num="7.54" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1202" published="2005-01-10" name="CVE-2004-1202" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in parser.php in phpCMS 1.2.1 and earlier, with non-stealth and debug modes enabled, allows remote attackers to inject arbitrary web script or HTML via the file parameter.</descript>
    </desc>
    <sols>
      <sol source="nvd">Successful exploitation requires that both the non-stealth and the debug modes are enabled.</sol>
    </sols>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/18272" source="XF" patch="1">phpcms-parser-xss(18272)</ref>
      <ref url="http://www.securityfocus.com/bid/11765" source="BID" patch="1">11765</ref>
      <ref url="http://www.phpcms.de/download/index.en.html" source="CONFIRM" patch="1">http://www.phpcms.de/download/index.en.html</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110149207123510&amp;w=2" source="BUGTRAQ" patch="1">20041126 phpCMS &lt;= 1.2.1 Xss Vulnerability, Information disclosure</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2004-November/029499.html" source="FULLDISC" patch="1">20041126 phpCMS &lt;= 1.2.1 Xss Vulnerability, Information disclosure</ref>
    </refs>
    <vuln_soft>
      <prod vendor="phpcms" name="phpcms">
        <vers num="1.1.9" />
        <vers num="1.2" />
        <vers num="1.2.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1203" published="2005-01-10" name="CVE-2004-1203" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">parser.php in phpCMS 1.2.1 and earlier, with non-stealth and debug modes enabled, allows remote attackers to gain sensitive information via an invalid file parameter, which reveals the web server's installation path.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
      <config />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110149207123510&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20041126 phpCMS &lt;= 1.2.1 Xss Vulnerability, Information disclosure</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/18279" source="XF">phpcms-parser-path-disclosure(18279)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/18272" source="XF">phpcms-parser-xss(18272)</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2004-November/029499.html" source="FULLDISC">20041126 phpCMS &lt;= 1.2.1 Xss Vulnerability, Information disclosure</ref>
    </refs>
    <vuln_soft>
      <prod vendor="phpcms" name="phpcms">
        <vers num="1.1.9" />
        <vers num="1.2.0" />
        <vers num="1.2.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2004-1204" published="2005-01-10" name="CVE-2004-1204" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">FluxBox 0.9.10 and earlier versions allows local users to cause a denial of service (application crash) by calling Xman with a long -title value, possibly triggering a buffer overflow.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/18264" source="XF" adv="1">fluxbox-xman-dos(18264)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110149783715867&amp;w=2" source="BUGTRAQ" adv="1">20041126 FluxBox crash vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="fluxbox-team" name="fluxbot">
        <vers prev="1" num="0.9.10" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1205" published="2005-01-10" name="CVE-2004-1205" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">codebrowserpntm.php in PnTresMailer 6.03 allows remote attackers to gain sensitive information via an invalid filetohighlight parameter, which reveals the full path in an error message.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/18263" source="XF" adv="1">pntresmailer-information-disclosure(18263)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110149886306037&amp;w=2" source="BUGTRAQ" adv="1">20041126 PnTresMailer code browser 6.03 Vulnerabilities</ref>
    </refs>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1206" published="2005-01-10" name="CVE-2004-1206" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in codebrowserpntm.php in pnTresMailer 6.0.3 allows remote attackers to read arbitrary files via a .. (dot dot) in the filetodownload parameter.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/18263" source="XF">pntresmailer-information-disclosure(18263)</ref>
      <ref url="http://www.securityfocus.com/bid/11767" source="BID" adv="1">11767</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110149886306037&amp;w=2" source="BUGTRAQ">20041126 PnTresMailer code browser 6.03 Vulnerabilities</ref>
    </refs>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1207" published="2005-01-10" name="CVE-2004-1207" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The Serious engine, as used in (1) Alpha Black Zero Intrepid Protocol 1.04 and earlier, (2) Nitro family, and (3) Serious Sam Second Encounter 1.07 allows remote attackers to cause a denial of service (server crash) via a large number of UDP join requests that exceeds the maximum player limit, as originally reported for Alpha Black Zero.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/17545" source="XF">alphablackzero-udp-packet-dos(17545)</ref>
      <ref url="http://www.securityfocus.com/bid/11279" source="BID">11279</ref>
      <ref url="http://securitytracker.com/id?1011454" source="SECTRACK">1011454</ref>
      <ref url="http://secunia.com/advisories/12687" source="SECUNIA">12687</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109651567308405&amp;w=2" source="BUGTRAQ">20040929 Crash in Alpha Black Zero 1.04</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110180289205605&amp;w=2" source="BUGTRAQ">20041128 Players overflow in Serious engine UDP (was Alpha Black Zero, 29 Sep 2004)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="serioussam" name="seriousengine">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-1208" published="2005-01-10" name="CVE-2004-1208" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Buffer overflow in Orbz 2.10 and earlier allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a long password field in a join request.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/18298" source="XF" adv="1">orbz-join-password-bo(18298)</ref>
      <ref url="http://www.securityfocus.com/bid/11774" source="BID" adv="1">11774</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110176280402580&amp;w=2" source="BUGTRAQ" adv="1">20041129 Buffer-overflow in Orbz 2.10</ref>
    </refs>
    <vuln_soft>
      <prod vendor="21-6_productions" name="orbz">
        <vers num="2.10" />
        <vers num="2.5" />
        <vers num="2.6" />
        <vers num="2.7" />
        <vers num="2.8" />
        <vers num="2.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1209" published="2005-01-10" name="CVE-2004-1209" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Verisign Payflow Link, when running with empty Accepted URL fields, does not properly verify the data in the hidden AMOUNT field, which allows remote attackers to modify the price of the items that they purchase.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
      <config />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110181288820226&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20041129 [SHK-001]Payflow Link Default Config may lead to Hidden Field Modification</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/18299" source="XF" adv="1">payflow-link-modification(18299)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="verisign" name="payflow_link">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1210" published="2005-01-10" name="CVE-2004-1210" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in proxylog.dat in IPCop 1.4.1 and possibly other versions, allows remote attackers to inject arbitrary web script or HTML via the (1) url or (2) part variables.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/18301" source="XF">ipcop-proxylogdat-xss(18301)</ref>
      <ref url="http://www.securityfocus.com/bid/11779" source="BID">11779</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110197682705001&amp;w=2" source="BUGTRAQ">20041201 [KA Advisory 0411291] IPCop Cross Site Scripting Vulnerability in proxylog.dat</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ipcop" name="ipcop">
        <vers num="1.4.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-1211" published="2005-01-10" name="CVE-2004-1211" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Multiple buffer overflows in the IMAP service in Mercury/32 4.01a allow remote authenticated users to cause a denial of service (application crash) and possibly execute arbitrary code via long arguments to the (1) EXAMINE, (2) SUBSCRIBE, (3) STATUS, (4) APPEND, (5) CHECK, (6) CLOSE, (7) EXPUNGE, (8) FETCH, (9) RENAME, (10) DELETE, (11) LIST, (12) SEARCH, (13) CREATE, or (14) UNSUBSCRIBE commands.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/11775" source="BID" patch="1" adv="1">11775</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/18318" source="XF" adv="1">mercury-command-bo(18318)</ref>
      <ref url="http://www.osvdb.org/12508" source="OSVDB">12508</ref>
      <ref url="http://secunia.com/advisories/13348" source="SECUNIA" adv="1">13348</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110193702909991&amp;w=2" source="BUGTRAQ" adv="1">20041201 Multiple buffer overflows exist in Mercury/32, v4.01a, Dec 8 2003.</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2004-December/029701.html" source="FULLDISC">20041201 Multiple buffer overflows exist in Mercury/32, v4.01a, Dec 8 2003.</ref>
      <ref url="http://home.kabelfoon.nl/~jaabogae/han/m_401b.html" source="CONFIRM">http://home.kabelfoon.nl/~jaabogae/han/m_401b.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="david_harris" name="mercury">
        <vers num="4.0.1a" edition="" />
        <vers num="4.0.1a" edition=":win32" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1212" published="2005-01-10" name="CVE-2004-1212" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in btdownload.php in Blog Torrent preview 0.8 allows remote attackers to download arbitrary files via a .. (dot dot) in the file argument.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/11795" source="BID" patch="1" adv="1">11795</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110200971917165&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20041202 Blog Torrent preview 0.8 - arbitary file download</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/18356" source="XF" adv="1">blogtorrent-btdownloadphp-dir-traversal(18356)</ref>
      <ref url="http://cvs.sourceforge.net/viewcvs.py/battletorrent/btorrent_server/btdownload.php?r1=1.6&amp;r2=1.7" source="CONFIRM">http://cvs.sourceforge.net/viewcvs.py/battletorrent/btorrent_server/btdownload.php?r1=1.6&amp;r2=1.7</ref>
    </refs>
    <vuln_soft>
      <prod vendor="blog_torrent" name="blog_torrent_preview">
        <vers num="0.8" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1213" published="2005-01-10" name="CVE-2004-1213" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in index.php in Advanced Guestbook 2.3.1, 2.2, and possibly other versions allows remote attackers to inject arbitrary web script or HTML via the entry parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/18334" source="XF">advguestbook-indexphp-xss(18334)</ref>
      <ref url="http://www.securityfocus.com/bid/11798" source="BID">11798</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110238530129498&amp;w=2" source="BUGTRAQ">20041204 Re: Advanced Guestbook</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110206527624612&amp;w=2" source="BUGTRAQ">20041202 Advanced Guestbook</ref>
    </refs>
    <vuln_soft>
      <prod vendor="advanced_guestbook" name="advanced_guestbook">
        <vers num="2.2" />
        <vers num="2.3.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-1214" published="2005-01-10" name="CVE-2004-1214" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Format string vulnerability in Kreed 1.05 and earlier allows remote attackers to execute arbitrary code via format specifiers in (1) a nickname or (2) message text.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" admin="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/18343" source="XF" adv="1">kreed-message-nickname-format-string(18343)</ref>
      <ref url="http://www.securityfocus.com/bid/11799" source="BID" adv="1">11799</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110201776207915&amp;w=2" source="BUGTRAQ" adv="1">20041202 Multiple vulnerabilities in Kreed 1.05</ref>
    </refs>
    <vuln_soft>
      <prod vendor="burut" name="kreed">
        <vers num="1.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1215" published="2005-01-10" name="CVE-2004-1215" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Kreed 1.05 and earlier allows remote attackers to cause a denial of service (server disconnect) via a long UDP packet, which causes a "message too long" socket error.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/18344" source="XF" adv="1">kreed-udp-packet-dos(18344)</ref>
      <ref url="http://www.securityfocus.com/bid/11799" source="BID" adv="1">11799</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110201776207915&amp;w=2" source="BUGTRAQ" adv="1">20041202 Multiple vulnerabilities in Kreed 1.05</ref>
    </refs>
    <vuln_soft>
      <prod vendor="burut" name="kreed">
        <vers num="1.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1216" published="2005-01-10" name="CVE-2004-1216" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The scripts that handle players in Kreed 1.05 and earlier allow remote attackers to cause a denial of service (server freeze) via a long (1) nickname or (2) model type, which generates dialog boxes on the server that must be manually handled before the server continues the game.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/18345" source="XF" adv="1">kreed-nickname-modeltype-dos(18345)</ref>
      <ref url="http://www.securityfocus.com/bid/11799" source="BID" adv="1">11799</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110201776207915&amp;w=2" source="BUGTRAQ" adv="1">20041202 Multiple vulnerabilities in Kreed 1.05</ref>
    </refs>
    <vuln_soft>
      <prod vendor="burut" name="kreed">
        <vers num="1.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1217" published="2005-01-10" name="CVE-2004-1217" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Hosting Controller 6.1 Hotfix 1.4, and possibly other versions, allows remote attackers to view arbitrary directories by specifying the target pathname in the FilePath parameter to (1) Statsbrowse.asp or (2) Generalbrowse.asp.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <access />
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/18363" source="XF" adv="1">hosting-controller-view-files(18363)</ref>
      <ref url="http://www.securityfocus.com/bid/11822" source="BID" adv="1">11822</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110237762807764&amp;w=2" source="BUGTRAQ" adv="1">20041205 Hosting Controller</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hosting_controller" name="hosting_controller">
        <vers num="6.1" />
        <vers num="6.1_hotfix_1.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1218" published="2005-01-10" name="CVE-2004-1218" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Remote Execute 2.30 allows remote attackers to cause a denial of service (application crash) by making 7 simultaneous connections.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input bound="1" />
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/136424" source="CERT-VN" adv="1">VU#136424</ref>
      <ref url="http://www.securityfocus.com/bid/11821" source="BID" patch="1" adv="1">11821</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110238855010003&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20041206 DoS leading to crash of client in Remote Execute 2.30</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/18380" source="XF" adv="1">remote-execute-dos(18380)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibex_software" name="remote_execute">
        <vers num="2.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1219" published="2005-01-10" name="CVE-2004-1219" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">paFileDB 3.1, when using sessions authentication and while the administrator logs on, allows remote attackers to read the administrator's password hash and conduct brute force password guessing attacks by listing the contents of the sessions directory and reading the associated file for the administrator session.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/18364" source="XF" adv="1">pafiledb-session-information-disclosure(18364)</ref>
      <ref url="http://www.securityfocus.com/bid/11818" source="BID" adv="1">11818</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110245123927025&amp;w=2" source="BUGTRAQ" adv="1">20041207 Multiple Vulnerabilities in paFileDB 3.1</ref>
      <ref url="http://echo.or.id/adv/adv09-y3dips-2004.txt" source="MISC">http://echo.or.id/adv/adv09-y3dips-2004.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="php_arena" name="pafiledb">
        <vers num="3.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1220" published="2005-01-10" name="CVE-2004-1220" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Battlefield 1942 1.6.19 and earlier, and Battlefield Vietnam 1.2 and earlier, allows a remote master server to cause a denial of service (client crash) via a server reply that contains a large numplayers value, which triggers a null dereference.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/18402" source="XF" adv="1">battlefieldvietnam-numplayers-dos(18402)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/18400" source="XF">battlefield-numplayers-dos(18400)</ref>
      <ref url="http://www.securityfocus.com/bid/11838" source="BID" adv="1">11838</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110244662102167&amp;w=2" source="BUGTRAQ" adv="1">20041207 Broadcast client crash in Battlefield 1942 1.6.19 and Vietnam 1.2</ref>
    </refs>
    <vuln_soft>
      <prod vendor="digital_illusions" name="battlefield_1942">
        <vers num="1.6.19" />
      </prod>
      <prod vendor="digital_illusions" name="battlefield_vietnam">
        <vers num="1.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1221" published="2005-01-10" name="CVE-2004-1221" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in weblibs.pl in WebLibs 1.0 allows remote attackers to read arbitrary files via .. sequences in the TextFile parameter.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110245395510945&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20041207 Remote Web Server Text File Viewing Vulnerability in WebLibs 1.0</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/18399" source="XF" adv="1">weblibs-directory-traversal(18399)</ref>
      <ref url="http://www.securityfocus.com/bid/11848" source="BID" adv="1">11848</ref>
      <ref url="http://secunia.com/advisories/13400/" source="SECUNIA">13400</ref>
    </refs>
    <vuln_soft>
      <prod vendor="darryl_burgdorf" name="weblibs">
        <vers num="1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-1222" published="2005-01-10" name="CVE-2004-1222" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">weblibs.pl in WebLibs 1.0 allows remote attackers to execute arbitrary commands via shell metacharacters in the TextFile parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" admin="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110245395510945&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20041207 Remote Web Server Text File Viewing Vulnerability in WebLibs 1.0</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/18399" source="XF" adv="1">weblibs-directory-traversal(18399)</ref>
      <ref url="http://www.securityfocus.com/bid/11848" source="BID" adv="1">11848</ref>
    </refs>
    <vuln_soft>
      <prod vendor="darryl_burgdorf" name="weblibs">
        <vers num="1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1223" published="2005-01-10" name="CVE-2004-1223" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The Management Agent in F-Secure Policy Manager 5.11.2810 allows remote attackers to gain sensitive information, such as the absolute path for the web server, via an HTTP request to fsmsh.dll without any parameters.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/18413" source="XF" adv="1">fsecure-url-obtain-information(18413)</ref>
      <ref url="http://www.securityfocus.com/bid/11869" source="BID" adv="1">11869</ref>
      <ref url="http://www.oliverkarow.de/research/f-secure.txt" source="MISC">http://www.oliverkarow.de/research/f-secure.txt</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110262921306862&amp;w=2" source="BUGTRAQ" adv="1">20041209 =?iso-8859-1?Q?F-Secure_Policy_Manager_-__physical_path_disclosure?=</ref>
    </refs>
    <vuln_soft>
      <prod vendor="f-secure" name="policy_manager">
        <vers num="5.11" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1224" published="2005-01-10" name="CVE-2004-1224" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Off-by-one error in the mtr_curses_keyaction function for mtr 0.55 through 0.65 allows local users to hijack raw sockets, as demonstrated using the "s" keybinding, which leaves a buffer without a NULL terminator.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input bound="1" />
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110279034910663&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20041211 Local off-by-one in mtr versions 0.55 to 0.65</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/18428" source="XF">mtr-mtrcurseskeyaction-offbyone-bo(18428)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mtr" name="mtr">
        <vers num="0.55" />
        <vers num="0.56" />
        <vers num="0.57" />
        <vers num="0.58" />
        <vers num="0.59" />
        <vers num="0.60" />
        <vers num="0.61" />
        <vers num="0.62" />
        <vers num="0.63" />
        <vers num="0.64" />
        <vers num="0.65" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-1225" published="2005-01-10" name="CVE-2004-1225" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">SQL injection vulnerability in SugarCRM Sugar Sales before 2.0.1a allows remote attackers to execute arbitrary SQL commands and gain privileges via the record parameter in a DetailView action to index.php, and record parameters in other functionality.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" admin="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/18325" source="XF" adv="1">sugarcrm-record-sql-injection(18325)</ref>
      <ref url="http://www.securityfocus.com/bid/11740" source="BID" adv="1">11740</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110295433323795&amp;w=2" source="BUGTRAQ" adv="1">20041213 SugarSales Multiple Vulnerabilities</ref>
      <ref url="http://www.gulftech.org/?node=research&amp;article_id=00053-120104" source="MISC">http://www.gulftech.org/?node=research&amp;article_id=00053-120104</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sugarcrm" name="sugarcrm">
        <vers num="1.0" />
        <vers num="1.0f" />
        <vers num="1.0g" />
        <vers num="1.1" />
        <vers num="1.1a" />
        <vers num="1.1b" />
        <vers num="1.1c" />
        <vers num="1.1d" />
        <vers num="1.1e" />
        <vers num="1.1f" />
        <vers num="1.5d" />
        <vers num="2.0.1" />
        <vers num="2.0.1a" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1226" published="2005-01-10" name="CVE-2004-1226" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">SugarCRM Sugar Sales 2.0.1c and earlier allows remote attackers to gain sensitive information via certain requests to scripts that contain invalid input, which reveals the path in an error message, as demonstrated using phprint.php with an empty module parameter.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/18447" source="XF">sugar-sales-path-disclosure(18447)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110295433323795&amp;w=2" source="BUGTRAQ" adv="1">20041213 SugarSales Multiple Vulnerabilities</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sugarcrm" name="sugarcrm">
        <vers prev="1" num="2.0.1c" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-1227" published="2005-01-10" name="CVE-2004-1227" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in SugarCRM Sugar Sales 2.0.1c and earlier allows remote attackers to read arbitrary files and possibly execute arbitrary PHP code via .. (dot dot) sequences in the (1) module, (2) action, or (3) theme parameters to index.php, (4) the theme parameter to Login.php, and possibly other parameters or scripts.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" admin="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/18326" source="XF" adv="1">sugarcrm-directory-traversal(18326)</ref>
      <ref url="http://www.securityfocus.com/bid/11740" source="BID" adv="1">11740</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110295433323795&amp;w=2" source="BUGTRAQ" adv="1">20041213 SugarSales Multiple Vulnerabilities</ref>
      <ref url="http://www.gulftech.org/?node=research&amp;article_id=00053-120104" source="MISC">http://www.gulftech.org/?node=research&amp;article_id=00053-120104</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sugarcrm" name="sugar_sales">
        <vers prev="1" num="2.0.1c" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1228" published="2005-01-10" name="CVE-2004-1228" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:P)" CVSS_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_base_score="6.4">
    <desc>
      <descript source="cve">The install scripts in SugarCRM Sugar Sales 2.0.1c and earlier are not removed after installation, which allows attackers to obtain the MySQL administrative password in cleartext from an installation form, or to cause a denial of service by changing database settings to the default.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/18449" source="XF">sugar-sales-password-plaintext(18449)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110295433323795&amp;w=2" source="BUGTRAQ" adv="1">20041213 SugarSales Multiple Vulnerabilities</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sugarcrm" name="sugar_sales">
        <vers prev="1" num="2.0.1c" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-1229" published="2005-01-10" name="CVE-2004-1229" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Cross-site scripting vulnerability in the parser for Gadu-Gadu allows remote attackers to inject arbitrary web script or HTML via (1) http:// or (2) news:// URLs, a different vulnerability than CVE-2004-1410.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/11899" source="BID">11899</ref>
      <ref url="http://www.osvdb.org/12517" source="OSVDB">12517</ref>
      <ref url="http://www.man.poznan.pl/~security/gg-adv.txt" source="MISC" adv="1">http://www.man.poznan.pl/~security/gg-adv.txt</ref>
      <ref url="http://secunia.com/advisories/13450" source="SECUNIA" adv="1">13450</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110295777306493&amp;w=2" source="BUGTRAQ">20041213 Gadu-Gadu several vulnerabilities</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gadu-gadu" name="gadu-gadu_instant_messenger">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1230" published="2005-01-10" name="CVE-2004-1230" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Gadu-Gadu allows remote attackers to gain sensitive information and read files from the _cache directory of other users via a DCC connection and a CTCP packet that contains a 1 as the type and a 4 as the subtype.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/18461" source="XF">gadu-gadu-dcc-ctcp-obtain-files(18461)</ref>
      <ref url="http://www.man.poznan.pl/~security/gg-adv.txt" source="MISC">http://www.man.poznan.pl/~security/gg-adv.txt</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110295777306493&amp;w=2" source="BUGTRAQ">20041213 Gadu-Gadu several vulnerabilities</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gadu-gadu" name="gadu-gadu_instant_messenger">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1231" published="2005-01-10" name="CVE-2004-1231" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in Gadu-Gadu allows remote attackers to read arbitrary files via .. (dot dot) sequences in a DCC connection with a CTCP packet that contains a 1 as the type and a 4 as the subtype.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/18461" source="XF">gadu-gadu-dcc-ctcp-obtain-files(18461)</ref>
      <ref url="http://www.man.poznan.pl/~security/gg-adv.txt" source="MISC">http://www.man.poznan.pl/~security/gg-adv.txt</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110295777306493&amp;w=2" source="BUGTRAQ">20041213 Gadu-Gadu several vulnerabilities</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gadu-gadu" name="gadu-gadu_instant_messenger">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-1232" published="2005-01-10" name="CVE-2004-1232" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Stack-based buffer overflow in the code that sends images in Gadu-Gadu allows remote attackers to execute arbitrary code via a large image filename.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/18462" source="XF">gadu-gadu-image-filename-bo(18462)</ref>
      <ref url="http://www.man.poznan.pl/~security/gg-adv.txt" source="MISC">http://www.man.poznan.pl/~security/gg-adv.txt</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110295777306493&amp;w=2" source="BUGTRAQ">20041213 Gadu-Gadu several vulnerabilities</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gadu-gadu" name="gadu-gadu_instant_messenger">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1233" published="2005-01-10" name="CVE-2004-1233" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Integer overflow in Gadu-Gadu allows remote attackers to cause a denial of service (disk consumption) via a user packet to the DCC file transfer capability with an invalid file length.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/18465" source="XF">gadu-gadu-dcc-bo(18465)</ref>
      <ref url="http://www.man.poznan.pl/~security/gg-adv.txt" source="MISC">http://www.man.poznan.pl/~security/gg-adv.txt</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110295777306493&amp;w=2" source="BUGTRAQ">20041213 Gadu-Gadu several vulnerabilities</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gadu-gadu" name="gadu-gadu_instant_messenger">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2004-1234" published="2004-12-31" name="CVE-2004-1234" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">load_elf_binary in Linux before 2.4.26 allows local users to cause a denial of service (system crash) via an ELF binary in which the interpreter is NULL.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
      <exception />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="https://bugzilla.fedora.us/show_bug.cgi?id=2336" source="FEDORA" patch="1">FLSA:2336</ref>
      <ref url="http://www.securityfocus.com/bid/12101" source="BID" patch="1">12101</ref>
      <ref url="http://linux.bkbits.net:8080/linux-2.4/cset@4076466d_SqUm4azg4_v3FIG2-X6XQ" source="CONFIRM" patch="1">http://linux.bkbits.net:8080/linux-2.4/cset@4076466d_SqUm4azg4_v3FIG2-X6XQ</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/18687" source="XF">linux-loadelfbinary-dos(18687)</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-689.html" source="REDHAT">RHSA-2004:689</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10608" source="OVAL">oval:org.mitre.oval:def:10608</ref>
      <ref url="http://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=142965" source="CONFIRM">http://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=142965</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-017.html" source="REDHAT">RHSA-2005:017</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-016.html" source="REDHAT">RHSA-2005:016</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1082" source="DEBIAN">DSA-1082</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1070" source="DEBIAN">DSA-1070</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1069" source="DEBIAN">DSA-1069</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1067" source="DEBIAN">DSA-1067</ref>
      <ref url="http://secunia.com/advisories/20338" source="SECUNIA">20338</ref>
      <ref url="http://secunia.com/advisories/20202" source="SECUNIA">20202</ref>
      <ref url="http://secunia.com/advisories/20163" source="SECUNIA">20163</ref>
      <ref url="http://secunia.com/advisories/20162" source="SECUNIA">20162</ref>
    </refs>
    <vuln_soft>
      <prod vendor="linux" name="linux_kernel">
        <vers prev="1" num="2.4.0" edition="test1" />
        <vers prev="1" num="2.4.0" edition="test10" />
        <vers prev="1" num="2.4.0" edition="test11" />
        <vers prev="1" num="2.4.0" edition="test12" />
        <vers prev="1" num="2.4.0" edition="test2" />
        <vers prev="1" num="2.4.0" edition="test3" />
        <vers prev="1" num="2.4.0" edition="test4" />
        <vers prev="1" num="2.4.0" edition="test5" />
        <vers prev="1" num="2.4.0" edition="test6" />
        <vers prev="1" num="2.4.0" edition="test7" />
        <vers prev="1" num="2.4.0" edition="test8" />
        <vers prev="1" num="2.4.0" edition="test9" />
        <vers num="2.4.1" />
        <vers num="2.4.10" />
        <vers num="2.4.11" />
        <vers num="2.4.12" />
        <vers num="2.4.13" />
        <vers num="2.4.14" />
        <vers num="2.4.15" />
        <vers num="2.4.16" />
        <vers num="2.4.17" />
        <vers num="2.4.18" edition="" />
        <vers num="2.4.18" edition=":x86" />
        <vers num="2.4.18" edition="pre1" />
        <vers num="2.4.18" edition="pre2" />
        <vers num="2.4.18" edition="pre3" />
        <vers num="2.4.18" edition="pre4" />
        <vers num="2.4.18" edition="pre5" />
        <vers num="2.4.18" edition="pre6" />
        <vers num="2.4.18" edition="pre7" />
        <vers num="2.4.18" edition="pre8" />
        <vers num="2.4.19" edition="pre1" />
        <vers num="2.4.19" edition="pre2" />
        <vers num="2.4.19" edition="pre3" />
        <vers num="2.4.19" edition="pre4" />
        <vers num="2.4.19" edition="pre5" />
        <vers num="2.4.19" edition="pre6" />
        <vers num="2.4.2" />
        <vers num="2.4.20" />
        <vers num="2.4.21" edition="pre1" />
        <vers num="2.4.21" edition="pre4" />
        <vers num="2.4.21" edition="pre7" />
        <vers num="2.4.22" edition="pre10" />
        <vers num="2.4.23" edition="pre9" />
        <vers num="2.4.23_ow2" />
        <vers num="2.4.24" />
        <vers num="2.4.24_ow1" />
        <vers num="2.4.25" />
        <vers num="2.4.26" />
        <vers num="2.4.3" edition="pre3" />
        <vers num="2.4.4" />
        <vers num="2.4.5" />
        <vers num="2.4.6" />
        <vers num="2.4.7" />
        <vers num="2.4.8" />
        <vers num="2.4.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1235" published="2005-04-14" name="CVE-2004-1235" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:H/Au:N/C:C/I:C/A:C)" CVSS_score="6.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="1.9" CVSS_base_score="6.2">
    <desc>
      <descript source="cve">Race condition in the (1) load_elf_library and (2) binfmt_aout function calls for uselib in Linux kernel 2.4 through 2.429-rc2 and 2.6 through 2.6.10 allows local users to execute arbitrary code by manipulating the VMA descriptor.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <race />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/12190" source="BID" patch="1" adv="1">12190</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-043.html" source="REDHAT" patch="1" adv="1">RHSA-2005:043</ref>
      <ref url="https://bugzilla.fedora.us/show_bug.cgi?id=2336" source="FEDORA">FLSA:2336</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/18800" source="XF">linux-uselib-gain-privileges(18800)</ref>
      <ref url="http://www.trustix.org/errata/2005/0001/" source="TRUSTIX">2005-0001</ref>
      <ref url="http://www.securityfocus.com/advisories/7806" source="FEDORA">FEDORA-2005-013</ref>
      <ref url="http://www.securityfocus.com/advisories/7805" source="FEDORA">FEDORA-2005-014</ref>
      <ref url="http://www.securityfocus.com/advisories/7804" source="CONFIRM">http://www.securityfocus.com/advisories/7804</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-092.html" source="REDHAT">RHSA-2005:092</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9567" source="OVAL">oval:org.mitre.oval:def:9567</ref>
      <ref url="http://isec.pl/vulnerabilities/isec-0021-uselib.txt" source="MISC">http://isec.pl/vulnerabilities/isec-0021-uselib.txt</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/index.php?id=a&amp;anuncio=000930" source="CONECTIVA">CLA-2005:930</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-017.html" source="REDHAT">RHSA-2005:017</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-016.html" source="REDHAT">RHSA-2005:016</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2005_01_sr.html" source="SUSE">SUSE-SR:2005:001</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:022" source="MANDRAKE">MDKSA-2005:022</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1082" source="DEBIAN">DSA-1082</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1070" source="DEBIAN">DSA-1070</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1069" source="DEBIAN">DSA-1069</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1067" source="DEBIAN">DSA-1067</ref>
      <ref url="http://secunia.com/advisories/20338" source="SECUNIA">20338</ref>
      <ref url="http://secunia.com/advisories/20202" source="SECUNIA">20202</ref>
      <ref url="http://secunia.com/advisories/20163" source="SECUNIA">20163</ref>
      <ref url="http://secunia.com/advisories/20162" source="SECUNIA">20162</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110512575901427&amp;w=2" source="BUGTRAQ">20050107 Linux kernel sys_uselib local root vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="avaya" name="intuity_audix">
        <vers num="" edition=":lx" />
      </prod>
      <prod vendor="avaya" name="mn100">
        <vers num="" />
      </prod>
      <prod vendor="avaya" name="network_routing">
        <vers num="" />
      </prod>
      <prod vendor="mandrakesoft" name="mandrake_multi_network_firewall">
        <vers num="8.2" />
      </prod>
      <prod vendor="avaya" name="converged_communications_server">
        <vers num="2.0" />
      </prod>
      <prod vendor="avaya" name="s8300">
        <vers num="r2.0.0" />
        <vers num="r2.0.1" />
      </prod>
      <prod vendor="avaya" name="s8500">
        <vers num="r2.0.0" />
        <vers num="r2.0.1" />
      </prod>
      <prod vendor="avaya" name="s8700">
        <vers num="r2.0.0" />
        <vers num="r2.0.1" />
      </prod>
      <prod vendor="avaya" name="s8710">
        <vers num="r2.0.0" />
        <vers num="r2.0.1" />
      </prod>
      <prod vendor="avaya" name="modular_messaging_message_storage_server">
        <vers num="1.1" />
        <vers num="2.0" />
      </prod>
      <prod vendor="conectiva" name="linux">
        <vers num="10.0" />
      </prod>
      <prod vendor="linux" name="linux_kernel">
        <vers num="2.4.0" edition="test1" />
        <vers num="2.4.0" edition="test10" />
        <vers num="2.4.0" edition="test11" />
        <vers num="2.4.0" edition="test12" />
        <vers num="2.4.0" edition="test2" />
        <vers num="2.4.0" edition="test3" />
        <vers num="2.4.0" edition="test4" />
        <vers num="2.4.0" edition="test5" />
        <vers num="2.4.0" edition="test6" />
        <vers num="2.4.0" edition="test7" />
        <vers num="2.4.0" edition="test8" />
        <vers num="2.4.0" edition="test9" />
        <vers num="2.4.1" />
        <vers num="2.4.10" />
        <vers num="2.4.11" />
        <vers num="2.4.12" />
        <vers num="2.4.13" />
        <vers num="2.4.14" />
        <vers num="2.4.15" />
        <vers num="2.4.16" />
        <vers num="2.4.17" />
        <vers num="2.4.18" edition="" />
        <vers num="2.4.18" edition=":x86" />
        <vers num="2.4.18" edition="pre1" />
        <vers num="2.4.18" edition="pre2" />
        <vers num="2.4.18" edition="pre3" />
        <vers num="2.4.18" edition="pre4" />
        <vers num="2.4.18" edition="pre5" />
        <vers num="2.4.18" edition="pre6" />
        <vers num="2.4.18" edition="pre7" />
        <vers num="2.4.18" edition="pre8" />
        <vers num="2.4.19" edition="pre1" />
        <vers num="2.4.19" edition="pre2" />
        <vers num="2.4.19" edition="pre3" />
        <vers num="2.4.19" edition="pre4" />
        <vers num="2.4.19" edition="pre5" />
        <vers num="2.4.19" edition="pre6" />
        <vers num="2.4.2" />
        <vers num="2.4.20" />
        <vers num="2.4.21" edition="pre1" />
        <vers num="2.4.21" edition="pre4" />
        <vers num="2.4.21" edition="pre7" />
        <vers num="2.4.22" />
        <vers num="2.4.23" edition="pre9" />
        <vers num="2.4.23_ow2" />
        <vers num="2.4.24" />
        <vers num="2.4.24_ow1" />
        <vers num="2.4.25" />
        <vers num="2.4.26" />
        <vers num="2.4.27" edition="pre1" />
        <vers num="2.4.27" edition="pre2" />
        <vers num="2.4.27" edition="pre3" />
        <vers num="2.4.27" edition="pre4" />
        <vers num="2.4.27" edition="pre5" />
        <vers num="2.4.28" />
        <vers num="2.4.29" edition="rc2" />
        <vers num="2.4.3" />
        <vers num="2.4.4" />
        <vers num="2.4.5" />
        <vers num="2.4.6" />
        <vers num="2.4.7" />
        <vers num="2.4.8" />
        <vers num="2.4.9" />
        <vers num="2.6.0" edition="test1" />
        <vers num="2.6.0" edition="test10" />
        <vers num="2.6.0" edition="test11" />
        <vers num="2.6.0" edition="test2" />
        <vers num="2.6.0" edition="test3" />
        <vers num="2.6.0" edition="test4" />
        <vers num="2.6.0" edition="test5" />
        <vers num="2.6.0" edition="test6" />
        <vers num="2.6.0" edition="test7" />
        <vers num="2.6.0" edition="test8" />
        <vers num="2.6.0" edition="test9" />
        <vers num="2.6.1" edition="rc1" />
        <vers num="2.6.1" edition="rc2" />
        <vers num="2.6.10" edition="rc2" />
        <vers num="2.6.2" />
        <vers num="2.6.3" />
        <vers num="2.6.4" />
        <vers num="2.6.5" />
        <vers num="2.6.6" edition="rc1" />
        <vers num="2.6.7" edition="rc1" />
        <vers num="2.6.8" edition="rc1" />
        <vers num="2.6.8" edition="rc2" />
        <vers num="2.6.8" edition="rc3" />
        <vers num="2.6.9" edition="2.6.20" />
        <vers num="2.6_test9_cvs" />
      </prod>
      <prod vendor="mandrakesoft" name="mandrake_linux">
        <vers num="10.0" edition="" />
        <vers num="10.0" edition=":amd64" />
        <vers num="10.1" edition="" />
        <vers num="10.1" edition=":x86_64" />
        <vers num="9.2" edition="" />
        <vers num="9.2" edition=":amd64" />
      </prod>
      <prod vendor="mandrakesoft" name="mandrake_linux_corporate_server">
        <vers num="2.1" edition="" />
        <vers num="2.1" edition=":x86_64" />
        <vers num="3.0" />
      </prod>
      <prod vendor="redhat" name="enterprise_linux">
        <vers num="3.0" edition="" />
        <vers num="3.0" edition=":workstation" />
        <vers num="3.0" edition=":advanced_servers" />
        <vers num="3.0" edition=":enterprise_server" />
        <vers num="4.0" edition="" />
        <vers num="4.0" edition=":workstation" />
        <vers num="4.0" edition=":enterprise_server" />
        <vers num="4.0" edition=":advanced_server" />
      </prod>
      <prod vendor="redhat" name="enterprise_linux_desktop">
        <vers num="3.0" />
        <vers num="4.0" />
      </prod>
      <prod vendor="redhat" name="fedora_core">
        <vers num="core_1.0" />
        <vers num="core_2.0" />
        <vers num="core_3.0" />
      </prod>
      <prod vendor="redhat" name="linux">
        <vers num="7.3" edition="" />
        <vers num="7.3" edition=":i386" />
        <vers num="9.0" edition="" />
        <vers num="9.0" edition=":i386" />
      </prod>
      <prod vendor="suse" name="suse_linux">
        <vers num="1.0" edition="" />
        <vers num="1.0" edition=":desktop" />
        <vers num="8" edition="" />
        <vers num="8" edition=":enterprise_server" />
        <vers num="8.1" />
        <vers num="8.2" />
        <vers num="9.0" edition="" />
        <vers num="9.0" edition=":enterprise_server" />
        <vers num="9.1" />
        <vers num="9.2" />
      </prod>
      <prod vendor="ubuntu" name="ubuntu_linux">
        <vers num="4.1" edition="" />
        <vers num="4.1" edition=":ppc" />
        <vers num="4.1" edition=":ia64" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-1236" published="2004-12-31" name="CVE-2004-1236" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Buffer overflow in the LDAP component for Netscape Directory Server (NDS) 3.6 on HP-UX and other operating systems allows remote attackers to execute arbitrary code.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/258905" source="CERT-VN" adv="1">VU#258905</ref>
      <ref url="http://www.securityfocus.com/bid/12099" source="BID">12099</ref>
      <ref url="http://www.ciac.org/ciac/bulletins/p-083.shtml" source="CIAC">P-083</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-57754-1" source="SUNALERT" adv="1">57754</ref>
      <ref url="http://secunia.com/advisories/14960" source="SECUNIA">14960</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110384298016120" source="HP">SSRT4867</ref>
    </refs>
    <vuln_soft>
      <prod vendor="netscape" name="directory_server">
        <vers num="3.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2004-1237" published="2005-04-14" name="CVE-2004-1237" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">Unknown vulnerability in the system call filtering code in the audit subsystem for Red Hat Enterprise Linux 3 allows local users to cause a denial of service (system crash) via unknown vectors.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-043.html" source="REDHAT" patch="1" adv="1">RHSA-2005:043</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11282" source="OVAL">oval:org.mitre.oval:def:11282</ref>
    </refs>
    <vuln_soft>
      <prod vendor="linux" name="linux_kernel">
        <vers num="2.4.0" edition="test1" />
        <vers num="2.4.0" edition="test10" />
        <vers num="2.4.0" edition="test11" />
        <vers num="2.4.0" edition="test12" />
        <vers num="2.4.0" edition="test2" />
        <vers num="2.4.0" edition="test3" />
        <vers num="2.4.0" edition="test4" />
        <vers num="2.4.0" edition="test5" />
        <vers num="2.4.0" edition="test6" />
        <vers num="2.4.0" edition="test7" />
        <vers num="2.4.0" edition="test8" />
        <vers num="2.4.0" edition="test9" />
        <vers num="2.4.1" />
        <vers num="2.4.10" />
        <vers num="2.4.11" />
        <vers num="2.4.12" />
        <vers num="2.4.13" />
        <vers num="2.4.14" />
        <vers num="2.4.15" />
        <vers num="2.4.16" />
        <vers num="2.4.17" />
        <vers num="2.4.18" edition="" />
        <vers num="2.4.18" edition=":x86" />
        <vers num="2.4.18" edition="pre1" />
        <vers num="2.4.18" edition="pre2" />
        <vers num="2.4.18" edition="pre3" />
        <vers num="2.4.18" edition="pre4" />
        <vers num="2.4.18" edition="pre5" />
        <vers num="2.4.18" edition="pre6" />
        <vers num="2.4.18" edition="pre7" />
        <vers num="2.4.18" edition="pre8" />
        <vers num="2.4.19" edition="pre1" />
        <vers num="2.4.19" edition="pre2" />
        <vers num="2.4.19" edition="pre3" />
        <vers num="2.4.19" edition="pre4" />
        <vers num="2.4.19" edition="pre5" />
        <vers num="2.4.19" edition="pre6" />
        <vers num="2.4.2" />
        <vers num="2.4.20" />
        <vers num="2.4.21" edition="pre1" />
        <vers num="2.4.21" edition="pre4" />
        <vers num="2.4.21" edition="pre7" />
        <vers num="2.4.22" />
        <vers num="2.4.23" edition="pre9" />
        <vers num="2.4.23_ow2" />
        <vers num="2.4.24" />
        <vers num="2.4.24_ow1" />
        <vers num="2.4.25" />
        <vers num="2.4.26" />
        <vers num="2.4.27" edition="pre1" />
        <vers num="2.4.27" edition="pre2" />
        <vers num="2.4.27" edition="pre3" />
        <vers num="2.4.27" edition="pre4" />
        <vers num="2.4.27" edition="pre5" />
        <vers num="2.4.28" />
        <vers num="2.4.29" edition="rc1" />
        <vers num="2.4.29" edition="rc2" />
        <vers num="2.4.3" />
        <vers num="2.4.4" />
        <vers num="2.4.5" />
        <vers num="2.4.6" />
        <vers num="2.4.7" />
        <vers num="2.4.8" />
        <vers num="2.4.9" />
        <vers num="2.6.0" edition="test1" />
        <vers num="2.6.0" edition="test10" />
        <vers num="2.6.0" edition="test11" />
        <vers num="2.6.0" edition="test2" />
        <vers num="2.6.0" edition="test3" />
        <vers num="2.6.0" edition="test4" />
        <vers num="2.6.0" edition="test5" />
        <vers num="2.6.0" edition="test6" />
        <vers num="2.6.0" edition="test7" />
        <vers num="2.6.0" edition="test8" />
        <vers num="2.6.0" edition="test9" />
        <vers num="2.6.1" edition="rc1" />
        <vers num="2.6.1" edition="rc2" />
        <vers num="2.6.10" edition="rc2" />
        <vers num="2.6.2" />
        <vers num="2.6.3" />
        <vers num="2.6.4" />
        <vers num="2.6.5" />
        <vers num="2.6.6" edition="rc1" />
        <vers num="2.6.7" edition="rc1" />
        <vers num="2.6.8" edition="rc1" />
        <vers num="2.6.8" edition="rc2" />
        <vers num="2.6.8" edition="rc3" />
        <vers num="2.6.9" edition="2.6.20" />
        <vers num="2.6_test9_cvs" />
      </prod>
      <prod vendor="redhat" name="enterprise_linux">
        <vers num="3.0" edition="" />
        <vers num="3.0" edition=":workstation" />
        <vers num="3.0" edition=":advanced_servers" />
        <vers num="3.0" edition=":enterprise_server" />
      </prod>
      <prod vendor="redhat" name="enterprise_linux_desktop">
        <vers num="3.0" />
      </prod>
      <prod vendor="suse" name="suse_linux">
        <vers num="1.0" edition="" />
        <vers num="1.0" edition=":desktop" />
        <vers num="8" edition="" />
        <vers num="8" edition=":enterprise_server" />
        <vers num="8.1" />
        <vers num="8.2" />
        <vers num="9.0" edition="" />
        <vers num="9.0" edition=":enterprise_server" />
        <vers num="9.1" />
        <vers num="9.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" seq="2004-1238" reject="1" published="2004-12-31" name="CVE-2004-1238" modified="2008-09-10">
    <desc>
      <descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: none.  Reason: This candidate was in a CNA pool that was not assigned to any issues during 2004.  Notes: none.</descript>
    </desc>
    <refs />
  </entry>
  <entry type="CVE" seq="2004-1239" reject="1" published="2004-12-31" name="CVE-2004-1239" modified="2008-09-10">
    <desc>
      <descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: none.  Reason: This candidate was in a CNA pool that was not assigned to any issues during 2004.  Notes: none.</descript>
    </desc>
    <refs />
  </entry>
  <entry type="CVE" seq="2004-1240" reject="1" published="2004-12-31" name="CVE-2004-1240" modified="2008-09-10">
    <desc>
      <descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: none.  Reason: This candidate was in a CNA pool that was not assigned to any issues during 2004.  Notes: none.</descript>
    </desc>
    <refs />
  </entry>
  <entry type="CVE" seq="2004-1241" reject="1" published="2004-12-31" name="CVE-2004-1241" modified="2008-09-10">
    <desc>
      <descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: none.  Reason: This candidate was in a CNA pool that was not assigned to any issues during 2004.  Notes: none.</descript>
    </desc>
    <refs />
  </entry>
  <entry type="CVE" seq="2004-1242" reject="1" published="2004-12-31" name="CVE-2004-1242" modified="2008-09-10">
    <desc>
      <descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: none.  Reason: This candidate was in a CNA pool that was not assigned to any issues during 2004.  Notes: none.</descript>
    </desc>
    <refs />
  </entry>
  <entry type="CVE" seq="2004-1243" reject="1" published="2004-12-31" name="CVE-2004-1243" modified="2008-09-10">
    <desc>
      <descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: none.  Reason: This candidate was in a CNA pool that was not assigned to any issues during 2004.  Notes: none.</descript>
    </desc>
    <refs />
  </entry>
  <entry type="CVE" severity="High" seq="2004-1244" published="2004-02-08" name="CVE-2004-1244" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Windows Media Player 9 allows remote attackers to execute arbitrary code via a PNG file containing large (1) width or (2) height values, aka the "PNG Processing Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA05-039A.html" source="CERT" patch="1" adv="1">TA05-039A</ref>
      <ref url="http://www.kb.cert.org/vuls/id/259890" source="CERT-VN" patch="1" adv="1">VU#259890</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/19096" source="XF" patch="1" adv="1">win-ms05kb890261-update(19096)</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/MS05-009.mspx" source="MS" patch="1" adv="1">MS05-009</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2379" source="OVAL" sig="1">oval:org.mitre.oval:def:2379</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1568" source="OVAL" sig="1">oval:org.mitre.oval:def:1568</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1306" source="OVAL" sig="1">oval:org.mitre.oval:def:1306</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_media_player">
        <vers num="9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-1254" published="2005-01-10" name="CVE-2004-1254" modified="2009-06-13" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">WinRAR 3.40, and possibly earlier versions, allows remote attackers to execute arbitrary code via a ZIP file containing a file with a long filename, possibly causing an integer overflow that leads to a buffer overflow.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/18569" source="XF">winrar-zip-file-bo(18569)</ref>
      <ref url="http://www.frsirt.com/exploits/20041217.Winrar.c.php" source="MISC">http://www.frsirt.com/exploits/20041217.Winrar.c.php</ref>
    </refs>
    <vuln_soft>
      <prod vendor="rarlab" name="winrar">
        <vers num="3.0.0" />
        <vers num="3.10" />
        <vers num="3.10_beta3" />
        <vers num="3.10_beta5" />
        <vers num="3.11" />
        <vers num="3.20" />
        <vers num="3.40" />
        <vers num="3.41" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-1255" published="2005-01-10" name="CVE-2004-1255" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Buffer overflow in the expandtabs function in 2fax 3.04 allows remote attackers to execute arbitrary code via a text file that is converted to TIFF.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/10901" source="XF">2fax-bpcx-bo(10901)</ref>
      <ref url="http://tigger.uic.edu/~jlongs2/holes/2fax.txt" source="MISC" adv="1">http://tigger.uic.edu/~jlongs2/holes/2fax.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="2fax" name="2fax">
        <vers num="3.0_4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-1256" published="2005-01-10" name="CVE-2004-1256" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Multiple buffer overflows in the (1) event_text and (2) event_specific functions in abc2midi 2004.12.04 allow remote attackers to execute arbitrary code via crafted ABC files.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/18574" source="XF">abc2midi-eventspecific-bo(18574)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/18573" source="XF">abc2midi-eventtext-bo(18573)</ref>
      <ref url="http://tigger.uic.edu/~jlongs2/holes/abc2midi.txt" source="MISC" adv="1">http://tigger.uic.edu/~jlongs2/holes/abc2midi.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="abcmidi" name="abcmidi">
        <vers num="2004-12-04" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-1257" published="2005-01-10" name="CVE-2004-1257" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Buffer overflow in the process_abc function in abc.c for abc2mtex 1.6.1 allows remote attackers to execute arbitrary code via crafted ABC files.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/18578" source="XF">abc2mtex-processabc-bo(18578)</ref>
      <ref url="http://tigger.uic.edu/~jlongs2/holes/abc2mtex.txt" source="MISC" adv="1">http://tigger.uic.edu/~jlongs2/holes/abc2mtex.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="abc2mtex" name="abc2mtex">
        <vers num="1.6.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-1258" published="2005-01-10" name="CVE-2004-1258" modified="2011-04-29" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Buffer overflow in the put_words function in subs.c for abcm2ps 3.7.20 allows remote attackers to execute arbitrary code via crafted ABC files.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/18579" source="XF">abcm2ps-putwords-bo(18579)</ref>
      <ref url="http://tigger.uic.edu/~jlongs2/holes/abcm2ps.txt" source="MISC" adv="1">http://tigger.uic.edu/~jlongs2/holes/abcm2ps.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="moinejf" name="abcm2ps">
        <vers num="3.7.20" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-1259" published="2005-01-10" name="CVE-2004-1259" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Multiple buffer overflows in the handle_directive function in abcpp.c for abcpp 1.3.0 allow remote attackers to execute arbitrary code via crafted ABC files.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/18581" source="XF">abcpp-handledirective-bo(18581)</ref>
      <ref url="http://tigger.uic.edu/~jlongs2/holes/abcpp.txt" source="MISC" adv="1">http://tigger.uic.edu/~jlongs2/holes/abcpp.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="abcpp" name="abcpp">
        <vers num="1.3.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-1260" published="2005-01-10" name="CVE-2004-1260" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Multiple buffer overflows in the (1) write_heading function in subs.cpp or (2) trim_title function in parse.cpp for abctab2ps 1.6.3 allow remote attackers to execute arbitrary code via crafted ABC files.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/18584" source="XF">abctab2ps-trimtitle-bo(18584)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/18583" source="XF">abctab2ps-writeheading-bo(18583)</ref>
      <ref url="http://tigger.uic.edu/~jlongs2/holes/abctab2ps.txt" source="MISC" adv="1">http://tigger.uic.edu/~jlongs2/holes/abctab2ps.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="abctab2ps" name="abctab2ps">
        <vers num="1.6.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-1261" published="2005-01-10" name="CVE-2004-1261" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Multiple buffer overflows in the preparse function in asp2php 0.76.23 allow remote attackers to execute arbitrary code via crafted ASP scripts.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/18585" source="XF">asp2php-preparse-bo(18585)</ref>
      <ref url="http://tigger.uic.edu/~jlongs2/holes/asp2php.txt" source="MISC" adv="1">http://tigger.uic.edu/~jlongs2/holes/asp2php.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="asp2php" name="asp2php">
        <vers num="0.76.23" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-1262" published="2005-01-10" name="CVE-2004-1262" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Buffer overflow in the bsb_open_header function in libbsb for bsb2ppm 0.0.6 allows remote attackers to execute arbitrary code via crafted BSB pictures.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/18586" source="XF">bsb2ppm-bsbopenheader-bo(18586)</ref>
      <ref url="http://tigger.uic.edu/~jlongs2/holes/bsb2ppm.txt" source="MISC" adv="1">http://tigger.uic.edu/~jlongs2/holes/bsb2ppm.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="stuart_cunningham" name="bsb2ppm">
        <vers num="0.0.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-1263" published="2005-01-10" name="CVE-2004-1263" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">changepassword.cgi in ChangePassword 0.8, when installed setuid, allows local users to execute arbitrary code by modifying the PATH environment variable to point to a malicious "make" program.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" admin="1" />
    </loss_types>
    <vuln_types>
      <design />
      <config />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/18593" source="XF">changepassword-gain-privileges(18593)</ref>
      <ref url="http://tigger.uic.edu/~jlongs2/holes/changepassword.txt" source="MISC">http://tigger.uic.edu/~jlongs2/holes/changepassword.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="changepassword" name="changepassword">
        <vers num="0.1" />
        <vers num="0.2" />
        <vers num="0.3" />
        <vers num="0.4" />
        <vers num="0.5" />
        <vers num="0.6" />
        <vers num="0.6.1" />
        <vers num="0.7" />
        <vers num="0.8" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-1264" published="2005-01-10" name="CVE-2004-1264" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Buffer overflow in the simplify_path function in config.c for ChBg 1.5 allows remote attackers to execute arbitrary code via a crafted chbg scenario file.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/18595" source="XF">chbg-simplifypath-bo(18595)</ref>
      <ref url="http://www.debian.org/security/2005/dsa-644" source="DEBIAN">DSA-644</ref>
      <ref url="http://tigger.uic.edu/~jlongs2/holes/chbg.txt" source="MISC" adv="1">http://tigger.uic.edu/~jlongs2/holes/chbg.txt</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:027" source="MANDRAKE">MDKSA-2005:027</ref>
    </refs>
    <vuln_soft>
      <prod vendor="chbg" name="chbg">
        <vers num="1.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-1265" published="2005-01-10" name="CVE-2004-1265" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Buffer overflow in the readObjectChunk function in 3dsimp.cpp for the convex-tool program in Convex 3D 0.8pre1 allows remote attackers to execute arbitrary code via a crafted 3DS file.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/18601" source="XF">convex-3d-readobjectchunk-bo(18601)</ref>
      <ref url="http://tigger.uic.edu/~jlongs2/holes/convex3d.txt" source="MISC" adv="1">http://tigger.uic.edu/~jlongs2/holes/convex3d.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="alex_dunaevsky" name="convex_3d">
        <vers num="0.8_pre1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-1266" published="2005-01-10" name="CVE-2004-1266" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Buffer overflow in the get_field_headers function in csv2xml.cpp for csv2xml 0.5.1 allows remote attackers to execute arbitrary code via a crafted CSV file.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/18602" source="XF">csv2xml-getfieldheaders-bo(18602)</ref>
      <ref url="http://tigger.uic.edu/~jlongs2/holes/csv2xml.txt" source="MISC" adv="1">http://tigger.uic.edu/~jlongs2/holes/csv2xml.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="jacob_rhoden" name="csv2xml">
        <vers num="0.5.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1267" published="2005-01-10" name="CVE-2004-1267" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:P/A:P)" CVSS_score="6.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.0" CVSS_base_score="6.5">
    <desc>
      <descript source="cve">Buffer overflow in the ParseCommand function in hpgl-input.c in the hpgltops program for CUPS 1.1.22 allows remote attackers to execute arbitrary code via a crafted HPGL file.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/18604" source="XF">cups-parsecommand-hpgl-bo(18604)</ref>
      <ref url="http://www.ubuntulinux.org/support/documentation/usn/usn-50-1" source="UBUNTU">USN-50-1</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-053.html" source="REDHAT">RHSA-2005:053</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-013.html" source="REDHAT">RHSA-2005:013</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:008" source="MANDRAKE">MDKSA-2005:008</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200412-25.xml" source="GENTOO">GLSA-200412-25</ref>
      <ref url="http://tigger.uic.edu/~jlongs2/holes/cups.txt" source="MISC" adv="1">http://tigger.uic.edu/~jlongs2/holes/cups.txt</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10620" source="OVAL">oval:org.mitre.oval:def:10620</ref>
    </refs>
    <vuln_soft>
      <prod vendor="easy_software_products" name="cups">
        <vers num="1.0.4" />
        <vers num="1.0.4_8" />
        <vers num="1.1.1" />
        <vers num="1.1.10" />
        <vers num="1.1.12" />
        <vers num="1.1.13" />
        <vers num="1.1.14" />
        <vers num="1.1.15" />
        <vers num="1.1.16" />
        <vers num="1.1.17" />
        <vers num="1.1.18" />
        <vers num="1.1.19" />
        <vers num="1.1.19_rc5" />
        <vers num="1.1.20" />
        <vers num="1.1.21" />
        <vers num="1.1.22_rc1" />
        <vers num="1.1.4" />
        <vers num="1.1.4_2" />
        <vers num="1.1.4_3" />
        <vers num="1.1.4_5" />
        <vers num="1.1.6" />
        <vers num="1.1.7" />
      </prod>
      <prod vendor="redhat" name="fedora_core">
        <vers num="core_2.0" />
        <vers num="core_3.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2004-1268" published="2005-01-10" name="CVE-2004-1268" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">lppasswd in CUPS 1.1.22 ignores write errors when modifying the CUPS passwd file, which allows local users to corrupt the file by filling the associated file system and triggering the write errors.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/18606" source="XF">cups-lppasswd-passwd-truncate(18606)</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-053.html" source="REDHAT">RHSA-2005:053</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-013.html" source="REDHAT">RHSA-2005:013</ref>
      <ref url="http://tigger.uic.edu/~jlongs2/holes/cups2.txt" source="MISC" adv="1">http://tigger.uic.edu/~jlongs2/holes/cups2.txt</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10398" source="OVAL">oval:org.mitre.oval:def:10398</ref>
      <ref url="http://www.ubuntulinux.org/support/documentation/usn/usn-50-1" source="UBUNTU">USN-50-1</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:008" source="MANDRAKE">MDKSA-2005:008</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200412-25.xml" source="GENTOO">GLSA-200412-25</ref>
    </refs>
    <vuln_soft>
      <prod vendor="easy_software_products" name="cups">
        <vers num="1.0.4" />
        <vers num="1.0.4_8" />
        <vers num="1.1.1" />
        <vers num="1.1.10" />
        <vers num="1.1.12" />
        <vers num="1.1.13" />
        <vers num="1.1.14" />
        <vers num="1.1.15" />
        <vers num="1.1.16" />
        <vers num="1.1.17" />
        <vers num="1.1.18" />
        <vers num="1.1.19" />
        <vers num="1.1.19_rc5" />
        <vers num="1.1.20" />
        <vers num="1.1.21" />
        <vers num="1.1.22_rc1" />
        <vers num="1.1.4" />
        <vers num="1.1.4_2" />
        <vers num="1.1.4_3" />
        <vers num="1.1.4_5" />
        <vers num="1.1.6" />
        <vers num="1.1.7" />
      </prod>
      <prod vendor="redhat" name="fedora_core">
        <vers num="core_2.0" />
        <vers num="core_3.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1269" published="2005-01-10" name="CVE-2004-1269" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">lppasswd in CUPS 1.1.22 does not remove the passwd.new file if it encounters a file-size resource limit while writing to passwd.new, which causes subsequent invocations of lppasswd to fail.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/18608" source="XF">cups-lppasswd-dos(18608)</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-053.html" source="REDHAT">RHSA-2005:053</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-013.html" source="REDHAT">RHSA-2005:013</ref>
      <ref url="http://tigger.uic.edu/~jlongs2/holes/cups2.txt" source="MISC" adv="1">http://tigger.uic.edu/~jlongs2/holes/cups2.txt</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9545" source="OVAL">oval:org.mitre.oval:def:9545</ref>
      <ref url="http://www.ubuntulinux.org/support/documentation/usn/usn-50-1" source="UBUNTU">USN-50-1</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:008" source="MANDRAKE">MDKSA-2005:008</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200412-25.xml" source="GENTOO">GLSA-200412-25</ref>
    </refs>
    <vuln_soft>
      <prod vendor="easy_software_products" name="cups">
        <vers num="1.0.4" />
        <vers num="1.0.4_8" />
        <vers num="1.1.1" />
        <vers num="1.1.10" />
        <vers num="1.1.12" />
        <vers num="1.1.13" />
        <vers num="1.1.14" />
        <vers num="1.1.15" />
        <vers num="1.1.16" />
        <vers num="1.1.17" />
        <vers num="1.1.18" />
        <vers num="1.1.19" />
        <vers num="1.1.19_rc5" />
        <vers num="1.1.20" />
        <vers num="1.1.21" />
        <vers num="1.1.22_rc1" />
        <vers num="1.1.4" />
        <vers num="1.1.4_2" />
        <vers num="1.1.4_3" />
        <vers num="1.1.4_5" />
        <vers num="1.1.6" />
        <vers num="1.1.7" />
      </prod>
      <prod vendor="redhat" name="fedora_core">
        <vers num="core_2.0" />
        <vers num="core_3.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2004-1270" published="2005-01-10" name="CVE-2004-1270" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">lppasswd in CUPS 1.1.22, when run in environments that do not ensure that file descriptors 0, 1, and 2 are open when lppasswd is called, does not verify that the passwd.new file is different from STDERR, which allows local users to control output to passwd.new via certain user input that triggers an error message.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
      <env />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/18609" source="XF">cups-lppasswd-passwd-modify(18609)</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-053.html" source="REDHAT">RHSA-2005:053</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-013.html" source="REDHAT">RHSA-2005:013</ref>
      <ref url="http://tigger.uic.edu/~jlongs2/holes/cups2.txt" source="MISC" adv="1">http://tigger.uic.edu/~jlongs2/holes/cups2.txt</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11507" source="OVAL">oval:org.mitre.oval:def:11507</ref>
      <ref url="http://www.ubuntulinux.org/support/documentation/usn/usn-50-1" source="UBUNTU">USN-50-1</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:008" source="MANDRAKE">MDKSA-2005:008</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200412-25.xml" source="GENTOO">GLSA-200412-25</ref>
    </refs>
    <vuln_soft>
      <prod vendor="easy_software_products" name="cups">
        <vers num="1.0.4" />
        <vers num="1.0.4_8" />
        <vers num="1.1.1" />
        <vers num="1.1.10" />
        <vers num="1.1.12" />
        <vers num="1.1.13" />
        <vers num="1.1.14" />
        <vers num="1.1.15" />
        <vers num="1.1.16" />
        <vers num="1.1.17" />
        <vers num="1.1.18" />
        <vers num="1.1.19" />
        <vers num="1.1.19_rc5" />
        <vers num="1.1.20" />
        <vers num="1.1.21" />
        <vers num="1.1.22_rc1" />
        <vers num="1.1.4" />
        <vers num="1.1.4_2" />
        <vers num="1.1.4_3" />
        <vers num="1.1.4_5" />
        <vers num="1.1.6" />
        <vers num="1.1.7" />
      </prod>
      <prod vendor="redhat" name="fedora_core">
        <vers num="core_2.0" />
        <vers num="core_3.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-1271" published="2005-01-10" name="CVE-2004-1271" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Buffer overflow in the dxfin function in d.c for dxfscope 0.2 allows remote attackers to execute arbitrary code via a crafted DXF file.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/18558" source="XF">dxfscope-dxfin-bo(18558)</ref>
      <ref url="http://tigger.uic.edu/~jlongs2/holes/dxfscope.txt" source="MISC" adv="1">http://tigger.uic.edu/~jlongs2/holes/dxfscope.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="dxfscope" name="dxf_file_format_viewer">
        <vers num="0.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-1272" published="2005-01-10" name="CVE-2004-1272" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Buffer overflow in the save_embedded_address function in filter.c for elm/bolthole filter 2.6.1 allows remote attackers to execute arbitrary code via a crafted email message.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/18607" source="XF">elm-bolthole-bo(18607)</ref>
      <ref url="http://tigger.uic.edu/~jlongs2/holes/elm-bolthole-filter.txt" source="MISC" adv="1">http://tigger.uic.edu/~jlongs2/holes/elm-bolthole-filter.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="bolthole" name="filter">
        <vers num="2.6.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-1273" published="2005-01-10" name="CVE-2004-1273" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Buffer overflow in the DownloadLoop function in main.c for greed 0.81p allows remote attackers to execute arbitrary code via a GRX file containing a long filename.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/18633" source="XF">greed-downloadloop-bo(18633)</ref>
      <ref url="http://tigger.uic.edu/~jlongs2/holes/greed.txt" source="MISC" adv="1">http://tigger.uic.edu/~jlongs2/holes/greed.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="greed" name="greed">
        <vers num="0.81p" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-1274" published="2005-01-10" name="CVE-2004-1274" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">The DownloadLoop function in main.c for greed 0.81p allows remote attackers to execute arbitrary code via a GRX file containing a filename with shell metacharacters.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" admin="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/18634" source="XF">greed-downloadloop-command-execution(18634)</ref>
      <ref url="http://tigger.uic.edu/~jlongs2/holes/greed.txt" source="MISC" adv="1">http://tigger.uic.edu/~jlongs2/holes/greed.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="greed" name="greed">
        <vers num="0.81p" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-1275" published="2005-01-10" name="CVE-2004-1275" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Buffer overflow in the remove_quote function in convert.c for html2hdml 1.0.3 allows remote attackers to execute arbitrary code via a crafted HTML file.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/18556" source="XF">html2hdml-removequote-bo(18556)</ref>
      <ref url="http://tigger.uic.edu/~jlongs2/holes/html2hdml.txt" source="MISC" adv="1">http://tigger.uic.edu/~jlongs2/holes/html2hdml.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="html2hdml" name="html2hdml">
        <vers num="1.0.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2004-1276" published="2005-01-10" name="CVE-2004-1276" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">IglooFTP 0.6.1, when recursively uploading a directory, allows local users to overwrite the files that are being uploaded by creating temporary files with names generated by the tmpnam function, before the files are opened by IglooFTP.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/18632" source="XF">iglooftp-file-overwrites(18632)</ref>
      <ref url="http://tigger.uic.edu/~jlongs2/holes/iglooftp.txt" source="MISC" adv="1">http://tigger.uic.edu/~jlongs2/holes/iglooftp.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="iglooftp" name="iglooftp">
        <vers num="0.6.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1277" published="2005-01-10" name="CVE-2004-1277" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The download_selection_recursive() function in ftplist.c for IglooFTP 0.6.1 allows remote malicious FTP servers to overwrite arbitrary files via filenames that contain / (slash) characters.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/18561" source="XF">iglooftp-file-overwrite(18561)</ref>
      <ref url="http://tigger.uic.edu/~jlongs2/holes/iglooftp2.txt" source="MISC" adv="1">http://tigger.uic.edu/~jlongs2/holes/iglooftp2.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="iglooftp" name="iglooftp">
        <vers num="0.6.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-1278" published="2005-01-10" name="CVE-2004-1278" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Buffer overflow in the switch_voice function in parse.c for jcabc2ps 20040902 allows remote attackers to execute arbitrary code via a crafted ABC file.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/18563" source="XF">jcabc2ps-switchvoice-bo(18563)</ref>
      <ref url="http://tigger.uic.edu/~jlongs2/holes/jcabc2ps.txt" source="MISC" adv="1">http://tigger.uic.edu/~jlongs2/holes/jcabc2ps.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="abc2ps" name="abc2ps">
        <vers num="1.2" />
      </prod>
      <prod vendor="john_chambers" name="jcabc2ps">
        <vers num="2004-09-02" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-1279" published="2005-01-10" name="CVE-2004-1279" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Buffer overflow in the get_file_list_stdin function in jpegtoavi 1.5 allows remote attackers to execute arbitrary code via a crafted set of JPEG files and filenames.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/18565" source="XF">jpegtoavi-getfileliststdin-bo(18565)</ref>
      <ref url="http://tigger.uic.edu/~jlongs2/holes/jpegtoavi.txt" source="MISC">http://tigger.uic.edu/~jlongs2/holes/jpegtoavi.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="jpegtoavi" name="jpegtoavi">
        <vers num="1.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-1280" published="2005-01-10" name="CVE-2004-1280" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">The gui_popup_view_fly function in gui_tview_popup.c for junkie 0.3.1 allows remote malicious FTP servers to execute arbitrary commands via shell metacharacters in a filename.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" admin="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/18567" source="XF">junkie-command-execution(18567)</ref>
      <ref url="http://tigger.uic.edu/~jlongs2/holes/junkie.txt" source="MISC" adv="1">http://tigger.uic.edu/~jlongs2/holes/junkie.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="junkie" name="junkie_ftp_client">
        <vers num="0.3.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1281" published="2005-01-10" name="CVE-2004-1281" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The ftp_retr function in junkie 0.3.1 allows remote malicious FTP servers to overwrite arbitrary files via .. (dot dot) sequences in a filename.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/18568" source="XF">junkie-ftpretr-command-execution(18568)</ref>
      <ref url="http://tigger.uic.edu/~jlongs2/holes/junkie.txt" source="MISC" adv="1">http://tigger.uic.edu/~jlongs2/holes/junkie.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="junkie" name="junkie_ftp_client">
        <vers num="0.3.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-1282" published="2005-01-10" name="CVE-2004-1282" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Buffer overflow in the strexpand function in string.c for LinPopUp 1.2.0 allows remote attackers to execute arbitrary code via a crafted message that is not properly handled during a Reply operation.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/18627" source="XF">linpopup-strexpand-bo(18627)</ref>
      <ref url="http://www.debian.org/security/2005/dsa-632" source="DEBIAN">DSA-632</ref>
      <ref url="http://tigger.uic.edu/~jlongs2/holes/linpopup.txt" source="MISC" adv="1">http://tigger.uic.edu/~jlongs2/holes/linpopup.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="linpopup" name="linpopup">
        <vers num="1.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-1283" published="2005-01-10" name="CVE-2004-1283" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Buffer overflow in the Mesh::type method in mesh.c for the mview program in Mesh Viewer 0.2.2 allows remote attackers to execute arbitrary code via crafted mesh files.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/18616" source="XF">mesh-type-bo(18616)</ref>
      <ref url="http://tigger.uic.edu/~jlongs2/holes/meshviewer.txt" source="MISC" adv="1">http://tigger.uic.edu/~jlongs2/holes/meshviewer.txt</ref>
    </refs>
  </entry>
  <entry type="CVE" severity="High" seq="2004-1284" published="2005-01-10" name="CVE-2004-1284" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Buffer overflow in the find_next_file function in playlist.c for mpg123 0.59r allows remote attackers to execute arbitrary code via a crafted MP3 playlist.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/18626" source="XF">mpg123-findnextfile-bo(18626)</ref>
      <ref url="http://tigger.uic.edu/~jlongs2/holes/mpg123.txt" source="MISC" adv="1">http://tigger.uic.edu/~jlongs2/holes/mpg123.txt</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2005_01_sr.html" source="SUSE">SUSE-SR:2005:001</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mpg123" name="mpg123">
        <vers num="0.59m" />
        <vers num="0.59n" />
        <vers num="0.59o" />
        <vers num="0.59p" />
        <vers num="0.59q" />
        <vers num="0.59r" />
        <vers num="pre0.59s" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-1285" published="2005-01-10" name="CVE-2004-1285" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Buffer overflow in the get_header function in asf_mmst_streaming.c for MPlayer 1.0pre5 allows remote attackers to execute arbitrary code via a crafted ASF video stream.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/18631" source="XF">mplayer-getdata-bo(18631)</ref>
      <ref url="http://tigger.uic.edu/~jlongs2/holes/mplayer.txt" source="MISC" adv="1">http://tigger.uic.edu/~jlongs2/holes/mplayer.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mplayer" name="mplayer">
        <vers num="0.90" />
        <vers num="0.91" />
        <vers num="0.92" />
        <vers num="0.92.1" />
        <vers num="1.0_pre1" />
        <vers num="1.0_pre2" />
        <vers num="1.0_pre3" />
        <vers num="1.0_pre3try2" />
        <vers num="1.0_pre4" />
        <vers num="1.0_pre5" />
        <vers num="1.0_pre5try1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-1286" published="2005-01-10" name="CVE-2004-1286" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Buffer overflow in the auto_filter_extern function in auto.c for NapShare 1.2, with the extern filter enabled, allows remote attackers to execute arbitrary code via a crafted gnutella response.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/18630" source="XF">napshare-autofilterextern-bo(18630)</ref>
      <ref url="http://tigger.uic.edu/~jlongs2/holes/napshare.txt" source="MISC" adv="1">http://tigger.uic.edu/~jlongs2/holes/napshare.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="napshare" name="napshare">
        <vers num="1.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-1287" published="2005-01-10" name="CVE-2004-1287" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Buffer overflow in the error function in preproc.c for NASM 0.98.38 1.2 allows attackers to execute arbitrary code via a crafted asm file, a different vulnerability than CVE-2005-1194.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/18540" source="XF">nasm-preprocc-bo(18540)</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-381.html" source="REDHAT">RHSA-2005:381</ref>
      <ref url="http://tigger.uic.edu/~jlongs2/holes/nasm.txt" source="MISC" adv="1">http://tigger.uic.edu/~jlongs2/holes/nasm.txt</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11299" source="OVAL">oval:org.mitre.oval:def:11299</ref>
    </refs>
    <vuln_soft>
      <prod vendor="nasm" name="nasm">
        <vers num="0.98.38" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-1288" published="2005-01-10" name="CVE-2004-1288" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Buffer overflow in the parse_html function in o3read.c for o3read 0.0.3 allows remote attackers to execute arbitrary code via a crafted SXW file.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/18547" source="XF">o3read-parsehtml-bo(18547)</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200501-20.xml" source="GENTOO">GLSA-200501-20</ref>
      <ref url="http://tigger.uic.edu/~jlongs2/holes/o3read.txt" source="MISC" adv="1">http://tigger.uic.edu/~jlongs2/holes/o3read.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="siag" name="o3read">
        <vers num=".3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-1289" published="2005-01-10" name="CVE-2004-1289" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Multiple buffer overflows in (1) the getline function in pcalutil.c and (2) the get_holiday function in readfile.c for pcal 4.7.1 allow remote attackers to execute arbitrary code via a crafted calendar file.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/18552" source="XF">pcal-getline-pcalutil-bo(18552)</ref>
      <ref url="http://tigger.uic.edu/~jlongs2/holes/pcal.txt" source="MISC" adv="1">http://tigger.uic.edu/~jlongs2/holes/pcal.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="pcal" name="pcal">
        <vers num="4.1.0" />
        <vers num="4.3.0" />
        <vers num="4.5.0" />
        <vers num="4.6.0" />
        <vers num="4.7.0" />
        <vers num="4.7.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-1290" published="2005-01-10" name="CVE-2004-1290" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Buffer overflow in the process_moves function in pgn2web.c for pgn2web 0.3 allows remote attackers to execute arbitrary code via a crafted PGN file.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/18554" source="XF">pgn2web-pgn2webc-bo(18554)</ref>
      <ref url="http://tigger.uic.edu/~jlongs2/holes/pgn2web.txt" source="MISC">http://tigger.uic.edu/~jlongs2/holes/pgn2web.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="william_hoggarth" name="pgn2web">
        <vers num="0.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-1291" published="2005-01-10" name="CVE-2004-1291" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in qwik-smtpd allows remote attackers to use the server as an SMTP spam relay via a long HELO command, which overwrites the adjacent localIP data buffer.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/18555" source="XF">qwilmail-smtp-helo-open-relay(18555)</ref>
      <ref url="http://tigger.uic.edu/~jlongs2/holes/qwik-smtpd.txt" source="MISC" adv="1">http://tigger.uic.edu/~jlongs2/holes/qwik-smtpd.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="amir_malik" name="qwik_smtpd">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-1292" published="2005-01-10" name="CVE-2004-1292" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Buffer overflow in the parse_emelody function in parse_emelody.c for ringtonetools 2.22 allows remote attackers to execute arbitrary code via a crafted eMelody file.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/18557" source="XF">ringtonetools-parseemelody-bo(18557)</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200503-18.xml" source="GENTOO">GLSA-200503-18</ref>
      <ref url="http://tigger.uic.edu/~jlongs2/holes/ringtonetools.txt" source="MISC" adv="1">http://tigger.uic.edu/~jlongs2/holes/ringtonetools.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="michael_kohn" name="ringtonetools">
        <vers num="2.22" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-1293" published="2005-01-10" name="CVE-2004-1293" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Buffer overflow in the ReadFontTbl function in reader.c for rtf2latex2e 1.0fc2 allows remote attackers to execute arbitrary code via a crafted RTF file.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/18559" source="XF">rtf2latex2e-reader-bo(18559)</ref>
      <ref url="http://tigger.uic.edu/~jlongs2/holes/rtf2latex2e.txt" source="MISC" adv="1">http://tigger.uic.edu/~jlongs2/holes/rtf2latex2e.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="rtf2latex2e" name="rtf2latex2e">
        <vers num="1.0_fc2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1294" published="2005-01-10" name="CVE-2004-1294" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The mget function in cmds.c for tnftp 20030825 allows remote FTP servers to overwrite arbitrary files via FTP responses containing file names with / (slash) characters.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/18560" source="XF">tnftp-mget-cmds-file-overwrite(18560)</ref>
      <ref url="http://tigger.uic.edu/~jlongs2/holes/tnftp.txt" source="MISC" adv="1">http://tigger.uic.edu/~jlongs2/holes/tnftp.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="luke_mewburn" name="tnftp">
        <vers num="2003-08-25" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2004-1295" published="2005-01-10" name="CVE-2004-1295" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">The slip_down function in slip.c for the uml_net program in uml-utilities 20030903, when uml_net is installed setuid root, does not verify whether the calling user has sufficient permission to disable an interface, which allows local users to cause a denial of service (network service disabled).</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <access />
      <exception />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/18562" source="XF">umlutilities-umtnet-slipdown-dos(18562)</ref>
      <ref url="http://tigger.uic.edu/~jlongs2/holes/uml-utilites.txt" source="MISC" adv="1">http://tigger.uic.edu/~jlongs2/holes/uml-utilites.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="uml-utilities" name="uml-utilities">
        <vers num="2003-09-03" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2004-1296" published="2004-12-31" name="CVE-2004-1296" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">The (1) eqn2graph and (2) pic2graph scripts in groff 1.18.1 allow local users to overwrite arbitrary files via a symlink attack on temporary files.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110358225615424&amp;w=2" source="BUGTRAQ" patch="1">20041220 [USN-43-1] groff utility vulnerabilities</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/18660" source="XF">groff-eqn2graph-pic2graph-symlink(18660)</ref>
      <ref url="http://wwwnew.mandriva.com/security/advisories?name=MDKSA-2006:038" source="MANDRIVA">MDKSA-2006:038</ref>
      <ref url="http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=286372" source="CONFIRM">http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=286372</ref>
      <ref url="http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=286371" source="CONFIRM">http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=286371</ref>
    </refs>
  </entry>
  <entry type="CVE" severity="High" seq="2004-1297" published="2005-01-10" name="CVE-2004-1297" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Buffer overflow in the process_font_table function in convert.c for unrtf 0.19.3 allows remote attackers to execute arbitrary code via a crafted RTF file.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/18566" source="XF">unrtf-processfonttable-convert-bo(18566)</ref>
      <ref url="http://tigger.uic.edu/~jlongs2/holes/unrtf.txt" source="MISC" adv="1">http://tigger.uic.edu/~jlongs2/holes/unrtf.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="zack_smith" name="unrtf">
        <vers num="0.19.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-1298" published="2005-01-10" name="CVE-2004-1298" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Buffer overflow in the parse function in vb2c.c for vb2c 0.02 allows remote attackers to execute arbitrary code via a crafted FRM file.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/18605" source="XF">vb2c-gettoken-bo(18605)</ref>
      <ref url="http://tigger.uic.edu/~jlongs2/holes/vb2c.txt" source="MISC" adv="1">http://tigger.uic.edu/~jlongs2/holes/vb2c.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="michael_kohn" name="vb2c">
        <vers num="0.02" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-1299" published="2005-01-10" name="CVE-2004-1299" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Buffer overflow in the get_attr function in html.c for vilistextum 2.6.6 allows remote attackers to execute arbitrary code via a crafted web page.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/18610" source="XF">vilistextum-getattr-bo(18610)</ref>
      <ref url="http://tigger.uic.edu/~jlongs2/holes/vilistextum.txt" source="MISC" adv="1">http://tigger.uic.edu/~jlongs2/holes/vilistextum.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="vilistextum" name="vilistextum">
        <vers num="2.6.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-1300" published="2005-01-10" name="CVE-2004-1300" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Buffer overflow in the open_aiff_file function in demux_aiff.c for xine-lib (libxine) 1-rc7 allows remote attackers to execute arbitrary code via a crafted AIFF file.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/18611" source="XF">xine-openaifffile-bo(18611)</ref>
      <ref url="http://tigger.uic.edu/~jlongs2/holes/xine-lib.txt" source="MISC" adv="1">http://tigger.uic.edu/~jlongs2/holes/xine-lib.txt</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:011" source="MANDRAKE">MDKSA-2005:011</ref>
    </refs>
    <vuln_soft>
      <prod vendor="xine" name="xine-lib">
        <vers num="1_rc7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-1301" published="2005-01-10" name="CVE-2004-1301" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Buffer overflow in the book_format_sql function in format.c for xlreader 0.9.0 allows remote attackers to execute arbitrary code via a crafted Excel (XLS) file.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/18612" source="XF">xlreader-bookformatsql-bo(18612)</ref>
      <ref url="http://tigger.uic.edu/~jlongs2/holes/xlreader.txt" source="MISC" adv="1">http://tigger.uic.edu/~jlongs2/holes/xlreader.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="xlreader" name="xlreader">
        <vers num="0.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-1302" published="2005-01-10" name="CVE-2004-1302" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">The id3tag_sort function in id3tag.c for YAMT 0.5 allows remote attackers to execute arbitrary commands via an MP3 file with double quotes in the Artist tag.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" admin="1" />
    </loss_types>
    <vuln_types>
      <input />
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/18614" source="XF">yamt-id3tagsort-bo(18614)</ref>
      <ref url="http://www.securityfocus.com/bid/11999" source="BID">11999</ref>
      <ref url="http://tigger.uic.edu/~jlongs2/holes/yamt.txt" source="MISC" adv="1">http://tigger.uic.edu/~jlongs2/holes/yamt.txt</ref>
      <ref url="http://securitytracker.com/id?1012583" source="SECTRACK">1012583</ref>
      <ref url="http://secunia.com/advisories/13554" source="SECUNIA">13554</ref>
      <ref url="http://rpmfind.net/linux/RPM/suse/updates/8.2/i386/rpm/i586/yamt-0.5-1277.i586.html" source="CONFIRM">http://rpmfind.net/linux/RPM/suse/updates/8.2/i386/rpm/i586/yamt-0.5-1277.i586.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="yamt" name="yamt">
        <vers num="0.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-1303" published="2005-01-10" name="CVE-2004-1303" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Buffer overflow in the get function in get.c for Yanf 0.4 allows remote malicious web servers to execute arbitrary code via crafted HTTP responses.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/18615" source="XF">yanf-get-bo(18615)</ref>
      <ref url="http://tigger.uic.edu/~jlongs2/holes/yanf.txt" source="MISC" adv="1">http://tigger.uic.edu/~jlongs2/holes/yanf.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="yanf" name="yanf">
        <vers num="0.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-1304" published="2005-01-10" name="CVE-2004-1304" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Stack-based buffer overflow in the ELF header parsing code in file before 4.12 allows attackers to execute arbitrary code via a crafted ELF file.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/11771" source="BID" patch="1" adv="1">11771</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/18368" source="XF" adv="1">file-elf-header-bo(18368)</ref>
      <ref url="http://www.trustix.net/errata/2004/0063/" source="TRUSTIX">2004-0063</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200412-07.xml" source="GENTOO">GLSA-200412-07</ref>
      <ref url="http://securitytracker.com/id?1012433" source="SECTRACK">1012433</ref>
    </refs>
    <vuln_soft>
      <prod vendor="file" name="file">
        <vers num="4.0" />
        <vers num="4.1" />
        <vers num="4.10" />
        <vers num="4.11" />
        <vers num="4.2" />
        <vers num="4.3" />
        <vers num="4.4" />
        <vers num="4.5" />
        <vers num="4.6" />
        <vers num="4.7" />
        <vers num="4.8" />
        <vers num="4.9" />
      </prod>
      <prod vendor="gentoo" name="linux">
        <vers num="" />
      </prod>
      <prod vendor="trustix" name="secure_linux">
        <vers num="2.0" />
        <vers num="2.1" />
        <vers num="2.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1305" published="2004-12-23" name="CVE-2004-1305" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The Windows Animated Cursor (ANI) capability in Windows NT, Windows 2000 through SP4, Windows XP through SP1, and Windows 2003 allow remote attackers to cause a denial of service via (1) the frame number set to zero, which causes an invalid memory address to be used and leads to a kernel crash, or (2) the rate number set to zero, which leads to resource exhaustion and hang.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA05-012A.html" source="CERT" patch="1" adv="1">TA05-012A</ref>
      <ref url="http://www.kb.cert.org/vuls/id/697136" source="CERT-VN" patch="1" adv="1">VU#697136</ref>
      <ref url="http://www.kb.cert.org/vuls/id/177584" source="CERT-VN" patch="1" adv="1">VU#177584</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/18667" source="XF" patch="1" adv="1">win-ani-ratenumber-dos(18667)</ref>
      <ref url="http://www.microsoft.com/technet/Security/bulletin/ms05-002.mspx" source="MS" patch="1" adv="1">MS05-002</ref>
      <ref url="http://www.xfocus.net/flashsky/icoExp/" source="MISC" adv="1">http://www.xfocus.net/flashsky/icoExp/</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110382854111833&amp;w=2" source="BUGTRAQ" adv="1">20041223 Microsoft Windows Kernel ANI File Parsing Crash and DOS Vulnerability</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:712" source="OVAL" sig="1">oval:org.mitre.oval:def:712</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:3957" source="OVAL" sig="1">oval:org.mitre.oval:def:3957</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:3216" source="OVAL" sig="1">oval:org.mitre.oval:def:3216</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2580" source="OVAL" sig="1">oval:org.mitre.oval:def:2580</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1304" source="OVAL" sig="1">oval:org.mitre.oval:def:1304</ref>
    </refs>
    <vuln_soft>
      <prod vendor="nortel" name="ip_softphone_2050">
        <vers num="" />
      </prod>
      <prod vendor="nortel" name="media_communication_server_5100">
        <vers num="3.0" />
      </prod>
      <prod vendor="nortel" name="media_communication_server_5200">
        <vers num="3.0" />
      </prod>
      <prod vendor="nortel" name="media_processing_server">
        <vers num="" />
      </prod>
      <prod vendor="nortel" name="periphonics">
        <vers num="" />
      </prod>
      <prod vendor="nortel" name="symposium_agent">
        <vers num="" />
      </prod>
      <prod vendor="nortel" name="symposium_network_control_center">
        <vers num="" />
      </prod>
      <prod vendor="nortel" name="symposium_tapi_service_provider">
        <vers num="" />
      </prod>
      <prod vendor="nortel" name="symposium_web_centre_portal">
        <vers num="" />
      </prod>
      <prod vendor="nortel" name="symposium_web_client">
        <vers num="" />
      </prod>
      <prod vendor="nortel" name="symposium_call_center_server">
        <vers num="" />
      </prod>
      <prod vendor="nortel" name="symposium_express_call_center">
        <vers num="" />
      </prod>
      <prod vendor="microsoft" name="windows_2000">
        <vers num="" edition=":professional" />
        <vers num="" edition=":server" />
        <vers num="" edition=":advanced_server" />
        <vers num="" edition="sp1" />
        <vers num="" edition="sp1:professional" />
        <vers num="" edition="sp1:server" />
        <vers num="" edition="sp1:advanced_server" />
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:advanced_server" />
        <vers num="" edition="sp2:professional" />
        <vers num="" edition="sp2:server" />
        <vers num="" edition="sp3" />
        <vers num="" edition="sp3:server" />
        <vers num="" edition="sp3:professional" />
        <vers num="" edition="sp3:advanced_server" />
        <vers num="" edition="sp4" />
        <vers num="" edition="sp4:server" />
        <vers num="" edition="sp4:professional" />
        <vers num="" edition="sp4:advanced_server" />
      </prod>
      <prod vendor="microsoft" name="windows_2003_server">
        <vers num="enterprise" edition="" />
        <vers num="enterprise" edition=":64-bit" />
        <vers num="enterprise_64-bit" />
        <vers num="r2" edition="" />
        <vers num="r2" edition=":datacenter_64-bit" />
        <vers num="r2" edition=":64-bit" />
        <vers num="standard" edition="" />
        <vers num="standard" edition=":64-bit" />
        <vers num="web" />
      </prod>
      <prod vendor="microsoft" name="windows_98">
        <vers num="" edition="gold" />
      </prod>
      <prod vendor="microsoft" name="windows_98se">
        <vers num="" />
      </prod>
      <prod vendor="microsoft" name="windows_me">
        <vers num="" />
      </prod>
      <prod vendor="microsoft" name="windows_nt">
        <vers num="4.0" edition="" />
        <vers num="4.0" edition=":server" />
        <vers num="4.0" edition=":enterprise_server" />
        <vers num="4.0" edition=":terminal_server" />
        <vers num="4.0" edition=":workstation" />
        <vers num="4.0" edition="sp1" />
        <vers num="4.0" edition="sp1:server" />
        <vers num="4.0" edition="sp1:workstation" />
        <vers num="4.0" edition="sp1:terminal_server" />
        <vers num="4.0" edition="sp1:enterprise_server" />
        <vers num="4.0" edition="sp2" />
        <vers num="4.0" edition="sp2:enterprise_server" />
        <vers num="4.0" edition="sp2:server" />
        <vers num="4.0" edition="sp2:workstation" />
        <vers num="4.0" edition="sp2:terminal_server" />
        <vers num="4.0" edition="sp3" />
        <vers num="4.0" edition="sp3:workstation" />
        <vers num="4.0" edition="sp3:server" />
        <vers num="4.0" edition="sp3:terminal_server" />
        <vers num="4.0" edition="sp3:enterprise_server" />
        <vers num="4.0" edition="sp4" />
        <vers num="4.0" edition="sp4:workstation" />
        <vers num="4.0" edition="sp4:enterprise_server" />
        <vers num="4.0" edition="sp4:terminal_server" />
        <vers num="4.0" edition="sp4:server" />
        <vers num="4.0" edition="sp5" />
        <vers num="4.0" edition="sp5:workstation" />
        <vers num="4.0" edition="sp5:enterprise_server" />
        <vers num="4.0" edition="sp5:server" />
        <vers num="4.0" edition="sp5:terminal_server" />
        <vers num="4.0" edition="sp6" />
        <vers num="4.0" edition="sp6:terminal_server" />
        <vers num="4.0" edition="sp6:server" />
        <vers num="4.0" edition="sp6:enterprise_server" />
        <vers num="4.0" edition="sp6:workstation" />
        <vers num="4.0" edition="sp6a" />
        <vers num="4.0" edition="sp6a:server" />
        <vers num="4.0" edition="sp6a:enterprise_server" />
        <vers num="4.0" edition="sp6a:workstation" />
      </prod>
      <prod vendor="microsoft" name="windows_xp">
        <vers num="" edition=":home" />
        <vers num="" edition=":64-bit" />
        <vers num="" edition=":embedded" />
        <vers num="" edition=":media_center" />
        <vers num="" edition="gold" />
        <vers num="" edition="gold:professional" />
        <vers num="" edition="sp1" />
        <vers num="" edition="sp1:home" />
        <vers num="" edition="sp1:media_center" />
        <vers num="" edition="sp1:64-bit" />
        <vers num="" edition="sp1:embedded" />
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:tablet_pc" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1306" published="2004-12-31" name="CVE-2004-1306" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_score="5.1" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="4.9" CVSS_base_score="5.1">
    <desc>
      <descript source="cve">Heap-based buffer overflow in winhlp32.exe in Windows NT, Windows 2000 through SP4, Windows XP through SP2, and Windows 2003 allows remote attackers to execute arbitrary code via a crafted .hlp file.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/18678" source="XF">win-winhlp32-bo(18678)</ref>
      <ref url="http://www.xfocus.net/flashsky/icoExp/" source="MISC">http://www.xfocus.net/flashsky/icoExp/</ref>
      <ref url="http://www.securityfocus.com/bid/12092" source="BID">12092</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110383690219440&amp;w=2" source="BUGTRAQ">20041223 Microsoft Windows winhlp32.exe Heap Overflow Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_2000">
        <vers num="" edition=":professional" />
        <vers num="" edition=":server" />
        <vers num="" edition=":advanced_server" />
        <vers num="" edition=":datacenter_server" />
        <vers num="" edition="sp1" />
        <vers num="" edition="sp1:datacenter_server" />
        <vers num="" edition="sp1:professional" />
        <vers num="" edition="sp1:server" />
        <vers num="" edition="sp1:advanced_server" />
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:advanced_server" />
        <vers num="" edition="sp2:professional" />
        <vers num="" edition="sp2:datacenter_server" />
        <vers num="" edition="sp2:server" />
        <vers num="" edition="sp3" />
        <vers num="" edition="sp3:datacenter_server" />
        <vers num="" edition="sp3:server" />
        <vers num="" edition="sp3:professional" />
        <vers num="" edition="sp3:advanced_server" />
        <vers num="" edition="sp4" />
        <vers num="" edition="sp4:datacenter_server" />
        <vers num="" edition="sp4:server" />
        <vers num="" edition="sp4:professional" />
        <vers num="" edition="sp4:advanced_server" />
      </prod>
      <prod vendor="microsoft" name="windows_2003_server">
        <vers num="datacenter_64-bit" edition="sp1_beta_1" />
        <vers num="enterprise" edition="" />
        <vers num="enterprise" edition=":64-bit" />
        <vers num="enterprise" edition="sp1_beta_1" />
        <vers num="enterprise_64-bit" edition="sp1_beta_1" />
        <vers num="r2" edition="" />
        <vers num="r2" edition=":datacenter_64-bit" />
        <vers num="r2" edition=":64-bit" />
        <vers num="r2" edition="sp1_beta_1" />
        <vers num="standard" edition="" />
        <vers num="standard" edition=":64-bit" />
        <vers num="standard" edition="sp1_beta_1" />
        <vers num="web" edition="sp1_beta_1" />
      </prod>
      <prod vendor="microsoft" name="windows_nt">
        <vers num="4.0" edition="" />
        <vers num="4.0" edition=":server" />
        <vers num="4.0" edition=":enterprise_server" />
        <vers num="4.0" edition=":terminal_server" />
        <vers num="4.0" edition=":workstation" />
        <vers num="4.0" edition="sp1" />
        <vers num="4.0" edition="sp1:server" />
        <vers num="4.0" edition="sp1:workstation" />
        <vers num="4.0" edition="sp1:terminal_server" />
        <vers num="4.0" edition="sp1:enterprise_server" />
        <vers num="4.0" edition="sp2" />
        <vers num="4.0" edition="sp2:enterprise_server" />
        <vers num="4.0" edition="sp2:server" />
        <vers num="4.0" edition="sp2:workstation" />
        <vers num="4.0" edition="sp2:terminal_server" />
        <vers num="4.0" edition="sp3" />
        <vers num="4.0" edition="sp3:workstation" />
        <vers num="4.0" edition="sp3:server" />
        <vers num="4.0" edition="sp3:terminal_server" />
        <vers num="4.0" edition="sp3:enterprise_server" />
        <vers num="4.0" edition="sp4" />
        <vers num="4.0" edition="sp4:workstation" />
        <vers num="4.0" edition="sp4:enterprise_server" />
        <vers num="4.0" edition="sp4:terminal_server" />
        <vers num="4.0" edition="sp4:server" />
        <vers num="4.0" edition="sp5" />
        <vers num="4.0" edition="sp5:workstation" />
        <vers num="4.0" edition="sp5:enterprise_server" />
        <vers num="4.0" edition="sp5:server" />
        <vers num="4.0" edition="sp5:terminal_server" />
        <vers num="4.0" edition="sp6" />
        <vers num="4.0" edition="sp6:terminal_server" />
        <vers num="4.0" edition="sp6:server" />
        <vers num="4.0" edition="sp6:enterprise_server" />
        <vers num="4.0" edition="sp6:workstation" />
        <vers num="4.0" edition="sp6a" />
        <vers num="4.0" edition="sp6a:server" />
        <vers num="4.0" edition="sp6a:enterprise_server" />
        <vers num="4.0" edition="sp6a:terminal_server" />
        <vers num="4.0" edition="sp6a:workstation" />
      </prod>
      <prod vendor="microsoft" name="windows_xp">
        <vers num="" edition=":home" />
        <vers num="" edition=":64-bit" />
        <vers num="" edition=":media_center" />
        <vers num="" edition="gold" />
        <vers num="" edition="gold:professional" />
        <vers num="" edition="sp1" />
        <vers num="" edition="sp1:home" />
        <vers num="" edition="sp1:media_center" />
        <vers num="" edition="sp1:64-bit" />
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:home" />
        <vers num="" edition="sp2:media_center" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-1307" published="2004-12-21" name="CVE-2004-1307" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Integer overflow in the TIFFFetchStripThing function in tif_dirread.c for libtiff 3.6.1 allows remote attackers to execute arbitrary code via a TIFF file with the STRIPOFFSETS flag and a large number of strips, which causes a zero byte buffer to be allocated and leads to a heap-based buffer overflow.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/539110" source="CERT-VN" patch="1" adv="1">VU#539110</ref>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA05-136A.html" source="CERT">TA05-136A</ref>
      <ref url="http://www.idefense.com/application/poi/display?id=173&amp;type=vulnerabilities&amp;flashstatus=true" source="IDEFENSE" patch="1" adv="1">20041221 libtiff STRIPOFFSETS Integer Overflow Vulnerability</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2005/May/msg00001.html" source="APPLE" patch="1" adv="1">APPLE-SA-2005-05-03</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-66-201072-1" source="SUNALERT">201072</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11175" source="OVAL">oval:org.mitre.oval:def:11175</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-101677-1" source="SUNALERT">101677</ref>
    </refs>
    <vuln_soft>
      <prod vendor="avaya" name="call_management_system_server">
        <vers num="11.0" />
        <vers num="12.0" />
        <vers num="13.0" />
        <vers num="8.0" />
        <vers num="9.0" />
      </prod>
      <prod vendor="avaya" name="cvlan">
        <vers num="" />
      </prod>
      <prod vendor="avaya" name="integrated_management">
        <vers num="" />
      </prod>
      <prod vendor="avaya" name="interactive_response">
        <vers num="1.2.1" />
        <vers num="1.3" />
      </prod>
      <prod vendor="avaya" name="intuity_audix_lx">
        <vers num="" />
      </prod>
      <prod vendor="avaya" name="mn100">
        <vers num="" />
      </prod>
      <prod vendor="f5" name="icontrol_service_manager">
        <vers num="1.3" />
        <vers num="1.3.4" />
        <vers num="1.3.5" />
        <vers num="1.3.6" />
      </prod>
      <prod vendor="libtiff" name="libtiff">
        <vers num="3.4" />
        <vers num="3.5.1" />
        <vers num="3.5.2" />
        <vers num="3.5.3" />
        <vers num="3.5.4" />
        <vers num="3.5.5" />
        <vers num="3.5.7" />
        <vers num="3.6.0" />
        <vers num="3.6.1" />
        <vers num="3.7.0" />
      </prod>
      <prod vendor="sgi" name="propack">
        <vers num="3.0" />
      </prod>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.3" />
        <vers num="10.3.1" />
        <vers num="10.3.2" />
        <vers num="10.3.3" />
        <vers num="10.3.4" />
        <vers num="10.3.5" />
        <vers num="10.3.6" />
        <vers num="10.3.7" />
        <vers num="10.3.8" />
        <vers num="10.3.9" />
      </prod>
      <prod vendor="apple" name="mac_os_x_server">
        <vers num="10.3" />
        <vers num="10.3.1" />
        <vers num="10.3.2" />
        <vers num="10.3.3" />
        <vers num="10.3.4" />
        <vers num="10.3.5" />
        <vers num="10.3.6" />
        <vers num="10.3.7" />
        <vers num="10.3.8" />
        <vers num="10.3.9" />
      </prod>
      <prod vendor="avaya" name="modular_messaging_message_storage_server">
        <vers num="1.1" />
        <vers num="2.0" />
      </prod>
      <prod vendor="conectiva" name="linux">
        <vers num="10.0" />
        <vers num="9.0" />
      </prod>
      <prod vendor="gentoo" name="linux">
        <vers num="" />
      </prod>
      <prod vendor="mandrakesoft" name="mandrake_linux">
        <vers num="10.0" edition="" />
        <vers num="10.0" edition=":amd64" />
        <vers num="10.1" edition="" />
        <vers num="10.1" edition=":x86_64" />
      </prod>
      <prod vendor="mandrakesoft" name="mandrake_linux_corporate_server">
        <vers num="3.0" edition="" />
        <vers num="3.0" edition=":x86_64" />
      </prod>
      <prod vendor="sco" name="unixware">
        <vers num="7.1.4" />
      </prod>
      <prod vendor="sun" name="solaris">
        <vers num="10.0" edition="" />
        <vers num="10.0" edition=":x86" />
        <vers num="10.0" edition=":sparc" />
        <vers num="7.0" edition="" />
        <vers num="7.0" edition=":x86" />
        <vers num="8.0" edition="" />
        <vers num="8.0" edition=":x86" />
        <vers num="9.0" edition="" />
        <vers num="9.0" edition=":sparc" />
        <vers num="9.0" edition=":x86" />
        <vers num="9.0" edition="x86_update_2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-1308" published="2005-01-10" name="CVE-2004-1308" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Integer overflow in (1) tif_dirread.c and (2) tif_fax3.c for libtiff 3.5.7 and 3.7.0 allows remote attackers to execute arbitrary code via a TIFF file containing a TIFF_ASCII or TIFF_UNDEFINED directory entry with a -1 entry count, which leads to a heap-based buffer overflow.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/125598" source="CERT-VN">VU#125598</ref>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA05-136A.html" source="CERT">TA05-136A</ref>
      <ref url="http://www.idefense.com/application/poi/display?id=174&amp;type=vulnerabilities" source="IDEFENSE" patch="1" adv="1">20041221 libtiff Directory Entry Count Integer Overflow Vulnerability</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/18637" source="XF">libtiff-tiff-tdircount-bo(18637)</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-035.html" source="REDHAT">RHSA-2005:035</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-019.html" source="REDHAT">RHSA-2005:019</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2005_01_libtiff_tiff.html" source="SUSE">SUSE-SA:2005:001</ref>
      <ref url="http://www.debian.org/security/2004/dsa-617" source="DEBIAN">DSA-617</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-66-201072-1" source="SUNALERT">201072</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9392" source="OVAL">oval:org.mitre.oval:def:9392</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2005/May/msg00001.html" source="APPLE">APPLE-SA-2005-05-03</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:052" source="MANDRAKE">MDKSA-2005:052</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-101677-1" source="SUNALERT">101677</ref>
      <ref url="http://secunia.com/advisories/13776" source="SECUNIA">13776</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000920" source="CONECTIVA">CLA-2005:920</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:100117" source="OVAL" sig="1">oval:org.mitre.oval:def:100117</ref>
    </refs>
    <vuln_soft>
      <prod vendor="libtiff" name="libtiff">
        <vers num="3.4" />
        <vers num="3.5.1" />
        <vers num="3.5.2" />
        <vers num="3.5.3" />
        <vers num="3.5.4" />
        <vers num="3.5.5" />
        <vers num="3.5.7" />
        <vers num="3.6.0" />
        <vers num="3.6.1" />
        <vers num="3.7.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-1309" published="2005-01-10" name="CVE-2004-1309" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Heap-based buffer overflow in the demux_open_bmp function in demux_bmp.c for Unix MPlayer 1.0pre5 allows remote attackers to execute arbitrary code via a bitmap (BMP) file containing a large biClrUsed field.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/18527" source="XF">mplayer-bitmap-bo(18527)</ref>
      <ref url="http://www1.mplayerhq.hu/MPlayer/releases/ChangeLog" source="CONFIRM">http://www1.mplayerhq.hu/MPlayer/releases/ChangeLog</ref>
      <ref url="http://www.idefense.com/application/poi/display?id=168" source="IDEFENSE" adv="1">20041216 MPlayer Bitmap Parsing Remote Heap Overflow Vulnerability</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2004:157" source="MANDRAKE">MDKSA-2004:157</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mplayer" name="unix_mplayer">
        <vers num="1.0_pre5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-1310" published="2005-01-10" name="CVE-2004-1310" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Stack-based buffer overflow in the asf_mmst_streaming.c functionality for MPlayer 1.0pre5 allows remote attackers to execute arbitrary code via a large MMST stream packet.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/18526" source="XF">mplayer-mmst-bo(18526)</ref>
      <ref url="http://www1.mplayerhq.hu/MPlayer/releases/ChangeLog" source="CONFIRM">http://www1.mplayerhq.hu/MPlayer/releases/ChangeLog</ref>
      <ref url="http://www1.mplayerhq.hu/MPlayer/patches/mmst_fix_20041215.diff" source="CONFIRM">http://www1.mplayerhq.hu/MPlayer/patches/mmst_fix_20041215.diff</ref>
      <ref url="http://www.idefense.com/application/poi/display?id=167" source="IDEFENSE" adv="1">20041216 MPlayer MMST Streaming Stack Overflow Vulnerability</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2004:157" source="MANDRAKE">MDKSA-2004:157</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mplayer" name="mplayer">
        <vers num="1.0_pre5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-1311" published="2005-01-10" name="CVE-2004-1311" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Integer overflow in the real_setup_and_get_header function in real.c for Unix MPlayer 1.0pre5 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a Real RTSP streaming media file with a -1 content-length field, which leads to a heap-based buffer overflow.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" admin="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/18525" source="XF">mplayer-rtsp-bo(18525)</ref>
      <ref url="http://www1.mplayerhq.hu/MPlayer/releases/ChangeLog" source="CONFIRM">http://www1.mplayerhq.hu/MPlayer/releases/ChangeLog</ref>
      <ref url="http://www1.mplayerhq.hu/MPlayer/patches/rtsp_fix_20041215.diff" source="CONFIRM">http://www1.mplayerhq.hu/MPlayer/patches/rtsp_fix_20041215.diff</ref>
      <ref url="http://www.idefense.com/application/poi/display?id=166" source="IDEFENSE" adv="1">20041216 MPlayer Remote RTSP Heap Overflow Vulnerability</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2004:157" source="MANDRAKE">MDKSA-2004:157</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mplayer" name="mplayer">
        <vers num="1.0_pre5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-1312" published="2005-01-03" name="CVE-2004-1312" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">A bug in the HTML parser in a certain Microsoft HTML library, as used in various third party products, may allow remote attackers to cause a denial of service via certain strings, as reported in GFI MailEssentials for Exchange 9 and 10, and GFI MailSecurity for Exchange 8, which causes emails to remain in IIS or Exchange mail queues.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://kbase.gfi.com/showarticle.asp?id=KBID002249" source="CONFIRM" patch="1" adv="1">http://kbase.gfi.com/showarticle.asp?id=KBID002249</ref>
      <ref url="http://www.securityfocus.com/bid/12148" source="BID">12148</ref>
      <ref url="http://www.csis.dk/default.asp?m=1&amp;a=194" source="MISC" adv="1">http://www.csis.dk/default.asp?m=1&amp;a=194</ref>
      <ref url="http://secunia.com/advisories/13708" source="SECUNIA">13708</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gfi" name="mailessentials">
        <vers num="10.0" edition="" />
        <vers num="10.0" edition=":exchange_smtp" />
        <vers num="10.1" edition="" />
        <vers num="10.1" edition=":exchange_smtp" />
        <vers num="9.0" edition="" />
        <vers num="9.0" edition=":exchange_smtp" />
      </prod>
      <prod vendor="gfi" name="mailsecurity">
        <vers num="8.0" edition="" />
        <vers num="8.0" edition=":exchange_smtp" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-1313" published="2005-01-10" name="CVE-2004-1313" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">The Smc.exe process in My Firewall Plus 5.0 build 1117, and possibly other versions, does not drop privileges before invoking help, which allows local users to gain privileges.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" admin="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/18622" source="XF">my-firewall-plus-gain-privileges(18622)</ref>
      <ref url="http://secunia.com/secunia_research/2004-16/" source="MISC" adv="1">http://secunia.com/secunia_research/2004-16/</ref>
    </refs>
    <vuln_soft>
      <prod vendor="webroot_software" name="my_firewall_plus">
        <vers num="5.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-1314" published="2005-01-10" name="CVE-2004-1314" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Safari 1.x allows remote attackers to spoof arbitrary web sites by injecting content from one window into a target window whose name is known but resides in a different domain, as demonstrated using a pop-up window on a trusted web site, aka the "window injection" vulnerability, a different vulnerability than CVE-2004-1122.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/18397" source="XF">web-browser-popup-spoofing(18397)</ref>
      <ref url="http://secunia.com/secunia_research/2004-13/advisory/" source="MISC">http://secunia.com/secunia_research/2004-13/advisory/</ref>
      <ref url="http://secunia.com/multiple_browsers_window_injection_vulnerability_test/" source="MISC">http://secunia.com/multiple_browsers_window_injection_vulnerability_test/</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2005/Jan/msg00001.html" source="APPLE">APPLE-SA-2005-01-25</ref>
      <ref url="http://secunia.com/advisories/13252/" source="SECUNIA">13252</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="safari">
        <vers num="1.0" />
        <vers num="1.1" />
        <vers num="1.2" />
        <vers num="1.2.1" />
        <vers num="1.2.2" />
        <vers num="1.2.3" />
        <vers num="beta2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-1315" published="2004-11-12" name="CVE-2004-1315" modified="2008-11-15" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">viewtopic.php in phpBB 2.x before 2.0.11 improperly URL decodes the highlight parameter when extracting words and phrases to highlight, which allows remote attackers to execute arbitrary PHP code by double-encoding the highlight value so that special characters are inserted into the result, which is then processed by PHP exec, as exploited by the Santy.A worm.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA04-356A.html" source="CERT" patch="1" adv="1">TA04-356A</ref>
      <ref url="http://www.kb.cert.org/vuls/id/497400" source="CERT-VN" patch="1" adv="1">VU#497400</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/18052" source="XF" patch="1" adv="1">phpbb-view-sql-injection(18052)</ref>
      <ref url="http://secunia.com/advisories/13239/" source="SECUNIA" patch="1" adv="1">13239</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110143995118428&amp;w=2" source="GENTOO" patch="1" adv="1">GLSA-200411-32</ref>
      <ref url="http://www.securityfocus.com/bid/10701" source="BID">10701</ref>
      <ref url="http://www.securityfocus.com/archive/1/385208" source="BUGTRAQ">20041222 Re: phpBB Worm</ref>
      <ref url="http://www.phpbb.com/phpBB/viewtopic.php?t=240513" source="CONFIRM" adv="1">http://www.phpbb.com/phpBB/viewtopic.php?t=240513</ref>
      <ref url="http://marc.theaimsgroup.com/?t=110079440800004&amp;r=1&amp;w=2" source="BUGTRAQ" adv="1">20041118 EXEC exploit in phpBB - fix</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110365752909029&amp;w=2" source="BUGTRAQ" adv="1">20041220 phpBB Worm</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110029415208724&amp;w=2" source="BUGTRAQ" adv="1">20041112 phpBB Code EXEC (v2.0.10)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="phpbb_group" name="phpbb">
        <vers num="1.0.0" />
        <vers num="1.0.1" />
        <vers num="1.2.0" />
        <vers num="1.2.1" />
        <vers num="1.4.0" />
        <vers num="1.4.1" />
        <vers num="1.4.2" />
        <vers num="1.4.4" />
        <vers num="2.0.0" />
        <vers num="2.0.1" />
        <vers num="2.0.10" />
        <vers num="2.0.2" />
        <vers num="2.0.3" />
        <vers num="2.0.4" />
        <vers num="2.0.5" />
        <vers num="2.0.6" />
        <vers num="2.0.6c" />
        <vers num="2.0.6d" />
        <vers num="2.0.7" />
        <vers num="2.0.7a" />
        <vers num="2.0.8" />
        <vers num="2.0.8a" />
        <vers num="2.0.9" />
        <vers num="2.0_beta1" />
        <vers num="2.0_rc1" />
        <vers num="2.0_rc2" />
        <vers num="2.0_rc3" />
        <vers num="2.0_rc4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1316" published="2004-12-29" name="CVE-2004-1316" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Heap-based buffer overflow in MSG_UnEscapeSearchUrl in nsNNTPProtocol.cpp for Mozilla 1.7.3 and earlier allows remote attackers to cause a denial of service (application crash) via an NNTP URL (news:) with a trailing '\' (backslash) character, which prevents a string from being NULL terminated.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.mozilla.org/security/announce/mfsa2005-06.html" source="CONFIRM" patch="1" adv="1">http://www.mozilla.org/security/announce/mfsa2005-06.html</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/18711" source="XF" adv="1">mozilla-nntp-bo(18711)</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-038.html" source="REDHAT" adv="1">RHSA-2005:038</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2006_04_25.html" source="SUSE">SUSE-SA:2006:004</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9808" source="OVAL">oval:org.mitre.oval:def:9808</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110780717916478&amp;w=2" source="HP" adv="1">HPSBTU01114</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110436284718949&amp;w=2" source="BUGTRAQ" adv="1">20041229 Heap overflow in Mozilla Browser &lt;= 1.7.3 NNTP code.</ref>
      <ref url="http://isec.pl/vulnerabilities/isec-0020-mozilla.txt" source="MISC" adv="1">http://isec.pl/vulnerabilities/isec-0020-mozilla.txt</ref>
      <ref url="http://www.securityfocus.com/bid/12131" source="BID">12131</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2006_04_25.html" source="SUSE">SUSE-SA:2006:022</ref>
      <ref url="http://secunia.com/advisories/19823" source="SECUNIA">19823</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:100052" source="OVAL" sig="1">oval:org.mitre.oval:def:100052</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="mozilla">
        <vers num="1.3" />
        <vers num="1.4" edition="alpha" />
        <vers num="1.4.1" />
        <vers num="1.5" edition="alpha" />
        <vers num="1.5" edition="rc1" />
        <vers num="1.5" edition="rc2" />
        <vers num="1.5.1" />
        <vers num="1.6" edition="alpha" />
        <vers num="1.6" edition="beta" />
        <vers num="1.7" edition="alpha" />
        <vers num="1.7" edition="beta" />
        <vers num="1.7" edition="rc1" />
        <vers num="1.7" edition="rc2" />
        <vers num="1.7" edition="rc3" />
        <vers num="1.7.1" />
        <vers num="1.7.2" />
        <vers num="1.7.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-1317" published="2004-12-27" name="CVE-2004-1317" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Stack-based buffer overflow in doexec.c in Netcat for Windows 1.1, when running with the -e option, allows remote attackers to execute arbitrary code via a long DNS command.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/18681" source="XF" patch="1" adv="1">netcat-doexec-bo(18681)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110429204712327&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20041228 Re: [HAT-SQUAD] NetCat Remote Critical Vulnerability, Poc included</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110426936423890&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20041228 Netcat v1.11 For Windows , New fixed version</ref>
      <ref url="http://www.hat-squad.com/en/000142.html" source="MISC" adv="1">http://www.hat-squad.com/en/000142.html</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110425875504586&amp;w=2" source="BUGTRAQ" adv="1">20041227 [HAT-SQUAD] NetCat Remote Critical Vulnerability, Poc included</ref>
    </refs>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1318" published="2005-01-06" name="CVE-2004-1318" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in namazu.cgi for Namazu 2.0.13 and earlier allows remote attackers to inject arbitrary HTML and web script via a query that starts with a tab ("%09") character, which prevents the rest of the query from being properly sanitized.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.namazu.org/security.html.en#xss-tab" source="CONFIRM" patch="1" adv="1">http://www.namazu.org/security.html.en#xss-tab</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/18623" source="XF">namazu-tab-query-xss(18623)</ref>
      <ref url="http://www.securityfocus.com/bid/12053" source="BID">12053</ref>
      <ref url="http://www.securityfocus.com/advisories/9028" source="HP">HPSBMA01212</ref>
      <ref url="http://www.osvdb.org/12516" source="OSVDB">12516</ref>
      <ref url="http://www.linuxsecurity.com/content/view/117604/102/" source="FEDORA">FEDORA-2004-557</ref>
      <ref url="http://www.debian.org/security/2005/dsa-627" source="DEBIAN" adv="1">DSA-627</ref>
      <ref url="http://securitytracker.com/alerts/2005/Jan/1012805.html" source="SECTRACK">1012805</ref>
      <ref url="http://securitytracker.com/alerts/2005/Jan/1012802.html" source="SECTRACK">1012802</ref>
      <ref url="http://secunia.com/advisories/13600" source="SECUNIA">13600</ref>
      <ref url="http://jvn.jp/jp/JVN%23904429FE.html" source="MISC" adv="1">http://jvn.jp/jp/JVN%23904429FE.html</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2005_01_sr.html" source="SUSE">SUSE-SR:2005:001</ref>
    </refs>
    <vuln_soft>
      <prod vendor="namazu" name="namazu">
        <vers num="2.0.13" />
        <vers num="2.0.7" />
        <vers num="2.0.8" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1319" published="2004-12-15" name="CVE-2004-1319" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The DHTML Edit Control (dhtmled.ocx) allows remote attackers to inject arbitrary web script into other domains by setting a name for a window, opening a child page whose target is the window with the given name, then injecting the script from the parent into the child using execScript, as demonstrated by "AbusiveParent" in Internet Explorer 6.0.2900.2180.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA05-039A.html" source="CERT" patch="1" adv="1">TA05-039A</ref>
      <ref url="http://www.kb.cert.org/vuls/id/356600" source="CERT-VN" patch="1" adv="1">VU#356600</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/18504" source="XF" patch="1" adv="1">ie-dhtml-xss(18504)</ref>
      <ref url="http://www.securityfocus.com/bid/11950" source="BID" patch="1" adv="1">11950</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms05-013.mspx" source="MS" patch="1" adv="1">MS05-013</ref>
      <ref url="http://secunia.com/advisories/13482/" source="SECUNIA" patch="1" adv="1">13482</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2004-12/0167.html" source="BUGTRAQ" adv="1">20041215 MSIE DHTML Edit Control Cross Site Scripting Vulnerability</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:4758" source="OVAL" sig="1">oval:org.mitre.oval:def:4758</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:3851" source="OVAL" sig="1">oval:org.mitre.oval:def:3851</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:3464" source="OVAL" sig="1">oval:org.mitre.oval:def:3464</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1701" source="OVAL" sig="1">oval:org.mitre.oval:def:1701</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1114" source="OVAL" sig="1">oval:org.mitre.oval:def:1114</ref>
    </refs>
    <vuln_soft>
      <prod vendor="nortel" name="ip_softphone_2050">
        <vers num="" />
      </prod>
      <prod vendor="nortel" name="mobile_voice_client_2050">
        <vers num="" />
      </prod>
      <prod vendor="nortel" name="optivity_telephony_manager">
        <vers num="" />
      </prod>
      <prod vendor="microsoft" name="windows_2000">
        <vers num="" edition=":advanced_server" />
        <vers num="" edition=":professional" />
        <vers num="" edition=":datacenter_server" />
        <vers num="" edition="sp1" />
        <vers num="" edition="sp1:datacenter_server" />
        <vers num="" edition="sp1:professional" />
        <vers num="" edition="sp1:advanced_server" />
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:advanced_server" />
        <vers num="" edition="sp2:professional" />
        <vers num="" edition="sp2:datacenter_server" />
        <vers num="" edition="sp3" />
        <vers num="" edition="sp3:datacenter_server" />
        <vers num="" edition="sp3:professional" />
        <vers num="" edition="sp3:advanced_server" />
        <vers num="" edition="sp4" />
        <vers num="" edition="sp4:datacenter_server" />
        <vers num="" edition="sp4:professional" />
        <vers num="" edition="sp4:advanced_server" />
      </prod>
      <prod vendor="microsoft" name="windows_2003_server">
        <vers num="enterprise" edition="" />
        <vers num="enterprise" edition=":64-bit" />
        <vers num="enterprise_64-bit" />
        <vers num="r2" edition="" />
        <vers num="r2" edition=":64-bit" />
        <vers num="r2" edition=":datacenter_64-bit" />
        <vers num="standard" edition="" />
        <vers num="standard" edition=":64-bit" />
        <vers num="web" />
      </prod>
      <prod vendor="microsoft" name="windows_98">
        <vers num="" edition="gold" />
      </prod>
      <prod vendor="microsoft" name="windows_98se">
        <vers num="" />
      </prod>
      <prod vendor="microsoft" name="windows_me">
        <vers num="" />
      </prod>
      <prod vendor="microsoft" name="windows_xp">
        <vers num="" edition=":media_center" />
        <vers num="" edition=":home" />
        <vers num="" edition=":64-bit" />
        <vers num="" edition="gold" />
        <vers num="" edition="gold:professional" />
        <vers num="" edition="sp1" />
        <vers num="" edition="sp1:64-bit" />
        <vers num="" edition="sp1:home" />
        <vers num="" edition="sp1:media_center" />
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:home" />
        <vers num="" edition="sp2:media_center" />
        <vers num="" edition="sp2:tablet_pc" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-1320" published="2004-12-15" name="CVE-2004-1320" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Asante FM2008 running firmware 1.06 is shipped with a default username and password, which could allow remote attackers to gain unauthorized access.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <design />
      <config />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/18521" source="XF">asante-fm2008-default-account(18521)</ref>
      <ref url="http://www.securityfocus.com/bid/11947" source="BID" adv="1">11947</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110312733624864&amp;w=2" source="BUGTRAQ" adv="1">20041215 Asante FM2008 10/100 Ethernet switch backdoor login</ref>
    </refs>
    <vuln_soft>
      <prod vendor="asante" name="fm2008_managed_ethernet_switch">
        <vers num="1.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-1321" published="2004-12-15" name="CVE-2004-1321" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">The configuration backup in Asante FM2008 running firmware 1.06 stores the username and password in cleartext, which could allow remote attackers to gain unauthorized access.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110312733624864&amp;w=2" source="BUGTRAQ" adv="1">20041215 Asante FM2008 10/100 Ethernet switch backdoor login</ref>
    </refs>
    <vuln_soft>
      <prod vendor="asante" name="fm2008_managed_ethernet_switch">
        <vers num="1.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-1322" published="2004-12-15" name="CVE-2004-1322" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Cisco Unity 2.x, 3.x, and 4.x, when integrated with Microsoft Exchange, has several hard coded usernames and passwords, which allows remote attackers to gain unauthorized access and change configuration settings or read outgoing or incoming e-mail messages.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <config />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/18489" source="XF" patch="1" adv="1">cisco-unity-exchange-default-accounts(18489)</ref>
      <ref url="http://www.securityfocus.com/bid/11954" source="BID" patch="1" adv="1">11954</ref>
      <ref url="http://www.cisco.com/warp/public/707/cisco-sa-20041215-unity.shtml" source="CISCO" patch="1" adv="1">20041215 Cisco Unity Integrated with Exchange Has Default Passwords</ref>
      <ref url="http://www.ciac.org/ciac/bulletins/p-060.shtml" source="CIAC" patch="1" adv="1">P-060</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="unity_server">
        <vers num="2.0" />
        <vers num="2.1" />
        <vers num="2.2" />
        <vers num="2.3" />
        <vers num="2.4" />
        <vers num="2.46" />
        <vers num="3.0" />
        <vers num="3.1" />
        <vers num="3.2" />
        <vers num="3.3" />
        <vers num="4.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2004-1323" published="2004-12-16" name="CVE-2004-1323" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">Multiple syscalls in the compat subsystem for NetBSD before 2.0 allow local users to cause a denial of service (kernel crash) via a large signal number to (1) xxx_sys_kill, (2) xxx_sys_sigaction, and possibly other translation functions.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/18564" source="XF" patch="1" adv="1">netbsd-compat-gain-privileges(18564)</ref>
      <ref url="http://secunia.com/advisories/13501/" source="SECUNIA" patch="1" adv="1">13501</ref>
      <ref url="http://gleg.net/advisory_netbsd2.shtml" source="MISC" patch="1" adv="1">http://gleg.net/advisory_netbsd2.shtml</ref>
    </refs>
    <vuln_soft>
      <prod vendor="netbsd" name="netbsd">
        <vers num="1.5" />
        <vers num="1.5.1" />
        <vers num="1.5.2" />
        <vers num="1.5.3" />
        <vers num="1.6" />
        <vers num="1.6.1" />
        <vers num="1.6.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2004-1324" published="2004-12-18" name="CVE-2004-1324" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:P/A:N)" CVSS_score="2.6" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="4.9" CVSS_base_score="2.6">
    <desc>
      <descript source="cve">The Microsoft Windows Media Player 9.0 ActiveX control may allow remote attackers to execute arbitrary web script in the Local computer zone via the (1) artist or (2) song fields of a music file, if the file is processed using Internet Explorer.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/18576" source="XF" patch="1" adv="1">mediaplayer-mp3-code-execution(18576)</ref>
      <ref url="http://www.securityfocus.com/bid/12031" source="BID" patch="1" adv="1">12031</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110352518211306&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20041218 MS Windows Media Player 9 Vulns (2)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_media_player">
        <vers num="9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1325" published="2004-12-18" name="CVE-2004-1325" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The getItemInfoByAtom function in the ActiveX control for Microsoft Windows Media Player 9.0 returns a 0 if the file does not exist and the size of the file if the file exists, which allows remote attackers to determine the existence of files on the local system.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/18587" source="XF" patch="1" adv="1">mediaplayer-activex-information-disclosure(18587)</ref>
      <ref url="http://www.securityfocus.com/bid/12032" source="BID" patch="1" adv="1">12032</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110352518211306&amp;w=2" source="BUGTRAQ" adv="1">20041218 MS Windows Media Player 9 Vulns (2)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_media_player">
        <vers num="9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-1326" published="2004-12-20" name="CVE-2004-1326" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Buffer overflow in dxterm in Ultrix 4.5 allows local users to execute arbitrary code via a long -setup parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/18613" source="XF" adv="1">ultrix-dxterm-bo(18613)</ref>
      <ref url="http://www.securityfocus.com/bid/12049" source="BID" adv="1">12049</ref>
      <ref url="http://www.frsirt.com/exploits/20041220.ultrix_dxterm_4.5_exploit.c.php" source="MISC" adv="1">http://www.frsirt.com/exploits/20041220.ultrix_dxterm_4.5_exploit.c.php</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110356470029424&amp;w=2" source="BUGTRAQ" adv="1">20041219 Exploit for Ultrix 4.5 dxterm</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ultrix" name="dxterm">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-1327" published="2004-12-31" name="CVE-2004-1327" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in Crystal FTP Client 2.8 allows remote malicious servers to execute arbitrary code via a response to a LIST command that contains a file name with a long extension.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/18594" source="XF">crystal-ftp-list-bo(18594)</ref>
      <ref url="http://www.securityfocus.com/bid/12038" source="BID">12038</ref>
      <ref url="http://secunia.com/advisories/13583/" source="SECUNIA">13583</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110356203624337&amp;w=2" source="BUGTRAQ">20041220 Crystal FTP Pro Client Buffer Overflow</ref>
    </refs>
    <vuln_soft>
      <prod vendor="crystal_art_software" name="crystal_ftp">
        <vers num="2.4" />
        <vers num="2.5" />
        <vers num="2.6" />
        <vers num="2.7" />
        <vers num="2.8" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-1328" published="2004-12-31" name="CVE-2004-1328" modified="2009-03-04" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Unknown vulnerability in newgrp in HP-UX B.11.00, B.11.04, and B.11.11 allows local users to gain elevated privileges.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <other />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/12029" source="BID" patch="1">12029</ref>
      <ref url="http://secunia.com/advisories/13565/" source="SECUNIA" patch="1">13565</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110355911415320&amp;w=2" source="HP" patch="1">SSRT4687</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/18577" source="XF">hp-newgrp-gain-privileges(18577)</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5622" source="OVAL">oval:org.mitre.oval:def:5622</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hp" name="hp-ux">
        <vers num="11.00" />
        <vers num="11.11" />
        <vers num="11.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-1329" published="2004-12-20" name="CVE-2004-1329" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Untrusted execution path vulnerability in the diag commands (1) lsmcode, (2) diag_exec, (3) invscout, and (4) invscoutd in AIX 5.1 through 5.3 allows local users to execute arbitrary programs by modifying the DIAGNOSTICS environment variable to point to a malicious Dctrl program.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <design />
      <exception />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/18620" source="XF" patch="1" adv="1">aix-diagnostics-gain-privileges(18620)</ref>
      <ref url="http://www.securityfocus.com/bid/12041" source="BID" patch="1" adv="1">12041</ref>
      <ref url="http://www-1.ibm.com/support/search.wss?rs=0&amp;q=IY64389&amp;apar=only" source="AIXAPAR" patch="1" adv="1">IY64389</ref>
      <ref url="http://www-1.ibm.com/support/search.wss?rs=0&amp;q=IY64277&amp;apar=only" source="AIXAPAR" patch="1" adv="1">IY64277</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110355931920123&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20041220 AIX 5.1/5.2/5.3 local root exploits</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/464481/100/0/threaded" source="BUGTRAQ">20070402 Re: AIX 4.3 lsmcode local root command execution</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/464276/100/0/threaded" source="BUGTRAQ">20070330 AIX 4.3 lsmcode local root command execution</ref>
      <ref url="http://milw0rm.com/exploits/701" source="MILW0RM">701</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="aix">
        <vers num="5.1" />
        <vers num="5.1l" />
        <vers num="5.2" />
        <vers num="5.2.2" />
        <vers num="5.2_l" />
        <vers num="5.3" />
        <vers num="5.3_l" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-1330" published="2004-12-31" name="CVE-2004-1330" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Buffer overflow in paginit in AIX 5.1 through 5.3 allows local users to execute arbitrary code via a long username.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/12043" source="BID" patch="1">12043</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/18618" source="XF">aix-paginit-username-bo(18618)</ref>
      <ref url="http://www.frsirt.com/exploits/20041220.paginit.c.php" source="MISC">http://www.frsirt.com/exploits/20041220.paginit.c.php</ref>
      <ref url="http://www-1.ibm.com/support/search.wss?rs=0&amp;q=IY64522&amp;apar=only" source="AIXAPAR" adv="1">IY64522</ref>
      <ref url="http://www-1.ibm.com/support/search.wss?rs=0&amp;q=IY64358&amp;apar=only" source="AIXAPAR" adv="1">IY64358</ref>
      <ref url="http://www-1.ibm.com/support/search.wss?rs=0&amp;q=IY64312&amp;apar=only" source="AIXAPAR" adv="1">IY64312</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110355931920123&amp;w=2" source="BUGTRAQ">20041220 AIX 5.1/5.2/5.3 local root exploits</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="aix">
        <vers num="5.2" />
        <vers num="5.2.2" />
        <vers num="5.2_l" />
        <vers num="5.3" />
        <vers num="5.3_l" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2004-1331" published="2004-11-16" name="CVE-2004-1331" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:P/A:N)" CVSS_score="2.6" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="4.9" CVSS_base_score="2.6">
    <desc>
      <descript source="cve">The execCommand method in Microsoft Internet Explorer 6.0 SP2 allows remote attackers to bypass the "File Download - Security Warning" dialog and save arbitrary files with arbitrary extensions via the SaveAs command.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/743974" source="CERT-VN" adv="1">VU#743974</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/18181" source="XF" adv="1">ie-execommand-warning-bypass(18181)</ref>
      <ref url="http://www.securityfocus.com/bid/11686" source="BID" adv="1">11686</ref>
      <ref url="http://www.frsirt.com/exploits/20041119.IESP2Unpatched.php" source="MISC" adv="1">http://www.frsirt.com/exploits/20041119.IESP2Unpatched.php</ref>
      <ref url="http://secunia.com/advisories/13203/" source="SECUNIA" adv="1">13203</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2004-11/0260.html" source="BUGTRAQ" adv="1">20041119 Microsoft Internet Explorer 6 SP2 Vulnerabilities / Full disclosure Vs. Security by Obscurity...</ref>
      <ref url="http://securityreason.com/securityalert/3220" source="SREASON">3220</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="ie">
        <vers num="6.0" edition="sp1" />
        <vers num="6.0" edition="sp2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-1332" published="2004-12-31" name="CVE-2004-1332" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Stack-based buffer overflow in the FTP daemon in HP-UX 11.11i, with the -v (debug) option enabled, allows remote attackers to execute arbitrary code via a long command request.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/647438" source="CERT-VN" patch="1" adv="1">VU#647438</ref>
      <ref url="http://www.securityfocus.com/bid/12077" source="BID" patch="1">12077</ref>
      <ref url="http://secunia.com/advisories/13608" source="SECUNIA" patch="1">13608</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110797179710695&amp;w=2" source="HP" patch="1">SSRT4883</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/18636" source="XF">hp-ftpd-bo(18636)</ref>
      <ref url="http://www.idefense.com/application/poi/display?id=175&amp;type=vulnerabilities&amp;flashstatus=false" source="IDEFENSE">20041221 Hewlett Packard HP-UX ftpd Remote Buffer Overflow Vulnerability</ref>
      <ref url="http://securitytracker.com/id?1012650" source="SECTRACK">1012650</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5701" source="OVAL">oval:org.mitre.oval:def:5701</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110797179710695&amp;w=2" source="HP">HPSBUX01118</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hp" name="hp-ux">
        <vers num="10.01" />
        <vers num="10.10" />
        <vers num="10.20" />
        <vers num="10.24" />
        <vers num="11.00" />
        <vers num="11.11" />
        <vers num="11.11i" />
        <vers num="11.22" />
        <vers num="11.23" />
        <vers num="11.4" />
      </prod>
      <prod vendor="hp" name="hp-ux_series_700">
        <vers num="10.20" />
      </prod>
      <prod vendor="hp" name="hp-ux_series_800">
        <vers num="10.20" />
      </prod>
      <prod vendor="hp" name="sis">
        <vers num="" />
      </prod>
      <prod vendor="hp" name="vvos">
        <vers num="10.24" />
        <vers num="11.04" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2004-1333" published="2004-12-15" name="CVE-2004-1333" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">Integer overflow in the vc_resize function in the Linux kernel 2.4 and 2.6 before 2.6.10 allows local users to cause a denial of service (kernel crash) via a short new screen value, which leads to a buffer overflow.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=152532" source="FEDORA" patch="1" adv="1">FLSA:152532</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/18523" source="XF" patch="1" adv="1">linux-vcresize-dos(18523)</ref>
      <ref url="http://www.ubuntulinux.org/support/documentation/usn/usn-47-1" source="UBUNTU" patch="1" adv="1">USN-47-1</ref>
      <ref url="http://www.securityfocus.com/bid/11956" source="BID" patch="1" adv="1">11956</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2005_18_kernel.html" source="SUSE" patch="1" adv="1">SUSE-SA:2005:018</ref>
      <ref url="http://www.guninski.com/where_do_you_want_billg_to_go_today_2.html" source="MISC" patch="1" adv="1">http://www.guninski.com/where_do_you_want_billg_to_go_today_2.html</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:219" source="MANDRAKE">MDKSA-2005:219</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:219" source="MANDRIVA">MDKSA-2005:219</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:218" source="MANDRAKE">MDKSA-2005:218</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1082" source="DEBIAN">DSA-1082</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1070" source="DEBIAN">DSA-1070</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1069" source="DEBIAN">DSA-1069</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1067" source="DEBIAN">DSA-1067</ref>
      <ref url="http://secunia.com/advisories/20338" source="SECUNIA">20338</ref>
      <ref url="http://secunia.com/advisories/20202" source="SECUNIA">20202</ref>
      <ref url="http://secunia.com/advisories/20163" source="SECUNIA">20163</ref>
      <ref url="http://secunia.com/advisories/20162" source="SECUNIA">20162</ref>
      <ref url="http://secunia.com/advisories/17826" source="SECUNIA">17826</ref>
    </refs>
    <vuln_soft>
      <prod vendor="linux" name="linux_kernel">
        <vers num="2.4.0" edition="test1" />
        <vers num="2.4.0" edition="test10" />
        <vers num="2.4.0" edition="test11" />
        <vers num="2.4.0" edition="test12" />
        <vers num="2.4.0" edition="test2" />
        <vers num="2.4.0" edition="test3" />
        <vers num="2.4.0" edition="test4" />
        <vers num="2.4.0" edition="test5" />
        <vers num="2.4.0" edition="test6" />
        <vers num="2.4.0" edition="test7" />
        <vers num="2.4.0" edition="test8" />
        <vers num="2.4.0" edition="test9" />
        <vers num="2.4.1" />
        <vers num="2.4.10" />
        <vers num="2.4.11" />
        <vers num="2.4.12" />
        <vers num="2.4.13" />
        <vers num="2.4.14" />
        <vers num="2.4.15" />
        <vers num="2.4.16" />
        <vers num="2.4.17" />
        <vers num="2.4.18" edition="" />
        <vers num="2.4.18" edition=":x86" />
        <vers num="2.4.18" edition="pre1" />
        <vers num="2.4.18" edition="pre2" />
        <vers num="2.4.18" edition="pre3" />
        <vers num="2.4.18" edition="pre4" />
        <vers num="2.4.18" edition="pre5" />
        <vers num="2.4.18" edition="pre6" />
        <vers num="2.4.18" edition="pre7" />
        <vers num="2.4.18" edition="pre8" />
        <vers num="2.4.19" edition="pre1" />
        <vers num="2.4.19" edition="pre2" />
        <vers num="2.4.19" edition="pre3" />
        <vers num="2.4.19" edition="pre4" />
        <vers num="2.4.19" edition="pre5" />
        <vers num="2.4.19" edition="pre6" />
        <vers num="2.4.2" />
        <vers num="2.4.20" />
        <vers num="2.4.21" edition="pre1" />
        <vers num="2.4.21" edition="pre4" />
        <vers num="2.4.21" edition="pre7" />
        <vers num="2.4.22" />
        <vers num="2.4.23" edition="pre9" />
        <vers num="2.4.23_ow2" />
        <vers num="2.4.24" />
        <vers num="2.4.24_ow1" />
        <vers num="2.4.25" />
        <vers num="2.4.26" />
        <vers num="2.4.27" edition="pre1" />
        <vers num="2.4.27" edition="pre2" />
        <vers num="2.4.27" edition="pre3" />
        <vers num="2.4.27" edition="pre4" />
        <vers num="2.4.27" edition="pre5" />
        <vers num="2.4.28" />
        <vers num="2.4.3" />
        <vers num="2.4.4" />
        <vers num="2.4.5" />
        <vers num="2.4.6" />
        <vers num="2.4.7" />
        <vers num="2.4.8" />
        <vers num="2.4.9" />
        <vers num="2.6.0" edition="test1" />
        <vers num="2.6.0" edition="test10" />
        <vers num="2.6.0" edition="test11" />
        <vers num="2.6.0" edition="test2" />
        <vers num="2.6.0" edition="test3" />
        <vers num="2.6.0" edition="test4" />
        <vers num="2.6.0" edition="test5" />
        <vers num="2.6.0" edition="test6" />
        <vers num="2.6.0" edition="test7" />
        <vers num="2.6.0" edition="test8" />
        <vers num="2.6.0" edition="test9" />
        <vers num="2.6.1" edition="rc1" />
        <vers num="2.6.1" edition="rc2" />
        <vers num="2.6.10" edition="rc2" />
        <vers num="2.6.2" />
        <vers num="2.6.3" />
        <vers num="2.6.4" />
        <vers num="2.6.5" />
        <vers num="2.6.6" edition="rc1" />
        <vers num="2.6.7" edition="rc1" />
        <vers num="2.6.8" edition="rc1" />
        <vers num="2.6.8" edition="rc2" />
        <vers num="2.6.8" edition="rc3" />
        <vers num="2.6.9" edition="2.6.20" />
        <vers num="2.6_test9_cvs" />
      </prod>
      <prod vendor="redhat" name="fedora_core">
        <vers num="core_1.0" />
        <vers num="core_2.0" />
        <vers num="core_3.0" />
      </prod>
      <prod vendor="redhat" name="linux">
        <vers num="7.3" edition="" />
        <vers num="7.3" edition=":i386" />
        <vers num="7.3" edition=":i686" />
        <vers num="9.0" edition="" />
        <vers num="9.0" edition=":i386" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2004-1334" published="2004-12-15" name="CVE-2004-1334" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">Integer overflow in the ip_options_get function in the Linux kernel before 2.6.10 allows local users to cause a denial of service (kernel crash) via a cmsg_len that contains a -1, which leads to a buffer overflow.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/18522" source="XF" patch="1" adv="1">linux-ipoptionsget-dos(18522)</ref>
      <ref url="http://www.securitytrap.com/mail/full-disclosure/2004/Dec/0323.html" source="FULLDISC" patch="1" adv="1">20041215 fun with linux kernel</ref>
      <ref url="http://www.securityfocus.com/bid/11956" source="BID" patch="1" adv="1">11956</ref>
      <ref url="http://www.guninski.com/where_do_you_want_billg_to_go_today_2.html" source="MISC" patch="1" adv="1">http://www.guninski.com/where_do_you_want_billg_to_go_today_2.html</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110383108211524&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20041215 [USN-47-1] Linux kernel vulnerabilities</ref>
    </refs>
  </entry>
  <entry type="CVE" severity="Low" seq="2004-1335" published="2004-12-15" name="CVE-2004-1335" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">Memory leak in the ip_options_get function in the Linux kernel before 2.6.10 allows local users to cause a denial of service (memory consumption) by repeatedly calling the ip_cmsg_send function.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/18524" source="XF" patch="1" adv="1">linux-ipoptionsget-memory-leak(18524)</ref>
      <ref url="http://www.securitytrap.com/mail/full-disclosure/2004/Dec/0323.html" source="FULLDISC" patch="1" adv="1">20041215 fun with linux kernel</ref>
      <ref url="http://www.securityfocus.com/bid/11956" source="BID" patch="1" adv="1">11956</ref>
      <ref url="http://www.guninski.com/where_do_you_want_billg_to_go_today_2.html" source="MISC" patch="1" adv="1">http://www.guninski.com/where_do_you_want_billg_to_go_today_2.html</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110383108211524&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20041215 [USN-47-1] Linux kernel vulnerabilities</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11085" source="OVAL">oval:org.mitre.oval:def:11085</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-017.html" source="REDHAT">RHSA-2005:017</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-016.html" source="REDHAT">RHSA-2005:016</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1082" source="DEBIAN">DSA-1082</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1070" source="DEBIAN">DSA-1070</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1069" source="DEBIAN">DSA-1069</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1067" source="DEBIAN">DSA-1067</ref>
      <ref url="http://secunia.com/advisories/20338" source="SECUNIA">20338</ref>
      <ref url="http://secunia.com/advisories/20202" source="SECUNIA">20202</ref>
      <ref url="http://secunia.com/advisories/20163" source="SECUNIA">20163</ref>
    </refs>
    <vuln_soft>
      <prod vendor="linux" name="linux_kernel">
        <vers num="2.4.0" edition="test1" />
        <vers num="2.4.0" edition="test10" />
        <vers num="2.4.0" edition="test11" />
        <vers num="2.4.0" edition="test12" />
        <vers num="2.4.0" edition="test2" />
        <vers num="2.4.0" edition="test3" />
        <vers num="2.4.0" edition="test4" />
        <vers num="2.4.0" edition="test5" />
        <vers num="2.4.0" edition="test6" />
        <vers num="2.4.0" edition="test7" />
        <vers num="2.4.0" edition="test8" />
        <vers num="2.4.0" edition="test9" />
        <vers num="2.4.1" />
        <vers num="2.4.10" />
        <vers num="2.4.11" />
        <vers num="2.4.12" />
        <vers num="2.4.13" />
        <vers num="2.4.14" />
        <vers num="2.4.15" />
        <vers num="2.4.16" />
        <vers num="2.4.17" />
        <vers num="2.4.18" edition="" />
        <vers num="2.4.18" edition=":x86" />
        <vers num="2.4.18" edition="pre1" />
        <vers num="2.4.18" edition="pre2" />
        <vers num="2.4.18" edition="pre3" />
        <vers num="2.4.18" edition="pre4" />
        <vers num="2.4.18" edition="pre5" />
        <vers num="2.4.18" edition="pre6" />
        <vers num="2.4.18" edition="pre7" />
        <vers num="2.4.18" edition="pre8" />
        <vers num="2.4.19" edition="pre1" />
        <vers num="2.4.19" edition="pre2" />
        <vers num="2.4.19" edition="pre3" />
        <vers num="2.4.19" edition="pre4" />
        <vers num="2.4.19" edition="pre5" />
        <vers num="2.4.19" edition="pre6" />
        <vers num="2.4.2" />
        <vers num="2.4.20" />
        <vers num="2.4.21" edition="pre1" />
        <vers num="2.4.21" edition="pre4" />
        <vers num="2.4.21" edition="pre7" />
        <vers num="2.4.22" />
        <vers num="2.4.23" edition="pre9" />
        <vers num="2.4.23_ow2" />
        <vers num="2.4.24" />
        <vers num="2.4.24_ow1" />
        <vers num="2.4.25" />
        <vers num="2.4.26" />
        <vers num="2.4.27" edition="pre1" />
        <vers num="2.4.27" edition="pre2" />
        <vers num="2.4.27" edition="pre3" />
        <vers num="2.4.27" edition="pre4" />
        <vers num="2.4.27" edition="pre5" />
        <vers num="2.4.28" />
        <vers num="2.4.3" />
        <vers num="2.4.4" />
        <vers num="2.4.5" />
        <vers num="2.4.6" />
        <vers num="2.4.7" />
        <vers num="2.4.8" />
        <vers num="2.4.9" />
        <vers num="2.6.0" edition="test1" />
        <vers num="2.6.0" edition="test10" />
        <vers num="2.6.0" edition="test11" />
        <vers num="2.6.0" edition="test2" />
        <vers num="2.6.0" edition="test3" />
        <vers num="2.6.0" edition="test4" />
        <vers num="2.6.0" edition="test5" />
        <vers num="2.6.0" edition="test6" />
        <vers num="2.6.0" edition="test7" />
        <vers num="2.6.0" edition="test8" />
        <vers num="2.6.0" edition="test9" />
        <vers num="2.6.1" edition="rc1" />
        <vers num="2.6.1" edition="rc2" />
        <vers num="2.6.10" edition="rc2" />
        <vers num="2.6.2" />
        <vers num="2.6.3" />
        <vers num="2.6.4" />
        <vers num="2.6.5" />
        <vers num="2.6.6" edition="rc1" />
        <vers num="2.6.7" edition="rc1" />
        <vers num="2.6.8" edition="rc1" />
        <vers num="2.6.8" edition="rc2" />
        <vers num="2.6.8" edition="rc3" />
        <vers num="2.6.9" edition="2.6.20" />
        <vers num="2.6_test9_cvs" />
      </prod>
      <prod vendor="redhat" name="fedora_core">
        <vers num="core_1.0" />
        <vers num="core_2.0" />
        <vers num="core_3.0" />
      </prod>
      <prod vendor="redhat" name="linux">
        <vers num="7.3" edition="" />
        <vers num="7.3" edition=":i386" />
        <vers num="7.3" edition=":i686" />
        <vers num="9.0" edition="" />
        <vers num="9.0" edition=":i386" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2004-1336" published="2004-12-23" name="CVE-2004-1336" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">The xdvizilla script in tetex-bin 2.0.2 creates temporary files with predictable file names, which allows local users to overwrite arbitrary files via a symlink attack.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/18708" source="XF" patch="1" adv="1">xdvizilla-symlink(18708)</ref>
      <ref url="http://www.securityfocus.com/bid/12100" source="BID" patch="1" adv="1">12100</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110383942014839&amp;w=2" source="BUGTRAQ" adv="1">20041223 [USN-51-1] teTeX auxiliary script vulnerability</ref>
      <ref url="http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=286370" source="CONFIRM" adv="1">http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=286370</ref>
    </refs>
    <vuln_soft>
      <prod vendor="debian" name="tetex-bin">
        <vers num="2.0.2" />
      </prod>
      <prod vendor="gentoo" name="linux">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-1337" published="2004-12-23" name="CVE-2004-1337" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">The POSIX Capability Linux Security Module (LSM) for Linux kernel 2.6 does not properly handle the credentials of a process that is launched before the module is loaded, which allows local users to gain privileges.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/18673" source="XF" patch="1" adv="1">linux-security-module-gain-privileges(18673)</ref>
      <ref url="http://www.securityfocus.com/bid/12093" source="BID" patch="1" adv="1">12093</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110384535113035&amp;w=2" source="BUGTRAQ" adv="1">20041223 Linux 2.6  Kernel Capability LSM Module Local Privilege Elevation</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/index.php?id=a&amp;anuncio=000930" source="CONECTIVA" adv="1">CLA-2005:930</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gnu" name="realtime_linux_security_module">
        <vers num="0.8.7" />
      </prod>
      <prod vendor="conectiva" name="linux">
        <vers num="10.0" />
      </prod>
      <prod vendor="ubuntu" name="ubuntu_linux">
        <vers num="4.1" edition="" />
        <vers num="4.1" edition=":ia64" />
        <vers num="4.1" edition=":ppc" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1338" published="2004-12-23" name="CVE-2004-1338" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:P/A:P)" CVSS_score="6.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.0" CVSS_base_score="6.5">
    <desc>
      <descript source="cve">The triggers in Oracle 9i and 10g allow local users to gain privileges by using a sequence of partially privileged actions: using CCBKAPPLROWTRIG or EXEC_CBK_FN_DML to add arbitrary functions to the SDO_CMT_DBK_FN_TABLE and SDO_CMT_CBK_DML_TABLE, then performing a DELETE on the SDO_TXN_IDX_INSERTS table, which causes the SDO_CMT_CBK_TRIG trigger to execute the user-supplied functions.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/18655" source="XF" patch="1" adv="1">oracle-triggers-gain-privileges(18655)</ref>
      <ref url="http://www.ngssoftware.com/advisories/oracle23122004I.txt" source="MISC" patch="1" adv="1">http://www.ngssoftware.com/advisories/oracle23122004I.txt</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110382230614420&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20041223 Oracle Trigger Abuse (#NISR2122004I)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="database_server">
        <vers num="10.2.1" edition="r2" />
      </prod>
      <prod vendor="oracle" name="oracle9i">
        <vers num="9.0" />
        <vers num="9.0.1" />
        <vers num="9.0.1.2" />
        <vers num="9.0.1.3" />
        <vers num="9.0.1.4" />
        <vers num="9.0.2" />
        <vers num="9.0.2.0.0" />
        <vers num="9.0.2.0.1" />
        <vers num="9.0.2.1" />
        <vers num="9.0.2.2" />
        <vers num="9.0.2.3" />
        <vers num="9.2.0.1" />
        <vers num="9.2.0.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1339" published="2004-12-23" name="CVE-2004-1339" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:P/A:P)" CVSS_score="6.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.0" CVSS_base_score="6.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in the (1) MDSYS.SDO_GEOM_TRIG_INS1 and (2) MDSYS.SDO_LRS_TRIG_INS default triggers in Oracle 9i and 10g allows remote attackers to execute arbitrary SQL commands via the new.table_name or new.column_name parameters.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/18655" source="XF" patch="1" adv="1">oracle-triggers-gain-privileges(18655)</ref>
      <ref url="http://www.ngssoftware.com/advisories/oracle23122004I.txt" source="MISC" patch="1" adv="1">http://www.ngssoftware.com/advisories/oracle23122004I.txt</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110382230614420&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20041223 Oracle Trigger Abuse (#NISR2122004I)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="database_server">
        <vers num="10.2.1" edition="r2" />
      </prod>
      <prod vendor="oracle" name="oracle9i">
        <vers num="9.0" />
        <vers num="9.0.1" />
        <vers num="9.0.1.2" />
        <vers num="9.0.1.3" />
        <vers num="9.0.1.4" />
        <vers num="9.0.2" />
        <vers num="9.0.2.0.0" />
        <vers num="9.0.2.0.1" />
        <vers num="9.0.2.1" />
        <vers num="9.0.2.2" />
        <vers num="9.0.2.3" />
        <vers num="9.2.0.1" />
        <vers num="9.2.0.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2004-1340" published="2005-01-26" name="CVE-2004-1340" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">Debian GNU/Linux 3.0 installs the libpam-radius-auth package with the pam_radius_auth.conf set to be world-readable, which allows local users to obtain sensitive information.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <config />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/19087" source="XF" patch="1" adv="1">libpamradiusauth-insecure-permission(19087)</ref>
      <ref url="http://www.debian.org/security/2005/dsa-659" source="DEBIAN" patch="1" adv="1">DSA-659</ref>
      <ref url="http://securitytracker.com/id?1013030" source="SECTRACK">1013030</ref>
      <ref url="http://secunia.com/advisories/14046" source="SECUNIA">14046</ref>
    </refs>
    <vuln_soft>
      <prod vendor="debian" name="debian_linux">
        <vers num="3.0" edition="" />
        <vers num="3.0" edition=":hppa" />
        <vers num="3.0" edition=":mipsel" />
        <vers num="3.0" edition=":mips" />
        <vers num="3.0" edition=":ia-32" />
        <vers num="3.0" edition=":m68k" />
        <vers num="3.0" edition=":sparc" />
        <vers num="3.0" edition=":s-390" />
        <vers num="3.0" edition=":alpha" />
        <vers num="3.0" edition=":arm" />
        <vers num="3.0" edition=":ia-64" />
        <vers num="3.0" edition=":ppc" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1341" published="2005-04-19" name="CVE-2004-1341" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in info2www before 1.2.2.9 allows remote attackers to inject arbitrary web script or HTML via the arguments to info2www.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/20179" source="XF" patch="1" adv="1">info2www-url-xss(20179)</ref>
      <ref url="http://www.debian.org/security/2005/dsa-711" source="DEBIAN" patch="1" adv="1">DSA-711</ref>
    </refs>
    <vuln_soft>
      <prod vendor="roar_smith" name="info2www">
        <vers num="1.2.2_.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-1342" published="2005-04-27" name="CVE-2004-1342" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">CVS 1.12 and earlier on Debian GNU/Linux, when using the repouid patch, allows remote attackers to bypass authentication via the pserver access method.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.debian.org/security/2005/dsa-715" source="DEBIAN" patch="1" adv="1">DSA-715</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cvs" name="cvs">
        <vers num="1.10" />
        <vers num="1.10.6" />
        <vers num="1.10.7" />
        <vers num="1.10.8" />
        <vers num="1.11" />
        <vers num="1.11.1" />
        <vers num="1.11.10" />
        <vers num="1.11.11" />
        <vers num="1.11.14" />
        <vers num="1.11.15" />
        <vers num="1.11.16" />
        <vers num="1.11.1_p1" />
        <vers num="1.11.2" />
        <vers num="1.11.3" />
        <vers num="1.11.4" />
        <vers num="1.11.5" />
        <vers num="1.11.6" />
        <vers num="1.12" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1343" published="2004-12-31" name="CVE-2004-1343" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">CVS 1.12 and earlier on Debian GNU/Linux does not properly handle when a mapping for the current repository does not exist in the cvs-repouids file, which allows remote attackers to cause a denial of service (server crash).</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.debian.org/security/2005/dsa-715" source="DEBIAN" patch="1" adv="1">DSA-715</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cvs" name="cvs">
        <vers num="1.10" />
        <vers num="1.10.6" />
        <vers num="1.10.7" />
        <vers num="1.10.8" />
        <vers num="1.11" />
        <vers num="1.11.1" />
        <vers num="1.11.10" />
        <vers num="1.11.11" />
        <vers num="1.11.14" />
        <vers num="1.11.15" />
        <vers num="1.11.16" />
        <vers num="1.11.1_p1" />
        <vers num="1.11.2" />
        <vers num="1.11.3" />
        <vers num="1.11.4" />
        <vers num="1.11.5" />
        <vers num="1.11.6" />
        <vers num="1.12" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-1345" published="2004-06-21" name="CVE-2004-1345" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Unknown vulnerability in Sun StorEdge Enterprise Storage Manager (ESM) 2.1 for Solaris 8 and Solaris 9 allows local users with the "ESMUser" role to gain root access.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <other />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/976470" source="CERT-VN" patch="1" adv="1">VU#976470</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/16463" source="XF" patch="1" adv="1">esm-esmuser-gain-privileges(16463)</ref>
      <ref url="http://www.securityfocus.com/bid/10580" source="BID" patch="1" adv="1">10580</ref>
      <ref url="http://www.ciac.org/ciac/bulletins/o-166.shtml" source="CIAC" patch="1" adv="1">O-166</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-57581-1&amp;searchclause=security" source="SUNALERT" patch="1" adv="1">57581</ref>
      <ref url="http://secunia.com/advisories/11935/" source="SECUNIA" patch="1" adv="1">11935</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1707" source="OVAL">oval:org.mitre.oval:def:1707</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="enterprise_storage_manager">
        <vers num="2.1" />
      </prod>
      <prod vendor="sun" name="storedge_3310_scsi_array">
        <vers num="" />
      </prod>
      <prod vendor="sun" name="storedge_3510_fc_array">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2004-1346" published="2004-06-19" name="CVE-2004-1346" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">The Sun Solaris Volume Manager (SVM) on Solaris 9 allows local users to cause a denial of service (kernel panic) via a malformed probe request to the SVM.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
      <exception />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/390742" source="CERT-VN" patch="1" adv="1">VU#390742</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/16729" source="XF" patch="1" adv="1">solaris-svm-dos(16729)</ref>
      <ref url="http://www.securityfocus.com/bid/10747" source="BID" patch="1" adv="1">10747</ref>
      <ref url="http://www.auscert.org.au/render.html?it=4253" source="AUSCERT" patch="1" adv="1">ESB-2004.0463</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-57598-1&amp;searchclause=security" source="SUNALERT" patch="1" adv="1">57598</ref>
      <ref url="http://secunia.com/advisories/12104/" source="SECUNIA" patch="1" adv="1">12104</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:3465" source="OVAL" sig="1">oval:org.mitre.oval:def:3465</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="solaris">
        <vers num="9.0" edition="" />
        <vers num="9.0" edition=":sparc" />
        <vers num="9.0" edition=":x86" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1347" published="2004-08-10" name="CVE-2004-1347" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">X Display Manager (XDM) on Solaris 8 allows remote attackers to cause a denial of service (XDM crash) via an invalid X Display Manager Control Protocol (XDMCP) request.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/139504" source="CERT-VN" patch="1" adv="1">VU#139504</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/16940" source="XF" patch="1" adv="1">xdm-xdmcp-dos(16940)</ref>
      <ref url="http://www.securityfocus.com/bid/10911" source="BID" patch="1" adv="1">10911</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-57619-1&amp;searchclause=security" source="SUNALERT" patch="1" adv="1">57619</ref>
      <ref url="http://secunia.com/advisories/12257/" source="SECUNIA" patch="1" adv="1">12257</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-101549-1" source="SUNALERT">101549</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:100113" source="OVAL" sig="1">oval:org.mitre.oval:def:100113</ref>
    </refs>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1348" published="2004-09-06" name="CVE-2004-1348" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Unknown vulnerability in in.named on Solaris 8 allows remote attackers to cause a denial of service (process crash).</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/17269" source="XF" patch="1" adv="1">solaris-innamed-dynamic-dos(17269)</ref>
      <ref url="http://www.securityfocus.com/bid/11118" source="BID" patch="1" adv="1">11118</ref>
      <ref url="http://www.auscert.org.au/render.html?it=4369" source="AUSCERT" patch="1" adv="1">ESB-2004.0565</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-57614-1" source="SUNALERT" patch="1" adv="1">57614</ref>
      <ref url="http://secunia.com/advisories/12470/" source="SECUNIA" patch="1" adv="1">12470</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:3960" source="OVAL" sig="1">oval:org.mitre.oval:def:3960</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="solaris">
        <vers num="8.0" edition="" />
        <vers num="8.0" edition=":x86" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2004-1349" published="2004-10-04" name="CVE-2004-1349" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">gzip before 1.3 in Solaris 8, when called with the -f or -force flags, will change the permissions of files that are hard linked to the target files, which allows local users to view or modify these files.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/635998" source="CERT-VN" patch="1" adv="1">VU#635998</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/17577" source="XF" patch="1" adv="1">solaris-gzip-modify-privileges(17577)</ref>
      <ref url="http://www.securityfocus.com/bid/11318" source="BID" patch="1" adv="1">11318</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-57600-1&amp;searchclause=security" source="SUNALERT" patch="1" adv="1">57600</ref>
      <ref url="http://secunia.com/advisories/12744" source="SECUNIA" patch="1" adv="1">12744</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1654" source="OVAL" sig="1">oval:org.mitre.oval:def:1654</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="solaris">
        <vers num="8.0" edition="" />
        <vers num="8.0" edition=":x86" />
        <vers num="9.0" edition="" />
        <vers num="9.0" edition=":sparc" />
        <vers num="9.0" edition=":x86" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-1350" published="2004-10-30" name="CVE-2004-1350" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple buffer overflows in Sun Java System Web Proxy Server (formerly Sun ONE Proxy Server) 3.6 through 3.6 SP4 allow remote attackers to execute arbitrary code via unknown vectors, possibly CONNECT requests.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/964401" source="CERT-VN">VU#964401</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/17920" source="XF" patch="1" adv="1">sun-web-proxy-bo(17920)</ref>
      <ref url="http://www.securityfocus.com/bid/11566" source="BID" patch="1" adv="1">11566</ref>
      <ref url="http://www.osvdb.org/displayvuln.php?osvdb_id=11304" source="OSVDB" patch="1" adv="1">11304</ref>
      <ref url="http://securitytracker.com/id?1012005" source="SECTRACK" patch="1" adv="1">1012005</ref>
      <ref url="http://secunia.com/advisories/13036/" source="SECUNIA" patch="1" adv="1">13036</ref>
      <ref url="http://www.pentest.co.uk/documents/ptl-2004-06.html" source="MISC">http://www.pentest.co.uk/documents/ptl-2004-06.html</ref>
      <ref url="http://www.ciac.org/ciac/bulletins/p-027.shtml" source="CIAC">P-027</ref>
      <ref url="http://www.auscert.org.au/render.html?it=4516" source="AUSCERT">ESB-2004.0691</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-57606-1&amp;searchclause=security" source="SUNALERT">57606</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="java_system_web_proxy_server">
        <vers num="3.6" edition="sp1" />
        <vers num="3.6" edition="sp2" />
        <vers num="3.6" edition="sp3" />
        <vers num="3.6" edition="sp4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-1351" published="2004-12-07" name="CVE-2004-1351" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Unknown vulnerability in the rwho daemon (in.rwhod) for Solaris 7 through 9 allows remote attackers to execute arbitrary code.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/18385" source="XF" patch="1" adv="1">solaris-inrwhod-command-execution(18385)</ref>
      <ref url="http://www.securityfocus.com/bid/11840" source="BID" patch="1" adv="1">11840</ref>
      <ref url="http://www.ciac.org/ciac/bulletins/p-050.shtml" source="CIAC" patch="1" adv="1">P-050</ref>
      <ref url="http://www.auscert.org.au/render.html?it=4597" source="AUSCERT" patch="1" adv="1">ESB-2004.0759</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-57659-1&amp;searchclause=%22category:security%22%20%22availability,%20security%22" source="SUNALERT" patch="1" adv="1">57659</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:592" source="OVAL" sig="1">oval:org.mitre.oval:def:592</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="solaris">
        <vers num="7.0" edition="" />
        <vers num="7.0" edition=":x86" />
        <vers num="8.0" edition="" />
        <vers num="8.0" edition=":x86" />
        <vers num="9.0" edition="" />
        <vers num="9.0" edition=":sparc" />
        <vers num="9.0" edition=":x86" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-1352" published="2004-12-01" name="CVE-2004-1352" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Buffer overflow in the ping daemon of Sun Solaris 7 through 9 may allow local users to execute arbitrary code.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/11782" source="BID" patch="1" adv="1">11782</ref>
      <ref url="http://www.osvdb.org/displayvuln.php?osvdb_id=12168" source="OSVDB" patch="1" adv="1">12168</ref>
      <ref url="http://securitytracker.com/id?1012368" source="SECTRACK" patch="1" adv="1">1012368</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/18310" source="XF">solaris-ping-bo(18310)</ref>
      <ref url="http://www.ciac.org/ciac/bulletins/p-045.shtml" source="CIAC">P-045</ref>
      <ref url="http://www.auscert.org.au/render.html?it=4586" source="AUSCERT">ESB-2004.0749</ref>
      <ref url="http://secunia.com/advisories/13340" source="SECUNIA">13340</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-57675-1&amp;searchclause=%22category:security%22%20%22availability,%20security%22" source="SUNALERT">57675</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:3400" source="OVAL" sig="1">oval:org.mitre.oval:def:3400</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="solaris">
        <vers num="7.0" edition="" />
        <vers num="7.0" edition=":x86" />
        <vers num="8.0" edition="" />
        <vers num="8.0" edition=":x86" />
        <vers num="9.0" edition="" />
        <vers num="9.0" edition=":sparc" />
        <vers num="9.0" edition=":x86" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-1353" published="2004-10-19" name="CVE-2004-1353" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Unknown vulnerability in LDAP on Sun Solaris 8 and 9, when using Role Based Access Control (RBAC), allows local users to execute certain commands with additional privileges.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/17757" source="XF" patch="1" adv="1">solaris-ldap-rbac-gain-priv(17757)</ref>
      <ref url="http://www.securityfocus.com/bid/11459" source="BID" patch="1" adv="1">11459</ref>
      <ref url="http://www.ciac.org/ciac/bulletins/p-017.shtml" source="CIAC" patch="1" adv="1">P-017</ref>
      <ref url="http://www.auscert.org.au/render.html?it=4482" source="AUSCERT" patch="1" adv="1">ESB-2004.0661</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-57657-1&amp;searchclause=%22category:security%22%20%22availability,%20security%22" source="SUNALERT" patch="1" adv="1">57657</ref>
      <ref url="http://securitytracker.com/id?1011789" source="SECTRACK" patch="1" adv="1">1011789</ref>
      <ref url="http://secunia.com/advisories/12873/" source="SECUNIA" patch="1" adv="1">12873</ref>
      <ref url="http://www.osvdb.org/displayvuln.php?osvdb_id=10939" source="OSVDB" adv="1">10939</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:4834" source="OVAL" sig="1">oval:org.mitre.oval:def:4834</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="solaris">
        <vers num="8.0" edition="" />
        <vers num="8.0" edition=":x86" />
        <vers num="9.0" edition="" />
        <vers num="9.0" edition=":sparc" />
        <vers num="9.0" edition=":x86" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1354" published="2004-05-14" name="CVE-2004-1354" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The Solaris Management Console (SMC) in Sun Solaris 8 and 9 generates different 404 error messages when a file does not exist versus when a file exists but is otherwise inacessible, which could allow remote attackers to obtain sensitive information in conjunction with a directory traversal (..) attack.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/16146" source="XF" patch="1">smc-dotdot-directory-traversal(16146)</ref>
      <ref url="http://www.securityfocus.com/bid/10349" source="BID" patch="1">10349</ref>
      <ref url="http://www.osvdb.org/displayvuln.php?osvdb_id=6119" source="OSVDB" patch="1">6119</ref>
      <ref url="http://www.auscert.org.au/render.html?it=4105" source="AUSCERT" patch="1" adv="1">ESB-2004.0347</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-57559-1&amp;searchclause=%22category:security%22%20%20111313-02" source="SUNALERT" patch="1" adv="1">57559</ref>
      <ref url="http://spoofed.org/files/text/solaris-smc-advisory.txt" source="MISC" patch="1">http://spoofed.org/files/text/solaris-smc-advisory.txt</ref>
      <ref url="http://secunia.com/advisories/11616/" source="SECUNIA" patch="1" adv="1">11616</ref>
      <ref url="http://www.securityfocus.com/bid/8873" source="BID">8873</ref>
      <ref url="http://www.derkeiler.com/Mailing-Lists/securityfocus/focus-sun/2003-10/0032.html" source="MLIST">[focus-sun] 20031022 Information disclosure with SMC webserver on Solaris 9</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1482" source="OVAL" sig="1">oval:org.mitre.oval:def:1482</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="solaris">
        <vers num="8.0" edition="" />
        <vers num="8.0" edition=":x86" />
        <vers num="9.0" edition="" />
        <vers num="9.0" edition=":sparc" />
        <vers num="9.0" edition=":x86" />
        <vers num="9.0" edition="x86_update_2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2004-1355" published="2004-04-26" name="CVE-2004-1355" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">Unknown vulnerability in the TCP/IP stack for Sun Solaris 8 and 9 allows local users to cause a denial of service (system panic) via unknown vectors.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <other />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/15955" source="XF" patch="1">solaris-tcp-ip-dos(15955)</ref>
      <ref url="http://www.securityfocus.com/bid/10216" source="BID" patch="1">10216</ref>
      <ref url="http://www.osvdb.org/displayvuln.php?osvdb_id=5665" source="OSVDB" patch="1">5665</ref>
      <ref url="http://www.auscert.org.au/render.html?it=4057" source="AUSCERT" patch="1" adv="1">ESB-2004.0308</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-57545-1&amp;searchclause=%22category:security%22%20%20111313-02" source="SUNALERT" patch="1" adv="1">57545</ref>
      <ref url="http://secunia.com/advisories/11483/" source="SECUNIA" patch="1" adv="1">11483</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2972" source="OVAL" sig="1">oval:org.mitre.oval:def:2972</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="solaris">
        <vers num="9.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2004-1356" published="2004-04-23" name="CVE-2004-1356" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">Unknown vulnerability in the sendfilev function in Sun Solaris 8 and 9 allows local users to cause a denial of service (system panic) via unknown vectors.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <other />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/15946" source="XF" patch="1">solaris-sendfilev-dos(15946)</ref>
      <ref url="http://www.securityfocus.com/bid/10202" source="BID" patch="1">10202</ref>
      <ref url="http://www.osvdb.org/displayvuln.php?osvdb_id=5619" source="OSVDB" patch="1">5619</ref>
      <ref url="http://www.auscert.org.au/render.html?it=4056" source="AUSCERT" patch="1" adv="1">ESB-2004.0307</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-57470-1&amp;searchclause=%22category:security%22%20%20108528-27" source="SUNALERT" patch="1" adv="1">57470</ref>
      <ref url="http://secunia.com/advisories/11457/" source="SECUNIA" patch="1" adv="1">11457</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1684" source="OVAL" sig="1">oval:org.mitre.oval:def:1684</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="solaris">
        <vers num="8.0" edition="" />
        <vers num="8.0" edition=":x86" />
        <vers num="9.0" edition="" />
        <vers num="9.0" edition=":sparc" />
        <vers num="9.0" edition=":x86" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1357" published="2004-04-07" name="CVE-2004-1357" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The Secure Shell (SSH) Daemon (SSHD) in Sun Solaris 9 does not properly log IP addresses when SSHD is configured with the ListenAddress as 0.0.0.0, which makes it easier for remote attackers to hide the source of their activities.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <config />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/737548" source="CERT-VN" patch="1" adv="1">VU#737548</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15784" source="XF" patch="1">solaris-sshd-log-bypass(15784)</ref>
      <ref url="http://www.securityfocus.com/bid/10080" source="BID" patch="1">10080</ref>
      <ref url="http://www.auscert.org.au/render.html?it=4003" source="AUSCERT" patch="1" adv="1">ESB-2004.0263</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-57538-1" source="SUNALERT" patch="1" adv="1">57538</ref>
      <ref url="http://secunia.com/advisories/11316/" source="SECUNIA" patch="1" adv="1">11316</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:3505" source="OVAL" sig="1">oval:org.mitre.oval:def:3505</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="solaris">
        <vers num="9.0" edition="" />
        <vers num="9.0" edition=":sparc" />
        <vers num="9.0" edition=":x86" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1358" published="2004-03-12" name="CVE-2004-1358" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The patches (1) 114332-08 and (2) 114929-06 for Sun Solaris 9 disable the auditing functionality of the Basic Security Module (BSM), which allows attackers to avoid having their activity logged.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/14918" source="XF" patch="1">solaris-patches-disable-bsm(14918)</ref>
      <ref url="http://www.securityfocus.com/bid/9852" source="BID" patch="1">9852</ref>
      <ref url="http://www.ciac.org/ciac/bulletins/o-099.shtml" source="CIAC" patch="1" adv="1">O-099</ref>
      <ref url="http://www.auscert.org.au/render.html?it=3788" source="AUSCERT" patch="1" adv="1">ESB-2004.0069</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-57478-1&amp;searchclause=%22category:security%22%20%20114332-08" source="SUNALERT" patch="1" adv="1">57478</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:3567" source="OVAL" sig="1">oval:org.mitre.oval:def:3567</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="solaris">
        <vers num="9.0" edition="" />
        <vers num="9.0" edition=":sparc" />
        <vers num="9.0" edition=":x86" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1359" published="2004-03-04" name="CVE-2004-1359" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Multiple buffer overflows in uucp for Sun Solaris 2.6, 7, 8, and 9 allow local users to execute arbitrary code as the uucp user.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/15425" source="XF" patch="1">solaris-uucp-multiple-bo(15425)</ref>
      <ref url="http://www.auscert.org.au/render.html?it=3935" source="AUSCERT" patch="1" adv="1">ESB-2004.0201</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-57508-1" source="SUNALERT" patch="1" adv="1">57508</ref>
      <ref url="http://www.securityfocus.com/bid/9837" source="BID">9837</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1127" source="OVAL" sig="1">oval:org.mitre.oval:def:1127</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="solaris">
        <vers num="2.6" edition="" />
        <vers num="2.6" edition=":x86" />
        <vers num="7.0" edition="" />
        <vers num="7.0" edition=":x86" />
        <vers num="8.0" edition="" />
        <vers num="8.0" edition=":x86" />
        <vers num="9.0" edition="" />
        <vers num="9.0" edition=":sparc" />
        <vers num="9.0" edition=":x86" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2004-1360" published="2004-02-27" name="CVE-2004-1360" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">Unknown vulnerability in conv_fix in Sun Solaris 7 through 9, when invoked by conv_lpd, allows local users to overwrite arbitrary files.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/412566" source="CERT-VN" patch="1" adv="1">VU#412566</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15331" source="XF" patch="1">solaris-covfix-gain-privileges(15331)</ref>
      <ref url="http://www.ciac.org/ciac/bulletins/o-089.shtml" source="CIAC" patch="1" adv="1">O-089</ref>
      <ref url="http://www.auscert.org.au/render.html?it=3902" source="AUSCERT" patch="1" adv="1">ESB-2004.0169</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-57509-1" source="SUNALERT" patch="1" adv="1">57509</ref>
      <ref url="http://secunia.com/advisories/10991" source="SECUNIA" patch="1" adv="1">10991</ref>
      <ref url="http://www.osvdb.org/displayvuln.php?osvdb_id=4071" source="OSVDB">4071</ref>
      <ref url="http://www.securityfocus.com/bid/9759" source="BID">9759</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1732" source="OVAL" sig="1">oval:org.mitre.oval:def:1732</ref>
    </refs>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1361" published="2004-12-23" name="CVE-2004-1361" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Integer underflow in winhlp32.exe in Windows NT, Windows 2000 through SP4, Windows XP through SP2, and Windows 2003 allows remote attackers to execute arbitrary code via a malformed .hlp file, which leads to a heap-based buffer overflow.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/18678" source="XF">win-winhlp32-bo(18678)</ref>
      <ref url="http://www.xfocus.net/flashsky/icoExp/" source="MISC">http://www.xfocus.net/flashsky/icoExp/</ref>
      <ref url="http://www.securityfocus.com/bid/12091" source="BID">12091</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110383690219440&amp;w=2" source="BUGTRAQ" adv="1">20041223 Microsoft Windows winhlp32.exe Heap Overflow Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_2000">
        <vers num="" edition=":professional" />
        <vers num="" edition=":server" />
        <vers num="" edition=":advanced_server" />
        <vers num="" edition=":datacenter_server" />
        <vers num="" edition="sp1" />
        <vers num="" edition="sp1:datacenter_server" />
        <vers num="" edition="sp1:professional" />
        <vers num="" edition="sp1:server" />
        <vers num="" edition="sp1:advanced_server" />
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:advanced_server" />
        <vers num="" edition="sp2:professional" />
        <vers num="" edition="sp2:datacenter_server" />
        <vers num="" edition="sp2:server" />
        <vers num="" edition="sp3" />
        <vers num="" edition="sp3:datacenter_server" />
        <vers num="" edition="sp3:server" />
        <vers num="" edition="sp3:professional" />
        <vers num="" edition="sp3:advanced_server" />
        <vers num="" edition="sp4" />
        <vers num="" edition="sp4:datacenter_server" />
        <vers num="" edition="sp4:server" />
        <vers num="" edition="sp4:professional" />
        <vers num="" edition="sp4:advanced_server" />
      </prod>
      <prod vendor="microsoft" name="windows_2003_server">
        <vers num="enterprise" edition="" />
        <vers num="enterprise" edition=":64-bit" />
        <vers num="enterprise" edition="sp1_beta_1" />
        <vers num="enterprise_64-bit" />
        <vers num="r2" edition="" />
        <vers num="r2" edition=":datacenter_64-bit" />
        <vers num="r2" edition=":64-bit" />
        <vers num="r2" edition="sp1_beta_1" />
        <vers num="standard" edition="" />
        <vers num="standard" edition=":64-bit" />
        <vers num="standard" edition="sp1_beta_1" />
        <vers num="web" edition="sp1_beta_1" />
      </prod>
      <prod vendor="microsoft" name="windows_nt">
        <vers num="4.0" edition="" />
        <vers num="4.0" edition=":server" />
        <vers num="4.0" edition=":enterprise_server" />
        <vers num="4.0" edition=":terminal_server" />
        <vers num="4.0" edition=":workstation" />
        <vers num="4.0" edition="sp1" />
        <vers num="4.0" edition="sp1:server" />
        <vers num="4.0" edition="sp1:workstation" />
        <vers num="4.0" edition="sp1:terminal_server" />
        <vers num="4.0" edition="sp1:enterprise_server" />
        <vers num="4.0" edition="sp2" />
        <vers num="4.0" edition="sp2:enterprise_server" />
        <vers num="4.0" edition="sp2:server" />
        <vers num="4.0" edition="sp2:workstation" />
        <vers num="4.0" edition="sp2:terminal_server" />
        <vers num="4.0" edition="sp3" />
        <vers num="4.0" edition="sp3:workstation" />
        <vers num="4.0" edition="sp3:server" />
        <vers num="4.0" edition="sp3:terminal_server" />
        <vers num="4.0" edition="sp3:enterprise_server" />
        <vers num="4.0" edition="sp4" />
        <vers num="4.0" edition="sp4:workstation" />
        <vers num="4.0" edition="sp4:enterprise_server" />
        <vers num="4.0" edition="sp4:terminal_server" />
        <vers num="4.0" edition="sp4:server" />
        <vers num="4.0" edition="sp5" />
        <vers num="4.0" edition="sp5:workstation" />
        <vers num="4.0" edition="sp5:enterprise_server" />
        <vers num="4.0" edition="sp5:server" />
        <vers num="4.0" edition="sp5:terminal_server" />
        <vers num="4.0" edition="sp6" />
        <vers num="4.0" edition="sp6:terminal_server" />
        <vers num="4.0" edition="sp6:server" />
        <vers num="4.0" edition="sp6:enterprise_server" />
        <vers num="4.0" edition="sp6:workstation" />
        <vers num="4.0" edition="sp6a" />
        <vers num="4.0" edition="sp6a:server" />
        <vers num="4.0" edition="sp6a:enterprise_server" />
        <vers num="4.0" edition="sp6a:terminal_server" />
        <vers num="4.0" edition="sp6a:workstation" />
      </prod>
      <prod vendor="microsoft" name="windows_xp">
        <vers num="" edition=":home" />
        <vers num="" edition=":64-bit" />
        <vers num="" edition=":media_center" />
        <vers num="" edition="gold" />
        <vers num="" edition="gold:professional" />
        <vers num="" edition="sp1" />
        <vers num="" edition="sp1:home" />
        <vers num="" edition="sp1:media_center" />
        <vers num="" edition="sp1:64-bit" />
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:home" />
        <vers num="" edition="sp2:media_center" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-1362" published="2004-08-04" name="CVE-2004-1362" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">The PL/SQL module for the Oracle HTTP Server in Oracle Application Server 10g, when using the WE8ISO8859P1 character set, does not perform character conversions properly, which allows remote attackers to bypass access restrictions for certain procedures via an encoded URL with "%FF" encoded sequences that are improperly converted to "Y" characters.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <access />
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA04-245A.html" source="CERT" patch="1" adv="1">TA04-245A</ref>
      <ref url="http://www.kb.cert.org/vuls/id/435974" source="CERT-VN" adv="1">VU#435974</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/18657" source="XF" patch="1">oracle-character-conversion-gain-privileges(18657)</ref>
      <ref url="http://www.securityfocus.com/bid/10871" source="BID" patch="1">10871</ref>
      <ref url="http://www.oracle.com/technology/deploy/security/pdf/2004alert68.pdf" source="CONFIRM" patch="1" adv="1">http://www.oracle.com/technology/deploy/security/pdf/2004alert68.pdf</ref>
      <ref url="http://www.ngssoftware.com/advisories/oracle23122004G.txt" source="MISC" patch="1" adv="1">http://www.ngssoftware.com/advisories/oracle23122004G.txt</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110382306006205&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20041223 Oracle Character Conversion Bugs (#NISR2122004G)</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-101782-1" source="SUNALERT">101782</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="application_server">
        <vers num="9.0.2" />
        <vers num="9.0.2.0.0" />
        <vers num="9.0.2.0.1" />
        <vers num="9.0.2.1" />
        <vers num="9.0.2.2" />
        <vers num="9.0.2.3" />
        <vers num="9.0.3" />
        <vers num="9.0.3.1" />
        <vers num="9.0.4" />
        <vers num="9.0.4.0" />
        <vers num="9.0.4.1" />
      </prod>
      <prod vendor="oracle" name="collaboration_suite">
        <vers num="release_1" />
      </prod>
      <prod vendor="oracle" name="e-business_suite">
        <vers num="11.5.1" />
        <vers num="11.5.2" />
        <vers num="11.5.3" />
        <vers num="11.5.4" />
        <vers num="11.5.5" />
        <vers num="11.5.6" />
        <vers num="11.5.7" />
        <vers num="11.5.8" />
        <vers num="11.5.9" />
      </prod>
      <prod vendor="oracle" name="enterprise_manager">
        <vers num="9" />
        <vers num="9.0.1" />
      </prod>
      <prod vendor="oracle" name="enterprise_manager_database_control">
        <vers num="10.1.2" />
      </prod>
      <prod vendor="oracle" name="enterprise_manager_grid_control">
        <vers num="10.1.0.2" />
      </prod>
      <prod vendor="oracle" name="oracle10g">
        <vers num="enterprise_10.1.0.2" />
        <vers num="enterprise_9.0.4_.0" />
        <vers num="personal_10.1_.0.2" />
        <vers num="personal_9.0.4_.0" />
        <vers num="standard_10.1_.0.2" />
        <vers num="standard_9.0.4_.0" />
      </prod>
      <prod vendor="oracle" name="oracle8i">
        <vers num="enterprise_8.0.5_.0.0" />
        <vers num="enterprise_8.0.6_.0.0" />
        <vers num="enterprise_8.0.6_.0.1" />
        <vers num="enterprise_8.1.5_.0.0" />
        <vers num="enterprise_8.1.5_.0.2" />
        <vers num="enterprise_8.1.5_.1.0" />
        <vers num="enterprise_8.1.6_.0.0" />
        <vers num="enterprise_8.1.6_.1.0" />
        <vers num="enterprise_8.1.7_.0.0" />
        <vers num="enterprise_8.1.7_.1.0" />
        <vers num="enterprise_8.1.7_.4" />
        <vers num="standard_8.0.6" />
        <vers num="standard_8.0.6_.3" />
        <vers num="standard_8.1.5" />
        <vers num="standard_8.1.6" />
        <vers num="standard_8.1.7" />
        <vers num="standard_8.1.7_.0.0" />
        <vers num="standard_8.1.7_.1" />
        <vers num="standard_8.1.7_.4" />
      </prod>
      <prod vendor="oracle" name="oracle9i">
        <vers num="client_9.2.0.1" />
        <vers num="client_9.2.0.2" />
        <vers num="enterprise_8.1.7" />
        <vers num="enterprise_9.0.1" />
        <vers num="enterprise_9.0.1.4" />
        <vers num="enterprise_9.0.1.5" />
        <vers num="enterprise_9.2.0" />
        <vers num="enterprise_9.2.0.1" />
        <vers num="enterprise_9.2.0.2" />
        <vers num="enterprise_9.2.0.3" />
        <vers num="enterprise_9.2.0.4" />
        <vers num="enterprise_9.2.0.5" />
        <vers num="personal_8.1.7" />
        <vers num="personal_9.0.1" />
        <vers num="personal_9.0.1.4" />
        <vers num="personal_9.0.1.5" />
        <vers num="personal_9.2" />
        <vers num="personal_9.2.0.1" />
        <vers num="personal_9.2.0.2" />
        <vers num="personal_9.2.0.3" />
        <vers num="personal_9.2.0.4" />
        <vers num="personal_9.2.0.5" />
        <vers num="standard_8.1.7" />
        <vers num="standard_9.0" />
        <vers num="standard_9.0.1" />
        <vers num="standard_9.0.1.2" />
        <vers num="standard_9.0.1.3" />
        <vers num="standard_9.0.1.4" />
        <vers num="standard_9.0.1.5" />
        <vers num="standard_9.0.2" />
        <vers num="standard_9.2" />
        <vers num="standard_9.2.0.1" />
        <vers num="standard_9.2.0.2" />
        <vers num="standard_9.2.0.3" />
        <vers num="standard_9.2.0.4" />
        <vers num="standard_9.2.0.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-1363" published="2004-08-04" name="CVE-2004-1363" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Buffer overflow in extproc in Oracle 10g allows remote attackers to execute arbitrary code via environment variables in the library name, which are expanded after the length check is performed.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA04-245A.html" source="CERT" patch="1" adv="1">TA04-245A</ref>
      <ref url="http://www.kb.cert.org/vuls/id/316206" source="CERT-VN">VU#316206</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/18659" source="XF" patch="1">oracle-extproc-library-bo(18659)</ref>
      <ref url="http://www.securityfocus.com/bid/10871" source="BID" patch="1">10871</ref>
      <ref url="http://www.oracle.com/technology/deploy/security/pdf/2004alert68.pdf" source="CONFIRM" patch="1" adv="1">http://www.oracle.com/technology/deploy/security/pdf/2004alert68.pdf</ref>
      <ref url="http://www.ngssoftware.com/advisories/oracle23122004.txt" source="MISC" patch="1" adv="1">http://www.ngssoftware.com/advisories/oracle23122004.txt</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110382345829397&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20041223 Oracle extproc buffer overflow (#NISR23122004A)</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-101782-1" source="SUNALERT">101782</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="application_server">
        <vers num="9.0.2" />
        <vers num="9.0.2.0.0" />
        <vers num="9.0.2.0.1" />
        <vers num="9.0.2.1" />
        <vers num="9.0.2.2" />
        <vers num="9.0.2.3" />
        <vers num="9.0.3" />
        <vers num="9.0.3.1" />
        <vers num="9.0.4" />
        <vers num="9.0.4.0" />
        <vers num="9.0.4.1" />
      </prod>
      <prod vendor="oracle" name="collaboration_suite">
        <vers num="release_1" />
      </prod>
      <prod vendor="oracle" name="e-business_suite">
        <vers num="11.5.1" />
        <vers num="11.5.2" />
        <vers num="11.5.3" />
        <vers num="11.5.4" />
        <vers num="11.5.5" />
        <vers num="11.5.6" />
        <vers num="11.5.7" />
        <vers num="11.5.8" />
        <vers num="11.5.9" />
      </prod>
      <prod vendor="oracle" name="enterprise_manager">
        <vers num="9" />
        <vers num="9.0.1" />
      </prod>
      <prod vendor="oracle" name="enterprise_manager_database_control">
        <vers num="10.1.2" />
      </prod>
      <prod vendor="oracle" name="enterprise_manager_grid_control">
        <vers num="10.1.0.2" />
      </prod>
      <prod vendor="oracle" name="oracle10g">
        <vers num="enterprise_10.1.0.2" />
        <vers num="enterprise_9.0.4_.0" />
        <vers num="personal_10.1_.0.2" />
        <vers num="personal_9.0.4_.0" />
        <vers num="standard_10.1_.0.2" />
        <vers num="standard_9.0.4_.0" />
      </prod>
      <prod vendor="oracle" name="oracle8i">
        <vers num="enterprise_8.0.5_.0.0" />
        <vers num="enterprise_8.0.6_.0.0" />
        <vers num="enterprise_8.0.6_.0.1" />
        <vers num="enterprise_8.1.5_.0.0" />
        <vers num="enterprise_8.1.5_.0.2" />
        <vers num="enterprise_8.1.5_.1.0" />
        <vers num="enterprise_8.1.6_.0.0" />
        <vers num="enterprise_8.1.6_.1.0" />
        <vers num="enterprise_8.1.7_.0.0" />
        <vers num="enterprise_8.1.7_.1.0" />
        <vers num="enterprise_8.1.7_.4" />
        <vers num="standard_8.0.6" />
        <vers num="standard_8.0.6_.3" />
        <vers num="standard_8.1.5" />
        <vers num="standard_8.1.6" />
        <vers num="standard_8.1.7" />
        <vers num="standard_8.1.7_.0.0" />
        <vers num="standard_8.1.7_.1" />
        <vers num="standard_8.1.7_.4" />
      </prod>
      <prod vendor="oracle" name="oracle9i">
        <vers num="client_9.2.0.1" />
        <vers num="client_9.2.0.2" />
        <vers num="enterprise_8.1.7" />
        <vers num="enterprise_9.0.1" />
        <vers num="enterprise_9.0.1.4" />
        <vers num="enterprise_9.0.1.5" />
        <vers num="enterprise_9.2.0" />
        <vers num="enterprise_9.2.0.1" />
        <vers num="enterprise_9.2.0.2" />
        <vers num="enterprise_9.2.0.3" />
        <vers num="enterprise_9.2.0.4" />
        <vers num="enterprise_9.2.0.5" />
        <vers num="personal_8.1.7" />
        <vers num="personal_9.0.1" />
        <vers num="personal_9.0.1.4" />
        <vers num="personal_9.0.1.5" />
        <vers num="personal_9.2" />
        <vers num="personal_9.2.0.1" />
        <vers num="personal_9.2.0.2" />
        <vers num="personal_9.2.0.3" />
        <vers num="personal_9.2.0.4" />
        <vers num="personal_9.2.0.5" />
        <vers num="standard_8.1.7" />
        <vers num="standard_9.0" />
        <vers num="standard_9.0.1" />
        <vers num="standard_9.0.1.2" />
        <vers num="standard_9.0.1.3" />
        <vers num="standard_9.0.1.4" />
        <vers num="standard_9.0.1.5" />
        <vers num="standard_9.0.2" />
        <vers num="standard_9.2" />
        <vers num="standard_9.2.0.1" />
        <vers num="standard_9.2.0.2" />
        <vers num="standard_9.2.0.3" />
        <vers num="standard_9.2.0.4" />
        <vers num="standard_9.2.0.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-1364" published="2004-08-04" name="CVE-2004-1364" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:S/C:C/I:C/A:C)" CVSS_score="8.5" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="6.8" CVSS_base_score="8.5">
    <desc>
      <descript source="cve">Directory traversal vulnerability in extproc in Oracle 9i and 10g allows remote attackers to access arbitrary libraries outside of the $ORACLE_HOME\bin directory.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA04-245A.html" source="CERT" patch="1" adv="1">TA04-245A</ref>
      <ref url="http://www.kb.cert.org/vuls/id/316206" source="CERT-VN">VU#316206</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/18658" source="XF" patch="1">oracle-extproc-directory-traversal(18658)</ref>
      <ref url="http://www.securityfocus.com/bid/10871" source="BID" patch="1">10871</ref>
      <ref url="http://www.oracle.com/technology/deploy/security/pdf/2004alert68.pdf" source="CONFIRM" patch="1" adv="1">http://www.oracle.com/technology/deploy/security/pdf/2004alert68.pdf</ref>
      <ref url="http://www.ngssoftware.com/advisories/oracle23122004B.txt" source="MISC" patch="1" adv="1">http://www.ngssoftware.com/advisories/oracle23122004B.txt</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110382406002365&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20041223 Oracle extproc directory traversal (#NISR23122004B)</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/454861/100/0/threaded" source="BUGTRAQ">20061219 Oracle &lt;= 9i / 10g (extproc) Local/Remote Command Execution Exploit</ref>
      <ref url="http://www.0xdeadbeef.info/exploits/raptor_oraextproc.sql" source="MISC">http://www.0xdeadbeef.info/exploits/raptor_oraextproc.sql</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-101782-1" source="SUNALERT">101782</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="application_server">
        <vers num="9.0.2" />
        <vers num="9.0.2.0.0" />
        <vers num="9.0.2.0.1" />
        <vers num="9.0.2.1" />
        <vers num="9.0.2.2" />
        <vers num="9.0.2.3" />
        <vers num="9.0.3" />
        <vers num="9.0.3.1" />
        <vers num="9.0.4" />
        <vers num="9.0.4.0" />
        <vers num="9.0.4.1" />
      </prod>
      <prod vendor="oracle" name="collaboration_suite">
        <vers num="release_1" />
      </prod>
      <prod vendor="oracle" name="e-business_suite">
        <vers num="11.5.1" />
        <vers num="11.5.2" />
        <vers num="11.5.3" />
        <vers num="11.5.4" />
        <vers num="11.5.5" />
        <vers num="11.5.6" />
        <vers num="11.5.7" />
        <vers num="11.5.8" />
        <vers num="11.5.9" />
      </prod>
      <prod vendor="oracle" name="enterprise_manager">
        <vers num="9" />
        <vers num="9.0.1" />
      </prod>
      <prod vendor="oracle" name="enterprise_manager_database_control">
        <vers num="10.1.2" />
      </prod>
      <prod vendor="oracle" name="enterprise_manager_grid_control">
        <vers num="10.1.0.2" />
      </prod>
      <prod vendor="oracle" name="oracle10g">
        <vers num="enterprise_10.1.0.2" />
        <vers num="enterprise_9.0.4_.0" />
        <vers num="personal_10.1_.0.2" />
        <vers num="personal_9.0.4_.0" />
        <vers num="standard_10.1_.0.2" />
        <vers num="standard_9.0.4_.0" />
      </prod>
      <prod vendor="oracle" name="oracle8i">
        <vers num="enterprise_8.0.5_.0.0" />
        <vers num="enterprise_8.0.6_.0.0" />
        <vers num="enterprise_8.0.6_.0.1" />
        <vers num="enterprise_8.1.5_.0.0" />
        <vers num="enterprise_8.1.5_.0.2" />
        <vers num="enterprise_8.1.5_.1.0" />
        <vers num="enterprise_8.1.6_.0.0" />
        <vers num="enterprise_8.1.6_.1.0" />
        <vers num="enterprise_8.1.7_.0.0" />
        <vers num="enterprise_8.1.7_.1.0" />
        <vers num="enterprise_8.1.7_.4" />
        <vers num="standard_8.0.6" />
        <vers num="standard_8.0.6_.3" />
        <vers num="standard_8.1.5" />
        <vers num="standard_8.1.6" />
        <vers num="standard_8.1.7" />
        <vers num="standard_8.1.7_.0.0" />
        <vers num="standard_8.1.7_.1" />
        <vers num="standard_8.1.7_.4" />
      </prod>
      <prod vendor="oracle" name="oracle9i">
        <vers num="client_9.2.0.1" />
        <vers num="client_9.2.0.2" />
        <vers num="enterprise_8.1.7" />
        <vers num="enterprise_9.0.1" />
        <vers num="enterprise_9.0.1.4" />
        <vers num="enterprise_9.0.1.5" />
        <vers num="enterprise_9.2.0" />
        <vers num="enterprise_9.2.0.1" />
        <vers num="enterprise_9.2.0.2" />
        <vers num="enterprise_9.2.0.3" />
        <vers num="enterprise_9.2.0.4" />
        <vers num="enterprise_9.2.0.5" />
        <vers num="personal_8.1.7" />
        <vers num="personal_9.0.1" />
        <vers num="personal_9.0.1.4" />
        <vers num="personal_9.0.1.5" />
        <vers num="personal_9.2" />
        <vers num="personal_9.2.0.1" />
        <vers num="personal_9.2.0.2" />
        <vers num="personal_9.2.0.3" />
        <vers num="personal_9.2.0.4" />
        <vers num="personal_9.2.0.5" />
        <vers num="standard_8.1.7" />
        <vers num="standard_9.0" />
        <vers num="standard_9.0.1" />
        <vers num="standard_9.0.1.2" />
        <vers num="standard_9.0.1.3" />
        <vers num="standard_9.0.1.4" />
        <vers num="standard_9.0.1.5" />
        <vers num="standard_9.0.2" />
        <vers num="standard_9.2" />
        <vers num="standard_9.2.0.1" />
        <vers num="standard_9.2.0.2" />
        <vers num="standard_9.2.0.3" />
        <vers num="standard_9.2.0.4" />
        <vers num="standard_9.2.0.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1365" published="2004-08-04" name="CVE-2004-1365" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Extproc in Oracle 9i and 10g does not require authentication to load a library or execute a function, which allows local users to execute arbitrary commands as the Oracle user.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <access />
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA04-245A.html" source="CERT" patch="1" adv="1">TA04-245A</ref>
      <ref url="http://www.kb.cert.org/vuls/id/316206" source="CERT-VN">VU#316206</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/18662" source="XF" patch="1">oracle-extproc-command-execution(18662)</ref>
      <ref url="http://www.securityfocus.com/bid/10871" source="BID" patch="1">10871</ref>
      <ref url="http://www.ngssoftware.com/advisories/oracle23122004C.txt" source="MISC" patch="1" adv="1">http://www.ngssoftware.com/advisories/oracle23122004C.txt</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110382471608835&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20041223 Oracle extproc local command execution (#NISR23122004C)</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-101782-1" source="SUNALERT">101782</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="application_server">
        <vers num="9.0.2" />
        <vers num="9.0.2.0.0" />
        <vers num="9.0.2.0.1" />
        <vers num="9.0.2.1" />
        <vers num="9.0.2.2" />
        <vers num="9.0.2.3" />
        <vers num="9.0.3" />
        <vers num="9.0.3.1" />
        <vers num="9.0.4" />
        <vers num="9.0.4.0" />
        <vers num="9.0.4.1" />
      </prod>
      <prod vendor="oracle" name="collaboration_suite">
        <vers num="release_1" />
      </prod>
      <prod vendor="oracle" name="e-business_suite">
        <vers num="11.5.1" />
        <vers num="11.5.2" />
        <vers num="11.5.3" />
        <vers num="11.5.4" />
        <vers num="11.5.5" />
        <vers num="11.5.6" />
        <vers num="11.5.7" />
        <vers num="11.5.8" />
        <vers num="11.5.9" />
      </prod>
      <prod vendor="oracle" name="enterprise_manager">
        <vers num="9" />
        <vers num="9.0.1" />
      </prod>
      <prod vendor="oracle" name="enterprise_manager_database_control">
        <vers num="10.1.2" />
      </prod>
      <prod vendor="oracle" name="enterprise_manager_grid_control">
        <vers num="10.1.0.2" />
      </prod>
      <prod vendor="oracle" name="oracle10g">
        <vers num="enterprise_10.1.0.2" />
        <vers num="enterprise_9.0.4_.0" />
        <vers num="personal_10.1_.0.2" />
        <vers num="personal_9.0.4_.0" />
        <vers num="standard_10.1_.0.2" />
        <vers num="standard_9.0.4_.0" />
      </prod>
      <prod vendor="oracle" name="oracle8i">
        <vers num="enterprise_8.0.5_.0.0" />
        <vers num="enterprise_8.0.6_.0.0" />
        <vers num="enterprise_8.0.6_.0.1" />
        <vers num="enterprise_8.1.5_.0.0" />
        <vers num="enterprise_8.1.5_.0.2" />
        <vers num="enterprise_8.1.5_.1.0" />
        <vers num="enterprise_8.1.6_.0.0" />
        <vers num="enterprise_8.1.6_.1.0" />
        <vers num="enterprise_8.1.7_.0.0" />
        <vers num="enterprise_8.1.7_.1.0" />
        <vers num="enterprise_8.1.7_.4" />
        <vers num="standard_8.0.6" />
        <vers num="standard_8.0.6_.3" />
        <vers num="standard_8.1.5" />
        <vers num="standard_8.1.6" />
        <vers num="standard_8.1.7" />
        <vers num="standard_8.1.7_.0.0" />
        <vers num="standard_8.1.7_.1" />
        <vers num="standard_8.1.7_.4" />
      </prod>
      <prod vendor="oracle" name="oracle9i">
        <vers num="client_9.2.0.1" />
        <vers num="client_9.2.0.2" />
        <vers num="enterprise_8.1.7" />
        <vers num="enterprise_9.0.1" />
        <vers num="enterprise_9.0.1.4" />
        <vers num="enterprise_9.0.1.5" />
        <vers num="enterprise_9.2.0" />
        <vers num="enterprise_9.2.0.1" />
        <vers num="enterprise_9.2.0.2" />
        <vers num="enterprise_9.2.0.3" />
        <vers num="enterprise_9.2.0.4" />
        <vers num="enterprise_9.2.0.5" />
        <vers num="personal_8.1.7" />
        <vers num="personal_9.0.1" />
        <vers num="personal_9.0.1.4" />
        <vers num="personal_9.0.1.5" />
        <vers num="personal_9.2" />
        <vers num="personal_9.2.0.1" />
        <vers num="personal_9.2.0.2" />
        <vers num="personal_9.2.0.3" />
        <vers num="personal_9.2.0.4" />
        <vers num="personal_9.2.0.5" />
        <vers num="standard_8.1.7" />
        <vers num="standard_9.0" />
        <vers num="standard_9.0.1" />
        <vers num="standard_9.0.1.2" />
        <vers num="standard_9.0.1.3" />
        <vers num="standard_9.0.1.4" />
        <vers num="standard_9.0.1.5" />
        <vers num="standard_9.0.2" />
        <vers num="standard_9.2" />
        <vers num="standard_9.2.0.1" />
        <vers num="standard_9.2.0.2" />
        <vers num="standard_9.2.0.3" />
        <vers num="standard_9.2.0.4" />
        <vers num="standard_9.2.0.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1366" published="2004-08-04" name="CVE-2004-1366" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Oracle 10g Database Server stores the password for the SYSMAN account in cleartext in the world-readable emoms.properties file, which could allow local users to gain DBA privileges.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA04-245A.html" source="CERT" patch="1" adv="1">TA04-245A</ref>
      <ref url="http://www.kb.cert.org/vuls/id/316206" source="CERT-VN">VU#316206</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/18661" source="XF" patch="1">oracle-sysman-password-plaintext(18661)</ref>
      <ref url="http://www.securityfocus.com/bid/10871" source="BID" patch="1">10871</ref>
      <ref url="http://www.securityfocus.com/archive/1/385323" source="BUGTRAQ" patch="1">20041223 Oracle clear text passwords (#NISR2122004D)</ref>
      <ref url="http://www.oracle.com/technology/deploy/security/pdf/2004alert68.pdf" source="CONFIRM" patch="1" adv="1">http://www.oracle.com/technology/deploy/security/pdf/2004alert68.pdf</ref>
      <ref url="http://www.ngssoftware.com/advisories/oracle23122004D.txt" source="MISC" patch="1" adv="1">http://www.ngssoftware.com/advisories/oracle23122004D.txt</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-101782-1" source="SUNALERT">101782</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="application_server">
        <vers num="9.0.2" />
        <vers num="9.0.2.0.0" />
        <vers num="9.0.2.0.1" />
        <vers num="9.0.2.1" />
        <vers num="9.0.2.2" />
        <vers num="9.0.2.3" />
        <vers num="9.0.3" />
        <vers num="9.0.3.1" />
        <vers num="9.0.4" />
        <vers num="9.0.4.0" />
        <vers num="9.0.4.1" />
      </prod>
      <prod vendor="oracle" name="collaboration_suite">
        <vers num="release_1" />
      </prod>
      <prod vendor="oracle" name="e-business_suite">
        <vers num="11.5.1" />
        <vers num="11.5.2" />
        <vers num="11.5.3" />
        <vers num="11.5.4" />
        <vers num="11.5.5" />
        <vers num="11.5.6" />
        <vers num="11.5.7" />
        <vers num="11.5.8" />
        <vers num="11.5.9" />
      </prod>
      <prod vendor="oracle" name="enterprise_manager">
        <vers num="9" />
        <vers num="9.0.1" />
      </prod>
      <prod vendor="oracle" name="enterprise_manager_database_control">
        <vers num="10.1.2" />
      </prod>
      <prod vendor="oracle" name="enterprise_manager_grid_control">
        <vers num="10.1.0.2" />
      </prod>
      <prod vendor="oracle" name="oracle10g">
        <vers num="enterprise_10.1.0.2" />
        <vers num="enterprise_9.0.4_.0" />
        <vers num="personal_10.1_.0.2" />
        <vers num="personal_9.0.4_.0" />
        <vers num="standard_10.1_.0.2" />
        <vers num="standard_9.0.4_.0" />
      </prod>
      <prod vendor="oracle" name="oracle8i">
        <vers num="enterprise_8.0.5_.0.0" />
        <vers num="enterprise_8.0.6_.0.0" />
        <vers num="enterprise_8.0.6_.0.1" />
        <vers num="enterprise_8.1.5_.0.0" />
        <vers num="enterprise_8.1.5_.0.2" />
        <vers num="enterprise_8.1.5_.1.0" />
        <vers num="enterprise_8.1.6_.0.0" />
        <vers num="enterprise_8.1.6_.1.0" />
        <vers num="enterprise_8.1.7_.0.0" />
        <vers num="enterprise_8.1.7_.1.0" />
        <vers num="enterprise_8.1.7_.4" />
        <vers num="standard_8.0.6" />
        <vers num="standard_8.0.6_.3" />
        <vers num="standard_8.1.5" />
        <vers num="standard_8.1.6" />
        <vers num="standard_8.1.7" />
        <vers num="standard_8.1.7_.0.0" />
        <vers num="standard_8.1.7_.1" />
        <vers num="standard_8.1.7_.4" />
      </prod>
      <prod vendor="oracle" name="oracle9i">
        <vers num="client_9.2.0.1" />
        <vers num="client_9.2.0.2" />
        <vers num="enterprise_8.1.7" />
        <vers num="enterprise_9.0.1" />
        <vers num="enterprise_9.0.1.4" />
        <vers num="enterprise_9.0.1.5" />
        <vers num="enterprise_9.2.0" />
        <vers num="enterprise_9.2.0.1" />
        <vers num="enterprise_9.2.0.2" />
        <vers num="enterprise_9.2.0.3" />
        <vers num="enterprise_9.2.0.4" />
        <vers num="enterprise_9.2.0.5" />
        <vers num="personal_8.1.7" />
        <vers num="personal_9.0.1" />
        <vers num="personal_9.0.1.4" />
        <vers num="personal_9.0.1.5" />
        <vers num="personal_9.2" />
        <vers num="personal_9.2.0.1" />
        <vers num="personal_9.2.0.2" />
        <vers num="personal_9.2.0.3" />
        <vers num="personal_9.2.0.4" />
        <vers num="personal_9.2.0.5" />
        <vers num="standard_8.1.7" />
        <vers num="standard_9.0" />
        <vers num="standard_9.0.1" />
        <vers num="standard_9.0.1.2" />
        <vers num="standard_9.0.1.3" />
        <vers num="standard_9.0.1.4" />
        <vers num="standard_9.0.1.5" />
        <vers num="standard_9.0.2" />
        <vers num="standard_9.2" />
        <vers num="standard_9.2.0.1" />
        <vers num="standard_9.2.0.2" />
        <vers num="standard_9.2.0.3" />
        <vers num="standard_9.2.0.4" />
        <vers num="standard_9.2.0.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1367" published="2004-08-04" name="CVE-2004-1367" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:L/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="4.4" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.4" CVSS_base_score="4.4">
    <desc>
      <descript source="cve">Oracle 10g Database Server, when installed with a password that contains an exclamation point ("!") for the (1) DBSNMP or (2) SYSMAN user, generates an error that logs the password in the world-readable postDBCreation.log file, which could allow local users to obtain that password and use it against SYS or SYSTEM accounts, which may have been installed with the same password.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA04-245A.html" source="CERT">TA04-245A</ref>
      <ref url="http://www.kb.cert.org/vuls/id/316206" source="CERT-VN">VU#316206</ref>
      <ref url="http://www.oracle.com/technology/deploy/security/pdf/2004alert68.pdf" source="CONFIRM" patch="1" adv="1">http://www.oracle.com/technology/deploy/security/pdf/2004alert68.pdf</ref>
      <ref url="http://www.ngssoftware.com/advisories/oracle23122004D.txt" source="MISC" patch="1" adv="1">http://www.ngssoftware.com/advisories/oracle23122004D.txt</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110382247308064&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20041223 Oracle clear text passwords (#NISR2122004D)</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-101782-1" source="SUNALERT">101782</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="application_server">
        <vers num="9.0.2" />
        <vers num="9.0.2.0.0" />
        <vers num="9.0.2.0.1" />
        <vers num="9.0.2.1" />
        <vers num="9.0.2.2" />
        <vers num="9.0.2.3" />
        <vers num="9.0.3" />
        <vers num="9.0.3.1" />
        <vers num="9.0.4" />
        <vers num="9.0.4.0" />
        <vers num="9.0.4.1" />
      </prod>
      <prod vendor="oracle" name="collaboration_suite">
        <vers num="release_1" />
      </prod>
      <prod vendor="oracle" name="e-business_suite">
        <vers num="11.5.1" />
        <vers num="11.5.2" />
        <vers num="11.5.3" />
        <vers num="11.5.4" />
        <vers num="11.5.5" />
        <vers num="11.5.6" />
        <vers num="11.5.7" />
        <vers num="11.5.8" />
        <vers num="11.5.9" />
      </prod>
      <prod vendor="oracle" name="enterprise_manager">
        <vers num="9" />
        <vers num="9.0.1" />
      </prod>
      <prod vendor="oracle" name="enterprise_manager_database_control">
        <vers num="10.1.2" />
      </prod>
      <prod vendor="oracle" name="enterprise_manager_grid_control">
        <vers num="10.1.0.2" />
      </prod>
      <prod vendor="oracle" name="oracle10g">
        <vers num="enterprise_10.1.0.2" />
        <vers num="enterprise_9.0.4_.0" />
        <vers num="personal_10.1_.0.2" />
        <vers num="personal_9.0.4_.0" />
        <vers num="standard_10.1_.0.2" />
        <vers num="standard_9.0.4_.0" />
      </prod>
      <prod vendor="oracle" name="oracle8i">
        <vers num="enterprise_8.0.5_.0.0" />
        <vers num="enterprise_8.0.6_.0.0" />
        <vers num="enterprise_8.0.6_.0.1" />
        <vers num="enterprise_8.1.5_.0.0" />
        <vers num="enterprise_8.1.5_.0.2" />
        <vers num="enterprise_8.1.5_.1.0" />
        <vers num="enterprise_8.1.6_.0.0" />
        <vers num="enterprise_8.1.6_.1.0" />
        <vers num="enterprise_8.1.7_.0.0" />
        <vers num="enterprise_8.1.7_.1.0" />
        <vers num="enterprise_8.1.7_.4" />
        <vers num="standard_8.0.6" />
        <vers num="standard_8.0.6_.3" />
        <vers num="standard_8.1.5" />
        <vers num="standard_8.1.6" />
        <vers num="standard_8.1.7" />
        <vers num="standard_8.1.7_.0.0" />
        <vers num="standard_8.1.7_.1" />
        <vers num="standard_8.1.7_.4" />
      </prod>
      <prod vendor="oracle" name="oracle9i">
        <vers num="client_9.2.0.1" />
        <vers num="client_9.2.0.2" />
        <vers num="enterprise_8.1.7" />
        <vers num="enterprise_9.0.1" />
        <vers num="enterprise_9.0.1.4" />
        <vers num="enterprise_9.0.1.5" />
        <vers num="enterprise_9.2.0" />
        <vers num="enterprise_9.2.0.1" />
        <vers num="enterprise_9.2.0.2" />
        <vers num="enterprise_9.2.0.3" />
        <vers num="enterprise_9.2.0.4" />
        <vers num="enterprise_9.2.0.5" />
        <vers num="personal_8.1.7" />
        <vers num="personal_9.0.1" />
        <vers num="personal_9.0.1.4" />
        <vers num="personal_9.0.1.5" />
        <vers num="personal_9.2" />
        <vers num="personal_9.2.0.1" />
        <vers num="personal_9.2.0.2" />
        <vers num="personal_9.2.0.3" />
        <vers num="personal_9.2.0.4" />
        <vers num="personal_9.2.0.5" />
        <vers num="standard_8.1.7" />
        <vers num="standard_9.0" />
        <vers num="standard_9.0.1" />
        <vers num="standard_9.0.1.2" />
        <vers num="standard_9.0.1.3" />
        <vers num="standard_9.0.1.4" />
        <vers num="standard_9.0.1.5" />
        <vers num="standard_9.0.2" />
        <vers num="standard_9.2" />
        <vers num="standard_9.2.0.1" />
        <vers num="standard_9.2.0.2" />
        <vers num="standard_9.2.0.3" />
        <vers num="standard_9.2.0.4" />
        <vers num="standard_9.2.0.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-1368" published="2004-08-04" name="CVE-2004-1368" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:N/A:N)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">ISQL*Plus in Oracle 10g Application Server allows remote attackers to execute arbitrary files via an absolute pathname in the file parameter to the load.uix script.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA04-245A.html" source="CERT" patch="1" adv="1">TA04-245A</ref>
      <ref url="http://www.kb.cert.org/vuls/id/435974" source="CERT-VN">VU#435974</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/18656" source="XF" patch="1">oracle-isqlplus-file-access(18656)</ref>
      <ref url="http://www.securityfocus.com/bid/10871" source="BID" patch="1">10871</ref>
      <ref url="http://www.ngssoftware.com/advisories/oracle23122004E.txt" source="MISC" patch="1" adv="1">http://www.ngssoftware.com/advisories/oracle23122004E.txt</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110382264415387&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20041223 Oracle ISQLPlus file access vulnerability (#NISR2122004E)</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-101782-1" source="SUNALERT">101782</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="application_server">
        <vers num="9.0.2" />
        <vers num="9.0.2.0.0" />
        <vers num="9.0.2.0.1" />
        <vers num="9.0.2.1" />
        <vers num="9.0.2.2" />
        <vers num="9.0.2.3" />
        <vers num="9.0.3" />
        <vers num="9.0.3.1" />
        <vers num="9.0.4" />
        <vers num="9.0.4.0" />
        <vers num="9.0.4.1" />
      </prod>
      <prod vendor="oracle" name="collaboration_suite">
        <vers num="release_1" />
      </prod>
      <prod vendor="oracle" name="e-business_suite">
        <vers num="11.5.1" />
        <vers num="11.5.2" />
        <vers num="11.5.3" />
        <vers num="11.5.4" />
        <vers num="11.5.5" />
        <vers num="11.5.6" />
        <vers num="11.5.7" />
        <vers num="11.5.8" />
        <vers num="11.5.9" />
      </prod>
      <prod vendor="oracle" name="enterprise_manager">
        <vers num="9" />
        <vers num="9.0.1" />
      </prod>
      <prod vendor="oracle" name="enterprise_manager_database_control">
        <vers num="10.1.2" />
      </prod>
      <prod vendor="oracle" name="enterprise_manager_grid_control">
        <vers num="10.1.0.2" />
      </prod>
      <prod vendor="oracle" name="oracle10g">
        <vers num="enterprise_10.1.0.2" />
        <vers num="enterprise_9.0.4_.0" />
        <vers num="personal_10.1_.0.2" />
        <vers num="personal_9.0.4_.0" />
        <vers num="standard_10.1_.0.2" />
        <vers num="standard_9.0.4_.0" />
      </prod>
      <prod vendor="oracle" name="oracle8i">
        <vers num="enterprise_8.0.5_.0.0" />
        <vers num="enterprise_8.0.6_.0.0" />
        <vers num="enterprise_8.0.6_.0.1" />
        <vers num="enterprise_8.1.5_.0.0" />
        <vers num="enterprise_8.1.5_.0.2" />
        <vers num="enterprise_8.1.5_.1.0" />
        <vers num="enterprise_8.1.6_.0.0" />
        <vers num="enterprise_8.1.6_.1.0" />
        <vers num="enterprise_8.1.7_.0.0" />
        <vers num="enterprise_8.1.7_.1.0" />
        <vers num="enterprise_8.1.7_.4" />
        <vers num="standard_8.0.6" />
        <vers num="standard_8.0.6_.3" />
        <vers num="standard_8.1.5" />
        <vers num="standard_8.1.6" />
        <vers num="standard_8.1.7" />
        <vers num="standard_8.1.7_.0.0" />
        <vers num="standard_8.1.7_.1" />
        <vers num="standard_8.1.7_.4" />
      </prod>
      <prod vendor="oracle" name="oracle9i">
        <vers num="client_9.2.0.1" />
        <vers num="client_9.2.0.2" />
        <vers num="enterprise_8.1.7" />
        <vers num="enterprise_9.0.1" />
        <vers num="enterprise_9.0.1.4" />
        <vers num="enterprise_9.0.1.5" />
        <vers num="enterprise_9.2.0" />
        <vers num="enterprise_9.2.0.1" />
        <vers num="enterprise_9.2.0.2" />
        <vers num="enterprise_9.2.0.3" />
        <vers num="enterprise_9.2.0.4" />
        <vers num="enterprise_9.2.0.5" />
        <vers num="personal_8.1.7" />
        <vers num="personal_9.0.1" />
        <vers num="personal_9.0.1.4" />
        <vers num="personal_9.0.1.5" />
        <vers num="personal_9.2" />
        <vers num="personal_9.2.0.1" />
        <vers num="personal_9.2.0.2" />
        <vers num="personal_9.2.0.3" />
        <vers num="personal_9.2.0.4" />
        <vers num="personal_9.2.0.5" />
        <vers num="standard_8.1.7" />
        <vers num="standard_9.0" />
        <vers num="standard_9.0.1" />
        <vers num="standard_9.0.1.2" />
        <vers num="standard_9.0.1.3" />
        <vers num="standard_9.0.1.4" />
        <vers num="standard_9.0.1.5" />
        <vers num="standard_9.0.2" />
        <vers num="standard_9.2" />
        <vers num="standard_9.2.0.1" />
        <vers num="standard_9.2.0.2" />
        <vers num="standard_9.2.0.3" />
        <vers num="standard_9.2.0.4" />
        <vers num="standard_9.2.0.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1369" published="2004-08-04" name="CVE-2004-1369" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The TNS Listener in Oracle 10g allows remote attackers to cause a denial of service (listener crash) via a malformed service_register_NSGR request containing a value that is used as an invalid offset for a pointer that references incorrect memory.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA04-245A.html" source="CERT" patch="1" adv="1">TA04-245A</ref>
      <ref url="http://www.kb.cert.org/vuls/id/316206" source="CERT-VN">VU#316206</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/18664" source="XF" patch="1">oracle-tnslsnr-nsgr-dos(18664)</ref>
      <ref url="http://www.securityfocus.com/bid/10871" source="BID" patch="1">10871</ref>
      <ref url="http://www.oracle.com/technology/deploy/security/pdf/2004alert68.pdf" source="CONFIRM" patch="1" adv="1">http://www.oracle.com/technology/deploy/security/pdf/2004alert68.pdf</ref>
      <ref url="http://www.ngssoftware.com/advisories/oracle23122004F.txt" source="MISC" patch="1" adv="1">http://www.ngssoftware.com/advisories/oracle23122004F.txt</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110382524401468&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20041223 Oracle TNS Listener DoS (#NISR2122004F)</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-101782-1" source="SUNALERT">101782</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="application_server">
        <vers num="9.0.2" />
        <vers num="9.0.2.0.0" />
        <vers num="9.0.2.0.1" />
        <vers num="9.0.2.1" />
        <vers num="9.0.2.2" />
        <vers num="9.0.2.3" />
        <vers num="9.0.3" />
        <vers num="9.0.3.1" />
        <vers num="9.0.4" />
        <vers num="9.0.4.0" />
        <vers num="9.0.4.1" />
      </prod>
      <prod vendor="oracle" name="collaboration_suite">
        <vers num="release_1" />
      </prod>
      <prod vendor="oracle" name="e-business_suite">
        <vers num="11.5.1" />
        <vers num="11.5.2" />
        <vers num="11.5.3" />
        <vers num="11.5.4" />
        <vers num="11.5.5" />
        <vers num="11.5.6" />
        <vers num="11.5.7" />
        <vers num="11.5.8" />
        <vers num="11.5.9" />
      </prod>
      <prod vendor="oracle" name="enterprise_manager">
        <vers num="9" />
        <vers num="9.0.1" />
      </prod>
      <prod vendor="oracle" name="enterprise_manager_database_control">
        <vers num="10.1.2" />
      </prod>
      <prod vendor="oracle" name="enterprise_manager_grid_control">
        <vers num="10.1.0.2" />
      </prod>
      <prod vendor="oracle" name="oracle10g">
        <vers num="enterprise_10.1.0.2" />
        <vers num="enterprise_9.0.4_.0" />
        <vers num="personal_10.1_.0.2" />
        <vers num="personal_9.0.4_.0" />
        <vers num="standard_10.1_.0.2" />
        <vers num="standard_9.0.4_.0" />
      </prod>
      <prod vendor="oracle" name="oracle8i">
        <vers num="enterprise_8.0.5_.0.0" />
        <vers num="enterprise_8.0.6_.0.0" />
        <vers num="enterprise_8.0.6_.0.1" />
        <vers num="enterprise_8.1.5_.0.0" />
        <vers num="enterprise_8.1.5_.0.2" />
        <vers num="enterprise_8.1.5_.1.0" />
        <vers num="enterprise_8.1.6_.0.0" />
        <vers num="enterprise_8.1.6_.1.0" />
        <vers num="enterprise_8.1.7_.0.0" />
        <vers num="enterprise_8.1.7_.1.0" />
        <vers num="enterprise_8.1.7_.4" />
        <vers num="standard_8.0.6" />
        <vers num="standard_8.0.6_.3" />
        <vers num="standard_8.1.5" />
        <vers num="standard_8.1.6" />
        <vers num="standard_8.1.7" />
        <vers num="standard_8.1.7_.0.0" />
        <vers num="standard_8.1.7_.1" />
        <vers num="standard_8.1.7_.4" />
      </prod>
      <prod vendor="oracle" name="oracle9i">
        <vers num="client_9.2.0.1" />
        <vers num="client_9.2.0.2" />
        <vers num="enterprise_8.1.7" />
        <vers num="enterprise_9.0.1" />
        <vers num="enterprise_9.0.1.4" />
        <vers num="enterprise_9.0.1.5" />
        <vers num="enterprise_9.2.0" />
        <vers num="enterprise_9.2.0.1" />
        <vers num="enterprise_9.2.0.2" />
        <vers num="enterprise_9.2.0.3" />
        <vers num="enterprise_9.2.0.4" />
        <vers num="enterprise_9.2.0.5" />
        <vers num="personal_8.1.7" />
        <vers num="personal_9.0.1" />
        <vers num="personal_9.0.1.4" />
        <vers num="personal_9.0.1.5" />
        <vers num="personal_9.2" />
        <vers num="personal_9.2.0.1" />
        <vers num="personal_9.2.0.2" />
        <vers num="personal_9.2.0.3" />
        <vers num="personal_9.2.0.4" />
        <vers num="personal_9.2.0.5" />
        <vers num="standard_8.1.7" />
        <vers num="standard_9.0" />
        <vers num="standard_9.0.1" />
        <vers num="standard_9.0.1.2" />
        <vers num="standard_9.0.1.3" />
        <vers num="standard_9.0.1.4" />
        <vers num="standard_9.0.1.5" />
        <vers num="standard_9.0.2" />
        <vers num="standard_9.2" />
        <vers num="standard_9.2.0.1" />
        <vers num="standard_9.2.0.2" />
        <vers num="standard_9.2.0.3" />
        <vers num="standard_9.2.0.4" />
        <vers num="standard_9.2.0.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-1370" published="2004-08-04" name="CVE-2004-1370" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple SQL injection vulnerabilities in PL/SQL procedures that run with definer rights in Oracle 9i and 10g allow remote attackers to execute arbitrary SQL commands and gain privileges via (1) DBMS_EXPORT_EXTENSION, (2) WK_ACL.GET_ACL, (3) WK_ACL.STORE_ACL, (4) WK_ADM.COMPLETE_ACL_SNAPSHOT, (5) WK_ACL.DELETE_ACLS_WITH_STATEMENT, or (6) DRILOAD.VALIDATE_STMT.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA04-245A.html" source="CERT" patch="1" adv="1">TA04-245A</ref>
      <ref url="http://www.kb.cert.org/vuls/id/316206" source="CERT-VN">VU#316206</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/18665" source="XF" patch="1">oracle-procedure-sql-injection(18665)</ref>
      <ref url="http://www.securityfocus.com/bid/10871" source="BID" patch="1">10871</ref>
      <ref url="http://www.oracle.com/technology/deploy/security/pdf/2004alert68.pdf" source="CONFIRM" patch="1" adv="1">http://www.oracle.com/technology/deploy/security/pdf/2004alert68.pdf</ref>
      <ref url="http://www.ngssoftware.com/advisories/oracle23122004H.txt" source="MISC" patch="1" adv="1">http://www.ngssoftware.com/advisories/oracle23122004H.txt</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110382596129607&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20041223 Oracle multiple PL/SQL injection vulnerabilities (#NISR2122004H)</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-101782-1" source="SUNALERT">101782</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="application_server">
        <vers num="9.0.2" />
        <vers num="9.0.2.0.0" />
        <vers num="9.0.2.0.1" />
        <vers num="9.0.2.1" />
        <vers num="9.0.2.2" />
        <vers num="9.0.2.3" />
        <vers num="9.0.3" />
        <vers num="9.0.3.1" />
        <vers num="9.0.4" />
        <vers num="9.0.4.0" />
        <vers num="9.0.4.1" />
      </prod>
      <prod vendor="oracle" name="collaboration_suite">
        <vers num="release_1" />
      </prod>
      <prod vendor="oracle" name="e-business_suite">
        <vers num="11.5.1" />
        <vers num="11.5.2" />
        <vers num="11.5.3" />
        <vers num="11.5.4" />
        <vers num="11.5.5" />
        <vers num="11.5.6" />
        <vers num="11.5.7" />
        <vers num="11.5.8" />
        <vers num="11.5.9" />
      </prod>
      <prod vendor="oracle" name="enterprise_manager">
        <vers num="9" />
        <vers num="9.0.1" />
      </prod>
      <prod vendor="oracle" name="enterprise_manager_database_control">
        <vers num="10.1.2" />
      </prod>
      <prod vendor="oracle" name="enterprise_manager_grid_control">
        <vers num="10.1.0.2" />
      </prod>
      <prod vendor="oracle" name="oracle10g">
        <vers num="enterprise_10.1.0.2" />
        <vers num="enterprise_9.0.4_.0" />
        <vers num="personal_10.1_.0.2" />
        <vers num="personal_9.0.4_.0" />
        <vers num="standard_10.1_.0.2" />
        <vers num="standard_9.0.4_.0" />
      </prod>
      <prod vendor="oracle" name="oracle8i">
        <vers num="enterprise_8.0.5_.0.0" />
        <vers num="enterprise_8.0.6_.0.0" />
        <vers num="enterprise_8.0.6_.0.1" />
        <vers num="enterprise_8.1.5_.0.0" />
        <vers num="enterprise_8.1.5_.0.2" />
        <vers num="enterprise_8.1.5_.1.0" />
        <vers num="enterprise_8.1.6_.0.0" />
        <vers num="enterprise_8.1.6_.1.0" />
        <vers num="enterprise_8.1.7_.0.0" />
        <vers num="enterprise_8.1.7_.1.0" />
        <vers num="enterprise_8.1.7_.4" />
        <vers num="standard_8.0.6" />
        <vers num="standard_8.0.6_.3" />
        <vers num="standard_8.1.5" />
        <vers num="standard_8.1.6" />
        <vers num="standard_8.1.7" />
        <vers num="standard_8.1.7_.0.0" />
        <vers num="standard_8.1.7_.1" />
        <vers num="standard_8.1.7_.4" />
      </prod>
      <prod vendor="oracle" name="oracle9i">
        <vers num="client_9.2.0.1" />
        <vers num="client_9.2.0.2" />
        <vers num="enterprise_8.1.7" />
        <vers num="enterprise_9.0.1" />
        <vers num="enterprise_9.0.1.4" />
        <vers num="enterprise_9.0.1.5" />
        <vers num="enterprise_9.2.0" />
        <vers num="enterprise_9.2.0.1" />
        <vers num="enterprise_9.2.0.2" />
        <vers num="enterprise_9.2.0.3" />
        <vers num="enterprise_9.2.0.4" />
        <vers num="enterprise_9.2.0.5" />
        <vers num="personal_8.1.7" />
        <vers num="personal_9.0.1" />
        <vers num="personal_9.0.1.4" />
        <vers num="personal_9.0.1.5" />
        <vers num="personal_9.2" />
        <vers num="personal_9.2.0.1" />
        <vers num="personal_9.2.0.2" />
        <vers num="personal_9.2.0.3" />
        <vers num="personal_9.2.0.4" />
        <vers num="personal_9.2.0.5" />
        <vers num="standard_8.1.7" />
        <vers num="standard_9.0" />
        <vers num="standard_9.0.1" />
        <vers num="standard_9.0.1.2" />
        <vers num="standard_9.0.1.3" />
        <vers num="standard_9.0.1.4" />
        <vers num="standard_9.0.1.5" />
        <vers num="standard_9.0.2" />
        <vers num="standard_9.2" />
        <vers num="standard_9.2.0.1" />
        <vers num="standard_9.2.0.2" />
        <vers num="standard_9.2.0.3" />
        <vers num="standard_9.2.0.4" />
        <vers num="standard_9.2.0.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-1371" published="2004-08-04" name="CVE-2004-1371" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:S/C:C/I:C/A:C)" CVSS_score="9.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.0" CVSS_base_score="9.0">
    <desc>
      <descript source="cve">Stack-based buffer overflow in Oracle 9i and 10g allows remote attackers to execute arbitrary code via a long token in the text of a wrapped procedure.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA04-245A.html" source="CERT" patch="1" adv="1">TA04-245A</ref>
      <ref url="http://www.kb.cert.org/vuls/id/316206" source="CERT-VN">VU#316206</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/18666" source="XF" patch="1">oracle-wrapped-procedure-bo(18666)</ref>
      <ref url="http://www.securityfocus.com/bid/10871" source="BID" patch="1">10871</ref>
      <ref url="http://www.oracle.com/technology/deploy/security/pdf/2004alert68.pdf" source="CONFIRM" patch="1" adv="1">http://www.oracle.com/technology/deploy/security/pdf/2004alert68.pdf</ref>
      <ref url="http://www.ngssoftware.com/advisories/oracle23122004J.txt" source="MISC" patch="1" adv="1">http://www.ngssoftware.com/advisories/oracle23122004J.txt</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110382570313035&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20041223 Oracle wrapped procedure overflow (#NISR2122004J)</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-101782-1" source="SUNALERT">101782</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="application_server">
        <vers num="9.0.2" />
        <vers num="9.0.2.0.0" />
        <vers num="9.0.2.0.1" />
        <vers num="9.0.2.1" />
        <vers num="9.0.2.2" />
        <vers num="9.0.2.3" />
        <vers num="9.0.3" />
        <vers num="9.0.3.1" />
        <vers num="9.0.4" />
        <vers num="9.0.4.0" />
        <vers num="9.0.4.1" />
      </prod>
      <prod vendor="oracle" name="collaboration_suite">
        <vers num="release_1" />
      </prod>
      <prod vendor="oracle" name="database_server">
        <vers num="9i_application_server" />
      </prod>
      <prod vendor="oracle" name="e-business_suite">
        <vers num="11.5.1" />
        <vers num="11.5.2" />
        <vers num="11.5.3" />
        <vers num="11.5.4" />
        <vers num="11.5.5" />
        <vers num="11.5.6" />
        <vers num="11.5.7" />
        <vers num="11.5.8" />
        <vers num="11.5.9" />
      </prod>
      <prod vendor="oracle" name="enterprise_manager">
        <vers num="9" />
        <vers num="9.0.1" />
      </prod>
      <prod vendor="oracle" name="enterprise_manager_database_control">
        <vers num="10.1.2" />
      </prod>
      <prod vendor="oracle" name="enterprise_manager_grid_control">
        <vers num="10.1.0.2" />
      </prod>
      <prod vendor="oracle" name="oracle10g">
        <vers num="enterprise_10.1.0.2" />
        <vers num="enterprise_9.0.4_.0" />
        <vers num="personal_10.1_.0.2" />
        <vers num="personal_9.0.4_.0" />
        <vers num="standard_10.1_.0.2" />
        <vers num="standard_9.0.4_.0" />
      </prod>
      <prod vendor="oracle" name="oracle8i">
        <vers num="enterprise_8.0.5_.0.0" />
        <vers num="enterprise_8.0.6_.0.0" />
        <vers num="enterprise_8.0.6_.0.1" />
        <vers num="enterprise_8.1.5_.0.0" />
        <vers num="enterprise_8.1.5_.0.2" />
        <vers num="enterprise_8.1.5_.1.0" />
        <vers num="enterprise_8.1.6_.0.0" />
        <vers num="enterprise_8.1.6_.1.0" />
        <vers num="enterprise_8.1.7_.0.0" />
        <vers num="enterprise_8.1.7_.1.0" />
        <vers num="enterprise_8.1.7_.4" />
        <vers num="standard_8.0.6" />
        <vers num="standard_8.0.6_.3" />
        <vers num="standard_8.1.5" />
        <vers num="standard_8.1.6" />
        <vers num="standard_8.1.7" />
        <vers num="standard_8.1.7_.0.0" />
        <vers num="standard_8.1.7_.1" />
        <vers num="standard_8.1.7_.4" />
      </prod>
      <prod vendor="oracle" name="oracle9i">
        <vers num="client_9.2.0.1" />
        <vers num="client_9.2.0.2" />
        <vers num="enterprise_8.1.7" />
        <vers num="enterprise_9.0.1" />
        <vers num="enterprise_9.0.1.4" />
        <vers num="enterprise_9.0.1.5" />
        <vers num="enterprise_9.2.0" />
        <vers num="enterprise_9.2.0.1" />
        <vers num="enterprise_9.2.0.2" />
        <vers num="enterprise_9.2.0.3" />
        <vers num="enterprise_9.2.0.4" />
        <vers num="enterprise_9.2.0.5" />
        <vers num="personal_8.1.7" />
        <vers num="personal_9.0.1" />
        <vers num="personal_9.0.1.4" />
        <vers num="personal_9.0.1.5" />
        <vers num="personal_9.2" />
        <vers num="personal_9.2.0.1" />
        <vers num="personal_9.2.0.2" />
        <vers num="personal_9.2.0.3" />
        <vers num="personal_9.2.0.4" />
        <vers num="personal_9.2.0.5" />
        <vers num="standard_8.1.7" />
        <vers num="standard_9.0" />
        <vers num="standard_9.0.1" />
        <vers num="standard_9.0.1.2" />
        <vers num="standard_9.0.1.3" />
        <vers num="standard_9.0.1.4" />
        <vers num="standard_9.0.1.5" />
        <vers num="standard_9.0.2" />
        <vers num="standard_9.2" />
        <vers num="standard_9.2.0.1" />
        <vers num="standard_9.2.0.2" />
        <vers num="standard_9.2.0.3" />
        <vers num="standard_9.2.0.4" />
        <vers num="standard_9.2.0.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-1372" published="2004-09-01" name="CVE-2004-1372" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Multiple stack-based buffer overflows in IBM DB2 7.x and 8.1 allow local users to execute arbitrary code via (1) a long third argument to the rec2xml function or (2) a long filename argument to the generate_distfile procedure.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/18682" source="XF" patch="1">db2-rec2xml-bo(18682)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/18663" source="XF" patch="1">db2-generatedistfile-bo(18663)</ref>
      <ref url="http://www.securityfocus.com/bid/11089" source="BID" patch="1">11089</ref>
      <ref url="http://www.ngssoftware.com/advisories/db223122004L.txt" source="MISC" patch="1" adv="1">http://www.ngssoftware.com/advisories/db223122004L.txt</ref>
      <ref url="http://www.ngssoftware.com/advisories/db223122004K.txt" source="MISC" patch="1" adv="1">http://www.ngssoftware.com/advisories/db223122004K.txt</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110382730431065&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20041223 IBM DB2 rec2xml buffer overflow vulnerability (#NISR2122004J)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110382462924162&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20041223 IBM DB2 generate_distfile buffer overflow vulnerability (#NISR2122004L)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="db2_universal_database">
        <vers num="7.0" edition="" />
        <vers num="7.0" edition=":linux" />
        <vers num="7.1" edition="" />
        <vers num="7.1" edition=":linux" />
        <vers num="7.2" edition="" />
        <vers num="7.2" edition=":linux" />
        <vers num="8.1" edition="" />
        <vers num="8.1" edition=":aix" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-1373" published="2004-12-23" name="CVE-2004-1373" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Format string vulnerability in SHOUTcast 1.9.4 allows remote attackers to cause a denial of service (application crash) and execute arbitrary code via format string specifiers in a content URL, as demonstrated in the filename portion of a .mp3 file.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/18669" source="XF" patch="1">shoutcast-format-string(18669)</ref>
      <ref url="http://www.securityfocus.com/bid/12096" source="BID" patch="1">12096</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200501-04.xml" source="GENTOO" patch="1">GLSA-200501-04</ref>
      <ref url="http://securitytracker.com/id?1012675" source="SECTRACK">1012675</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110886444014745&amp;w=2" source="BUGTRAQ">20050219 exwormshoucast  part of PTjob project: SHOUTcast v1.9.4 remote</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110382975516003&amp;w=2" source="BUGTRAQ">20041223 SHOUTcast remote format string vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="nullsoft" name="shoutcast_server">
        <vers num="1.9.4" edition="" />
        <vers num="1.9.4" edition=":mac_os_x" />
        <vers num="1.9.4" edition=":win32" />
        <vers num="1.9.4" edition=":linux" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-1374" published="2004-12-18" name="CVE-2004-1374" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Multiple buffer overflows in NetBSD kernel may allow local users to execute arbitrary code and gain privileges.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://gleg.net/advisory_netbsd2.shtml" source="MISC" adv="1">http://gleg.net/advisory_netbsd2.shtml</ref>
    </refs>
    <vuln_soft>
      <prod vendor="netbsd" name="netbsd">
        <vers num="2.0.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1375" published="2004-12-23" name="CVE-2004-1375" modified="2009-03-04" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Unknown vulnerability in System Administration Manager (SAM) in HP-UX B.11.00, B.11.11, B.11.22, and B.11.23 allows local users to gain privileges.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/18674" source="XF" patch="1">hp-sam-gain-privileges(18674)</ref>
      <ref url="http://www.securityfocus.com/bid/12098" source="BID" patch="1">12098</ref>
      <ref url="http://www.ciac.org/ciac/bulletins/p-085.shtml" source="CIAC" patch="1" adv="1">P-085</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110384155209555&amp;w=2" source="HP" patch="1">SSRT4699</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5435" source="OVAL">oval:org.mitre.oval:def:5435</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hp" name="hp-ux">
        <vers num="11.00" />
        <vers num="11.11" />
        <vers num="11.22" />
        <vers num="11.23" edition="" />
        <vers num="11.23" edition=":ia64_64-bit" />
        <vers num="11.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1376" published="2004-12-30" name="CVE-2004-1376" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in Microsoft Internet Explorer 5.01, 5.5, and 6.0 allows remote malicious FTP servers to overwrite arbitrary files via .. (dot dot) sequences in filenames returned from a LIST command.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/13704" source="SECUNIA" patch="1" adv="1">13704</ref>
      <ref url="http://www.7a69ezine.org/node/view/176" source="MISC" adv="1">http://www.7a69ezine.org/node/view/176</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110461358930103&amp;w=2" source="BUGTRAQ" adv="1">20041230 7a69Adv#17 - Internet Explorer FTP download path disclosure</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="ie">
        <vers num="5.01" />
        <vers num="5.5" />
        <vers num="6.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2004-1377" published="2004-12-27" name="CVE-2004-1377" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">The (1) fixps (aka fixps.in) and (2) psmandup (aka psmandup.in) scripts in a2ps before 4.13 allow local users to overwrite arbitrary files via a symlink attack on temporary files.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <access />
      <input />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/12109" source="BID" patch="1">12109</ref>
      <ref url="http://www.securityfocus.com/bid/12108" source="BID" patch="1">12108</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200501-02.xml" source="GENTOO" patch="1">GLSA-200501-02</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/18672" source="XF">gnu-a2ps-psmanupin-symlink(18672)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/18671" source="XF">gnu-a2ps-fixpsin-symlink(18671)</ref>
      <ref url="http://www.vuxml.org/freebsd/9168253c-5a6d-11d9-a9e7-0001020eed82.html" source="CONFIRM">http://www.vuxml.org/freebsd/9168253c-5a6d-11d9-a9e7-0001020eed82.html</ref>
      <ref url="http://secunia.com/advisories/13641" source="SECUNIA" adv="1">13641</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gnu" name="a2ps">
        <vers num="4.13" />
        <vers num="4.13b" />
      </prod>
      <prod vendor="turbolinux" name="turbolinux_home">
        <vers num="" />
      </prod>
      <prod vendor="turbolinux" name="turbolinux_server">
        <vers num="7.0" />
        <vers num="8.0" />
      </prod>
      <prod vendor="turbolinux" name="turbolinux_workstation">
        <vers num="7.0" />
        <vers num="8.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1378" published="2004-09-21" name="CVE-2004-1378" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The expat XML parser code, as used in the open source Jabber (jabberd) 1.4.3 and earlier, jadc2s 0.9.0 and earlier, and possibly other packages, allows remote attackers to cause a denial of service (application crash) via a malformed packet to a socket that accepts XML connections.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/17466" source="XF" patch="1">jabberd-xml-dos(17466)</ref>
      <ref url="http://www.securityfocus.com/bid/11231" source="BID" patch="1">11231</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200409-31.xml" source="GENTOO" patch="1">GLSA-200409-31</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109583829122679&amp;w=2" source="BUGTRAQ" patch="1">20040920 Possible DoS attack against jabberd 1.4.3 and jadc2s 0.9.0</ref>
      <ref url="http://devel.amessage.info/jabberd14/" source="CONFIRM" patch="1">http://devel.amessage.info/jabberd14/</ref>
      <ref url="http://www.vuxml.org/freebsd/2e25d38b-54d1-11d9-b612-000c6e8f12ef.html" source="CONFIRM">http://www.vuxml.org/freebsd/2e25d38b-54d1-11d9-b612-000c6e8f12ef.html</ref>
      <ref url="http://mail.jabber.org/pipermail/jabberd/2004-September/002004.html" source="MLIST">[jabberd] 20040919 Jabberd 1.4 critical bug</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/17467" source="XF">jadc2s-xml-dos(17467)</ref>
      <ref url="http://www.osvdb.org/10257" source="OSVDB">10257</ref>
      <ref url="http://securitytracker.com/id?1011384" source="SECTRACK">1011384</ref>
      <ref url="http://securitytracker.com/id?1011383" source="SECTRACK">1011383</ref>
      <ref url="http://secunia.com/advisories/12636" source="SECUNIA">12636</ref>
    </refs>
    <vuln_soft>
      <prod vendor="jabberstudio" name="jabberd">
        <vers num="1.4" />
        <vers num="1.4.1" />
        <vers num="1.4.2" />
        <vers num="1.4.2a" />
        <vers num="1.4.3" />
      </prod>
      <prod vendor="jabberstudio" name="jadc2s">
        <vers num="0.6" />
        <vers num="0.7" />
        <vers num="0.8" />
        <vers num="0.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-1379" published="2004-09-16" name="CVE-2004-1379" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Heap-based buffer overflow in the DVD subpicture decoder in xine xine-lib 1-rc5 and earlier allows remote attackers to execute arbitrary code via a (1) DVD or (2) MPEG subpicture header where the second field reuses RLE data from the end of the first field.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xinehq.de/index.php/security/XSA-2004-5" source="CONFIRM" patch="1" adv="1">http://xinehq.de/index.php/security/XSA-2004-5</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/17423" source="XF" patch="1">xine-dvd-subpicture-bo(17423)</ref>
      <ref url="http://www.securityfocus.com/bid/11205" source="BID" patch="1">11205</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200409-30.xml" source="GENTOO" patch="1">GLSA-200409-30</ref>
      <ref url="http://www.debian.org/security/2005/dsa-657" source="DEBIAN" patch="1" adv="1">DSA-657</ref>
      <ref url="http://slackware.com/security/viewer.php?l=slackware-security&amp;y=2004&amp;m=slackware-security.320308" source="SLACKWARE" patch="1">SSA:2004-266</ref>
      <ref url="http://www.vuxml.org/freebsd/131bd7c4-64a3-11d9-829a-000a95bc6fae.html" source="CONFIRM">http://www.vuxml.org/freebsd/131bd7c4-64a3-11d9-829a-000a95bc6fae.html</ref>
      <ref url="http://www.securityfocus.com/archive/1/375482/2004-09-02/2004-09-08/0" source="BUGTRAQ">20040906 XSA-2004-5: heap overflow in DVD subpicture decoder</ref>
    </refs>
    <vuln_soft>
      <prod vendor="xine" name="xine">
        <vers num="1_alpha" />
        <vers num="1_beta1" />
        <vers num="1_beta10" />
        <vers num="1_beta11" />
        <vers num="1_beta12" />
        <vers num="1_beta2" />
        <vers num="1_beta3" />
        <vers num="1_beta4" />
        <vers num="1_beta5" />
        <vers num="1_beta6" />
        <vers num="1_beta7" />
        <vers num="1_beta8" />
        <vers num="1_beta9" />
        <vers num="1_rc0" />
        <vers num="1_rc0a" />
        <vers num="1_rc1" />
        <vers num="1_rc2" />
        <vers num="1_rc3" />
        <vers num="1_rc3a" />
        <vers num="1_rc3b" />
        <vers num="1_rc4" />
        <vers num="1_rc5" />
      </prod>
      <prod vendor="xine" name="xine-lib">
        <vers num="0.9.8" />
        <vers num="1_beta12" />
        <vers num="1_beta2" />
        <vers num="1_beta3" />
        <vers num="1_beta4" />
        <vers num="1_beta5" />
        <vers num="1_beta6" />
        <vers num="1_beta7" />
        <vers num="1_beta8" />
        <vers num="1_beta9" />
        <vers num="1_rc0" />
        <vers num="1_rc1" />
        <vers num="1_rc2" />
        <vers num="1_rc3" />
        <vers num="1_rc3a" />
        <vers num="1_rc3b" />
        <vers num="1_rc3c" />
        <vers num="1_rc4" />
        <vers num="1_rc5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1380" published="2004-10-20" name="CVE-2004-1380" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Firefox before 1.0 and Mozilla before 1.7.5 allows inactive (background) tabs to launch dialog boxes, which can allow remote attackers to spoof the dialog boxes from web sites in other windows and facilitate phishing attacks, aka the "Dialog Box Spoofing Vulnerability."</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/18864" source="XF" patch="1">web-browser-modal-spoofing(18864)</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-335.html" source="REDHAT" patch="1" adv="1">RHSA-2005:335</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-323.html" source="REDHAT" patch="1" adv="1">RHSA-2005:323</ref>
      <ref url="http://www.mozilla.org/security/announce/mfsa2005-05.html" source="CONFIRM" patch="1" adv="1">http://www.mozilla.org/security/announce/mfsa2005-05.html</ref>
      <ref url="http://secunia.com/advisories/12712" source="SECUNIA" patch="1" adv="1">12712</ref>
      <ref url="http://secunia.com/multiple_browsers_form_field_focus_test/" source="MISC" adv="1">http://secunia.com/multiple_browsers_form_field_focus_test/</ref>
      <ref url="http://secunia.com/multiple_browsers_dialog_box_spoofing_test/" source="MISC" adv="1">http://secunia.com/multiple_browsers_dialog_box_spoofing_test/</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10211" source="OVAL">oval:org.mitre.oval:def:10211</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:100050" source="OVAL" sig="1">oval:org.mitre.oval:def:100050</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="firefox">
        <vers num="0.10" />
        <vers num="0.10.1" />
        <vers num="0.8" />
        <vers num="0.9" edition="rc" />
        <vers num="0.9.1" />
        <vers num="0.9.2" />
        <vers num="0.9.3" />
      </prod>
      <prod vendor="mozilla" name="mozilla">
        <vers num="1.3" />
        <vers num="1.4" edition="alpha" />
        <vers num="1.4.1" />
        <vers num="1.5" edition="alpha" />
        <vers num="1.5" edition="rc1" />
        <vers num="1.5" edition="rc2" />
        <vers num="1.5.1" />
        <vers num="1.6" edition="alpha" />
        <vers num="1.6" edition="beta" />
        <vers num="1.7" edition="alpha" />
        <vers num="1.7" edition="beta" />
        <vers num="1.7" edition="rc1" />
        <vers num="1.7" edition="rc2" />
        <vers num="1.7" edition="rc3" />
        <vers num="1.7.1" />
        <vers num="1.7.2" />
        <vers num="1.7.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1381" published="2004-10-20" name="CVE-2004-1381" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Firefox before 1.0 and Mozilla before 1.7.5 allow inactive (background) tabs to focus on input being entered in the active tab, as originally reported using form fields, which allows remote attackers to steal sensitive data that is intended for other sites, which could facilitate phishing attacks.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.mozilla.org/security/announce/mfsa2005-05.html" source="CONFIRM" patch="1" adv="1">http://www.mozilla.org/security/announce/mfsa2005-05.html</ref>
      <ref url="http://secunia.com/advisories/12712" source="SECUNIA" patch="1" adv="1">12712</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/17789" source="XF">web-browser-inactive-info-disclosure(17789)</ref>
      <ref url="http://secunia.com/multiple_browsers_form_field_focus_test/" source="MISC" adv="1">http://secunia.com/multiple_browsers_form_field_focus_test/</ref>
      <ref url="http://secunia.com/multiple_browsers_dialog_box_spoofing_test/" source="MISC" adv="1">http://secunia.com/multiple_browsers_dialog_box_spoofing_test/</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:100053" source="OVAL" sig="1">oval:org.mitre.oval:def:100053</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="firefox">
        <vers num="0.10" />
        <vers num="0.10.1" />
        <vers num="0.8" />
        <vers num="0.9" edition="rc" />
        <vers num="0.9.1" />
        <vers num="0.9.2" />
        <vers num="0.9.3" />
      </prod>
      <prod vendor="mozilla" name="mozilla">
        <vers num="1.3" />
        <vers num="1.4" edition="alpha" />
        <vers num="1.4.1" />
        <vers num="1.5" edition="alpha" />
        <vers num="1.5" edition="rc1" />
        <vers num="1.5" edition="rc2" />
        <vers num="1.5.1" />
        <vers num="1.6" edition="alpha" />
        <vers num="1.6" edition="beta" />
        <vers num="1.7" edition="alpha" />
        <vers num="1.7" edition="beta" />
        <vers num="1.7" edition="rc1" />
        <vers num="1.7" edition="rc2" />
        <vers num="1.7" edition="rc3" />
        <vers num="1.7.1" />
        <vers num="1.7.2" />
        <vers num="1.7.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2004-1382" published="2004-12-31" name="CVE-2004-1382" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">The glibcbug script in glibc 2.3.4 and earlier allows local users to overwrite arbitrary files via a symlink attack on temporary files, a different vulnerability than CVE-2004-0968.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.debian.org/security/2005/dsa-636" source="DEBIAN" patch="1" adv="1">DSA-636</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109899903129801&amp;w=2" source="BUGTRAQ" patch="1">20041028 [USN-4-1] Standard C library script vulnerabilities</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-261.html" source="REDHAT">RHSA-2005:261</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2004:159" source="MANDRAKE">MDKSA-2004:159</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gnu" name="glibc">
        <vers num="2.0" />
        <vers num="2.0.1" />
        <vers num="2.0.2" />
        <vers num="2.0.3" />
        <vers num="2.0.4" />
        <vers num="2.0.5" />
        <vers num="2.0.6" />
        <vers num="2.1" />
        <vers num="2.1.1" />
        <vers num="2.1.1.6" />
        <vers num="2.1.2" />
        <vers num="2.1.3" />
        <vers num="2.1.3.10" />
        <vers num="2.1.9" />
        <vers num="2.2" />
        <vers num="2.2.1" />
        <vers num="2.2.2" />
        <vers num="2.2.3" />
        <vers num="2.2.4" />
        <vers num="2.2.5" />
        <vers num="2.3" />
        <vers num="2.3.1" />
        <vers num="2.3.10" />
        <vers num="2.3.2" />
        <vers num="2.3.3" />
        <vers num="2.3.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-1383" published="2004-12-31" name="CVE-2004-1383" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple SQL injection vulnerabilities in phpGroupWare 0.9.16.003 and earlier allow remote attackers to execute arbitrary SQL statements via the (1) order, (2) project_id, (3) pro_main, or (4) hours_id parameters to index.php or (5) ticket_id to viewticket_details.php.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/11952" source="BID" patch="1">11952</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200501-08.xml" source="GENTOO" patch="1">GLSA-200501-08</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/18498" source="XF">phpgroupware-projectid-sql-injection(18498)</ref>
      <ref url="http://www.gulftech.org/?node=research&amp;article_id=00054-12142004" source="MISC">http://www.gulftech.org/?node=research&amp;article_id=00054-12142004</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110312656029072&amp;w=2" source="BUGTRAQ">20041215 Multiple phpGroupWare Vulnerabilities [ phpGroupWare 0.9.16.003 &amp;&amp; Earlier ]</ref>
    </refs>
    <vuln_soft>
      <prod vendor="phpgroupware" name="phpgroupware">
        <vers num="0.9.12" />
        <vers num="0.9.13" />
        <vers num="0.9.14" />
        <vers num="0.9.14.003" />
        <vers num="0.9.14.005" />
        <vers num="0.9.14.006" />
        <vers num="0.9.14.007" />
        <vers num="0.9.16.000" />
        <vers num="0.9.16.002" />
        <vers num="0.9.16.003" />
        <vers num="0.9.16_rc1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1384" published="2004-12-31" name="CVE-2004-1384" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in phpGroupWare 0.9.16.003 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) kp3, (2) type, (3) msg, (4) forum_id, (5) pos, (6) cats_app, (7) cat_id, (8) msgball[msgnum], (9) fldball[acctnum] parameters to index.php or (10) ticket_id to viewticket_details.php.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/11952" source="BID" patch="1">11952</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200501-08.xml" source="GENTOO" patch="1">GLSA-200501-08</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/18496" source="XF">phpgroupware-index-preferences-xss(18496)</ref>
      <ref url="http://www.gulftech.org/?node=research&amp;article_id=00054-12142004" source="MISC">http://www.gulftech.org/?node=research&amp;article_id=00054-12142004</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110312656029072&amp;w=2" source="BUGTRAQ">20041215 Multiple phpGroupWare Vulnerabilities [ phpGroupWare 0.9.16.003 &amp;&amp; Earlier ]</ref>
    </refs>
    <vuln_soft>
      <prod vendor="phpgroupware" name="phpgroupware">
        <vers num="0.9.12" />
        <vers num="0.9.13" />
        <vers num="0.9.14" />
        <vers num="0.9.14.003" />
        <vers num="0.9.14.005" />
        <vers num="0.9.14.006" />
        <vers num="0.9.14.007" />
        <vers num="0.9.16.000" />
        <vers num="0.9.16.002" />
        <vers num="0.9.16.003" />
        <vers num="0.9.16_rc1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1385" published="2004-12-31" name="CVE-2004-1385" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">phpGroupWare 0.9.16.003 and earlier allows remote attackers to gain sensitive information via (1) unexpected characters in the session ID such as shell metacharacters, (2) an invalid appname parameter to preferences.php or (3) an invalid menuaction parameter to index.php, which reveals the web server path in an error message.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200501-08.xml" source="GENTOO" patch="1">GLSA-200501-08</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/18497" source="XF">phpgroupware-path-disclosure(18497)</ref>
      <ref url="http://www.gulftech.org/?node=research&amp;article_id=00054-12142004" source="MISC">http://www.gulftech.org/?node=research&amp;article_id=00054-12142004</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110312656029072&amp;w=2" source="BUGTRAQ">20041215 Multiple phpGroupWare Vulnerabilities [ phpGroupWare 0.9.16.003 &amp;&amp; Earlier ]</ref>
    </refs>
    <vuln_soft>
      <prod vendor="phpgroupware" name="phpgroupware">
        <vers num="0.9.12" />
        <vers num="0.9.13" />
        <vers num="0.9.14" />
        <vers num="0.9.14.003" />
        <vers num="0.9.14.005" />
        <vers num="0.9.14.006" />
        <vers num="0.9.14.007" />
        <vers num="0.9.16.000" />
        <vers num="0.9.16.002" />
        <vers num="0.9.16.003" />
        <vers num="0.9.16_rc1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-1386" published="2004-12-31" name="CVE-2004-1386" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">TikiWiki before 1.8.4.1 does not properly verify uploaded images, which could allow remote attackers to upload and execute arbitrary PHP scripts, a different vulnerability than CVE-2005-0200.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/12110" source="BID" patch="1">12110</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200501-12.xml" source="GENTOO" patch="1">GLSA-200501-12</ref>
      <ref url="http://tikiwiki.org/tiki-read_article.php?articleId=97" source="CONFIRM" patch="1">http://tikiwiki.org/tiki-read_article.php?articleId=97</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/18691" source="XF">tikiwiki-image-command-execution(18691)</ref>
      <ref url="http://www.ciac.org/ciac/bulletins/p-084.shtml" source="CIAC">P-084</ref>
      <ref url="http://www.osvdb.org/12628" source="OSVDB">12628</ref>
      <ref url="http://securitytracker.com/id?1012700" source="SECTRACK">1012700</ref>
    </refs>
    <vuln_soft>
      <prod vendor="tikiwiki_project" name="tikiwiki">
        <vers num="1.7.1.1" />
        <vers num="1.7.2" />
        <vers num="1.7.3" />
        <vers num="1.7.4" />
        <vers num="1.7.5" />
        <vers num="1.7.6" />
        <vers num="1.7.7" />
        <vers num="1.7.8" />
        <vers num="1.8" />
        <vers num="1.8.1" />
        <vers num="1.8.2" />
        <vers num="1.8.3" />
        <vers num="1.8.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2004-1387" published="2004-12-31" name="CVE-2004-1387" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">The check_forensic script in apache-utils package 1.3.31 allows local users to overwrite or create arbitrary files via a symlink attack on temporary files.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/18993" source="XF">apache-checkforensic-symlink(18993)</ref>
      <ref url="http://secunia.com/advisories/13925" source="SECUNIA">13925</ref>
      <ref url="http://www.ubuntulinux.org/support/documentation/usn/usn-65-1" source="UBUNTU">USN-65-1</ref>
      <ref url="http://lists.debian.org/debian-apache/2005/01/msg00076.html" source="MLIST">[debian-apache] 20050119 Bug#290974: marked as done (apache: Temporary usage bugs that can be used in symlink attacks)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apache" name="http_server">
        <vers num="1.3.31" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-1388" published="2004-12-31" name="CVE-2004-1388" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Format string vulnerability in the gpsd_report function for BerliOS GPD daemon (gpsd, formerly pygps) 1.9.0 through 2.7 allows remote attackers to execute arbitrary code via certain GPS requests containing format string specifiers that are not properly handled in syslog calls.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://lists.berlios.de/pipermail/gpsd-announce/2005-January/000018.html" source="MLIST" patch="1">[Gpsd-announce] 20050127 Announcing release 2.8 of gpsd</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/19079" source="XF">gpsd-format-string(19079)</ref>
      <ref url="http://www.mail-archive.com/debian-bugs-closed@lists.debian.org/msg02103.html" source="CONFIRM">http://www.mail-archive.com/debian-bugs-closed@lists.debian.org/msg02103.html</ref>
      <ref url="http://www.digitalmunition.com/DMA%5B2005-0125a%5D.txt" source="MISC">http://www.digitalmunition.com/DMA%5B2005-0125a%5D.txt</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110677341711505&amp;w=2" source="BUGTRAQ">20050126 DMA[2005-0125a] - 'berlios gpsd format string vulnerability'</ref>
    </refs>
    <vuln_soft>
      <prod vendor="berlios" name="gps_daemon">
        <vers num="1.25" />
        <vers num="1.26" />
        <vers num="1.9.0" />
        <vers num="1.91" />
        <vers num="1.92" />
        <vers num="1.93" />
        <vers num="1.94" />
        <vers num="1.95" />
        <vers num="1.96" />
        <vers num="1.97" />
        <vers num="1.98" />
        <vers num="2.0" />
        <vers num="2.1" />
        <vers num="2.2" />
        <vers num="2.3" />
        <vers num="2.4" />
        <vers num="2.7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1389" published="2004-12-31" name="CVE-2004-1389" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:L/AC:H/Au:S/C:C/I:C/A:C)" CVSS_score="6.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="1.5" CVSS_base_score="6.0">
    <desc>
      <descript source="cve">Unknown vulnerability in the Veritas NetBackup Administrative Assistant interface for NetBackup BusinesServer 3.4, 3.4.1, and 4.5, DataCenter 3.4, 3.4.1, and 4.5, Enterprise Server 5.1, and NetBackup Server 5.0 and 5.1, allows attackers to execute arbitrary commands via the bpjava-susvc process, possibly related to the call-back feature.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/685456" source="CERT-VN" patch="1" adv="1">VU#685456</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/17811" source="XF" patch="1">nebackup-bpjavasusvc-gain-privileges(17811)</ref>
      <ref url="http://www.ciac.org/ciac/bulletins/p-020.shtml" source="CIAC" patch="1" adv="1">P-020</ref>
      <ref url="http://seer.support.veritas.com/docs/271727.htm" source="CONFIRM" patch="1" adv="1">http://seer.support.veritas.com/docs/271727.htm</ref>
      <ref url="http://www.securityfocus.com/bid/11494" source="BID">11494</ref>
      <ref url="http://secunia.com/advisories/12901/" source="SECUNIA" adv="1">12901</ref>
    </refs>
    <vuln_soft>
      <prod vendor="veritas" name="netbackup">
        <vers num="3.4.0" edition="" />
        <vers num="3.4.0" edition=":datacenter" />
        <vers num="3.4.0" edition=":businessserver" />
        <vers num="3.4.1" edition="" />
        <vers num="3.4.1" edition=":datacenter" />
        <vers num="3.4.1" edition=":businessserver" />
        <vers num="4.5.0" edition="" />
        <vers num="4.5.0" edition=":businessserver" />
        <vers num="4.5.0" edition=":datacenter" />
        <vers num="5.0" edition="" />
        <vers num="5.0" edition=":server" />
        <vers num="5.1" edition="" />
        <vers num="5.1" edition=":enterprise_server" />
        <vers num="5.1" edition=":server" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-1390" published="2004-12-31" name="CVE-2004-1390" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Multiple buffer overflows in the PPPoE daemon (PPPoEd) in QNX RTP 6.1 allow remote attackers to execute arbitrary code via a long argument to the (1) -F, (2) name, (3) en, (4) upscript, (5) downscript, (6) retries, (7) timeout, (8) scriptdetach, (9) noscript, (10) nodetach, (11) remote_mac, or (12) local_mac flags.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/961686" source="CERT-VN" adv="1">VU#961686</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/17280" source="XF">Qnx-rtp-pppoed-flags-bo(17280)</ref>
      <ref url="http://www.securityfocus.com/bid/11104" source="BID">11104</ref>
      <ref url="http://archives.neohapsis.com/archives/fulldisclosure/2004-09/0155.html" source="FULLDISC">20040903 [RLSA_01-2004] QNX PPPoEd local root vulnerabilities</ref>
    </refs>
    <vuln_soft>
      <prod vendor="qnx" name="rtos">
        <vers num="2.4" />
        <vers num="4.25" />
        <vers num="6.1.0" />
        <vers num="6.2.0" />
        <vers num="6.2.0a" />
      </prod>
      <prod vendor="qnx" name="rtp">
        <vers num="6.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1391" published="2004-12-31" name="CVE-2004-1391" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Untrusted execution path vulnerability in the PPPoE daemon (PPPoEd) in QNX RTP 6.1 allows local users to execute arbitrary programs by modifying the PATH environment variable to point to a malicious mount program.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/577566" source="CERT-VN" adv="1">VU#577566</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/17284" source="XF">qnx-rtp-mount-command-execute(17284)</ref>
      <ref url="http://www.securityfocus.com/bid/11105" source="BID">11105</ref>
      <ref url="http://www.osvdb.org/9661" source="OSVDB">9661</ref>
      <ref url="http://archives.neohapsis.com/archives/fulldisclosure/2004-09/0155.html" source="FULLDISC">20040903 [RLSA_01-2004] QNX PPPoEd local root vulnerabilities</ref>
    </refs>
    <vuln_soft>
      <prod vendor="qnx" name="rtos">
        <vers num="6.1.0" />
        <vers num="6.1.0a" />
        <vers num="6.2.0" />
        <vers num="6.2.1a" />
        <vers num="6.2.1b" />
        <vers num="6.3.0" />
      </prod>
      <prod vendor="qnx" name="rtp">
        <vers num="6.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1392" published="2004-12-31" name="CVE-2004-1392" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">PHP 4.0 with cURL functions allows remote attackers to bypass the open_basedir setting and read arbitrary files via a file: URL argument to the curl_init function.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="https://bugzilla.fedora.us/show_bug.cgi?id=2344" source="FEDORA" patch="1">FLSA:2344</ref>
      <ref url="http://www.securityfocus.com/bid/11557" source="BID" patch="1">11557</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110625060220934&amp;w=2" source="BUGTRAQ" patch="1">20050120 [USN-66-1] PHP vulnerabilities</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/17900" source="XF">php-openbasedir-restriction-bypass(17900)</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-406.html" source="REDHAT">RHSA-2005:406</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-405.html" source="REDHAT">RHSA-2005:405</ref>
      <ref url="http://securitytracker.com/id?1011984" source="SECTRACK">1011984</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9279" source="OVAL">oval:org.mitre.oval:def:9279</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109898213806099&amp;w=2" source="BUGTRAQ">20041027 PHP4 cURL functions bypass open_basedir</ref>
    </refs>
    <vuln_soft>
      <prod vendor="php" name="php">
        <vers num="4.0" />
        <vers num="4.0.1" edition="patch1" />
        <vers num="4.0.1" edition="patch2" />
        <vers num="4.0.2" />
        <vers num="4.0.3" edition="patch1" />
        <vers num="4.0.4" />
        <vers num="4.0.5" />
        <vers num="4.0.6" />
        <vers num="4.0.7" edition="rc1" />
        <vers num="4.0.7" edition="rc2" />
        <vers num="4.0.7" edition="rc3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1393" published="2004-12-31" name="CVE-2004-1393" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Unknown vulnerability in the tcsetattr function for Sun Solaris for SPARC 2.6, 7, and 8 allows local users to cause a denial of service (system hang).</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <other />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/379390" source="CERT-VN" adv="1">VU#379390</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-57474-1" source="SUNALERT" patch="1" adv="1">57474</ref>
      <ref url="http://secunia.com/advisories/10730/" source="SECUNIA" patch="1">10730</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/14998" source="XF">solaris-tcsetattr-dos(14998)</ref>
      <ref url="http://www.osvdb.org/3786" source="OSVDB">3786</ref>
      <ref url="http://www.auscert.org.au/render.html?it=3806" source="AUSCERT" adv="1">ESB-2004.0085</ref>
      <ref url="http://www.securityfocus.com/bid/9548" source="BID">9548</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="solaris">
        <vers num="2.6" />
        <vers num="7.0" />
        <vers num="8.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1394" published="2004-12-31" name="CVE-2004-1394" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">The pfexec function for Sun Solaris 8 and 9 does not properly handle when a custom profile contains an invalid entry in the exec_attr database, which may allow local users with custom rights profiles to execute profile commands with additional privileges.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-57453-1" source="SUNALERT" patch="1" adv="1">57453</ref>
      <ref url="http://secunia.com/advisories/10755/" source="SECUNIA" patch="1">10755</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/14988" source="XF">solaris-pfexec-gain-privileges(14988)</ref>
      <ref url="http://www.osvdb.org/3764" source="OSVDB">3764</ref>
      <ref url="http://www.auscert.org.au/render.html?it=3800" source="AUSCERT" adv="1">ESB-2004.0079</ref>
      <ref url="http://www.securitytracker.com/id?1008893" source="SECTRACK">1008893</ref>
      <ref url="http://www.securityfocus.com/bid/9534" source="BID">9534</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="solaris">
        <vers num="8.0" />
        <vers num="9.0" edition="" />
        <vers num="9.0" edition=":sparc" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1395" published="2004-12-31" name="CVE-2004-1395" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The Lithtech engine, as used in (1) Contract Jack 1.1 and earlier, (2) No one lives forever 2 1.3 and earlier, (3) Tron 2.0 1.042 and earlier, (4) F.E.A.R. (First Encounter Assault and Recon), and possibly other games, allows remote attackers to cause a denial of service (connection refused) via a UDP packet that causes recvfrom to generate a return code that causes the listening loop to exit, as demonstrated using zero byte packets or packets between 8193 and 12280 bytes, which result in conditions that are not "Operation would block."</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2004-December/029932.html" source="FULLDISC" patch="1">20041213 Socket unreacheable in the Lithtech engine (new protocol)</ref>
      <ref url="http://aluigi.altervista.org/adv/lithsock-adv.txt" source="MISC" patch="1">http://aluigi.altervista.org/adv/lithsock-adv.txt</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/18456" source="XF">lithtech-engine-communication-dos(18456)</ref>
      <ref url="http://www.securityfocus.com/bid/11902" source="BID">11902</ref>
      <ref url="http://secunia.com/advisories/17317" source="SECUNIA">17317</ref>
      <ref url="http://secunia.com/advisories/13446/" source="SECUNIA">13446</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110297515500671&amp;w=2" source="BUGTRAQ">20041213 Socket unreacheable in the Lithtech engine (new protocol)</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2005-October/038095.html" source="FULLDISC">20051021 F.E.A.R. 1.01 likes lithsock</ref>
    </refs>
    <vuln_soft>
      <prod vendor="monolith_productions" name="contract_jack">
        <vers num="1.1" />
      </prod>
      <prod vendor="monolith_productions" name="no_one_lives_forever_2">
        <vers num="1.0.004" />
        <vers num="1.3" />
      </prod>
      <prod vendor="monolith_productions" name="tron">
        <vers num="2.0.1.0" />
        <vers num="2.0.1.42" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2004-1396" published="2004-12-31" name="CVE-2004-1396" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:N/A:P)" CVSS_score="2.6" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="4.9" CVSS_base_score="2.6">
    <desc>
      <descript source="cve">Winamp 5.07 and possibly other versions, allows remote attackers to cause a denial of service (application crash or CPU consumption) via (1) an mp4 or m4a playlist file that contains invalid tag data or (2) an invalid .nsv or .nsa file.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
      <exception />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/372968" source="CERT-VN">VU#372968</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/18466" source="XF">winamp-mp4-m4a-dos(18466)</ref>
      <ref url="http://www.securityfocus.com/bid/11909" source="BID">11909</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110297310503541&amp;w=2" source="BUGTRAQ">20041213 Winamp 5.07 (latest version) Remote Crash + other stupid shizle</ref>
      <ref url="http://forums.winamp.com/showthread.php?s=&amp;threadid=202007" source="CONFIRM">http://forums.winamp.com/showthread.php?s=&amp;threadid=202007</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/18467" source="XF">winamp-nsa-nsv-dos(18467)</ref>
      <ref url="http://securitytracker.com/alerts/2004/Dec/1012525.html" source="SECTRACK">1012525</ref>
      <ref url="http://marc.theaimsgroup.com/?l=full-disclosure&amp;m=110303988101973&amp;w=2" source="FULLDISC">20041213 Winamp 5.07 (latest version) Remote Crash + other</ref>
    </refs>
    <vuln_soft>
      <prod vendor="nullsoft" name="winamp">
        <vers num="5.07" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1397" published="2004-12-31" name="CVE-2004-1397" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in UseModWiki 1.0 allows remote attackers to inject arbitrary web script or HTML via an argument to wiki.pl.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/18458" source="XF">usemodwiki-wiki-xss(18458)</ref>
      <ref url="http://www.securityfocus.com/bid/11924" source="BID">11924</ref>
      <ref url="http://secunia.com/advisories/13441/" source="SECUNIA">13441</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110305173302388&amp;w=2" source="BUGTRAQ">20041214 STG Security Advisory: [SSA-20041209-13] UseModWiki XSS vulnerability</ref>
    </refs>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1398" published="2004-12-31" name="CVE-2004-1398" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Format string vulnerability in prelink.c in kextload in Apple OS X, as used by TDIXSupport in Roxio Toast Titanium and possibly other products, allows local users to execute arbitrary code via format string specifiers in the extension argument.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/18472" source="XF">roxio-toast-tdixsupport-format-string(18472)</ref>
      <ref url="http://www.securityfocus.com/bid/20031" source="BID">20031</ref>
      <ref url="http://www.securityfocus.com/bid/11926" source="BID">11926</ref>
      <ref url="http://www.netragard.com/pdfs/research/apple-kext-tools-20060822.txt" source="MISC">http://www.netragard.com/pdfs/research/apple-kext-tools-20060822.txt</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110305083706943&amp;w=2" source="BUGTRAQ">20041214 Possible local root vulnerability in Roxio Toast on Mac OS X</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2006-September/049452.html" source="FULLDISC">20060913 [NETRAGARD-20060822 SECURITY ADVISORY] [ APPLE COMPUTER CORPORATION KEXTLOAD VULNERABILITY + ROXIO TOAST TITANUM 7 HELPER APP - LOCAL ROOT COMROMISE]</ref>
    </refs>
    <vuln_soft>
      <prod vendor="roxio" name="toast">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1399" published="2004-12-31" name="CVE-2004-1399" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in the Attachment module 2.3.10 and earlier for phpBB allows remote attackers to read arbitrary files via a .. (dot dot) in the filename.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/11893" source="BID" patch="1">11893</ref>
      <ref url="http://secunia.com/advisories/13421/" source="SECUNIA" patch="1">13421</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/18437" source="XF">attachment-mod-directory-traversal(18437)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110304269031484&amp;w=2" source="BUGTRAQ">20041214 phpBB Attachment Mod Directory Traversal HTTP POST Injection</ref>
    </refs>
    <vuln_soft>
      <prod vendor="opentools" name="attachment_mod">
        <vers num="2.3.10" />
        <vers num="2.3.4" />
        <vers num="2.3.5" />
        <vers num="2.3.6" />
        <vers num="2.3.7" />
        <vers num="2.3.8" />
        <vers num="2.3.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-1400" published="2004-12-31" name="CVE-2004-1400" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">The control panel in ASP Calendar does not require authentication to access, which allows remote attackers to gain unauthorized access via a direct request to main.asp.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/18474" source="XF">asp-calendar-gain-access(18474)</ref>
      <ref url="http://www.securityfocus.com/bid/11931" source="BID">11931</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110304839629822&amp;w=2" source="BUGTRAQ">20041214 ASP Calendar Vulnerability &lt;www.ashiyane.com></ref>
    </refs>
    <vuln_soft>
      <prod vendor="active_server_corner" name="asp_calendar">
        <vers num="1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-1401" published="2004-12-31" name="CVE-2004-1401" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in verify.asp in Asp-rider allows remote attackers to execute arbitrary SQL statements and bypass authentication via the username parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/18479" source="XF" patch="1">asp-rider-verify-sql-injection(18479)</ref>
      <ref url="http://secunia.com/advisories/13470/" source="SECUNIA" patch="1">13470</ref>
      <ref url="http://www.securityfocus.com/bid/11933" source="BID">11933</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110305802005220&amp;w=2" source="BUGTRAQ">20041214 ASP-rider is vulnerable to sql injection attack</ref>
    </refs>
    <vuln_soft>
      <prod vendor="asp-rider" name="asp-rider">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-1402" published="2004-12-31" name="CVE-2004-1402" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">SQL injection vulnerability in iWebNegar allows remote attackers to execute arbitrary SQL commands via (1) the string parameter for index.php, (2) comments.php, or (3) the administrator login page.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/18505" source="XF">iwebnegar-sql-injection(18505)</ref>
      <ref url="http://www.securityfocus.com/bid/11946" source="BID">11946</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110314454810163&amp;w=2" source="BUGTRAQ">20041215 iwebnegar is vulnerable to all kind of sql injections</ref>
    </refs>
    <vuln_soft>
      <prod vendor="iwebnegar" name="iwebnegar">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-1403" published="2004-12-31" name="CVE-2004-1403" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">PHP remote file inclusion vulnerability in index.php in GNUBoard 3.39 and earlier allows remote attackers to execute arbitrary PHP code by modifying the doc parameter to reference a URL on a remote web server that contains the code.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/13479/" source="SECUNIA" patch="1">13479</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110313585810712&amp;w=2" source="BUGTRAQ" patch="1">20041215 STG Security Advisory: [SSA-20041214-14] GNUBoard PHP injection vulnerability</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/18494" source="XF">gnuboard-doc-index-file-include(18494)</ref>
      <ref url="http://www.securityfocus.com/bid/11948" source="BID">11948</ref>
      <ref url="http://sir.co.kr/?doc=bbs/gnuboard.php&amp;bo_table=pds&amp;page=1&amp;wr_id=1871" source="MISC">http://sir.co.kr/?doc=bbs/gnuboard.php&amp;bo_table=pds&amp;page=1&amp;wr_id=1871</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sir" name="gnuboard">
        <vers num="3.30" />
        <vers num="3.31" />
        <vers num="3.32" />
        <vers num="3.33" />
        <vers num="3.34" />
        <vers num="3.35" />
        <vers num="3.36" />
        <vers num="3.37" />
        <vers num="3.38" />
        <vers num="3.39" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-1404" published="2004-12-31" name="CVE-2004-1404" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Attachment Mod 2.3.10 module for phpBB, when used with Apache mod_mime, does not properly handle files with multiple file extensions, such as .php.rar, which allows remote attackers to upload and execute arbitrary code.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/11893" source="BID" patch="1">11893</ref>
      <ref url="http://www.opentools.de/board/viewtopic.php?t=3590" source="CONFIRM" patch="1">http://www.opentools.de/board/viewtopic.php?t=3590</ref>
      <ref url="http://secunia.com/advisories/13421/" source="SECUNIA" patch="1">13421</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110321557806215&amp;w=2" source="BUGTRAQ" patch="1">20041216 STG Security Advisory: [SSA-20041215-18] Vulnerability of uploading files with multiple extensions in phpBB Attachment Mod</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/18438" source="XF">attachment-mod-file-upload(18438)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="opentools" name="attachment_mod">
        <vers num="2.3.10" />
        <vers num="2.3.4" />
        <vers num="2.3.5" />
        <vers num="2.3.6" />
        <vers num="2.3.7" />
        <vers num="2.3.8" />
        <vers num="2.3.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-1405" published="2004-12-31" name="CVE-2004-1405" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">MediaWiki 1.3.8 and earlier, when used with Apache mod_mime, does not properly handle files with two file extensions, such as .php.rar, which allows remote attackers to upload and execute arbitrary code.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/11985" source="BID" patch="1">11985</ref>
      <ref url="http://wikipedia.sourceforge.net/" source="MISC" patch="1">http://wikipedia.sourceforge.net/</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110321710420059&amp;w=2" source="BUGTRAQ" patch="1">20041216 STG Security Advisory: [SSA-20041215-19] Vulnerability of uploading files with multiple extensions in MediaWiki</ref>
      <ref url="http://secunia.com/advisories/13478/" source="SECUNIA">13478</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mediawiki" name="mediawiki">
        <vers num="1.3" />
        <vers num="1.3.0" />
        <vers num="1.3.1" />
        <vers num="1.3.10" />
        <vers num="1.3.11" />
        <vers num="1.3.2" />
        <vers num="1.3.3" />
        <vers num="1.3.4" />
        <vers num="1.3.5" />
        <vers num="1.3.6" />
        <vers num="1.3.7" />
        <vers num="1.3.8" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-1406" published="2004-12-31" name="CVE-2004-1406" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in ikonboard.cgi in Ikonboard 3.1.0 through 3.1.3 allows remote attackers to inject arbitrary SQL commands via the (1) st or (2) keywords parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/11982" source="BID" patch="1">11982</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/18533" source="XF">ikonboard-ikonboard-sql-injection(18533)</ref>
      <ref url="http://secunia.com/advisories/13513" source="SECUNIA">13513</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110321654705580&amp;w=2" source="BUGTRAQ">20041216 [MaxPatrol] SQL-injection in Ikonboard 3.1.x</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ikonboard.com" name="ikonboard">
        <vers num="3.0.1" />
        <vers num="3.1.1" />
        <vers num="3.1.2a" />
        <vers num="3.1.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1407" published="2004-12-31" name="CVE-2004-1407" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Multiple directory traversal vulnerabilities in singapore Image Gallery Web Application 0.9.10 allow remote attackers to (1) read arbitrary files via the showThumb method for thumb.php, or (2) delete arbitrary files via admin.class.php.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/11990" source="BID" patch="1">11990</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/18532" source="XF">singapore-adminclass-directory-traversal(18532)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/18528" source="XF">singapore-thumb-directory-traversal(18528)</ref>
      <ref url="http://www.security.org.sg/vuln/singapore0910.html" source="MISC">http://www.security.org.sg/vuln/singapore0910.html</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110323479715051&amp;w=2" source="BUGTRAQ">20041216 [SIG^2 G-TEC] singapore Image Gallery Web Application v0.9.10 Multiple Vulnerabilities</ref>
    </refs>
    <vuln_soft>
      <prod vendor="singapore" name="image_gallery_web_application">
        <vers num="0.9.10" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-1408" published="2004-12-31" name="CVE-2004-1408" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">The addImage method for admin.class.php in Image Gallery Web Application 0.9.10 does not properly check filenames, which allows remote attackers to upload and execute arbitrary files.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/11990" source="BID" patch="1">11990</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/18531" source="XF">singapore-adminclass-file-upload(18531)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110323479715051&amp;w=2" source="BUGTRAQ">20041216 [SIG^2 G-TEC] singapore Image Gallery Web Application v0.9.10 Multiple Vulnerabilities</ref>
    </refs>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1409" published="2004-12-31" name="CVE-2004-1409" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Multiple cross-site scripting vulnerabilities in Image Gallery Web Application 0.9.10 allow remote attackers to inject arbitrary web script or HTML.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/11990" source="BID" patch="1">11990</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110323479715051&amp;w=2" source="BUGTRAQ">20041216 [SIG^2 G-TEC] singapore Image Gallery Web Application v0.9.10 Multiple Vulnerabilities</ref>
    </refs>
    <vuln_soft>
      <prod vendor="singapore" name="image_gallery_web_application">
        <vers num="0.9.10" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1410" published="2004-12-31" name="CVE-2004-1410" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in Gadu-Gadu build 155 and earlier allows remote attackers to inject arbitrary web script via a URL, which is echoed in a popup window that displays a parsing error message, a different vulnerability than CVE-2004-1229.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110330741828726&amp;w=2" source="BUGTRAQ">20041217 Gadu-Gadu, another two bugs</ref>
      <ref url="http://www.securityfocus.com/bid/11998" source="BID">11998</ref>
      <ref url="http://www.osvdb.org/12524" source="OSVDB">12524</ref>
      <ref url="http://secunia.com/advisories/13450" source="SECUNIA">13450</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gadu-gadu" name="gadu-gadu_instant_messenger">
        <vers num="6.0_build149" />
        <vers num="6.0_build150" />
        <vers num="6.0_build151" />
        <vers num="6.0_build152" />
        <vers num="6.0_build153" />
        <vers num="6.0_build154" />
        <vers num="6.0_build155" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2004-1411" published="2004-12-31" name="CVE-2004-1411" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:N/A:P)" CVSS_score="2.6" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="4.9" CVSS_base_score="2.6">
    <desc>
      <descript source="cve">Gadu-Gadu build 155 and earlier allows remote attackers to cause a denial of service (infinite loop) via a message that contains an image whose filename does not start with restricted characters.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/18580" source="XF">gadu-gadu-image-dos(18580)</ref>
      <ref url="http://www.securityfocus.com/bid/11998" source="BID">11998</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110330741828726&amp;w=2" source="BUGTRAQ">20041217 Gadu-Gadu, another two bugs</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gadu-gadu" name="gadu-gadu_instant_messenger">
        <vers num="6.0_build149" />
        <vers num="6.0_build150" />
        <vers num="6.0_build151" />
        <vers num="6.0_build152" />
        <vers num="6.0_build153" />
        <vers num="6.0_build154" />
        <vers num="6.0_build155" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1412" published="2004-12-31" name="CVE-2004-1412" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in index.php in Kayako eSupport 2.x allows remote attackers to inject arbitrary web script or HTML via the searchm parameter.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/18571" source="XF">kayako-index-xss(18571)</ref>
      <ref url="http://www.securityfocus.com/bid/12037" source="BID">12037</ref>
      <ref url="http://www.gulftech.org/?node=research&amp;article_id=00056-12182004" source="MISC">http://www.gulftech.org/?node=research&amp;article_id=00056-12182004</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110352428607171&amp;w=2" source="BUGTRAQ">20041218 Multiple Vulnerabilities In Kayako eSupport v2.x</ref>
    </refs>
    <vuln_soft>
      <prod vendor="kayako" name="esupport">
        <vers num="2.1.2" />
        <vers num="2.1.8" />
        <vers num="2.2" />
        <vers num="2.2.5" />
        <vers num="2.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1413" published="2004-12-31" name="CVE-2004-1413" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Multiple SQL injection vulnerabilities in Kayako eSupport 2.x allow remote attackers to execute arbitrary SQL commands via the (1) subcat, (2) rate, (3) questiondetails, (4) ticketkey22, (5) email22 parameters to index.php, or (6) the e-mail field of the Forgot Key feature.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/18572" source="XF">kayako-sql-injection(18572)</ref>
      <ref url="http://www.securityfocus.com/bid/12037" source="BID">12037</ref>
      <ref url="http://www.gulftech.org/?node=research&amp;article_id=00056-12182004" source="MISC">http://www.gulftech.org/?node=research&amp;article_id=00056-12182004</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110352428607171&amp;w=2" source="BUGTRAQ">20041218 Multiple Vulnerabilities In Kayako eSupport v2.x</ref>
    </refs>
    <vuln_soft>
      <prod vendor="kayako" name="esupport">
        <vers num="2.1.2" />
        <vers num="2.1.8" />
        <vers num="2.2" />
        <vers num="2.2.5" />
        <vers num="2.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1414" published="2004-12-31" name="CVE-2004-1414" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Gadu-Gadu 6.1 build 156 allows remote attackers to cause a denial of service (application hang) via a message that contains many special strings that are converted to images.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.soltysiak.com/gg-dos.txt" source="MISC">http://www.soltysiak.com/gg-dos.txt</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110357519312200&amp;w=2" source="BUGTRAQ">20041220 Gadu-Gadu Remote DoS (all versions)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gadu-gadu" name="gadu-gadu_instant_messenger">
        <vers num="6.1_build156" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1415" published="2004-12-31" name="CVE-2004-1415" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">SQL injection vulnerability in (1) disp_album.php and possibly (2) disp_img.php in 2Bgal 2.4 and 2.5.1 allows remote attackers to execute arbitrary SQL commands via the id_album parameter.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/12083" source="BID" patch="1">12083</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/18645" source="XF">2bgal-dispalbum-sql-injection(18645)</ref>
      <ref url="http://secunia.com/advisories/13620" source="SECUNIA">13620</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110375900916558&amp;w=2" source="BUGTRAQ">20041222 2Bgal : 2.4 &amp; 2.5.1 SQL injection Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ben3w" name="2bgal">
        <vers num="2.4" />
        <vers num="2.5.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1416" published="2004-12-31" name="CVE-2004-1416" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_score="5.1" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="4.9" CVSS_base_score="5.1">
    <desc>
      <descript source="cve">pnxr3260.dll in the RealOne 2.0 build 6.0.11.868 browser plugin, as used in Internet Explorer, allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a crafted embed tag.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.osvdb.org/12660" source="OSVDB">12660</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110374765215675&amp;w=2" source="BUGTRAQ">20041222 Realone2.0 "pnxr3260.dll" Lets Remote Users IE  Browser Crash</ref>
    </refs>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1417" published="2004-12-31" name="CVE-2004-1417" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in login.php in PsychoStats 2.2.4 Beta and earlier allows remote attackers to inject arbitrary web script or HTML via the login parameter.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/12089" source="BID" patch="1">12089</ref>
      <ref url="http://www.psychostats.com/forums/viewtopic.php?t=11022" source="MISC" patch="1">http://www.psychostats.com/forums/viewtopic.php?t=11022</ref>
      <ref url="http://www.gulftech.org/?node=research&amp;article_id=00057-12222004" source="MISC" patch="1">http://www.gulftech.org/?node=research&amp;article_id=00057-12222004</ref>
      <ref url="http://secunia.com/advisories/13619/" source="SECUNIA" patch="1">13619</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110383119525592&amp;w=2" source="BUGTRAQ" patch="1">20041223 Cross Site Scripting In PsychoStats 2.2.4 Beta &amp;&amp; Earlier</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/18651" source="XF">psychostats-login-xss(18651)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="psychostats" name="psychostats">
        <vers num="2.0.1_beta" />
        <vers num="2.0_beta" />
        <vers num="2.1_beta" />
        <vers num="2.2.1_beta" />
        <vers num="2.2.2_beta" />
        <vers num="2.2.4_beta" />
        <vers num="2.2_beta" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1418" published="2004-12-31" name="CVE-2004-1418" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in WPKontakt 3.0.1 and earlier allows remote attackers to inject arbitrary web script or HTML via an e-mail address, which is not quoted when a parsing error is generated.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/12097" source="BID" patch="1">12097</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110384387332443&amp;w=2" source="BUGTRAQ" patch="1">20041223 WPkontakt message parsing error</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/18685" source="XF">wpkontakt-email-command-execution(18685)</ref>
    </refs>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1419" published="2004-12-31" name="CVE-2004-1419" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">PHP remote file inclusion vulnerability in ZeroBoard 4.1pl4 and earlier allows remote attackers to execute arbitrary PHP code by modifying the (1) _zb_path parameter to outlogin.php or (2) dir parameter to write.php to reference a URL on a remote web server that contains the code.</descript>
      <descript source="nvd">requires that register_globals be enabled</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110391024404947&amp;w=2" source="BUGTRAQ" patch="1">20041224 STG Security Advisory: [SSA-20041220-16] PHP source injection and cross-site scripting vulnerabilities in ZeroBoard</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2004-December/030224.html" source="FULLDISC" patch="1">20041223 STG Security Advisory: [SSA-20041220-16] PHP source injection and cross-site scripting vulnerabilities in ZeroBoard</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/18679" source="XF">zeroboard-write-file-include(18679)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/18677" source="XF">zeroboard-outlogin-file-include(18677)</ref>
      <ref url="http://www.securityfocus.com/bid/12103" source="BID">12103</ref>
      <ref url="http://www.osvdb.org/12581" source="OSVDB">12581</ref>
      <ref url="http://www.osvdb.org/12580" source="OSVDB">12580</ref>
      <ref url="http://securitytracker.com/id?1012677" source="SECTRACK">1012677</ref>
      <ref url="http://secunia.com/advisories/13649" source="SECUNIA">13649</ref>
    </refs>
    <vuln_soft>
      <prod vendor="zeroboard" name="zeroboard">
        <vers num="4.1_pl2" />
        <vers num="4.1_pl3" />
        <vers num="4.1_pl4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1420" published="2004-12-31" name="CVE-2004-1420" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in header.php in WHM AutoPilot 2.4.6.5 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) site_title or (2) http_images parameter.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.whmautopilot.com/forum/lofiversion/index.php/t6785.html" source="CONFIRM" patch="1" adv="1">http://www.whmautopilot.com/forum/lofiversion/index.php/t6785.html</ref>
      <ref url="http://secunia.com/advisories/13673" source="SECUNIA" patch="1">13673</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/18700" source="XF">whm-autopilot-header-xss(18700)</ref>
      <ref url="http://www.securityfocus.com/bid/12119" source="BID">12119</ref>
      <ref url="http://www.gulftech.org/?node=research&amp;article_id=00059-12272004" source="MISC">http://www.gulftech.org/?node=research&amp;article_id=00059-12272004</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110451997904494&amp;w=2" source="BUGTRAQ">20041231 WHM AutoPilot Security Release [ Plus Upgrade Instructions ]</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110425620105529&amp;w=2" source="BUGTRAQ">20041228 Multiple WHM Autopilot Vulnerabilities</ref>
    </refs>
    <vuln_soft>
      <prod vendor="whm" name="autopilot">
        <vers num="2.4.5" />
        <vers num="2.4.6" />
        <vers num="2.4.6.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-1421" published="2004-12-31" name="CVE-2004-1421" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple PHP remote file inclusion vulnerabilities (1) step_one.php, (2) step_one_tables.php, (3) step_two_tables.php in WHM AutoPilot 2.4.6.5 and earlier allow remote attackers to execute arbitrary PHP code by modifying the server_inc parameter to reference a URL on a remote web server that contains the code.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.whmautopilot.com/forum/lofiversion/index.php/t6785.html" source="CONFIRM" patch="1" adv="1">http://www.whmautopilot.com/forum/lofiversion/index.php/t6785.html</ref>
      <ref url="http://www.gulftech.org/?node=research&amp;article_id=00059-12272004" source="MISC" patch="1">http://www.gulftech.org/?node=research&amp;article_id=00059-12272004</ref>
      <ref url="http://secunia.com/advisories/13673" source="SECUNIA" patch="1">13673</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110451997904494&amp;w=2" source="BUGTRAQ" patch="1">20041231 WHM AutoPilot Security Release [ Plus Upgrade Instructions ]</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/18699" source="XF">whm-autopilot-php-file-include(18699)</ref>
      <ref url="http://www.securityfocus.com/bid/12119" source="BID">12119</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110425620105529&amp;w=2" source="BUGTRAQ">20041228 Multiple WHM Autopilot Vulnerabilities</ref>
      <ref url="http://www.osvdb.org/12695" source="OSVDB">12695</ref>
      <ref url="http://securitytracker.com/id?1012707" source="SECTRACK">1012707</ref>
    </refs>
    <vuln_soft>
      <prod vendor="whm" name="whm_autopilot">
        <vers num="2.4.5" />
        <vers num="2.4.6" />
        <vers num="2.4.6.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1422" published="2004-12-31" name="CVE-2004-1422" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">WHM AutoPilot 2.4.6.5 and earlier allows remote attackers to gain sensitive information via phpinfo, which reveals php settings.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.whmautopilot.com/forum/lofiversion/index.php/t6785.html" source="CONFIRM" patch="1" adv="1">http://www.whmautopilot.com/forum/lofiversion/index.php/t6785.html</ref>
      <ref url="http://secunia.com/advisories/13673" source="SECUNIA" patch="1">13673</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/18701" source="XF">whm-autopilot-information-disclosure(18701)</ref>
      <ref url="http://www.securityfocus.com/bid/12119" source="BID">12119</ref>
      <ref url="http://www.gulftech.org/?node=research&amp;article_id=00059-12272004" source="MISC">http://www.gulftech.org/?node=research&amp;article_id=00059-12272004</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110451997904494&amp;w=2" source="BUGTRAQ">20041231 WHM AutoPilot Security Release [ Plus Upgrade Instructions ]</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110425620105529&amp;w=2" source="BUGTRAQ">20041228 Multiple WHM Autopilot Vulnerabilities</ref>
    </refs>
    <vuln_soft>
      <prod vendor="whm" name="whm_autopilot">
        <vers num="2.4.5" />
        <vers num="2.4.6" />
        <vers num="2.4.6.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-1423" published="2004-12-31" name="CVE-2004-1423" modified="2011-09-08" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple PHP remote file inclusion vulnerabilities in Sean Proctor PHP-Calendar before 0.10.1, as used in Commonwealth of Massachusetts Virtual Law Office (VLO) and other products, allow remote attackers to execute arbitrary PHP code via a URL in the phpc_root_path parameter to (1) includes/calendar.php or (2) includes/setup.php.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.gulftech.org/?node=research&amp;article_id=00060-12292004" source="MISC" patch="1">http://www.gulftech.org/?node=research&amp;article_id=00060-12292004</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110434580716205&amp;w=2" source="BUGTRAQ" patch="1">20041229 php-Calendar File Include Vulnerability [ Command Exec ]</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/29710" source="XF">vlo-phpcrootpath-file-include(29710)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/18710" source="XF">php-calendar-file-include(18710)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/4145" source="VUPEN" adv="1">ADV-2006-4145</ref>
      <ref url="http://www.securityfocus.com/bid/20657" source="BID">20657</ref>
      <ref url="http://www.securityfocus.com/bid/12127" source="BID">12127</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/449397/100/0/threaded" source="BUGTRAQ">20061021 Virtual Law Office (phpc_root_path) Remote File Include Vulnerability</ref>
      <ref url="http://www.milw0rm.com/exploits/2608" source="MILW0RM">2608</ref>
      <ref url="http://sourceforge.net/project/shownotes.php?release_id=296020&amp;group_id=46800" source="CONFIRM">http://sourceforge.net/project/shownotes.php?release_id=296020&amp;group_id=46800</ref>
      <ref url="http://securitytracker.com/id?1017107" source="SECTRACK">1017107</ref>
      <ref url="http://secunia.com/advisories/22516" source="SECUNIA">22516</ref>
    </refs>
    <vuln_soft>
      <prod vendor="php-calendar" name="php-calendar">
        <vers num="0.1" />
        <vers prev="1" num="0.10" />
        <vers num="0.2" />
        <vers num="0.3" />
        <vers num="0.4" />
        <vers num="0.5" />
        <vers num="0.6" />
        <vers num="0.7" />
        <vers num="0.8" />
        <vers num="0.9" />
        <vers num="0.9.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1424" published="2004-12-31" name="CVE-2004-1424" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in view.php in Moodle 1.4.2 and earlier allows remote attackers to inject arbitrary web script or HTML via the search parameter.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/12120" source="BID" patch="1">12120</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/18702" source="XF">moodle-view-search-xss(18702)</ref>
      <ref url="http://secunia.com/advisories/13694" source="SECUNIA" adv="1">13694</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110444531816566&amp;w=2" source="BUGTRAQ">20041230 Re: Multiple Vulnerabilities in Moodle</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110425409614735&amp;w=2" source="BUGTRAQ">20041227 Multiple Vulnerabilities in Moodle</ref>
    </refs>
    <vuln_soft>
      <prod vendor="moodle" name="moodle">
        <vers num="1.1.1" />
        <vers num="1.2" />
        <vers num="1.2.1" />
        <vers num="1.3" />
        <vers num="1.3.1" />
        <vers num="1.3.2" />
        <vers num="1.3.3" />
        <vers num="1.3.4" />
        <vers num="1.4.1" />
        <vers num="1.4.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1425" published="2004-12-31" name="CVE-2004-1425" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in file.php in Moodle 1.4.2 and earlier allows remote attackers to read arbitrary session files for known session IDs via a .. (dot dot) in the file parameter.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/12120" source="BID" patch="1">12120</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/18550" source="XF">moodle-directory-traversal(18550)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110444531816566&amp;w=2" source="BUGTRAQ">20041230 Re: Multiple Vulnerabilities in Moodle</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110425409614735&amp;w=2" source="BUGTRAQ">20041227 Multiple Vulnerabilities in Moodle</ref>
    </refs>
    <vuln_soft>
      <prod vendor="moodle" name="moodle">
        <vers num="1.1.1" />
        <vers num="1.2" />
        <vers num="1.2.1" />
        <vers num="1.3" />
        <vers num="1.3.1" />
        <vers num="1.3.2" />
        <vers num="1.3.3" />
        <vers num="1.3.4" />
        <vers num="1.4.1" />
        <vers num="1.4.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1426" published="2004-12-31" name="CVE-2004-1426" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in index.php in KorWeblog 1.6.2-cvs and earlier allows remote attackers to read arbitrary files and execute arbitrary PHP files via .. (dot dot) sequences in the lng parameter.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110442847614890&amp;w=2" source="BUGTRAQ" patch="1">20041230 KorWeblog php injection Vulnerability</ref>
      <ref url="http://www.securityfocus.com/bid/12132" source="BID">12132</ref>
    </refs>
    <vuln_soft>
      <prod vendor="korweblog" name="korweblog">
        <vers num="1.6.1" />
        <vers num="1.6.2cvs" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-1427" published="2004-12-31" name="CVE-2004-1427" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">PHP remote file inclusion vulnerability in main.inc in KorWeblog 1.6.2-cvs and earlier allows remote attackers to execute arbitrary PHP code by modifying the G_PATH parameter to reference a URL on a remote web server that contains the code, as demonstrated in index.php when using .. (dot dot) sequences in the lng parameter to cause main.inc to be loaded.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110442847614890&amp;w=2" source="BUGTRAQ" patch="1">20041230 KorWeblog php injection Vulnerability</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/18717" source="XF">korweblog-install-file-include(18717)</ref>
      <ref url="http://www.securityfocus.com/bid/12132" source="BID">12132</ref>
      <ref url="http://secunia.com/advisories/13700" source="SECUNIA">13700</ref>
    </refs>
    <vuln_soft>
      <prod vendor="korweblog" name="korweblog">
        <vers num="1.6.1" />
        <vers num="1.6.2cvs" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1428" published="2004-12-31" name="CVE-2004-1428" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">ArGoSoft FTP before 1.4.2.1 generates an error message if the user name does not exist instead of prompting for a password, which allows remote attackers to determine valid usernames.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/18721" source="XF">argosoft-information-disclosure(18721)</ref>
      <ref url="http://www.securityfocus.com/bid/12139" source="BID">12139</ref>
      <ref url="http://www.lovebug.org/argosoft_advisory.txt" source="MISC">http://www.lovebug.org/argosoft_advisory.txt</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110451582011666&amp;w=2" source="BUGTRAQ">20041231 ArGoSoft FTP Server reveals valid usernames and allows for brute force attacks</ref>
      <ref url="http://www.osvdb.org/11335" source="OSVDB">11335</ref>
      <ref url="http://www.argosoft.com/ftpserver/changelist.aspx" source="CONFIRM">http://www.argosoft.com/ftpserver/changelist.aspx</ref>
      <ref url="http://securitytracker.com/id?1012744" source="SECTRACK">1012744</ref>
      <ref url="http://secunia.com/advisories/13063" source="SECUNIA">13063</ref>
    </refs>
    <vuln_soft>
      <prod vendor="argosoft" name="ftp_server">
        <vers num="1.4.1.1" />
        <vers num="1.4.1.2" />
        <vers num="1.4.1.3" />
        <vers num="1.4.1.4" />
        <vers num="1.4.1.5" />
        <vers num="1.4.1.6" />
        <vers num="1.4.1.7" />
        <vers num="1.4.1.8" />
        <vers num="1.4.1.9" />
        <vers num="1.4.2" />
        <vers num="1.4.2.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-1429" published="2004-12-31" name="CVE-2004-1429" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">ArGoSoft FTP 1.4.2.4 and earlier does not limit the number of times that a bad password can be entered, which makes it easier for remote attackers to guess passwords via a brute force attack.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/18722" source="XF">argosoft-bruteforce(18722)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110451582011666&amp;w=2" source="BUGTRAQ">20041231 ArGoSoft FTP Server reveals valid usernames and allows for brute</ref>
    </refs>
    <vuln_soft>
      <prod vendor="argosoft" name="ftp_server">
        <vers num="1.4.1.1" />
        <vers num="1.4.1.2" />
        <vers num="1.4.1.3" />
        <vers num="1.4.1.4" />
        <vers num="1.4.1.5" />
        <vers num="1.4.1.6" />
        <vers num="1.4.1.7" />
        <vers num="1.4.1.8" />
        <vers num="1.4.1.9" />
        <vers num="1.4.2" />
        <vers num="1.4.2.1" />
        <vers prev="1" num="1.4.2.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-1430" published="2004-12-31" name="CVE-2004-1430" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in the show_stats module in Arcade.php in IbProArcade allows remote attackers to execute arbitrary SQL code via the gameid parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110451448630711&amp;w=2" source="BUGTRAQ" patch="1">20041231 SQL Injection Vulnerability In IBProArcade</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/18720" source="XF">ibproarcade-gameid-sql-injection(18720)</ref>
      <ref url="http://www.securityfocus.com/bid/12138" source="BID">12138</ref>
      <ref url="http://secunia.com/advisories/13260" source="SECUNIA">13260</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ipbproarcade" name="ipbproarcade">
        <vers num="2.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1431" published="2004-12-31" name="CVE-2004-1431" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">FormMail.php 5.0, and possibly other versions, allows remote attackers to read arbitrary files via a full pathname in the ar_file (auto-reply) parameter.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110460092827419&amp;w=2" source="BUGTRAQ" patch="1">20041231 Jacks FormMail.php remote file access vulnerability</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/18724" source="XF">jack-formmail-arfile-view-files(18724)</ref>
      <ref url="http://www.securityfocus.com/bid/12145" source="BID">12145</ref>
      <ref url="http://secunia.com/advisories/10815" source="SECUNIA">10815</ref>
    </refs>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1432" published="2004-12-31" name="CVE-2004-1432" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Multiple versions of Cisco ONS 15327, ONS 15454, and ONS 15454 SDH, including 4.6(0) and 4.6(1), 4.5(x), 4.1(0) to 4.1(3), 4.0(0) to 4.0(2), and earlier versions, allows remote attackers to cause a denial of service (control card reset) via malformed (1) IP or (2) ICMP packets.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/969344" source="CERT-VN" adv="1">VU#969344</ref>
      <ref url="http://www.kb.cert.org/vuls/id/918920" source="CERT-VN" adv="1">VU#918920</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/16761" source="XF">cisco-ons-icmp-dos(16761)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/16760" source="XF">cisco-ons-ip-dos(16760)</ref>
      <ref url="http://www.securityfocus.com/bid/10768" source="BID">10768</ref>
      <ref url="http://www.cisco.com/warp/public/707/cisco-sa-20040721-ons.shtml" source="CISCO" adv="1">20040721 Cisco ONS 15327, ONS 15454, ONS 15454 SDH, and ONS 15600 Malformed Packet Vulnerabilities</ref>
      <ref url="http://secunia.com/advisories/12117" source="SECUNIA">12117</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="ons_15327">
        <vers num="3.0" />
        <vers num="3.1" />
        <vers num="3.2" />
        <vers num="3.3" />
        <vers num="3.4" />
        <vers num="4.0" />
        <vers num="4.0(1)" />
        <vers num="4.0(2)" />
        <vers num="4.1(0)" />
        <vers num="4.1(1)" />
        <vers num="4.1(2)" />
        <vers num="4.1(3)" />
        <vers num="4.6(0)" />
        <vers num="4.6(1)" />
      </prod>
      <prod vendor="cisco" name="ons_15454_optical_transport_platform">
        <vers num="2.3(5)" />
        <vers num="3.0" />
        <vers num="3.1.0" />
        <vers num="3.2.0" />
        <vers num="3.3" />
        <vers num="3.4" />
        <vers num="4.0" />
        <vers num="4.0(1)" />
        <vers num="4.0(2)" />
        <vers num="4.1(0)" />
        <vers num="4.1(1)" />
        <vers num="4.1(2)" />
        <vers num="4.1(3)" />
        <vers num="4.5" />
        <vers num="4.6(0)" />
        <vers num="4.6(1)" />
      </prod>
      <prod vendor="cisco" name="ons_15454sdh">
        <vers num="2.3(5)" />
        <vers num="3.1" />
        <vers num="3.2" />
        <vers num="3.3" />
        <vers num="3.4" />
        <vers num="4.0(0)" />
        <vers num="4.0(1)" />
        <vers num="4.0(2)" />
        <vers num="4.1(0)" />
        <vers num="4.1(1)" />
        <vers num="4.1(2)" />
        <vers num="4.1(3)" />
        <vers num="4.5" />
        <vers num="4.6(0)" />
        <vers num="4.6(1)" />
      </prod>
      <prod vendor="cisco" name="ons_15600">
        <vers num="1.0" />
        <vers num="1.1" />
        <vers num="1.1(0)" />
        <vers num="1.1(1)" />
        <vers num="1.3(0)" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1433" published="2004-12-31" name="CVE-2004-1433" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Multiple versions of Cisco ONS 15327, ONS 15454, and ONS 15454 SDH, including 4.6(0) and 4.6(1), 4.5(x), 4.1(0) to 4.1(3), 4.0(0) to 4.0(2), and earlier versions, and ONS 15600 1.x(x), allows remote attackers to cause a denial of service (control card reset) via malformed (1) TCP and (2) UDP packets.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/800384" source="CERT-VN" adv="1">VU#800384</ref>
      <ref url="http://www.kb.cert.org/vuls/id/486224" source="CERT-VN" adv="1">VU#486224</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/16764" source="XF">cisco-ons-udp-dos(16764)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/16762" source="XF">cisco-ons-tcp-dos(16762)</ref>
      <ref url="http://www.securityfocus.com/bid/10768" source="BID">10768</ref>
      <ref url="http://www.cisco.com/warp/public/707/cisco-sa-20040721-ons.shtml" source="CISCO" adv="1">20040721 Cisco ONS 15327, ONS 15454, ONS 15454 SDH, and ONS 15600 Malformed Packet Vulnerabilities</ref>
      <ref url="http://secunia.com/advisories/12117" source="SECUNIA">12117</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="ons_15327">
        <vers num="3.0" />
        <vers num="3.1" />
        <vers num="3.2" />
        <vers num="3.3" />
        <vers num="3.4" />
        <vers num="4.0" />
        <vers num="4.0(1)" />
        <vers num="4.0(2)" />
        <vers num="4.1(0)" />
        <vers num="4.1(1)" />
        <vers num="4.1(2)" />
        <vers num="4.1(3)" />
        <vers num="4.6(0)" />
        <vers num="4.6(1)" />
      </prod>
      <prod vendor="cisco" name="ons_15454_optical_transport_platform">
        <vers num="2.3(5)" />
        <vers num="3.0" />
        <vers num="3.1.0" />
        <vers num="3.2.0" />
        <vers num="3.3" />
        <vers num="3.4" />
        <vers num="4.0" />
        <vers num="4.0(1)" />
        <vers num="4.0(2)" />
        <vers num="4.1(0)" />
        <vers num="4.1(1)" />
        <vers num="4.1(2)" />
        <vers num="4.1(3)" />
        <vers num="4.5" />
        <vers num="4.6(0)" />
        <vers num="4.6(1)" />
      </prod>
      <prod vendor="cisco" name="ons_15454sdh">
        <vers num="2.3(5)" />
        <vers num="3.1" />
        <vers num="3.2" />
        <vers num="3.3" />
        <vers num="3.4" />
        <vers num="4.0(0)" />
        <vers num="4.0(1)" />
        <vers num="4.0(2)" />
        <vers num="4.1(0)" />
        <vers num="4.1(1)" />
        <vers num="4.1(2)" />
        <vers num="4.1(3)" />
        <vers num="4.5" />
        <vers num="4.6(0)" />
        <vers num="4.6(1)" />
      </prod>
      <prod vendor="cisco" name="ons_15600">
        <vers num="1.0" />
        <vers num="1.1" />
        <vers num="1.1(0)" />
        <vers num="1.1(1)" />
        <vers num="1.3(0)" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1434" published="2004-12-31" name="CVE-2004-1434" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Multiple versions of Cisco ONS 15327, ONS 15454, and ONS 15454 SDH, including 4.1(0) to 4.1(2), 4.5(x), 4.0(0) to 4.0(2), and earlier versions, allows remote attackers to cause a denial of service (control card reset) via malformed SNMP packets.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/548968" source="CERT-VN">VU#548968</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/16765" source="XF">cisco-ons-snmp-dos(16765)</ref>
      <ref url="http://www.securityfocus.com/bid/10768" source="BID">10768</ref>
      <ref url="http://www.cisco.com/warp/public/707/cisco-sa-20040721-ons.shtml" source="CISCO" adv="1">20040721 Cisco ONS 15327, ONS 15454, ONS 15454 SDH, and ONS 15600 Malformed Packet Vulnerabilities</ref>
      <ref url="http://secunia.com/advisories/12117" source="SECUNIA">12117</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="ons_15327">
        <vers num="3.0" />
        <vers num="3.1" />
        <vers num="3.2" />
        <vers num="3.3" />
        <vers num="3.4" />
        <vers num="4.0" />
        <vers num="4.0(1)" />
        <vers num="4.0(2)" />
        <vers num="4.1(0)" />
        <vers num="4.1(1)" />
        <vers num="4.1(2)" />
        <vers num="4.1(3)" />
        <vers num="4.6(0)" />
        <vers num="4.6(1)" />
      </prod>
      <prod vendor="cisco" name="ons_15454_optical_transport_platform">
        <vers num="2.3(5)" />
        <vers num="3.0" />
        <vers num="3.1.0" />
        <vers num="3.2.0" />
        <vers num="3.3" />
        <vers num="3.4" />
        <vers num="4.0" />
        <vers num="4.0(1)" />
        <vers num="4.0(2)" />
        <vers num="4.1(0)" />
        <vers num="4.1(1)" />
        <vers num="4.1(2)" />
        <vers num="4.1(3)" />
        <vers num="4.5" />
        <vers num="4.6(0)" />
        <vers num="4.6(1)" />
      </prod>
      <prod vendor="cisco" name="ons_15454sdh">
        <vers num="2.3(5)" />
        <vers num="3.1" />
        <vers num="3.2" />
        <vers num="3.3" />
        <vers num="3.4" />
        <vers num="4.0(0)" />
        <vers num="4.0(1)" />
        <vers num="4.0(2)" />
        <vers num="4.1(0)" />
        <vers num="4.1(1)" />
        <vers num="4.1(2)" />
        <vers num="4.1(3)" />
        <vers num="4.5" />
        <vers num="4.6(0)" />
        <vers num="4.6(1)" />
      </prod>
      <prod vendor="cisco" name="ons_15600">
        <vers num="1.0" />
        <vers num="1.1" />
        <vers num="1.1(0)" />
        <vers num="1.1(1)" />
        <vers num="1.3(0)" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1435" published="2004-12-31" name="CVE-2004-1435" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Multiple versions of Cisco ONS 15327, ONS 15454, and ONS 15454 SDH, including 4.6(0) and 4.6(1), 4.5(x), 4.1(0) to 4.1(3), 4.0(0) to 4.0(2), and earlier versions, allows remote attackers to cause a denial of service (control card reset) via a large number of TCP connections with an invalid response instead of the final ACK (TCP-ACK).</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/277048" source="CERT-VN" adv="1">VU#277048</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/16763" source="XF">cisco-ons-tcp-ack-dos(16763)</ref>
      <ref url="http://www.securityfocus.com/bid/10768" source="BID">10768</ref>
      <ref url="http://www.cisco.com/warp/public/707/cisco-sa-20040721-ons.shtml" source="CISCO" adv="1">20040721 Cisco ONS 15327, ONS 15454, ONS 15454 SDH, and ONS 15600 Malformed Packet Vulnerabilities</ref>
      <ref url="http://secunia.com/advisories/12117" source="SECUNIA">12117</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="ons_15327">
        <vers num="3.0" />
        <vers num="3.1" />
        <vers num="3.2" />
        <vers num="3.3" />
        <vers num="3.4" />
        <vers num="4.0" />
        <vers num="4.0(1)" />
        <vers num="4.0(2)" />
        <vers num="4.1(0)" />
        <vers num="4.1(1)" />
        <vers num="4.1(2)" />
        <vers num="4.1(3)" />
        <vers num="4.6(0)" />
        <vers num="4.6(1)" />
      </prod>
      <prod vendor="cisco" name="ons_15454_optical_transport_platform">
        <vers num="2.3(5)" />
        <vers num="3.0" />
        <vers num="3.1.0" />
        <vers num="3.2.0" />
        <vers num="3.3" />
        <vers num="3.4" />
        <vers num="4.0" />
        <vers num="4.0(1)" />
        <vers num="4.0(2)" />
        <vers num="4.1(0)" />
        <vers num="4.1(1)" />
        <vers num="4.1(2)" />
        <vers num="4.1(3)" />
        <vers num="4.5" />
        <vers num="4.6(0)" />
        <vers num="4.6(1)" />
      </prod>
      <prod vendor="cisco" name="ons_15454sdh">
        <vers num="2.3(5)" />
        <vers num="3.1" />
        <vers num="3.2" />
        <vers num="3.3" />
        <vers num="3.4" />
        <vers num="4.0(0)" />
        <vers num="4.0(1)" />
        <vers num="4.0(2)" />
        <vers num="4.1(0)" />
        <vers num="4.1(1)" />
        <vers num="4.1(2)" />
        <vers num="4.1(3)" />
        <vers num="4.5" />
        <vers num="4.6(0)" />
        <vers num="4.6(1)" />
      </prod>
      <prod vendor="cisco" name="ons_15600">
        <vers num="1.0" />
        <vers num="1.1" />
        <vers num="1.1(0)" />
        <vers num="1.1(1)" />
        <vers num="1.3(0)" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-1436" published="2004-12-31" name="CVE-2004-1436" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">The Transaction Language 1 (TL1) login interface in Cisco ONS 15327 4.6(0) and 4.6(1) and 15454 and 15454 SDH 4.6(0) and 4.6(1), when a user account is configured with a blank password, allows remote attackers to gain unauthorized access by logging in with a password larger than 10 characters.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
      <config />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/760432" source="CERT-VN" adv="1">VU#760432</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/16766" source="XF">cisco-ons-tl1-auth-bypass(16766)</ref>
      <ref url="http://www.securityfocus.com/bid/10768" source="BID">10768</ref>
      <ref url="http://www.cisco.com/warp/public/707/cisco-sa-20040721-ons.shtml" source="CISCO" adv="1">20040721 Cisco ONS 15327, ONS 15454, ONS 15454 SDH, and ONS 15600 Malformed Packet Vulnerabilities</ref>
      <ref url="http://secunia.com/advisories/12117" source="SECUNIA">12117</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="ons_15327">
        <vers num="3.0" />
        <vers num="3.1" />
        <vers num="3.2" />
        <vers num="3.3" />
        <vers num="3.4" />
        <vers num="4.0" />
        <vers num="4.0(1)" />
        <vers num="4.0(2)" />
        <vers num="4.1(0)" />
        <vers num="4.1(1)" />
        <vers num="4.1(2)" />
        <vers num="4.1(3)" />
        <vers num="4.6(0)" />
        <vers num="4.6(1)" />
      </prod>
      <prod vendor="cisco" name="ons_15454_optical_transport_platform">
        <vers num="2.3(5)" />
        <vers num="3.0" />
        <vers num="3.1.0" />
        <vers num="3.2.0" />
        <vers num="3.3" />
        <vers num="3.4" />
        <vers num="4.0" />
        <vers num="4.0(1)" />
        <vers num="4.0(2)" />
        <vers num="4.1(0)" />
        <vers num="4.1(1)" />
        <vers num="4.1(2)" />
        <vers num="4.1(3)" />
        <vers num="4.5" />
        <vers num="4.6(0)" />
        <vers num="4.6(1)" />
      </prod>
      <prod vendor="cisco" name="ons_15454sdh">
        <vers num="2.3(5)" />
        <vers num="3.1" />
        <vers num="3.2" />
        <vers num="3.3" />
        <vers num="3.4" />
        <vers num="4.0(0)" />
        <vers num="4.0(1)" />
        <vers num="4.0(2)" />
        <vers num="4.1(0)" />
        <vers num="4.1(1)" />
        <vers num="4.1(2)" />
        <vers num="4.1(3)" />
        <vers num="4.5" />
        <vers num="4.6(0)" />
        <vers num="4.6(1)" />
      </prod>
      <prod vendor="cisco" name="ons_15600">
        <vers num="1.0" />
        <vers num="1.1" />
        <vers num="1.1(0)" />
        <vers num="1.1(1)" />
        <vers num="1.3(0)" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-1437" published="2004-12-31" name="CVE-2004-1437" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple buffer overflows in the digest authentication functionality in Pavuk 0.9.28-r2 and earlier allow remote attackers to execute arbitrary code.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/10797" source="BID" patch="1">10797</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200407-19.xml" source="GENTOO" patch="1">GLSA-200407-19</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/16807" source="XF">pavuk-digest-auth-bo(16807)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="pavuk" name="pavuk">
        <vers num="0.928r1" />
        <vers num="0.928r2" />
        <vers num="0.9pl28i" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2004-1438" published="2004-12-31" name="CVE-2004-1438" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">The mod_authz_svn Apache module for Subversion 1.0.4-r1 and earlier allows remote authenticated users, with write access to the repository, to read unauthorized parts of the repository via the svn copy command.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/10800" source="BID" patch="1">10800</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200407-20.xml" source="GENTOO" patch="1">GLSA-200407-20</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/16803" source="XF">subversion-modauthzsvn-restriction-bypass(16803)</ref>
      <ref url="http://svn.collab.net/repos/svn/tags/1.0.6/CHANGES" source="CONFIRM">http://svn.collab.net/repos/svn/tags/1.0.6/CHANGES</ref>
      <ref url="http://securitytracker.com/id?1010779" source="SECTRACK">1010779</ref>
      <ref url="http://securityreason.com/securityalert/60" source="SREASON">60</ref>
    </refs>
    <vuln_soft>
      <prod vendor="subversion" name="subversion">
        <vers num="1.0" />
        <vers num="1.0.1" />
        <vers num="1.0.2" />
        <vers num="1.0.3" />
        <vers num="1.0.4" />
        <vers num="1.0.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-1439" published="2004-12-31" name="CVE-2004-1439" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in BlackJumboDog 3.x allows remote attackers to execute arbitrary code via long FTP commands such as (1) USER, (2) PASS, (3) RETR,(4) CWD, (5) XMKD, and (6) XRMD.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/714584" source="CERT-VN" patch="1" adv="1">VU#714584</ref>
      <ref url="http://www.securityfocus.com/bid/10834" source="BID" patch="1">10834</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/16842" source="XF">blackjumbodog-long-string-bo(16842)</ref>
      <ref url="http://www.security.org.sg/vuln/bjd361.html" source="MISC">http://www.security.org.sg/vuln/bjd361.html</ref>
      <ref url="http://www.ir3ip.net/pipermail/bugtraq/2004-September/009960.html" source="BUGTRAQ">20040910 BlackJumboDog FTP Server version 3.6.1 Buffer Overflow [Exploit included]</ref>
      <ref url="http://secunia.com/advisories/12203" source="SECUNIA">12203</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sapporoworks" name="black_jumbodog">
        <vers num="3.6.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-1440" published="2004-12-31" name="CVE-2004-1440" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple heap-based buffer overflows in the modpow function in PuTTY before 0.55 allow (1) remote attackers to execute arbitrary code via an SSH2 packet with a base argument that is larger than the mod argument, which causes the modpow function to write memory before the beginning of its buffer, and (2) remote malicious servers to cause a denial of service (client crash) and possibly execute arbitrary code via a large bignum during authentication.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/10850" source="BID" patch="1">10850</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200408-04.xml" source="GENTOO" patch="1">GLSA-200408-04 </ref>
      <ref url="http://secunia.com/advisories/12212/" source="SECUNIA" patch="1">12212</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109167869528138&amp;w=2" source="BUGTRAQ" patch="1">20040804 CORE-2004-0705: Vulnerabilities in PuTTY and PSCP</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/16885" source="XF">putty-code-execution(16885)</ref>
      <ref url="http://www.chiark.greenend.org.uk/~sgtatham/putty/wishlist/vuln-modpow.html" source="CONFIRM">http://www.chiark.greenend.org.uk/~sgtatham/putty/wishlist/vuln-modpow.html</ref>
      <ref url="http://www.chiark.greenend.org.uk/~sgtatham/putty/changes.html" source="CONFIRM">http://www.chiark.greenend.org.uk/~sgtatham/putty/changes.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="putty" name="putty">
        <vers num="0.48" />
        <vers num="0.49" />
        <vers num="0.50" />
        <vers num="0.51" />
        <vers num="0.52" />
        <vers num="0.53" />
        <vers num="0.53b" />
        <vers num="0.54" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-1441" published="2004-12-31" name="CVE-2004-1441" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in icq.cgi in Board Power 2.04PF allows remote attackers to inject arbitrary web script or HTML via the action parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/744590" source="CERT-VN">VU#744590</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/16698" source="XF">boardpower-icq-xss(16698)</ref>
      <ref url="http://www.securityfocus.com/bid/10734" source="BID">10734</ref>
      <ref url="http://archives.neohapsis.com/archives/fulldisclosure/2004-07/0642.html" source="FULLDISC">20040715 XSS in Board Power forum</ref>
    </refs>
    <vuln_soft>
      <prod vendor="board_power" name="board_power">
        <vers num="2.04pf" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1442" published="2004-12-31" name="CVE-2004-1442" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in db2www CGI interpreter in IBM Net.Data 7 and 7.2 allows remote attackers to inject arbitrary web script or HTML via a macro filename, which is not properly handled by error emssages such as "DTWP001E."</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/DMOA-5VNPEL" source="CONFIRM" adv="1">http://www.kb.cert.org/vuls/id/DMOA-5VNPEL</ref>
      <ref url="http://www.kb.cert.org/vuls/id/197318" source="CERT-VN" adv="1">VU#197318</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/14925" source="XF">ibm-netdata-db2wwwcomponent-xss(14925)</ref>
      <ref url="http://www.securityfocus.com/bid/9488" source="BID">9488</ref>
      <ref url="http://secunia.com/advisories/10709/" source="SECUNIA">10709</ref>
      <ref url="http://www.securitytracker.com/id?1008845" source="SECTRACK">1008845</ref>
      <ref url="http://www.osvdb.org/3712" source="OSVDB">3712</ref>
      <ref url="http://secunia.com/secunia_research/2004-1/advisory/" source="MISC">http://secunia.com/secunia_research/2004-1/advisory/</ref>
      <ref url="http://archives.neohapsis.com/archives/vulnwatch/2004-q1/0019.html" source="VULNWATCH">20040126 Secunia Research: IBM Net.Data Macro Name Cross-Site Scripting Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="net.data">
        <vers num="7.0" />
        <vers num="7.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1443" published="2004-12-31" name="CVE-2004-1443" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in the inline MIME viewer in Horde-IMP (Internet Messaging Program) 3.2.4 and earlier, when used with Internet Explorer, allows remote attackers to inject arbitrary web script or HTML via an e-mail message.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/10845" source="BID" patch="1">10845</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200408-07.xml" source="GENTOO" patch="1">GLSA-200408-07</ref>
      <ref url="http://secunia.com/advisories/12202/" source="SECUNIA" patch="1">12202</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/16866" source="XF">imp-html-viewer-xss(16866)</ref>
      <ref url="http://cvs.horde.org/diff.php/imp/docs/CHANGES?r1=1.389.2.106&amp;r2=1.389.2.109&amp;ty=h" source="CONFIRM">http://cvs.horde.org/diff.php/imp/docs/CHANGES?r1=1.389.2.106&amp;r2=1.389.2.109&amp;ty=h</ref>
    </refs>
    <vuln_soft>
      <prod vendor="horde" name="imp">
        <vers num="2.0" />
        <vers num="2.2" />
        <vers num="2.2.1" />
        <vers num="2.2.2" />
        <vers num="2.2.3" />
        <vers num="2.2.4" />
        <vers num="2.2.5" />
        <vers num="2.2.6" />
        <vers num="2.2.7" />
        <vers num="2.2.8" />
        <vers num="2.3" />
        <vers num="3.0" />
        <vers num="3.1" />
        <vers num="3.1.2" />
        <vers num="3.2" />
        <vers num="3.2.1" />
        <vers num="3.2.2" />
        <vers num="3.2.3" />
        <vers num="3.2.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1444" published="2004-12-31" name="CVE-2004-1444" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in Roundup 0.6.4 and earlier allows remote attackers to view arbitrary files via .. (dot dot) sequences in an @@ command in an HTTP GET request.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/10495" source="BID" patch="1">10495</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200408-09.xml" source="GENTOO" patch="1">GLSA-200408-09</ref>
      <ref url="http://secunia.com/advisories/11801/" source="SECUNIA" patch="1">11801</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/16350" source="XF">roundup-get-view-file(16350)</ref>
      <ref url="http://securitytracker.com/id?1010415" source="SECTRACK">1010415</ref>
      <ref url="http://packetstormsecurity.nl/0406-exploits/roundUP.txt" source="MISC">http://packetstormsecurity.nl/0406-exploits/roundUP.txt</ref>
      <ref url="http://sourceforge.net/tracker/index.php?func=detail&amp;aid=961511&amp;group_id=31577&amp;atid=402788" source="CONFIRM">http://sourceforge.net/tracker/index.php?func=detail&amp;aid=961511&amp;group_id=31577&amp;atid=402788</ref>
    </refs>
    <vuln_soft>
      <prod vendor="roundup" name="roundup">
        <vers num="0.5" />
        <vers num="0.5.1" />
        <vers num="0.5.2" />
        <vers num="0.5.3" />
        <vers num="0.5.4" />
        <vers num="0.5.5" />
        <vers num="0.5.6" />
        <vers num="0.5.7" />
        <vers num="0.5.8_stable" />
        <vers num="0.5.9" />
        <vers num="0.6.11" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2004-1445" published="2004-12-31" name="CVE-2004-1445" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:H/Au:N/C:P/I:P/A:P)" CVSS_score="3.7" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="1.9" CVSS_base_score="3.7">
    <desc>
      <descript source="cve">A race condition in nessus-adduser in Nessus 2.0.11 and possibly earlier versions, if the TMPDIR environment variable is not set, allows local users to gain privileges.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <race />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/10784" source="BID" patch="1">10784</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200408-11.xml" source="GENTOO" patch="1">GLSA-200408-11</ref>
      <ref url="http://secunia.com/advisories/12127/" source="SECUNIA" patch="1">12127</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/16768" source="XF">nessus-adduser-race-condition(16768)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="nessus" name="nessus">
        <vers num="2.0" />
        <vers num="2.0.1" />
        <vers num="2.0.10" />
        <vers num="2.0.11" />
        <vers num="2.0.2" />
        <vers num="2.0.3" />
        <vers num="2.0.4" />
        <vers num="2.0.5" />
        <vers num="2.0.6" />
        <vers num="2.0.7" />
        <vers num="2.0.8" />
        <vers num="2.0.9" />
        <vers num="2.1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1446" published="2004-12-31" name="CVE-2004-1446" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Unknown vulnerability in ScreenOS in Juniper Networks NetScreen firewall 3.x through 5.x allows remote attackers to cause a denial of service (device reboot or hang) via a crafted SSH v1 packet.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/749870" source="CERT-VN">VU#749870</ref>
      <ref url="http://www.securityfocus.com/bid/10854" source="BID" patch="1">10854</ref>
      <ref url="http://www.juniper.net/support/security/alerts/screenos-sshv1-2.txt" source="CONFIRM" patch="1">http://www.juniper.net/support/security/alerts/screenos-sshv1-2.txt</ref>
      <ref url="http://secunia.com/advisories/12208/" source="SECUNIA" patch="1">12208</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/16876" source="XF">netscreen-screenos-sshv1-dos(16876)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="juniper" name="netscreen_screenos">
        <vers num="1.64" />
        <vers num="1.66" />
        <vers num="1.66_r2" />
        <vers num="1.7" />
        <vers num="1.73_r1" />
        <vers num="1.73_r2" />
        <vers num="2.0.1_r8" />
        <vers num="2.1" />
        <vers num="2.10_r3" />
        <vers num="2.10_r4" />
        <vers num="2.1_r6" />
        <vers num="2.1_r7" />
        <vers num="2.5" />
        <vers num="2.5r1" />
        <vers num="2.5r2" />
        <vers num="2.5r6" />
        <vers num="2.6.0" />
        <vers num="2.6.1" />
        <vers num="2.6.1r1" />
        <vers num="2.6.1r10" />
        <vers num="2.6.1r11" />
        <vers num="2.6.1r12" />
        <vers num="2.6.1r2" />
        <vers num="2.6.1r3" />
        <vers num="2.6.1r4" />
        <vers num="2.6.1r5" />
        <vers num="2.6.1r6" />
        <vers num="2.6.1r7" />
        <vers num="2.6.1r8" />
        <vers num="2.6.1r9" />
        <vers num="2.7.1" />
        <vers num="2.7.1r1" />
        <vers num="2.7.1r2" />
        <vers num="2.7.1r3" />
        <vers num="2.8" />
        <vers num="2.8_r1" />
        <vers num="3.0.0" />
        <vers num="3.0.0r1" />
        <vers num="3.0.0r2" />
        <vers num="3.0.0r3" />
        <vers num="3.0.0r4" />
        <vers num="3.0.1" />
        <vers num="3.0.1r1" />
        <vers num="3.0.1r2" />
        <vers num="3.0.1r3" />
        <vers num="3.0.1r4" />
        <vers num="3.0.1r5" />
        <vers num="3.0.1r6" />
        <vers num="3.0.1r7" />
        <vers num="3.0.2" />
        <vers num="3.0.3" />
        <vers num="3.0.3_r1.1" />
        <vers num="3.0.3r1" />
        <vers num="3.0.3r2" />
        <vers num="3.0.3r3" />
        <vers num="3.0.3r4" />
        <vers num="3.0.3r5" />
        <vers num="3.0.3r6" />
        <vers num="3.0.3r7" />
        <vers num="3.0.3r8" />
        <vers num="3.1.0" />
        <vers num="3.1.0r1" />
        <vers num="3.1.0r10" />
        <vers num="3.1.0r11" />
        <vers num="3.1.0r12" />
        <vers num="3.1.0r2" />
        <vers num="3.1.0r3" />
        <vers num="3.1.0r4" />
        <vers num="3.1.0r5" />
        <vers num="3.1.0r6" />
        <vers num="3.1.0r7" />
        <vers num="3.1.0r8" />
        <vers num="3.1.0r9" />
        <vers num="3.1.1_r2" />
        <vers num="4.0.0" edition="" />
        <vers num="4.0.0" edition=":dial" />
        <vers num="4.0.0r1" />
        <vers num="4.0.0r10" />
        <vers num="4.0.0r11" />
        <vers num="4.0.0r12" />
        <vers num="4.0.0r2" />
        <vers num="4.0.0r3" />
        <vers num="4.0.0r4" />
        <vers num="4.0.0r5" />
        <vers num="4.0.0r6" />
        <vers num="4.0.0r7" />
        <vers num="4.0.0r8" />
        <vers num="4.0.0r9" />
        <vers num="4.0.1" />
        <vers num="4.0.1r1" />
        <vers num="4.0.1r10" />
        <vers num="4.0.1r2" />
        <vers num="4.0.1r3" />
        <vers num="4.0.1r4" />
        <vers num="4.0.1r5" />
        <vers num="4.0.1r6" />
        <vers num="4.0.1r7" />
        <vers num="4.0.1r8" />
        <vers num="4.0.1r9" />
        <vers num="4.0.2" />
        <vers num="4.0.3" />
        <vers num="4.0.3r1" />
        <vers num="4.0.3r2" />
        <vers num="4.0.3r3" />
        <vers num="4.0.3r4" />
        <vers num="5.0.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1447" published="2004-12-31" name="CVE-2004-1447" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Jetbox One 2.0.8 and possibly other versions stores passwords in the database in plaintext, which could allow attackers to gain sensitive information.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/586720" source="CERT-VN">VU#586720</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/16898" source="XF">jetbox-one-plaintext-password(16898)</ref>
      <ref url="http://www.securityfocus.com/bid/10858" source="BID">10858</ref>
      <ref url="http://www.securityfocus.com/archive/1/370852" source="BUGTRAQ">20040804 vulnerabilities in JetboxOne CMS</ref>
      <ref url="http://secunia.com/advisories/12230" source="SECUNIA">12230</ref>
      <ref url="http://echo.or.id/adv/adv03-y3dips-2004.txt" source="MISC">http://echo.or.id/adv/adv03-y3dips-2004.txt</ref>
      <ref url="http://www.osvdb.org/8325" source="OSVDB">8325</ref>
    </refs>
    <vuln_soft>
      <prod vendor="jetbox" name="jetbox_one_cms">
        <vers num="2.0.8" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1448" published="2004-12-31" name="CVE-2004-1448" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Jetbox One 2.0.8 and possibly other versions allow remote attackers with Author privileges in the IMAGES module to upload PHP files and execute arbitrary code.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/417408" source="CERT-VN" adv="1">VU#417408</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/16900" source="XF">jetbox-one-file-upload(16900)</ref>
      <ref url="http://www.securityfocus.com/bid/10859" source="BID">10859</ref>
      <ref url="http://www.securityfocus.com/archive/1/370852" source="BUGTRAQ">20040804 vulnerabilities in JetboxOne CMS</ref>
      <ref url="http://secunia.com/advisories/12230/" source="SECUNIA">12230</ref>
      <ref url="http://echo.or.id/adv/adv03-y3dips-2004.txt" source="MISC">http://echo.or.id/adv/adv03-y3dips-2004.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="jetbox" name="jetbox_one_cms">
        <vers num="2.0.8" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2004-1449" published="2004-12-31" name="CVE-2004-1449" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:N/A:N)" CVSS_score="2.6" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="4.9" CVSS_base_score="2.6">
    <desc>
      <descript source="cve">Mozilla before 1.7, Firefox before 0.9, and Thunderbird before 0.7 allows remote attackers to determine the location of files on a user's hard drive by obscuring a file upload control and tricking the user into dragging text into that control.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://bugzilla.mozilla.org/show_bug.cgi?id=206859#c0" source="CONFIRM">http://bugzilla.mozilla.org/show_bug.cgi?id=206859#c0</ref>
    </refs>
    <vuln_soft>
      <prod vendor="firebirdsql" name="firebird">
        <vers num="0.7" />
      </prod>
      <prod vendor="mozilla" name="mozilla">
        <vers num="0.8" />
        <vers num="0.9.2" />
        <vers num="0.9.2.1" />
        <vers num="0.9.3" />
        <vers num="0.9.35" />
        <vers num="0.9.4" />
        <vers num="0.9.4.1" />
        <vers num="0.9.48" />
        <vers num="0.9.5" />
        <vers num="0.9.6" />
        <vers num="0.9.7" />
        <vers num="0.9.8" />
        <vers num="0.9.9" />
        <vers num="1.0" edition="rc1" />
        <vers num="1.0" edition="rc2" />
        <vers num="1.0.1" />
        <vers num="1.0.2" />
        <vers num="1.1" edition="alpha" />
        <vers num="1.1" edition="beta" />
        <vers num="1.2" edition="alpha" />
        <vers num="1.2" edition="beta" />
        <vers num="1.2.1" />
        <vers num="1.3" />
        <vers num="1.3.1" />
        <vers num="1.4" edition="alpha" />
        <vers num="1.4" edition="beta" />
        <vers num="1.4.1" />
        <vers num="1.4.2" />
        <vers num="1.4.4" />
        <vers num="1.5" />
        <vers num="1.5.1" />
        <vers num="1.6" />
      </prod>
      <prod vendor="mozilla" name="thunderbird">
        <vers num="0.1" />
        <vers num="0.2" />
        <vers num="0.3" />
        <vers num="0.4" />
        <vers num="0.5" />
        <vers num="0.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1450" published="2004-12-31" name="CVE-2004-1450" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Unknown vulnerability in LiveConnect in Mozilla 1.7 beta allows remote attackers to read arbitrary files in known locations.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://bugzilla.mozilla.org/show_bug.cgi?id=239122" source="CONFIRM" patch="1">http://bugzilla.mozilla.org/show_bug.cgi?id=239122</ref>
      <ref url="http://www.mozilla.org/projects/security/known-vulnerabilities.html" source="CONFIRM">http://www.mozilla.org/projects/security/known-vulnerabilities.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="mozilla">
        <vers num="1.7" edition="beta" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2004-1451" published="2004-12-31" name="CVE-2004-1451" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:P/A:N)" CVSS_score="2.6" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="4.9" CVSS_base_score="2.6">
    <desc>
      <descript source="cve">Mozilla before 1.6 does not display the entire URL in the status bar when a link contains %00, which could allow remote attackers to trick users into clicking on unknown or untrusted sites and facilitate phishing attacks.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://bugzilla.mozilla.org/show_bug.cgi?id=228176" source="CONFIRM" patch="1">http://bugzilla.mozilla.org/show_bug.cgi?id=228176</ref>
      <ref url="http://www.mozilla.org/projects/security/known-vulnerabilities.html" source="CONFIRM">http://www.mozilla.org/projects/security/known-vulnerabilities.html</ref>
      <ref url="http://secunia.com/advisories/10419/" source="SECUNIA">10419</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="mozilla">
        <vers num="0.8" />
        <vers num="0.9.2" />
        <vers num="0.9.2.1" />
        <vers num="0.9.3" />
        <vers num="0.9.35" />
        <vers num="0.9.4" />
        <vers num="0.9.4.1" />
        <vers num="0.9.48" />
        <vers num="0.9.5" />
        <vers num="0.9.6" />
        <vers num="0.9.7" />
        <vers num="0.9.8" />
        <vers num="0.9.9" />
        <vers num="1.0" edition="rc1" />
        <vers num="1.0" edition="rc2" />
        <vers num="1.0.1" />
        <vers num="1.0.2" />
        <vers num="1.1" edition="alpha" />
        <vers num="1.1" edition="beta" />
        <vers num="1.2" edition="alpha" />
        <vers num="1.2" edition="beta" />
        <vers num="1.2.1" />
        <vers num="1.3" />
        <vers num="1.3.1" />
        <vers num="1.4" edition="alpha" />
        <vers num="1.4" edition="beta" />
        <vers num="1.4.1" />
        <vers num="1.4.2" />
        <vers num="1.4.4" />
        <vers num="1.5" />
        <vers num="1.5.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-1452" published="2004-12-31" name="CVE-2004-1452" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Tomcat before 5.0.27-r3 in Gentoo Linux sets the default permissions on the init scripts as tomcat:tomcat, but executes the scripts with root privileges, which could allow local users in the tomcat group to execute arbitrary commands as root by modifying the scripts.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <config />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/10951" source="BID" patch="1">10951</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200408-15.xml" source="GENTOO" patch="1">GLSA-200408-15</ref>
      <ref url="http://secunia.com/advisories/12296/" source="SECUNIA" patch="1">12296</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/16993" source="XF">gentoo-tomcat-gain-privileges(16993)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gentoo" name="linux">
        <vers num="0.5" />
        <vers num="0.7" />
        <vers num="1.1a" />
        <vers num="1.2" />
        <vers num="1.4" edition="rc1" />
        <vers num="1.4" edition="rc2" />
        <vers num="1.4" edition="rc3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2004-1453" published="2004-12-31" name="CVE-2004-1453" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">GNU glibc 2.3.4 before 2.3.4.20040619, 2.3.3 before 2.3.3.20040420, and 2.3.2 before 2.3.2-r10 does not restrict the use of LD_DEBUG for a setuid program, which allows local users to gain sensitive information, such as the list of symbols used by the program.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/10963" source="BID" patch="1">10963</ref>
      <ref url="http://secunia.com/advisories/12306" source="SECUNIA" patch="1">12306</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/17006" source="XF">glibc-suid-info-disclosure(17006)</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-261.html" source="REDHAT" adv="1">RHSA-2005:261</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-256.html" source="REDHAT" adv="1">RHSA-2005:256</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200408-16.xml" source="GENTOO">GLSA-200408-16</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10762" source="OVAL">oval:org.mitre.oval:def:10762</ref>
      <ref url="http://bugs.gentoo.org/show_bug.cgi?id=59526" source="MISC">http://bugs.gentoo.org/show_bug.cgi?id=59526</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gnu" name="glibc">
        <vers num="2.0" />
        <vers num="2.0.1" />
        <vers num="2.0.2" />
        <vers num="2.0.3" />
        <vers num="2.0.4" />
        <vers num="2.0.5" />
        <vers num="2.0.6" />
        <vers num="2.1" />
        <vers num="2.1.1" />
        <vers num="2.1.1.6" />
        <vers num="2.1.2" />
        <vers num="2.1.3" />
        <vers num="2.1.3.10" />
        <vers num="2.1.9" />
        <vers num="2.2" />
        <vers num="2.2.1" />
        <vers num="2.2.2" />
        <vers num="2.2.3" />
        <vers num="2.2.4" />
        <vers num="2.2.5" />
        <vers num="2.3" />
        <vers num="2.3.1" />
        <vers num="2.3.2" />
        <vers num="2.3.3" />
        <vers num="2.3.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1454" published="2004-12-31" name="CVE-2004-1454" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Cisco IOS 12.0S, 12.2, and 12.3, with Open Shortest Path First (OSPF) enabled, allows remote attackers to cause a denial of service (device reload) via a malformed OSPF packet.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/989406" source="CERT-VN" patch="1" adv="1">VU#989406</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/17033" source="XF">cisco-ios-ospf-dos(17033)</ref>
      <ref url="http://www.securityfocus.com/bid/10971" source="BID">10971</ref>
      <ref url="http://www.cisco.com/warp/public/707/cisco-sa-20040818-ospf.shtml" source="CISCO" adv="1">20040818 Cisco IOS Malformed OSPF Packet Causes Reload</ref>
      <ref url="http://www.ciac.org/ciac/bulletins/o-199.shtml" source="CIAC" adv="1">O-199</ref>
      <ref url="http://secunia.com/advisories/12322" source="SECUNIA">12322</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="ios">
        <vers num="12.0(22)s" />
        <vers num="12.0(22)s4" />
        <vers num="12.0(22)s5" />
        <vers num="12.0(22)sy" />
        <vers num="12.0(23)sx" />
        <vers num="12.0(23)sz" />
        <vers num="12.2(11)yu" />
        <vers num="12.2(11)yv" />
        <vers num="12.2(13)zd" />
        <vers num="12.2(13)ze" />
        <vers num="12.2(13)zf" />
        <vers num="12.2(13)zg" />
        <vers num="12.2(13)zh" />
        <vers num="12.2(14)sz" />
        <vers num="12.2(14)sz1" />
        <vers num="12.2(14)sz2" />
        <vers num="12.2(15)b" />
        <vers num="12.2(15)bc" />
        <vers num="12.2(15)bc1" />
        <vers num="12.2(15)bx" />
        <vers num="12.2(15)bz" />
        <vers num="12.2(15)cx" />
        <vers num="12.2(15)mc1" />
        <vers num="12.2(15)t" />
        <vers num="12.2(15)t5" />
        <vers num="12.2(15)zj" />
        <vers num="12.2(15)zj1" />
        <vers num="12.2(15)zj2" />
        <vers num="12.2(15)zj3" />
        <vers num="12.2(15)zk" />
        <vers num="12.2(15)zl" />
        <vers num="12.2(15)zl1" />
        <vers num="12.2(15)zn" />
        <vers num="12.2(15)zo" />
        <vers num="12.2(18)ew" />
        <vers num="12.2(18)s" />
        <vers num="12.2(18)se" />
        <vers num="12.2(18)sv" />
        <vers num="12.2(18)sw" />
        <vers num="12.3" />
        <vers num="12.3(1a)" />
        <vers num="12.3(2)t3" />
        <vers num="12.3(2)xc1" />
        <vers num="12.3(2)xc2" />
        <vers num="12.3(2)xc3" />
        <vers num="12.3(3e)" />
        <vers num="12.3(4)eo1" />
        <vers num="12.3(4)t" />
        <vers num="12.3(4)t1" />
        <vers num="12.3(4)t2" />
        <vers num="12.3(4)t3" />
        <vers num="12.3(4)t4" />
        <vers num="12.3(4)xd" />
        <vers num="12.3(4)xd1" />
        <vers num="12.3(4)xd2" />
        <vers num="12.3(4)xg1" />
        <vers num="12.3(4)xh" />
        <vers num="12.3(4)xk" />
        <vers num="12.3(4)xq" />
        <vers num="12.3(5)" />
        <vers num="12.3(5)b1" />
        <vers num="12.3(5a)" />
        <vers num="12.3(5a)b" />
        <vers num="12.3(5b)" />
        <vers num="12.3(5c)" />
        <vers num="12.3(6)" />
        <vers num="12.3(6a)" />
        <vers num="12.3(7)t" />
        <vers num="12.3(7.7)" />
        <vers num="12.3(9)" />
        <vers num="12.3b" />
        <vers num="12.3bw" />
        <vers num="12.3t" />
        <vers num="12.3xa" />
        <vers num="12.3xb" />
        <vers num="12.3xc" />
        <vers num="12.3xe" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1455" published="2004-12-31" name="CVE-2004-1455" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_score="5.1" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="4.9" CVSS_base_score="5.1">
    <desc>
      <descript source="cve">Stack-based buffer overflow in Xine-lib-rc5 in xine-lib 1_rc5-r2 and earlier allows remote attackers to execute arbitrary code via crafted playlists that result in a long vcd:// URL.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/10890" source="BID" patch="1">10890</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200408-18.xml" source="GENTOO" patch="1">GLSA-200408-18 </ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/16930" source="XF">xine-vcd-identifier-bo(16930)</ref>
      <ref url="http://secunia.com/advisories/12194/" source="SECUNIA">12194</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109284737628045&amp;w=2" source="BUGTRAQ">20040817 Open Security Group Advisory #6</ref>
    </refs>
    <vuln_soft>
      <prod vendor="xine" name="xine-lib">
        <vers num="1_beta1" />
        <vers num="1_beta10" />
        <vers num="1_beta11" />
        <vers num="1_beta2" />
        <vers num="1_beta3" />
        <vers num="1_beta4" />
        <vers num="1_beta5" />
        <vers num="1_beta6" />
        <vers num="1_beta7" />
        <vers num="1_beta8" />
        <vers num="1_beta9" />
        <vers num="1_rc2" />
        <vers num="1_rc3a" />
        <vers num="1_rc3b" />
        <vers num="1_rc3c" />
        <vers num="1_rc4" />
        <vers num="1_rc5" />
        <vers num="1_rc5_r2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-1456" published="2004-12-31" name="CVE-2004-1456" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">filediff in CVStrac allows remote attackers to execute arbitrary commands via shell metacharacters in rcsinfo.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/770816" source="CERT-VN" adv="1">VU#770816</ref>
      <ref url="http://www.cvstrac.org/cvstrac/chngview?cn=316" source="CONFIRM" patch="1">http://www.cvstrac.org/cvstrac/chngview?cn=316</ref>
      <ref url="http://secunia.com/advisories/12090/" source="SECUNIA" patch="1">12090</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/16929" source="XF">cvstrac-command-execute(16929)</ref>
      <ref url="http://www.securityfocus.com/bid/10878" source="BID">10878</ref>
      <ref url="http://www.osvdb.org/8373" source="OSVDB">8373</ref>
      <ref url="http://www.cvstrac.org/cvstrac/tktview?tn=339" source="CONFIRM">http://www.cvstrac.org/cvstrac/tktview?tn=339</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109173359428253&amp;w=2" source="BUGTRAQ">20040805 CVStrac Remote Arbitrary Code Execution exploit</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cvstrac" name="cvstrac">
        <vers num="1.1" />
        <vers num="1.1.1" />
        <vers num="1.1.2" />
        <vers num="1.1.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1457" published="2004-12-31" name="CVE-2004-1457" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The Virtual Private Network (VPN) capability in Novell Bordermanager 3.8 allows remote attackers to cause a denial of service (ABEND in IKE.NLM) via a malformed IKE packet, as sent by the Striker ISAKMP Protocol Test Suite.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/432097" source="CERT-VN" adv="1">VU#432097</ref>
      <ref url="http://www.securityfocus.com/bid/10727" source="BID" patch="1">10727</ref>
      <ref url="http://support.novell.com/cgi-bin/search/searchtid.cgi?/10093576.htm" source="CONFIRM" patch="1">http://support.novell.com/cgi-bin/search/searchtid.cgi?/10093576.htm</ref>
      <ref url="http://secunia.com/advisories/12067/" source="SECUNIA" patch="1">12067</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/16697" source="XF">novell-bordermanger-ikenlm-dos(16697)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="novell" name="bordermanager">
        <vers num="3.8" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1458" published="2004-12-31" name="CVE-2004-1458" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The CSAdmin web administration interface for Cisco Secure Access Control Server (ACS) 3.2(2) build 15 allows remote attackers to cause a denial of service (hang) via a flood of TCP connections to port 2002.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.cisco.com/warp/public/707/cisco-sa-20040825-acs.shtml" source="CISCO" patch="1" adv="1">20040825 Multiple Vulnerabilities in Cisco Secure Access Control Server</ref>
      <ref url="http://www.securityfocus.com/bid/11047" source="BID">11047</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/17114" source="XF">ciscosecure-csadmin-tcp-dos(17114)</ref>
      <ref url="http://www.ciac.org/ciac/bulletins/o-203.shtml" source="CIAC">O-203</ref>
      <ref url="http://secunia.com/advisories/12386/" source="SECUNIA">12386</ref>
      <ref url="http://osvdb.org/9182" source="OSVDB">9182</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="secure_access_control_server">
        <vers num="3.0" />
        <vers num="3.1" />
        <vers num="3.2" edition="" />
        <vers num="3.2" edition=":windows_server" />
        <vers num="3.2(1)" />
        <vers num="3.2(2)" />
        <vers num="3.2(2)_build_15" />
        <vers num="3.2(3)" />
        <vers num="3.3" />
        <vers num="3.3(1)" />
      </prod>
      <prod vendor="cisco" name="secure_acs_solution_engine">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1459" published="2004-12-31" name="CVE-2004-1459" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Cisco Secure Access Control Server (ACS) 3.2, when configured as a Light Extensible Authentication Protocol (LEAP) RADIUS proxy, allows remote attackers to cause a denial of service (device crash) via certain LEAP authentication requests.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <access />
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.cisco.com/warp/public/707/cisco-sa-20040825-acs.shtml" source="CISCO" patch="1">20040825 Multiple Vulnerabilities in Cisco Secure Access Control Server</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/17116" source="XF">ciscosecure-leap-radius-dos(17116)</ref>
      <ref url="http://www.securityfocus.com/bid/11047" source="BID">11047</ref>
    </refs>
  </entry>
  <entry type="CVE" severity="High" seq="2004-1460" published="2004-12-31" name="CVE-2004-1460" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Cisco Secure Access Control Server (ACS) 3.2(3) and earlier, when configured with an anonymous bind in Novell Directory Services (NDS) and authenticating NDS users with NDS, allows remote attackers to gain unauthorized access to AAA clients via a blank password.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.cisco.com/warp/public/707/cisco-sa-20040825-acs.shtml" source="CISCO" patch="1" adv="1">20040825 Multiple Vulnerabilities in Cisco Secure Access Control Server</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/17117" source="XF">ciscosecure-nds-blank-authentication(17117)</ref>
      <ref url="http://www.securityfocus.com/bid/11047" source="BID">11047</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="secure_access_control_server">
        <vers num="3.0" />
        <vers num="3.1" />
        <vers num="3.2" edition="" />
        <vers num="3.2" edition=":windows_server" />
        <vers num="3.2(1)" />
        <vers num="3.2(2)" />
        <vers num="3.2(3)" />
        <vers num="3.3" />
        <vers num="3.3(1)" />
      </prod>
      <prod vendor="cisco" name="secure_acs_solution_engine">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-1461" published="2004-12-31" name="CVE-2004-1461" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Cisco Secure Access Control Server (ACS) 3.2(3) and earlier spawns a separate unauthenticated TCP connection on a random port when a user authenticates to the ACS GUI, which allows remote attackers to bypass authentication by connecting to that port from the same IP address.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.cisco.com/warp/public/707/cisco-sa-20040825-acs.shtml" source="CISCO" patch="1" adv="1">20040825 Multiple Vulnerabilities in Cisco Secure Access Control Server</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/17118" source="XF">ciscosecure-csadmin-auth-bypass(17118)</ref>
      <ref url="http://www.securityfocus.com/bid/11047" source="BID">11047</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="secure_access_control_server">
        <vers num="3.0" />
        <vers num="3.1" />
        <vers num="3.2" edition="" />
        <vers num="3.2" edition=":windows_server" />
        <vers num="3.2(1)" />
        <vers num="3.2(2)" />
        <vers num="3.2(3)" />
        <vers num="3.3" />
        <vers num="3.3(1)" />
      </prod>
      <prod vendor="cisco" name="secure_acs_solution_engine">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-1462" published="2004-12-31" name="CVE-2004-1462" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Unknown vulnerability in MoinMoin 1.2.2 and earlier allows remote attackers to gain unauthorized access to administrator functions such as (1) revert and (2) delete.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="https://sourceforge.net/project/shownotes.php?group_id=8482&amp;release_id=254801" source="CONFIRM" patch="1">https://sourceforge.net/project/shownotes.php?group_id=8482&amp;release_id=254801</ref>
      <ref url="http://www.securityfocus.com/bid/10805" source="BID" patch="1">10805</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200408-25.xml" source="GENTOO" patch="1">GLSA-200408-25</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/16833" source="XF">moinmoin-acl-gain-privileges(16833)</ref>
      <ref url="http://www.osvdb.org/displayvuln.php?osvdb_id=8194" source="OSVDB">8194</ref>
    </refs>
    <vuln_soft>
      <prod vendor="moinmoin" name="moinmoin">
        <vers num="0.1" />
        <vers num="0.10" />
        <vers num="0.11" />
        <vers num="0.2" />
        <vers num="0.3" />
        <vers num="0.7" />
        <vers num="0.8" />
        <vers num="0.9" />
        <vers num="1.0" />
        <vers num="1.1" />
        <vers num="1.2" />
        <vers num="1.2.1" />
        <vers num="1.2.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-1463" published="2004-12-31" name="CVE-2004-1463" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Unknown vulnerability in the PageEditor in MoinMoin 1.2.2 and earlier, related to Access Control Lists (ACL), has unknown impact.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/10801" source="BID" patch="1">10801</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200408-25.xml" source="GENTOO" patch="1">GLSA-200408-25</ref>
      <ref url="http://sourceforge.net/project/shownotes.php?group_id=8482&amp;release_id=254801" source="CONFIRM" patch="1">http://sourceforge.net/project/shownotes.php?group_id=8482&amp;release_id=254801</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/16832" source="XF">moinmoin-pageeditor-gain-privilege(16832)</ref>
      <ref url="http://www.osvdb.org/displayvuln.php?osvdb_id=8195" source="OSVDB">8195</ref>
    </refs>
    <vuln_soft>
      <prod vendor="moinmoin" name="moinmoin">
        <vers num="0.1" />
        <vers num="0.10" />
        <vers num="0.11" />
        <vers num="0.2" />
        <vers num="0.3" />
        <vers num="0.7" />
        <vers num="0.8" />
        <vers num="0.9" />
        <vers num="1.0" />
        <vers num="1.1" />
        <vers num="1.2" />
        <vers num="1.2.1" />
        <vers num="1.2.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1464" published="2004-12-31" name="CVE-2004-1464" modified="2008-09-10" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Cisco IOS 12.2(15) and earlier allows remote attackers to cause a denial of service (refused VTY (virtual terminal) connections), via a crafted TCP connection to the Telnet or reverse Telnet port.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/384230" source="CERT-VN" patch="1" adv="1">VU#384230</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/17131" source="XF">cisco-ios-telnet-dos(17131)</ref>
      <ref url="http://www.securityfocus.com/bid/11060" source="BID">11060</ref>
      <ref url="http://www.cisco.com/warp/public/707/cisco-sa-20040827-telnet.shtml" source="CISCO" adv="1">20040827 Cisco Telnet Denial of Service Vulnerability</ref>
      <ref url="http://securitytracker.com/id?1011079" source="SECTRACK">1011079</ref>
      <ref url="http://secunia.com/advisories/12395/" source="SECUNIA" adv="1">12395</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="ios">
        <vers prev="1" num="12.2" />
        <vers num="12.2(1)" />
        <vers num="12.2(1)dx" />
        <vers num="12.2(1)s" />
        <vers num="12.2(1)t" />
        <vers num="12.2(1)xa" />
        <vers num="12.2(1)xd" />
        <vers num="12.2(1)xd1" />
        <vers num="12.2(1)xd3" />
        <vers num="12.2(1)xd4" />
        <vers num="12.2(1)xe" />
        <vers num="12.2(1)xe2" />
        <vers num="12.2(1)xe3" />
        <vers num="12.2(1)xh" />
        <vers num="12.2(1)xq" />
        <vers num="12.2(1)xs" />
        <vers num="12.2(1)xs1" />
        <vers num="12.2(1.1)" />
        <vers num="12.2(1.1)pi" />
        <vers num="12.2(1.4)s" />
        <vers num="12.2(10)da2" />
        <vers num="12.2(10g)" />
        <vers num="12.2(11)bc3c" />
        <vers num="12.2(11)ja" />
        <vers num="12.2(11)ja1" />
        <vers num="12.2(11)t" />
        <vers num="12.2(11)t2" />
        <vers num="12.2(11)t3" />
        <vers num="12.2(11)t8" />
        <vers num="12.2(11)t9" />
        <vers num="12.2(11)yp1" />
        <vers num="12.2(11)yu" />
        <vers num="12.2(11)yv" />
        <vers num="12.2(11)yx1" />
        <vers num="12.2(11)yz2" />
        <vers num="12.2(12)" />
        <vers num="12.2(12)da3" />
        <vers num="12.2(12.02)s" />
        <vers num="12.2(12.02)t" />
        <vers num="12.2(12.05)" />
        <vers num="12.2(12.05)s" />
        <vers num="12.2(12.05)t" />
        <vers num="12.2(12b)" />
        <vers num="12.2(12c)" />
        <vers num="12.2(12g)" />
        <vers num="12.2(12h)" />
        <vers num="12.2(12i)" />
        <vers num="12.2(13)" />
        <vers num="12.2(13)ja1" />
        <vers num="12.2(13)mc1" />
        <vers num="12.2(13)t" />
        <vers num="12.2(13)t1" />
        <vers num="12.2(13)t9" />
        <vers num="12.2(13)zc" />
        <vers num="12.2(13)zd" />
        <vers num="12.2(13)ze" />
        <vers num="12.2(13)zf" />
        <vers num="12.2(13)zg" />
        <vers num="12.2(13)zh" />
        <vers num="12.2(13)zh3" />
        <vers num="12.2(13)zj" />
        <vers num="12.2(13)zk" />
        <vers num="12.2(13)zl" />
        <vers num="12.2(13.03)b" />
        <vers num="12.2(13a)" />
        <vers num="12.2(13e)" />
        <vers num="12.2(14)s" />
        <vers num="12.2(14)sx1" />
        <vers num="12.2(14)sy" />
        <vers num="12.2(14)sy03" />
        <vers num="12.2(14)sy1" />
        <vers num="12.2(14)sz" />
        <vers num="12.2(14)sz1" />
        <vers num="12.2(14)sz2" />
        <vers num="12.2(14)za" />
        <vers num="12.2(14)za2" />
        <vers num="12.2(14)za8" />
        <vers num="12.2(14.5)" />
        <vers num="12.2(14.5)t" />
        <vers num="12.2(15)b" />
        <vers num="12.2(15)bc" />
        <vers num="12.2(15)bc1" />
        <vers num="12.2(15)bx" />
        <vers num="12.2(15)bz" />
        <vers num="12.2(15)cx" />
        <vers num="12.2(15)mc1" />
        <vers num="12.2(15)sl1" />
        <vers num="12.2(15)t" />
        <vers num="12.2(15)t5" />
        <vers num="12.2(15)t7" />
        <vers num="12.2(15)t8" />
        <vers num="12.2(15)t9" />
        <vers num="12.2(15)ys_1.2(1)" />
        <vers num="12.2(15)zj" />
        <vers num="12.2(15)zj1" />
        <vers num="12.2(15)zj2" />
        <vers num="12.2(15)zj3" />
        <vers num="12.2(15)zk" />
        <vers num="12.2(15)zl" />
        <vers num="12.2(15)zl1" />
        <vers num="12.2(15)zn" />
        <vers num="12.2(15)zo" />
        <vers num="12.2(15.1)s" />
        <vers num="12.2(16)b" />
        <vers num="12.2(16)b1" />
        <vers num="12.2(16)bx" />
        <vers num="12.2(16.1)b" />
        <vers num="12.2(16.5)s" />
        <vers num="12.2(16f)" />
        <vers num="12.2(17)" />
        <vers num="12.2(17)a" />
        <vers num="12.2(17a)" />
        <vers num="12.2(17a)sxa" />
        <vers num="12.2(17b)sxa" />
        <vers num="12.2(17d)" />
        <vers num="12.2(17d)sxb" />
        <vers num="12.2(18)ew" />
        <vers num="12.2(18)s" />
        <vers num="12.2(18)se" />
        <vers num="12.2(18)sv" />
        <vers num="12.2(18)sw" />
        <vers num="12.2(18.2)" />
        <vers num="12.2(19)" />
        <vers num="12.2(19)b" />
        <vers num="12.2(1b)" />
        <vers num="12.2(1b)da1" />
        <vers num="12.2(1d)" />
        <vers num="12.2(2)b" />
        <vers num="12.2(2)bx" />
        <vers num="12.2(2)by" />
        <vers num="12.2(2)by2" />
        <vers num="12.2(2)dd3" />
        <vers num="12.2(2)t" />
        <vers num="12.2(2)t1" />
        <vers num="12.2(2)t4" />
        <vers num="12.2(2)xa" />
        <vers num="12.2(2)xa1" />
        <vers num="12.2(2)xa5" />
        <vers num="12.2(2)xb" />
        <vers num="12.2(2)xb11" />
        <vers num="12.2(2)xb14" />
        <vers num="12.2(2)xb15" />
        <vers num="12.2(2)xb3" />
        <vers num="12.2(2)xb4" />
        <vers num="12.2(2)xc1" />
        <vers num="12.2(2)xf" />
        <vers num="12.2(2)xg" />
        <vers num="12.2(2)xh" />
        <vers num="12.2(2)xh2" />
        <vers num="12.2(2)xh3" />
        <vers num="12.2(2)xi" />
        <vers num="12.2(2)xi1" />
        <vers num="12.2(2)xi2" />
        <vers num="12.2(2)xj" />
        <vers num="12.2(2)xj1" />
        <vers num="12.2(2)xk" />
        <vers num="12.2(2)xk2" />
        <vers num="12.2(2)xn" />
        <vers num="12.2(2)xt" />
        <vers num="12.2(2)xt3" />
        <vers num="12.2(2)xu" />
        <vers num="12.2(2)xu2" />
        <vers num="12.2(2)yc" />
        <vers num="12.2(2.2)t" />
        <vers num="12.2(20)s" />
        <vers num="12.2(20)s1" />
        <vers num="12.2(20)s2" />
        <vers num="12.2(21)" />
        <vers num="12.2(21a)" />
        <vers num="12.2(21b)" />
        <vers num="12.2(22)s" />
        <vers num="12.2(23)" />
        <vers num="12.2(23)sw" />
        <vers num="12.2(23.6)" />
        <vers num="12.2(23a)" />
        <vers num="12.2(24)" />
        <vers num="12.2(3)" />
        <vers num="12.2(3.4)bp" />
        <vers num="12.2(3d)" />
        <vers num="12.2(4)" />
        <vers num="12.2(4)b" />
        <vers num="12.2(4)b1" />
        <vers num="12.2(4)b2" />
        <vers num="12.2(4)b3" />
        <vers num="12.2(4)b4" />
        <vers num="12.2(4)bc1" />
        <vers num="12.2(4)bc1a" />
        <vers num="12.2(4)bx" />
        <vers num="12.2(4)ja" />
        <vers num="12.2(4)ja1" />
        <vers num="12.2(4)mb12" />
        <vers num="12.2(4)mb3" />
        <vers num="12.2(4)mx" />
        <vers num="12.2(4)mx1" />
        <vers num="12.2(4)t" />
        <vers num="12.2(4)t1" />
        <vers num="12.2(4)t3" />
        <vers num="12.2(4)t6" />
        <vers num="12.2(4)xl" />
        <vers num="12.2(4)xl4" />
        <vers num="12.2(4)xm" />
        <vers num="12.2(4)xm2" />
        <vers num="12.2(4)xw" />
        <vers num="12.2(4)xw1" />
        <vers num="12.2(4)ya" />
        <vers num="12.2(4)ya1" />
        <vers num="12.2(4)ya7" />
        <vers num="12.2(4)ya8" />
        <vers num="12.2(4)yb" />
        <vers num="12.2(5)" />
        <vers num="12.2(5)ca1" />
        <vers num="12.2(5d)" />
        <vers num="12.2(6.8)t0a" />
        <vers num="12.2(6.8)t1a" />
        <vers num="12.2(6c)" />
        <vers num="12.2(7)" />
        <vers num="12.2(7)da" />
        <vers num="12.2(7.4)s" />
        <vers num="12.2(7a)" />
        <vers num="12.2(7b)" />
        <vers num="12.2(8)bc1" />
        <vers num="12.2(8)ja" />
        <vers num="12.2(8)t" />
        <vers num="12.2(8)t10" />
        <vers num="12.2(8)yd" />
        <vers num="12.2(8)yw2" />
        <vers num="12.2(8)yw3" />
        <vers num="12.2(8)yy" />
        <vers num="12.2(8)yy3" />
        <vers num="12.2(8)zb7" />
        <vers num="12.2(9)s" />
        <vers num="12.2b" />
        <vers num="12.2bc" />
        <vers num="12.2bw" />
        <vers num="12.2bx" />
        <vers num="12.2by" />
        <vers num="12.2bz" />
        <vers num="12.2cx" />
        <vers num="12.2cy" />
        <vers num="12.2da" />
        <vers num="12.2dd" />
        <vers num="12.2dx" />
        <vers num="12.2ew" />
        <vers num="12.2ja" />
        <vers num="12.2jk" />
        <vers num="12.2mb" />
        <vers num="12.2mc" />
        <vers num="12.2mx" />
        <vers num="12.2pb" />
        <vers num="12.2pi" />
        <vers num="12.2s" />
        <vers num="12.2sa" />
        <vers num="12.2se" />
        <vers num="12.2su" />
        <vers num="12.2sv" />
        <vers num="12.2sw" />
        <vers num="12.2sx" />
        <vers num="12.2sxa" />
        <vers num="12.2sxb" />
        <vers num="12.2sxd" />
        <vers num="12.2sy" />
        <vers num="12.2sz" />
        <vers num="12.2t" />
        <vers num="12.2xa" />
        <vers num="12.2xb" />
        <vers num="12.2xc" />
        <vers num="12.2xd" />
        <vers num="12.2xe" />
        <vers num="12.2xf" />
        <vers num="12.2xg" />
        <vers num="12.2xh" />
        <vers num="12.2xi" />
        <vers num="12.2xj" />
        <vers num="12.2xk" />
        <vers num="12.2xl" />
        <vers num="12.2xm" />
        <vers num="12.2xn" />
        <vers num="12.2xq" />
        <vers num="12.2xr" />
        <vers num="12.2xs" />
        <vers num="12.2xt" />
        <vers num="12.2xu" />
        <vers num="12.2xw" />
        <vers num="12.2ya" />
        <vers num="12.2yb" />
        <vers num="12.2yc" />
        <vers num="12.2yd" />
        <vers num="12.2ye" />
        <vers num="12.2yf" />
        <vers num="12.2yg" />
        <vers num="12.2yh" />
        <vers num="12.2yj" />
        <vers num="12.2yk" />
        <vers num="12.2yl" />
        <vers num="12.2ym" />
        <vers num="12.2yn" />
        <vers num="12.2yo" />
        <vers num="12.2yp" />
        <vers num="12.2yq" />
        <vers num="12.2yr" />
        <vers num="12.2ys" />
        <vers num="12.2yt" />
        <vers num="12.2yu" />
        <vers num="12.2yv" />
        <vers num="12.2yw" />
        <vers num="12.2yx" />
        <vers num="12.2yy" />
        <vers num="12.2yz" />
        <vers num="12.2za" />
        <vers num="12.2zb" />
        <vers num="12.2zc" />
        <vers num="12.2zd" />
        <vers num="12.2ze" />
        <vers num="12.2zf" />
        <vers num="12.2zg" />
        <vers num="12.2zh" />
        <vers num="12.2zi" />
        <vers num="12.2zj" />
        <vers num="12.2zk" />
        <vers num="12.2zl" />
        <vers num="12.2zn" />
        <vers num="12.2zo" />
        <vers num="12.2zp" />
        <vers num="12.2zq" />
        <vers num="12.3" />
        <vers num="12.3(1a)" />
        <vers num="12.3(2)t3" />
        <vers num="12.3(2)xc1" />
        <vers num="12.3(2)xc2" />
        <vers num="12.3(2)xc3" />
        <vers num="12.3(3e)" />
        <vers num="12.3(4)eo1" />
        <vers num="12.3(4)t" />
        <vers num="12.3(4)t1" />
        <vers num="12.3(4)t2" />
        <vers num="12.3(4)t3" />
        <vers num="12.3(4)t4" />
        <vers num="12.3(4)xd" />
        <vers num="12.3(4)xd1" />
        <vers num="12.3(4)xd2" />
        <vers num="12.3(4)xg1" />
        <vers num="12.3(4)xh" />
        <vers num="12.3(4)xk" />
        <vers num="12.3(4)xq" />
        <vers num="12.3(5)" />
        <vers num="12.3(5)b1" />
        <vers num="12.3(5a)" />
        <vers num="12.3(5a)b" />
        <vers num="12.3(5b)" />
        <vers num="12.3(5c)" />
        <vers num="12.3(6)" />
        <vers num="12.3(6a)" />
        <vers num="12.3(7)t" />
        <vers num="12.3(7.7)" />
        <vers num="12.3(9)" />
        <vers num="12.3b" />
        <vers num="12.3bc" />
        <vers num="12.3bw" />
        <vers num="12.3ja" />
        <vers num="12.3t" />
        <vers num="12.3xa" />
        <vers num="12.3xb" />
        <vers num="12.3xc" />
        <vers num="12.3xd" />
        <vers num="12.3xe" />
        <vers num="12.3xf" />
        <vers num="12.3xg" />
        <vers num="12.3xh" />
        <vers num="12.3xi" />
        <vers num="12.3xj" />
        <vers num="12.3xk" />
        <vers num="12.3xl" />
        <vers num="12.3xm" />
        <vers num="12.3xn" />
        <vers num="12.3xq" />
        <vers num="12.3xr" />
        <vers num="12.3xt" />
        <vers num="12.3xu" />
        <vers num="12.3yd" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2004-1465" published="2004-12-31" name="CVE-2004-1465" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:H/Au:N/C:P/I:P/A:P)" CVSS_score="3.7" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="1.9" CVSS_base_score="3.7">
    <desc>
      <descript source="cve">Multiple buffer overflows in WinZip 9.0 and earlier may allow attackers to execute arbitrary code via multiple vectors, including the command line.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.winzip.com/wz90sr1.htm" source="CONFIRM" patch="1">http://www.winzip.com/wz90sr1.htm</ref>
      <ref url="http://www.securityfocus.com/bid/11092" source="BID" patch="1">11092</ref>
      <ref url="http://securitytracker.com/id?1011132" source="SECTRACK" patch="1">1011132</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/17197" source="XF">winzip-command-line-bo(17197)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/17192" source="XF">winzip-code-execution(17192)</ref>
      <ref url="http://www.ciac.org/ciac/bulletins/o-211.shtml" source="CIAC" adv="1">O-211</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109416099301369&amp;w=2" source="BUGTRAQ">20040901 WinZip Unspecified Buffer Overflows May Let Remote or Local Users Execute Arbitrary Code</ref>
    </refs>
    <vuln_soft>
      <prod vendor="winzip" name="winzip">
        <vers num="7.0" />
        <vers num="8.0" />
        <vers num="8.1" edition="sr1" />
        <vers num="9.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-1466" published="2004-12-31" name="CVE-2004-1466" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">The set_time_limit function in Gallery before 1.4.4_p2 deletes non-image files in a temporary directory every 30 seconds after they have been uploaded using save_photos.php, which allows remote attackers to upload and execute execute arbitrary scripts before they are deleted, if the temporary directory is under the web root.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/10968" source="BID" patch="1">10968</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200409-05.xml" source="GENTOO" patch="1">GLSA-200409-05</ref>
      <ref url="http://gallery.menalto.com/modules.php?op=modload&amp;name=News&amp;file=article&amp;sid=134&amp;mode=thread&amp;order=0&amp;thold=0" source="CONFIRM" patch="1">http://gallery.menalto.com/modules.php?op=modload&amp;name=News&amp;file=article&amp;sid=134&amp;mode=thread&amp;order=0&amp;thold=0</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/17021" source="XF">gallery-savephotos-file-upload(17021)</ref>
      <ref url="http://archives.neohapsis.com/archives/fulldisclosure/2004-08/0757.html" source="FULLDISC">20040817 Gallery 1.4.4 save_photos.php PHP Insertion Proof of Concept</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gallery_project" name="gallery">
        <vers num="1.4.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1467" published="2004-12-31" name="CVE-2004-1467" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in eGroupWare 1.0.00.003 and earlier allow remote attackers to inject arbitrary web script or HTML via (1) date or search text field in the calendar module, (2) Field parameter, Filter parameter, QField parameter, Start parameter or Search field in the address module, (3) Subject field in the message module or (4) Subject field in the Ticket module.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/11013" source="BID" patch="1">11013</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200409-06.xml" source="GENTOO" patch="1">GLSA-200409-06</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/17078" source="XF">egroupware-mult-modules-xss(17078)</ref>
      <ref url="http://www.securityfocus.com/archive/1/372603" source="BUGTRAQ">20040822 Multiple Cross Site Scripting Vulnerabilities in eGroupWare</ref>
      <ref url="http://sourceforge.net/forum/forum.php?forum_id=401807" source="CONFIRM">http://sourceforge.net/forum/forum.php?forum_id=401807</ref>
    </refs>
    <vuln_soft>
      <prod vendor="egroupware" name="egroupware">
        <vers num="1.0" />
        <vers num="1.0.1" />
        <vers num="1.0.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-1468" published="2004-12-31" name="CVE-2004-1468" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">The web mail functionality in Usermin 1.x and Webmin 1.x allows remote attackers to execute arbitrary commands via shell metacharacters in an e-mail message.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/11122" source="BID" patch="1">1122</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200409-15.xml" source="GENTOO" patch="1">GLSA-200409-15</ref>
      <ref url="http://secunia.com/advisories/12488/" source="SECUNIA" patch="1">12488</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/17293" source="XF">usermin-web-mail-command-execution(17293)</ref>
      <ref url="http://www.lac.co.jp/security/csl/intelligence/SNSadvisory_e/77_e.html" source="MISC">http://www.lac.co.jp/security/csl/intelligence/SNSadvisory_e/77_e.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="usermin" name="usermin">
        <vers num="1.000" />
        <vers num="1.010" />
        <vers num="1.020" />
        <vers num="1.030" />
        <vers num="1.040" />
        <vers num="1.051" />
        <vers num="1.060" />
        <vers num="1.070" />
        <vers num="1.080" />
      </prod>
      <prod vendor="webmin" name="webmin">
        <vers num="1.0.00" />
        <vers num="1.0.20" />
        <vers num="1.0.50" />
        <vers num="1.0.60" />
        <vers num="1.0.70" />
        <vers num="1.0.80" />
        <vers num="1.0.90" />
        <vers num="1.1.00" />
        <vers num="1.1.10" />
        <vers num="1.1.21" />
        <vers num="1.1.30" />
        <vers num="1.1.40" />
        <vers num="1.1.50" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-1469" published="2004-12-31" name="CVE-2004-1469" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Format string vulnerability in the log function in SUS 2.0.2, and other versions before 2.0.6, allows local users to execute arbitrary code via format string specifiers in a command line argument that is passed directly to syslog.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/11176" source="BID" patch="1">11176</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200409-17.xml" source="GENTOO" patch="1">GLSA-200409-17</ref>
      <ref url="http://security.lss.hr/index.php?page=details&amp;ID=LSS-2004-09-01" source="MISC" patch="1" adv="1">http://security.lss.hr/index.php?page=details&amp;ID=LSS-2004-09-01</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109517782910407&amp;w=2" source="BUGTRAQ" patch="1">20040914 SUS 2.0.2 local root vulnerability</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/17361" source="XF">sus-log-format-string(17361)</ref>
      <ref url="http://pdg.uow.edu.au/sus/CHANGES" source="CONFIRM">http://pdg.uow.edu.au/sus/CHANGES</ref>
    </refs>
    <vuln_soft>
      <prod vendor="peter_d._gray" name="sus">
        <vers num="2.0" />
        <vers num="2.0.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1470" published="2004-12-31" name="CVE-2004-1470" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">CRLF injection vulnerability in SnipSnap 0.5.2a, and other versions before 1.0b1, allows remote attackers to perform HTTP Response Splitting attacks to modify expected HTML content from the server.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/11180" source="BID" patch="1">11180</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200409-23.xml" source="GENTOO" patch="1">GLSA-200409-23</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/17364" source="XF">snipsnap-response-splitting(17364)</ref>
      <ref url="http://www.snipsnap.org/space/start" source="CONFIRM">http://www.snipsnap.org/space/start</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109518773223511&amp;w=2" source="BUGTRAQ">20040914 ADVISORY: http response splitting in snipsnap</ref>
    </refs>
    <vuln_soft>
      <prod vendor="snipsnap" name="snipsnap">
        <vers num="0.5.2a" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-1471" published="2004-12-31" name="CVE-2004-1471" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:H/Au:S/C:C/I:C/A:C)" CVSS_score="7.1" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.1">
    <desc>
      <descript source="cve">Format string vulnerability in wrapper.c in CVS 1.12.x through 1.12.8, and 1.11.x through 1.11.16 allows remote attackers with CVSROOT commit access to cause a denial of service (application crash) and possibly execute arbitrary code via format string specifiers in a wrapper line.</descript>
    </desc>
    <impacts>
      <impact source="nvd">Failed exploit attempts will likely cause a denial of service condition.</impact>
    </impacts>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/10499" source="BID" patch="1">10499</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/16365" source="XF">cvs-wrapper-format-string(16365)</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2004-June/022441.html" source="FULLDISC" adv="1">20040609 Advisory 09/2004: More CVS remote vulnerabilities</ref>
      <ref url="ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-04:14.cvs.asc" source="FREEBSD" adv="1">FreeBSD-SA-04:14</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cvs" name="cvs">
        <vers num="1.10.7" />
        <vers num="1.10.8" />
        <vers num="1.11" />
        <vers num="1.11.1" />
        <vers num="1.11.10" />
        <vers num="1.11.11" />
        <vers num="1.11.14" />
        <vers num="1.11.15" />
        <vers num="1.11.16" />
        <vers num="1.11.1_p1" />
        <vers num="1.11.2" />
        <vers num="1.11.3" />
        <vers num="1.11.4" />
        <vers num="1.11.5" />
        <vers num="1.11.6" />
        <vers num="1.12.1" />
        <vers num="1.12.2" />
        <vers num="1.12.5" />
        <vers num="1.12.7" />
        <vers num="1.12.8" />
      </prod>
      <prod vendor="openpkg" name="openpkg">
        <vers num="1.3" />
        <vers num="2.0" />
        <vers num="current" />
      </prod>
      <prod vendor="sgi" name="propack">
        <vers num="2.4" />
        <vers num="3.0" />
      </prod>
      <prod vendor="freebsd" name="freebsd">
        <vers num="1.1.5.1" />
        <vers num="2.0" />
        <vers num="2.0.5" />
        <vers num="2.1.0" />
        <vers num="2.1.5" />
        <vers num="2.1.6" />
        <vers num="2.1.6.1" />
        <vers num="2.1.7.1" />
        <vers num="2.2" />
        <vers num="2.2.2" />
        <vers num="2.2.3" />
        <vers num="2.2.4" />
        <vers num="2.2.5" />
        <vers num="2.2.6" />
        <vers num="2.2.8" />
        <vers num="3.0" edition="releng" />
        <vers num="3.1" />
        <vers num="3.2" />
        <vers num="3.3" />
        <vers num="3.4" />
        <vers num="3.5" edition="stable" />
        <vers num="3.5.1" edition="release" />
        <vers num="3.5.1" edition="stable" />
        <vers num="4.0" edition="alpha" />
        <vers num="4.0" edition="releng" />
        <vers num="4.1" />
        <vers num="4.1.1" edition="release" />
        <vers num="4.1.1" edition="stable" />
        <vers num="4.10" edition="release" />
        <vers num="4.10" edition="releng" />
        <vers num="4.2" edition="stable" />
        <vers num="4.3" edition="release" />
        <vers num="4.3" edition="release_p38" />
        <vers num="4.3" edition="releng" />
        <vers num="4.3" edition="stable" />
        <vers num="4.4" edition="release_p42" />
        <vers num="4.4" edition="releng" />
        <vers num="4.4" edition="stable" />
        <vers num="4.5" edition="release" />
        <vers num="4.5" edition="release_p32" />
        <vers num="4.5" edition="releng" />
        <vers num="4.5" edition="stable" />
        <vers num="4.6" edition="release" />
        <vers num="4.6" edition="release_p20" />
        <vers num="4.6" edition="releng" />
        <vers num="4.6" edition="stable" />
        <vers num="4.6.2" />
        <vers num="4.7" edition="release" />
        <vers num="4.7" edition="release_p17" />
        <vers num="4.7" edition="releng" />
        <vers num="4.7" edition="stable" />
        <vers num="4.8" edition="pre-release" />
        <vers num="4.8" edition="release_p6" />
        <vers num="4.8" edition="releng" />
        <vers num="4.9" edition="pre-release" />
        <vers num="4.9" edition="releng" />
        <vers num="5.0" edition="alpha" />
        <vers num="5.0" edition="release_p14" />
        <vers num="5.0" edition="releng" />
        <vers num="5.1" edition="alpha" />
        <vers num="5.1" edition="release" />
        <vers num="5.1" edition="release_p5" />
        <vers num="5.1" edition="releng" />
        <vers num="5.2" />
        <vers num="5.2.1" edition="release" />
        <vers num="5.2.1" edition="releng" />
      </prod>
      <prod vendor="gentoo" name="linux">
        <vers num="1.4" />
      </prod>
      <prod vendor="openbsd" name="openbsd">
        <vers num="3.4" />
        <vers num="3.5" />
        <vers num="current" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1472" published="2004-12-31" name="CVE-2004-1472" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Symantec Enterprise Firewall/VPN Appliances 100, 200, and 200R running firmware before 1.63 allow remote attackers to cause a denial of service (device freeze) via a fast UDP port scan on the WAN interface.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/441078" source="CERT-VN" adv="1">VU#441078</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/17469" source="XF">symantec-firewallvpn-udp-dos(17469)</ref>
      <ref url="http://www.securityfocus.com/bid/11237" source="BID">11237</ref>
      <ref url="http://securityresponse.symantec.com/avcenter/security/Content/2004.09.22.html" source="CONFIRM" adv="1">http://securityresponse.symantec.com/avcenter/security/Content/2004.09.22.html</ref>
      <ref url="http://www.osvdb.org/10204" source="OSVDB">10204</ref>
      <ref url="http://secunia.com/advisories/12635" source="SECUNIA">12635</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109588376426070&amp;w=2" source="BUGTRAQ">20040922 Multiple Vulnerabilities in Symantec Enterprise Firewall/Gateway Security Products</ref>
    </refs>
    <vuln_soft>
      <prod vendor="symantec" name="firewall_vpn_appliance_100">
        <vers num="" />
      </prod>
      <prod vendor="symantec" name="firewall_vpn_appliance_200">
        <vers num="" />
      </prod>
      <prod vendor="symantec" name="firewall_vpn_appliance_200r">
        <vers num="" />
      </prod>
      <prod vendor="symantec" name="gateway_security">
        <vers num="320" />
        <vers num="360" />
        <vers num="360r" />
      </prod>
      <prod vendor="symantec" name="nexland_isb_soho_firewall_appliance">
        <vers num="" />
      </prod>
      <prod vendor="symantec" name="nexland_pro100_firewall_appliance">
        <vers num="" />
      </prod>
      <prod vendor="symantec" name="nexland_pro400_firewall_appliance">
        <vers num="" />
      </prod>
      <prod vendor="symantec" name="nexland_pro800_firewall_appliance">
        <vers num="" />
      </prod>
      <prod vendor="symantec" name="nexland_pro800turbo_firewall_appliance">
        <vers num="" />
      </prod>
      <prod vendor="symantec" name="nexland_wavebase_firewall_appliance">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1473" published="2004-12-31" name="CVE-2004-1473" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Symantec Enterprise Firewall/VPN Appliances 100, 200, and 200R running firmware before 1.63 and Gateway Security 320, 360, and 360R running firmware before 622 allow remote attackers to bypass filtering and determine whether the device is running services such as tftpd, snmpd, or isakmp via a UDP port scan with a source port of UDP 53.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/329230" source="CERT-VN" patch="1" adv="1">VU#329230</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/17470" source="XF" patch="1">symantec-udp-obtain-info(17470)</ref>
      <ref url="http://securityresponse.symantec.com/avcenter/security/Content/2004.09.22.html" source="CONFIRM" patch="1" adv="1">http://securityresponse.symantec.com/avcenter/security/Content/2004.09.22.html</ref>
      <ref url="http://www.securityfocus.com/bid/11237" source="BID">11237</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109588376426070&amp;w=2" source="BUGTRAQ" adv="1">20040922 Multiple Vulnerabilities in Symantec Enterprise Firewall/Gateway Security Products</ref>
      <ref url="http://www.osvdb.org/10205" source="OSVDB">10205</ref>
      <ref url="http://secunia.com/advisories/12635" source="SECUNIA">12635</ref>
    </refs>
    <vuln_soft>
      <prod vendor="symantec" name="firewall_vpn_appliance_100">
        <vers num="" />
      </prod>
      <prod vendor="symantec" name="firewall_vpn_appliance_200">
        <vers num="" />
      </prod>
      <prod vendor="symantec" name="firewall_vpn_appliance_200r">
        <vers num="" />
      </prod>
      <prod vendor="symantec" name="gateway_security_320">
        <vers num="" />
      </prod>
      <prod vendor="symantec" name="gateway_security_360">
        <vers num="" />
      </prod>
      <prod vendor="symantec" name="gateway_security_360r">
        <vers num="" />
      </prod>
      <prod vendor="symantec" name="nexland_isb_soho_firewall_appliance">
        <vers num="" />
      </prod>
      <prod vendor="symantec" name="nexland_pro100_firewall_appliance">
        <vers num="" />
      </prod>
      <prod vendor="symantec" name="nexland_pro400_firewall_appliance">
        <vers num="" />
      </prod>
      <prod vendor="symantec" name="nexland_pro800_firewall_appliance">
        <vers num="" />
      </prod>
      <prod vendor="symantec" name="nexland_pro800turbo_firewall_appliance">
        <vers num="" />
      </prod>
      <prod vendor="symantec" name="nexland_wavebase_firewall_appliance">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1474" published="2004-12-31" name="CVE-2004-1474" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Symantec Enterprise Firewall/VPN Appliances 100, 200, and 200R running firmware before 1.63 and Gateway Security 320, 360, and 360R running firmware before 622 uses a default read/write SNMP community string, which allows remote attackers to alter the firewall's configuration file.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/173910" source="CERT-VN" patch="1" adv="1">VU#173910</ref>
      <ref url="http://www.securityfocus.com/bid/11237" source="BID" patch="1">11237</ref>
      <ref url="http://securityresponse.symantec.com/avcenter/security/Content/2004.09.22.html" source="CONFIRM" patch="1" adv="1">http://securityresponse.symantec.com/avcenter/security/Content/2004.09.22.html</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109588376426070&amp;w=2" source="BUGTRAQ" adv="1">20040922 Multiple Vulnerabilities in Symantec Enterprise Firewall/Gateway Security Products</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/17471" source="XF">symantec-default-snmp(17471)</ref>
      <ref url="http://www.osvdb.org/10206" source="OSVDB">10206</ref>
      <ref url="http://secunia.com/advisories/12635" source="SECUNIA">12635</ref>
    </refs>
    <vuln_soft>
      <prod vendor="symantec" name="firewall_vpn_appliance_100">
        <vers num="" />
      </prod>
      <prod vendor="symantec" name="firewall_vpn_appliance_200">
        <vers num="" />
      </prod>
      <prod vendor="symantec" name="firewall_vpn_appliance_200r">
        <vers num="" />
      </prod>
      <prod vendor="symantec" name="gateway_security_320">
        <vers num="" />
      </prod>
      <prod vendor="symantec" name="gateway_security_360">
        <vers num="" />
      </prod>
      <prod vendor="symantec" name="gateway_security_360r">
        <vers num="" />
      </prod>
      <prod vendor="symantec" name="nexland_isb_soho_firewall_appliance">
        <vers num="" />
      </prod>
      <prod vendor="symantec" name="nexland_pro100_firewall_appliance">
        <vers num="" />
      </prod>
      <prod vendor="symantec" name="nexland_pro400_firewall_appliance">
        <vers num="" />
      </prod>
      <prod vendor="symantec" name="nexland_pro800_firewall_appliance">
        <vers num="" />
      </prod>
      <prod vendor="symantec" name="nexland_pro800turbo_firewall_appliance">
        <vers num="" />
      </prod>
      <prod vendor="symantec" name="nexland_wavebase_firewall_appliance">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1475" published="2004-12-31" name="CVE-2004-1475" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_score="5.1" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="4.9" CVSS_base_score="5.1">
    <desc>
      <descript source="cve">Multiple stack-based buffer overflows in xine-lib 1-rc2 through 1-rc5 allow attackers to execute arbitrary code via (1) long VideoCD vcd:// MRLs or (2) long subtitle lines.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/11206" source="BID" patch="1">11206</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200409-30.xml" source="GENTOO" patch="1">GLSA-200409-30</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200408-18.xml" source="GENTOO" patch="1">GLSA-200408-18</ref>
      <ref url="http://xinehq.de/index.php/security/XSA-2004-4" source="CONFIRM">http://xinehq.de/index.php/security/XSA-2004-4</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/17432" source="XF">xine-subtitle-bo(17432)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/17430" source="XF">xine-videocd-mrl-bo(17430)</ref>
      <ref url="http://www.securityfocus.com/archive/1/375485/2004-09-02/2004-09-08/0" source="BUGTRAQ" adv="1">20040907 XSA-2004-4: multiple string overflows</ref>
    </refs>
    <vuln_soft>
      <prod vendor="xine" name="xine">
        <vers num="0.9.18" />
        <vers num="1_rc2" />
        <vers num="1_rc3" />
        <vers num="1_rc4" />
        <vers num="1_rc5" />
      </prod>
      <prod vendor="xine" name="xine-lib">
        <vers num="0.99" />
        <vers num="1_rc2" />
        <vers num="1_rc3" />
        <vers num="1_rc4" />
        <vers num="1_rc5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1476" published="2004-12-31" name="CVE-2004-1476" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_score="5.1" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="4.9" CVSS_base_score="5.1">
    <desc>
      <descript source="cve">Stack-based buffer overflow in the VideoCD (VCD) code in xine-lib 1-rc2 through 1-rc5, as derived from libcdio, allows attackers to execute arbitrary code via a VideoCD with an unterminated disk label.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xinehq.de/index.php/security/XSA-2004-4" source="CONFIRM" patch="1" adv="1">http://xinehq.de/index.php/security/XSA-2004-4</ref>
      <ref url="http://www.securityfocus.com/bid/11206" source="BID" patch="1">11206</ref>
      <ref url="http://www.securityfocus.com/archive/1/375485/2004-09-02/2004-09-08/0" source="BUGTRAQ" patch="1" adv="1">20040907 XSA-2004-4: multiple string overflows</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200409-30.xml" source="GENTOO" patch="1" adv="1">GLSA-200409-30</ref>
    </refs>
    <vuln_soft>
      <prod vendor="xine" name="xine">
        <vers num="0.9.18" />
        <vers num="1_rc2" />
        <vers num="1_rc3" />
        <vers num="1_rc4" />
        <vers num="1_rc5" />
      </prod>
      <prod vendor="xine" name="xine-lib">
        <vers num="0.99" />
        <vers num="1_rc2" />
        <vers num="1_rc3" />
        <vers num="1_rc4" />
        <vers num="1_rc5" />
      </prod>
      <prod vendor="suse" name="suse_linux">
        <vers num="8.0" />
        <vers num="8.1" />
        <vers num="8.2" edition="" />
        <vers num="8.2" edition=":personal" />
        <vers num="9.0" edition="" />
        <vers num="9.0" edition=":x86_64" />
        <vers num="9.0" edition=":personal" />
        <vers num="9.1" edition="" />
        <vers num="9.1" edition=":personal" />
        <vers num="9.2" edition="" />
        <vers num="9.2" edition=":personal" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1477" published="2004-12-31" name="CVE-2004-1477" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in the Management Console in JRun 4.0 allows remote attackers to execute arbitrary web script or HTML and possibly hijack a user's session.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/668206" source="CERT-VN" patch="1" adv="1">VU#668206</ref>
      <ref url="http://www.securityfocus.com/bid/11245" source="BID" patch="1">11245</ref>
      <ref url="http://www.macromedia.com/devnet/security/security_zone/mpsb04-08.html" source="CONFIRM" patch="1" adv="1">http://www.macromedia.com/devnet/security/security_zone/mpsb04-08.html</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/17483" source="XF">jrun-management-console-xss(17483)</ref>
      <ref url="http://secunia.com/advisories/12638/" source="SECUNIA">12638</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109621995623823&amp;w=2" source="BUGTRAQ">20040923 New Macromedia Security Zone Bulletins Posted</ref>
    </refs>
    <vuln_soft>
      <prod vendor="macromedia" name="jrun">
        <vers num="3.0" />
        <vers num="3.1" />
        <vers num="4.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-1478" published="2004-12-31" name="CVE-2004-1478" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">JRun 4.0 does not properly generate and handle the JSESSIONID, which allows remote attackers to perform a session fixation attack and hijack a user's HTTP session.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/584958" source="CERT-VN" patch="1" adv="1">VU#584958</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/17481" source="XF" patch="1">jrun-jsessionid-hijack(17481)</ref>
      <ref url="http://www.securityfocus.com/bid/11245" source="BID" patch="1">11245</ref>
      <ref url="http://www.macromedia.com/devnet/security/security_zone/mpsb04-08.html" source="CONFIRM" patch="1">http://www.macromedia.com/devnet/security/security_zone/mpsb04-08.html</ref>
      <ref url="http://secunia.com/advisories/12638/" source="SECUNIA" patch="1" adv="1">12638</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109621995623823&amp;w=2" source="BUGTRAQ" adv="1">20040923 New Macromedia Security Zone Bulletins Posted</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hitachi" name="cosminexus_enterprise">
        <vers num="01_01_1" edition="" />
        <vers num="01_01_1" edition=":enterprise" />
        <vers num="01_01_1" edition=":standard" />
        <vers num="01_02_2" edition="" />
        <vers num="01_02_2" edition=":standard" />
        <vers num="01_02_2" edition=":enterprise" />
      </prod>
      <prod vendor="hitachi" name="cosminexus_server">
        <vers num="web_01-01_1" />
        <vers num="web_01-01_2" />
      </prod>
      <prod vendor="macromedia" name="coldfusion">
        <vers num="6.0" />
        <vers num="6.1" edition="" />
        <vers num="6.1" edition=":j2ee_application_server" />
      </prod>
      <prod vendor="macromedia" name="jrun">
        <vers num="3.0" />
        <vers num="3.1" />
        <vers num="4.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" seq="2004-1479" reject="1" published="2004-12-31" name="CVE-2004-1479" modified="2008-09-10">
    <desc>
      <descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: CVE-2004-0928.  Reason: This candidate is a duplicate of CVE-2004-0928.  Notes: All CVE users should reference CVE-2004-0928 instead of this candidate.  All references and descriptions in this candidate have been removed to prevent accidental usage.</descript>
    </desc>
    <refs />
  </entry>
  <entry type="CVE" severity="High" seq="2004-1480" published="2004-12-31" name="CVE-2004-1480" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Unknown vulnerability in the management station in HP StorageWorks Command View XP 1.8B and earlier allows remote attackers to bypass access restrictions.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://securitytracker.com/id?1011407" source="SECTRACK" patch="1">1011407</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/17490" source="XF">hp-storageworks-restriction-bypass(17490)</ref>
      <ref url="http://www.securityfocus.com/bid/11249" source="BID">11249</ref>
      <ref url="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=PSD_HPSBST01071" source="HP" adv="1">SSRT4794 </ref>
    </refs>
    <vuln_soft>
      <prod vendor="hp" name="storageworks_command_view">
        <vers num="1.11" edition="" />
        <vers num="1.11" edition=":xp" />
        <vers num="1.11.1" edition="" />
        <vers num="1.11.1" edition=":xp" />
        <vers num="1.11.2" edition="" />
        <vers num="1.11.2" edition=":xp" />
        <vers num="1.30.00" edition="" />
        <vers num="1.30.00" edition=":xp" />
        <vers num="1.40.01" edition="" />
        <vers num="1.40.01" edition=":xp" />
        <vers num="1.40.04" edition="" />
        <vers num="1.40.04" edition=":xp" />
        <vers num="1.51.00" edition="" />
        <vers num="1.51.00" edition=":xp" />
        <vers num="1.52.00" edition="" />
        <vers num="1.52.00" edition=":xp" />
        <vers num="1.53.00" edition="" />
        <vers num="1.53.00" edition=":xp" />
        <vers num="1.53.01a" edition="" />
        <vers num="1.53.01a" edition=":xp" />
        <vers num="1.53.05a" edition="" />
        <vers num="1.53.05a" edition=":xp" />
        <vers num="1.60.00" edition="" />
        <vers num="1.60.00" edition=":xp" />
        <vers num="1.7a" edition="" />
        <vers num="1.7a" edition=":xp" />
        <vers num="1.7b" edition="" />
        <vers num="1.7b" edition=":xp" />
        <vers num="1.8" edition="" />
        <vers num="1.8" edition=":xp" />
        <vers num="1.8a" edition="" />
        <vers num="1.8a" edition=":xp" />
        <vers num="1.8b" edition="" />
        <vers num="1.8b" edition=":xp" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1481" published="2004-12-31" name="CVE-2004-1481" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_score="5.1" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="4.9" CVSS_base_score="5.1">
    <desc>
      <descript source="cve">Integer overflow in pnen3260.dll in RealPlayer 8 through 10.5 (6.0.12.1040) and earlier, and RealOne Player 1 or 2 on Windows or Mac OS, allows remote attackers to execute arbitrary code via a SMIL file and a .rm movie file with a large length field for the data chunk, which leads to a heap-based buffer overflow.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.service.real.com/help/faq/security/040928_player/EN/" source="CONFIRM" patch="1" adv="1">http://www.service.real.com/help/faq/security/040928_player/EN/</ref>
      <ref url="http://www.securityfocus.com/bid/11309" source="BID" patch="1">11309</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/17549" source="XF">realplayer-rm-code-execution(17549)</ref>
      <ref url="http://secunia.com/advisories/12672" source="SECUNIA">12672</ref>
      <ref url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=109708374115061&amp;w=2" source="BUGTRAQ">20041001 EEYE: RealPlayer pnen3260.dll Heap Overflow</ref>
    </refs>
    <vuln_soft>
      <prod vendor="realnetworks" name="helix_player">
        <vers num="1.0" edition="" />
        <vers num="1.0" edition=":linux" />
      </prod>
      <prod vendor="realnetworks" name="realone_player">
        <vers num="1.0" />
        <vers num="2.0" />
        <vers num="9.0.0.288" edition="" />
        <vers num="9.0.0.288" edition=":mac_os_x" />
        <vers num="9.0.0.297" edition="" />
        <vers num="9.0.0.297" edition=":mac_os_x" />
      </prod>
      <prod vendor="realnetworks" name="realplayer">
        <vers num="" edition=":enterprise" />
        <vers num="10.0" edition="" />
        <vers num="10.0" edition=":german" />
        <vers num="10.0" edition=":linux" />
        <vers num="10.0" edition=":" />
        <vers num="10.0" edition="::english" />
        <vers num="10.0" edition="::japanese" />
        <vers num="10.0_6.0.12.690" />
        <vers num="10.0_beta" edition="" />
        <vers num="10.0_beta" edition=":mac_os" />
        <vers num="10.5" />
        <vers num="10.5_6.0.12.1016_beta" />
        <vers num="10.5_6.0.12.1040" />
        <vers num="8.0" edition="" />
        <vers num="8.0" edition=":win32" />
        <vers num="8.0" edition=":mac_os" />
        <vers num="8.0" edition=":unix" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-1482" published="2004-12-31" name="CVE-2004-1482" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">The sbuf_getmsg function in BNC incorrectly handles backspace characters, which could allow remote attackers to bypass authentication and gain access to arbitrary scripts.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/11355" source="BID" patch="1">11355</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200410-13.xml" source="GENTOO" patch="1">GLSA-200410-13</ref>
      <ref url="http://secunia.com/advisories/12770/" source="SECUNIA" patch="1">12770</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/17672" source="XF">bnc-backspace-command-execution(17672)</ref>
      <ref url="http://www.osvdb.org/10596" source="OSVDB">10596</ref>
    </refs>
    <vuln_soft>
      <prod vendor="bnc" name="bnc">
        <vers num="2.2.4" />
        <vers num="2.4.6" />
        <vers num="2.4.8" />
        <vers num="2.6" />
        <vers num="2.6.2" />
        <vers num="2.8.8" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-1483" published="2004-12-31" name="CVE-2004-1483" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Multiple unknown vulnerabilities in the ActiveX and HTML file browsers in Symantec Clientless VPN Gateway 4400 Series 5.0 have unknown attack vectors and unknown impact.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/760256" source="CERT-VN" patch="1" adv="1">VU#760256</ref>
      <ref url="http://secunia.com/advisories/12254/" source="SECUNIA" patch="1">12254</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/16933" source="XF">symantec-clientless-file-browsers(16933)</ref>
      <ref url="http://www.securityfocus.com/bid/10903" source="BID">10903</ref>
      <ref url="http://www.osvdb.org/8508" source="OSVDB">8508</ref>
      <ref url="ftp://ftp.symantec.com/public/english_us_canada/products/sym_clientless_vpn/sym_clientless_vpn_5/updates/hf3-readme.txt" source="CONFIRM">ftp://ftp.symantec.com/public/english_us_canada/products/sym_clientless_vpn/sym_clientless_vpn_5/updates/hf3-readme.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="symantec" name="clientless_vpn_gateway_4400">
        <vers num="5.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1484" published="2004-12-31" name="CVE-2004-1484" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Format string vulnerability in the _msg function in error.c in socat 1.4.0.3 and earlier, when used as an HTTP proxy client and run with the -ly option, allows remote attackers or local users to execute arbitrary code via format string specifiers in a syslog message.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/17822" source="XF" patch="1">socat-format-string(17822)</ref>
      <ref url="http://www.securityfocus.com/bid/11505" source="BID" patch="1">11505</ref>
      <ref url="http://www.nosystem.com.ar/advisories/advisory-07.txt" source="MISC" patch="1" adv="1">http://www.nosystem.com.ar/advisories/advisory-07.txt</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200410-26.xml" source="GENTOO" patch="1" adv="1">GLSA-200410-26</ref>
      <ref url="http://secunia.com/advisories/12936/" source="SECUNIA" patch="1" adv="1">12936</ref>
      <ref url="http://www.dest-unreach.org/socat/advisory/socat-adv-1.html" source="CONFIRM" adv="1">http://www.dest-unreach.org/socat/advisory/socat-adv-1.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="socat" name="socat">
        <vers num="1.0.3.0" />
        <vers num="1.0.4.0" />
        <vers num="1.0.4.1" />
        <vers num="1.0.4.2" />
        <vers num="1.1.0.0" />
        <vers num="1.1.0.1" />
        <vers num="1.2.0.0" />
        <vers num="1.3.0.0" />
        <vers num="1.3.0.1" />
        <vers num="1.3.1.0" />
        <vers num="1.3.2.0" />
        <vers num="1.3.2.1" />
        <vers num="1.3.2.2" />
        <vers num="1.4.0.0" />
        <vers num="1.4.0.1" />
        <vers num="1.4.0.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-1485" published="2004-12-31" name="CVE-2004-1485" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in the TFTP client in InetUtils 1.4.2 allows remote malicious DNS servers to execute arbitrary code via a large DNS response that is handled by the gethostbyname function.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/17878" source="XF">inetutils-tftp-dns-bo(17878)</ref>
      <ref url="http://www.securityfocus.com/bid/11527" source="BID">11527</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109882085912915&amp;w=2" source="BUGTRAQ">20041026 inetutils tftp client, DNS resolving bofs</ref>
    </refs>
  </entry>
  <entry type="CVE" severity="High" seq="2004-1486" published="2004-12-31" name="CVE-2004-1486" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Unknown vulnerability in Serviceguard A.11.13 through A.11.16.00 and Cluster Object Manager A.01.03 and B.01.04 through B.03.00.01 on HP-UX, Serviceguard A.11.14.04 and A.11.15.04 and Cluster Object Manager B.02.01.02 and B.02.02.02 on HP Linux, allow remote attackers to gain privileges via unknown attack vectors.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <other />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/17867" source="XF" patch="1">hp-cluster-serviceguard-gain-privileges(17867)</ref>
      <ref url="http://www.securityfocus.com/bid/11507" source="BID" patch="1">11507</ref>
      <ref url="http://secunia.com/advisories/12946" source="SECUNIA" patch="1" adv="1">12946</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109893515704267&amp;w=2" source="HP" patch="1" adv="1">SSRT3526</ref>
    </refs>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1487" published="2005-04-27" name="CVE-2004-1487" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">wget 1.8.x and 1.9.x allows a remote malicious web server to overwrite certain files via a redirection URL containing a ".." that resolves to the IP address of the malicious server, which bypasses wget's filtering for ".." sequences.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/18420" source="XF" adv="1">wget-file-overwrite(18420)</ref>
      <ref url="http://www.ubuntulinux.org/support/documentation/usn/usn-145-1" source="UBUNTU">USN-145-1</ref>
      <ref url="http://www.securityfocus.com/bid/11871" source="BID" adv="1">11871</ref>
      <ref url="http://securitytracker.com/id?1012472" source="SECTRACK">1012472</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11682" source="OVAL">oval:org.mitre.oval:def:11682</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110269474112384&amp;w=2" source="BUGTRAQ">20041209 wget: Arbitrary file overwriting/appending/creating and other vulnerabilities</ref>
      <ref url="http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=261755" source="MISC" adv="1">http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=261755</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-771.html" source="REDHAT">RHSA-2005:771</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gnu" name="wget">
        <vers num="1.8" />
        <vers num="1.8.1" />
        <vers num="1.8.2" />
        <vers num="1.9" />
        <vers num="1.9.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1488" published="2005-04-27" name="CVE-2004-1488" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">wget 1.8.x and 1.9.x does not filter or quote control characters when displaying HTTP responses to the terminal, which may allow remote malicious web servers to inject terminal escape sequences and execute arbitrary code.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/18421" source="XF" adv="1">wget-terminal-overwrite(18421)</ref>
      <ref url="http://www.ubuntulinux.org/support/documentation/usn/usn-145-1" source="UBUNTU">USN-145-1</ref>
      <ref url="http://www.securityfocus.com/bid/11871" source="BID" adv="1">11871</ref>
      <ref url="http://securitytracker.com/id?1012472" source="SECTRACK">1012472</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9750" source="OVAL">oval:org.mitre.oval:def:9750</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110269474112384&amp;w=2" source="BUGTRAQ">20041209 wget: Arbitrary file overwriting/appending/creating and other vulnerabilities</ref>
      <ref url="http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=261755" source="MISC" adv="1">http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=261755</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-771.html" source="REDHAT">RHSA-2005:771</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2006_16_sr.html" source="SUSE">SUSE-SR:2006:016</ref>
      <ref url="http://secunia.com/advisories/20960" source="SECUNIA">20960</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gnu" name="wget">
        <vers num="1.8" />
        <vers num="1.8.1" />
        <vers num="1.8.2" />
        <vers num="1.9" />
        <vers num="1.9.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2004-1489" published="2004-12-31" name="CVE-2004-1489" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:N/A:N)" CVSS_score="2.6" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="4.9" CVSS_base_score="2.6">
    <desc>
      <descript source="cve">Opera 7.54 and earlier does not properly limit an applet's access to internal Java packages from Sun, which allows remote attackers to gain sensitive information, such as user names and the installation directory.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200502-17.xml" source="GENTOO" patch="1">GLSA-200502-17</ref>
      <ref url="http://www.opera.com/linux/changelogs/754u1/" source="CONFIRM">http://www.opera.com/linux/changelogs/754u1/</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2004-November/029044.html" source="FULLDISC">20041119 Java Vulnerabilities in Opera 7.54</ref>
    </refs>
    <vuln_soft>
      <prod vendor="opera_software" name="opera_web_browser">
        <vers num="5.0" edition="" />
        <vers num="5.0" edition=":linux" />
        <vers num="5.0" edition=":mac" />
        <vers num="5.0.2" edition="" />
        <vers num="5.0.2" edition=":win32" />
        <vers num="5.1.0" edition="" />
        <vers num="5.1.0" edition=":win32" />
        <vers num="5.1.1" edition="" />
        <vers num="5.1.1" edition=":win32" />
        <vers num="5.12" edition="" />
        <vers num="5.12" edition=":win32" />
        <vers num="6.0" edition="" />
        <vers num="6.0" edition=":win32" />
        <vers num="6.0.1" edition="" />
        <vers num="6.0.1" edition=":win32" />
        <vers num="6.0.1" edition=":linux" />
        <vers num="6.0.2" edition="" />
        <vers num="6.0.2" edition=":linux" />
        <vers num="6.0.2" edition=":win32" />
        <vers num="6.0.3" edition="" />
        <vers num="6.0.3" edition=":linux" />
        <vers num="6.0.3" edition=":win32" />
        <vers num="6.0.4" edition="" />
        <vers num="6.0.4" edition=":win32" />
        <vers num="6.0.5" edition="" />
        <vers num="6.0.5" edition=":win32" />
        <vers num="6.0.6" edition="" />
        <vers num="6.0.6" edition=":win32" />
        <vers num="6.10" edition="" />
        <vers num="6.10" edition=":linux" />
        <vers num="7.0" edition="" />
        <vers num="7.0" edition=":win32" />
        <vers num="7.0.1" edition="" />
        <vers num="7.0.1" edition=":win32" />
        <vers num="7.0.2" edition="" />
        <vers num="7.0.2" edition=":win32" />
        <vers num="7.0.3" edition="" />
        <vers num="7.0.3" edition=":win32" />
        <vers num="7.0_beta1" edition="" />
        <vers num="7.0_beta1" edition=":win32" />
        <vers num="7.0_beta2" edition="" />
        <vers num="7.0_beta2" edition=":win32" />
        <vers num="7.10" />
        <vers num="7.11" />
        <vers num="7.11b" />
        <vers num="7.11j" />
        <vers num="7.20" />
        <vers num="7.20_beta1_build2981" />
        <vers num="7.21" />
        <vers num="7.22" />
        <vers num="7.23" />
        <vers num="7.50" />
        <vers num="7.50b1" />
        <vers num="7.51" />
        <vers num="7.52" />
        <vers num="7.53" />
        <vers num="7.54" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2004-1490" published="2004-12-31" name="CVE-2004-1490" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:P/A:N)" CVSS_score="2.6" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="4.9" CVSS_base_score="2.6">
    <desc>
      <descript source="cve">Opera 7.54 and earlier allows remote attackers to spoof file types in the download dialog via dots and non-breaking spaces (ASCII character code 160) in the (1) Content-Disposition or (2) Content-Type headers.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
      <design />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/11883" source="BID" patch="1">11883</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200502-17.xml" source="GENTOO" patch="1">GLSA-200502-17</ref>
      <ref url="http://secunia.com/secunia_research/2004-19/advisory/" source="MISC" patch="1">http://secunia.com/secunia_research/2004-19/advisory/</ref>
      <ref url="http://secunia.com/advisories/12981" source="SECUNIA" patch="1">12981</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/18423" source="XF">opera-file-type-spoofing(18423)</ref>
      <ref url="http://www.opera.com/linux/changelogs/754u1/" source="CONFIRM">http://www.opera.com/linux/changelogs/754u1/</ref>
    </refs>
    <vuln_soft>
      <prod vendor="opera_software" name="opera_web_browser">
        <vers num="5.0" edition="" />
        <vers num="5.0" edition=":linux" />
        <vers num="5.0" edition=":mac" />
        <vers num="5.0.2" edition="" />
        <vers num="5.0.2" edition=":win32" />
        <vers num="5.1.0" edition="" />
        <vers num="5.1.0" edition=":win32" />
        <vers num="5.1.1" edition="" />
        <vers num="5.1.1" edition=":win32" />
        <vers num="5.12" edition="" />
        <vers num="5.12" edition=":win32" />
        <vers num="6.0" edition="" />
        <vers num="6.0" edition=":win32" />
        <vers num="6.0.1" edition="" />
        <vers num="6.0.1" edition=":win32" />
        <vers num="6.0.1" edition=":linux" />
        <vers num="6.0.2" edition="" />
        <vers num="6.0.2" edition=":linux" />
        <vers num="6.0.2" edition=":win32" />
        <vers num="6.0.3" edition="" />
        <vers num="6.0.3" edition=":linux" />
        <vers num="6.0.3" edition=":win32" />
        <vers num="6.0.4" edition="" />
        <vers num="6.0.4" edition=":win32" />
        <vers num="6.0.5" edition="" />
        <vers num="6.0.5" edition=":win32" />
        <vers num="6.0.6" edition="" />
        <vers num="6.0.6" edition=":win32" />
        <vers num="6.10" edition="" />
        <vers num="6.10" edition=":linux" />
        <vers num="7.0" edition="" />
        <vers num="7.0" edition=":win32" />
        <vers num="7.0.1" edition="" />
        <vers num="7.0.1" edition=":win32" />
        <vers num="7.0.2" edition="" />
        <vers num="7.0.2" edition=":win32" />
        <vers num="7.0.3" edition="" />
        <vers num="7.0.3" edition=":win32" />
        <vers num="7.0_beta1" edition="" />
        <vers num="7.0_beta1" edition=":win32" />
        <vers num="7.0_beta2" edition="" />
        <vers num="7.0_beta2" edition=":win32" />
        <vers num="7.10" />
        <vers num="7.11" />
        <vers num="7.11b" />
        <vers num="7.11j" />
        <vers num="7.20" />
        <vers num="7.20_beta1_build2981" />
        <vers num="7.21" />
        <vers num="7.22" />
        <vers num="7.23" />
        <vers num="7.50" />
        <vers num="7.50b1" />
        <vers num="7.51" />
        <vers num="7.52" />
        <vers num="7.53" />
        <vers num="7.54" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1491" published="2004-12-31" name="CVE-2004-1491" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Opera 7.54 and earlier uses kfmclient exec to handle unknown MIME types, which allows remote attackers to execute arbitrary code via a shortcut or launcher that contains an Exec entry.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/11901" source="BID" patch="1">11901</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200502-17.xml" source="GENTOO" patch="1" adv="1">GLSA-200502-17</ref>
      <ref url="http://secunia.com/advisories/13447/" source="SECUNIA" patch="1" adv="1">13447</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/18457" source="XF">pera-kfmclient-command-execution(18457)</ref>
      <ref url="http://www.zone-h.org/advisories/read/id=6503" source="MISC" adv="1">http://www.zone-h.org/advisories/read/id=6503</ref>
      <ref url="http://www.opera.com/linux/changelogs/754u2/" source="CONFIRM">http://www.opera.com/linux/changelogs/754u2/</ref>
      <ref url="http://lists.suse.com/archive/suse-security-announce/2005-Mar/0007.html" source="SUSE" adv="1">SUSE-SR:2005:008</ref>
    </refs>
    <vuln_soft>
      <prod vendor="opera_software" name="opera_web_browser">
        <vers num="7.54" />
      </prod>
      <prod vendor="gentoo" name="linux">
        <vers num="" />
      </prod>
      <prod vendor="kde" name="kde">
        <vers num="3.2.3" />
      </prod>
      <prod vendor="suse" name="suse_linux">
        <vers num="1.0" />
        <vers num="2.0" />
        <vers num="3.0" />
        <vers num="4.0" />
        <vers num="4.2" />
        <vers num="4.3" />
        <vers num="4.4" />
        <vers num="4.4.1" />
        <vers num="5.0" />
        <vers num="5.1" />
        <vers num="5.2" />
        <vers num="5.3" />
        <vers num="6.0" />
        <vers num="6.1" edition="alpha" />
        <vers num="6.2" />
        <vers num="6.3" edition="" />
        <vers num="6.3" edition=":ppc" />
        <vers num="6.3" edition="alpha" />
        <vers num="6.4" edition="" />
        <vers num="6.4" edition=":i386" />
        <vers num="6.4" edition=":ppc" />
        <vers num="6.4" edition="alpha" />
        <vers num="7.0" edition="" />
        <vers num="7.0" edition=":sparc" />
        <vers num="7.0" edition=":i386" />
        <vers num="7.0" edition=":ppc" />
        <vers num="7.0" edition="alpha" />
        <vers num="7.1" edition="" />
        <vers num="7.1" edition=":spa" />
        <vers num="7.1" edition=":sparc" />
        <vers num="7.1" edition=":x86" />
        <vers num="7.1" edition="alpha" />
        <vers num="7.2" edition="" />
        <vers num="7.2" edition=":i386" />
        <vers num="7.3" edition="" />
        <vers num="7.3" edition=":ppc" />
        <vers num="7.3" edition=":i386" />
        <vers num="7.3" edition=":sparc" />
        <vers num="8.0" edition="" />
        <vers num="8.0" edition=":i386" />
        <vers num="8.1" />
        <vers num="8.2" edition="" />
        <vers num="8.2" edition=":personal" />
        <vers num="9.0" edition="" />
        <vers num="9.0" edition=":personal" />
        <vers num="9.0" edition=":x86_64" />
        <vers num="9.1" edition="" />
        <vers num="9.1" edition=":personal" />
        <vers num="9.1" edition=":x86_64" />
        <vers num="9.2" edition="" />
        <vers num="9.2" edition=":x86_64" />
        <vers num="9.2" edition=":personal" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1492" published="2004-12-31" name="CVE-2004-1492" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Master of Orion III 1.2.5 and earlier allows remote attackers to cause a denial of service (game exit) via a data packet that contains a large size specifier, which causes a large memory allocation to fail.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/17908" source="XF">master-of-orion-size-dos(17908)</ref>
      <ref url="http://www.securityfocus.com/bid/11550" source="BID">11550</ref>
      <ref url="http://secunia.com/advisories/13008" source="SECUNIA">13008</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109889705116038&amp;w=2" source="BUGTRAQ">20041027 Crashs in Master of Orion III 1.2.5</ref>
    </refs>
    <vuln_soft>
      <prod vendor="quicksilver" name="master_of_orion_iii">
        <vers prev="1" num="1.2.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1493" published="2004-12-31" name="CVE-2004-1493" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Master of Orion III 1.2.5 and earlier allows remote attackers to cause a denial of service (server crash) via multiple connections with long nicknames, possibly triggering a buffer overflow.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/17884" source="XF">master-of-orion-nickname-dos(17884)</ref>
      <ref url="http://www.securityfocus.com/bid/11550" source="BID">11550</ref>
      <ref url="http://secunia.com/advisories/13008" source="SECUNIA" adv="1">13008</ref>
      <ref url="http://packetstormsecurity.nl/0410-advisories/masterOrionIII.txt" source="MISC" adv="1">http://packetstormsecurity.nl/0410-advisories/masterOrionIII.txt</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109889705116038&amp;w=2" source="BUGTRAQ" adv="1">20041027 Crashs in Master of Orion III 1.2.5</ref>
    </refs>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1494" published="2004-12-31" name="CVE-2004-1494" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Buffer overflow in the Screen Fetch option in XDICT 2002 through 2005 allows remote attackers to cause a denial of service ( CPU consumption or application exit) and possibly execute arbitrary code via a long string.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/17929" source="XF">xdict-screen-fetch-bo(17929)</ref>
      <ref url="http://secway.org/Advisory/Ad20041026EN.txt" source="MISC" adv="1">http://secway.org/Advisory/Ad20041026EN.txt</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109933696831725&amp;w=2" source="BUGTRAQ" adv="1">20041101 XDICT Buffer OverRun Vulnerability,funny :-)</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2004-November/028241.html" source="FULLDISC" adv="1">20041101 XDICT Buffer OverRun Vulnerability,funny :-)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="kingsoft" name="xdict">
        <vers num="2002" />
        <vers num="2003" />
        <vers num="2004" />
        <vers num="2005" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2004-1495" published="2004-12-31" name="CVE-2004-1495" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:N/A:P)" CVSS_score="2.6" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="4.9" CVSS_base_score="2.6">
    <desc>
      <descript source="cve">The Repair Archive command in WinRAR 3.40 allows remote attackers to cause a denial of service (application crash) via a corrupt ZIP archive.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/11581" source="BID" patch="1">11581</ref>
      <ref url="http://secunia.com/advisories/13070" source="SECUNIA" patch="1">13070</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/17937" source="XF">winrar-repair-archive(17937)</ref>
      <ref url="http://www.rarlabs.com/rarnew.htm" source="CONFIRM">http://www.rarlabs.com/rarnew.htm</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109941351432699&amp;w=2" source="BUGTRAQ">20041102 Medium Risk Vulnerability in WinRAR</ref>
    </refs>
    <vuln_soft>
      <prod vendor="rarlab" name="winrar">
        <vers num="2.90" />
        <vers num="3.0.0" />
        <vers num="3.10" />
        <vers num="3.10_beta3" />
        <vers num="3.10_beta5" />
        <vers num="3.11" />
        <vers num="3.20" />
        <vers num="3.40" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1496" published="2004-12-31" name="CVE-2004-1496" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in Web Forums Server 1.6 and 2.0 Power Pack allows remote attackers to read arbitrary files via a URL containing (1) "..\" (dot dot backslash), (2) "../" (dot dot slash), (3) "/%2E%2E%5C" (encoded dot dot backslash), or (4) "%2E%2E%2F" (encoded dot dot slash).</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109943267328552&amp;w=2" source="BUGTRAQ" adv="1">20041102 Multiple Vulnerabilities in Web Forums Server</ref>
    </refs>
    <vuln_soft>
      <prod vendor="minihttpserver.net" name="web_forums_server">
        <vers num="1.6" />
        <vers num="2.0_power_pack" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1497" published="2004-12-31" name="CVE-2004-1497" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Web Forums Server 1.6 and 2.0 Power Pack stores passwords in plaintext in the Username.ini file, which allows local users to gain privileges.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109943267328552&amp;w=2" source="BUGTRAQ" adv="1">20041102 Multiple Vulnerabilities in Web Forums Server</ref>
    </refs>
  </entry>
  <entry type="CVE" severity="High" seq="2004-1498" published="2004-12-31" name="CVE-2004-1498" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in the compose message form in HELM 3.1.19 and earlier allows remote attackers to execute arbitrary SQL commands via the messageToUserAccNum parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/13079" source="SECUNIA" patch="1" adv="1">13079</ref>
      <ref url="http://www.securityfocus.com/bid/11586" source="BID">11586</ref>
      <ref url="http://www.hat-squad.com/en/000077.html" source="MISC" adv="1">http://www.hat-squad.com/en/000077.html</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109943858026542&amp;w=2" source="BUGTRAQ" adv="1">20041102 [Hat-Squad] SQL injection and XSS Vulnerabilities in HELM</ref>
    </refs>
    <vuln_soft>
      <prod vendor="webhost_automation" name="helm_control_panel">
        <vers num="3.1.10" />
        <vers num="3.1.11" />
        <vers num="3.1.12" />
        <vers num="3.1.13" />
        <vers num="3.1.14" />
        <vers num="3.1.15" />
        <vers num="3.1.16" />
        <vers num="3.1.17" />
        <vers num="3.1.18" />
        <vers num="3.1.19" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1499" published="2004-12-31" name="CVE-2004-1499" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in the compose message form in HELM 3.1.19 and earlier allows remote attackers to execute arbitrary web script or HTML via the Subject field.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/13079" source="SECUNIA" patch="1">13079</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/17943" source="XF">helm-subject-xss(17943)</ref>
      <ref url="http://www.securityfocus.com/bid/11586" source="BID">11586</ref>
      <ref url="http://www.hat-squad.com/en/000077.html" source="MISC" adv="1">http://www.hat-squad.com/en/000077.html</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109943858026542&amp;w=2" source="BUGTRAQ">20041102 [Hat-Squad] SQL injection and XSS Vulnerabilities in HELM</ref>
    </refs>
    <vuln_soft>
      <prod vendor="webhost_automation" name="helm_control_panel">
        <vers num="3.1.10" />
        <vers num="3.1.11" />
        <vers num="3.1.12" />
        <vers num="3.1.13" />
        <vers num="3.1.14" />
        <vers num="3.1.15" />
        <vers num="3.1.16" />
        <vers num="3.1.17" />
        <vers num="3.1.18" />
        <vers num="3.1.19" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2004-1500" published="2004-12-31" name="CVE-2004-1500" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">Format string vulnerability in the Lithtech engine, as used in multiple games, allows remote authenticated users to cause a denial of service (application crash) via format string specifiers in (1) a nickname or (2) a message.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/17972" source="XF" patch="1">lithtech-format-string(17972)</ref>
      <ref url="http://www.securityfocus.com/bid/11610" source="BID">11610</ref>
      <ref url="http://secunia.com/advisories/17317" source="SECUNIA">17317</ref>
      <ref url="http://secunia.com/advisories/13116/" source="SECUNIA" adv="1">13116</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109969394601331&amp;w=2" source="BUGTRAQ" adv="1">20041105 In-game format string bug in the Lithtech engine</ref>
      <ref url="http://aluigi.altervista.org/adv/lithfs-adv.txt" source="MISC">http://aluigi.altervista.org/adv/lithfs-adv.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="freeform_interactive" name="purge_jihad">
        <vers num="2.2.1" />
      </prod>
      <prod vendor="monolith_productions" name="alien_versus_predator">
        <vers num="2.1.0.9.6" />
      </prod>
      <prod vendor="monolith_productions" name="blood">
        <vers num="2.2.1" />
      </prod>
      <prod vendor="monolith_productions" name="contract_jack">
        <vers num="1.1" />
      </prod>
      <prod vendor="monolith_productions" name="global_operations">
        <vers num="2.0" />
        <vers num="2.1" />
      </prod>
      <prod vendor="monolith_productions" name="kiss_psycho_circus">
        <vers num="1.13" />
      </prod>
      <prod vendor="monolith_productions" name="legends_of_might_and_magic">
        <vers num="1.1" />
      </prod>
      <prod vendor="monolith_productions" name="no_one_lives_forever">
        <vers num="1.0.004" />
        <vers num="2.1.3" />
      </prod>
      <prod vendor="monolith_productions" name="sanity">
        <vers num="1.0" />
      </prod>
      <prod vendor="monolith_productions" name="shogo">
        <vers num="2.2" />
      </prod>
      <prod vendor="monolith_productions" name="tron">
        <vers num="2.0.1.42" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1501" published="2004-12-31" name="CVE-2004-1501" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The webmail service in 602 Lan Suite 2004.0.04.0909 and earlier allows remote attackers to cause a denial of service (CPU and memory consumption) by sending a POST request with a large Content-Length value, then disconnecting without sending that amount of data.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/17977" source="XF" patch="1">602pro-mail-post-dos(17977)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109976745017459&amp;w=2" source="BUGTRAQ" adv="1">20041106 Resources consumption in 602 Lan Suite 2004.0.04.0909</ref>
    </refs>
    <vuln_soft>
      <prod vendor="software602" name="602lan_suite">
        <vers prev="1" num="2004.0.04.0909" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1502" published="2004-12-31" name="CVE-2004-1502" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The Telnet proxy in 602 Lan Suite 2004.0.04.0909 and earlier allows remote attackers to cause a denial of service (socket exhaustion) via a Telnet request to an IP address of the proxy's network interface, which causes a loop.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/17979" source="XF" patch="1">602pro-telnet-loopback-dos(17979)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109976745017459&amp;w=2" source="BUGTRAQ" adv="1">20041106 Resources consumption in 602 Lan Suite 2004.0.04.0909</ref>
    </refs>
    <vuln_soft>
      <prod vendor="software602" name="602lan_suite">
        <vers prev="1" num="2004.0.04.0909" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1503" published="2004-12-31" name="CVE-2004-1503" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Integer overflow in the InitialDirContext in Java Runtime Environment (JRE) 1.4.2, 1.5.0 and possibly other versions allows remote attackers to cause a denial of service (Java exception and failed DNS requests) via a large number of DNS requests, which causes the xid variable to wrap around and become negative.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input bound="1" />
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/17990" source="XF">sun-jre-dns-dos(17990)</ref>
      <ref url="http://www.securityfocus.com/bid/11619" source="BID">11619</ref>
      <ref url="http://secunia.com/advisories/13142" source="SECUNIA" adv="1">13142</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109994063331773&amp;w=2" source="BUGTRAQ" adv="1">20041108 DOS against Java JNDI/DNS</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="jre">
        <vers num="1.4.2" />
        <vers num="1.5.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1504" published="2004-12-31" name="CVE-2004-1504" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The displaycontent function in config.php for Just Another Flat file (JAF) CMS 3.0RC allows remote attackers to gain sensitive information via a blank show parameter, which reveals the installation path in an error message, as demonstrated using index.php.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/18006" source="XF" patch="1">jaf-cms-path-disclosure(18006)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110004150430309&amp;w=2" source="BUGTRAQ" adv="1">20041109 Vulnerabilities in JAF CMS</ref>
      <ref url="http://echo.or.id/adv/adv08-y3dips-2004.txt" source="MISC" adv="1">http://echo.or.id/adv/adv08-y3dips-2004.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="salims_softhouse" name="jaf_cms">
        <vers num="3.0" edition="rc" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-1505" published="2004-12-31" name="CVE-2004-1505" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Directory traversal vulnerability in index.php in Just Another Flat file (JAF) CMS 3.0RC allows remote attackers to read arbitrary files and possibly execute PHP code via a .. (dot dot) in the show parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/17983" source="XF" patch="1">jaf-cms-file-inlcude(17983)</ref>
      <ref url="http://www.securityfocus.com/bid/11627" source="BID" patch="1">11627</ref>
      <ref url="http://secunia.com/advisories/13104" source="SECUNIA" patch="1" adv="1">13104</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110004150430309&amp;w=2" source="BUGTRAQ">20041109 Vulnerabilities in JAF CMS</ref>
      <ref url="http://echo.or.id/adv/adv08-y3dips-2004.txt" source="MISC" adv="1">http://echo.or.id/adv/adv08-y3dips-2004.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="salims_softhouse" name="jaf_cms">
        <vers num="3.0" edition="rc" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1506" published="2004-12-31" name="CVE-2004-1506" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in WebCalendar allow remote attackers to inject arbitrary web script via (1) view_entry.php, (2) view_d.php, (3) usersel.php, (4) datesel.php, (5) trailer.php, or (6) styles.php, as demonstrated using img srg tags.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/18026" source="XF" patch="1">webcalendar-img-src-xss(18026)</ref>
      <ref url="http://www.securityfocus.com/bid/11651" source="BID">11651</ref>
      <ref url="http://secunia.com/advisories/13164" source="SECUNIA" adv="1">13164</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110011618724455&amp;w=2" source="BUGTRAQ">20041109 Multiple Vulnerabilities in WebCalendar</ref>
    </refs>
    <vuln_soft>
      <prod vendor="webcalendar" name="webcalendar">
        <vers num="0.9.11" />
        <vers num="0.9.15" />
        <vers num="0.9.16" />
        <vers num="0.9.19" />
        <vers num="0.9.20" />
        <vers num="0.9.21" />
        <vers num="0.9.22" />
        <vers num="0.9.23" />
        <vers num="0.9.24" />
        <vers num="0.9.25" />
        <vers num="0.9.26" />
        <vers num="0.9.27" />
        <vers num="0.9.28" />
        <vers num="0.9.29" />
        <vers num="0.9.30" />
        <vers num="0.9.31" />
        <vers num="0.9.32" />
        <vers num="0.9.33" />
        <vers num="0.9.34" />
        <vers num="0.9.35" />
        <vers num="0.9.36" />
        <vers num="0.9.37" />
        <vers num="0.9.38" />
        <vers num="0.9.39" />
        <vers num="0.9.40" />
        <vers num="0.9.41" />
        <vers num="0.9.42" />
        <vers num="0.9.43" />
        <vers num="0.9.44" />
        <vers num="0.9.8" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1507" published="2004-12-31" name="CVE-2004-1507" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">CRLF injection vulnerability in login.php in WebCalendar allows remote attackers to inject CRLF sequences via the return_path parameter and perform HTTP Response Splitting attacks to modify expected HTML content from the server.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/18027" source="XF" patch="1">webcalendar-response-splitting(18027)</ref>
      <ref url="http://www.securityfocus.com/bid/11651" source="BID">11651</ref>
      <ref url="http://secunia.com/advisories/13164" source="SECUNIA" adv="1">13164</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110011618724455&amp;w=2" source="BUGTRAQ">20041109 Multiple Vulnerabilities in WebCalendar</ref>
    </refs>
    <vuln_soft>
      <prod vendor="webcalendar" name="webcalendar">
        <vers num="0.9.11" />
        <vers num="0.9.15" />
        <vers num="0.9.16" />
        <vers num="0.9.19" />
        <vers num="0.9.20" />
        <vers num="0.9.21" />
        <vers num="0.9.22" />
        <vers num="0.9.23" />
        <vers num="0.9.24" />
        <vers num="0.9.25" />
        <vers num="0.9.26" />
        <vers num="0.9.27" />
        <vers num="0.9.28" />
        <vers num="0.9.29" />
        <vers num="0.9.30" />
        <vers num="0.9.31" />
        <vers num="0.9.32" />
        <vers num="0.9.33" />
        <vers num="0.9.34" />
        <vers num="0.9.35" />
        <vers num="0.9.36" />
        <vers num="0.9.37" />
        <vers num="0.9.38" />
        <vers num="0.9.39" />
        <vers num="0.9.40" />
        <vers num="0.9.41" />
        <vers num="0.9.42" />
        <vers num="0.9.43" />
        <vers num="0.9.44" />
        <vers num="0.9.8" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-1508" published="2004-12-31" name="CVE-2004-1508" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">init.php in WebCalendar allows remote attackers to execute arbitrary local PHP scripts via the user_inc parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/18028" source="XF" patch="1">webcalendar-init-file-include(18028)</ref>
      <ref url="http://www.securityfocus.com/bid/11651" source="BID">11651</ref>
      <ref url="http://secunia.com/advisories/13164" source="SECUNIA" adv="1">13164</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110011618724455&amp;w=2" source="BUGTRAQ">20041109 Multiple Vulnerabilities in WebCalendar</ref>
    </refs>
    <vuln_soft>
      <prod vendor="webcalendar" name="webcalendar">
        <vers num="0.9.11" />
        <vers num="0.9.15" />
        <vers num="0.9.16" />
        <vers num="0.9.19" />
        <vers num="0.9.20" />
        <vers num="0.9.21" />
        <vers num="0.9.22" />
        <vers num="0.9.23" />
        <vers num="0.9.24" />
        <vers num="0.9.25" />
        <vers num="0.9.26" />
        <vers num="0.9.27" />
        <vers num="0.9.28" />
        <vers num="0.9.29" />
        <vers num="0.9.30" />
        <vers num="0.9.31" />
        <vers num="0.9.32" />
        <vers num="0.9.33" />
        <vers num="0.9.34" />
        <vers num="0.9.35" />
        <vers num="0.9.36" />
        <vers num="0.9.37" />
        <vers num="0.9.38" />
        <vers num="0.9.39" />
        <vers num="0.9.40" />
        <vers num="0.9.41" />
        <vers num="0.9.42" />
        <vers num="0.9.43" />
        <vers num="0.9.44" />
        <vers num="0.9.8" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1509" published="2004-12-31" name="CVE-2004-1509" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">validate.php in WebCalendar allows remote attackers to gain sensitive information via an invalid encoded_login parameter, which reveals the full path in an error message.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/18029" source="XF" patch="1">webcalendar-encodedlogin-path-disclosure(18029)</ref>
      <ref url="http://www.securityfocus.com/bid/11651" source="BID">11651</ref>
      <ref url="http://secunia.com/advisories/13164" source="SECUNIA" adv="1">13164</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110011618724455&amp;w=2" source="BUGTRAQ">20041109 Multiple Vulnerabilities in WebCalendar</ref>
    </refs>
  </entry>
  <entry type="CVE" severity="High" seq="2004-1510" published="2004-12-31" name="CVE-2004-1510" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">WebCalendar allows remote attackers to gain privileges by modifying critical parameters to (1) view_entry.php or (2) upcoming.php.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/18030" source="XF" patch="1">webcalendar-scripts-gain-access(18030)</ref>
      <ref url="http://www.securityfocus.com/bid/11651" source="BID">11651</ref>
      <ref url="http://secunia.com/advisories/13164" source="SECUNIA" adv="1">13164</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110011618724455&amp;w=2" source="BUGTRAQ" adv="1">20041109 Multiple Vulnerabilities in WebCalendar</ref>
    </refs>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1511" published="2004-12-31" name="CVE-2004-1511" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Hotfoon 4.0 does not notify users before opening links in web browsers, which could allow remote attackers to execute arbitrary code via a certian link sent in a chat window.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/18038" source="XF">hotfoon-url-command-execution(18038)</ref>
      <ref url="http://secunia.com/advisories/13173" source="SECUNIA" adv="1">13173</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110014517703092&amp;w=2" source="BUGTRAQ">20041110 Hotfoon Ver 4.0 Highv Risk</ref>
    </refs>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1512" published="2004-12-31" name="CVE-2004-1512" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in Response_default.html in 04WebServer 1.42 allows remote attackers to execute arbitrary web script or HTML via script code in the URL, which is not quoted in the resulting default error page.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/18033" source="XF" patch="1">04webserver-error-xss(18033)</ref>
      <ref url="http://www.securityfocus.com/bid/11652" source="BID" patch="1">11652</ref>
      <ref url="http://www.security.org.sg/vuln/04webserver142.html" source="MISC" patch="1">http://www.security.org.sg/vuln/04webserver142.html</ref>
      <ref url="http://secunia.com/advisories/13159/" source="SECUNIA" adv="1">13159</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110054395311823&amp;w=2" source="BUGTRAQ">20041115 Re: 04WebServer Three Vulnerabilities</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110012542615484&amp;w=2" source="BUGTRAQ">20041110 04WebServer Three Vulnerabilities</ref>
      <ref url="http://www.soft3304.net/04WebServer/Security.html" source="CONFIRM">http://www.soft3304.net/04WebServer/Security.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="soft3304" name="04webserver">
        <vers num="1.42" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1513" published="2004-12-31" name="CVE-2004-1513" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">04WebServer 1.42 does not adequately filter data that is written to log files, which could allow remote attackers to inject carriage return characters into the log file and spoof log entries.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/18034" source="XF" patch="1">04webserver-web-log-spoofing(18034)</ref>
      <ref url="http://www.securityfocus.com/bid/11652" source="BID" patch="1">11652</ref>
      <ref url="http://www.security.org.sg/vuln/04webserver142.html" source="MISC" patch="1" adv="1">http://www.security.org.sg/vuln/04webserver142.html</ref>
      <ref url="http://secunia.com/advisories/13159/" source="SECUNIA" adv="1">13159</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110054395311823&amp;w=2" source="BUGTRAQ">20041115 Re: 04WebServer Three Vulnerabilities</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110012542615484&amp;w=2" source="BUGTRAQ">20041110 04WebServer Three Vulnerabilities</ref>
      <ref url="http://www.soft3304.net/04WebServer/Security.html" source="CONFIRM">http://www.soft3304.net/04WebServer/Security.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="soft3304" name="04webserver">
        <vers num="1.42" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1514" published="2004-12-31" name="CVE-2004-1514" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">04WebServer 1.42 allows remote attackers to cause a denial of service (fail to restart properly) via an HTTP request for an MS-DOS device name such as COM2.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/18036" source="XF" patch="1">04webserver-dos-devices-dos(18036)</ref>
      <ref url="http://www.securityfocus.com/bid/11652" source="BID" patch="1">11652</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110054395311823&amp;w=2" source="BUGTRAQ" patch="1">20041115 Re: 04WebServer Three Vulnerabilities</ref>
      <ref url="http://www.security.org.sg/vuln/04webserver142.html" source="MISC" adv="1">http://www.security.org.sg/vuln/04webserver142.html</ref>
      <ref url="http://secunia.com/advisories/13159/" source="SECUNIA" adv="1">13159</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110012542615484&amp;w=2" source="BUGTRAQ">20041110 04WebServer Three Vulnerabilities</ref>
      <ref url="http://www.soft3304.net/04WebServer/Security.html" source="CONFIRM">http://www.soft3304.net/04WebServer/Security.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="soft3304" name="04webserver">
        <vers num="1.42" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-1515" published="2004-12-31" name="CVE-2004-1515" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in (1) ttlast.php and (2) last10.php in vBulletin 3.0.x allows remote attackers to execute arbitrary SQL statements via the fsel parameter, as demonstrated using last.php.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110019198507100&amp;w=2" source="BUGTRAQ" adv="1">20041111 SQL injection in vBulletin forums (last10.php)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="jelsoft" name="vbulletin">
        <vers num="3.0.0" />
        <vers num="3.0.0_beta_2" />
        <vers num="3.0.0_can4" />
        <vers num="3.0.0_rc4" />
        <vers num="3.0.1" />
        <vers num="3.0.2" />
        <vers num="3.0.3" />
        <vers num="3.0.4" />
        <vers num="3.0.5" />
        <vers num="3.0.6" />
        <vers num="3.0_beta_2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1516" published="2004-12-31" name="CVE-2004-1516" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">CRLF injection vulnerability in index.php in phpWebSite 0.9.3-4 allows remote attackers to perform HTTP Response Splitting attacks to modify expected HTML content from the server via the block_username parameter in the user module.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/18046" source="XF" patch="1">phpwebsite-response-splitting(18046)</ref>
      <ref url="http://www.securityfocus.com/bid/11673" source="BID" patch="1">11673</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200411-35.xml" source="GENTOO" patch="1" adv="1">GLSA-200411-35</ref>
      <ref url="http://secunia.com/advisories/13172/" source="SECUNIA" patch="1" adv="1">13172</ref>
      <ref url="http://phpwebsite.appstate.edu/index.php?module=announce&amp;ANN_id=863&amp;ANN_user_op=view" source="CONFIRM" patch="1">http://phpwebsite.appstate.edu/index.php?module=announce&amp;ANN_id=863&amp;ANN_user_op=view</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110022027420583&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20041111 security hole (http response splitting) in phpwebsite</ref>
    </refs>
    <vuln_soft>
      <prod vendor="phpwebsite" name="phpwebsite">
        <vers num="0.7.3" />
        <vers num="0.8.2" />
        <vers num="0.8.3" />
        <vers num="0.9.3" />
        <vers num="0.9.3.1" />
        <vers num="0.9.3.2" />
        <vers num="0.9.3.3" />
        <vers num="0.9.3.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-1517" published="2004-12-31" name="CVE-2004-1517" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Zone Labs IMsecure and IMsecure Pro before 1.5 allow remote attackers to bypass Active Link Filtering via an instant message containing a URL with hex encoded file extenstions.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/18042" source="XF" patch="1">imsecure-active-link-bypass(18042)</ref>
      <ref url="http://www.securityfocus.com/bid/11662" source="BID" patch="1">11662</ref>
      <ref url="http://download.zonelabs.com/bin/free/securityAlert/16.html" source="CONFIRM" patch="1" adv="1">http://download.zonelabs.com/bin/free/securityAlert/16.html</ref>
      <ref url="http://secunia.com/advisories/13169" source="SECUNIA" adv="1">13169</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110020607924001&amp;w=2" source="BUGTRAQ" adv="1">20041111 Zone Labs IMsecure Active Link Filter Bypass</ref>
    </refs>
    <vuln_soft>
      <prod vendor="zonelabs" name="imsecure">
        <vers num="1.0.0.0" />
        <vers num="1.0.1.0" />
        <vers num="1.0.2.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1518" published="2004-12-31" name="CVE-2004-1518" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">SQL injection vulnerability in follow.php in Phorum 5.0.12 and earlier allows remote authenticated users to execute arbitrary SQL command via the forum_id parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/18045" source="XF" patch="1">phorum-followphp-sql-injection(18045)</ref>
      <ref url="http://www.securityfocus.com/bid/11660" source="BID" patch="1">11660</ref>
      <ref url="http://secunia.com/advisories/13174" source="SECUNIA" patch="1" adv="1">13174</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110021385926870&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20041111 [waraxe-2004-SA#037 - Sql injection bug in Phorum 5.0.12 and older versions]</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2004-November/028609.html" source="FULLDISC" patch="1" adv="1">20041111 [waraxe-2004-SA#037 - Sql injection bug in Phorum 5.0.12 and older versions]</ref>
    </refs>
  </entry>
  <entry type="CVE" severity="High" seq="2004-1519" published="2004-12-31" name="CVE-2004-1519" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in bug.php in phpBugTracker 0.9.1 allows remote attackers to execute arbitrary SQL commands via (1) the bug_id parameter in a viewvotes operation or (2) the project parameter in an add operation.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/18053" source="XF">phpbugtracker-bug-sql-injection(18053)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/18079" source="XF">phpbugtracker-project-sql-injection(18079)</ref>
      <ref url="http://www.osvdb.org/displayvuln.php?osvdb_id=11718" source="OSVDB">11718</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110037408101974&amp;w=2" source="BUGTRAQ">20041112 SQL Injection in phpBT (bug.php) add project</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110037345428403&amp;w=2" source="BUGTRAQ">20041112 SQL Injection in phpBT (bug.php - Add)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110029315521568&amp;w=2" source="BUGTRAQ">20041112 SQL Injection in phpBT (bug.php)</ref>
    </refs>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1520" published="2004-12-31" name="CVE-2004-1520" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Stack-based buffer overflow in IPSwitch IMail 8.13 allows remote authenticated users to execute arbitrary code via a long IMAP DELETE command.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/11675" source="BID" patch="1">11675</ref>
      <ref url="http://secunia.com/advisories/13200" source="SECUNIA" patch="1" adv="1">13200</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/18058" source="XF">ipswitch-delete-bo(18058)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110037283803560&amp;w=2" source="BUGTRAQ">20041112 IPSwitch-IMail-8.13 Stack Overflow in the DELETE Command</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ipswitch" name="imail">
        <vers num="8.13" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1521" published="2004-12-31" name="CVE-2004-1521" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Eudora 6.2.0.14 does not issue a warning when a user forwards an e-mail message that contains base64 or quoted-printable encoded attachments, which makes it easier for remote attackers to read arbitrary files via spoofed "Converted" headers.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/18064" source="XF">eudora-base64-attach-spoof-variant(18064)</ref>
      <ref url="http://packetstormsecurity.nl/0411-exploits/eudora62014.txt" source="MISC" adv="1">http://packetstormsecurity.nl/0411-exploits/eudora62014.txt</ref>
      <ref url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=110053102601655&amp;w=2" source="NTBUGTRAQ" adv="1">20041113 Eudora 6.2 attachment spoof</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110037078519691&amp;w=2" source="BUGTRAQ" adv="1">20041113 Eudora 6.2 attachment spoof</ref>
    </refs>
    <vuln_soft>
      <prod vendor="qualcomm" name="eudora">
        <vers num="6.2.0.14" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1522" published="2004-12-31" name="CVE-2004-1522" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Format string vulnerability in Army Men RTS 1.0 allows remote attackers to cause a denial of service (application crash) via a nickname that contains format strings.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/18065" source="XF">army-men-rts-format-string(18065)</ref>
      <ref url="http://www.securityfocus.com/bid/11679" source="BID">11679</ref>
      <ref url="http://secunia.com/advisories/13186" source="SECUNIA" adv="1">13186</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110053709800174&amp;w=2" source="BUGTRAQ" adv="1">20041114 Format string bug in Army Men RTS</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2004-November/028757.html" source="FULLDISC" adv="1">20041114 Format string bug in Army Men RTS</ref>
    </refs>
    <vuln_soft>
      <prod vendor="3do" name="army_men_real_time_strategy_game">
        <vers num="1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1523" published="2004-12-31" name="CVE-2004-1523" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Format string vulnerability in the game console in Hired Team: Trial 2.0 and earlier and 2.200 allows remote attackers to cause a denial of service (application crash) via format string specifiers in a message.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/18083" source="XF">hired-team-format-string(18083)</ref>
      <ref url="http://www.securityfocus.com/bid/11683" source="BID">11683</ref>
      <ref url="http://secunia.com/advisories/13207" source="SECUNIA" adv="1">13207</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110054260919742&amp;w=2" source="BUGTRAQ" adv="1">20041115 Multiple vulnerabilities in Hired Team: Trial (Shine engine)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="new_media_generation" name="hired_team_trial">
        <vers num="2.0" />
        <vers num="2.1" />
        <vers num="2.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1524" published="2004-12-31" name="CVE-2004-1524" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Hired Team: Trial 2.0 and earlier and 2.200 allows remote attackers to cause a denial of service (game interruption) via a malformed UDP packet sent to a game port, such as port 29200.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/18085" source="XF">hired-team-udp-dos(18085)</ref>
      <ref url="http://www.securityfocus.com/bid/11683" source="BID">11683</ref>
      <ref url="http://secunia.com/advisories/13207" source="SECUNIA">13207</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110054260919742&amp;w=2" source="BUGTRAQ">20041115 Multiple vulnerabilities in Hired Team: Trial (Shine engine)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="new_media_generation" name="hired_team_trial">
        <vers prev="1" num="2.0" />
        <vers num="2.1" />
        <vers num="2.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1525" published="2004-12-31" name="CVE-2004-1525" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Hired Team: Trial 2.0 and earlier and 2.200 allows remote attackers to cause a denial of service (application crash) via the status command.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/18086" source="XF">hired-team-status-dos(18086)</ref>
      <ref url="http://www.securityfocus.com/bid/11683" source="BID">11683</ref>
      <ref url="http://secunia.com/advisories/13207" source="SECUNIA">13207</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110054260919742&amp;w=2" source="BUGTRAQ">20041115 Multiple vulnerabilities in Hired Team: Trial (Shine engine)</ref>
    </refs>
  </entry>
  <entry type="CVE" severity="High" seq="2004-1526" published="2004-12-31" name="CVE-2004-1526" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Hired Team: Trial 2.0 and earlier and 2.200 does not limit how game players can kick other players off the server, including the administrator.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/13207" source="SECUNIA">13207</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110054260919742&amp;w=2" source="BUGTRAQ">20041115 Multiple vulnerabilities in Hired Team: Trial (Shine engine)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="new_media_generation" name="hired_team_trial">
        <vers prev="1" num="2.0" />
        <vers num="2.1" />
        <vers num="2.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1527" published="2004-12-31" name="CVE-2004-1527" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Microsoft Internet Explorer 6.0 SP1 does not properly handle certain character strings in the Path attribute, which can cause it to modify cookies in other domains when the attacker's domain name is within the target's domain name or when wildcard DNS is being used, which allows remote attackers to hijack web sessions.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.lac.co.jp/business/sns/intelligence/SNSadvisory_e/79_e.html" source="MISC" patch="1" adv="1">http://www.lac.co.jp/business/sns/intelligence/SNSadvisory_e/79_e.html</ref>
      <ref url="http://secunia.com/advisories/13208" source="SECUNIA" patch="1">13208</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/18073" source="XF">ie-path-cookie-overwrite(18073)</ref>
      <ref url="http://www.securityfocus.com/bid/11680" source="BID">11680</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110053968530613&amp;w=2" source="BUGTRAQ">20041115 [SNS Advisory No.79] A Possibility of Cookie Overwrite in Microsoft Internet Explorer</ref>
    </refs>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1528" published="2004-12-31" name="CVE-2004-1528" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The Event Calendar module 2.13 for PHP-Nuke allows remote attackers to gain sensitive information via an HTTP request to (1) config.php, (2) index.php, or (3) submit.php, which reveal the full path in an error message.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/18105" source="XF">event-calendar-path-disclosure(18105)</ref>
      <ref url="http://www.waraxe.us/index.php?modname=sa&amp;id=38" source="MISC">http://www.waraxe.us/index.php?modname=sa&amp;id=38</ref>
      <ref url="http://www.securityfocus.com/bid/11693" source="BID">11693</ref>
      <ref url="http://secunia.com/advisories/13213" source="SECUNIA">13213</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110064626111756&amp;w=2" source="BUGTRAQ">20041116 [waraxe-2004-SA#038 - Multiple vulnerabilities in Event Calendar module for PhpNuke]</ref>
    </refs>
    <vuln_soft>
      <prod vendor="rob_sutton" name="php-nuke_event_calendar">
        <vers num="2.13" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1529" published="2004-12-31" name="CVE-2004-1529" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in the Event Calendar module 2.13 for PHP-Nuke allows remote attackers to execute arbitrary web script via the (1) type, (2) day, (3) month, or (4) year parameters in a Preview operation, or (5) event comments.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/18107" source="XF">event-calendar-comment-xss(18107)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/18106" source="XF">event-calendar-xss(18106)</ref>
      <ref url="http://www.waraxe.us/index.php?modname=sa&amp;id=38" source="MISC">http://www.waraxe.us/index.php?modname=sa&amp;id=38</ref>
      <ref url="http://www.securityfocus.com/bid/11693" source="BID">11693</ref>
      <ref url="http://secunia.com/advisories/13213" source="SECUNIA">13213</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110064626111756&amp;w=2" source="BUGTRAQ">20041116 [waraxe-2004-SA#038 - Multiple vulnerabilities in Event Calendar module for PhpNuke]</ref>
    </refs>
    <vuln_soft>
      <prod vendor="rob_sutton" name="php-nuke_event_calendar">
        <vers num="2.13" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-1530" published="2004-12-31" name="CVE-2004-1530" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in the Event Calendar module 2.13 for PHP-Nuke allows remote attackers to execute arbitrary SQL commands via the (1) eid or (2) cid parameters.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/18104" source="XF">event-calendar-sql-injection(18104)</ref>
      <ref url="http://www.waraxe.us/index.php?modname=sa&amp;id=38" source="MISC">http://www.waraxe.us/index.php?modname=sa&amp;id=38</ref>
      <ref url="http://www.securityfocus.com/bid/11693" source="BID">11693</ref>
      <ref url="http://secunia.com/advisories/13213" source="SECUNIA">13213</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110064626111756&amp;w=2" source="BUGTRAQ">20041116 [waraxe-2004-SA#038 - Multiple vulnerabilities in Event Calendar module for PhpNuke]</ref>
    </refs>
  </entry>
  <entry type="CVE" severity="High" seq="2004-1531" published="2004-12-31" name="CVE-2004-1531" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in post.php in Invision Power Board (IPB) 2.0.0 through 2.0.2 allows remote attackers to execute arbitrary SQL commands via the qpid parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/13245" source="SECUNIA" patch="1">13245</ref>
      <ref url="http://forums.invisionpower.com/index.php?showtopic=154916" source="CONFIRM" patch="1">http://forums.invisionpower.com/index.php?showtopic=154916</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/18164" source="XF">invisionpowerboard-sql-injection(18164)</ref>
      <ref url="http://www.securityfocus.com/bid/11703" source="BID">11703</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111462421824202&amp;w=2" source="BUGTRAQ">20050427 Re: SQL-injections in Invision Power Board v2.0.1</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111454805209191&amp;w=2" source="BUGTRAQ">20050425 SQL-injections in Invision Power Board v2.0.1</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110079592702417&amp;w=2" source="BUGTRAQ">20041118 [MaxPatrol] SQL-injection in Invision Power Board 2.x</ref>
    </refs>
    <vuln_soft>
      <prod vendor="invision_power_services" name="invision_board">
        <vers num="2.0" />
        <vers num="2.0.1" />
        <vers num="2.0.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-1532" published="2004-12-31" name="CVE-2004-1532" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">AppServ 2.5.x and earlier installs a default username and password, which allows remote attackers to gain access.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <config />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/18163" source="XF">appserv-default-account(18163)</ref>
      <ref url="http://www.securityfocus.com/bid/11704" source="BID">11704</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110079586328430&amp;w=2" source="BUGTRAQ">20041118 AppServ 2.5.x and Prior Exploit</ref>
    </refs>
    <vuln_soft>
      <prod vendor="appserv_open_project" name="appserv">
        <vers num="2.4" />
        <vers num="2.4.1" />
        <vers num="2.4.2" />
        <vers num="2.5" />
        <vers num="2.5.1" />
        <vers num="2.5.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1533" published="2004-12-31" name="CVE-2004-1533" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Buffer overflow in pop3svr.exe for DMS POP3 1.5.3.27 and earlier allows remote attackers to cause a denial of service (service crash) via a long (1) username or (2) password.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/18161" source="XF" patch="1">dms-pop3-username-bo(18161)</ref>
      <ref url="http://www.securityfocus.com/bid/11705" source="BID" patch="1">11705</ref>
      <ref url="http://www.digitalmapping.sk.ca/pop3srv/Update.asp" source="CONFIRM" patch="1">http://www.digitalmapping.sk.ca/pop3srv/Update.asp</ref>
      <ref url="http://secunia.com/advisories/13248" source="SECUNIA" patch="1" adv="1">13248</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110081437508585&amp;w=2" source="BUGTRAQ">20041118 Buffer overlow in DMS POP3 Server for Windows 2000/XP 1.5.3 build</ref>
    </refs>
    <vuln_soft>
      <prod vendor="digital_mappings_systems" name="pop3_server">
        <vers num="1.5.3_build37" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1534" published="2004-12-31" name="CVE-2004-1534" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">ZoneAlarm and ZoneAlarm Pro before 5.5.062, with ad-blocking enabled, allows remote web sites to cause a denial of service (application instability or system hang) via certain JavaScript.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/18159" source="XF" patch="1">zonealarm-adblock-dos(18159)</ref>
      <ref url="http://www.securityfocus.com/bid/11706" source="BID" patch="1">11706</ref>
      <ref url="http://secunia.com/advisories/13244/" source="SECUNIA" patch="1" adv="1">13244</ref>
      <ref url="http://download.zonelabs.com/bin/free/securityAlert/18.html" source="CONFIRM" patch="1" adv="1">http://download.zonelabs.com/bin/free/securityAlert/18.html</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110088808402495&amp;w=2" source="BUGTRAQ">20041118 Zone Labs Ad-Blocking Instability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="zonelabs" name="zonealarm">
        <vers num="4.0" edition="" />
        <vers num="4.0" edition=":pro" />
        <vers num="4.5" edition="" />
        <vers num="4.5" edition=":pro" />
        <vers num="4.5.538.001" edition="" />
        <vers num="4.5.538.001" edition=":pro" />
        <vers num="5.0.590.015" edition="" />
        <vers num="5.0.590.015" edition=":pro" />
        <vers num="5.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-1535" published="2004-12-31" name="CVE-2004-1535" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">PHP remote file inclusion vulnerability in admin_cash.php for the Cash Mod module for phpBB allows remote attackers to execute arbitrary PHP code by modifying the phpbb_root_path parameter to reference a URL on a remote web server that contains the code.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/18151" source="XF" patch="1">phpbb-admincashphp-file-include(18151)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110082153702843&amp;w=2" source="BUGTRAQ">20041118 Re: Vulnerabilities in forum phpBB2 with Cash_Mod (all ver.)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110075903308817&amp;w=2" source="BUGTRAQ">20041118 Vulnerabilities in forum phpBB2 with Cash_Mod (all ver.)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="phpbb_group" name="phpbb">
        <vers num="2.0.0" />
        <vers num="2.0.1" />
        <vers num="2.0.10" />
        <vers num="2.0.2" />
        <vers num="2.0.3" />
        <vers num="2.0.4" />
        <vers num="2.0.5" />
        <vers num="2.0.6" />
        <vers num="2.0.7" />
        <vers num="2.0.8" />
        <vers num="2.0.9" />
        <vers num="rc1" />
        <vers num="rc1_pre" />
        <vers num="rc2" />
        <vers num="rc3" />
        <vers num="rc4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-1536" published="2004-12-31" name="CVE-2004-1536" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in index.php in the ibProArcade module for Invision Power Board (IPB) 1.x and 2.x allows remote attackers to execute arbitrary SQL commands via the cat parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/18180" source="XF">ibproarcade-category-sql-injection(18180)</ref>
      <ref url="http://www.securityfocus.com/bid/11719" source="BID">11719</ref>
      <ref url="http://securitytracker.com/id?1012292" source="SECTRACK">1012292</ref>
      <ref url="http://secunia.com/advisories/13260" source="SECUNIA" adv="1">13260</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110098512318132&amp;w=2" source="BUGTRAQ">20041120 IpbProArace 2.5.x SQL injection.</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ipbproarcade" name="ipbproarcade">
        <vers prev="1" num="2.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1537" published="2004-12-31" name="CVE-2004-1537" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in popup.php in PHPKIT 1.6.03 through 1.6.1 allows remote attackers to execute arbitrary web script via the img parameter.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/18204" source="XF">phpkit-popup-xss(18204)</ref>
      <ref url="http://www.securityfocus.com/bid/11725" source="BID">11725</ref>
      <ref url="http://secunia.com/advisories/13262" source="SECUNIA" adv="1">13262</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110117116115493&amp;w=2" source="BUGTRAQ">20041122 PHPKIT SQL Injection, XSS</ref>
    </refs>
    <vuln_soft>
      <prod vendor="phpkit" name="phpkit">
        <vers num="1.6.02" />
        <vers num="1.6.03" />
        <vers num="1.6.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-1538" published="2004-12-31" name="CVE-2004-1538" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in include.php in PHPKIT 1.6.03 through 1.6.1 allows remote attackers to execute arbitrary SQL commands via the id parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/18205" source="XF">phpkit-include-sql-injection(18205)</ref>
      <ref url="http://www.securityfocus.com/bid/11725" source="BID">11725</ref>
      <ref url="http://secunia.com/advisories/13262" source="SECUNIA" adv="1">13262</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110117116115493&amp;w=2" source="BUGTRAQ">20041122 PHPKIT SQL Injection, XSS</ref>
    </refs>
    <vuln_soft>
      <prod vendor="phpkit" name="phpkit">
        <vers num="1.6.02" />
        <vers num="1.6.03" />
        <vers num="1.6.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1539" published="2004-12-31" name="CVE-2004-1539" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Halo: Combat Evolved 1.05 and earlier allows remote game servers to cause a denial of service (client crash) via a long value in a game server reply, which triggers a NULL dereference.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/18196" source="XF" patch="1">halo-long-reply-dos(18196)</ref>
      <ref url="http://secunia.com/advisories/13273" source="SECUNIA" patch="1" adv="1">13273</ref>
      <ref url="http://www.securityfocus.com/bid/11724" source="BID">11724</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110114770406920&amp;w=2" source="BUGTRAQ">20041122 Broadcast client crash in Halo 1.05</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gearbox_software" name="halo_combat_evolved">
        <vers num="1.2" />
        <vers num="1.31" />
        <vers num="1.4" />
        <vers num="1.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1540" published="2004-12-31" name="CVE-2004-1540" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">ZyXEL Prestige 623, 650, and 652 HW Routers, and possibly other versions, with HTTP Remote Administration enabled, does not require a password to access rpFWUpload.html, which allows remote attackers to reset the router configuration file.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/18202" source="XF">zyxel-configuration-reset(18202)</ref>
      <ref url="http://www.securityfocus.com/bid/11723" source="BID">11723</ref>
      <ref url="http://securitytracker.com/id?1012298" source="SECTRACK">1012298</ref>
      <ref url="http://secunia.com/advisories/13278" source="SECUNIA" adv="1">13278</ref>
      <ref url="http://www.osvdb.org/12108" source="OSVDB">12108</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110135136811344&amp;w=2" source="BUGTRAQ">20041124 Re: Router ZyXEL Prestige 650 HW http remote admin.</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110116413414615&amp;w=2" source="BUGTRAQ">20041121 Router ZyXEL Prestige 650 HW http remote admin.</ref>
    </refs>
    <vuln_soft>
      <prod vendor="zyxel" name="prestige">
        <vers num="645r_a1" />
        <vers num="650h" />
        <vers num="650hw" />
        <vers num="650hw_31" />
        <vers num="650r" />
      </prod>
      <prod vendor="zyxel" name="zynos">
        <vers num="3.40" />
        <vers num="is.3" />
        <vers num="is.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-1541" published="2004-12-31" name="CVE-2004-1541" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SecureCRT 4.0, 4.1, and possibly other versions, allows remote attackers to execute arbitrary commands via a telnet:// URL that uses the /F option to specify a configuration file on a samba share.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/18201" source="XF" patch="1">securecrt-folder-command-execution(18201)</ref>
      <ref url="http://www.securityfocus.com/bid/11731" source="BID" patch="1">11731</ref>
      <ref url="http://secunia.com/advisories/13275/" source="SECUNIA" patch="1" adv="1">13275</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110129164332226&amp;w=2" source="BUGTRAQ">20041123 SecureCRT - Remote Command Execution</ref>
    </refs>
    <vuln_soft>
      <prod vendor="van_dyke_technologies" name="securecrt">
        <vers num="4.0.1" />
        <vers num="4.0.2" />
        <vers num="4.0.3" />
        <vers num="4.0.4" />
        <vers num="4.0.5" />
        <vers num="4.1" />
        <vers num="4.1.1" />
        <vers num="4.1.2" />
        <vers num="4.1.3" />
        <vers num="4.1.4" />
        <vers num="4.1.5" />
        <vers num="4.1.6" />
        <vers num="4.1.7" />
        <vers num="4.1.8" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1542" published="2004-12-31" name="CVE-2004-1542" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Buffer overflow in Soldier of Fortune II 1.03 Gold and earlier allows remote attackers to cause a denial of service (server or client crash) via a long (1) query or (2) reply.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/18211" source="XF">soldier-fortune-bo(18211)</ref>
      <ref url="http://www.securityfocus.com/bid/11735" source="BID">11735</ref>
      <ref url="http://secunia.com/advisories/13289" source="SECUNIA" adv="1">13289</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110124208811327&amp;w=2" source="BUGTRAQ">20041123 Broadcast memory corruption in Soldier of Fortune II 1.03</ref>
    </refs>
    <vuln_soft>
      <prod vendor="raven_software" name="soldier_of_fortune">
        <vers num="2.1.0.2" />
        <vers num="2.1.0.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1543" published="2004-12-31" name="CVE-2004-1543" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in viewimg.php in KorWeblog 1.6.2-cvs and earlier allows remote attackers to list arbitrary directories via a .. (dot dot) in the path parameter.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/18234" source="XF">korweblog-viewimg-directory-traversal(18234)</ref>
      <ref url="http://www.securityfocus.com/bid/11744" source="BID">11744</ref>
      <ref url="http://secunia.com/advisories/13286" source="SECUNIA" adv="1">13286</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2004-November/029342.html" source="FULLDISC" adv="1">20041124 STG Security Advisory: [SSA-20041122-10] KorWeblog directory traversal vulnerability</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110132543805873&amp;w=2" source="BUGTRAQ">20041124 STG Security Advisory: [SSA-20041122-10] KorWeblog directory traversal vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="korweblog" name="korweblog">
        <vers num="1.6.2cvs" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1544" published="2004-12-31" name="CVE-2004-1544" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in Search.jsp in JSPWiki 2.1.120-cvs and earlier allows remote attackers to execute arbitrary web script as other users via the query parameter.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/18236" source="XF" patch="1">jspwiki-query-xss(18236)</ref>
      <ref url="http://www.securityfocus.com/bid/11746" source="BID" patch="1">11746</ref>
      <ref url="http://secunia.com/advisories/13285/" source="SECUNIA" patch="1" adv="1">13285</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110135663220831&amp;w=2" source="BUGTRAQ">20041124 STG Security Advisory: [SSA-20041122-11] JSPWiki XSS vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="jspwiki" name="jspwiki">
        <vers num="2.1.120" />
        <vers num="2.1.121" />
        <vers num="2.1.122" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1545" published="2004-12-31" name="CVE-2004-1545" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">UploadFile.php in MoniWiki 1.0.9.2 and earlier, when used with Apache mod_mime, does not properly handle files with two file extensions, such as .php.hwp, which allows remote attackers to upload and execute arbitrary code.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/18493" source="XF" patch="1">moniwiki-file-upload(18493)</ref>
      <ref url="http://www.securityfocus.com/bid/11951" source="BID" patch="1">11951</ref>
      <ref url="http://archives.neohapsis.com/archives/fulldisclosure/2004-12/0448.html" source="FULLDISC" patch="1" adv="1">20041215 STG Security Advisory: [SSA-20041215-15] Vulnerability of uploading files with multiple extensions in MoniWiki</ref>
      <ref url="http://secunia.com/advisories/13478" source="SECUNIA" adv="1">13478</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110314544711884&amp;w=2" source="BUGTRAQ">20041215 STG Security Advisory: [SSA-20041215-15] Vulnerability of uploading files with multiple extensions in MoniWiki</ref>
      <ref url="http://kldp.net/scm/cvsweb.php/moniwiki/plugin/UploadFile.php.diff?cvsroot=moniwiki&amp;only_with_tag=HEAD&amp;r1=text&amp;tr1=1.17&amp;r2=text&amp;tr2=1.16&amp;f=h" source="CONFIRM">http://kldp.net/scm/cvsweb.php/moniwiki/plugin/UploadFile.php.diff?cvsroot=moniwiki&amp;only_with_tag=HEAD&amp;r1=text&amp;tr1=1.17&amp;r2=text&amp;tr2=1.16&amp;f=h</ref>
    </refs>
    <vuln_soft>
      <prod vendor="moniwiki" name="moniwiki">
        <vers num="1.0.8" />
        <vers num="1.0.9" />
        <vers num="1.0.9.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1546" published="2004-12-31" name="CVE-2004-1546" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Multiple buffer overflows in MDaemon 6.5.1 allow remote attackers to cause a denial of service (application crash) via a long (1) SAML, SOML, SEND, or MAIL command to the SMTP server or (2) LIST command to the IMAP server.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/17477" source="XF" patch="1">mdaemon-smtp-bo(17477)</ref>
      <ref url="http://www.securityfocus.com/bid/11238" source="BID">11238</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2004-September/026770.html" source="FULLDISC">20040922 Remote buffer overflow in MDaemon IMAP and SMTP server</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/17476" source="XF">mdaemon-imap-list-bo(17476)</ref>
      <ref url="http://www.securitylab.ru/48146.html" source="MISC">http://www.securitylab.ru/48146.html</ref>
      <ref url="http://www.osvdb.org/10224" source="OSVDB">10224</ref>
      <ref url="http://www.osvdb.org/10223" source="OSVDB">10223</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109591179510781&amp;w=2" source="BUGTRAQ">20040922 Remote buffer overflow in MDaemon IMAP and SMTP server</ref>
    </refs>
    <vuln_soft>
      <prod vendor="alt-n" name="mdaemon">
        <vers num="6.5.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1547" published="2004-12-31" name="CVE-2004-1547" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The file server in ActivePost Standard 3.1 and earlier allows remote authenticated users to cause a denial of service (application crash) via a long filename, possibly triggering a buffer overflow.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/17482" source="XF">activepost-long-filename-dos(17482)</ref>
      <ref url="http://www.securityfocus.com/bid/11244" source="BID">11244</ref>
      <ref url="http://securitytracker.com/id?1011406" source="SECTRACK">1011406</ref>
      <ref url="http://secunia.com/advisories/5/" source="SECUNIA">12642</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109597139011373&amp;w=2" source="BUGTRAQ">20040923 Multiple vulnerabilities in ActivePost Standard 3.1</ref>
      <ref url="http://aluigi.altervista.org/adv/actp-adv.txt" source="MISC">http://aluigi.altervista.org/adv/actp-adv.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="onnuri_infotek" name="activepost_standard">
        <vers num="3.0" />
        <vers num="3.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1548" published="2004-12-31" name="CVE-2004-1548" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in the file server in ActivePost Standard 3.1 allows remote authenticated users to upload arbitrary files via a .. (dot dot) in the filename.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/17488" source="XF">activepost-dotdot-directory-traversal(17488)</ref>
      <ref url="http://www.securityfocus.com/bid/11244" source="BID">11244</ref>
      <ref url="http://securitytracker.com/id?1011406" source="SECTRACK">1011406</ref>
      <ref url="http://secunia.com/advisories/12642/" source="SECUNIA" adv="1">12642</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109597139011373&amp;w=2" source="BUGTRAQ">20040923 Multiple vulnerabilities in ActivePost Standard 3.1</ref>
      <ref url="http://aluigi.altervista.org/adv/actp-adv.txt" source="MISC">http://aluigi.altervista.org/adv/actp-adv.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="onnuri_infotek" name="activepost_standard">
        <vers num="3.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1549" published="2004-12-31" name="CVE-2004-1549" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The conference menu in ActivePost Standard 3.1 sends passwords of password-protected rooms in cleartext, which could allow remote attackers to gain sensitive information by sniffing the network connection.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/17486" source="XF">activepost-plaintext-password(17486)</ref>
      <ref url="http://www.securityfocus.com/bid/11244" source="BID">11244</ref>
      <ref url="http://securitytracker.com/id?1011406" source="SECTRACK">1011406</ref>
      <ref url="http://secunia.com/advisories/12642/" source="SECUNIA" adv="1">12642</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109597139011373&amp;w=2" source="BUGTRAQ">20040923 Multiple vulnerabilities in ActivePost Standard 3.1</ref>
      <ref url="http://aluigi.altervista.org/adv/actp-adv.txt" source="MISC">http://aluigi.altervista.org/adv/actp-adv.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="onnuri_infotek" name="activepost_standard">
        <vers num="3.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-1550" published="2004-12-31" name="CVE-2004-1550" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Motorola Wireless Router WR850G running firmware 4.03 allows remote attackers to bypass authentication, log on as an administrator, and obtain sensitive information by repeatedly making an HTTP request for ver.asp until an administrator logs on.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <access />
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/11241" source="BID" patch="1">11241</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/17474" source="XF">motorola-wr850g-gain-access(17474)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109613135105800&amp;w=2" source="BUGTRAQ" adv="1">20040924 Motorola Wireless Router WR850G Authentication Circumvention</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2004-September/026791.html" source="FULLDISC" adv="1">20040923 Motorola Wireless Router WR850G Authentication Circumvention</ref>
    </refs>
    <vuln_soft>
      <prod vendor="motorola" name="wr850g">
        <vers num="4.0.3_firmware" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1551" published="2004-12-31" name="CVE-2004-1551" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in the (1) email or (2) file modules in paFileDB 3.1 Final allows remote attackers to execute arbitrary web script or HTML via the id parameter.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/17504" source="XF">pafiledb-pafiledb-xss(17504)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109613031414184&amp;w=2" source="BUGTRAQ" adv="1">20040925 New XSS vulnerabilities in paFileDB 3.1 final</ref>
    </refs>
    <vuln_soft>
      <prod vendor="php_arena" name="pafiledb">
        <vers num="3.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-1552" published="2004-12-31" name="CVE-2004-1552" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in aspWebCalendar allows remote attackers to execute arbitrary SQL statements via (1) the username field on the login page or (2) the eventid parameter to calendar.asp.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/17506" source="XF">aspwebcalendar-sql-injection(17506)</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/1093" source="VUPEN">ADV-2007-1093</ref>
      <ref url="http://www.securityfocus.com/bid/11246" source="BID">11246</ref>
      <ref url="http://secunia.com/advisories/12651" source="SECUNIA" adv="1">12651</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109604910025090&amp;w=2" source="BUGTRAQ" adv="1">20040923 aspWebCalendar /aspWebAlbum: SQL injection</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/33157" source="XF">aspwebcalendar-calendar-sql-injection(33157)</ref>
      <ref url="http://www.securityfocus.com/bid/23098" source="BID">23098</ref>
      <ref url="http://www.milw0rm.com/exploits/3546" source="MILW0RM">3546</ref>
      <ref url="http://secunia.com/advisories/24622" source="SECUNIA">24622</ref>
    </refs>
    <vuln_soft>
      <prod vendor="full_revolution" name="aspwebcalendar">
        <vers num="4.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-1553" published="2004-12-31" name="CVE-2004-1553" modified="2009-08-19" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in aspWebAlbum allows remote attackers to execute arbitrary SQL statements via (1) the username field on the login page or (2) the cat parameter to album.asp.  NOTE: it was later reported that vector 1 affects aspWebAlbum 3.2, and the vector involves the txtUserName parameter in a processlogin action to album.asp, as reachable from the login action.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/44877" source="XF">aspwebalbum-album-sql-injection(44877)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/44876" source="XF">aspwebalbum-image-file-upload(44876)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/17507" source="XF">aspwebalbum-sql-injection(17507)</ref>
      <ref url="http://www.securityfocus.com/bid/30996" source="BID">30996</ref>
      <ref url="http://www.securityfocus.com/bid/11246" source="BID">11246</ref>
      <ref url="http://www.milw0rm.com/exploits/6420" source="MILW0RM">6420</ref>
      <ref url="http://www.milw0rm.com/exploits/6357" source="MILW0RM">6357</ref>
      <ref url="http://secunia.com/advisories/31649" source="SECUNIA" adv="1">31649</ref>
      <ref url="http://osvdb.org/47914" source="OSVDB">47914</ref>
      <ref url="http://osvdb.org/47913" source="OSVDB">47913</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109604910025090&amp;w=2" source="BUGTRAQ">20040923 aspWebCalendar /aspWebAlbum: SQL injection</ref>
    </refs>
    <vuln_soft>
      <prod vendor="fullrevolution" name="aspwebalbum">
        <vers num="3.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-1554" published="2004-12-31" name="CVE-2004-1554" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">PHP remote file inclusion vulnerability in livre_include.php in @lex Guestbook allows remote attackers to execute arbitrary PHP code by modifying the chem_absolu parameter to reference a URL on a remote web server that contains the code.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/11260" source="BID" patch="1">11260</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/17516" source="XF">@lex-guestbook-file-include(17516)</ref>
      <ref url="http://securitytracker.com/id?1011432" source="SECTRACK">1011432</ref>
      <ref url="http://packetstormsecurity.nl/0410-exploits/alexPHP.txt" source="MISC" adv="1">http://packetstormsecurity.nl/0410-exploits/alexPHP.txt</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109635806703748&amp;w=2" source="BUGTRAQ" adv="1">20040926 @lex Guestbook (PHP) Include file</ref>
    </refs>
    <vuln_soft>
      <prod vendor="alexphpteam" name="alex_guestbook">
        <vers num="3.12" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-1555" published="2004-12-31" name="CVE-2004-1555" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple SQL injection vulnerabilities in BroadBoard Instant ASP Message Board allow remote attackers to run arbitrary SQL commands via the (1) keywords parameter to search.asp, (2) handle parameter to profile.asp, (3) txtUserHandle parameter to reg2.asp or (4) txtUserEmail parameter to forgot.asp.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/17502" source="XF">broadboard-forgotasp-sql-injection(17502)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/17501" source="XF">broadboard-reg2asp-sql-injection(17501)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/17500" source="XF">broadboard-profileasp-sql-injection(17500)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/17498" source="XF">broadboard-searchasp-sql-injection(17498)</ref>
      <ref url="http://www.securityfocus.com/bid/11250" source="BID">11250</ref>
      <ref url="http://secunia.com/advisories/12658" source="SECUNIA" adv="1">12658</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109630777608244&amp;w=2" source="BUGTRAQ" adv="1">20040926 SQL injection in BroadBoard Instant ASP Message Board</ref>
      <ref url="http://securitytracker.com/id?1011419" source="SECTRACK">1011419</ref>
    </refs>
    <vuln_soft>
      <prod vendor="broadboard_instant" name="asp_message_board">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1556" published="2004-12-31" name="CVE-2004-1556" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">MyWebServer 1.0.3 allows remote attackers to cause a denial of service (application crash) via a large number of connections within a short time.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/17519" source="XF">mywebserver-mult-connections-dos(17519)</ref>
      <ref url="http://www.securityfocus.com/bid/11254" source="BID">11254</ref>
      <ref url="http://secunia.com/advisories/12689" source="SECUNIA" adv="1">12689</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109630333230707&amp;w=2" source="BUGTRAQ" adv="1">20040927 MyWebServer 1.0.3</ref>
      <ref url="http://securitytracker.com/id?1011461" source="SECTRACK">1011461</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mywebserver" name="mywebserver">
        <vers num="1.0.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1557" published="2004-12-31" name="CVE-2004-1557" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)" CVSS_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_base_score="6.4">
    <desc>
      <descript source="cve">MyWebServer 1.0.3 allows remote attackers to bypass authentication, modify configuration, and read arbitrary files via a direct HTTP request to (1) /admin or (2) ServerProperties.html.</descript>
    </desc>
    <loss_types>
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <access />
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/17520" source="XF">mywebserver-admin-access(17520)</ref>
      <ref url="http://www.securityfocus.com/bid/11254" source="BID">11254</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109630333230707&amp;w=2" source="BUGTRAQ" adv="1">20040927 MyWebServer 1.0.3</ref>
      <ref url="http://securitytracker.com/id?1011461" source="SECTRACK">1011461</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mywebserver" name="mywebserver">
        <vers num="1.0.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-1558" published="2004-12-31" name="CVE-2004-1558" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple stack-based buffer overflows in YPOPs! (aka YahooPOPS) 0.4 through 0.6 allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long (1) POP3 USER command or (2) SMTP request.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/17518" source="XF" patch="1">ypops-smtp-bo(17518)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/17515" source="XF" patch="1">ypops-pop3-bo(17515)</ref>
      <ref url="http://www.securityfocus.com/bid/11256" source="BID" patch="1">11256</ref>
      <ref url="http://www.hat-squad.com/en/000075.html" source="MISC" adv="1">http://www.hat-squad.com/en/000075.html</ref>
      <ref url="http://www.attrition.org/pipermail/vim/2006-October/001089.html" source="VIM">20061020 vendor ACK for old YPOPs! issue</ref>
      <ref url="http://securitytracker.com/alerts/2004/Sep/1011426.html" source="SECTRACK">1011426</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109630699829536&amp;w=2" source="BUGTRAQ" adv="1">20040927 [Hat-Squad] Remote Buffer overflow Vulnerability in YahooPOPS</ref>
      <ref url="http://dbeusee.home.comcast.net/history.html" source="CONFIRM">http://dbeusee.home.comcast.net/history.html</ref>
      <ref url="http://www.osvdb.org/10367" source="OSVDB">10367</ref>
      <ref url="http://www.osvdb.org/10366" source="OSVDB">10366</ref>
      <ref url="http://secunia.com/advisories/12660" source="SECUNIA">12660</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ypops" name="ypops">
        <vers num="0.4" />
        <vers num="0.4.1" />
        <vers num="0.4.2" />
        <vers num="0.4.3" />
        <vers num="0.4.4" />
        <vers num="0.4.5" />
        <vers num="0.4.6" />
        <vers num="0.5" />
        <vers num="0.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1559" published="2004-12-31" name="CVE-2004-1559" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in Wordpress 1.2 allow remote attackers to inject arbitrary web script or HTML via the (1) redirect_to, text, popupurl, or popuptitle parameters to wp-login.php, (2) redirect_url parameter to admin-header.php, (3) popuptitle, popupurl, content, or post_title parameters to bookmarklet.php, (4) cat_ID parameter to categories.php, (5) s parameter to edit.php, or (6) s or mode parameter to edit-comments.php.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/17532" source="XF" patch="1">wordpress-multiple-scripts-xss(17532)</ref>
      <ref url="http://www.securityfocus.com/bid/11268" source="BID" patch="1">11268</ref>
      <ref url="http://secunia.com/advisories/12683" source="SECUNIA" adv="1">12683</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109641484723194&amp;w=2" source="BUGTRAQ" adv="1">20040927 Multiple XSS Vulnerabilities in Wordpress 1.2</ref>
      <ref url="http://securitytracker.com/id?1011440" source="SECTRACK">1011440</ref>
    </refs>
    <vuln_soft>
      <prod vendor="wordpress" name="wordpress">
        <vers num="1.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1560" published="2004-12-31" name="CVE-2004-1560" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Microsoft SQL Server 7.0 allows remote attackers to cause a denial of service (mssqlserver service halt) via a long request to TCP port 1433, possibly triggering a buffer overflow.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/17542" source="XF">mssql-data-buffer-dos(17542)</ref>
      <ref url="http://www.securityfocus.com/bid/11265" source="BID">11265</ref>
      <ref url="http://securitytracker.com/id?1011434" source="SECTRACK">1011434</ref>
      <ref url="http://secunia.com/advisories/12680" source="SECUNIA" adv="1">12680</ref>
      <ref url="http://packetstormsecurity.nl/0410-exploits/mssql.7.0.dos.c" source="MISC">http://packetstormsecurity.nl/0410-exploits/mssql.7.0.dos.c</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109650760210411&amp;w=2" source="BUGTRAQ">20040928 MSSQL 7.0 DoS</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="sql_server">
        <vers num="7.0" edition="sp1" />
        <vers num="7.0" edition="sp2" />
        <vers num="7.0" edition="sp3" />
        <vers num="7.0" edition="sp4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-1561" published="2004-12-31" name="CVE-2004-1561" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in Icecast 2.0.1 and earlier allows remote attackers to execute arbitrary code via an HTTP request with a large number of headers.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/17538" source="XF" patch="1">icecast-http-bo(17538)</ref>
      <ref url="http://www.securityfocus.com/bid/11271" source="BID" patch="1">11271</ref>
      <ref url="http://secunia.com/advisories/12666/" source="SECUNIA" patch="1" adv="1">12666</ref>
      <ref url="http://www.securiteam.com/exploits/6X00315BFM.html" source="MISC" adv="1">http://www.securiteam.com/exploits/6X00315BFM.html</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109674593230539&amp;w=2" source="BUGTRAQ">20041002 Re:2. Code execution in Icecast 2.0.1(exploit with shellcode)</ref>
      <ref url="http://aluigi.altervista.org/adv/iceexec-adv.txt" source="MISC" adv="1">http://aluigi.altervista.org/adv/iceexec-adv.txt</ref>
      <ref url="http://www.osvdb.org/10446" source="OSVDB">10446</ref>
      <ref url="http://securitytracker.com/id?1011439" source="SECTRACK">1011439</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109640005127644&amp;w=2" source="BUGTRAQ">20040928 Code execution in Icecast 2.0.1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="icecast" name="icecast">
        <vers num="2.0" />
        <vers num="2.0.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-1562" published="2004-12-31" name="CVE-2004-1562" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in redir_url.php in w-Agora 4.1.6a allows remote attackers to execute arbitrary SQL commands via the key parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/17557" source="XF" patch="1">wagora-redirurl-sql-injection(17557)</ref>
      <ref url="http://secunia.com/advisories/12695" source="SECUNIA" patch="1" adv="1">12695</ref>
      <ref url="http://www.securityfocus.com/bid/11283" source="BID">11283</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109655691512298&amp;w=2" source="BUGTRAQ" adv="1">20040930 Multiple vulnerabilities in w-agora forum</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2004-September/027040.html" source="FULLDISC" adv="1">20040930 Multiple vulnerabilities in w-agora forum</ref>
      <ref url="http://securitytracker.com/id?1011463" source="SECTRACK">1011463</ref>
    </refs>
    <vuln_soft>
      <prod vendor="w-agora" name="w-agora">
        <vers num="4.1.6a" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1563" published="2004-12-31" name="CVE-2004-1563" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in w-Agora 4.1.6a allow remote attackers to execute arbitrary web script or HTML via the (1) thread parameter to download_thread.php, (2) loginuser parameter to login.php, or (3) userid parameter to forgot_password.php.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/17553" source="XF" patch="1">wagora-get-post-xss(17553)</ref>
      <ref url="http://secunia.com/advisories/12695" source="SECUNIA" patch="1" adv="1">12695</ref>
      <ref url="http://www.securityfocus.com/bid/11283" source="BID">11283</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109655691512298&amp;w=2" source="BUGTRAQ" adv="1">20040930 Multiple vulnerabilities in w-agora forum</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2004-September/027040.html" source="FULLDISC" adv="1">20040930 Multiple vulnerabilities in w-agora forum</ref>
      <ref url="http://securitytracker.com/id?1011463" source="SECTRACK">1011463</ref>
    </refs>
    <vuln_soft>
      <prod vendor="w-agora" name="w-agora">
        <vers num="4.1.6a" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1564" published="2004-12-31" name="CVE-2004-1564" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">CRLF injection vulnerability in subscribe_thread.php in w-Agora 4.1.6a allows remote attackers to perform HTTP Response Splitting attacks to modify expected HTML content from the server via the thread parameter.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/12695" source="SECUNIA" patch="1" adv="1">12695</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/17558" source="XF">wagora-response-splitting(17558)</ref>
      <ref url="http://www.securityfocus.com/bid/11283" source="BID">11283</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109655691512298&amp;w=2" source="BUGTRAQ" adv="1">20040930 Multiple vulnerabilities in w-agora forum</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2004-September/027040.html" source="FULLDISC" adv="1">20040930 Multiple vulnerabilities in w-agora forum</ref>
      <ref url="http://securitytracker.com/id?1011463" source="SECTRACK">1011463</ref>
    </refs>
    <vuln_soft>
      <prod vendor="w-agora" name="w-agora">
        <vers num="4.1.6a" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1565" published="2004-12-31" name="CVE-2004-1565" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">list.php in w-Agora 4.1.6a allows remote attackers to reveal the full path via a crafted HTTP request, possibly involving a malformed id parameter.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/12695" source="SECUNIA" patch="1" adv="1">12695</ref>
      <ref url="http://www.securityfocus.com/bid/11283" source="BID">11283</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109655691512298&amp;w=2" source="BUGTRAQ" adv="1">20040930 Multiple vulnerabilities in w-agora forum</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2004-September/027040.html" source="FULLDISC" adv="1">20040930 Multiple vulnerabilities in w-agora forum</ref>
      <ref url="http://securitytracker.com/id?1011463" source="SECTRACK">1011463</ref>
    </refs>
    <vuln_soft>
      <prod vendor="w-agora" name="w-agora">
        <vers num="4.1.6a" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1566" published="2004-12-31" name="CVE-2004-1566" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in index.php in Silent Storm Portal 2.1 and 2.2 allows remote attackers to execute arbitrary web script or HTML via the module parameter.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/17554" source="XF">silent-storm-xss(17554)</ref>
      <ref url="http://www.securityfocus.com/bid/11284" source="BID">11284</ref>
      <ref url="http://secunia.com/advisories/12704" source="SECUNIA" adv="1">12704</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109655763808924&amp;w=2" source="BUGTRAQ" adv="1">20040930 Multiple Vulnerabilities in Silent Storm Portal</ref>
      <ref url="http://securitytracker.com/id?1011470" source="SECTRACK">1011470</ref>
    </refs>
    <vuln_soft>
      <prod vendor="silent-storm" name="silent-storm_portal">
        <vers num="2.1" />
        <vers num="2.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-1567" published="2004-12-31" name="CVE-2004-1567" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">profile.php in Silent Storm Portal 2.1 and 2.2 allows remote attackers to gain privileges by setting the mail parameter to 1, which is the value for an administrator.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/17555" source="XF">silent-storm-gain-admin(17555)</ref>
      <ref url="http://www.securityfocus.com/bid/11284" source="BID">11284</ref>
      <ref url="http://secunia.com/advisories/12704" source="SECUNIA">12704</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109655763808924&amp;w=2" source="BUGTRAQ">20040930 Multiple Vulnerabilities in Silent Storm Portal</ref>
      <ref url="http://securitytracker.com/id?1011470" source="SECTRACK">1011470</ref>
    </refs>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1568" published="2004-12-31" name="CVE-2004-1568" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in ParaChat Server 5.5 allows remote attackers to read arbitrary files via a ..%5C (hex-encoded dot dot) in the URL.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/17541" source="XF" patch="1">parachat-directory-traversal(17541)</ref>
      <ref url="http://www.securityfocus.com/bid/11272" source="BID">11272</ref>
      <ref url="http://secunia.com/advisories/12678/" source="SECUNIA" adv="1">12678</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109656982803391&amp;w=2" source="BUGTRAQ">20040930 Re: directory traversal in ParaChat Server 5.5</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109647769526696&amp;w=2" source="BUGTRAQ" adv="1">20040929 directory traversal in ParaChat Server 5.5</ref>
      <ref url="http://www.osvdb.org/10436" source="OSVDB">10436</ref>
      <ref url="http://securitytracker.com/id?1011438" source="SECTRACK">1011438</ref>
      <ref url="http://archives.neohapsis.com/archives/fulldisclosure/2004-09/1063.html" source="FULLDISC">20040929 Re: directory traversal in ParaChat Server 5.5</ref>
      <ref url="http://archives.neohapsis.com/archives/fulldisclosure/2004-09/1047.html" source="FULLDISC">20040928 directory traversal in ParaChat Server 5.5</ref>
    </refs>
    <vuln_soft>
      <prod vendor="parachat" name="parachat_server">
        <vers num="5.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1569" published="2004-12-31" name="CVE-2004-1569" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:P/A:P)" CVSS_score="4.0" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="4.9" CVSS_base_score="4.0">
    <desc>
      <descript source="cve">Buffer overflow in (1) MusicConverter.exe, (2) playlist.exe, and (3) amp.exe in dBpowerAMP Audio Player 2.0 and dbPowerAmp Music Converter 10.0 allows remote attackers to cause a denial of service or execute arbitrary code via a .pls or .m3u playlist that contains long File1 (filename) fields.</descript>
    </desc>
    <loss_types>
      <avail />
      <int />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/17539" source="XF">dbpoweramp-converter-filename-bo(17539)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/17535" source="XF">dbpoweramp-player-filename-bo(17535)</ref>
      <ref url="http://www.securityfocus.com/bid/11266" source="BID">11266</ref>
      <ref url="http://www.gulftech.org/?node=research&amp;article_id=00052-09272004" source="MISC" adv="1">http://www.gulftech.org/?node=research&amp;article_id=00052-09272004</ref>
      <ref url="http://secunia.com/advisories/12684/" source="SECUNIA" adv="1">12684</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109668542406346&amp;w=2" source="BUGTRAQ" adv="1">20040930 dbPowerAmp Buffer Overflow And Dos Vulnerabilities</ref>
    </refs>
    <vuln_soft>
      <prod vendor="illustrate" name="dbpoweramp_audio_player">
        <vers num="2.0" />
      </prod>
      <prod vendor="illustrate" name="dbpoweramp_music_converter">
        <vers num="10.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-1570" published="2004-12-31" name="CVE-2004-1570" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in bBlog 0.7.2 and 0.7.3 allows remote attackers to execute arbitrary SQL commands via the p parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109665351632048&amp;w=2" source="BUGTRAQ" patch="1">20041001 SQL Injection vulnerability in bBlog 0.7.3</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/17552" source="XF">bblog-array-sql-injection(17552)</ref>
      <ref url="http://www.servers.co.nz/security/SCN200409-1.php" source="MISC">http://www.servers.co.nz/security/SCN200409-1.php</ref>
      <ref url="http://www.securityfocus.com/bid/11303" source="BID">11303</ref>
      <ref url="http://secunia.com/advisories/12691" source="SECUNIA">12691</ref>
    </refs>
    <vuln_soft>
      <prod vendor="eaden_mckee" name="bblog">
        <vers num="0.7.2" />
        <vers num="0.7.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1571" published="2004-12-31" name="CVE-2004-1571" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">AJ-Fork 167 allows remote attackers to gain sensitive information via a direct request to (1) auto-acronyms.php, (2) auto-archive.php, (3) ount-article-views.php, (4) kses.php, (5) custom-quick-tags.php, (6) disable-all-comments.php, (7) easy-date-format.php, (8) enable-disable-comments.php, (9) filter-by-author.php, (10) format-switcher.php, (11) long-to-short.php, (12) prospective-posting.php, or (13) sort-by-xfield.php, which displays the full path in an error message.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/17568" source="XF">aj-fork-path-disclosure(17568)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109664986210763&amp;w=2" source="BUGTRAQ" adv="1">20041001 Multiple Vulnerabilities in AJ-Fork</ref>
      <ref url="http://echo.or.id/adv/adv07-y3dips-2004.txt" source="MISC" adv="1">http://echo.or.id/adv/adv07-y3dips-2004.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="aj-fork" name="aj-fork">
        <vers num="167" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1572" published="2004-12-31" name="CVE-2004-1572" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">AJ-Fork 167 does not restrict access to directories such as (1) data, (2) inc, (3) plugins, (4) skins, or (5) tools, which allows remote attackers to list files in those directories via a direct HTTP request.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/17569" source="XF">af-fork-directory-disclosure(17569)</ref>
      <ref url="http://www.securityfocus.com/bid/11301" source="BID">11301</ref>
      <ref url="http://securitytracker.com/id?1011484" source="SECTRACK">1011484</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109664986210763&amp;w=2" source="BUGTRAQ" adv="1">20041001 Multiple Vulnerabilities in AJ-Fork</ref>
      <ref url="http://echo.or.id/adv/adv07-y3dips-2004.txt" source="MISC">http://echo.or.id/adv/adv07-y3dips-2004.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="aj-fork" name="aj-fork">
        <vers num="167" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-1573" published="2004-12-31" name="CVE-2004-1573" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">The documentation for AJ-Fork 167 implies that users should set permissions for users.db.php to 777, which allows local users to execute arbitrary PHP code and gain privileges as the administrator.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <config />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/17571" source="XF">aj-fork-usersdbphp-write-access(17571)</ref>
      <ref url="http://www.securityfocus.com/bid/11301" source="BID">11301</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109664986210763&amp;w=2" source="BUGTRAQ" adv="1">20041001 Multiple Vulnerabilities in AJ-Fork</ref>
      <ref url="http://echo.or.id/adv/adv07-y3dips-2004.txt" source="MISC" adv="1">http://echo.or.id/adv/adv07-y3dips-2004.txt</ref>
      <ref url="http://securitytracker.com/id?1011484" source="SECTRACK">1011484</ref>
    </refs>
    <vuln_soft>
      <prod vendor="aj-fork" name="aj-fork">
        <vers num="167" />
      </prod>
      <prod vendor="cutephp" name="cutenews">
        <vers num="0.88" />
        <vers num="1.3" />
        <vers num="1.3.1" />
        <vers num="1.3.2" />
        <vers num="1.3.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-1574" published="2004-12-31" name="CVE-2004-1574" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in Vypress Messenger 3.5.1 and earlier allows remote attackers to execute arbitrary code via a message with a long first field.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/11310" source="BID" patch="1">11310</ref>
      <ref url="http://secunia.com/advisories/12605" source="SECUNIA" patch="1">12605</ref>
      <ref url="http://aluigi.altervista.org/adv/vymesbof-adv.txt" source="MISC" patch="1">http://aluigi.altervista.org/adv/vymesbof-adv.txt</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/17572" source="XF">vypress-visual-bo(17572)</ref>
      <ref url="http://www.osvdb.org/10451" source="OSVDB">10451</ref>
      <ref url="http://securitytracker.com/id?1011489" source="SECTRACK">1011489</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109665993315769&amp;w=2" source="BUGTRAQ">20041001 Broadcast buffer-overflow in Vypress Messenger 3.5.1</ref>
    </refs>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1575" published="2004-12-31" name="CVE-2004-1575" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The XML parser in Xerces-C++ 2.5.0 allows remote attackers to cause a denial of service (CPU consumption) via XML attributes in a crafted XML document.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/11312" source="BID" patch="1">11312</ref>
      <ref url="http://secunia.com/advisories/12715" source="SECUNIA" patch="1">12715</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/17575" source="XF">xercescplusplus-xml-parser-dos(17575)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109674050017645&amp;w=2" source="BUGTRAQ">20041002 Security advisory - Xerces-C++ 2.5.0: Attribute blowup</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apache" name="xerces-c++">
        <vers num="2.5.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1576" published="2004-12-31" name="CVE-2004-1576" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Format string vulnerability in Judge Dredd: Dredd vs. Death 1.01 and earlier allows remote attackers to cause a denial of service (application crash) via format string specifiers in a chat message.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/17579" source="XF">judge-dredd-death-format-string(17579)</ref>
      <ref url="http://secunia.com/advisories/12710" source="SECUNIA" adv="1">12710</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109674541519610&amp;w=2" source="BUGTRAQ" adv="1">20041002 In-game format string in Judge Dredd vs. Death 1.01</ref>
    </refs>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1577" published="2004-12-31" name="CVE-2004-1577" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">index.php in PHP Links allows remote attackers to gain sensitive information via an invalid show parameter, which reveals the full path in an error message.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/17588" source="XF">phplinks-path-disclosure(17588)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109693280416747&amp;w=2" source="BUGTRAQ" adv="1">20041003 Full path disclosure in PHP Links</ref>
    </refs>
    <vuln_soft>
      <prod vendor="greg_donald" name="phplinks">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1578" published="2004-12-31" name="CVE-2004-1578" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in index.php in Invision Power Board 2.0.0 allows remote attackers to execute arbitrary web script or HTML via the Referer field in the HTTP header.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/17604" source="XF">invision-referer-header-xss(17604)</ref>
      <ref url="http://www.securityfocus.com/bid/11332" source="BID">11332</ref>
      <ref url="http://secunia.com/advisories/12740" source="SECUNIA">12740</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109701091207517&amp;w=2" source="BUGTRAQ">20041005 [MAXPATROL Security Advisories] Cross site scripting in Invision Power Board</ref>
    </refs>
    <vuln_soft>
      <prod vendor="invision_power_services" name="invision_power_board">
        <vers num="2.0.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1579" published="2004-12-31" name="CVE-2004-1579" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">index.php in CubeCart 2.0.1 allows remote attackers to gain sensitive information via an HTTP request with an invalid cat_id parameter, which reveals the full path in a PHP error message.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/17630" source="XF">cubecart-catid-path-disclosure(17630)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109713382400457&amp;w=2" source="BUGTRAQ">20041006 Full path disclosure and sql injection on CubeCart 2.0.1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="devellion" name="cubecart">
        <vers num="2.0.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-1580" published="2004-12-31" name="CVE-2004-1580" modified="2010-11-03" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in index.php in CubeCart 2.0.1 allows remote attackers to execute arbitrary SQL commands via the cat_id parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/12764" source="SECUNIA" patch="1" adv="1">12764</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/17632" source="XF">cubecart-catid-sql-injection(17632)</ref>
      <ref url="http://www.securityfocus.com/bid/11337" source="BID">11337</ref>
      <ref url="http://www.exploit-db.com/exploits/15278" source="EXPLOIT-DB">15278</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109713382400457&amp;w=2" source="BUGTRAQ" adv="1">20041006 Full path disclosure and sql injection on CubeCart 2.0.1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="devellion" name="cubecart">
        <vers num="2.0.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1581" published="2004-12-31" name="CVE-2004-1581" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">BlackBoard 1.5.1 allows remote attackers to gains sensitive information via a direct request to (1) checkdb.inc.php, (2) admin.inc.php or (3) cp.inc.php, which reveals the path in a PHP error message.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/17636" source="XF">blackboard-directory-traversal(17636)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109707701719659&amp;w=2" source="BUGTRAQ" adv="1">20041006 Multiple vulnerabilities in BlackBoard</ref>
    </refs>
    <vuln_soft>
      <prod vendor="blackboard" name="blackboard">
        <vers num="1.5.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-1582" published="2004-12-31" name="CVE-2004-1582" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">PHP remote file inclusion vulnerability in BlackBoard 1.5.1 allows remote attackers to execute arbitrary PHP code by modifying the libpath parameter (incorrectly called "libpach") to reference a URL on a remote web server that contains _more.php, as demonstrated using checkdb.inc.php.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/17637" source="XF" patch="1">blackboard-lang-file-include(17637)</ref>
      <ref url="http://www.securityfocus.com/bid/11336" source="BID" patch="1">11336</ref>
      <ref url="http://secunia.com/advisories/12757" source="SECUNIA" patch="1" adv="1">12757</ref>
      <ref url="http://blackboard.unclassified.de/70,1#1031" source="CONFIRM" patch="1">http://blackboard.unclassified.de/70,1#1031</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109707701719659&amp;w=2" source="BUGTRAQ" adv="1">20041006 Multiple vulnerabilities in BlackBoard</ref>
    </refs>
    <vuln_soft>
      <prod vendor="blackboard_internet_newsboard_system" name="blackboard_internet_newsboard_system">
        <vers num="1.5.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1583" published="2004-12-31" name="CVE-2004-1583" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)" CVSS_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_base_score="6.4">
    <desc>
      <descript source="cve">Directory traversal vulnerability in the FTP server in TriDComm 1.3 and earlier allows remote attackers read or write arbitrary files via a .. (dot dot) in FTP commands such as (1) DIR, (2) GET, or (3) PUT.</descript>
    </desc>
    <loss_types>
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/12755" source="SECUNIA" patch="1">12755</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/17631" source="XF">tridcomm-dotdot-directory-traversal(17631)</ref>
      <ref url="http://www.securityfocus.com/bid/11343" source="BID">11343</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109709637732276&amp;w=2" source="BUGTRAQ" adv="1">20041006 Directory traversal in Tridcomm 1.3</ref>
    </refs>
    <vuln_soft>
      <prod vendor="tridcomm" name="tridcomm">
        <vers num="1.2" />
        <vers num="1.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1584" published="2004-12-31" name="CVE-2004-1584" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">CRLF injection vulnerability in wp-login.php in WordPress 1.2 allows remote attackers to perform HTTP Response Splitting attacks to modify expected HTML content from the server via the text parameter.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/11348" source="BID" patch="1">11348</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200410-12.xml" source="GENTOO" patch="1">GLSA-200410-12</ref>
      <ref url="http://wordpress.org/development/2004/10/wp-121/" source="CONFIRM" patch="1">http://wordpress.org/development/2004/10/wp-121/</ref>
      <ref url="http://secunia.com/advisories/12773" source="SECUNIA" patch="1">12773</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109716327724041&amp;w=2" source="BUGTRAQ" patch="1">20041006 HTTP Response Splitting Vulnerability in Wordpress 1.2</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/17649" source="XF">wordpress-response-splitting(17649)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="wordpress" name="wordpress">
        <vers num="1.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1585" published="2004-12-31" name="CVE-2004-1585" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Flash Messaging 5.2.0g (rev 1.1.2) and earlier allows remote attackers to cause a denial of service (application crash) via certain wide characters.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/17647" source="XF">flash-messaging-dos(17647)</ref>
      <ref url="http://www.securityfocus.com/bid/11351" source="BID">11351</ref>
      <ref url="http://securitytracker.com/id?1011569" source="SECTRACK">1011569</ref>
      <ref url="http://secunia.com/advisories/12759/" source="SECUNIA" adv="1">12759</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109716787607302&amp;w=2" source="BUGTRAQ" adv="1">20041007 Server crash in Flash Messaging 5.2.0g</ref>
    </refs>
    <vuln_soft>
      <prod vendor="jera_technology" name="flash_messaging">
        <vers num="5.2" />
        <vers num="5.2g" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2004-1586" published="2004-12-31" name="CVE-2004-1586" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">Flash Messaging clients can ignore disconnecting commands such as "shutdown" from the Flash Messaging Server 5.2.0g (rev 1.1.2), which could allow remote attackers to stay connected.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <access />
      <exception />
      <other />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://securitytracker.com/id?1011569" source="SECTRACK">1011569</ref>
      <ref url="http://secunia.com/advisories/12759/" source="SECUNIA">12759</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109716787607302&amp;w=2" source="BUGTRAQ" adv="1">20041007 Server crash in Flash Messaging 5.2.0g</ref>
    </refs>
    <vuln_soft>
      <prod vendor="jera_technology" name="flash_messaging_server">
        <vers num="5.2.0g" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1587" published="2004-12-31" name="CVE-2004-1587" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Buffer overflow in Monolith games including (1) Alien versus Predator 2 1.0.9.6 and earlier, (2) Blood 2 2.1 and earlier, (3) No one lives forever 1.004 and earlier and (4) Shogo 2.2 and earlier allows remote attackers to cause a denial of service (application crash) via a long secure Gamespy query.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/11354" source="BID" patch="1">11354</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109728194025487&amp;w=2" source="BUGTRAQ" patch="1">20041008 Limited \secure\ buffer-overflow in some old Monolith games</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/17670" source="XF">shogo-long-query-bo(17670)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/17668" source="XF">blood2-long-query-bo(17668)</ref>
      <ref url="http://secunia.com/advisories/12776/" source="SECUNIA">12776</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/17669" source="XF">nolf-long-query-bo(17669)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/17665" source="XF">avp2-long-query-bo(17665)</ref>
      <ref url="http://www.osvdb.org/displayvuln.php?osvdb_id=10635" source="OSVDB">10635</ref>
      <ref url="http://securitytracker.com/alerts/2004/Oct/1011603.html" source="SECTRACK">1011603</ref>
      <ref url="http://marc.theaimsgroup.com/?l=full-disclosure&amp;m=109727077824860&amp;w=2" source="FULLDISC">20041008 Limited \secure\ buffer-overflow in some old Monolith games</ref>
    </refs>
    <vuln_soft>
      <prod vendor="monolith_productions" name="alien_versus_predator">
        <vers num="2.1.0.9.6" />
      </prod>
      <prod vendor="monolith_productions" name="blood">
        <vers num="2_2.1" />
      </prod>
      <prod vendor="monolith_productions" name="no_one_lives_forever">
        <vers num="1.0.004" />
      </prod>
      <prod vendor="monolith_productions" name="shogo">
        <vers num="2.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-1588" published="2004-12-31" name="CVE-2004-1588" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in GoSmart Message Board allows remote attackers to execute arbitrary SQL code via the (1) QuestionNumber and Category parameters to Forum.asp or (2) Username and Password parameter to Login_Exec.asp.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/17678" source="XF">gosmart-forum-loginexec-sql-injection(17678)</ref>
      <ref url="http://www.securityfocus.com/bid/11361" source="BID">11361</ref>
      <ref url="http://secunia.com/advisories/12790/" source="SECUNIA" adv="1">12790</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109751522823011&amp;w=2" source="BUGTRAQ" adv="1">20041011 [MAxpatrol Security Advisory]  Multiple vulnerabilities in GoSmart Message Board</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gosmart" name="gosmart_message_board">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1589" published="2004-12-31" name="CVE-2004-1589" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in GoSmart Message Board allows remote attackers to execute inject web script or HTML via the (1) Category parameter to Forum.asp or (2) MainMessageID parameter to ReplyToQuestion.asp.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/17679" source="XF">gosmart-forum-mainmessageid-xss(17679)</ref>
      <ref url="http://www.securityfocus.com/bid/11361" source="BID">11361</ref>
      <ref url="http://secunia.com/advisories/12790/" source="SECUNIA">12790</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109751522823011&amp;w=2" source="BUGTRAQ">20041011 [MAxpatrol Security Advisory]  Multiple vulnerabilities in GoSmart Message Board</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gosmart" name="gosmart_message_board">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1590" published="2004-12-31" name="CVE-2004-1590" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Clientexec allows remote attackers to gain sensitive information via an HTTP request to phpinfo.php, which calls the phpinfo function.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/17741" source="XF">clientexec-phpinfo-info-disclosure(17741)</ref>
      <ref url="http://secunia.com/advisories/12862" source="SECUNIA">12862</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109787365801512&amp;w=2" source="BUGTRAQ">20041012 Clientexec Billing Software</ref>
    </refs>
    <vuln_soft>
      <prod vendor="clientexec" name="clientexec">
        <vers num="2.2.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-1591" published="2004-12-31" name="CVE-2004-1591" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">The web interface for Micronet Wireless Broadband Router SP916BM running firmware before 1.9 08/04/2004 resets the password to the default password when the router is shut off, which could allow remote attackers to gain access.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/17697" source="XF" patch="1">micronet-router-password-reset(17697)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109759963126161&amp;w=2" source="BUGTRAQ" adv="1">20041012 Micronet wireless broadband router SP916BM admin password reset when power off</ref>
    </refs>
    <vuln_soft>
      <prod vendor="micronet" name="sp916bm">
        <vers num="1.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-1592" published="2004-12-31" name="CVE-2004-1592" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">PHP remote file inclusion vulnerability in index.php in ocPortal 1.0.3 and earlier allows remote attackers to execute arbitrary PHP code by modifying the req_path parameter to reference a URL on a remote web server that contains a malicious funcs.php script.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/11368" source="BID" patch="1">11368</ref>
      <ref url="http://secunia.com/advisories/12811/" source="SECUNIA" patch="1">12811</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/17699" source="XF">ocportal-reqpath-file-include(17699)</ref>
      <ref url="http://www.hackgen.org/advisories/hackgen-2004-002.txt" source="MISC" adv="1">http://www.hackgen.org/advisories/hackgen-2004-002.txt</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109763314312828&amp;w=2" source="BUGTRAQ" adv="1">20041012 [hackgen-2004-#002] - Remote file inclusion bug in ocPortal 1.0.3.</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ocportal" name="ocportal">
        <vers num="1.0.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1593" published="2004-12-31" name="CVE-2004-1593" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in render.UserLayoutRootNode.uP in SCT Campus Pipeline allows remote attackers to inject arbitrary web script or HTML via the utf parameter.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/17704" source="XF">sct-campus-userlayoutrootnode-xss(17704)</ref>
      <ref url="http://www.securityfocus.com/bid/11392" source="BID">11392</ref>
      <ref url="http://secunia.com/advisories/12826" source="SECUNIA" adv="1">12826</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109768337007983&amp;w=2" source="BUGTRAQ">20041013 XXS in SCT email client</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sct_corporation" name="campus_pipeline">
        <vers num="1.0" />
        <vers num="2.0" />
        <vers num="2.1" />
        <vers num="2.2" />
        <vers num="3.0" />
        <vers num="3.1" />
        <vers num="3.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1594" published="2004-10-13" name="CVE-2004-1594" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in FuseTalk 4.0 allows remote attackers to execute arbitrary web script via an img src tag.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/12823" source="SECUNIA" patch="1" adv="1">12823</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109768460312168&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20041013 XXS in fusetalk forum</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/17701" source="XF" adv="1">fusetalk-imgsrc-xss(17701)</ref>
      <ref url="http://www.securityfocus.com/bid/11393" source="SECUNIA" adv="1">12823</ref>
    </refs>
    <vuln_soft>
      <prod vendor="e-zone_media_inc." name="fusetalk">
        <vers num="4.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-1595" published="2004-10-13" name="CVE-2004-1595" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in ShixxNote 6.net build 117 allows remote attackers to execute arbitrary code via a long font field.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/17705" source="XF" adv="1">shixxnote-font-bo(17705)</ref>
      <ref url="http://www.securityfocus.com/bid/11409" source="BID" adv="1">11409</ref>
      <ref url="http://secunia.com/advisories/12822/" source="SECUNIA" adv="1">12822</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109778648232233&amp;w=2" source="BUGTRAQ" adv="1">20041013 Buffer-overflow in ShixxNOTE 6.net</ref>
    </refs>
    <vuln_soft>
      <prod vendor="shixxnote" name="shixxnote">
        <vers num="6.net" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-1596" published="2004-10-13" name="CVE-2004-1596" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">The 3COM Wireless router 3CRADSL72 running Boot Code 1.3d allows remote attackers to gain sensitive information such as passwords and router settings via a direct HTTP request to app_sta.stm.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/17723" source="XF" adv="1">3com-officeconnect-obtain-info(17723)</ref>
      <ref url="http://www.securityfocus.com/bid/11408" source="BID" adv="1">11408</ref>
      <ref url="http://www.securityfocus.com/archive/1/378551" source="BUGTRAQ" adv="1">20041015 More details on BID 11408 (3com 3cradsl72 wireless router)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109810854031673&amp;w=2" source="BUGTRAQ" adv="1">20041015 Re: 3COM Wireless router (3CRADSL72) information disclosure</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109778914829901&amp;w=2" source="BUGTRAQ" adv="1">20041013 3COM Wireless router (3CRADSL72) information disclosure</ref>
    </refs>
    <vuln_soft>
      <prod vendor="3com" name="3cradsl72">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1597" published="2004-10-13" name="CVE-2004-1597" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">RIM Blackberry 7230 running RIM Blackberry OS 3.7 SP1 allows remote attackers to cause a denial of service (device reboot and possibly data corruption) via a calendar message with a long Location field, which triggers a watchdog while the message is being stored.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input bound="1" />
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/17700" source="XF" patch="1" adv="1">blackberry-calendar-bo(17700)</ref>
      <ref url="http://www.securityfocus.com/bid/11389" source="BID" patch="1" adv="1">11389</ref>
      <ref url="http://www.blackberry.com/knowledgecenterpublic/livelink.exe/fetch/2000/8021/7925/8142/Known_%20Issues_-_HexView_advisory_on_BlackBerry_buffer_overflow,_DoS,_and_data_loss.html?nodeid=737173&amp;vernum=0" source="CONFIRM" patch="1" adv="1">http://www.blackberry.com/knowledgecenterpublic/livelink.exe/fetch/2000/8021/7925/8142/Known_%20Issues_-_HexView_advisory_on_BlackBerry_buffer_overflow,_DoS,_and_data_loss.html?nodeid=737173&amp;vernum=0</ref>
      <ref url="http://secunia.com/advisories/12814" source="SECUNIA" patch="1" adv="1">12814</ref>
      <ref url="http://www.hexview.com/docs/20041012-1.txt" source="MISC" adv="1">http://www.hexview.com/docs/20041012-1.txt</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109778267829493&amp;w=2" source="BUGTRAQ" adv="1">20041014 [HV-MED] UPDATE: RIM Blackberry DoS, data loss</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109769022430842&amp;w=2" source="BUGTRAQ" adv="1">20041013 [HV-HIGH] RIM Blackberry buffer overflow, DoS, data loss</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2004-October/027487.html" source="FULLDISC" adv="1">20041012 [HV-HIGH] RIM Blackberry buffer overflow, DoS, data loss</ref>
    </refs>
    <vuln_soft>
      <prod vendor="rim" name="blackberry">
        <vers num="7230_3.7.1_.41" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1598" published="2004-10-12" name="CVE-2004-1598" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Adobe Acrobat and Acrobat Reader 6.0 allow remote attackers to read arbitrary files via a PDF file that contains an embedded Shockwave (swf) file that references files outside of the temporary directory.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/17694" source="XF" adv="1">adobe-acrobat-swf-read-files(17694)</ref>
      <ref url="http://www.securityfocus.com/bid/11386" source="BID" adv="1">11386</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109812210520520&amp;w=2" source="BUGTRAQ" adv="1">20041015 Re: Adobe acrobat / Adobe Reader 6 can read local files</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109779541602447&amp;w=2" source="BUGTRAQ" adv="1">20041014 Re: Adobe acrobat / Adobe Reader 6 can read local files</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109771686326956&amp;w=2" source="BUGTRAQ" adv="1">20041012 Adobe acrobat / Adobe Reader 6 can read local files</ref>
    </refs>
    <vuln_soft>
      <prod vendor="adobe" name="acrobat">
        <vers num="6.0" />
        <vers num="6.0.1" />
        <vers num="6.0.2" />
      </prod>
      <prod vendor="adobe" name="acrobat_reader">
        <vers num="6.0" />
        <vers num="6.0.1" />
        <vers num="6.0.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1599" published="2004-10-16" name="CVE-2004-1599" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in index.php in CoolPHP 1.0-stable allows remote attackers to execute arbitrary web script or HTML via the (1) query or (2) nick parameters.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/17742" source="XF" adv="1">coolphp-multiple-xss(17742)</ref>
      <ref url="http://www.securityfocus.com/bid/11437" source="BID" adv="1">11437</ref>
      <ref url="http://securitytracker.com/id?1011748" source="SECTRACK" adv="1">1011748</ref>
      <ref url="http://secunia.com/advisories/12850" source="SECUNIA" adv="1">12850</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109810941419669&amp;w=2" source="BUGTRAQ" adv="1">20041016 Multiple Vulnerabilities in CoolPHP</ref>
    </refs>
    <vuln_soft>
      <prod vendor="coolphp" name="coolphpweb_portal">
        <vers num="1.0_stable" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1600" published="2004-10-16" name="CVE-2004-1600" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">index.php in CoolPHP 1.0-stable allows remote attackers to gain sensitive information via an invalid op parameter, which reveals the path in an error message.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/17744" source="XF" adv="1">coolphp-path-disclosure(17744)</ref>
      <ref url="http://securitytracker.com/id?1011748" source="SECTRACK" adv="1">1011748</ref>
      <ref url="http://secunia.com/advisories/12850" source="SECUNIA" adv="1">12850</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109810941419669&amp;w=2" source="BUGTRAQ" adv="1">20041016 Multiple Vulnerabilities in CoolPHP</ref>
    </refs>
    <vuln_soft>
      <prod vendor="coolphp" name="coolphp">
        <vers num="1.0_stable" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-1601" published="2004-10-16" name="CVE-2004-1601" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Directory traversal vulnerability in index.php in CoolPHP 1.0-stable allows remote attackers to access arbitrary files and execute local PHP scripts via a .. (dot dot) in the op parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/17745" source="XF" adv="1">coolphp-dotdot-directory-traversal(17745)</ref>
      <ref url="http://www.securityfocus.com/bid/11437" source="BID">11437</ref>
      <ref url="http://securitytracker.com/id?1011748" source="SECTRACK" adv="1">1011748</ref>
      <ref url="http://secunia.com/advisories/12850" source="SECUNIA" adv="1">12850</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109810941419669&amp;w=2" source="BUGTRAQ" adv="1">20041016 Multiple Vulnerabilities in CoolPHP</ref>
    </refs>
    <vuln_soft>
      <prod vendor="coolphp" name="coolphp_web_portal">
        <vers num="1.0_stable" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1602" published="2004-10-15" name="CVE-2004-1602" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">ProFTPD 1.2.x, including 1.2.8 and 1.2.10, responds in a different amount of time when a given username exists, which allows remote attackers to identify valid usernames by timing the server response.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <other />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://securitytracker.com/id?1011687" source="SECTRACK" patch="1" adv="1">1011687</ref>
      <ref url="http://security.lss.hr/index.php?page=details&amp;ID=LSS-2004-10-02" source="MISC" patch="1" adv="1">http://security.lss.hr/index.php?page=details&amp;ID=LSS-2004-10-02</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109786760926133&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20041015 ProFTPD 1.2.x remote users enumeration bug</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/17724" source="XF" adv="1">proftpd-info-disclosure(17724)</ref>
      <ref url="http://www.securityfocus.com/bid/11430" source="BID" adv="1">11430</ref>
    </refs>
    <vuln_soft>
      <prod vendor="proftpd_project" name="proftpd">
        <vers num="1.2" />
        <vers num="1.2.0_rc1" />
        <vers num="1.2.0_rc2" />
        <vers num="1.2.0_rc3" />
        <vers num="1.2.1" />
        <vers num="1.2.2" />
        <vers num="1.2.2_rc1" />
        <vers num="1.2.2_rc3" />
        <vers num="1.2.3" />
        <vers num="1.2.4" />
        <vers num="1.2.5" />
        <vers num="1.2.5_rc1" />
        <vers num="1.2.6" />
        <vers num="1.2.7" />
        <vers num="1.2.7_rc1" />
        <vers num="1.2.7_rc2" />
        <vers num="1.2.7_rc3" />
        <vers num="1.2.8" />
        <vers num="1.2.8_rc1" />
        <vers num="1.2.8_rc2" />
        <vers num="1.2.9" />
        <vers num="1.2.9_rc1" />
        <vers num="1.2.9_rc2" />
        <vers num="1.2.9_rc3" />
        <vers num="1.2_pre1" />
        <vers num="1.2_pre10" />
        <vers num="1.2_pre11" />
        <vers num="1.2_pre2" />
        <vers num="1.2_pre3" />
        <vers num="1.2_pre4" />
        <vers num="1.2_pre5" />
        <vers num="1.2_pre6" />
        <vers num="1.2_pre7" />
        <vers num="1.2_pre8" />
        <vers num="1.2_pre9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1603" published="2004-10-18" name="CVE-2004-1603" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">cPanel 9.4.1-RELEASE-64 follows hard links, which allows local users to (1) read arbitrary files via the backup feature or (2) chown arbitrary files via the .htaccess file when Front Page extensions are enabled or disabled.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/11455" source="BID" patch="1" adv="1">11455</ref>
      <ref url="http://www.securityfocus.com/bid/11449" source="BID" patch="1" adv="1">11449</ref>
      <ref url="http://secunia.com/advisories/12865" source="SECUNIA" patch="1" adv="1">12865</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/17780" source="XF" adv="1">cpanel-htaccess-modify-ownership(17780)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/17779" source="XF" adv="1">cpanel-backup-view-file(17779)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109811654104208&amp;w=2" source="BUGTRAQ" adv="1">20041018 cPanel hardlink chown issue</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109811572123753&amp;w=2" source="BUGTRAQ" adv="1">20041018 cPanel hardlink backup issue</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cpanel" name="cpanel">
        <vers num="9.4.1_r64" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1604" published="2004-09-30" name="CVE-2004-1604" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">cPanel 9.9.1-RELEASE-3 allows remote authenticated users to chmod arbitrary files via a symlink attack on the _private directory, which is created when Front Page extensions are enabled.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109811762230326&amp;w=2" source="BUGTRAQ" adv="1">20041018 cPanel symlink chmod issue</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cpanel" name="cpanel">
        <vers num="9.9.1_r3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-1605" published="2004-10-14" name="CVE-2004-1605" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SalesLogix 6.1 allows remote attackers to bypass authentication by modifying the slxweb cookie to set user=Admin, teams=ADMIN!, and usertype=Administrator.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <access />
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/17749" source="XF" patch="1" adv="1">saleslogix-cookie-admin-access(17749)</ref>
      <ref url="http://www.securityfocus.com/bid/11450" source="BID" patch="1" adv="1">11450</ref>
      <ref url="http://secunia.com/advisories/12883" source="SECUNIA" patch="1" adv="1">12883</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109811852218478&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20041018 Multiple vulnerabilities in Sage Saleslogix</ref>
      <ref url="http://www.osvdb.org/10942" source="OSVDB">10942</ref>
      <ref url="http://securitytracker.com/id?1011769" source="SECTRACK">1011769</ref>
      <ref url="http://archives.neohapsis.com/archives/fulldisclosure/2004-10/0661.html" source="FULLDISC">20041018 Multiple vulnerabilities in Sage Saleslogix</ref>
    </refs>
    <vuln_soft>
      <prod vendor="best_software" name="saleslogix">
        <vers num="" />
      </prod>
      <prod vendor="saleslogix_corporation" name="saleslogix">
        <vers num="2000.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1606" published="2004-10-18" name="CVE-2004-1606" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:P)" CVSS_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_base_score="6.4">
    <desc>
      <descript source="cve">slxweb.dll in SalesLogix 6.1 allows remote attackers to cause a denial service (application crash) via an invalid HTTP request, which might also leak sensitive information in the ErrorLogMsg cookie.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
    </loss_types>
    <vuln_types>
      <input />
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/17750" source="XF" patch="1" adv="1">saleslogix-info-disclosure(17750)</ref>
      <ref url="http://www.securityfocus.com/bid/11450" source="BID" patch="1" adv="1">11450</ref>
      <ref url="http://secunia.com/advisories/12883" source="SECUNIA" patch="1" adv="1">12883</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109811852218478&amp;w=2" source="BUGTRAQ" adv="1">20041018 Multiple vulnerabilities in Sage Saleslogix</ref>
      <ref url="http://www.osvdb.org/10943" source="OSVDB">10943</ref>
      <ref url="http://securitytracker.com/id?1011769" source="SECTRACK">1011769</ref>
      <ref url="http://archives.neohapsis.com/archives/fulldisclosure/2004-10/0661.html" source="FULLDISC">20041018 Multiple vulnerabilities in Sage Saleslogix</ref>
    </refs>
    <vuln_soft>
      <prod vendor="best_software" name="saleslogix">
        <vers num="" />
      </prod>
      <prod vendor="saleslogix_corporation" name="saleslogix">
        <vers num="2000.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1607" published="2004-10-18" name="CVE-2004-1607" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">slxweb.dll in SalesLogix 6.1 allows remote attackers to obtain sensitive information via a (1) Library or (2) Attachment request with an invalid file parameter, which reveals the path in an error message.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/17751" source="XF" patch="1" adv="1">saleslogix-filename-path-disclosure(17751)</ref>
      <ref url="http://www.securityfocus.com/bid/11450" source="BID" patch="1" adv="1">11450</ref>
      <ref url="http://secunia.com/advisories/12883" source="SECUNIA" patch="1" adv="1">12883</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109811852218478&amp;w=2" source="BUGTRAQ" adv="1">20041018 Multiple vulnerabilities in Sage Saleslogix</ref>
      <ref url="http://www.osvdb.org/10944" source="OSVDB">10944</ref>
      <ref url="http://securitytracker.com/id?1011769" source="SECTRACK">1011769</ref>
      <ref url="http://archives.neohapsis.com/archives/fulldisclosure/2004-10/0661.html" source="FULLDISC">20041018 Multiple vulnerabilities in Sage Saleslogix</ref>
    </refs>
    <vuln_soft>
      <prod vendor="best_software" name="saleslogix">
        <vers num="" />
      </prod>
      <prod vendor="saleslogix_corporation" name="saleslogix">
        <vers num="2000.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-1608" published="2004-10-18" name="CVE-2004-1608" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in SalesLogix 6.1 allows remote attackers to execute arbitrary SQL statements via the id parameter in a view operation.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/17752" source="XF" patch="1" adv="1">saleslogix-sql-injection(17752)</ref>
      <ref url="http://www.securityfocus.com/bid/11450" source="BID" patch="1" adv="1">11450</ref>
      <ref url="http://secunia.com/advisories/12883" source="SECUNIA" patch="1" adv="1">12883</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109811852218478&amp;w=2" source="BUGTRAQ" adv="1">20041018 Multiple vulnerabilities in Sage Saleslogix</ref>
      <ref url="http://www.osvdb.org/10945" source="OSVDB">10945</ref>
      <ref url="http://securitytracker.com/id?1011769" source="SECTRACK">1011769</ref>
      <ref url="http://archives.neohapsis.com/archives/fulldisclosure/2004-10/0661.html" source="FULLDISC">20041018 Multiple vulnerabilities in Sage Saleslogix</ref>
    </refs>
    <vuln_soft>
      <prod vendor="best_software" name="saleslogix">
        <vers num="" />
      </prod>
      <prod vendor="saleslogix_corporation" name="saleslogix">
        <vers num="2000.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1609" published="2004-10-18" name="CVE-2004-1609" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">SalesLogix 6.1 includes usernames, passwords, and other sensitive information in the headers of an HTTP response, which could allow remote attackers to gain access.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/17753" source="XF" patch="1" adv="1">saleslogix-obtain-passwords(17753)</ref>
      <ref url="http://www.securityfocus.com/bid/11450" source="BID" patch="1" adv="1">11450</ref>
      <ref url="http://secunia.com/advisories/12883" source="SECUNIA" patch="1" adv="1">12883</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109811852218478&amp;w=2" source="BUGTRAQ" adv="1">20041018 Multiple vulnerabilities in Sage Saleslogix</ref>
      <ref url="http://www.osvdb.org/10946" source="OSVDB">10946</ref>
      <ref url="http://securitytracker.com/id?1011769" source="SECTRACK">1011769</ref>
      <ref url="http://archives.neohapsis.com/archives/fulldisclosure/2004-10/0661.html" source="FULLDISC">20041018 Multiple vulnerabilities in Sage Saleslogix</ref>
    </refs>
    <vuln_soft>
      <prod vendor="best_software" name="saleslogix">
        <vers num="" />
      </prod>
      <prod vendor="saleslogix_corporation" name="saleslogix">
        <vers num="2000.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-1610" published="2004-10-18" name="CVE-2004-1610" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SalesLogix 6.1 uses client-specified pathnames for writing certain files, which might allow remote authenticated users to create arbitrary files and execute code via the (1) vMME.AttachmentPath or (2) vMME.LibraryPath variables.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109811852218478&amp;w=2" source="BUGTRAQ" adv="1">20041018 Multiple vulnerabilities in Sage Saleslogix</ref>
    </refs>
    <vuln_soft>
      <prod vendor="best_software" name="saleslogix">
        <vers num="" />
      </prod>
      <prod vendor="saleslogix_corporation" name="saleslogix">
        <vers num="2000.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1611" published="2004-10-18" name="CVE-2004-1611" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_score="5.1" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="4.9" CVSS_base_score="5.1">
    <desc>
      <descript source="cve">SalesLogix 6.1 does not verify if a user is authenticated before performing sensitive operations, which could allow remote attackers to (1) execute arbitrary SLX commands on the server or spoof the server via a man-in-the-middle (MITM) attack, or (2) obtain the database password via a GetConnection request to TCP port 1707.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <race />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/17754" source="XF" patch="1" adv="1">saleslogix-getconnection-account-disclosure(17754)</ref>
      <ref url="http://www.securityfocus.com/bid/11450" source="BID" patch="1" adv="1">11450</ref>
      <ref url="http://secunia.com/advisories/12883" source="SECUNIA" patch="1" adv="1">12883</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109811852218478&amp;w=2" source="BUGTRAQ" adv="1">20041018 Multiple vulnerabilities in Sage Saleslogix</ref>
      <ref url="http://www.osvdb.org/10948" source="OSVDB">10948</ref>
      <ref url="http://www.osvdb.org/10947" source="OSVDB">10947</ref>
      <ref url="http://securitytracker.com/id?1011769" source="SECTRACK">1011769</ref>
      <ref url="http://archives.neohapsis.com/archives/fulldisclosure/2004-10/0661.html" source="FULLDISC">20041018 Multiple vulnerabilities in Sage Saleslogix</ref>
    </refs>
    <vuln_soft>
      <prod vendor="best_software" name="saleslogix">
        <vers num="" />
      </prod>
      <prod vendor="saleslogix_corporation" name="saleslogix">
        <vers num="2000.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1612" published="2004-10-18" name="CVE-2004-1612" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in SalesLogix 6.1 allows remote attackers to upload arbitrary files via a .. (dot dot) in a ProcessQueueFile request.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/17765" source="XF" patch="1" adv="1">saleslogix-processqueuefile-file-upload(17765)</ref>
      <ref url="http://www.securityfocus.com/bid/11450" source="BID" patch="1" adv="1">11450</ref>
      <ref url="http://secunia.com/advisories/12883" source="SECUNIA" patch="1" adv="1">12883</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109811852218478&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20041018 Multiple vulnerabilities in Sage Saleslogix</ref>
      <ref url="http://www.osvdb.org/10949" source="OSVDB">10949</ref>
      <ref url="http://securitytracker.com/id?1011769" source="SECTRACK">1011769</ref>
      <ref url="http://archives.neohapsis.com/archives/fulldisclosure/2004-10/0661.html" source="FULLDISC">20041018 Multiple vulnerabilities in Sage Saleslogix</ref>
    </refs>
    <vuln_soft>
      <prod vendor="saleslogix_corporation" name="saleslogix">
        <vers num="2000.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1613" published="2004-10-18" name="CVE-2004-1613" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Mozilla allows remote attackers to cause a denial of service (application crash from null dereference or infinite loop) via a web page that contains a (1) TEXTAREA, (2) INPUT, (3) FRAMESET or (4) IMG tag followed by a null character and some trailing characters, as demonstrated by mangleme.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/11439" source="BID" patch="1" adv="1">11439</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-323.html" source="REDHAT" patch="1" adv="1">RHSA-2005:323</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/17805" source="XF" adv="1">mozilla-html-tags-dos(17805)</ref>
      <ref url="http://securitytracker.com/id?1011810" source="SECTRACK" adv="1">1011810</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10227" source="OVAL">oval:org.mitre.oval:def:10227</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109811406620511&amp;w=2" source="BUGTRAQ" adv="1">20041018 Web browsers - a mini-farce</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2004-October/027709.html" source="FULLDISC" adv="1">20041018 Web browsers - a mini-farce</ref>
      <ref url="http://lcamtuf.coredump.cx/mangleme/gallery/" source="MISC">http://lcamtuf.coredump.cx/mangleme/gallery/</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="mozilla">
        <vers num="1.0" edition="rc1" />
        <vers num="1.0" edition="rc2" />
        <vers num="1.0.1" />
        <vers num="1.0.2" />
        <vers num="1.1" edition="alpha" />
        <vers num="1.1" edition="beta" />
        <vers num="1.2" edition="alpha" />
        <vers num="1.2" edition="beta" />
        <vers num="1.2.1" />
        <vers num="1.3" />
        <vers num="1.3.1" />
        <vers num="1.4" edition="alpha" />
        <vers num="1.4" edition="beta" />
        <vers num="1.4.1" />
        <vers num="1.4.2" />
        <vers num="1.4.4" />
        <vers num="1.5" />
        <vers num="1.6" />
        <vers num="1.7" edition="rc3" />
        <vers num="1.7.1" />
        <vers num="1.7.2" />
        <vers num="1.7.3" />
        <vers num="1.8" edition="alpha2" />
      </prod>
      <prod vendor="sgi" name="propack">
        <vers num="3.0" />
      </prod>
      <prod vendor="redhat" name="enterprise_linux">
        <vers num="2.1" edition="" />
        <vers num="2.1" edition=":advanced_server" />
        <vers num="2.1" edition=":enterprise_server" />
        <vers num="2.1" edition=":workstation" />
        <vers num="3.0" edition="" />
        <vers num="3.0" edition=":advanced_servers" />
        <vers num="3.0" edition=":enterprise_server" />
        <vers num="3.0" edition=":workstation" />
      </prod>
      <prod vendor="redhat" name="enterprise_linux_desktop">
        <vers num="3.0" />
      </prod>
      <prod vendor="redhat" name="fedora_core">
        <vers num="core_1.0" />
        <vers num="core_2.0" />
      </prod>
      <prod vendor="redhat" name="linux">
        <vers num="7.3" edition="" />
        <vers num="7.3" edition=":i386" />
        <vers num="7.3" edition=":i686" />
        <vers num="9.0" edition="" />
        <vers num="9.0" edition=":i386" />
      </prod>
      <prod vendor="redhat" name="linux_advanced_workstation">
        <vers num="2.1" edition="" />
        <vers num="2.1" edition=":itanium" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1614" published="2004-10-18" name="CVE-2004-1614" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Mozilla allows remote attackers to cause a denial of service (application crash from invalid memory access) via an "unusual combination of visual elements," including several large MARQUEE tags with large height parameters, as demonstrated by mangleme.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/11440" source="BID" adv="1">11440</ref>
      <ref url="http://securitytracker.com/id?1011810" source="SECTRACK">1011810</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109811406620511&amp;w=2" source="BUGTRAQ" adv="1">20041018 Web browsers - a mini-farce</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2004-October/027709.html" source="FULLDISC" adv="1">20041018 Web browsers - a mini-farce</ref>
      <ref url="http://lcamtuf.coredump.cx/mangleme/gallery/" source="MISC" adv="1">http://lcamtuf.coredump.cx/mangleme/gallery/</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="mozilla">
        <vers num="1.0" edition="rc1" />
        <vers num="1.0" edition="rc2" />
        <vers num="1.0.1" />
        <vers num="1.0.2" />
        <vers num="1.1" edition="alpha" />
        <vers num="1.1" edition="beta" />
        <vers num="1.2" edition="alpha" />
        <vers num="1.2" edition="beta" />
        <vers num="1.2.1" />
        <vers num="1.3" />
        <vers num="1.3.1" />
        <vers num="1.4" edition="alpha" />
        <vers num="1.4" edition="beta" />
        <vers num="1.4.1" />
        <vers num="1.4.2" />
        <vers num="1.5" />
        <vers num="1.6" />
        <vers num="1.7" edition="rc3" />
        <vers num="1.7.1" />
        <vers num="1.7.2" />
        <vers num="1.7.3" />
        <vers num="1.8" edition="alpha2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2004-1615" published="2004-10-18" name="CVE-2004-1615" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:N/A:P)" CVSS_score="2.6" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="4.9" CVSS_base_score="2.6">
    <desc>
      <descript source="cve">Opera allows remote attackers to cause a denial of service (invalid memory reference and application crash) via a web page or HTML email that contains a TBODY tag with a large COL SPAN value, as demonstrated by mangleme.</descript>
    </desc>
    <sols>
      <sol source="nvd">This was fixed in version 7.60.</sol>
    </sols>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/11441" source="BID" patch="1" adv="1">11441</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/17806" source="XF" adv="1">opera-colspan-tbody-dos(17806)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109811406620511&amp;w=2" source="BUGTRAQ" adv="1">20041018 Web browsers - a mini-farce</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2004-October/027709.html" source="FULLDISC" adv="1">20041018 Web browsers - a mini-farce</ref>
      <ref url="http://lcamtuf.coredump.cx/mangleme/gallery/" source="MISC" adv="1">http://lcamtuf.coredump.cx/mangleme/gallery/</ref>
    </refs>
    <vuln_soft>
      <prod vendor="opera_software" name="opera_web_browser">
        <vers num="6.0" edition="" />
        <vers num="6.0" edition=":win32" />
        <vers num="6.0.1" edition="" />
        <vers num="6.0.1" edition=":win32" />
        <vers num="6.0.1" edition=":linux" />
        <vers num="6.0.2" edition="" />
        <vers num="6.0.2" edition=":linux" />
        <vers num="6.0.2" edition=":win32" />
        <vers num="6.0.3" edition="" />
        <vers num="6.0.3" edition=":linux" />
        <vers num="6.0.3" edition=":win32" />
        <vers num="6.0.4" edition="" />
        <vers num="6.0.4" edition=":win32" />
        <vers num="6.0.5" edition="" />
        <vers num="6.0.5" edition=":win32" />
        <vers num="6.0.6" edition="" />
        <vers num="6.0.6" edition=":win32" />
        <vers num="6.10" edition="" />
        <vers num="6.10" edition=":linux" />
        <vers num="7.0" edition="" />
        <vers num="7.0" edition=":win32" />
        <vers num="7.0.1" edition="" />
        <vers num="7.0.1" edition=":win32" />
        <vers num="7.0.2" edition="" />
        <vers num="7.0.2" edition=":win32" />
        <vers num="7.0.3" edition="" />
        <vers num="7.0.3" edition=":win32" />
        <vers num="7.0_beta1" edition="" />
        <vers num="7.0_beta1" edition=":win32" />
        <vers num="7.0_beta2" edition="" />
        <vers num="7.0_beta2" edition=":win32" />
        <vers num="7.10" />
        <vers num="7.11" />
        <vers num="7.11b" />
        <vers num="7.11j" />
        <vers num="7.20" />
        <vers num="7.20_beta1_build2981" />
        <vers num="7.21" />
        <vers num="7.22" />
        <vers num="7.23" />
        <vers num="7.50" />
        <vers num="7.51" />
        <vers num="7.52" />
        <vers num="7.53" />
        <vers num="7.54" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1616" published="2004-10-18" name="CVE-2004-1616" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Links allows remote attackers to cause a denial of service (memory consumption) via a web page or HTML email that contains a table with a td element and a large rowspan value,as demonstrated by mangleme.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/17803" source="XF" adv="1">links-large-table-dos(17803)</ref>
      <ref url="http://www.securityfocus.com/bid/11442" source="BID" adv="1">11442</ref>
      <ref url="http://securitytracker.com/id?1011808" source="SECTRACK">1011808</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109811406620511&amp;w=2" source="BUGTRAQ" adv="1">20041018 Web browsers - a mini-farce</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2004-October/027709.html" source="FULLDISC" adv="1">20041018 Web browsers - a mini-farce</ref>
      <ref url="http://lcamtuf.coredump.cx/mangleme/gallery/" source="MISC" adv="1">http://lcamtuf.coredump.cx/mangleme/gallery/</ref>
    </refs>
    <vuln_soft>
      <prod vendor="links" name="links">
        <vers num="0.91" />
        <vers num="0.92" />
        <vers num="0.93" />
        <vers num="0.94" />
        <vers num="0.95" />
        <vers num="0.96" />
        <vers num="0.97" />
        <vers num="0.98" />
        <vers num="0.99" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1617" published="2004-10-18" name="CVE-2004-1617" modified="2008-09-10" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Lynx, lynx-ssl, and lynx-cur before 2.8.6dev.8 allow remote attackers to cause a denial of service (infinite loop) via a web page or HTML email that contains invalid HTML including (1) a TEXTAREA tag with a large COLS value and (2) a large tag name in an element that is not terminated, as demonstrated by mangleme.  NOTE: a followup suggests that the relevant trigger for this issue is the large COLS value.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/17804" source="XF" adv="1">lynx-dos(17804)</ref>
      <ref url="http://www.securityfocus.com/bid/11443" source="BID" adv="1">11443</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/435689/30/4740/threaded" source="BUGTRAQ">20060602 Re: [SECURITY] [DSA 1085-1] New lynx-cur packages fix several vulnerabilities</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1085" source="DEBIAN">DSA-1085</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1077" source="DEBIAN">DSA-1077</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1076" source="DEBIAN">DSA-1076</ref>
      <ref url="http://securitytracker.com/id?1011809" source="SECTRACK">1011809</ref>
      <ref url="http://secunia.com/advisories/20383" source="SECUNIA" adv="1">20383</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109811406620511&amp;w=2" source="BUGTRAQ" adv="1">20041018 Web browsers - a mini-farce</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2004-October/027709.html" source="FULLDISC" adv="1">20041018 Web browsers - a mini-farce</ref>
      <ref url="http://lcamtuf.coredump.cx/mangleme/gallery/" source="MISC" adv="1">http://lcamtuf.coredump.cx/mangleme/gallery/</ref>
    </refs>
    <vuln_soft>
      <prod vendor="university_of_kansas" name="lynx">
        <vers num="2.7" />
        <vers num="2.8" />
        <vers num="2.8.1" />
        <vers num="2.8.2_rel1" />
        <vers num="2.8.3" />
        <vers num="2.8.3_dev22" />
        <vers num="2.8.3_pre5" />
        <vers num="2.8.3_rel1" />
        <vers num="2.8.4" />
        <vers num="2.8.4_rel1" />
        <vers num="2.8.5" />
        <vers num="2.8.5_dev2" />
        <vers num="2.8.5_dev3" />
        <vers num="2.8.5_dev4" />
        <vers num="2.8.5_dev5" />
        <vers num="2.8.5_dev8" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1618" published="2004-10-19" name="CVE-2004-1618" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Vypress Tonecast 1.3 and earlier allows remote attackers to cause a denial of service (application crash) via a malformed mp2 stream.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/17775" source="XF" adv="1">vypress-tonecast-dos(17775)</ref>
      <ref url="http://www.securityfocus.com/bid/11462" source="BID" adv="1">11462</ref>
      <ref url="http://secunia.com/advisories/12890" source="SECUNIA" adv="1">12890</ref>
      <ref url="http://aluigi.altervista.org/adv/toneboom-adv.txt" source="MISC" adv="1">http://aluigi.altervista.org/adv/toneboom-adv.txt</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109820344806472&amp;w=2" source="BUGTRAQ">20041019 Broadcast crash in Vypress Tonecast 1.3</ref>
    </refs>
    <vuln_soft>
      <prod vendor="vypress" name="tonecast">
        <vers prev="1" num="1.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-1619" published="2004-10-20" name="CVE-2004-1619" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in Privateer's Bounty: Age of Sail II allows remote attackers to execute arbitrary code via a long nickname.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/17791" source="XF" adv="1">age-of-sail-bo(17791)</ref>
      <ref url="http://www.securityfocus.com/bid/11479" source="BID" adv="1">11479</ref>
      <ref url="http://secunia.com/advisories/12905" source="SECUNIA" adv="1">12905</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109829017407842&amp;w=2" source="BUGTRAQ" adv="1">20041020 Buffer-overflow in Age of Sail II 1.04.151</ref>
    </refs>
    <vuln_soft>
      <prod vendor="akella" name="privateers_bounty_age_of_sail_ii">
        <vers num="1.4.51" />
        <vers num="1.55" />
        <vers num="1.56" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1620" published="2004-10-21" name="CVE-2004-1620" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">CRLF injection vulnerability in Serendipity before 0.7rc1 allows remote attackers to perform HTTP Response Splitting attacks to modify expected HTML content from the server via the url parameter in (1) index.php and (2) exit.php, or (3) the HTTP Referer field in comment.php.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/17798" source="XF" patch="1" adv="1">serendipity-response-splitting(17798)</ref>
      <ref url="http://www.securityfocus.com/bid/11497" source="BID" patch="1" adv="1">11497</ref>
      <ref url="http://www.s9y.org/5.html" source="CONFIRM" patch="1" adv="1">http://www.s9y.org/5.html</ref>
      <ref url="http://secunia.com/advisories/12909/" source="SECUNIA" patch="1" adv="1">12909</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109841283115808&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20041021 HTTP Response Splitting in Serendipity 0.7-beta4</ref>
      <ref url="http://www.osvdb.org/11039" source="OSVDB">11039</ref>
      <ref url="http://www.osvdb.org/11038" source="OSVDB">11038</ref>
      <ref url="http://www.osvdb.org/11013" source="OSVDB">11013</ref>
      <ref url="http://sourceforge.net/project/shownotes.php?release_id=276694" source="CONFIRM">http://sourceforge.net/project/shownotes.php?release_id=276694</ref>
      <ref url="http://securitytracker.com/id?1011864" source="SECTRACK">1011864</ref>
      <ref url="http://cvs.sourceforge.net/viewcvs.py/php-blog/serendipity/index.php?rev=1.52&amp;view=markup" source="CONFIRM">http://cvs.sourceforge.net/viewcvs.py/php-blog/serendipity/index.php?rev=1.52&amp;view=markup</ref>
      <ref url="http://cvs.sourceforge.net/viewcvs.py/php-blog/serendipity/exit.php?rev=1.10&amp;view=markup" source="CONFIRM">http://cvs.sourceforge.net/viewcvs.py/php-blog/serendipity/exit.php?rev=1.10&amp;view=markup</ref>
      <ref url="http://cvs.sourceforge.net/viewcvs.py/php-blog/serendipity/comment.php?rev=1.49&amp;view=markup" source="CONFIRM">http://cvs.sourceforge.net/viewcvs.py/php-blog/serendipity/comment.php?rev=1.49&amp;view=markup</ref>
    </refs>
    <vuln_soft>
      <prod vendor="s9y" name="serendipity">
        <vers num="0.3" />
        <vers num="0.4" />
        <vers num="0.5" />
        <vers num="0.5_pl1" />
        <vers num="0.6" />
        <vers num="0.6_pl1" />
        <vers num="0.6_pl2" />
        <vers num="0.6_pl3" />
        <vers num="0.6_rc1" />
        <vers num="0.6_rc2" />
        <vers num="0.7_beta1" />
        <vers num="0.7_beta2" />
        <vers num="0.7_beta3" />
        <vers num="0.7_beta4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1621" published="2004-10-18" name="CVE-2004-1621" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">** DISPUTED **  NOTE: this issue has been disputed by the vendor.  Cross-site scripting (XSS) vulnerability in IBM Lotus Notes R6 and Domino R6, and possibly earlier versions, allows remote attackers to execute arbitrary web script or HTML via square brackets at the beginning and end of (1) computed for display, (2) computed when composed, or (3) computed text element fields.  NOTE: the vendor has disputed this issue, saying that it is not a problem with Notes/Domino itself, but with the applications that do not properly handle this feature.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/17758" source="XF" adv="1">lotus-notes-xss(17758)</ref>
      <ref url="http://www.securityfocus.com/bid/11458" source="BID" adv="1">11458</ref>
      <ref url="http://www-1.ibm.com/support/docview.wss?rs=463&amp;uid=swg21187833" source="MISC" adv="1">http://www-1.ibm.com/support/docview.wss?rs=463&amp;uid=swg21187833</ref>
      <ref url="http://securitytracker.com/id?1011779" source="SECTRACK" adv="1">1011779</ref>
      <ref url="http://secunia.com/advisories/12891" source="SECUNIA" adv="1">12891</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109841682529328&amp;w=2" source="BUGTRAQ" adv="1">20041021 Re: IBM Lotus Notes/Domino fails to encode Square Brackets ( [  ] )</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109812960023736&amp;w=2" source="BUGTRAQ" adv="1">20041018 IBM Lotus Notes/Domino fails to encode Square Brackets ( [  ] )</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="lotus_domino">
        <vers num="6.0" />
        <vers num="6.0.1" />
        <vers num="6.0.2" />
        <vers num="6.0.2_cf2" />
        <vers num="6.0.3" />
        <vers num="6.5.0" />
        <vers num="6.5.1" />
        <vers num="6.5.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-1622" published="2004-10-21" name="CVE-2004-1622" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in dosearch.php in UBB.threads 3.4.x allows remote attackers to execute arbitrary SQL statements via the Name parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/17821" source="XF" adv="1">ubbthreads-sql-injection(17821)</ref>
      <ref url="http://www.securityfocus.com/bid/11502" source="BID" adv="1">11502</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109839925207038&amp;w=2" source="BUGTRAQ" adv="1">20041021 SQL Injection in UBB.threads 3.4.x</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ubbcentral" name="ubb.threads">
        <vers num="3.4" />
        <vers num="3.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1623" published="2004-10-22" name="CVE-2004-1623" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The WAV file property handler in Windows XP SP1 allows remote attackers to cause a denial of service (infinite loop in Explorer) via a WAV file with an invalid file header whose fmt chunk length is set to 0xFFFFFFFF.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/11503" source="BID" adv="1">11503</ref>
      <ref url="http://www.hexview.com/docs/20041021-1.txt" source="MISC" adv="1">http://www.hexview.com/docs/20041021-1.txt</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109846319313443&amp;w=2" source="BUGTRAQ" adv="1">20041021 [HV-LOW] Unsafe WAV header handling can cause DoS on Windows</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/17864" source="XF">windowsxp-explorer-wav-dos(17864)</ref>
      <ref url="http://www.osvdb.org/11053" source="OSVDB">11053</ref>
      <ref url="http://securitytracker.com/id?1011880" source="SECTRACK">1011880</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_xp">
        <vers num="" edition=":media_center" />
        <vers num="" edition=":embedded" />
        <vers num="" edition=":home" />
        <vers num="" edition="gold" />
        <vers num="" edition="gold:professional" />
        <vers num="" edition="sp1" />
        <vers num="" edition="sp1:embedded" />
        <vers num="" edition="sp1:home" />
        <vers num="" edition="sp1:media_center" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-1624" published="2004-10-21" name="CVE-2004-1624" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Carbon Copy 6.0.5257 does not drop system privileges when opening external programs through the help topic interface, which allows local users to gain privileges via (1) the help topic interface in CCW32.exe, which launches Notepad, or (2) the help button in the Carbon Copy Scheduler (CCSched.exe).</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/17838" source="XF" adv="1">carboncopy-help-gain-privileges(17838)</ref>
      <ref url="http://www.securityfocus.com/bid/11500" source="BID" adv="1">11500</ref>
      <ref url="http://secunia.com/advisories/12962" source="SECUNIA" adv="1">12962</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109846296406459&amp;w=2" source="BUGTRAQ" adv="1">20041022 [Fwd: Altiris Carbon Copy Remote Control  local SYSTEM exploitation.]</ref>
    </refs>
    <vuln_soft>
      <prod vendor="altiris" name="carbon_copy">
        <vers num="5.0" />
        <vers num="6.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1625" published="2004-10-22" name="CVE-2004-1625" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">pGina 1.7.6 and possibly older versions, when the Restart or Shutdown options are enabled on the login screen, allows remote attackers to cause a denial of service by connecting via Remote Desktop and clicking restart or shutdown.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/17836" source="XF" adv="1">pgina-dos(17836)</ref>
      <ref url="http://www.lovebug.org/pgina_dos.txt" source="MISC">http://www.lovebug.org/pgina_dos.txt</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109849689808245&amp;w=2" source="BUGTRAQ" adv="1">20041022 Windows DoS in certain pGina configurations</ref>
    </refs>
    <vuln_soft>
      <prod vendor="pgina" name="pgina">
        <vers num="1.7.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1626" published="2004-10-22" name="CVE-2004-1626" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Buffer overflow in Ability Server 2.34, and possibly other versions, allows remote attackers to execute arbitrary code via a long STOR command.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/857846" source="CERT-VN" adv="1">VU#857846</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/17823" source="XF" adv="1">abilityftpserver-stor-dos(17823)</ref>
      <ref url="http://www.securityfocus.com/bid/11508" source="BID" adv="1">11508</ref>
      <ref url="http://www.osvdb.org/11030" source="OSVDB" adv="1">11030</ref>
      <ref url="http://secunia.com/advisories/12941" source="SECUNIA" adv="1">12941</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109850947508816&amp;w=2" source="BUGTRAQ" adv="1">20041022 Ability FTP Server 2.34 Buffer Overflow Exploit</ref>
    </refs>
    <vuln_soft>
      <prod vendor="code-crafters" name="ability_server">
        <vers num="2.2.5" />
        <vers num="2.3.2" />
        <vers num="2.3.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-1627" published="2004-10-22" name="CVE-2004-1627" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in Ability Server 2.25, 2.32, 2.34, and possibly other versions, allows remote attackers to execute arbitrary code via a long APPE command.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/11508" source="BID" adv="1">11508</ref>
      <ref url="http://securitytracker.com/id?1012464" source="SECTRACK" adv="1">1012464</ref>
      <ref url="http://secunia.com/advisories/12941" source="SECUNIA" adv="1">12941</ref>
      <ref url="http://lists.virus.org/dw-0day-0412/msg00004.html" source="MLIST" adv="1">[0day] 20041208 Ability Server 2.25 - 2.34 FTP => 'APPE' Buffer Overflow - PnK:: DCN3T</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/18405" source="XF">ability-appe-bo(18405)</ref>
      <ref url="http://www.osvdb.org/12347" source="OSVDB">12347</ref>
    </refs>
    <vuln_soft>
      <prod vendor="code-crafters" name="ability_server">
        <vers num="2.2.5" />
        <vers num="2.3.2" />
        <vers num="2.3.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-1628" published="2004-10-23" name="CVE-2004-1628" modified="2005-10-20" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Format string vulnerability in log.c in rssh before 2.2.2 allows remote authenticated users to execute arbitrary code.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/17831" source="XF" patch="1" adv="1">rssh-format-string(17831)</ref>
      <ref url="http://www.pizzashack.org/rssh/" source="CONFIRM" patch="1">http://www.pizzashack.org/rssh/</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200410-28.xml" source="GENTOO" patch="1" adv="1">GLSA-200410-28</ref>
      <ref url="http://secunia.com/advisories/12954" source="SECUNIA" patch="1" adv="1">12954</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109855982425122&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20041023 rssh: pizzacode security alert</ref>
    </refs>
  </entry>
  <entry type="CVE" severity="High" seq="2004-1629" published="2004-10-23" name="CVE-2004-1629" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple SQL injection vulnerabilities in Dwc_articles 1.6 and earlier allow remote attackers to execute arbitrary SQL statements.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/17830" source="XF" adv="1">dwc-articles-sql-injection(17830)</ref>
      <ref url="http://www.securityfocus.com/bid/11509" source="BID" adv="1">11509</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109855895702903&amp;w=2" source="BUGTRAQ" adv="1">20041023 dwc_articles possible sql injection</ref>
    </refs>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1630" published="2004-10-25" name="CVE-2004-1630" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in the login form in Open WorkFlow Engine (OpenWFE) 1.4.x allows remote attackers to execute arbitrary web script or HTML via the url parameter.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/11514" source="BID" patch="1" adv="1">11514</ref>
      <ref url="http://secunia.com/advisories/12970" source="SECUNIA" patch="1" adv="1">12970</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/17853" source="XF" adv="1">openwfe-login-form-xss(17853)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109876304705234&amp;w=2" source="BUGTRAQ" adv="1">20041024 Two Vulnerabilities in OpenWFE Web Client</ref>
    </refs>
    <vuln_soft>
      <prod vendor="openwfe" name="work_flow_engine">
        <vers num="1.4" />
        <vers num="1.4.1" />
        <vers num="1.4.2" />
        <vers num="1.4.3" />
        <vers num="1.4.4" />
        <vers num="1.4.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1631" published="2004-10-25" name="CVE-2004-1631" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Open WorkFlow Engine (OpenWFE) 1.4.x allows remote attackers to conduct port scans of remote hosts by specifying the target in an rmi:// Worklist URL, then using the response times to infer the results.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/17852" source="XF" patch="1" adv="1">openwfe-rmi-obtain-information(17852)</ref>
      <ref url="http://www.securityfocus.com/bid/11514" source="BID" patch="1" adv="1">11514</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109876304705234&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20041024 Two Vulnerabilities in OpenWFE Web Client</ref>
      <ref url="http://secunia.com/advisories/12970" source="SECUNIA" adv="1">12970</ref>
    </refs>
    <vuln_soft>
      <prod vendor="openwfe" name="work_flow_engine">
        <vers num="1.4" />
        <vers num="1.4.1" />
        <vers num="1.4.2" />
        <vers num="1.4.3" />
        <vers num="1.4.4" />
        <vers num="1.4.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1632" published="2004-10-25" name="CVE-2004-1632" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in wiki.php in MoniWiki 1.0.8 and earlier allows remote attackers to inject arbitrary web script or HTML via the arguments to wiki.php.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/17835" source="XF" patch="1" adv="1">moniwiki-wiki-xss(17835)</ref>
      <ref url="http://www.securityfocus.com/bid/11516" source="BID" patch="1" adv="1">11516</ref>
      <ref url="http://secunia.com/advisories/12975" source="SECUNIA" patch="1" adv="1">12975</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109873622006103&amp;w=2" source="BUGTRAQ" adv="1">20041025 STG Security Advisory: [SSA-20041022-08] MoniWiki XSS vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="moniwiki" name="moniwiki">
        <vers num="1.0.8" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1633" published="2004-10-25" name="CVE-2004-1633" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">process_bug.cgi in Bugzilla 2.9 through 2.18rc2 and 2.19 from CVS does not check edit permissions on the keywords field, which allows remote authenticated users to modify the keywords in a bug via the keywordaction parameter.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/17840" source="XF" patch="1" adv="1">bugzilla-bug-change(17840)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109872095201238&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20041025 [BUGZILLA] Vulnerabilities in Bugzilla 2.16.6 and 2.18rc2</ref>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=252638" source="CONFIRM" adv="1">https://bugzilla.mozilla.org/show_bug.cgi?id=252638</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="bugzilla">
        <vers num="2.10" />
        <vers num="2.12" />
        <vers num="2.14" />
        <vers num="2.14.1" />
        <vers num="2.14.2" />
        <vers num="2.14.3" />
        <vers num="2.14.4" />
        <vers num="2.14.5" />
        <vers num="2.16" />
        <vers num="2.16.1" />
        <vers num="2.16.2" />
        <vers num="2.16.3" />
        <vers num="2.16.4" />
        <vers num="2.16.5" />
        <vers num="2.17" />
        <vers num="2.17.1" />
        <vers num="2.17.3" />
        <vers num="2.17.4" />
        <vers num="2.17.5" />
        <vers num="2.17.6" />
        <vers num="2.17.7" />
        <vers num="2.18" edition="rc1" />
        <vers num="2.18" edition="rc2" />
        <vers num="2.19" />
        <vers num="2.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1634" published="2004-10-25" name="CVE-2004-1634" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">show_bug.cgi in Bugzilla 2.17.1 through 2.18rc2 and 2.19 from CVS, when using the insidergroup feature and exporting a bug to XML, shows comments and attachment summaries which are marked as private, which allows remote attackers to gain sensitive information.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/17841" source="XF" patch="1" adv="1">bugzilla-xml-information-disclosure(17841)</ref>
      <ref url="http://www.securityfocus.com/bid/11511" source="BID" patch="1" adv="1">11511</ref>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=263780" source="CONFIRM" adv="1">https://bugzilla.mozilla.org/show_bug.cgi?id=263780</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109872095201238&amp;w=2" source="BUGTRAQ" adv="1">20041025 [BUGZILLA] Vulnerabilities in Bugzilla 2.16.6 and 2.18rc2</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="bugzilla">
        <vers num="2.10" />
        <vers num="2.12" />
        <vers num="2.14" />
        <vers num="2.14.1" />
        <vers num="2.14.2" />
        <vers num="2.14.3" />
        <vers num="2.14.4" />
        <vers num="2.14.5" />
        <vers num="2.16" />
        <vers num="2.16.1" />
        <vers num="2.16.2" />
        <vers num="2.16.3" />
        <vers num="2.16.4" />
        <vers num="2.16.5" />
        <vers num="2.17" />
        <vers num="2.17.1" />
        <vers num="2.17.3" />
        <vers num="2.17.4" />
        <vers num="2.17.5" />
        <vers num="2.17.6" />
        <vers num="2.17.7" />
        <vers num="2.18" edition="rc1" />
        <vers num="2.18" edition="rc2" />
        <vers num="2.4" />
        <vers num="2.6" />
        <vers num="2.8" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1635" published="2004-10-24" name="CVE-2004-1635" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Bugzilla 2.17.1 through 2.18rc2 and 2.19 from cvs, when using the insidergroup feature, does not sufficiently protect private attachments when there are changes to the metadata, such as filename, description, MIME type, or review flags, which allows remote authenticated users to obtain sensitive information when (1) viewing the bug activity log or (2) receiving bug change notification mails.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/17842" source="XF" patch="1" adv="1">bugzila-metadata-information-disclosure(17842)</ref>
      <ref url="http://www.securityfocus.com/bid/11511" source="BID" patch="1" adv="1">11511</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109872095201238&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20041025 [BUGZILLA] Vulnerabilities in Bugzilla 2.16.6 and 2.18rc2</ref>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=253544" source="CONFIRM" adv="1">https://bugzilla.mozilla.org/show_bug.cgi?id=253544</ref>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=250605" source="CONFIRM" adv="1">https://bugzilla.mozilla.org/show_bug.cgi?id=250605</ref>
    </refs>
  </entry>
  <entry type="CVE" severity="High" seq="2004-1636" published="2004-10-26" name="CVE-2004-1636" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Heap-based buffer overflow in the WvTFTPServer::new_connection function in wvtftpserver.cc for WvTftp 0.9 allows remote attackers to execute arbitrary code via a long option string in a TFTP packet.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/12986" source="SECUNIA" patch="1" adv="1">12986</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/17869" source="XF" adv="1">wvtfpd-wvtftpservercc-bo(17869)</ref>
      <ref url="http://www.securityfocus.com/bid/11525" source="BID" adv="1">11525</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109885074513940&amp;w=2" source="BUGTRAQ" adv="1">20041026 wvtfpd remote root heap overflow</ref>
    </refs>
    <vuln_soft>
      <prod vendor="net_integration_technologies_inc." name="wvtftp">
        <vers num="0.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-1637" published="2004-10-26" name="CVE-2004-1637" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">The Hawking Technologies HAR11A modem/router allows remote attackers to obtain sensitive information by connecting to port 254, which displays a management interface and information on established connections.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/17877" source="XF" adv="1">har11a-gain-unauth-access(17877)</ref>
      <ref url="http://www.securityfocus.com/bid/11543" source="BID" adv="1">11543</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109882884617886&amp;w=2" source="BUGTRAQ" adv="1">20041026 Hawking Technologies HAR11A router considered insecure</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hawking_technology" name="har11a_dsl_router">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-1638" published="2004-10-16" name="CVE-2004-1638" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in MailCarrier 2.51 allows remote attackers to execute arbitrary code via a long (1) EHLO and possibly (2) HELO command.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/17861" source="XF" adv="1">mailcarrier-ehlo-helo-bo(17861)</ref>
      <ref url="http://www.securityfocus.com/bid/11535" source="BID" adv="1">11535</ref>
      <ref url="http://secunia.com/advisories/12999" source="SECUNIA" adv="1">12999</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109880961630050&amp;w=2" source="BUGTRAQ" adv="1">20041026 MailCarrier 2.51 SMTP server Buffer Overflow [PoC included]</ref>
    </refs>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1639" published="2004-10-26" name="CVE-2004-1639" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Mozilla Firefox before 0.10, Mozilla 5.0, and Gecko 20040913 allows remote attackers to cause a denial of service (application crash or memory consumption) via a large binary file with a .html extension.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/17839" source="XF" adv="1">mozilla-html-dos(17839)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109886388528179&amp;w=2" source="BUGTRAQ" adv="1">20041026 Rendering large binary file as HTML makes Mozilla Firefox stop responding</ref>
      <ref url="http://archives.neohapsis.com/archives/vulnwatch/2004-q4/0017.html" source="VULNWATCH" adv="1">20041026 Rendering large binary file as HTML makes Mozilla Firefox stop responding or crash</ref>
    </refs>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1640" published="2004-08-28" name="CVE-2004-1640" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in XOOPS 0.94 and 1.0 allow remote attackers to execute arbitrary web script and HTML via the (1) terme parameter to search.php or (2) letter parameter to letter.php.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/17154" source="XF" adv="1">xoops-dictionary-letter-xss(17154)</ref>
      <ref url="http://www.securityfocus.com/bid/11064" source="BID" adv="1">11064</ref>
      <ref url="http://secunia.com/advisories/12424" source="SECUNIA" adv="1">12424</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109394077209963&amp;w=2" source="BUGTRAQ" adv="1">20040828 Cross Site Scripting in XOOPS Version 2.x Dictionary module</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/17152" source="XF">xoops-dictionary-search-xss(17152)</ref>
      <ref url="http://www.osvdb.org/9394" source="OSVDB">9394</ref>
      <ref url="http://www.osvdb.org/9393" source="OSVDB">9393</ref>
      <ref url="http://cyruxnet.org/modulo_dic_xoops.htm" source="MISC">http://cyruxnet.org/modulo_dic_xoops.htm</ref>
    </refs>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1641" published="2004-08-29" name="CVE-2004-1641" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Heap-based buffer overflow in Titan FTP 3.21 and earlier allows remote attackers to cause a denial of service (crash) via a long FTP command such as (1) CWD, (2) STAT, or (3) LIST.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/11069" source="BID" patch="1" adv="1">11069</ref>
      <ref url="http://secunia.com/advisories/12419" source="SECUNIA" patch="1" adv="1">12419</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/17172" source="XF" adv="1">titan-long-command-bo(17172)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109396159332523&amp;w=2" source="BUGTRAQ" adv="1">20040829 [vulnwatch] Titan FTP Server Long Command Heap Overflow Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="south_river_technologies" name="titan_ftp_server">
        <vers num="2.10" />
        <vers num="2.2" />
        <vers num="3.01" />
        <vers num="3.10" />
        <vers num="3.21" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1642" published="2004-08-29" name="CVE-2004-1642" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">WFTPD Pro Server 3.21 allows remote authenticated users to cause a denial of service (crash) via a series of long MLIST commands.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/17169" source="XF" adv="1">wftpd-mlst-command-dos(17169)</ref>
      <ref url="http://www.securityfocus.com/bid/11067" source="BID" adv="1">11067</ref>
      <ref url="http://secunia.com/advisories/12420" source="SECUNIA" adv="1">12420</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109396193723317&amp;w=2" source="BUGTRAQ" adv="1">20040829 [vulnwatch] WFTPD Pro Server 3.21 MLST Command Denial of Service Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="texas_imperial_software" name="wftpd">
        <vers num="3.21" />
        <vers num="3.21_r1" />
        <vers num="3.21_r2" />
        <vers num="3.21_r3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1643" published="2004-08-29" name="CVE-2004-1643" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">WS_FTP 5.0.2 allows remote authenticated users to cause a denial of service (CPU consumption) via a CD command that contains an invalid path with a "../" sequence.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/12406" source="SECUNIA" patch="1" adv="1">12406</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/17155" source="XF" adv="1">wsftp-file-parsing-dos(17155)</ref>
      <ref url="http://www.securityfocus.com/bid/11065" source="BID" adv="1">11065</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109389890712888&amp;w=2" source="BUGTRAQ" adv="1">20040829 [vulnwatch] WS_FTP Server Denial of Service Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ipswitch" name="ws_ftp_server">
        <vers num="5.0.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1644" published="2004-08-30" name="CVE-2004-1644" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Xedus 1.0 allows remote attackers to cause a denial of service (refuse connections) by connecting multiple times from the same IP address.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/17165" source="XF" adv="1">xedus-mult-connection-dos(17165)</ref>
      <ref url="http://www.securityfocus.com/bid/11071" source="BID" adv="1">11071</ref>
      <ref url="http://www.gulftech.org/?node=research&amp;article_id=00047-08302004" source="MISC" adv="1">http://www.gulftech.org/?node=research&amp;article_id=00047-08302004</ref>
      <ref url="http://secunia.com/advisories/12418" source="SECUNIA" adv="1">12418</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109394018411394&amp;w=2" source="BUGTRAQ" adv="1">20040830 Multiple Vulnerabilities In Xedus Webserver</ref>
    </refs>
    <vuln_soft>
      <prod vendor="jerod_moemeka" name="xedus">
        <vers num="1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1645" published="2004-08-30" name="CVE-2004-1645" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in Xedus 1.0 allows remote attackers to execute arbitrary web script or HTML via the (1) username parameter to test.x, (2) username parameter to TestServer.x, or (3) param parameter to testgetrequest.x.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/17166" source="XF" adv="1">xedus-test-xss(17166)</ref>
      <ref url="http://www.securityfocus.com/bid/11071" source="BID" adv="1">11071</ref>
      <ref url="http://www.gulftech.org/?node=research&amp;article_id=00047-08302004" source="MISC">http://www.gulftech.org/?node=research&amp;article_id=00047-08302004</ref>
      <ref url="http://secunia.com/advisories/12418" source="SECUNIA" adv="1">12418</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109394018411394&amp;w=2" source="BUGTRAQ" adv="1">20040830 Multiple Vulnerabilities In Xedus Webserver</ref>
    </refs>
    <vuln_soft>
      <prod vendor="jerod_moemeka" name="xedus">
        <vers num="1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1646" published="2004-08-30" name="CVE-2004-1646" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in Xedus 1.0 allows remote attackers to read arbitrary files via a .. (dot dot) in the URL.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/17167" source="XF" adv="1">xedus-dotdot-directory-traversal(17167)</ref>
      <ref url="http://www.securityfocus.com/bid/11071" source="BID" adv="1">11071</ref>
      <ref url="http://www.gulftech.org/?node=research&amp;article_id=00047-08302004" source="MISC">http://www.gulftech.org/?node=research&amp;article_id=00047-08302004</ref>
      <ref url="http://secunia.com/advisories/12418" source="SECUNIA" adv="1">12418</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109394018411394&amp;w=2" source="BUGTRAQ" adv="1">20040830 Multiple Vulnerabilities In Xedus Webserver</ref>
    </refs>
    <vuln_soft>
      <prod vendor="jerod_moemeka" name="xedus">
        <vers num="1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-1647" published="2004-08-30" name="CVE-2004-1647" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in Password Protect allows remote attackers to execute arbitrary SQL statements and bypass authentication via (1) admin or Pass parameter to index_next.asp, (2) LoginId, OPass, or NPass to CPassChangePassword.asp, (3) users_edit.asp, or (4) users_add.asp.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/17188" source="XF">password-protect-sql-injection(17188)</ref>
      <ref url="http://www.securityfocus.com/bid/11073" source="BID" adv="1">11073</ref>
      <ref url="http://www.criolabs.net/advisories/passprotect.txt" source="MISC">http://www.criolabs.net/advisories/passprotect.txt</ref>
      <ref url="http://secunia.com/advisories/12407" source="SECUNIA" adv="1">12407</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109414967003192&amp;w=2" source="BUGTRAQ" adv="1">20040830 Password Protect XSS and SQL-Injection vulnerabilities.</ref>
    </refs>
    <vuln_soft>
      <prod vendor="web_animations" name="password_protect">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1648" published="2004-08-31" name="CVE-2004-1648" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in (1) index.asp, (2) ChangePassword.asp, (3) users_list.asp, (4) and users_add.asp in Password Protect allows remote attackers to inject arbitrary web script or HTML via the ShowMsg parameter.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/17187" source="XF" adv="1">password-protect-showmsg-xss(17187)</ref>
      <ref url="http://www.securityfocus.com/bid/11073" source="BID" adv="1">11073</ref>
      <ref url="http://www.criolabs.net/advisories/passprotect.txt" source="MISC" adv="1">http://www.criolabs.net/advisories/passprotect.txt</ref>
      <ref url="http://secunia.com/advisories/12407" source="SECUNIA" adv="1">12407</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109414967003192&amp;w=2" source="BUGTRAQ" adv="1">20040830 Password Protect XSS and SQL-Injection vulnerabilities.</ref>
    </refs>
    <vuln_soft>
      <prod vendor="web_animations" name="password_protect">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-1649" published="2004-08-31" name="CVE-2004-1649" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Buffer overflow in Microsoft Msinfo32.exe might allow local users to execute arbitrary code via a long filename in the msinfo_file command line parameter.  NOTE: this issue might not cross security boundaries, so it may be REJECTED in the future.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/17153" source="XF" adv="1">msinfo-msinfofile-bo(17153)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=full-disclosure&amp;m=109391133831787&amp;w=2" source="FULLDISC" adv="1">20040830 MSInfo  Buffer Overflow</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109413415205017&amp;w=2" source="BUGTRAQ" adv="1">20040831 MSInfo  Buffer Overflow</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2004-August/025902.html" source="FULLDISC" adv="1">20040830 MSInfo  Buffer Overflow</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_2000">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-1650" published="2004-08-31" name="CVE-2004-1650" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">D-Link DCS-900 Internet Camera listens on UDP port 62976 for an IP address, which allows remote attackers to change the IP address of the camera via a UDP broadcast packet.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/12425" source="SECUNIA" patch="1">12425</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/17171" source="XF" adv="1">dlink-dcs900-ip-modification(17171)</ref>
      <ref url="http://www.securityfocus.com/bid/11072" source="BID" adv="1">11072</ref>
      <ref url="http://securitytracker.com/id?1011100" source="SECTRACK">1011100</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109396893820049&amp;w=2" source="BUGTRAQ">20040831 D-Link DCS-900 IP camera remote exploit that change the IP</ref>
    </refs>
    <vuln_soft>
      <prod vendor="d-link" name="dcs-900_internet_camera">
        <vers num="2.10" />
        <vers num="2.20" />
        <vers num="2.28" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1651" published="2004-08-31" name="CVE-2004-1651" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in the registration page in phpScheduleIt 1.0.0 RC1 allow remote attackers to inject arbitrary web script or HTML via the (1) Name or (2) Lastname fields during new user registration, or (3) the Schedule Name field.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/11080" source="BID" patch="1" adv="1">11080</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109399590602709&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20040831 Multiple Vulnerabilities in phpScheduleIt</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/17193" source="XF">phpscheduleit-xss(17193)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/17194" source="XF">phpscheduleit-script-injection(17194)</ref>
      <ref url="http://www.osvdb.org/9451" source="OSVDB">9451</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2004-09/0216.html" source="BUGTRAQ">20040917 Re: Multiple Vulnerabilities in phpScheduleIt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="brickhost" name="phpscheduleit">
        <vers num="1.0_rc1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-1652" published="2004-08-31" name="CVE-2004-1652" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">phpScheduleIt 1.0.0 RC1 does not clear administrative privileges if the administrator logs in as a normal user, which allows users with physical access to gain administrative privileges.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/17195" source="XF" patch="1" adv="1">phpscheduleit-gain-privileges(17195)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109399590602709&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20040831 Multiple Vulnerabilities in phpScheduleIt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="brickhost" name="phpscheduleit">
        <vers num="1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1653" published="2004-08-31" name="CVE-2004-1653" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)" CVSS_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_base_score="6.4">
    <desc>
      <descript source="cve">The default configuration for OpenSSH enables AllowTcpForwarding, which could allow remote authenticated users to perform a port bounce, when configured with an anonymous access program such as AnonCVS.</descript>
    </desc>
    <loss_types>
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <config />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/17213" source="XF" adv="1">openssh-port-bounce(17213)</ref>
      <ref url="http://securitytracker.com/id?1011143" source="SECTRACK">1011143</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109413637313484&amp;w=2" source="BUGTRAQ">20040831 SSHD / AnonCVS Nastyness</ref>
      <ref url="http://www.osvdb.org/9562" source="OSVDB">9562</ref>
    </refs>
    <vuln_soft>
      <prod vendor="openbsd" name="openssh">
        <vers prev="1" num="3.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-1654" published="2004-09-01" name="CVE-2004-1654" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in the calendar module in phpWebsite 0.9.3-4 and earlier allows remote attackers to execute arbitrary SQL commands via cal_template.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/17199" source="XF" patch="1" adv="1">phpwebsite-calendar-module-sql-injection(17199)</ref>
      <ref url="http://www.securityfocus.com/bid/11088" source="BID" patch="1" adv="1">11088</ref>
      <ref url="http://www.phpwebsite.appstate.edu/index.php?module=announce&amp;ANN_user_op=view&amp;ANN_id=822" source="CONFIRM" patch="1">http://www.phpwebsite.appstate.edu/index.php?module=announce&amp;ANN_user_op=view&amp;ANN_id=822</ref>
      <ref url="http://www.gulftech.org/?node=research&amp;article_id=00048-08312004" source="MISC" patch="1" adv="1">http://www.gulftech.org/?node=research&amp;article_id=00048-08312004</ref>
      <ref url="http://secunia.com/advisories/12438" source="SECUNIA" patch="1" adv="1">12438</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109413493005513&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20040901 Multiple Vulnerabilities In phpWebsite</ref>
    </refs>
    <vuln_soft>
      <prod vendor="phpwebsite" name="phpwebsite">
        <vers num="0.7.3" />
        <vers num="0.8.2" />
        <vers num="0.8.3" />
        <vers num="0.9.3" />
        <vers num="0.9.3.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1655" published="2004-09-01" name="CVE-2004-1655" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in phpWebsite 0.9.3-4 and earlier allows remote attackers to inject arbitrary web script or HTML via the (1) CM_pid parameter in the comments module or (2) the subject or message fields in the notes module.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/17202" source="XF" patch="1" adv="1">phpwebsite-comments-module-xss(17202)</ref>
      <ref url="http://www.securityfocus.com/bid/11088" source="BID" patch="1" adv="1">11088</ref>
      <ref url="http://www.phpwebsite.appstate.edu/index.php?module=announce&amp;ANN_user_op=view&amp;ANN_id=822" source="CONFIRM" patch="1" adv="1">http://www.phpwebsite.appstate.edu/index.php?module=announce&amp;ANN_user_op=view&amp;ANN_id=822</ref>
      <ref url="http://www.gulftech.org/?node=research&amp;article_id=00048-08312004" source="MISC" patch="1" adv="1">http://www.gulftech.org/?node=research&amp;article_id=00048-08312004</ref>
      <ref url="http://secunia.com/advisories/12438" source="SECUNIA" patch="1" adv="1">12438</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109413493005513&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20040901 Multiple Vulnerabilities In phpWebsite</ref>
      <ref url="http://securitytracker.com/id?1011120" source="SECTRACK">1011120</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/17203" source="XF">phpwebsite-notes-script-injection(17203)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="phpwebsite" name="phpwebsite">
        <vers num="0.7.3" />
        <vers num="0.8.2" />
        <vers num="0.8.3" />
        <vers num="0.9.3" />
        <vers num="0.9.3.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1656" published="2004-09-01" name="CVE-2004-1656" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">CRLF injection vulnerability in Comersus Shopping Cart 5.0991 allows remote attackers to perform HTTP Response Splitting attacks to modify expected HTML content from the server via the redirecturl parameter.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/17201" source="XF" adv="1">comersus-cart-response-splitting(17201)</ref>
      <ref url="http://www.securityfocus.com/bid/11083" source="BID" adv="1">11083</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109405777905519&amp;w=2" source="BUGTRAQ" adv="1">20040901 ADVISORY: http response splitting hole in Comersus shopping cart</ref>
    </refs>
    <vuln_soft>
      <prod vendor="comersus_open_technologies" name="comersus_cart">
        <vers num="5.0.991" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1657" published="2004-09-01" name="CVE-2004-1657" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in the Activity and Events Viewer for Newtelligence DasBlog allows remote attackers to inject arbitrary web script or HTML via the (1) User Agent or (2) Referrer HTTP headers.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/17174" source="XF" patch="1" adv="1">dasblog-useragent-referer-xss(17174)</ref>
      <ref url="http://www.securityfocus.com/bid/11086" source="BID" patch="1" adv="1">11086</ref>
      <ref url="http://secunia.com/advisories/12416" source="SECUNIA" patch="1" adv="1">12416</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109443321830050&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20040901 Cross-Site Scripting Vulnerability in Newtelligence DasBlog</ref>
      <ref url="http://staff.newtelligence.net/clemensv/PermaLink.aspx?guid=69bce168-cb09-4f09-8d53-f0b97f11b198" source="CONFIRM" adv="1">http://staff.newtelligence.net/clemensv/PermaLink.aspx?guid=69bce168-cb09-4f09-8d53-f0b97f11b198</ref>
    </refs>
    <vuln_soft>
      <prod vendor="newtelligence" name="dasblog">
        <vers num="1.3" />
        <vers num="1.4" />
        <vers num="1.5" />
        <vers num="1.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1658" published="2004-09-02" name="CVE-2004-1658" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Kerio Personal Firewall 4.0 (KPF4) allows local users with administrative privileges to bypass the Application Security feature and execute arbitrary processes by directly writing to \device\physicalmemory to restore the running kernel's SDT ServiceTable.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/17270" source="XF" adv="1">kerio-pf-protection-dos(17270)</ref>
      <ref url="http://www.securityfocus.com/bid/11096" source="BID" adv="1">11096</ref>
      <ref url="http://www.security.org.sg/vuln/kerio4016.html" source="MISC" adv="1">http://www.security.org.sg/vuln/kerio4016.html</ref>
      <ref url="http://secunia.com/advisories/12468/" source="SECUNIA" adv="1">12468</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109420310631039&amp;w=2" source="BUGTRAQ" adv="1">20040902 Kerio Personal Firewall's Application Launch Protection Can Be Disabled by Direct Service Table Restoration</ref>
    </refs>
    <vuln_soft>
      <prod vendor="kerio" name="personal_firewall">
        <vers num="4.0.10" />
        <vers num="4.0.16" />
        <vers num="4.0.6" />
        <vers num="4.0.7" />
        <vers num="4.0.8" />
        <vers num="4.0.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1659" published="2004-09-02" name="CVE-2004-1659" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in index.php in CuteNews 1.3.6 and earlier allows remote attackers with Administrator, Editor, Journalist or Commenter privileges to inject arbitrary web script or HTML via the mod parameter.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/17214" source="XF" adv="1">cutenews-mod-xss(17214)</ref>
      <ref url="http://www.securityfocus.com/bid/11097" source="BID" adv="1">11097</ref>
      <ref url="http://secunia.com/advisories/12432" source="SECUNIA" adv="1">12432</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109415338521881&amp;w=2" source="BUGTRAQ" adv="1">20040902 [hackgen-2004-#001] - Non-critacal Cross-Site Scripting bug in CuteNews</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cutephp" name="cutenews">
        <vers num="0.88" />
        <vers num="1.3" />
        <vers num="1.3.1" />
        <vers num="1.3.2" />
        <vers num="1.3.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-1660" published="2004-08-30" name="CVE-2004-1660" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">PHP remote file inclusion vulnerability in CuteNews 1.3.6 and earlier allows remote attackers to execute arbitrary PHP code via the cutepath parameter to (1) show_archives.php or (2) show_news.php.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/17288" source="XF" adv="1">cutenews-file-include(17288)</ref>
      <ref url="http://www.7a69ezine.org/node/view/130" source="MISC" adv="1">http://www.7a69ezine.org/node/view/130</ref>
      <ref url="http://secunia.com/advisories/12432" source="SECUNIA" adv="1">12432</ref>
      <ref url="http://seclists.org/lists/bugtraq/2004/Sep/0014.html" source="BUGTRAQ" adv="1">20040830 RE: CuteNews News.txt writable to world</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cutephp" name="cutenews">
        <vers prev="1" num="1.3.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-1661" published="2004-09-02" name="CVE-2004-1661" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">MailWorks Professional allows remote attackers to bypass authentication and gain privileges via a cookie that contains "auth=1" and "uId=1."</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/17217" source="XF" patch="1" adv="1">mailworks-cookie-admin-access(17217)</ref>
      <ref url="http://www.securityfocus.com/bid/11095" source="BID" adv="1">11095</ref>
      <ref url="http://secunia.com/advisories/12458" source="SECUNIA" adv="1">12458</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109416709710447&amp;w=2" source="BUGTRAQ" adv="1">20040902 MailWorks Professional - Authentication bypass</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sitecubed" name="mailworks_professional">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1662" published="2004-08-25" name="CVE-2004-1662" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">YaBB SE 1.5.1 allows remote attackers to obtain sensitive information via a direct HTTP request to Admin.php, which reveals the full path in a PHP error message.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/17267" source="XF" adv="1">yabb-admin-path-disclosure(17267)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109441750900432&amp;w=2" source="BUGTRAQ" adv="1">20040904 FUll Path Disclosure in YABBSE</ref>
      <ref url="http://echo.or.id/adv/adv05-y3dips-2004.txt" source="MISC" adv="1">http://echo.or.id/adv/adv05-y3dips-2004.txt</ref>
    </refs>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1663" published="2004-09-04" name="CVE-2004-1663" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Engenio/LSI Logic storage controllers, as used in products such as Storagetek D280, and IBM DS4100 (formerly FastT 100) and Brocade SilkWorm Switches, allow remote attackers to cause a denial of service (freeze and possible data corruption) via crafted TCP packets.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/17290" source="XF" patch="1" adv="1">engenio-controller-tcp-dos(17290)</ref>
      <ref url="http://www.securityfocus.com/bid/11108" source="BID" adv="1">11108</ref>
      <ref url="http://secunia.com/advisories/12464" source="SECUNIA" adv="1">12464</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109435831811484&amp;w=2" source="BUGTRAQ" adv="1">20040904 Engenio/LSI Logic controllers denial of service/data corruption</ref>
    </refs>
    <vuln_soft>
      <prod vendor="brocade" name="silkworm">
        <vers num="3200" />
        <vers num="3250" />
        <vers num="3800" />
        <vers num="3850" />
        <vers num="3900" />
      </prod>
      <prod vendor="brocade" name="silkworm_fiber_channel_switch">
        <vers num="2010" />
        <vers num="2040" />
        <vers num="2050" />
      </prod>
      <prod vendor="engenio" name="storage_controller">
        <vers num="2822" />
        <vers num="2882" />
        <vers num="4884" />
        <vers num="5884" />
      </prod>
      <prod vendor="ibm" name="ds4100">
        <vers num="" />
      </prod>
      <prod vendor="storagetek" name="d280">
        <vers num="" />
      </prod>
      <prod vendor="brocade" name="fabric_os">
        <vers num="2.1.2" />
        <vers num="2.2" />
        <vers num="3.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1664" published="2004-09-05" name="CVE-2004-1664" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Call of Duty 1.4 and earlier allows remote attackers to cause a denial of service (game end) via a large (1) query or (2) reply packet, which is not properly handled by the buffer overflow protection mechanism. NOTE: this issue might overlap CVE-2005-0430.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/17286" source="XF" patch="1" adv="1">callofduty-dos(17286)</ref>
      <ref url="http://www.securityfocus.com/bid/11119" source="BID" patch="1" adv="1">11119</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109449953200587&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20040905 Broadcast shutdown in Call of Duty 1.4</ref>
    </refs>
    <vuln_soft>
      <prod vendor="activision" name="call_of_duty">
        <vers num="1.4" />
      </prod>
      <prod vendor="activision" name="call_of_duty_united_offensive">
        <vers num="1.41" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1665" published="2004-09-05" name="CVE-2004-1665" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in index.php in PsNews 1.1 allows remote attackers to inject arbitrary web script or HTML via the no parameter.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/17302" source="XF" adv="1">psnews-xss(17302)</ref>
      <ref url="http://www.securityfocus.com/bid/11124" source="BID" adv="1">11124</ref>
      <ref url="http://securitytracker.com/id?1011191" source="SECTRACK">1011191</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109458516524494&amp;w=2" source="BUGTRAQ" adv="1">20040905 Bug XSS in PsNews 1.1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="psnews" name="psnews">
        <vers num="1.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-1666" published="2004-12-31" name="CVE-2004-1666" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in the MSN module in Trillian 0.74i allows remote MSN servers to execute arbitrary code via a long string that ends in a newline character.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/17292" source="XF" adv="1">trillian-msn-bo(17292)</ref>
      <ref url="http://www.securityfocus.com/bid/11142" source="BID" adv="1">11142</ref>
      <ref url="http://unsecure.altervista.org/security/trillian.htm" source="MISC" adv="1">http://unsecure.altervista.org/security/trillian.htm</ref>
      <ref url="http://secunia.com/advisories/12487" source="SECUNIA" adv="1">12487</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109466618609375&amp;w=2" source="BUGTRAQ" adv="1">20040908 Cerulean Studios Trillian 0.74i Buffer Overflow in MSN module exploit</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cerulean_studios" name="trillian">
        <vers num="0.74i" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1667" published="2004-09-09" name="CVE-2004-1667" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Off-by-one error in Halo Combat Evolved 1.04 and earlier allows remote attackers to cause a denial of service (server crash) via a long client response.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/17310" source="XF" patch="1" adv="1">halo-response-offbyone-bo(17310)</ref>
      <ref url="http://www.securityfocus.com/bid/11147" source="BID" patch="1" adv="1">11147</ref>
      <ref url="http://www.bungie.net/News/Story.aspx?link=hpc105" source="MISC" patch="1" adv="1">http://www.bungie.net/News/Story.aspx?link=hpc105</ref>
      <ref url="http://secunia.com/advisories/12504" source="SECUNIA" patch="1" adv="1">12504</ref>
      <ref url="http://aluigi.altervista.org/adv/haloboom-adv.txt" source="MISC" adv="1">http://aluigi.altervista.org/adv/haloboom-adv.txt</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109479695022024&amp;w=2" source="BUGTRAQ">20040909 Off-by-one bug in Halo 1.04</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gearbox_software" name="halo_combat_evolved">
        <vers num="1.2" />
        <vers num="1.31" />
        <vers num="1.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-1668" published="2004-09-10" name="CVE-2004-1668" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple SQL injection vulnerabilities in index.php in Subjects 2.0 Postnuke module allow remote attackers to execute arbitrary SQL commands via the (1) pageid, (2) subid, or (3) catid parameters.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/12497" source="SECUNIA" patch="1" adv="1">12497</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/17311" source="XF" adv="1">subjects-indexphp-sql-injection(17311)</ref>
      <ref url="http://www.securityfocus.com/bid/11148" source="BID" adv="1">11148</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109483089621955&amp;w=2" source="BUGTRAQ" adv="1">20040910 SQL-Injection in Subjects 2.0 for Postnuke</ref>
    </refs>
    <vuln_soft>
      <prod vendor="easyweb" name="factory_subjects_module">
        <vers num="2.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1669" published="2004-09-10" name="CVE-2004-1669" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in MERAK Mail Server 7.4.5 with Icewarp Web Mail 5.2.7 and possibly other versions allows remote attackers to execute arbitrary web script or HTML via the (1) User name parameter to accountsettings.html or (2) Search string parameter to search.html.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/17313" source="XF" patch="1" adv="1">merak-icewarp-xss(17313)</ref>
      <ref url="http://www.securityfocus.com/bid/11371" source="BID" patch="1" adv="1">11371</ref>
      <ref url="http://secunia.com/advisories/12789" source="SECUNIA" adv="1">12789</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109483971420067&amp;w=2" source="BUGTRAQ" adv="1">20040910 Multiple vulnerabilities in Icewarp Web Mail 5.2.7</ref>
    </refs>
    <vuln_soft>
      <prod vendor="icewarp" name="web_mail">
        <vers num="3.3.2" />
        <vers num="5.2.7" />
        <vers num="5.2.8" />
      </prod>
      <prod vendor="merak" name="mail_server">
        <vers num="7.4.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-1670" published="2004-09-10" name="CVE-2004-1670" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple directory traversal vulnerabilities Merak Mail Server 7.4.5 with Icewarp Web Mail 5.2.7, and possibly other versions, allow remote attackers to (1) create arbitrary directories via a .. (dot dot) in the user parameter to viewaction.html or (2) rename arbitrary files via a ....// (doubled dot dot) in the folderold or folder parameters to folders.html.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/17314" source="XF" patch="1" adv="1">merak-icewarp-create-directory(17314)</ref>
      <ref url="http://www.securityfocus.com/bid/11371" source="BID" patch="1" adv="1">11371</ref>
      <ref url="http://secunia.com/advisories/12789" source="SECUNIA" adv="1">12789</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109483971420067&amp;w=2" source="BUGTRAQ" adv="1">20040910 Multiple vulnerabilities in Icewarp Web Mail 5.2.7</ref>
    </refs>
    <vuln_soft>
      <prod vendor="icewarp" name="web_mail">
        <vers num="3.3.2" />
        <vers num="5.2.7" />
        <vers num="5.2.8" />
      </prod>
      <prod vendor="merak" name="mail_server">
        <vers num="7.4.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1671" published="2004-10-12" name="CVE-2004-1671" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Merak Mail Server 7.4.5 with Icewarp Web Mail 5.2.7 and possibly other versions allows remote attackers to gain sensitive information via a direct request to (1) accountsettings_add.html or (2) topmenu.html.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/11371" source="BID" patch="1" adv="1">11371</ref>
      <ref url="http://secunia.com/advisories/12789" source="SECUNIA" patch="1" adv="1">12789</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109483971420067&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20040910 Multiple vulnerabilities in Icewarp Web Mail 5.2.7</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/17315" source="XF" adv="1">merak-icewarp-path-disclosure(17315)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="icewarp" name="web_mail">
        <vers num="3.3.2" />
        <vers num="5.2.7" />
        <vers num="5.2.8" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-1672" published="2004-10-12" name="CVE-2004-1672" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">attachment.html in Merak Mail Server 7.4.5 with Icewarp Web Mail 5.2.7 and possibly other versions allows remote attackers to view other users' attachments by specifying the username and message ID in an HTTP request.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/17316" source="XF" patch="1" adv="1">merak-icewarp-view-attachment(17316)</ref>
      <ref url="http://www.securityfocus.com/bid/11371" source="BID" patch="1" adv="1">11371</ref>
      <ref url="http://secunia.com/advisories/12789" source="SECUNIA" patch="1" adv="1">12789</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109483971420067&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20040910 Multiple vulnerabilities in Icewarp Web Mail 5.2.7</ref>
    </refs>
    <vuln_soft>
      <prod vendor="icewarp" name="web_mail">
        <vers num="3.3.2" />
        <vers num="5.2.7" />
        <vers num="5.2.8" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-1673" published="2004-10-12" name="CVE-2004-1673" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">accountsettings_add.html in Merak Mail Server 7.4.5 with Icewarp Web Mail 5.2.7 and possibly other versions allow remote attackers to create text files with arbitrary content via the accountid parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/11371" source="BID" patch="1" adv="1">11371</ref>
      <ref url="http://secunia.com/advisories/12789" source="SECUNIA" patch="1" adv="1">12789</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109483971420067&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20040910 Multiple vulnerabilities in Icewarp Web Mail 5.2.7</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/17317" source="XF" adv="1">merak-icewarp-create-file(17317)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="icewarp" name="web_mail">
        <vers num="3.3.2" />
        <vers num="5.2.7" />
        <vers num="5.2.8" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-1674" published="2004-10-12" name="CVE-2004-1674" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">viewaction.html in Merak Mail Server 7.4.5 with Icewarp Web Mail 5.2.7 and possibly other versions allows remote attackers to (1) delete arbitrary files via the originalfolder parameter or (2) move arbitrary files via the messageid parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/11371" source="BID" patch="1" adv="1">11371</ref>
      <ref url="http://secunia.com/advisories/12789" source="SECUNIA" patch="1" adv="1">12789</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109483971420067&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20040910 Multiple vulnerabilities in Icewarp Web Mail 5.2.7</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/17976" source="XF" adv="1">merak-icewarp-file-deletion(17976)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="icewarp" name="web_mail">
        <vers num="3.3.2" />
        <vers num="5.2.7" />
        <vers num="5.2.8" />
      </prod>
      <prod vendor="merak" name="mail_server">
        <vers num="7.4.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1675" published="2004-09-11" name="CVE-2004-1675" modified="2010-04-28" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Serv-U FTP server 4.x and 5.x allows remote attackers to cause a denial of service (application crash) via a STORE UNIQUE (STOU) command with an MS-DOS device name argument such as (1) COM1, (2) LPT1, (3) PRN, or (4) AUX.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/11155" source="BID" patch="1" adv="1">11155</ref>
      <ref url="http://secunia.com/advisories/12507/" source="SECUNIA" patch="1" adv="1">12507</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/17329" source="XF" adv="1">servu-stou-dos(17329)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109495074211638&amp;w=2" source="BUGTRAQ" adv="1">20040911 Serv-U up to 5.2 Denial of Service</ref>
    </refs>
    <vuln_soft>
      <prod vendor="serv-u" name="serv-u">
        <vers num="4.0.0.4" />
        <vers num="4.1.0.0" />
        <vers num="4.1.0.3" />
        <vers num="5.0.0.0" />
        <vers num="5.0.0.11" />
        <vers num="5.0.0.4" />
        <vers num="5.0.0.9" />
        <vers num="5.1.0.0" />
        <vers num="5.2.0.0" />
        <vers num="5.2.0.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-1676" published="2004-09-12" name="CVE-2004-1676" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Heap-based buffer overflow in the image sending feature in Gadu-Gadu 6.0 build 149 allows remote attackers to execute arbitrary code via a crafted GG_MSG_IMAGE_REPLY message.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/17324" source="XF" adv="1">gadu-gadu-image-bo(17324)</ref>
      <ref url="http://www.securityfocus.com/bid/11158" source="BID" adv="1">11158</ref>
      <ref url="http://secunia.com/advisories/12510" source="SECUNIA" adv="1">12510</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109508834910733&amp;w=2" source="BUGTRAQ" adv="1">20040912 Gadu-Gadu (all versions with image-send feature) Heap Overflow</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gadu-gadu" name="gadu-gadu_instant_messenger">
        <vers num="6.0" />
        <vers num="6.0_build149" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1677" published="2004-09-12" name="CVE-2004-1677" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">pdesk.cgi in PerlDesk allows remote attackers to gain sensitive information via an invalid lang parameter, which includes pathname information in an error message.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/12512" source="SECUNIA" patch="1" adv="1">12512</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/17343" source="XF">perldesk-lang-file-include(17343)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109509026406554&amp;w=2" source="BUGTRAQ" adv="1">20040912 Posible Inclusion File in Perl Desk</ref>
    </refs>
    <vuln_soft>
      <prod vendor="logicnow" name="perldesk">
        <vers prev="1" num="1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1678" published="2004-09-13" name="CVE-2004-1678" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in pdesk.cgi in PerlDesk allows remote attackers to read portions of arbitrary files and possibly execute arbitrary Perl modules via ".." sequences terminated by a %00 (null) character in the lang parameter, which can leak portions of the requested files if a compilation error message occurs.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/19712" source="XF" patch="1" adv="1">perldesk-directory-traversal(19712)</ref>
      <ref url="http://secunia.com/advisories/12512" source="SECUNIA" patch="1" adv="1">12512</ref>
      <ref url="http://www.securityfocus.com/bid/11160" source="BID" adv="1">11160</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109509026406554&amp;w=2" source="BUGTRAQ" adv="1">20040912 Posible Inclusion File in Perl Desk</ref>
    </refs>
    <vuln_soft>
      <prod vendor="logicnow" name="perldesk">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1679" published="2004-08-04" name="CVE-2004-1679" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in TwinFTP 1.0.3 R2 allows remote attackers create arbitrary files via a .../ (triple dot) in the (1) CWD, (2) STOR, or (3) RETR commands.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/17323" source="XF" patch="1" adv="1">twinftp-argument-directory-traversal(17323)</ref>
      <ref url="http://www.securityfocus.com/bid/11159" source="BID" patch="1" adv="1">11159</ref>
      <ref url="http://www.security.org.sg/vuln/twinftp103r2.html" source="MISC" adv="1">http://www.security.org.sg/vuln/twinftp103r2.html</ref>
      <ref url="http://secunia.com/advisories/12511/" source="SECUNIA" adv="1">12511</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109509243831121&amp;w=2" source="BUGTRAQ" adv="1">20040913 Directory Traversal Vulnerability in TwinFTP Server allows overwriting of files outside FTP directory</ref>
    </refs>
    <vuln_soft>
      <prod vendor="jigunet" name="twinftp_enterprise">
        <vers num="1.0.3_r2" />
      </prod>
      <prod vendor="jigunet" name="twinftp_standard">
        <vers num="1.0.3_r2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1680" published="2004-09-13" name="CVE-2004-1680" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">application.cgi in the Pingtel Xpressa handset running firmware 2.1.11.24 allows remote authenticated users to cause a denial of service (VxWorks OS crash) via a long HTTP GET request, possibly triggering a buffer overflow.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/17346" source="XF" patch="1" adv="1">xpressa-applicationcgi-dos(17346)</ref>
      <ref url="http://www.securityfocus.com/bid/11161" source="BID" patch="1" adv="1">11161</ref>
      <ref url="http://www.atstake.com/research/advisories/2004/a091304-2.txt" source="ATSTAKE" patch="1" adv="1">A091304-2</ref>
      <ref url="http://secunia.com/advisories/12523" source="SECUNIA" patch="1" adv="1">12523</ref>
    </refs>
    <vuln_soft>
      <prod vendor="pingtel" name="xpressa">
        <vers num="1.2.5" />
        <vers num="1.2.7.4" />
        <vers num="1.2.8" />
        <vers num="2.0" />
        <vers num="2.0.1" />
        <vers num="2.1.11.24" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-1681" published="2004-08-26" name="CVE-2004-1681" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Multiple buffer overflows in (1) phrelay-cfg, (2) phlocale, (3) pkg-installer, or (4) input-cfg in QNX Photon microGUI for QNX RTP 6.1 allow local users to gain privileges via a long -s (server) command line parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input bound="1" />
      <exception />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/17339" source="XF" adv="1">qnx-rtp-photon-bo(17339)</ref>
      <ref url="http://www.securityfocus.com/bid/11164" source="BID" adv="1">11164</ref>
      <ref url="http://www.rfdslabs.com.br/qnx-advs-03-2004.txt" source="MISC">http://www.rfdslabs.com.br/qnx-advs-03-2004.txt</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109510393407597&amp;w=2" source="BUGTRAQ" adv="1">20040913 [RLSA_02-2004] QNX Photon multiple buffer overflows</ref>
    </refs>
    <vuln_soft>
      <prod vendor="qnx" name="photon_microgui">
        <vers num="" />
      </prod>
      <prod vendor="qnx" name="rtp">
        <vers num="6.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-1682" published="2004-08-15" name="CVE-2004-1682" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Format string vulnerability in QNX 6.1 FTP client allows remote authenticated users to gain group bin privileges via format string specifiers in the QUOTE command.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input />
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/17347" source="XF" adv="1">qnx-ftp-quote-format-string(17347)</ref>
      <ref url="http://www.rfdslabs.com.br/qnx-advs-04-2004.txt" source="MISC">http://www.rfdslabs.com.br/qnx-advs-04-2004.txt</ref>
      <ref url="http://secunia.com/advisories/12533" source="SECUNIA" adv="1">12533</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109511327005476&amp;w=2" source="BUGTRAQ" adv="1">20040913 [RLSA_03-2004] QNX ftp client format string bug</ref>
    </refs>
    <vuln_soft>
      <prod vendor="qnx" name="rtp">
        <vers num="6.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2004-1683" published="2004-09-13" name="CVE-2004-1683" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:H/Au:N/C:P/I:P/A:P)" CVSS_score="3.7" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="1.9" CVSS_base_score="3.7">
    <desc>
      <descript source="cve">A race condition in crrtrap for QNX RTP 6.1 allows local users to gain privileges by modifying the PATH environment variable to reference a malicious io-graphics program before is executed by crrtrap.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <race />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/17345" source="XF" adv="1">qnx-rtp-crttrap-race-condition(17345)</ref>
      <ref url="http://www.securityfocus.com/bid/11165" source="BID" adv="1">11165</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109511737504357&amp;w=2" source="BUGTRAQ" adv="1">20040913 [RLSA_04-2004] QNX crrtrap possible race condition vulnerability</ref>
    </refs>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1684" published="2004-09-13" name="CVE-2004-1684" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Zyxel P681 running ZyNOS Vt020225a contains portions of memory in an ARP request, which allows remote attackers to obtain sensitive information by sniffing the network.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/17372" source="XF" adv="1">prestige-information-disclosure(17372)</ref>
      <ref url="http://www.securityfocus.com/bid/11167" source="BID" adv="1">11167</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109510732611448&amp;w=2" source="BUGTRAQ" adv="1">20040913 Zyxel Prestige 681 SDSL router information leak</ref>
      <ref url="http://www.osvdb.org/9962" source="OSVDB">9962</ref>
    </refs>
    <vuln_soft>
      <prod vendor="zyxel" name="prestige">
        <vers num="681" />
      </prod>
      <prod vendor="zyxel" name="zynos">
        <vers num="vt020225a" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-1685" published="2004-09-15" name="CVE-2004-1685" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SMC routers SMC7004VWBR running firmware 1.00.014 and SMC7008ABR EU running firmware 1.42.003 allow remote attackers to bypass authentication by connecting to it from the same IP address as the administrator who is logged in, then accessing the setup_status.htm or status.HTM pages.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/12601" source="SECUNIA" patch="1" adv="1">12601</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109526094614160&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20040915 SMC7004VWBR / SMC7008ABR "spoofing" vulnerability.</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/17443" source="XF" adv="1">smc-router-security-bypass(17443)</ref>
      <ref url="http://www.securityfocus.com/bid/11197" source="BID" adv="1">11197</ref>
      <ref url="http://www.osvdb.org/10088" source="OSVDB">10088</ref>
    </refs>
    <vuln_soft>
      <prod vendor="smc_networks" name="smc7004vwbr">
        <vers num="1.21a" />
        <vers num="1.22" />
        <vers num="1.23" />
      </prod>
      <prod vendor="smc_networks" name="smc7008abr">
        <vers num="1.32" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1686" published="2004-09-15" name="CVE-2004-1686" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Internet Explorer 6.0 in Windows XP SP2 allows remote attackers to bypass the Information Bar prompt for ActiveX and Javascript via an XHTML page that contains an Internet Explorer formatted comment between the DOCTYPE tag and the HTML tag, as demonstrated using the DesignScience MathPlayer ActiveX plugin.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/20617" source="XF">ie-information-bar-bypass(20617)</ref>
      <ref url="http://www.securityfocus.com/bid/11200" source="BID" adv="1">11200</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109539520310153&amp;w=2" source="BUGTRAQ" adv="1">20040915 IE6 + XP SP2 Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="ie">
        <vers num="6.0" edition="sp2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1687" published="2004-09-16" name="CVE-2004-1687" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">CRLF injection vulnerability in down.asp for Snitz Forums 2000 3.4.04 allows remote attackers to perform HTTP Response Splitting attacks to modify expected HTML content from the server via the location parameter.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/17421" source="XF" patch="1" adv="1">snitz-response-splitting(17421)</ref>
      <ref url="http://www.securityfocus.com/bid/11201" source="BID" patch="1" adv="1">11201</ref>
      <ref url="http://secunia.com/advisories/12590" source="SECUNIA" patch="1" adv="1">12590</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109537195413691&amp;w=2" source="BUGTRAQ" adv="1">20040916 ADVISORY: security hole (http response splitting) in snitz forums</ref>
      <ref url="http://forum.snitz.com/forum/topic.asp?ARCHIVE=true&amp;TOPIC_ID=54791" source="CONFIRM" adv="1">http://forum.snitz.com/forum/topic.asp?ARCHIVE=true&amp;TOPIC_ID=54791</ref>
    </refs>
    <vuln_soft>
      <prod vendor="snitz_communications" name="snitz_forums_2000">
        <vers num="3.0" />
        <vers num="3.1" edition="sr4" />
        <vers num="3.3" />
        <vers num="3.3.01" />
        <vers num="3.3.02" />
        <vers num="3.3.03" />
        <vers num="3.4.02" />
        <vers num="3.4.03" />
        <vers num="3.4.04" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1688" published="2004-09-16" name="CVE-2004-1688" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Pigeon Server 3.02.0143 and earlier allows remote attackers to cause a denial of service (infinite loop and CPU consumption) via a long login name sent to port 3103.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input bound="1" />
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/17427" source="XF" patch="1" adv="1">pigeon-server-dos(17427)</ref>
      <ref url="http://www.securityfocus.com/bid/11203" source="BID" patch="1" adv="1">11203</ref>
      <ref url="http://secunia.com/advisories/12585" source="SECUNIA" patch="1" adv="1">12585</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109543366631724&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20040916 Freeze in Pigeon Server 3.02.0143</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2004-September/026515.html" source="FULLDISC">20040916 Freeze in Pigeon Server 3.02.0143</ref>
    </refs>
    <vuln_soft>
      <prod vendor="tech-noel" name="pigeon_server">
        <vers num="3.02.0143" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2004-1689" published="2004-09-16" name="CVE-2004-1689" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">sudoedit (aka sudo -e) in sudo 1.6.8 opens a temporary file with root privileges, which allows local users to read arbitrary files via a symlink attack on the temporary file before quitting sudoedit.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/424358" source="CERT-VN" patch="1" adv="1">VU#424358</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/17424" source="XF" patch="1" adv="1">sudo-sudoedit-view-files(17424)</ref>
      <ref url="http://www.sudo.ws/sudo/alerts/sudoedit.html" source="CONFIRM" patch="1" adv="1">http://www.sudo.ws/sudo/alerts/sudoedit.html</ref>
      <ref url="http://www.securityfocus.com/bid/11204" source="BID" patch="1" adv="1">11204</ref>
      <ref url="http://www.osvdb.org/10023" source="OSVDB" patch="1" adv="1">10023 </ref>
      <ref url="http://www.ciac.org/ciac/bulletins/o-219.shtml" source="CIAC" patch="1" adv="1">O-219</ref>
      <ref url="http://secunia.com/advisories/12596" source="SECUNIA" patch="1" adv="1">12596</ref>
      <ref url="http://packetstormsecurity.nl/0409-exploits/sudoedit.txt" source="MISC" patch="1" adv="1">http://packetstormsecurity.nl/0409-exploits/sudoedit.txt</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109537972929201&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20040916 [sudo-announce] Sudo version 1.6.8p1 now available (fwd)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="todd_miller" name="sudo">
        <vers num="1.6.8" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1690" published="2004-09-18" name="CVE-2004-1690" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in the Web Server in DNS4Me 3.0.0.4 allows remote attackers to execute arbitrary web script or HTML via the URL.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/17425" source="XF" adv="1">dns4me-xss(17425)</ref>
      <ref url="http://www.securityfocus.com/bid/11213" source="BID" adv="1">11213</ref>
      <ref url="http://www.gulftech.org/?node=research&amp;article_id=00049-09162004" source="MISC" adv="1">http://www.gulftech.org/?node=research&amp;article_id=00049-09162004</ref>
      <ref url="http://securitytracker.com/id?1011334" source="SECTRACK" adv="1">1011334</ref>
      <ref url="http://secunia.com/advisories/12595" source="SECUNIA" adv="1">12595</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109552436811493&amp;w=2" source="BUGTRAQ" adv="1">20040918 RhinoSoft DNS4ME HTTP Server Vulnerabilities</ref>
    </refs>
    <vuln_soft>
      <prod vendor="rhinosoft" name="dns4me">
        <vers num="3.0.0.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1691" published="2004-09-18" name="CVE-2004-1691" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The Web Server in DNS4Me 3.0.0.4 allows remote attackers to cause a denial of service (CPU consumption and crash) via a large amount of data.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/17426" source="XF" adv="1">dns4me-dos(17426)</ref>
      <ref url="http://www.securityfocus.com/bid/11213" source="BID" adv="1">11213</ref>
      <ref url="http://www.gulftech.org/?node=research&amp;article_id=00049-09162004" source="MISC" adv="1">http://www.gulftech.org/?node=research&amp;article_id=00049-09162004</ref>
      <ref url="http://securitytracker.com/id?1011334" source="SECTRACK" adv="1">1011334</ref>
      <ref url="http://secunia.com/advisories/12595" source="SECUNIA" adv="1">12595</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109552436811493&amp;w=2" source="BUGTRAQ" adv="1">20040918 RhinoSoft DNS4ME HTTP Server Vulnerabilities</ref>
    </refs>
    <vuln_soft>
      <prod vendor="rhinosoft" name="dns4me">
        <vers num="3.0.0.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1692" published="2004-09-18" name="CVE-2004-1692" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in index.php in Mambo 4.5 (1.0.9) allows remote attackers to inject arbitrary web script or HTML via the (1) Itemid, (2) mosmsg, or (3) limit parameters.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/11220" source="BID" patch="1" adv="1">11220</ref>
      <ref url="http://www.osvdb.org/10179" source="OSVDB" patch="1" adv="1">10179</ref>
      <ref url="http://mamboforge.net/frs/shownotes.php?release_id=1672" source="CONFIRM" patch="1">http://mamboforge.net/frs/shownotes.php?release_id=1672</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/20616" source="XF">mambo-multiple-xss(20616)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109571849713158&amp;w=2" source="BUGTRAQ" adv="1">20040918 Vulnerabilities in TUTOS</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mambo" name="mambo_open_source">
        <vers num="4.5_1.0.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-1693" published="2004-09-18" name="CVE-2004-1693" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">PHP remote file inclusion vulnerability in Function.php in Mambo 4.5 (1.0.9) allows remote attackers to execute arbitrary PHP code by modifying the mosConfig_absolute_path parameter to reference a URL on a remote web server that contains the code.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/17449" source="XF" patch="1" adv="1">mambo-cachelibrary-execute-code(17449)</ref>
      <ref url="http://www.osvdb.org/10180" source="OSVDB" patch="1" adv="1">10180</ref>
      <ref url="http://www.securityfocus.com/bid/11220" source="BID" adv="1">11220</ref>
      <ref url="http://securitytracker.com/id?1011365" source="SECTRACK">1011365</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109571849713158&amp;w=2" source="BUGTRAQ" adv="1">20040918 Vulnerabilities in TUTOS</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mambo" name="mambo">
        <vers num="4.5_1.0.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-1694" published="2004-09-21" name="CVE-2004-1694" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Symantec ON Command CCM 5.4.x and iCommand 3.0.x has four default usernames and passwords, one of which is hardcoded, which allows remote attackers to gain unauthorized access.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/17447" source="XF" patch="1" adv="1">oncommand-multiple-default-accounts(17447)</ref>
      <ref url="http://www.securityfocus.com/bid/11225" source="BID" patch="1" adv="1">11225</ref>
      <ref url="http://secunia.com/advisories/12604" source="SECUNIA" patch="1" adv="1">12604</ref>
      <ref url="http://www.sarc.com/avcenter/security/Content/2004.09.29.html" source="CONFIRM" adv="1">http://www.sarc.com/avcenter/security/Content/2004.09.29.html</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109571689621784&amp;w=2" source="BUGTRAQ" adv="1">20040920 Default username/password pairs in ON Command CCM 5.x database</ref>
    </refs>
    <vuln_soft>
      <prod vendor="symantec" name="on_command_ccm">
        <vers num="5.0" />
        <vers num="5.1" />
        <vers num="5.2" />
        <vers num="5.3" />
        <vers num="5.4" />
      </prod>
      <prod vendor="symantec" name="on_icommand">
        <vers num="3.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-1695" published="2004-09-20" name="CVE-2004-1695" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">EmuLive Server4 Commerce Edition Build 7560 allows remote attackers to bypass authentication for the remote administration feature via a URL that contains an extra leading / (slash).</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/17450" source="XF" adv="1">emuliveserver4-url-gain-access(17450)</ref>
      <ref url="http://www.securityfocus.com/bid/11226" source="BID" adv="1">11226</ref>
      <ref url="http://www.gulftech.org/?node=research&amp;article_id=00051-09202004" source="MISC" adv="1">http://www.gulftech.org/?node=research&amp;article_id=00051-09202004</ref>
      <ref url="http://secunia.com/advisories/12616" source="SECUNIA" adv="1">12616</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109577497718374&amp;w=2" source="BUGTRAQ" adv="1">20040921 Multiple Vulnerabilities In EmuLive Server4</ref>
    </refs>
    <vuln_soft>
      <prod vendor="emulive" name="server4">
        <vers num="commerce_build_7560" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1696" published="2004-09-21" name="CVE-2004-1696" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">EmuLive Server4 Commerce Edition Build 7560 allows remote attackers to cause a denial of service (application crash) via a sequence of carriage returns sent to TCP port 66.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/12616" source="SECUNIA" patch="1" adv="1">12616</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/17451" source="XF" adv="1">emulive-tcp-port-dos(17451)</ref>
      <ref url="http://www.securityfocus.com/bid/11226" source="BID" adv="1">11226</ref>
      <ref url="http://www.gulftech.org/?node=research&amp;article_id=00051-09202004" source="MISC" adv="1">http://www.gulftech.org/?node=research&amp;article_id=00051-09202004</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109577497718374&amp;w=2" source="BUGTRAQ" adv="1">20040921 Multiple Vulnerabilities In EmuLive Server4</ref>
    </refs>
    <vuln_soft>
      <prod vendor="emulive" name="server4">
        <vers num="commerce_build_7560" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-1697" published="2004-09-21" name="CVE-2004-1697" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">The "Forgot your Password" link in Computer Associates (CA) Unicenter Management Portal 2.0 and 3.1 displays different error messages for users that exist and users that do not exist, which could allow remote attackers to guess valid usernames.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/17464" source="XF" patch="1" adv="1">unicenter-management-username-bruteforce(17464)</ref>
      <ref url="http://www.securityfocus.com/bid/11229" source="BID" patch="1" adv="1">11229</ref>
      <ref url="http://secunia.com/advisories/12620" source="SECUNIA" patch="1" adv="1">12620</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109579952809320&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20040921 CA UniCenter Management Portal Username Enumeration Vulnerability</ref>
    </refs>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1698" published="2004-09-24" name="CVE-2004-1698" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The Base64 function in PopMessenger 1.60 (before 20 Sep 2004) and earlier allows remote attackers to cause a denial of service (application crash) via invalid characters in a message, which causes several alert dialogs to be displayed and leads to a crash.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/12612/" source="SECUNIA" patch="1" adv="1">12612</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/17465" source="XF" adv="1">popmessenger-base64-dos(17465)</ref>
      <ref url="http://www.securityfocus.com/bid/11230" source="BID" adv="1">11230</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109581586128899&amp;w=2" source="BUGTRAQ" adv="1">20040921 Broadcast crash in Popmessenger 1.60 (before 20 Sep 2004)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="leadmind" name="popmessenger">
        <vers num="1.60" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1699" published="2004-09-21" name="CVE-2004-1699" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">SettingsBase.php in Pinnacle ShowCenter 1.51 allows remote attackers to cause a denial of service (web interface errors) via an invalid Skin parameter.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/17463" source="XF" adv="1">pinnacle-showcenter-dos(17463)</ref>
      <ref url="http://www.securityfocus.com/bid/11232" source="BID" adv="1">11232</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109589167110196&amp;w=2" source="BUGTRAQ" adv="1">20040922 Pinnacle ShowCenter 1.51 possible DoS</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2004-September/026733.html" source="FULLDISC" adv="1">20040921 Pinnacle ShowCenter Skin Denial of Service</ref>
    </refs>
    <vuln_soft>
      <prod vendor="pinnacle_systems" name="showcenter">
        <vers num="1.51" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1700" published="2004-10-14" name="CVE-2004-1700" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in SettingsBase.php in Pinnacle ShowCenter 1.51 build 121 allows remote attackers to inject arbitrary HTML or web script via the Skin parameter, which is echoed in an error message.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/12613" source="SECUNIA" patch="1" adv="1">12613</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/17708" source="XF">pinnacle-showcenter-xss(17708)</ref>
      <ref url="http://www.securityfocus.com/bid/11415" source="BID">11415</ref>
    </refs>
    <vuln_soft>
      <prod vendor="pinnacle_systems" name="showcenter">
        <vers num="1.51_build_121" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-1701" published="2004-08-09" name="CVE-2004-1701" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Heap-based buffer overflow in the AuthenticationDialogue function in cfservd for Cfengine 2.0.0 to 2.1.7p1 allows remote attackers to execute arbitrary code via a long SAUTH command during RSA authentication.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/16935" source="XF" patch="1" adv="1">cfengine-cfservd-command-execution(16935)</ref>
      <ref url="http://www.securityfocus.com/bid/10899" source="BID" patch="1" adv="1">10899</ref>
      <ref url="http://www.coresecurity.com/common/showdoc.php?idx=387&amp;idxseccion=10" source="MISC" patch="1" adv="1">http://www.coresecurity.com/common/showdoc.php?idx=387&amp;idxseccion=10</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200408-08.xml" source="GENTOO" patch="1" adv="1">GLSA-200408-08</ref>
      <ref url="http://secunia.com/advisories/12251" source="SECUNIA" patch="1" adv="1">12251</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110886670528775&amp;w=2" source="BUGTRAQ" adv="1">20050219 cfengine rsa heap remote exploit:   part of PTjob project</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109208394910086&amp;w=2" source="BUGTRAQ" adv="1">20040809 CORE-2004-0714: Cfengine RSA Authentication Heap Corruption</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gnu" name="cfengine">
        <vers num="2.0.0" />
        <vers num="2.0.1" />
        <vers num="2.0.2" />
        <vers num="2.0.3" />
        <vers num="2.0.4" />
        <vers num="2.0.5" edition="b1" />
        <vers num="2.0.5" edition="pre" />
        <vers num="2.0.5" edition="pre2" />
        <vers num="2.0.6" />
        <vers num="2.0.7" edition="p1" />
        <vers num="2.0.7" edition="p2" />
        <vers num="2.0.7" edition="p3" />
        <vers num="2.0.8" edition="p1" />
        <vers num="2.1.0" edition="a6" />
        <vers num="2.1.0" edition="a8" />
        <vers num="2.1.0" edition="a9" />
        <vers num="2.1.7" edition="p1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1702" published="2004-08-09" name="CVE-2004-1702" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The AuthenticationDialogue function in cfservd for Cfengine 2.0.0 to 2.1.7p1 does not properly check the return value of the ReceiveTransaction function, which leads to a failed malloc call and triggers to a null dereference, which allows remote attackers to cause a denial of service (crash).</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/16937" source="XF" patch="1" adv="1">cfengine-cfservd-dos(16937)</ref>
      <ref url="http://www.securityfocus.com/bid/10900" source="BID" patch="1" adv="1">10900</ref>
      <ref url="http://www.coresecurity.com/common/showdoc.php?idx=387&amp;idxseccion=10" source="MISC" patch="1" adv="1">http://www.coresecurity.com/common/showdoc.php?idx=387&amp;idxseccion=10</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200408-08.xml" source="GENTOO" patch="1" adv="1">GLSA-200408-08</ref>
      <ref url="http://secunia.com/advisories/12251" source="SECUNIA" patch="1" adv="1">12251</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109208394910086&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20040809 CORE-2004-0714: Cfengine RSA Authentication Heap Corruption</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gnu" name="cfengine">
        <vers num="2.0.0" />
        <vers num="2.0.1" />
        <vers num="2.0.2" />
        <vers num="2.0.3" />
        <vers num="2.0.4" />
        <vers num="2.0.5" edition="b1" />
        <vers num="2.0.5" edition="pre" />
        <vers num="2.0.5" edition="pre2" />
        <vers num="2.0.6" />
        <vers num="2.0.7" edition="p1" />
        <vers num="2.0.7" edition="p2" />
        <vers num="2.0.7" edition="p3" />
        <vers num="2.0.8" edition="p1" />
        <vers num="2.1.0" edition="a6" />
        <vers num="2.1.0" edition="a8" />
        <vers num="2.1.0" edition="a9" />
        <vers num="2.1.7" edition="p1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-1703" published="2004-07-30" name="CVE-2004-1703" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Fusion News 3.6.1 allows remote attackers to add user accounts, if the administrator is logged in, via a comment that contains an img bbcode tag that calls index.php with the signup action, which is executed when the administrator's browser loads the page with the img tag.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/16853" source="XF" adv="1">fusion-news-add-account(16853)</ref>
      <ref url="http://www.securityfocus.com/bid/10836" source="BID" adv="1">10836</ref>
      <ref url="http://securitytracker.com/id?1010829" source="SECTRACK" adv="1">1010829</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109122824523226&amp;w=2" source="BUGTRAQ" adv="1">20040729 Fusion News Yet Another Unauthorized Account Addition Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="fusionphp" name="fusion_news">
        <vers num="3.3" />
        <vers num="3.6.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-1704" published="2004-07-30" name="CVE-2004-1704" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">WpQuiz 2.60b1 through 2.60b8 allows remote attackers to gain privileges via a direct request to adminrestore.php in the extras directory.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/16848" source="XF" patch="1" adv="1">wpquiz-extra-gain-access(16848)</ref>
      <ref url="http://www.osvdb.org/8321" source="OSVDB" adv="1">8321</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109122270013514&amp;w=2" source="BUGTRAQ" adv="1">20040730 WpQuiz Gain Admin Rightd Exploit found</ref>
    </refs>
    <vuln_soft>
      <prod vendor="wire_plastic_design" name="wpquiz">
        <vers num="2.60b1" />
        <vers num="2.60b2" />
        <vers num="2.60b3" />
        <vers num="2.60b4" />
        <vers num="2.60b5" />
        <vers num="2.60b6" />
        <vers num="2.60b7" />
        <vers num="2.60b8" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1705" published="2004-07-30" name="CVE-2004-1705" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Buffer overflow in Citadel/UX 6.23 and earlier allows remote attackers to cause a denial of service via a long username.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/16840" source="XF" patch="1" adv="1">citadel-user-dos(16840)</ref>
      <ref url="http://www.securityfocus.com/bid/10833" source="BID" patch="1" adv="1">10833</ref>
      <ref url="http://www.nosystem.com.ar/advisories/advisory-04.txt" source="MISC" patch="1" adv="1">http://www.nosystem.com.ar/advisories/advisory-04.txt</ref>
      <ref url="http://securitytracker.com/id?1010809" source="SECTRACK" patch="1" adv="1">1010809</ref>
      <ref url="http://secunia.com/advisories/12197" source="SECUNIA" patch="1" adv="1">12197</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109146099404071&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20040731 Re: Citadel/UX Remote DoS Vulnerability</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109121546120575&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20040731 Citadel/UX Remote DoS Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="citadel" name="ux">
        <vers num="5.90" />
        <vers num="5.91" />
        <vers num="6.07" />
        <vers num="6.08" />
        <vers num="6.23" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-1706" published="2004-08-02" name="CVE-2004-1706" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">The U.S. Robotics USR808054 wireless access point allows remote attackers to cause a denial of service (device crash) and possibly execute arbitrary code via an HTTP GET request with a long version string.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/12207" source="SECUNIA" patch="1" adv="1">12207</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/16860" source="XF" adv="1">usrobotics-wireless-get-bo(16860)</ref>
      <ref url="http://www.securityfocus.com/bid/10840" source="BID" adv="1">10840</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109146350605751&amp;w=2" source="BUGTRAQ" adv="1">20040802 7a69Adv#13 - USRobotics AP Wireless Denial of Service</ref>
    </refs>
    <vuln_soft>
      <prod vendor="u.s.robotics" name="usr808054">
        <vers num="1.21_h" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-1707" published="2004-07-30" name="CVE-2004-1707" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">The (1) dbsnmp and (2) nmo programs in Oracle 8i, Oracle 9i, and Oracle IAS 9.0.2.0.1, on Unix systems, use a default path to find and execute library files while operating at raised privileges, which allows certain Oracle user accounts to gain root privileges via a modified libclntsh.so.9.0.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <config />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/12205" source="SECUNIA" patch="1" adv="1">12205</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109147677214087&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20040802 OPEN3S - Local Privilege Elevation through Oracle products (Unix Platform)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/16839" source="XF" adv="1">oracle-libraries-gain-privileges(16839)</ref>
      <ref url="http://www.securityfocus.com/bid/10829" source="BID" adv="1">10829</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="application_server">
        <vers num="1.0.2" />
        <vers num="1.0.2.1s" />
        <vers num="1.0.2.2" />
        <vers num="1.0.2.2.2" />
        <vers num="9.0.2" />
        <vers num="9.0.2.0.0" />
        <vers num="9.0.2.0.1" />
        <vers num="9.0.2.1" />
        <vers num="9.0.2.2" />
        <vers num="9.0.2.3" />
        <vers num="9.0.3" />
        <vers num="9.0.3.1" />
      </prod>
      <prod vendor="oracle" name="application_server_portal">
        <vers num="3.0.9.8.5" />
        <vers num="9.0.2.3" />
        <vers num="9.0.2.3a" />
        <vers num="9.0.2.3b" />
      </prod>
      <prod vendor="oracle" name="database_server_lite">
        <vers num="5.0" />
        <vers num="5.0.1" />
        <vers num="5.0.2" />
      </prod>
      <prod vendor="oracle" name="oracle8i">
        <vers num="enterprise_8.0.5_.0.0" />
        <vers num="enterprise_8.0.6_.0.0" />
        <vers num="enterprise_8.0.6_.0.1" />
        <vers num="enterprise_8.1.5_.0.0" />
        <vers num="enterprise_8.1.5_.0.2" />
        <vers num="enterprise_8.1.5_.1.0" />
        <vers num="enterprise_8.1.6_.0.0" />
        <vers num="enterprise_8.1.6_.1.0" />
        <vers num="enterprise_8.1.7_.0.0" />
        <vers num="enterprise_8.1.7_.1.0" />
        <vers num="standard_8.0.6" />
        <vers num="standard_8.0.6_.3" />
        <vers num="standard_8.1.5" />
        <vers num="standard_8.1.6" />
        <vers num="standard_8.1.7" />
        <vers num="standard_8.1.7_.0.0" />
        <vers num="standard_8.1.7_.1" />
        <vers num="standard_8.1.7_.4" />
      </prod>
      <prod vendor="oracle" name="oracle9i">
        <vers num="client_9.2.0.1" />
        <vers num="client_9.2.0.2" />
        <vers num="enterprise_9.0.1" />
        <vers num="enterprise_9.0.1.4" />
        <vers num="enterprise_9.0.1.5" />
        <vers num="enterprise_9.2.0" />
        <vers num="enterprise_9.2.0.1" />
        <vers num="enterprise_9.2.0.2" />
        <vers num="enterprise_9.2.0.3" />
        <vers num="enterprise_9.2.0.4" />
        <vers num="personal_8.1.7" />
        <vers num="personal_9.0.1" />
        <vers num="personal_9.0.1.4" />
        <vers num="personal_9.0.1.5" />
        <vers num="personal_9.2" />
        <vers num="personal_9.2.0.1" />
        <vers num="personal_9.2.0.2" />
        <vers num="personal_9.2.0.3" />
        <vers num="personal_9.2.0.4" />
        <vers num="standard_9.0" />
        <vers num="standard_9.0.1" />
        <vers num="standard_9.0.1.2" />
        <vers num="standard_9.0.1.3" />
        <vers num="standard_9.0.1.4" />
        <vers num="standard_9.0.1.5" />
        <vers num="standard_9.0.2" />
        <vers num="standard_9.2" />
        <vers num="standard_9.2.0.1" />
        <vers num="standard_9.2.0.2" />
        <vers num="standard_9.2.0.3" />
        <vers num="standard_9.2.0.4" />
        <vers num="standard_9.2.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1708" published="2004-08-02" name="CVE-2004-1708" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Webbsyte Chat 0.9.0 allows remote attackers to cause a denial of service (crash) via a large number of connections.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/16852" source="XF" adv="1">webbsyte-chat-dos(16852)</ref>
      <ref url="http://www.securityfocus.com/bid/10842" source="BID" adv="1">10842</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109156450320855&amp;w=2" source="BUGTRAQ" adv="1">20040803 DoS in Webbsyte Chat 0.9.0</ref>
    </refs>
    <vuln_soft>
      <prod vendor="shawn_webb" name="webbsyte_chat">
        <vers num="0.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2004-1709" published="2004-08-04" name="CVE-2004-1709" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">Datakey Rainbow iKey2032 USB token, when using the CIP client package, does not encrypt communications between the token and the driver, which could allow local users to obtain the PINs of other users.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/16887" source="XF" patch="1" adv="1">datakey-plaintext-pin(16887)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109164096013467&amp;w=2" source="BUGTRAQ" adv="1">20040804 Clear text password exposure in Datakey's tokens and smartcards</ref>
    </refs>
    <vuln_soft>
      <prod vendor="datakey" name="rainbow_ikey2032_usb_token">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-1710" published="2004-08-06" name="CVE-2004-1710" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">page.cgi allows remote attackers to execute arbitrary commands via shell metacharacters in the url parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/19713" source="XF" adv="1">pagecgi-url-command-execution(19713)</ref>
      <ref url="http://www.osvdb.org/8936" source="OSVDB" adv="1">8936</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109181771832634&amp;w=2" source="BUGTRAQ">20040806 Remote Command Execution</ref>
    </refs>
    <vuln_soft>
      <prod vendor="andrew_kilpatrick" name="page_cgi">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1711" published="2004-08-06" name="CVE-2004-1711" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in post.php in Moodle before 1.3 allows remote attackers to inject arbitrary web script or HTML via the reply parameter.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/16924" source="XF" patch="1" adv="1">moodle-post-xss(16924)</ref>
      <ref url="http://www.securityfocus.com/bid/10884" source="BID" patch="1" adv="1">10884</ref>
      <ref url="http://secunia.com/advisories/12262" source="SECUNIA" patch="1" adv="1">12262</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109182851216921&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20040806 xss in moodle (post.php)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="moodle" name="moodle">
        <vers num="1.1.1" />
        <vers num="1.2" />
        <vers num="1.2.1" />
        <vers num="1.3" />
        <vers num="1.3.1" />
        <vers num="1.3.2" />
        <vers num="1.3.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1712" published="2004-08-06" name="CVE-2004-1712" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in TypePad allows remote attackers inject arbitrary Javascript via the name parameter.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/19664" source="XF" adv="1">typepad-name-xss(19664)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109189453302959&amp;w=2" source="BUGTRAQ" adv="1">20040806 Type xxs</ref>
    </refs>
  </entry>
  <entry type="CVE" severity="Low" seq="2004-1713" published="2004-08-10" name="CVE-2004-1713" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">Unknown vulnerability in HP Process Resource Manager (PRM) C.02.01[.01] and earlier, as used by HP-UX Workload Manager (WLM), allows local users to corrupt data files.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <other />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/10907" source="BID" patch="1" adv="1">10907</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109215093809027&amp;w=2" source="HP" patch="1" adv="1">SSRT4785</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/16928" source="XF" adv="1">hp-prm-wlm-file-corruption(16928)</ref>
      <ref url="http://secunia.com/advisories/12245" source="SECUNIA" adv="1">12245</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hp" name="process_resource_manager">
        <vers num="c.01.07" />
        <vers num="c.01.08.02" />
        <vers num="c.02.01.01" />
      </prod>
      <prod vendor="hp" name="workload_manager">
        <vers num="a.02.01" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2004-1714" published="2004-08-11" name="CVE-2004-1714" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">BlackICE PC Protection and Server Protection installs (1) firewall.ini, (2) blackice.ini, (3) sigs.ini and (4) protect.ini with Everyone Full Control permissions, which allows local users to cause a denial of service (crash) or modify configuration, as demonstrated by modifying firewall.ini to contain a large firewall rule.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <config />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109223751031166&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20040811 BlackICE unprivileged local user attack</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2004-August/025112.html" source="FULLDISC" patch="1" adv="1">20040811 ISS BlackIce Server Protect Unprivileged User Attack</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/16959" source="XF" adv="1">blackice-firewall-dos(16959)</ref>
      <ref url="http://www.securityfocus.com/bid/10915" source="BID" adv="1">10915</ref>
    </refs>
    <vuln_soft>
      <prod vendor="iss" name="blackice_pc_protection">
        <vers num="3.6cbd" />
        <vers num="3.6cbr" />
        <vers num="3.6cbz" />
        <vers num="3.6cca" />
        <vers num="3.6ccb" />
        <vers num="3.6ccc" />
        <vers num="3.6ccd" />
        <vers num="3.6cce" />
        <vers num="3.6ccf" />
        <vers num="3.6ccg" />
      </prod>
      <prod vendor="iss" name="blackice_server_protection">
        <vers num="3.5cdf" />
        <vers num="3.6cbz" />
        <vers num="3.6cca" />
        <vers num="3.6ccb" />
        <vers num="3.6ccc" />
        <vers num="3.6ccd" />
        <vers num="3.6cce" />
        <vers num="3.6ccf" />
        <vers num="3.6ccg" />
        <vers num="3.6cch" />
        <vers num="3.6cno" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1715" published="2004-08-11" name="CVE-2004-1715" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in MIMEsweeper for Web before 5.0.4 allows remote attackers or local users to read arbitrary files via "..\\", "..\", and similar dot dot sequences in the URL.</descript>
    </desc>
    <sols>
      <sol source="nvd">This was fixed in MIMEsweeper for Web v5.0.4.</sol>
    </sols>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/16960" source="XF" patch="1" adv="1">mimesweeper-directory-traversal(16960)</ref>
      <ref url="http://www.securityfocus.com/bid/10918" source="BID" patch="1" adv="1">10918</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109225567212978&amp;w=2" source="BUGTRAQ" patch="1">20040811 Re: Clearswift Mimesweeper Path Traversal Vulnerability</ref>
      <ref url="http://secunia.com/advisories/12273" source="SECUNIA" adv="1">12273</ref>
      <ref url="http://packetstormsecurity.nl/0408-exploits/clearswift.txt" source="MISC" adv="1">http://packetstormsecurity.nl/0408-exploits/clearswift.txt</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109224211512029&amp;w=2" source="BUGTRAQ" adv="1">20040811 Clearswift Mimesweeper Path Traversal Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="clearswift" name="mimesweeper_for_web">
        <vers num="4.0" />
        <vers num="5.0.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1716" published="2004-08-16" name="CVE-2004-1716" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in PForum before 1.26 allows remote attackers to inject arbitrary web script or HTML via the (1) IRC Server or (2) AIM ID fields in the user profile.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/674542" source="CERT-VN" patch="1" adv="1">VU#674542</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/17003" source="XF" patch="1" adv="1">pforum-irc-aim-xss(17003)</ref>
      <ref url="http://www.securityfocus.com/bid/10954" source="BID" patch="1" adv="1">10954</ref>
      <ref url="http://secunia.com/advisories/12317/" source="SECUNIA" patch="1" adv="1">12317</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109267937212298&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20040814 pscript.de PFORUM XSS Vulnerability</ref>
      <ref url="http://www.osvdb.org/8985" source="OSVDB" adv="1">8985</ref>
    </refs>
    <vuln_soft>
      <prod vendor="powie" name="pforum">
        <vers num="1.24" />
        <vers num="1.25" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-1717" published="2004-08-16" name="CVE-2004-1717" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple buffer overflows in the psscan function in ps.c for gv (ghostview) allow remote attackers to execute arbitrary code via a Postscript file with a long (1) BoundingBox, (2) comment, (3) Orientation, (4) PageOrder, or (5) Pages value.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/17019" source="XF" adv="1">gv-psscan-header-bo(17019)</ref>
      <ref url="http://www.securityfocus.com/bid/10944" source="BID" adv="1">10944</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109267677114331&amp;w=2" source="BUGTRAQ">20040816 gv buffer overflows: here, there, and everywhere</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gv" name="gv">
        <vers num="2.7.6" />
        <vers num="2.7b1" />
        <vers num="2.7b2" />
        <vers num="2.7b3" />
        <vers num="2.7b4" />
        <vers num="2.7b5" />
        <vers num="2.9.4" />
        <vers num="3.0.0" />
        <vers num="3.0.4" />
        <vers num="3.1.4" />
        <vers num="3.1.6" />
        <vers num="3.2.4" />
        <vers num="3.4.12" />
        <vers num="3.4.2" />
        <vers num="3.4.3" />
        <vers num="3.5.2" />
        <vers num="3.5.3" />
        <vers num="3.5.8" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2004-1718" published="2004-08-17" name="CVE-2004-1718" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">The ZwOpenSection function in Integrity Protection Driver (IPD) 1.4 and earlier allows local users to cause a denial of service (crash) via an invalid pointer in the "oa" argument.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
      <exception />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/17010" source="XF" adv="1">ipd-oa-pointer-dos(17010)</ref>
      <ref url="http://www.securityfocus.com/bid/10965" source="BID" adv="1">10965</ref>
      <ref url="http://www.ngsec.com/docs/advisories/NGSEC-2004-6.txt" source="MISC" adv="1">http://www.ngsec.com/docs/advisories/NGSEC-2004-6.txt</ref>
      <ref url="http://secunia.com/advisories/12169" source="SECUNIA" adv="1">12169</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109276749821133&amp;w=2" source="BUGTRAQ" adv="1">20040817 [NGSEC-2004-6] IPD, local system denial of service.</ref>
    </refs>
    <vuln_soft>
      <prod vendor="pedestal_software" name="integrity_protection_driver">
        <vers num="1.2" />
        <vers num="1.3" />
        <vers num="1.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1719" published="2004-08-17" name="CVE-2004-1719" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in Merak Webmail Server 5.2.7 allow remote attackers to inject arbitrary web script or HTML via the (1) category, (2) cserver, (3) ext, (4) global, (5) showgroups, (6) or showlite parameters to address.html, or the (7) spage or (8) autoresponder parameters to settings.html, the (9) folder parameter to readmail.html, or the (10) attachmentpage_text_error parameter to attachment.html, (11) folder, (12) ct, or (13) cv parameters to calendar.html, (14) an &lt;img&gt; tag, or (15) the subject of an e-mail message.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/17024" source="XF" patch="1" adv="1">merak-xss(17024)</ref>
      <ref url="http://www.securityfocus.com/bid/10966" source="BID" patch="1" adv="1">10966</ref>
      <ref url="http://www.osvdb.org/9042" source="OSVDB" patch="1" adv="1">9042</ref>
      <ref url="http://www.osvdb.org/9041" source="OSVDB" patch="1" adv="1">9041</ref>
      <ref url="http://www.osvdb.org/9040" source="OSVDB" patch="1" adv="1">9040</ref>
      <ref url="http://www.osvdb.org/9039" source="OSVDB" patch="1" adv="1">9039</ref>
      <ref url="http://www.osvdb.org/9038" source="OSVDB" patch="1" adv="1">9038</ref>
      <ref url="http://www.osvdb.org/9037" source="OSVDB" patch="1" adv="1">9037</ref>
      <ref url="http://secunia.com/advisories/12269" source="SECUNIA" patch="1" adv="1">12269</ref>
      <ref url="http://packetstormsecurity.nl/0408-exploits/merak527.txt" source="MISC" patch="1" adv="1">http://packetstormsecurity.nl/0408-exploits/merak527.txt</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109279057326044&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20040817 Vulnerabilities in Merak Webmail Server</ref>
      <ref url="http://securitytracker.com/id?1010969" source="SECTRACK">1010969</ref>
    </refs>
    <vuln_soft>
      <prod vendor="merak" name="mail_server">
        <vers num="7.4.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1720" published="2004-08-17" name="CVE-2004-1720" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The (1) address.html and possibly (2) calendar.html pages in Merak Mail Server 5.2.7 allow remote attackers to gain sensitive information via an invalid HTTP request, which reveals the installation path. NOTE: it is unclear whether the calendar.html is an exposure, since the path is leaked in web logs that may only be available to the administrators, who would have access to the path through legitimate means.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/17027" source="XF" patch="1" adv="1">merak-address-calendar-path-disclosure(17027)</ref>
      <ref url="http://www.securityfocus.com/bid/10966" source="BID" patch="1" adv="1">10966</ref>
      <ref url="http://www.osvdb.org/9043" source="OSVDB" patch="1" adv="1">9043</ref>
      <ref url="http://secunia.com/advisories/12269" source="SECUNIA" patch="1" adv="1">12269</ref>
      <ref url="http://packetstormsecurity.nl/0408-exploits/merak527.txt" source="MISC" patch="1" adv="1">http://packetstormsecurity.nl/0408-exploits/merak527.txt</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109279057326044&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20040817 Vulnerabilities in Merak Webmail Server</ref>
      <ref url="http://securitytracker.com/id?1010969" source="SECTRACK">1010969</ref>
    </refs>
    <vuln_soft>
      <prod vendor="merak" name="mail_server">
        <vers num="7.4.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1721" published="2004-08-17" name="CVE-2004-1721" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The (1) function.php or (2) function.view.php scripts in Merak Mail Server 5.2.7 allow remote attackers to read arbitrary PHP files via a direct HTTP request to port 32000.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/17029" source="XF" patch="1" adv="1">merak-view-php-files(17029)</ref>
      <ref url="http://www.securityfocus.com/bid/10966" source="BID" patch="1" adv="1">10966</ref>
      <ref url="http://www.osvdb.org/9045" source="OSVDB" patch="1" adv="1">9045</ref>
      <ref url="http://secunia.com/advisories/12269" source="SECUNIA" patch="1" adv="1">12269</ref>
      <ref url="http://packetstormsecurity.nl/0408-exploits/merak527.txt" source="MISC" patch="1" adv="1">http://packetstormsecurity.nl/0408-exploits/merak527.txt</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109279057326044&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20040817 Vulnerabilities in Merak Webmail Server</ref>
      <ref url="http://securitytracker.com/id?1010969" source="SECTRACK">1010969</ref>
    </refs>
    <vuln_soft>
      <prod vendor="merak" name="mail_server">
        <vers num="5.2.7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-1722" published="2004-08-17" name="CVE-2004-1722" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in calendar.html in Merak Mail Server 5.2.7 allows remote attackers to execute arbitrary SQL statements via the schedule parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/17022" source="XF" patch="1" adv="1">merak-calendarhtml-sql-injection(17022)</ref>
      <ref url="http://www.securityfocus.com/bid/10966" source="BID" patch="1" adv="1">10966</ref>
      <ref url="http://www.osvdb.org/9044" source="OSVDB" patch="1" adv="1">9044</ref>
      <ref url="http://secunia.com/advisories/12269" source="SECUNIA" patch="1" adv="1">12269</ref>
      <ref url="http://packetstormsecurity.nl/0408-exploits/merak527.txt" source="MISC" patch="1" adv="1">http://packetstormsecurity.nl/0408-exploits/merak527.txt</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109279057326044&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20040817 Vulnerabilities in Merak Webmail Server</ref>
      <ref url="http://securitytracker.com/id?1010969" source="SECTRACK">1010969</ref>
    </refs>
    <vuln_soft>
      <prod vendor="merak" name="mail_server">
        <vers num="7.5.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1723" published="2004-12-31" name="CVE-2004-1723" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The (1) updateuser.php and (2) forums_prune.php scripts in PHP-Fusion 4.00 allow remote attackers to obtain sensitive information via a direct HTTP request, which reveals the installation path in an error message.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/17036" source="XF">phpfusion-path-disclosure(17036)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109285292901685&amp;w=2" source="BUGTRAQ">20040818 Multiple vulnerabilities in PHP-FUSION</ref>
    </refs>
    <vuln_soft>
      <prod vendor="php_fusion" name="php_fusion">
        <vers num="4.00" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-1724" published="2004-08-18" name="CVE-2004-1724" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">The ReadMe First.txt file in PHP-Fusion 4.0 instructs users to set the permissions on the fusion_admin/db_backups directory to world read/write/execute (777), which allows remote attackers to download or view database backups, which have easily guessable filenames and contain the administrator username and password.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <access />
      <design />
      <config />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/17037" source="XF" adv="1">phpfusion-database-file-access(17037)</ref>
      <ref url="http://www.securityfocus.com/bid/10974" source="BID" adv="1">10974</ref>
      <ref url="http://secunia.com/advisories/12336" source="SECUNIA" adv="1">12336</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109285292901685&amp;w=2" source="BUGTRAQ" adv="1">20040818 Multiple vulnerabilities in PHP-FUSION</ref>
    </refs>
    <vuln_soft>
      <prod vendor="php_fusion" name="php_fusion">
        <vers num="4.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-1725" published="2004-12-31" name="CVE-2004-1725" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Stack-based buffer overflow in xvbmp.c in XV allows remote attackers to execute arbitrary code via a crafted image file.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/10985" source="BID" patch="1">10985</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/17053" source="XF">xv-image-bo(17053)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109302498125092&amp;w=2" source="BUGTRAQ">20040820 XV multiple buffer overflows, exploit included</ref>
    </refs>
    <vuln_soft>
      <prod vendor="john_bradley" name="xv">
        <vers num="3.10a" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-1726" published="2004-08-20" name="CVE-2004-1726" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple integer overflows in (1) xviris.c, (2) xvpcx.c, and (3) xvpm.c in XV allow remote attackers to execute arbitrary code via a crafted image file that triggers a heap-based buffer overflow.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/10985" source="BID" patch="1" adv="1">10985</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/17053" source="XF" adv="1">xv-image-bo(17053)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109302498125092&amp;w=2" source="BUGTRAQ" adv="1">20040820 XV multiple buffer overflows, exploit included</ref>
    </refs>
    <vuln_soft>
      <prod vendor="john_bradley" name="xv">
        <vers num="3.10a" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1727" published="2004-08-20" name="CVE-2004-1727" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">BadBlue 2.5 allows remote attackers to cause a denial of service (refuse HTTP connections) via a large number of connections from the same IP address.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/17064" source="XF" adv="1">badblue-mult-connection-dos(17064)</ref>
      <ref url="http://www.securityfocus.com/bid/10983" source="BID" adv="1">10983</ref>
      <ref url="http://www.gulftech.org/?node=research&amp;article_id=00043-08202004" source="MISC" adv="1">http://www.gulftech.org/?node=research&amp;article_id=00043-08202004</ref>
      <ref url="http://secunia.com/advisories/12346" source="SECUNIA" adv="1">12346</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109309119502208&amp;w=2" source="BUGTRAQ" adv="1">20040820 BadBlue Webserver v2.5 Denial Of Service Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="working_resources_inc." name="badblue">
        <vers num="2.50" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-1728" published="2004-08-20" name="CVE-2004-1728" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in British National Corpus SARA (sarad) allows remote attackers to execute arbitrary code by calling the client with a long string.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/17060" source="XF" patch="1" adv="1">sara-server-bo(17060)</ref>
      <ref url="http://www.securityfocus.com/bid/10984" source="BID" patch="1" adv="1">10984</ref>
      <ref url="http://secunia.com/advisories/12348" source="SECUNIA" patch="1" adv="1">12348</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109308454122827&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20040820 Buffer overflow in sarad</ref>
    </refs>
    <vuln_soft>
      <prod vendor="british_national_corpus" name="sara">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1729" published="2004-08-20" name="CVE-2004-1729" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in Nihuo Web Log Analyzer 1.6 allows remote attackers to inject arbitrary web script or HTML via the User-Agent HTTP header.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/17055" source="XF" adv="1">nihuo-http-get-xss(17055)</ref>
      <ref url="http://www.securityfocus.com/bid/10988" source="BID" adv="1">10988</ref>
      <ref url="http://secunia.com/advisories/12347" source="SECUNIA" adv="1">12347</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109305923208449&amp;w=2" source="BUGTRAQ" adv="1">20040820 Cross-Site Scripting (XSS) in Nihuo Web Log Analyzer</ref>
    </refs>
    <vuln_soft>
      <prod vendor="nihuo_software" name="web_log_analyzer">
        <vers num="1.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1730" published="2004-12-31" name="CVE-2004-1730" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in Mantis bugtracker allows remote attackers to inject arbitrary web script or HTML via (1) the return parameter to login_page.php, (2) e-mail field in signup.php, (3) action parameter to login_select_proj_page.php, or (4) hide_status parameter to view_all_set.php.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/12338" source="SECUNIA" patch="1">12338</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/17072" source="XF">mantis-viewallset-xss(17072)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/17070" source="XF">mantis-loginselectprojpage-xss(17070)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/17069" source="XF">mantis-signup-xss(17069)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/17066" source="XF">mantis-loginpage-xss(17066)</ref>
      <ref url="http://www.securityfocus.com/bid/10994" source="BID">10994</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109312225727345&amp;w=2" source="BUGTRAQ">20040820 Multiple Vulnerabilities in Mantis Bugtracker</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mantis" name="mantis">
        <vers num="0.10" />
        <vers num="0.10.1" />
        <vers num="0.10.2" />
        <vers num="0.11" />
        <vers num="0.11.1" />
        <vers num="0.12" />
        <vers num="0.13" />
        <vers num="0.13.1" />
        <vers num="0.14" />
        <vers num="0.14.1" />
        <vers num="0.14.2" />
        <vers num="0.14.3" />
        <vers num="0.14.4" />
        <vers num="0.14.5" />
        <vers num="0.14.6" />
        <vers num="0.14.7" />
        <vers num="0.14.8" />
        <vers num="0.15" />
        <vers num="0.15.1" />
        <vers num="0.15.10" />
        <vers num="0.15.11" />
        <vers num="0.15.12" />
        <vers num="0.15.2" />
        <vers num="0.15.3" />
        <vers num="0.15.4" />
        <vers num="0.15.5" />
        <vers num="0.15.6" />
        <vers num="0.15.7" />
        <vers num="0.15.8" />
        <vers num="0.15.9" />
        <vers num="0.16" />
        <vers num="0.16.0" />
        <vers num="0.16.1" />
        <vers num="0.17" />
        <vers num="0.17.0" />
        <vers num="0.17.1" />
        <vers num="0.17.2" />
        <vers num="0.17.3" />
        <vers num="0.17.4" />
        <vers num="0.17.4a" />
        <vers num="0.17.5" />
        <vers num="0.18" />
        <vers num="0.18.0_rc1" />
        <vers num="0.18.0a2" />
        <vers num="0.18.0a3" />
        <vers num="0.18.0a4" />
        <vers num="0.18a1" />
        <vers num="0.19.0a" />
        <vers num="0.9" />
        <vers num="0.9.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1731" published="2004-08-20" name="CVE-2004-1731" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">signup_page.php in Mantis bugtracker allows remote attackers to send e-mail bombs by creating multiple users and providing the same e-mail address.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/17093" source="XF" patch="1" adv="1">mantis-improper-account-validation(17093)</ref>
      <ref url="http://www.securityfocus.com/bid/10995" source="BID" patch="1" adv="1">10995</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109312225727345&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20040820 Multiple Vulnerabilities in Mantis Bugtracker</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mantis" name="mantis">
        <vers num="0.10" />
        <vers num="0.10.1" />
        <vers num="0.10.2" />
        <vers num="0.11" />
        <vers num="0.11.1" />
        <vers num="0.12" />
        <vers num="0.13" />
        <vers num="0.13.1" />
        <vers num="0.14" />
        <vers num="0.14.1" />
        <vers num="0.14.2" />
        <vers num="0.14.3" />
        <vers num="0.14.4" />
        <vers num="0.14.5" />
        <vers num="0.14.6" />
        <vers num="0.14.7" />
        <vers num="0.14.8" />
        <vers num="0.15" />
        <vers num="0.15.1" />
        <vers num="0.15.10" />
        <vers num="0.15.11" />
        <vers num="0.15.12" />
        <vers num="0.15.2" />
        <vers num="0.15.3" />
        <vers num="0.15.4" />
        <vers num="0.15.5" />
        <vers num="0.15.6" />
        <vers num="0.15.7" />
        <vers num="0.15.8" />
        <vers num="0.15.9" />
        <vers num="0.16" />
        <vers num="0.16.0" />
        <vers num="0.16.1" />
        <vers num="0.17" />
        <vers num="0.17.0" />
        <vers num="0.17.1" />
        <vers num="0.17.2" />
        <vers num="0.17.3" />
        <vers num="0.17.4" />
        <vers num="0.17.4a" />
        <vers num="0.17.5" />
        <vers num="0.18" />
        <vers num="0.18.0_rc1" />
        <vers num="0.18.0a2" />
        <vers num="0.18.0a3" />
        <vers num="0.18.0a4" />
        <vers num="0.18a1" />
        <vers num="0.19.0a" />
        <vers num="0.9" />
        <vers num="0.9.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-1732" published="2004-08-20" name="CVE-2004-1732" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in out.ViewFolder.php in MyDMS before 1.4.2 allows remote attackers to execute arbitrary SQL commands via the folderid parameter.</descript>
    </desc>
    <sols>
      <sol source="nvd">This was fixed in version 1.4.2.</sol>
    </sols>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/17054" source="XF" patch="1" adv="1">mydms-folderld-sql-injection(17054)</ref>
      <ref url="http://www.securityfocus.com/bid/10996" source="BID" patch="1" adv="1">10996</ref>
      <ref url="http://secunia.com/advisories/12340" source="SECUNIA" patch="1" adv="1">12340</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109314495007280&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20040820 Multiple vulnerabilities in  MyDMS</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mydms" name="mydms">
        <vers num="1.4" />
        <vers num="1.4.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1733" published="2004-08-20" name="CVE-2004-1733" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in MyDMS 1.4.2 and other versions allows remote registered users to read arbitrary files via .. (dot dot) sequences in the URL.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/17058" source="XF" patch="1" adv="1">mydms-dotdot-file-download(17058)</ref>
      <ref url="http://www.securityfocus.com/bid/10996" source="BID" patch="1" adv="1">10996</ref>
      <ref url="http://secunia.com/advisories/12340" source="SECUNIA" patch="1" adv="1">12340</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109314495007280&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20040820 Multiple vulnerabilities in  MyDMS</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mydms" name="mydms">
        <vers num="1.4" />
        <vers num="1.4.1" />
        <vers num="1.4.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-1734" published="2004-12-31" name="CVE-2004-1734" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">PHP remote file inclusion vulnerability in Mantis 0.19.0a allows remote attackers to execute arbitrary PHP code by modifying the (1) t_core_path parameter to bug_api.php or (2) t_core_dir parameter to relationship_api.php to reference a URL on a remote web server that contains the code.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/10993" source="BID" patch="1">10993</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109313416727851&amp;w=2" source="BUGTRAQ" patch="1">20040820 Mantis Bugtracker Remote PHP Code Execution Vulnerability</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/17065" source="XF">mantis-php-file-include(17065)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mantis" name="mantis">
        <vers num="0.19.0a" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1735" published="2004-08-21" name="CVE-2004-1735" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in the create list option in Sympa 4.1.x and earlier allows remote authenticated users to inject arbitrary web script or HTML via the description field.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/17057" source="XF" adv="1">sympa-description-xss(17057)</ref>
      <ref url="http://www.securityfocus.com/bid/10992" source="BID" adv="1">10992</ref>
      <ref url="http://secunia.com/advisories/12339" source="SECUNIA" adv="1">12339</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109312475207604&amp;w=2" source="BUGTRAQ" adv="1">20040820 Cross Site Scripting Vulnerability in Sympa</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sympa" name="sympa">
        <vers num="4.0" />
        <vers num="4.1" />
        <vers num="4.1.1" />
        <vers num="4.1.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1736" published="2004-12-31" name="CVE-2004-1736" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Cacti 0.8.5a allows remote attackers to gain sensitive information via an HTTP request to (1) auth.php, (2) auth_login.php, (3) auth_changepassword.php, and possibly other php files, which reveal the installation path in a PHP error message.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/17014" source="XF">cacti-error-path-disclosure(17014)</ref>
      <ref url="http://secunia.com/advisories/12308" source="SECUNIA">12308</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109272483621038&amp;w=2" source="BUGTRAQ">20040816 SQL Injection in CACTI</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2004-August/025376.html" source="FULLDISC">20040816 SQL Injection in CACTI</ref>
    </refs>
    <vuln_soft>
      <prod vendor="the_cacti_group" name="cacti">
        <vers num="0.8.5a" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-1737" published="2004-08-16" name="CVE-2004-1737" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in auth_login.php in Cacti 0.8.5a allows remote attackers to execute arbitrary SQL commands and bypass authentication via the (1) username or (2) password parameters.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/17011" source="XF" patch="1" adv="1">cacti-authlogin-sql-injection(17011)</ref>
      <ref url="http://www.securityfocus.com/bid/10960" source="BID" patch="1" adv="1">10960</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200408-21.xml" source="GENTOO" patch="1" adv="1">GLSA-200408-21</ref>
      <ref url="http://secunia.com/advisories/12308" source="SECUNIA" patch="1" adv="1">12308</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109272483621038&amp;w=2" source="BUGTRAQ" adv="1">20040816 SQL Injection in CACTI</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2004-August/025376.html" source="FULLDISC">20040816 SQL Injection in CACTI</ref>
    </refs>
    <vuln_soft>
      <prod vendor="the_cacti_group" name="cacti">
        <vers num="0.6" />
        <vers num="0.6.1" />
        <vers num="0.6.2" />
        <vers num="0.6.3" />
        <vers num="0.6.4" />
        <vers num="0.6.5" />
        <vers num="0.6.6" />
        <vers num="0.6.7" />
        <vers num="0.6.8" />
        <vers num="0.6.8a" />
        <vers num="0.8" />
        <vers num="0.8.1" />
        <vers num="0.8.2" />
        <vers num="0.8.2a" />
        <vers num="0.8.3" />
        <vers num="0.8.3a" />
        <vers num="0.8.4" />
        <vers num="0.8.5" />
        <vers num="0.8.5a" />
      </prod>
      <prod vendor="gentoo" name="linux">
        <vers num="1.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1738" published="2004-12-31" name="CVE-2004-1738" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in page.php in JShop allows remote attackers to inject arbitrary web script or HTML via the xPage parameter.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/17075" source="XF">jshop-page-xpage-xss(17075)</ref>
      <ref url="http://securitytracker.com/id?1011020" source="SECTRACK">1011020</ref>
      <ref url="http://secunia.com/advisories/12345" source="SECUNIA">12345</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109327547026265&amp;w=2" source="BUGTRAQ">20040823 JShop Input Validation Hole in 'page.php' Permits Cross-Site</ref>
      <ref url="http://indohack.sourceforge.net/drponidi/jshop-vuln.txt" source="MISC">http://indohack.sourceforge.net/drponidi/jshop-vuln.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="jshop_e-commerce" name="jshop_server">
        <vers num="1.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1739" published="2004-08-23" name="CVE-2004-1739" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Bird Chat 1.61 allows remote attackers to cause a denial of service (crash) via invalid users.</descript>
    </desc>
    <sols>
      <sol source="nvd">This has been fixed in version 1.61 Security Release.</sol>
    </sols>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/12365" source="SECUNIA" patch="1" adv="1">12365</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/17080" source="XF" adv="1">bird-chat-dos(17080)</ref>
      <ref url="http://www.securityfocus.com/bid/11010" source="BID" adv="1">11010</ref>
      <ref url="http://www.autistici.org/fdonato/advisory/BirdChat1.61-adv.txt" source="MISC">http://www.autistici.org/fdonato/advisory/BirdChat1.61-adv.txt</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109327938924287&amp;w=2" source="BUGTRAQ" adv="1">20040823 DoS in Bird Chat 1.61</ref>
    </refs>
    <vuln_soft>
      <prod vendor="bird_chat" name="internet_chat_server">
        <vers num="1.61" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1740" published="2004-08-23" name="CVE-2004-1740" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Music daemon (musicd) 0.0.3 and earlier allows remote attackers to read arbitrary files by calling LOAD with a full pathname, then calling SHOWLIST.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://musicdaemon.sourceforge.net/" source="CONFIRM" patch="1">http://musicdaemon.sourceforge.net/</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/17067" source="XF" adv="1">musicd-commands-view-files(17067)</ref>
      <ref url="http://www.securityfocus.com/bid/11006" source="BID" adv="1">11006</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109329098806595&amp;w=2" source="BUGTRAQ" adv="1">20040823 MusicDaemon &lt;= 0.0.3 /etc/shadow Stealer / DoS Exploit</ref>
    </refs>
    <vuln_soft>
      <prod vendor="music_daemon" name="music_daemon">
        <vers num="0.1" />
        <vers num="0.2" />
        <vers num="0.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1741" published="2004-08-23" name="CVE-2004-1741" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Music daemon (musicd) 0.0.3 and earlier allows remote attackers to cause a denial of service (crash) by calling LOAD with a binary file as an argument, then calling SHOWLIST.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://musicdaemon.sourceforge.net/" source="CONFIRM" patch="1">http://musicdaemon.sourceforge.net/</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/17068" source="XF" adv="1">musicd-load-showlist-dos(17068)</ref>
      <ref url="http://www.securityfocus.com/bid/11006" source="BID" adv="1">11006</ref>
      <ref url="http://securitytracker.com/id?1011025" source="SECTRACK">1011025</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109329098806595&amp;w=2" source="BUGTRAQ" adv="1">20040823 MusicDaemon &lt;= 0.0.3 /etc/shadow Stealer / DoS Exploit</ref>
    </refs>
    <vuln_soft>
      <prod vendor="music_daemon" name="music_daemon">
        <vers num="0.1" />
        <vers num="0.2" />
        <vers num="0.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1742" published="2004-08-24" name="CVE-2004-1742" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in WebAPP 0.9.9 allows remote attackers to view arbitrary files via a .. (dot dot) in the viewcat parameter.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/12373" source="SECUNIA" patch="1" adv="1">12373</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/17100" source="XF" adv="1">webapp-dotdot-directory-traversal(17100)</ref>
      <ref url="http://www.securityfocus.com/bid/11028" source="BID" adv="1">11028</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109336268002879&amp;w=2" source="BUGTRAQ" adv="1">20040824 WebAPP directory traversal and ability to retrieve the DES encrypted password hash</ref>
      <ref url="http://cornerstone.web-app.org/cgi-bin/index.cgi?action=downloadinfo&amp;cat=updates&amp;id=1" source="CONFIRM">http://cornerstone.web-app.org/cgi-bin/index.cgi?action=downloadinfo&amp;cat=updates&amp;id=1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="web-app.org" name="webapp">
        <vers num="0.9.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1743" published="2004-08-24" name="CVE-2004-1743" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Easy File Sharing (EFS) Webserver 1.25 allows remote attackers to view arbitrary files via an HTTP request for the disk_c virtual folder.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/17109" source="XF" adv="1">easyfilesharing-obtain-info(17109)</ref>
      <ref url="http://www.securityfocus.com/bid/11034" source="BID" adv="1">11034</ref>
      <ref url="http://www.gulftech.org/?node=research&amp;article_id=00045-08242004" source="MISC" adv="1">http://www.gulftech.org/?node=research&amp;article_id=00045-08242004</ref>
      <ref url="http://securitytracker.com/id?1011045" source="SECTRACK" adv="1">1011045</ref>
      <ref url="http://secunia.com/advisories/12372" source="SECUNIA" adv="1">12372</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109341398102863&amp;w=2" source="BUGTRAQ" adv="1">20040824 Easy File Sharing Webserver v1.25 Vulnerabilities</ref>
    </refs>
    <vuln_soft>
      <prod vendor="efs_software" name="efs_web_server">
        <vers num="1.2" />
        <vers num="1.25" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1744" published="2004-08-24" name="CVE-2004-1744" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Easy File Sharing (EFS) Webserver 1.25 allows remote attackers to cause a denial of service (CPU consumption or crash) via many large HTTP requests.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input bound="1" />
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/17110" source="XF" adv="1">easyfilesharing-http-request-dos(17110)</ref>
      <ref url="http://www.securityfocus.com/bid/11036" source="BID" adv="1">11036</ref>
      <ref url="http://www.osvdb.org/9175" source="OSVDB">9175</ref>
      <ref url="http://www.gulftech.org/?node=research&amp;article_id=00045-08242004" source="MISC" adv="1">http://www.gulftech.org/?node=research&amp;article_id=00045-08242004</ref>
      <ref url="http://securitytracker.com/id?1011045" source="SECTRACK">1011045</ref>
      <ref url="http://secunia.com/advisories/12372" source="SECUNIA" adv="1">12372</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109341398102863&amp;w=2" source="BUGTRAQ" adv="1">20040824 Easy File Sharing Webserver v1.25 Vulnerabilities</ref>
    </refs>
    <vuln_soft>
      <prod vendor="efs_software" name="efs_web_server">
        <vers num="1.2" />
        <vers num="1.25" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1745" published="2004-08-24" name="CVE-2004-1745" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Buffer overflow in Painkiller 1.3.1 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long password.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/17101" source="XF" adv="1">painkiller-long-password-bo(17101)</ref>
      <ref url="http://www.securityfocus.com/bid/11029" source="BID" adv="1">11029</ref>
      <ref url="http://secunia.com/advisories/12367" source="SECUNIA" adv="1">12367</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109339761608821&amp;w=2" source="BUGTRAQ" adv="1">20040824 Limited buffer overflow in Painkiller 1.31</ref>
    </refs>
    <vuln_soft>
      <prod vendor="people_can_fly" name="painkiller">
        <vers num="1.3.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1746" published="2004-12-31" name="CVE-2004-1746" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in index.php in PHP Code Snippet Library allows remote attackers to inject arbitrary web script or HTML via the (1) cat_select or (2) show parameters.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/17108" source="XF">snippet-index-xss(17108)</ref>
      <ref url="http://www.securityfocus.com/bid/11038" source="BID">11038</ref>
      <ref url="http://secunia.com/advisories/12370" source="SECUNIA">12370</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109340580218818&amp;w=2" source="BUGTRAQ">20040824 PHP Code Snippet Library Multiple Cross-Site Scripting (XSS)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="php_code_snippet_library" name="php_code_snippet_library">
        <vers num="0.8" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1747" published="2004-12-31" name="CVE-2004-1747" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in NetworkEverywhere NR041 running firmware 1.2 Release 03 allows remote attackers to inject arbitrary web script or HTML via the DHCP HOSTNAME option.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/17120" source="XF">network-everywhere-dhcp-gain-access(17120)</ref>
      <ref url="http://www.securityfocus.com/bid/11046" source="BID">11046</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109344996523392&amp;w=2" source="BUGTRAQ">20040825 bug found</ref>
    </refs>
    <vuln_soft>
      <prod vendor="network_everywhere" name="nr041">
        <vers num="1.2_release_03" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2004-1748" published="2004-12-31" name="CVE-2004-1748" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">NtRegmon before 6.12 allows local users to cause a denial of service (crash), while NtRegmon is running, via invalid pointers to hook functions such as ZwSetQueryValue.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
      <exception />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/17106" source="XF">ntregmon-registry-dos(17106)</ref>
      <ref url="http://www.securityfocus.com/bid/11042" source="BID">11042</ref>
      <ref url="http://www.ngsec.com/docs/advisories/NGSEC-2004-7.txt" source="MISC">http://www.ngsec.com/docs/advisories/NGSEC-2004-7.txt</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109345177124374&amp;w=2" source="BUGTRAQ">20040825 [NGSEC-2004-7] NtRegmon, local system denial of service.</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sysinternals" name="regmon">
        <vers prev="1" num="6.11" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1749" published="2004-07-22" name="CVE-2004-1749" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Attack Mitigator IPS 5500 3.11.008, and possibly other versions, when configured in a one-armed routing configuration, allows remote attackers to cause a denial of service (CPU consumption) via a large number of HTTP requests.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/17125" source="XF" patch="1" adv="1">am-ips5500-http-dos(17125)</ref>
      <ref url="http://www.securityfocus.com/bid/11049" source="BID" patch="1" adv="1">11049</ref>
      <ref url="http://secunia.com/advisories/12390" source="SECUNIA" patch="1" adv="1">12390</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109345253016318&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20040825 IRM 010: Top Layer Attack Mitigator IPS 5500 Denial of Service</ref>
    </refs>
    <vuln_soft>
      <prod vendor="toplayer" name="attack_mitigator">
        <vers num="5500_3.11.008" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1750" published="2004-12-31" name="CVE-2004-1750" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">RealVNC 4.0 and earlier allows remote attackers to cause a denial of service (crash) via a large number of connections to port 5900.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <design />
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/17123" source="XF">realvnc-multiple-connections-dos(17123)</ref>
      <ref url="http://www.securityfocus.com/bid/11048" source="BID">11048</ref>
      <ref url="http://secunia.com/advisories/13143" source="SECUNIA">13143</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109346198700529&amp;w=2" source="BUGTRAQ">20040825 RealVNC 4.0 DoS</ref>
    </refs>
    <vuln_soft>
      <prod vendor="vnc" name="realvnc">
        <vers num="4.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1751" published="2004-08-26" name="CVE-2004-1751" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Ground Control II: Operation Exodus 1.0.0.7 and earlier allows remote servers to cause a denial of service (client or server crash) via a large packet, which generates a "Message too long" socket error that is treated as a critical error.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input bound="1" />
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/17130" source="XF" patch="1" adv="1">ground-control-dos(17130)</ref>
      <ref url="http://www.securityfocus.com/bid/11058" source="BID" patch="1" adv="1">11058</ref>
      <ref url="http://securitytracker.com/id?1011075" source="SECTRACK" patch="1" adv="1">1011075</ref>
      <ref url="http://aluigi.altervista.org/adv/gc2boom-adv.txt" source="MISC" patch="1" adv="1">http://aluigi.altervista.org/adv/gc2boom-adv.txt</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109357154602892&amp;w=2" source="BUGTRAQ">20040826 Broadcast forced exit in Ground Control II 1.0.0.7</ref>
    </refs>
    <vuln_soft>
      <prod vendor="massive_entertainment" name="ground_control_ii_operation_exodus">
        <vers num="1.0.0.7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-1752" published="2004-08-24" name="CVE-2004-1752" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Stack-based buffer overflow in Gaucho 1.4 Build 145 allows remote attackers to execute arbitrary code via a POP3 email with a long Content-Type header.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/17090" source="XF" patch="1" adv="1">gaucho-pop3-bo(17090)</ref>
      <ref url="http://www.securityfocus.com/bid/11023" source="BID" patch="1" adv="1">11023</ref>
      <ref url="http://www.security.org.sg/vuln/gaucho140.html" source="MISC" patch="1" adv="1">http://www.security.org.sg/vuln/gaucho140.html</ref>
      <ref url="http://securitytracker.com/id?1011032" source="SECTRACK" patch="1" adv="1">1011032</ref>
      <ref url="http://secunia.com/advisories/12387" source="SECUNIA" patch="1" adv="1">12387</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109364123707953&amp;w=2" source="BUGTRAQ" adv="1">20040826 Gaucho v1.4 Build 145 Buffer Overflow</ref>
    </refs>
  </entry>
  <entry type="CVE" severity="Low" seq="2004-1753" published="2004-12-31" name="CVE-2004-1753" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:P/A:N)" CVSS_score="2.6" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="4.9" CVSS_base_score="2.6">
    <desc>
      <descript source="cve">The Apple Java plugin, as used in Netscape 7.1 and 7.2, Mozilla 1.7.2, and Firefox 0.9.3 on MacOS X 10.3.5, when tabbed browsing is enabled, does not properly handle SetWindow(NULL) calls, which allows Java applets from one tab to draw to other tabs and facilitates phishing attacks that spoof tabs.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/17137" source="XF">netscape-java-tab-spoofing(17137)</ref>
      <ref url="http://www.securityfocus.com/bid/11059" source="BID">11059</ref>
      <ref url="http://www.securityfocus.com/archive/1/373309" source="BUGTRAQ">20040827 Re: Netscape Navigator 7.2 failure to isolate browser tabs (was Re: Computer Network Defence Vulnerability Alert State)</ref>
      <ref url="http://www.securityfocus.com/archive/1/373232" source="BUGTRAQ">20040827 Re: Netscape Navigator 7.2 failure to isolate browser tabs (was Re: Computer Network Defence Vulnerability Alert State)</ref>
      <ref url="http://www.securityfocus.com/archive/1/373080" source="BUGTRAQ">20040826 Netscape Navigator 7.2 failure to isolate browser tabs (was Re: Computer Network Defence Vulnerability Alert State)</ref>
      <ref url="http://secunia.com/advisories/12392" source="SECUNIA">12392</ref>
      <ref url="http://bugzilla.mozilla.org/show_bug.cgi?id=162134" source="MISC">http://bugzilla.mozilla.org/show_bug.cgi?id=162134</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="firefox">
        <vers num="0.9.3" />
      </prod>
      <prod vendor="mozilla" name="mozilla">
        <vers num="1.7.2" />
      </prod>
      <prod vendor="netscape" name="navigator">
        <vers num="7.1" />
        <vers num="7.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1754" published="2004-06-15" name="CVE-2004-1754" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The DNS proxy (DNSd) for multiple Symantec Gateway Security products allows remote attackers to poison the DNS cache via a malicious DNS server query response that contains authoritative or additional records.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <access />
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/10557" source="BID" patch="1" adv="1">10557</ref>
      <ref url="http://securityresponse.symantec.com/avcenter/security/Content/2004.06.21.html" source="CONFIRM" patch="1" adv="1">http://securityresponse.symantec.com/avcenter/security/Content/2004.06.21.html</ref>
      <ref url="http://secunia.com/advisories/11888" source="SECUNIA" patch="1" adv="1">11888</ref>
      <ref url="http://lists.virus.org/bugtraq-0406/msg00234.html" source="BUGTRAQ" adv="1">20040615 Symantec Enterprise Firewall DNSD cache poisoning Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="symantec" name="enterprise_firewall">
        <vers num="7.0.4" edition="" />
        <vers num="7.0.4" edition=":solaris" />
        <vers num="7.0.4" edition=":windows_2000_nt" />
        <vers num="8.0" edition="" />
        <vers num="8.0" edition=":solaris" />
        <vers num="8.0" edition=":windows_2000_nt" />
      </prod>
      <prod vendor="symantec" name="gateway_security">
        <vers num="5110_1.0" />
        <vers num="5200_1.0" />
        <vers num="5300_1.0" />
        <vers num="5310_1.0" />
        <vers num="5400_2.0" />
        <vers num="5400_2.0.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-1755" published="2004-12-31" name="CVE-2004-1755" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">The Web Services fat client for BEA WebLogic Server and Express 7.0 SP4 and earlier, when using 2-way SSL and multiple certificates to connect to the same URL, may use the incorrect identity after the first connection, which could allow users to gain privileges.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/858990" source="CERT-VN" adv="1">VU#858990</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15826" source="XF" patch="1">weblogic-multiple-connection-gain-access(15826)</ref>
      <ref url="http://www.securityfocus.com/bid/9502" source="BID" patch="1">9502</ref>
      <ref url="http://secunia.com/advisories/10725" source="SECUNIA" patch="1">10725</ref>
      <ref url="http://dev2dev.bea.com/resourcelibrary/advisoriesnotifications/BEA04_47.00.jsp" source="CONFIRM" patch="1">http://dev2dev.bea.com/resourcelibrary/advisoriesnotifications/BEA04_47.00.jsp</ref>
    </refs>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1756" published="2004-04-13" name="CVE-2004-1756" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">BEA WebLogic Server and WebLogic Express 8.1 SP2 and earlier, and 7.0 SP4 and earlier, when using 2-way SSL with a custom trust manager, may accept a certificate chain even if the trust manager rejects it, which allows remote attackers to spoof other users or servers.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/566390" source="CERT-VN" patch="1" adv="1">VU#566390</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15862" source="XF" patch="1" adv="1">weblogic-trust-certificate-spoofing(15862)</ref>
      <ref url="http://www.securityfocus.com/bid/10132" source="BID" patch="1" adv="1">10132</ref>
      <ref url="http://securitytracker.com/id?1009765" source="SECTRACK" patch="1" adv="1">1009765</ref>
      <ref url="http://secunia.com/advisories/11358" source="SECUNIA" patch="1" adv="1">11358</ref>
      <ref url="http://dev2dev.bea.com/resourcelibrary/advisoriesnotifications/BEA04_54.00.jsp" source="CONFIRM" patch="1" adv="1">http://dev2dev.bea.com/resourcelibrary/advisoriesnotifications/BEA04_54.00.jsp</ref>
    </refs>
    <vuln_soft>
      <prod vendor="bea" name="weblogic_server">
        <vers num="7.0" edition="" />
        <vers num="7.0" edition=":win32" />
        <vers num="7.0" edition=":express" />
        <vers num="7.0" edition="sp1" />
        <vers num="7.0" edition="sp1:express" />
        <vers num="7.0" edition="sp2" />
        <vers num="7.0" edition="sp2:express" />
        <vers num="7.0" edition="sp3" />
        <vers num="7.0" edition="sp3:express" />
        <vers num="7.0" edition="sp4" />
        <vers num="7.0" edition="sp4:win32" />
        <vers num="7.0" edition="sp4:express" />
        <vers num="8.1" edition="" />
        <vers num="8.1" edition=":win32" />
        <vers num="8.1" edition=":express" />
        <vers num="8.1" edition="sp1" />
        <vers num="8.1" edition="sp1:express" />
        <vers num="8.1" edition="sp1:win32" />
        <vers num="8.1" edition="sp2" />
        <vers num="8.1" edition="sp2:express" />
        <vers num="8.1" edition="sp2:win32" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1757" published="2004-12-31" name="CVE-2004-1757" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">BEA WebLogic Server and Express 8.1, SP1 and earlier, stores the administrator password in cleartext in config.xml, which allows local users to gain privileges.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/350350" source="CERT-VN" adv="1">VU#350350</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/14957" source="XF" patch="1">weblogic-boot-password-disclosure(14957)</ref>
      <ref url="http://www.securityfocus.com/bid/9501" source="BID" patch="1">9501</ref>
      <ref url="http://secunia.com/advisories/10728" source="SECUNIA" patch="1">10728</ref>
      <ref url="http://dev2dev.bea.com/resourcelibrary/advisoriesnotifications/BEA04_50.00.jsp" source="CONFIRM" patch="1" adv="1">http://dev2dev.bea.com/resourcelibrary/advisoriesnotifications/BEA04_50.00.jsp</ref>
    </refs>
    <vuln_soft>
      <prod vendor="bea" name="weblogic_server">
        <vers num="6.1" edition="" />
        <vers num="6.1" edition=":express" />
        <vers num="6.1" edition=":win32" />
        <vers num="6.1" edition="sp1" />
        <vers num="6.1" edition="sp1:express" />
        <vers num="6.1" edition="sp1:win32" />
        <vers num="6.1" edition="sp2" />
        <vers num="6.1" edition="sp2:win32" />
        <vers num="6.1" edition="sp3" />
        <vers num="6.1" edition="sp3:win32" />
        <vers num="6.1" edition="sp3:express" />
        <vers num="6.1" edition="sp4" />
        <vers num="6.1" edition="sp4:win32" />
        <vers num="6.1" edition="sp4:express" />
        <vers num="6.1" edition="sp5" />
        <vers num="6.1" edition="sp5:win32" />
        <vers num="6.1" edition="sp5:express" />
        <vers num="6.1" edition="sp6" />
        <vers num="6.1" edition="sp6:win32" />
        <vers num="7.0" edition="" />
        <vers num="7.0" edition=":win32" />
        <vers num="7.0" edition=":express" />
        <vers num="7.0" edition="sp1" />
        <vers num="7.0" edition="sp1:express" />
        <vers num="7.0" edition="sp1:win32" />
        <vers num="7.0" edition="sp2" />
        <vers num="7.0" edition="sp2:win32" />
        <vers num="7.0" edition="sp2:express" />
        <vers num="7.0" edition="sp3" />
        <vers num="7.0" edition="sp3:win32" />
        <vers num="7.0" edition="sp3:express" />
        <vers num="7.0" edition="sp4" />
        <vers num="7.0" edition="sp4:express" />
        <vers num="7.0" edition="sp4:win32" />
        <vers num="7.0" edition="sp5" />
        <vers num="7.0" edition="sp5:win32" />
        <vers num="7.0" edition="sp5:express" />
        <vers num="8.1" edition="" />
        <vers num="8.1" edition=":express" />
        <vers num="8.1" edition=":win32" />
        <vers num="8.1" edition="sp1" />
        <vers num="8.1" edition="sp1:express" />
        <vers num="8.1" edition="sp1:win32" />
        <vers num="8.1" edition="sp2" />
        <vers num="8.1" edition="sp2:express" />
        <vers num="8.1" edition="sp2:win32" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1758" published="2004-04-13" name="CVE-2004-1758" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">BEA WebLogic Server and WebLogic Express version 8.1 up to SP2, 7.0 up to SP4, and 6.1 up to SP6 may store the database username and password for an untargeted JDBC connection pool in plaintext in config.xml, which allows local users to gain privileges.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/920238" source="CERT-VN" patch="1" adv="1">VU#920238</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15860" source="XF" patch="1" adv="1">bea-configxml-plaintext-password(15860)</ref>
      <ref url="http://www.securityfocus.com/bid/10131" source="BID" patch="1" adv="1">10131</ref>
      <ref url="http://dev2dev.bea.com/resourcelibrary/advisoriesnotifications/BEA04_53.00.jsp" source="CONFIRM" patch="1" adv="1">http://dev2dev.bea.com/resourcelibrary/advisoriesnotifications/BEA04_53.00.jsp</ref>
      <ref url="http://www.osvdb.org/5297" source="OSVDB">5297</ref>
      <ref url="http://securitytracker.com/id?1009764" source="SECTRACK">1009764</ref>
      <ref url="http://secunia.com/advisories/11357" source="SECUNIA">11357</ref>
    </refs>
    <vuln_soft>
      <prod vendor="bea" name="weblogic_server">
        <vers num="6.1" edition="" />
        <vers num="6.1" edition=":express" />
        <vers num="6.1" edition=":win32" />
        <vers num="6.1" edition="sp1" />
        <vers num="6.1" edition="sp1:express" />
        <vers num="6.1" edition="sp1:win32" />
        <vers num="6.1" edition="sp2" />
        <vers num="6.1" edition="sp2:win32" />
        <vers num="6.1" edition="sp2:express" />
        <vers num="6.1" edition="sp3" />
        <vers num="6.1" edition="sp3:express" />
        <vers num="6.1" edition="sp4" />
        <vers num="6.1" edition="sp4:express" />
        <vers num="6.1" edition="sp5" />
        <vers num="6.1" edition="sp5:express" />
        <vers num="6.1" edition="sp6" />
        <vers num="7.0" edition="" />
        <vers num="7.0" edition=":win32" />
        <vers num="7.0" edition=":express" />
        <vers num="7.0" edition="sp1" />
        <vers num="7.0" edition="sp1:express" />
        <vers num="7.0" edition="sp2" />
        <vers num="7.0" edition="sp2:express" />
        <vers num="7.0" edition="sp3" />
        <vers num="7.0" edition="sp3:express" />
        <vers num="7.0" edition="sp4" />
        <vers num="7.0" edition="sp4:express" />
        <vers num="7.0" edition="sp4:win32" />
        <vers num="8.1" edition="" />
        <vers num="8.1" edition=":express" />
        <vers num="8.1" edition=":win32" />
        <vers num="8.1" edition="sp1" />
        <vers num="8.1" edition="sp1:express" />
        <vers num="8.1" edition="sp1:win32" />
        <vers num="8.1" edition="sp2" />
        <vers num="8.1" edition="sp2:express" />
        <vers num="8.1" edition="sp2:win32" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1759" published="2004-01-21" name="CVE-2004-1759" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Cisco voice products, when running the IBM Director Agent on IBM servers before OS 2000.2.6, allows remote attackers to cause a denial of service (CPU consumption) via arbitrary packets to TCP port 14247, as demonstrated using port scanning.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/721092" source="CERT-VN" patch="1" adv="1">VU#721092</ref>
      <ref url="http://www.securityfocus.com/bid/9469" source="BID" patch="1" adv="1">9469</ref>
      <ref url="http://www.cisco.com/warp/public/707/cisco-sa-20040121-voice.shtml" source="CISCO" patch="1" adv="1">20040121 Voice Product Vulnerabilities on IBM Servers</ref>
      <ref url="http://secunia.com/advisories/10696" source="SECUNIA" patch="1" adv="1">10696</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/14901" source="XF" adv="1">ciscovoice-ibmservers-dos(14901)</ref>
      <ref url="http://www.securitytracker.com/id?1008814" source="SECTRACK">1008814</ref>
      <ref url="http://www.osvdb.org/3691" source="OSVDB">3691</ref>
      <ref url="http://www.ciac.org/ciac/bulletins/o-066.shtml" source="CIAC">O-066</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="emergency_responder">
        <vers num="1.1" />
      </prod>
      <prod vendor="cisco" name="ip_call_center_express_enhanced">
        <vers num="3.0" />
      </prod>
      <prod vendor="cisco" name="ip_call_center_express_standard">
        <vers num="3.0" />
      </prod>
      <prod vendor="cisco" name="ip_interactive_voice_response">
        <vers num="3.0" />
      </prod>
      <prod vendor="cisco" name="personal_assistant">
        <vers num="1.3(1)" />
        <vers num="1.3(2)" />
        <vers num="1.3(3)" />
        <vers num="1.3(4)" />
        <vers num="1.4(1)" />
        <vers num="1.4(2)" />
      </prod>
      <prod vendor="ibm" name="director_agent">
        <vers num="2.2" />
        <vers num="3.11" />
      </prod>
      <prod vendor="cisco" name="call_manager">
        <vers num="1.0" />
        <vers num="2.0" />
        <vers num="3.0" />
        <vers num="3.1" />
        <vers num="3.1(2)" />
        <vers num="3.1(3a)" />
        <vers num="3.2" />
        <vers num="3.3" />
        <vers num="3.3(3)" />
        <vers num="4.0" />
      </prod>
      <prod vendor="cisco" name="internet_service_node">
        <vers num="" />
      </prod>
      <prod vendor="ibm" name="mcs-7815-1000">
        <vers num="" />
      </prod>
      <prod vendor="ibm" name="mcs-7815i-2.0">
        <vers num="" />
      </prod>
      <prod vendor="ibm" name="mcs-7835i-2.4">
        <vers num="" />
      </prod>
      <prod vendor="ibm" name="mcs-7835i-3.0">
        <vers num="" />
      </prod>
      <prod vendor="ibm" name="x330">
        <vers num="8654" />
        <vers num="8674" />
      </prod>
      <prod vendor="ibm" name="x340">
        <vers num="" />
      </prod>
      <prod vendor="ibm" name="x342">
        <vers num="" />
      </prod>
      <prod vendor="ibm" name="x345">
        <vers num="" />
      </prod>
      <prod vendor="cisco" name="conference_connection">
        <vers num="1.1(1)" />
        <vers num="1.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-1760" published="2004-01-21" name="CVE-2004-1760" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">The default installation of Cisco voice products, when running the IBM Director Agent on IBM servers before OS 2000.2.6, does not require authentication, which allows remote attackers to gain administrator privileges by connecting to TCP port 14247.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/602734" source="CERT-VN" patch="1" adv="1">VU#602734</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/14900" source="XF" patch="1" adv="1">ciscovoice-ibmservers-admin-access(14900)</ref>
      <ref url="http://www.securityfocus.com/bid/9468" source="BID" patch="1" adv="1">9468</ref>
      <ref url="http://www.cisco.com/warp/public/707/cisco-sa-20040121-voice.shtml" source="CISCO" patch="1" adv="1">20040121 Voice Product Vulnerabilities on IBM Servers</ref>
      <ref url="http://secunia.com/advisories/10696" source="SECUNIA" patch="1" adv="1">10696</ref>
      <ref url="http://www.securitytracker.com/id?1008814" source="SECTRACK">1008814</ref>
      <ref url="http://www.osvdb.org/3692" source="OSVDB">3692</ref>
      <ref url="http://www.ciac.org/ciac/bulletins/o-066.shtml" source="CIAC">O-066</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="emergency_responder">
        <vers num="1.1" />
      </prod>
      <prod vendor="cisco" name="ip_call_center_express_enhanced">
        <vers num="3.0" />
      </prod>
      <prod vendor="cisco" name="ip_call_center_express_standard">
        <vers num="3.0" />
      </prod>
      <prod vendor="cisco" name="ip_interactive_voice_response">
        <vers num="3.0" />
      </prod>
      <prod vendor="cisco" name="personal_assistant">
        <vers num="1.3(1)" />
        <vers num="1.3(2)" />
        <vers num="1.3(3)" />
        <vers num="1.3(4)" />
        <vers num="1.4(1)" />
        <vers num="1.4(2)" />
      </prod>
      <prod vendor="ibm" name="director_agent">
        <vers num="2.2" />
        <vers num="3.11" />
      </prod>
      <prod vendor="cisco" name="call_manager">
        <vers num="1.0" />
        <vers num="2.0" />
        <vers num="3.0" />
        <vers num="3.1" />
        <vers num="3.1(2)" />
        <vers num="3.1(3a)" />
        <vers num="3.2" />
        <vers num="3.3" />
        <vers num="3.3(3)" />
        <vers num="4.0" />
      </prod>
      <prod vendor="cisco" name="internet_service_node">
        <vers num="" />
      </prod>
      <prod vendor="ibm" name="mcs-7815-1000">
        <vers num="" />
      </prod>
      <prod vendor="ibm" name="mcs-7815i-2.0">
        <vers num="" />
      </prod>
      <prod vendor="ibm" name="mcs-7835i-2.4">
        <vers num="" />
      </prod>
      <prod vendor="ibm" name="mcs-7835i-3.0">
        <vers num="" />
      </prod>
      <prod vendor="ibm" name="x330">
        <vers num="8654" />
        <vers num="8674" />
      </prod>
      <prod vendor="ibm" name="x340">
        <vers num="" />
      </prod>
      <prod vendor="ibm" name="x342">
        <vers num="" />
      </prod>
      <prod vendor="ibm" name="x345">
        <vers num="" />
      </prod>
      <prod vendor="cisco" name="conference_connection">
        <vers num="1.1(1)" />
        <vers num="1.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1761" published="2004-12-31" name="CVE-2004-1761" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Unknown vulnerability in Ethereal 0.8.13 to 0.10.2 allows attackers to cause a denial of service (segmentation fault) via a malformed color filter file.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/695486" source="CERT-VN">VU#695486</ref>
      <ref url="http://secunia.com/advisories/11185" source="SECUNIA" patch="1">11185</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15572" source="XF">ethereal-colour-filter-dos(15572)</ref>
      <ref url="http://www.ethereal.com/appnotes/enpa-sa-00013.html" source="CONFIRM">http://www.ethereal.com/appnotes/enpa-sa-00013.html</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10013" source="OVAL">oval:org.mitre.oval:def:10013</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-136.html" source="REDHAT">RHSA-2004:136</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ethereal_group" name="ethereal">
        <vers num="0.10.0" />
        <vers num="0.10.0a" />
        <vers num="0.10.1" />
        <vers num="0.10.2" />
        <vers num="0.8.13" />
        <vers num="0.8.14" />
        <vers num="0.8.15" />
        <vers num="0.8.16" />
        <vers num="0.8.17a" />
        <vers num="0.8.18" />
        <vers num="0.8.19" />
        <vers num="0.8.20" />
        <vers num="0.9.0" />
        <vers num="0.9.1" />
        <vers num="0.9.10" />
        <vers num="0.9.11" />
        <vers num="0.9.12" />
        <vers num="0.9.13" />
        <vers num="0.9.14" />
        <vers num="0.9.15" />
        <vers num="0.9.16" />
        <vers num="0.9.2" />
        <vers num="0.9.3" />
        <vers num="0.9.4" />
        <vers num="0.9.5" />
        <vers num="0.9.6" />
        <vers num="0.9.7" />
        <vers num="0.9.8" />
        <vers num="0.9.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-1762" published="2004-12-31" name="CVE-2004-1762" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Unknown vulnerability in F-Secure Anti-Virus (FSAV) 4.52 for Linux before Hotfix 3 allows the Sober.D worm to bypass FASV.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <other />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/415734" source="CERT-VN" patch="1" adv="1">VU#415734</ref>
      <ref url="http://support.f-secure.com/enu/corporate/downloads/hotfixes/av-linux-hotfixes.shtml" source="CONFIRM" patch="1">http://support.f-secure.com/enu/corporate/downloads/hotfixes/av-linux-hotfixes.shtml</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15432" source="XF">fsecure-antivirus-protection-bypass(15432)</ref>
      <ref url="http://secunia.com/advisories/11089" source="SECUNIA">11089</ref>
    </refs>
    <vuln_soft>
      <prod vendor="f-secure" name="f-secure_anti-virus">
        <vers num="4.50_hotfix_1" edition="" />
        <vers num="4.50_hotfix_1" edition=":linux" />
        <vers num="4.50_hotfix_2" edition="" />
        <vers num="4.50_hotfix_2" edition=":linux" />
        <vers num="4.51_hotfix_2" edition="" />
        <vers num="4.51_hotfix_2" edition=":linux" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-1763" published="2004-12-31" name="CVE-2004-1763" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Buffer overflow in hsrun.exe for HAHTsite Scenario Server 5.1 Patch 06 (build 91) allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long project name.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/705958" source="CERT-VN" adv="1">VU#705958</ref>
      <ref url="http://www.securityfocus.com/bid/10033" source="BID" patch="1">10033</ref>
      <ref url="http://secunia.com/advisories/11288" source="SECUNIA" patch="1">11288</ref>
      <ref url="http://marc.theaimsgroup.com/?l=full-disclosure&amp;m=108091662105032&amp;w=2" source="FULLDISC" patch="1">20040402 Buffer Overflow in HAHTsite Scenario Server 5.1</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15717" source="XF">hahtsite-long-request-bo(15717)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="haht_commerce" name="hahtsite_scenario_server">
        <vers num="5.1" />
        <vers num="5.1_patch_1" />
        <vers num="5.1_patch_2" />
        <vers num="5.1_patch_3" />
        <vers num="5.1_patch_4" />
        <vers num="5.1_patch_5" />
        <vers num="5.1_patch_6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-1764" published="2004-01-14" name="CVE-2004-1764" modified="2009-03-04" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Buffer overflow in CDE libDtSvc on HP-UX B.11.00, B.11.04, B.11.11, and B.11.22 allows local users to gain root privileges via unknown vectors.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/406406" source="CERT-VN" adv="1">VU#406406</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/14828" source="XF" patch="1" adv="1">hp-libdtsvc-bo(14828)</ref>
      <ref url="http://www.securityfocus.com/advisories/6237" source="HP" patch="1" adv="1">HPSBUX0401-308</ref>
      <ref url="http://www.ciac.org/ciac/bulletins/o-057.shtml" source="CIAC" adv="1">O-057</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5789" source="OVAL">oval:org.mitre.oval:def:5789</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hp" name="hp-ux">
        <vers num="11.00" />
        <vers num="11.11" />
        <vers num="11.22" />
        <vers num="11.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-1765" published="2004-12-31" name="CVE-2004-1765" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Off-by-one buffer overflow in ModSecurity (mod_security) 1.7.4 for Apache 2.x, when SecFilterScanPost is enabled, allows remote attackers to execute arbitrary code via crafted POST requests.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/779438" source="CERT-VN" adv="1">VU#779438</ref>
      <ref url="http://www.securityfocus.com/bid/9885" source="BID" patch="1">9885</ref>
      <ref url="http://secunia.com/advisories/11138" source="SECUNIA" patch="1">11138</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15489" source="XF">mod-security-offbyone-bo(15489)</ref>
      <ref url="http://www.s-quadra.com/advisories/Adv-20040315.txt" source="MISC">http://www.s-quadra.com/advisories/Adv-20040315.txt</ref>
      <ref url="http://www.modsecurity.org/" source="CONFIRM">http://www.modsecurity.org/</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107945597331370&amp;w=2" source="BUGTRAQ">20040316 ModSecurity 1.7.4 for Apache 2.x remote off-by-one overflow</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mod_security" name="mod_security">
        <vers num="1.7.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1766" published="2004-01-20" name="CVE-2004-1766" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The default installation of NetScreen-Security Manager before Feature Pack 1 does not enable encryption for communication with devices running ScreenOS 5.0, which allows remote attackers to obtain sensitive information via sniffing.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <config />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/CRDY-5VEU8N" source="CONFIRM" adv="1">http://www.kb.cert.org/vuls/id/CRDY-5VEU8N</ref>
      <ref url="http://www.kb.cert.org/vuls/id/927630" source="CERT-VN" adv="1">VU#927630</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/14886" source="XF" adv="1">netscreen-information-disclosure(14886)</ref>
      <ref url="http://www.securityfocus.com/bid/9455" source="BID" adv="1">9455</ref>
      <ref url="http://secunia.com/advisories/10675" source="SECUNIA" adv="1">10675</ref>
      <ref url="http://www.osvdb.org/3613" source="OSVDB">3613</ref>
      <ref url="http://www.juniper.net/support/security/alerts/58290.txt" source="CONFIRM">http://www.juniper.net/support/security/alerts/58290.txt</ref>
    </refs>
  </entry>
  <entry type="CVE" severity="High" seq="2004-1767" published="2004-12-31" name="CVE-2004-1767" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">The kernel in Solaris 2.6, 7, 8, and 9 allows local users to gain privileges by loading arbitrary loadable kernel modules (LKM), possibly involving the modload function.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/702526" source="CERT-VN" adv="1">VU#702526</ref>
      <ref url="http://www.securityfocus.com/bid/9477" source="BID" patch="1">9477</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-57479-1" source="SUNALERT" patch="1" adv="1">57479</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/14917" source="XF">solaris-kernel-module-gain-privilege(14917)</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:4532" source="OVAL" sig="1">oval:org.mitre.oval:def:4532</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="solaris">
        <vers num="2.6" />
        <vers num="7.0" edition="" />
        <vers num="7.0" edition=":x86" />
        <vers num="8.0" edition="" />
        <vers num="8.0" edition=":x86" />
        <vers num="9.0" edition="" />
        <vers num="9.0" edition=":sparc" />
        <vers num="9.0" edition=":x86" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1768" published="2004-12-17" name="CVE-2004-1768" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The character converters in the Spamhunter and Language ID modules for Symantec Brightmail AntiSpam 6.0.1 before patch 132 allow remote attackers to cause a denial of service (crash) via messages with the ISO-8859-10 character set, which is not recognized by the converters.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/697598" source="CERT-VN" patch="1" adv="1">VU#697598</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/18530" source="XF" patch="1" adv="1">symantec-brightmail-spamhunter-dos(18530)</ref>
      <ref url="http://www.osvdb.org/12459" source="OSVDB" patch="1" adv="1">12459</ref>
      <ref url="http://secunia.com/advisories/13489" source="SECUNIA" patch="1" adv="1">13489</ref>
      <ref url="ftp://ftp.symantec.com/public/english_us_canada/products/sba/sba_60x/updates/p132_notes.htm" source="CONFIRM" patch="1">ftp://ftp.symantec.com/public/english_us_canada/products/sba/sba_60x/updates/p132_notes.htm</ref>
    </refs>
    <vuln_soft>
      <prod vendor="symantec" name="brightmail_antispam">
        <vers num="6.0.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-1769" published="2004-03-11" name="CVE-2004-1769" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">The "Allow cPanel users to reset their password via email" feature in cPanel 9.1.0 build 34 and earlier, including 8.x, allows remote attackers to execute arbitrary code via the user parameter to resetpass.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/831534" source="CERT-VN" adv="1">VU#831534</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15443" source="XF" patch="1" adv="1">cpanel-resetpass-execute-commands(15443)</ref>
      <ref url="http://www.securityfocus.com/bid/9848" source="BID" adv="1">9848</ref>
      <ref url="http://www.securityfocus.com/archive/1/357064/2004-03-08/2004-03-14/0" source="BUGTRAQ" adv="1">20040311 Cpanel 8.*.* have a problem ?</ref>
      <ref url="http://secunia.com/advisories/11111" source="SECUNIA" adv="1">11111</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107904890724201&amp;w=2" source="BUGTRAQ" adv="1">20040311 cPanel Secuirty Advisory CPANEL-2004:01-01</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cpanel" name="cpanel">
        <vers num="5.0" />
        <vers num="5.3" />
        <vers num="6.0" />
        <vers num="6.2" />
        <vers num="6.4" />
        <vers num="6.4.1" />
        <vers num="6.4.2" />
        <vers num="6.4.2_stable_48" />
        <vers num="7.0" />
        <vers num="8.0" />
        <vers num="9.0" />
        <vers num="9.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-1770" published="2004-03-11" name="CVE-2004-1770" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">The login page for cPanel 9.1.0, and possibly other versions, allows remote attackers to execute arbitrary code via shell metacharacters in the user parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/831534" source="CERT-VN" patch="1" adv="1">VU#831534</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15486" source="XF" adv="1">cpanel-login-execute-commands(15486)</ref>
      <ref url="http://www.securityfocus.com/bid/9855" source="BID" adv="1">9855</ref>
      <ref url="http://secunia.com/advisories/11124" source="SECUNIA" adv="1">11124</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107911581732035&amp;w=2" source="BUGTRAQ">20040312 Cpanel 9.1.0 have a problem ?</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cpanel" name="cpanel">
        <vers num="5.0" />
        <vers num="5.3" />
        <vers num="6.0" />
        <vers num="6.2" />
        <vers num="6.4" />
        <vers num="6.4.1" />
        <vers num="6.4.2" />
        <vers num="6.4.2_stable_48" />
        <vers num="7.0" />
        <vers num="8.0" />
        <vers num="9.0" />
        <vers num="9.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1771" published="2004-11-30" name="CVE-2004-1771" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Scalable OGo (SOGo) 1.0 allows remote authenticated users to bypass intended permissions and view private appointments of other users.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/19820" source="XF" adv="1">ogo-permission-information-disclosure(19820)</ref>
      <ref url="http://www.osvdb.org/14675" source="OSVDB" adv="1">14675</ref>
      <ref url="http://securitytracker.com/id?1013553" source="SECTRACK" adv="1">1013553</ref>
      <ref url="http://bugzilla.opengroupware.org/bugzilla/show_bug.cgi?id=1060" source="MISC" adv="1">http://bugzilla.opengroupware.org/bugzilla/show_bug.cgi?id=1060</ref>
    </refs>
    <vuln_soft>
      <prod vendor="open_group" name="scalable_ogo">
        <vers num="1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1772" published="2004-12-31" name="CVE-2004-1772" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Stack-based buffer overflow in shar in GNU sharutils 4.2.1 allows local users to execute arbitrary code via a long -o command line argument.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="https://bugzilla.fedora.us/show_bug.cgi?id=2155" source="FEDORA" patch="1">FLSA:2155</ref>
      <ref url="http://www.securityfocus.com/bid/10066" source="BID" patch="1">10066</ref>
      <ref url="http://www.securityfocus.com/archive/1/359639" source="BUGTRAQ" patch="1">20040406 GNU Sharutils buffer overflow vulnerability.</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108137386310299&amp;w=2" source="OPENPKG" patch="1">OpenPKG-SA-2004.011</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15759" source="XF">sharutils-shar-bo(15759)</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-377.html" source="REDHAT">RHSA-2005:377</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11722" source="OVAL">oval:org.mitre.oval:def:11722</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gnu" name="sharutils">
        <vers num="4.2" />
        <vers num="4.2.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-1773" published="2004-12-31" name="CVE-2004-1773" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple buffer overflows in sharutils 4.2.1 and earlier may allow attackers to execute arbitrary code via (1) long output from wc to shar, or (2) unknown vectors in unshar.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="https://bugzilla.fedora.us/show_bug.cgi?id=2155" source="FEDORA" patch="1">FLSA:2155</ref>
      <ref url="http://www.securityfocus.com/bid/11298" source="BID" patch="1">11298</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200410-01.xml" source="GENTOO" patch="1" adv="1">GLSA-200410-01</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-377.html" source="REDHAT">RHSA-2005:377</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11093" source="OVAL">oval:org.mitre.oval:def:11093</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gnu" name="sharutils">
        <vers num="4.2" />
        <vers num="4.2.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-1774" published="2004-08-31" name="CVE-2004-1774" modified="2010-02-06" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Buffer overflow in the SDO_CODE_SIZE procedure of the MD2 package (MDSYS.MD2.SDO_CODE_SIZE) in Oracle 10g before 10.1.0.2 Patch 2 allows local users to execute arbitrary code via a long LAYER parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securiteam.com/securitynews/5CP010KE0W.html" source="MISC" patch="1" adv="1">http://www.securiteam.com/securitynews/5CP010KE0W.html</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/20078" source="XF">oracle-mdsysmd2sdocodesize-bo(20078)</ref>
      <ref url="http://www.securityfocus.com/bid/13145" source="BID" adv="1">13145</ref>
      <ref url="http://www.oracle.com/technology/deploy/security/pdf/2004alert68.pdf" source="CONFIRM" adv="1">http://www.oracle.com/technology/deploy/security/pdf/2004alert68.pdf</ref>
      <ref url="http://www.frsirt.com/exploits/20050413.OracleExploit.sql.php" source="MISC">http://www.frsirt.com/exploits/20050413.OracleExploit.sql.php</ref>
      <ref url="http://www.appsecinc.com/resources/alerts/oracle/2004-0001/" source="MISC">http://www.appsecinc.com/resources/alerts/oracle/2004-0001/</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2004-September/025984.html" source="FULLDISC" adv="1">20040902 [SHATTER Team Security Alert] Multiple vulnerabilities in Oracle Database Server</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="application_server">
        <vers num="10.1.0.2" />
      </prod>
      <prod vendor="oracle" name="oracle10g">
        <vers num="enterprise_10.1.0.2" />
        <vers num="personal_10.1.0.2" />
        <vers num="standard_10.1.0.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1775" published="2004-12-31" name="CVE-2004-1775" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Cisco VACM (View-based Access Control MIB) for Catalyst Operating Software (CatOS) 5.5 and 6.1 and IOS 12.0 and 12.1 allows remote attackers to read and modify device configuration via the read-write community string.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/645400" source="CERT-VN" patch="1" adv="1">VU#645400</ref>
      <ref url="http://www.securityfocus.com/bid/5030" source="BID" patch="1">5030</ref>
      <ref url="http://www.cisco.com/warp/public/707/ios-snmp-community-vulns-pub.shtml" source="CISCO" patch="1" adv="1">20041008 Cisco IOS Software Multiple SNMP Community String Vulnerabilities</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/6179" source="XF">cisco-snmp-vacm(6179)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="catos">
        <vers num="5.5" />
        <vers num="6.1" />
      </prod>
      <prod vendor="cisco" name="ios">
        <vers num="12.0da" />
        <vers num="12.0db" />
        <vers num="12.0dc" />
        <vers num="12.0s" />
        <vers num="12.0sc" />
        <vers num="12.0sl" />
        <vers num="12.0st" />
        <vers num="12.0t" />
        <vers num="12.0xa" />
        <vers num="12.0xb" />
        <vers num="12.0xc" />
        <vers num="12.0xd" />
        <vers num="12.0xe" />
        <vers num="12.0xf" />
        <vers num="12.0xg" />
        <vers num="12.0xh" />
        <vers num="12.0xi" />
        <vers num="12.0xj" />
        <vers num="12.0xk" />
        <vers num="12.0xl" />
        <vers num="12.0xm" />
        <vers num="12.0xn" />
        <vers num="12.0xp" />
        <vers num="12.0xq" />
        <vers num="12.0xr" />
        <vers num="12.0xs" />
        <vers num="12.0xu" />
        <vers num="12.0xv" />
        <vers num="12.0xw" />
        <vers num="12.1" />
        <vers num="12.1aa" />
        <vers num="12.1cx" />
        <vers num="12.1da" />
        <vers num="12.1db" />
        <vers num="12.1dc" />
        <vers num="12.1e" />
        <vers num="12.1ea" />
        <vers num="12.1ec" />
        <vers num="12.1ex" />
        <vers num="12.1t" />
        <vers num="12.1xa" />
        <vers num="12.1xb" />
        <vers num="12.1xc" />
        <vers num="12.1xd" />
        <vers num="12.1xe" />
        <vers num="12.1xf" />
        <vers num="12.1xg" />
        <vers num="12.1xh" />
        <vers num="12.1xi" />
        <vers num="12.1xk" />
        <vers num="12.1xl" />
        <vers num="12.1xm" />
        <vers num="12.1xp" />
        <vers num="12.1xq" />
        <vers num="12.1xr" />
        <vers num="12.1xs" />
        <vers num="12.1xt" />
        <vers num="12.1xu" />
        <vers num="12.1xv" />
        <vers num="12.1xw" />
        <vers num="12.1xx" />
        <vers num="12.1xy" />
        <vers num="12.1xz" />
        <vers num="12.1ya" />
        <vers num="12.1yb" />
        <vers num="12.1yc" />
        <vers num="12.1yd" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-1776" published="2001-02-28" name="CVE-2004-1776" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Cisco IOS 12.1(3) and 12.1(3)T allows remote attackers to read and modify device configuration data via the cable-docsis read-write community string used by the Data Over Cable Service Interface Specification (DOCSIS) standard.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <design />
      <config />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/840665" source="CERT-VN" patch="1" adv="1">VU#840665</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/6180" source="XF" patch="1" adv="1">cisco-ios-cable-docsis(6180)</ref>
      <ref url="http://www.cisco.com/warp/public/707/ios-snmp-community-vulns-pub.shtml" source="CISCO" patch="1" adv="1">20041008 Cisco IOS Software Multiple SNMP Community String Vulnerabilities</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="ios">
        <vers num="12.1(3)" />
        <vers num="12.1(3)t" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1777" published="2004-12-31" name="CVE-2004-1777" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">A "range check error" in Skype for Windows before 0.98.0.28 allows local and remote attackers to cause a denial of service (application crash) via long command line arguments or a long callto:// URL, a different vulnerability than CVE-2004-1114.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.skype.com/security/ssa-2004-01.html" source="CONFIRM" patch="1">http://www.skype.com/security/ssa-2004-01.html</ref>
      <ref url="http://www.osvdb.org/11860" source="OSVDB">11860</ref>
      <ref url="http://securitytracker.com/id?1010490" source="SECTRACK">1010490</ref>
      <ref url="http://lists.virus.org/bugtraq-0406/msg00221.html" source="BUGTRAQ">20040615 Skype URI callto username overflow</ref>
    </refs>
    <vuln_soft>
      <prod vendor="skype_technologies" name="skype">
        <vers num="0.98.0.04" />
        <vers prev="1" num="0.98.0.27" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1778" published="2004-12-22" name="CVE-2004-1778" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Skype 0.92.0.12 and 1.0.0.1 for Linux, and possibly other versions, creates the /usr/share/skype/lang directory with world-writable permissions, which allows local users to modify language files and possibly conduct social engineering or other attacks.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <config />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/18644" source="XF" patch="1" adv="1">skype-lang-insecure-permissions(18644)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110374568916303&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20041222 Permission problem in Skype BETA for linux</ref>
      <ref url="http://www.securityfocus.com/bid/12081" source="BID" adv="1">12081</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110868557905786&amp;w=2" source="BUGTRAQ" adv="1">20050216 Re: Permission problem in Skype BETA for linux</ref>
    </refs>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1779" published="2004-12-31" name="CVE-2004-1779" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in board.php for ThWboard before beta 2.84 allows remote attackers to inject arbitrary web script or HTML via the lastvisited parameter.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/9367" source="BID" patch="1">9367</ref>
      <ref url="http://securitytracker.com/id?1008617" source="SECTRACK" patch="1">1008617</ref>
      <ref url="http://secunia.com/advisories/10546" source="SECUNIA" patch="1">10546</ref>
      <ref url="http://cvs.sourceforge.net/viewcvs.py/thwb/thwb/board.php?r1=1.11&amp;r2=1.12" source="CONFIRM" patch="1">http://cvs.sourceforge.net/viewcvs.py/thwb/thwb/board.php?r1=1.11&amp;r2=1.12</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/14143" source="XF">thwboard-board-xss(14143)</ref>
      <ref url="http://www.osvdb.org/3330" source="OSVDB">3330</ref>
      <ref url="http://sourceforge.net/project/shownotes.php?release_id=207893" source="CONFIRM">http://sourceforge.net/project/shownotes.php?release_id=207893</ref>
    </refs>
    <vuln_soft>
      <prod vendor="thwboard" name="thwboard_beta">
        <vers num="2.8" />
        <vers num="2.81" />
        <vers num="2.82" />
        <vers num="2.83" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1780" published="2004-12-31" name="CVE-2004-1780" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Info Touch Surfnet kiosk allows local users to deposit extra time into Internet kiosk accounts via repeated authentication attempts.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/9347" source="BID">9347</ref>
    </refs>
    <vuln_soft>
      <prod vendor="info_touch" name="surfnet">
        <vers num="1.31" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1781" published="2004-12-31" name="CVE-2004-1781" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Info Touch Surfnet kiosk allows local users to crash Surfnet and access the underlying operating system via the CMD_CREDITCARD_CHARGE command.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/9348" source="BID">9348</ref>
    </refs>
    <vuln_soft>
      <prod vendor="info_touch" name="surfnet">
        <vers num="1.31" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-1782" published="2004-12-31" name="CVE-2004-1782" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">athenareg.php in Athena Web Registration allows remote attackers to execute arbitrary commands via shell metacharacters in the pass parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/9349" source="BID">9349</ref>
      <ref url="http://www.osvdb.org/16861" source="OSVDB">16861</ref>
    </refs>
    <vuln_soft>
      <prod vendor="david_maciejak" name="athena_web_registration">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-1783" published="2004-12-31" name="CVE-2004-1783" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Directory traversal vulnerability in Net2Soft Flash FTP Server 1.0 allows remote attackers to read and create arbitrary files via a /.. (slash dot dot).</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/10522" source="SECUNIA" patch="1">10522</ref>
      <ref url="http://www.securityfocus.com/bid/9350" source="BID">9350</ref>
      <ref url="http://www.securiteam.com/windowsntfocus/5FP051FBPQ.html" source="MISC">http://www.securiteam.com/windowsntfocus/5FP051FBPQ.html</ref>
      <ref url="http://securitytracker.com/id?1008588" source="SECTRACK">1008588</ref>
    </refs>
  </entry>
  <entry type="CVE" severity="High" seq="2004-1784" published="2004-01-03" name="CVE-2004-1784" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in the web server of Webcam Watchdog 3.63 allows remote attackers to execute arbitrary code via a long HTTP GET request.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/10527" source="SECUNIA" patch="1" adv="1">10527</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/14131" source="XF" adv="1">webcam-watchdog-get-bo(14131)</ref>
      <ref url="http://www.webcamsoft.com/en/watchdog_h.html" source="MISC">http://www.webcamsoft.com/en/watchdog_h.html</ref>
      <ref url="http://www.securityfocus.com/bid/9351" source="BID" adv="1">9351</ref>
      <ref url="http://www.securityfocus.com/archive/1/348818" source="BUGTRAQ" adv="1">20040103 Webcam Watchdog Stack Overflow Vulnerability</ref>
      <ref url="http://www.osvdb.org/3312" source="OSVDB" adv="1">3312</ref>
      <ref url="http://www.elitehaven.net/webcamwatchdog.txt" source="MISC">http://www.elitehaven.net/webcamwatchdog.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="webcam_corp" name="webcam_watchdog">
        <vers num="1.0" />
        <vers num="1.1" />
        <vers num="3.63" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-1785" published="2004-01-03" name="CVE-2004-1785" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in calendar.php for Invision Power Board 1.3 allows remote attackers to execute arbitrary SQL commands via the m parameter, which sets the $this->chosen_month variable.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/9353" source="BID" patch="1" adv="1">9353</ref>
      <ref url="http://www.osvdb.org/3319" source="OSVDB" patch="1" adv="1">3319</ref>
      <ref url="http://secunia.com/advisories/10530" source="SECUNIA" patch="1" adv="1">10530</ref>
      <ref url="http://www.securityfocus.com/archive/1/348821" source="BUGTRAQ" adv="1">20040103 [SCSA-025] Invision Power Board SQL Injection Vulnerability</ref>
      <ref url="http://www.securitytracker.com/id?1008589" source="SECTRACK">1008589</ref>
    </refs>
    <vuln_soft>
      <prod vendor="invision_power_services" name="invision_board">
        <vers num="1.0" />
        <vers num="1.0.1" />
        <vers num="1.1.1" />
        <vers num="1.1.2" />
        <vers num="1.2" />
        <vers num="1.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1786" published="2004-01-04" name="CVE-2004-1786" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">PortalApp places user credentials under the web root with insufficient access control, which allows remote attackers to gain access to sensitive information via a direct request to 8275.mdb.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/14169" source="XF" adv="1">portalapp-url-access-database(14169)</ref>
      <ref url="http://www.securityfocus.com/bid/9354" source="BID" adv="1">9354</ref>
      <ref url="http://securitytracker.com/id?1008627" source="SECTRACK" adv="1">1008627</ref>
    </refs>
    <vuln_soft>
      <prod vendor="iatek" name="portalapp">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-1787" published="2004-12-31" name="CVE-2004-1787" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in PostCalendar 4.0.0 allows remote attackers to execute arbitrary SQL commands via search queries.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/9372" source="BID" patch="1">9372</ref>
      <ref url="http://securitytracker.com/id?1008621" source="SECTRACK" patch="1">1008621</ref>
      <ref url="http://secunia.com/advisories/10554" source="SECUNIA" patch="1">10554</ref>
      <ref url="http://news.postnuke.com/modules.php?op=modload&amp;name=News&amp;file=article&amp;sid=2537" source="CONFIRM" patch="1">http://news.postnuke.com/modules.php?op=modload&amp;name=News&amp;file=article&amp;sid=2537</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/14111" source="XF">postcalendar-search-sql-injection(14111)</ref>
      <ref url="http://www.osvdb.org/3336" source="OSVDB">3336</ref>
    </refs>
    <vuln_soft>
      <prod vendor="postnuke_software_foundation" name="postcalendar">
        <vers num="4.0.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1788" published="2004-12-31" name="CVE-2004-1788" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">ASP-Nuke 1.3 and earlier places user credentials under the web document root with insufficient access control, which allows remote attackers to obtain sensitive information via a direct request to main.mdb.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <access />
      <config />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/9355" source="BID">9355</ref>
    </refs>
    <vuln_soft>
      <prod vendor="asp-nuke" name="asp-nuke">
        <vers num="1.0" />
        <vers num="1.2" />
        <vers num="1.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1789" published="2004-12-31" name="CVE-2004-1789" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in the web management interface in ZyWALL 10 4.07 allows remote attackers to inject arbitrary web script or HTML via the rpAuth_1 page.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/14163" source="XF">zywall-xss(14163)</ref>
      <ref url="http://www.securityfocus.com/bid/9373" source="BID">9373</ref>
      <ref url="http://www.securityfocus.com/archive/1/349085" source="BUGTRAQ">20040106 ZyXEL10 OF ZyWALL Series Router Cross Site Scripting Vulnerabillity</ref>
      <ref url="http://www.osvdb.org/3443" source="OSVDB">3443</ref>
      <ref url="http://securitytracker.com/id?1008644" source="SECTRACK">1008644</ref>
      <ref url="http://www.osvdb.org/12793" source="OSVDB">12793</ref>
      <ref url="http://secunia.com/advisories/10574" source="SECUNIA">10574</ref>
    </refs>
    <vuln_soft>
      <prod vendor="zyxel" name="zywall10">
        <vers num="3.20_wa0" />
        <vers num="3.20_wa1" />
        <vers num="3.24_wa0" />
        <vers num="3.24_wa1" />
        <vers num="3.24_wa2" />
        <vers num="3.50_wa1" />
        <vers num="3.50_wa2" />
        <vers num="4.07" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1790" published="2004-12-31" name="CVE-2004-1790" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in the web management interface in Edimax AR-6004 ADSL Routers allows remote attackers to inject arbitrary web script or HTML via the URL.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/14165" source="XF">edimax-ar6004-xss(14165)</ref>
      <ref url="http://www.securityfocus.com/bid/9374" source="BID">9374</ref>
      <ref url="http://www.securityfocus.com/archive/1/349089" source="BUGTRAQ">20040106 EDIMAX AR-6004 Full Rate ADSL Router Cross Site Scripting Vulnerabillity</ref>
      <ref url="http://www.osvdb.org/3435" source="OSVDB">3435</ref>
      <ref url="http://securitytracker.com/id?1008643" source="SECTRACK">1008643</ref>
      <ref url="http://secunia.com/advisories/10576" source="SECUNIA">10576</ref>
    </refs>
    <vuln_soft>
      <prod vendor="edimax" name="full_rate_adsl_router">
        <vers num="ar_6004" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-1791" published="2004-12-31" name="CVE-2004-1791" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">The web management interface in Edimax AR-6004 ADSL Routers uses a default administrator name and password, which also appear as the default login text for the management interface, which allows remote attackers to gain access.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <config />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/349089" source="BUGTRAQ">20040106 EDIMAX AR-6004 Full Rate ADSL Router Cross Site Scripting Vulnerabillity</ref>
      <ref url="http://www.osvdb.org/3511" source="OSVDB">3511</ref>
      <ref url="http://securitytracker.com/id?1008643" source="SECTRACK">1008643</ref>
    </refs>
    <vuln_soft>
      <prod vendor="edimax" name="full_rate_adsl_router">
        <vers num="ar_6004" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1792" published="2004-12-31" name="CVE-2004-1792" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">swnet.dll in YaSoft Switch Off 2.3 and earlier allows remote attackers to cause a denial of service (infinite loop) via a long packet with two CRLF sequences to the service management port (TCP 8000).</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/14123" source="XF">switch-off-swnet-dos(14123)</ref>
      <ref url="http://www.securityfocus.com/bid/9339" source="BID">9339</ref>
      <ref url="http://www.securityfocus.com/archive/1/348693" source="BUGTRAQ">20040102 Switch Off Multiple Vulnerabilities</ref>
      <ref url="http://www.elitehaven.net/switchoff.txt" source="MISC">http://www.elitehaven.net/switchoff.txt</ref>
      <ref url="http://securitytracker.com/id?1008581" source="SECTRACK">1008581</ref>
      <ref url="http://secunia.com/advisories/10521" source="SECUNIA">10521</ref>
    </refs>
    <vuln_soft>
      <prod vendor="yatsoft" name="switch_off">
        <vers num="0.7" />
        <vers num="1.0" />
        <vers num="1.1" />
        <vers num="1.2" />
        <vers num="1.3" />
        <vers num="1.4" />
        <vers num="1.5" />
        <vers num="1.5.1" />
        <vers num="1.6" />
        <vers num="1.7" />
        <vers num="1.8" />
        <vers num="1.9" />
        <vers num="2.0" />
        <vers num="2.1" />
        <vers num="2.2" />
        <vers num="2.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-1793" published="2004-12-31" name="CVE-2004-1793" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Stack-based buffer overflow in swnet.dll in YaSoft Switch Off 2.3 and earlier allows remote authenticated users to execute arbitrary code via a long message parameter in a SendMsg action to action.htm.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/14124" source="XF">switch-off-swnet-bo(14124)</ref>
      <ref url="http://www.securityfocus.com/bid/9340" source="BID">9340</ref>
      <ref url="http://www.securityfocus.com/archive/1/348693" source="BUGTRAQ">20040102 Switch Off Multiple Vulnerabilities</ref>
      <ref url="http://www.osvdb.org/3309" source="OSVDB">3309</ref>
      <ref url="http://www.elitehaven.net/switchoff.txt" source="MISC">http://www.elitehaven.net/switchoff.txt</ref>
      <ref url="http://securitytracker.com/id?1008581" source="SECTRACK">1008581</ref>
      <ref url="http://secunia.com/advisories/10521" source="SECUNIA">10521</ref>
    </refs>
    <vuln_soft>
      <prod vendor="yatsoft" name="switch_off">
        <vers num="0.7" />
        <vers num="1.0" />
        <vers num="1.1" />
        <vers num="1.2" />
        <vers num="1.3" />
        <vers num="1.4" />
        <vers num="1.5" />
        <vers num="1.5.1" />
        <vers num="1.6" />
        <vers num="1.7" />
        <vers num="1.8" />
        <vers num="1.9" />
        <vers num="2.0" />
        <vers num="2.1" />
        <vers num="2.2" />
        <vers num="2.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1794" published="2004-12-31" name="CVE-2004-1794" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in the VCard4J Toolkit allows remote attackers to inject arbitrary web script or HTML via the NICKNAME tag in a vCard.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://securitytracker.com/id?1008582" source="SECTRACK" patch="1">1008582</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/14120" source="XF">vcard4j-nickname-xss(14120)</ref>
      <ref url="http://www.securityfocus.com/bid/9343" source="BID">9343</ref>
      <ref url="http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2004-01/0006.html" source="BUGTRAQ">20040101 Possible XSS vuln in VCard4J</ref>
    </refs>
    <vuln_soft>
      <prod vendor="vcard4j" name="vcard4j">
        <vers num="0.1" />
        <vers num="0.2" />
        <vers num="1.0" />
        <vers num="1.1" />
        <vers num="1.1.1" />
        <vers num="1.1.2" />
        <vers num="1.1.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2004-1795" published="2004-12-31" name="CVE-2004-1795" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">Info Touch Surfnet kiosk allows local users to access the underlying filesystem via a 'file://' URI.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <access />
      <input />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/9346" source="BID">9346</ref>
    </refs>
  </entry>
  <entry type="CVE" severity="High" seq="2004-1796" published="2004-12-31" name="CVE-2004-1796" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">PHP remote file inclusion vulnerability in HotNews 0.7.2 and earlier allows remote attackers to execute arbitrary PHP code via the (1) config[header] parameter to hotnews-engine.inc.php3 or (2) config[incdir] parameter to hnmain.inc.php3.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/14140" source="XF" patch="1">hotnews-php-file-include(14140)</ref>
      <ref url="http://www.securityfocus.com/bid/9357" source="BID" patch="1">9357</ref>
      <ref url="http://www.securityfocus.com/archive/1/348840" source="BUGTRAQ" patch="1">20040104 HotNews arbitary file inclusion</ref>
      <ref url="http://sourceforge.net/forum/forum.php?forum_id=342594" source="CONFIRM" patch="1">http://sourceforge.net/forum/forum.php?forum_id=342594</ref>
      <ref url="http://securitytracker.com/id?1008608" source="SECTRACK" patch="1">1008608</ref>
      <ref url="http://secunia.com/advisories/10551" source="SECUNIA" patch="1">10551</ref>
      <ref url="http://www.osvdb.org/3405" source="OSVDB">3405</ref>
      <ref url="http://www.osvdb.org/3332" source="OSVDB">3332</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hotnews" name="hotnews">
        <vers num="0.5.3" />
        <vers num="0.6.0" />
        <vers num="0.6.0_pre" />
        <vers num="0.6.1" />
        <vers num="0.7.0" />
        <vers num="0.7.1" />
        <vers num="0.7.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1797" published="2004-12-31" name="CVE-2004-1797" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in search.php for FreznoShop 1.3.0 RC1 and earlier allows remote attackers to inject arbitrary web script or HTML via the search parameter.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://securitytracker.com/id?1008606" source="SECTRACK" patch="1">1008606</ref>
      <ref url="http://secunia.com/advisories/10547" source="SECUNIA" patch="1">10547</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/14147" source="XF">freznoshop-searchphp-xss(14147)</ref>
      <ref url="http://www.securityfocus.com/bid/9359" source="BID">9359</ref>
      <ref url="http://www.osvdb.org/3335" source="OSVDB">3335</ref>
    </refs>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1798" published="2004-12-31" name="CVE-2004-1798" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_score="5.1" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="4.9" CVSS_base_score="5.1">
    <desc>
      <descript source="cve">RealOne player 6.0.11.868 allows remote attackers to execute arbitrary script in the "My Computer" zone via a Synchronized Multimedia Integration Language (SMIL) presentation with a "file:javascript:" URL, which is executed in the security context of the previously loaded URL, a different vulnerability than CVE-2003-0726.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/9378" source="BID" patch="1">9378</ref>
      <ref url="http://www.osvdb.org/3826" source="OSVDB" patch="1">3826</ref>
      <ref url="http://secunia.com/advisories/9584" source="SECUNIA" patch="1" adv="1">9584</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/14168" source="XF">realoneplayer-smil-xss(14168)</ref>
      <ref url="http://www.securityfocus.com/archive/1/349086" source="BUGTRAQ">20040107 RealNetworks fails to address Cross-Site Scripting in RealOne Player</ref>
      <ref url="http://securitytracker.com/id?1008647" source="SECTRACK">1008647</ref>
    </refs>
    <vuln_soft>
      <prod vendor="realnetworks" name="realone_desktop_manager">
        <vers num="" />
      </prod>
      <prod vendor="realnetworks" name="realone_enterprise_desktop">
        <vers num="6.0.11.774" />
      </prod>
      <prod vendor="realnetworks" name="realone_player">
        <vers num="1.0" />
        <vers num="2.0" />
        <vers num="6.0.10.505" edition="gold,_windows" />
        <vers num="6.0.11.818" />
        <vers num="6.0.11.830" />
        <vers num="6.0.11.841" />
        <vers num="6.0.11.853" />
        <vers num="6.0.11.868" />
      </prod>
      <prod vendor="realnetworks" name="realplayer">
        <vers num="8.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-1799" published="2004-12-31" name="CVE-2004-1799" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">PF in certain OpenBSD versions, when stateful filtering is enabled, does not limit packets for a session to the original interface, which allows remote attackers to bypass intended packet filters via spoofed packets to other interfaces.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <design />
      <config />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/9362" source="BID">9362</ref>
      <ref url="http://marc.theaimsgroup.com/?l=full-disclosure&amp;m=107331321302113&amp;w=2" source="FULLDISC">20040105 firewall security bug?</ref>
      <ref url="http://www.osvdb.org/19105" source="OSVDB">19105</ref>
    </refs>
    <vuln_soft>
      <prod vendor="openbsd" name="openbsd">
        <vers num="3.0" />
        <vers num="3.1" />
        <vers num="3.2" />
        <vers num="3.3" />
        <vers num="3.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-1800" published="2004-12-31" name="CVE-2004-1800" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Unknown vulnerability in Sysbotz SimpleData 4.0.1 and possibly earlier versions allows remote attackers to gain access via a crafted URL and a certain cookie.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <access />
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/14206" source="XF">simpledata-gain-unauth-access(14206)</ref>
      <ref url="http://www.securityfocus.com/bid/9380" source="BID">9380</ref>
      <ref url="http://securitytracker.com/id?1008695" source="SECTRACK">1008695</ref>
      <ref url="http://secunia.com/advisories/10595" source="SECUNIA">10595</ref>
    </refs>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1801" published="2004-12-31" name="CVE-2004-1801" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in PWebServer 0.3.3 allows remote attackers to read arbitrary files via a .. (dot dot) in the URL.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/9817" source="BID" patch="1">9817</ref>
      <ref url="http://www.autistici.org/fdonato/advisory/PWebServer0.3.3-adv.txt" source="MISC" patch="1">http://www.autistici.org/fdonato/advisory/PWebServer0.3.3-adv.txt</ref>
      <ref url="http://secunia.com/advisories/11057" source="SECUNIA" patch="1">11057</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107876388211413&amp;w=2" source="BUGTRAQ" patch="1">20040308 directory traversal in PWebServer 0.3.3</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15404" source="XF">pwebserver-dotdot-directory-traversal(15404)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="pwebserver" name="pwebserver_web_server">
        <vers num="0.3.0" />
        <vers num="0.3.2" />
        <vers num="0.3.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1802" published="2004-12-31" name="CVE-2004-1802" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Chat Anywhere 2.72 and earlier allows remote attackers to hide their IP address by using %00 before the nickname, which causes the IP address to be displayed as $IP$ on the administration web page.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.lionmax.com/chatanywhere.htm" source="CONFIRM" patch="1">http://www.lionmax.com/chatanywhere.htm</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15416" source="XF">chat-anywhere-admin-bypass(15416)</ref>
      <ref url="http://www.securityfocus.com/bid/9823" source="BID">9823</ref>
      <ref url="http://aluigi.altervista.org/adv/chatany-ghost-adv.txt" source="MISC">http://aluigi.altervista.org/adv/chatany-ghost-adv.txt</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107885946220895&amp;w=2" source="BUGTRAQ">20040309 Ghost users in Chat Anywhere 2.72</ref>
    </refs>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1804" published="2004-12-31" name="CVE-2004-1804" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">wMCam server 2.1.348 allows remote attackers to cause a denial of service (no new connections) via multiple malformed HTTP requests without the GET command.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/15431" source="XF">wmcam-multiple-connections-dos(15431)</ref>
      <ref url="http://www.securityfocus.com/bid/9839" source="BID">9839</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107894337524376&amp;w=2" source="BUGTRAQ">20040310 DoS in wMCam server 2.1.348</ref>
    </refs>
    <vuln_soft>
      <prod vendor="invicta" name="wmcam_server">
        <vers num="2.1.348" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1805" published="2004-12-31" name="CVE-2004-1805" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Format string vulnerability in games using the Epic Games Unreal Engine 436 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via format string specifiers in class names.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/9840" source="BID" patch="1">9840</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15430" source="XF">ut-class-format-string(15430)</ref>
      <ref url="http://secunia.com/advisories/11108" source="SECUNIA">11108</ref>
      <ref url="http://aluigi.altervista.org/adv/unrfs-adv.txt" source="MISC">http://aluigi.altervista.org/adv/unrfs-adv.txt</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107902755204583&amp;w=2" source="BUGTRAQ">20040311 Re: Format string bug in EpicGames Unreal engine</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107893764406905&amp;w=2" source="BUGTRAQ">20040310 Format string bug in EpicGames Unreal engine</ref>
    </refs>
    <vuln_soft>
      <prod vendor="epic_games" name="unreal_engine">
        <vers num="226f" />
        <vers num="433" />
        <vers num="436" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-1806" published="2004-12-31" name="CVE-2004-1806" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in index.cfm in CFWebstore 5.0 allows remote attackers to execute SQL commands via the (1) category_id, (2) product_id, or (3) feature_id parameters.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/11112" source="SECUNIA" patch="1">11112</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15447" source="XF">cfwebstore-index-sql-injection(15447)</ref>
      <ref url="http://www.securityfocus.com/bid/9854" source="BID">9854</ref>
      <ref url="http://www.s-quadra.com/advisories/Adv-20040312.txt" source="MISC" adv="1">http://www.s-quadra.com/advisories/Adv-20040312.txt</ref>
      <ref url="http://www.osvdb.org/4229" source="OSVDB">4229</ref>
      <ref url="http://securitytracker.com/id?1009403" source="SECTRACK">1009403</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107911090901744&amp;w=2" source="BUGTRAQ" adv="1">20040312 Dogpatch Software CFWebstore 5.0 shopping cart software multiple security vulnerabilities</ref>
    </refs>
    <vuln_soft>
      <prod vendor="dogpatch_software" name="cfwebstore">
        <vers num="5.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1807" published="2004-12-31" name="CVE-2004-1807" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in index.cfm in CFWebstore 5.0 allows remote attackers to inject arbitrary web script or HTML via the URL.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/11112" source="SECUNIA" patch="1">11112</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15454" source="XF">cfwebstore-url-xss(15454)</ref>
      <ref url="http://www.securityfocus.com/bid/9856" source="BID">9856</ref>
      <ref url="http://www.s-quadra.com/advisories/Adv-20040312.txt" source="MISC" adv="1">http://www.s-quadra.com/advisories/Adv-20040312.txt</ref>
      <ref url="http://www.osvdb.org/4230" source="OSVDB">4230</ref>
      <ref url="http://securitytracker.com/id?1009403" source="SECTRACK">1009403</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107911090901744&amp;w=2" source="BUGTRAQ" adv="1">20040312 Dogpatch Software CFWebstore 5.0 shopping cart software multiple security vulnerabilities</ref>
    </refs>
    <vuln_soft>
      <prod vendor="dogpatch_software" name="cfwebstore">
        <vers num="5.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2004-1808" published="2004-12-31" name="CVE-2004-1808" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">Extcompose in metamail does not verify the output file before writing to it, which allows local users to overwrite arbitrary files via a symlink attack.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <design />
      <env />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/15460" source="XF">metamail-extcompose-symlink(15460)</ref>
      <ref url="http://www.securityfocus.com/bid/9850" source="BID">9850</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107910934926062&amp;w=2" source="BUGTRAQ">20040312 Metamail 'extcompose' script Symlink Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="metamail_corporation" name="metamail">
        <vers num="2.7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1809" published="2004-12-31" name="CVE-2004-1809" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in phpBB 2.0.6d and earlier allows remote attackers to inject arbitrary web script or HTML via the (1) postdays parameter to viewtopic.php or (2) topicdays parameter to viewforum.php.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/9866" source="BID" patch="1">9866</ref>
      <ref url="http://www.securityfocus.com/bid/9865" source="BID" patch="1">9865</ref>
      <ref url="http://secunia.com/advisories/11121" source="SECUNIA" patch="1">11121</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107920498205324&amp;w=2" source="BUGTRAQ" patch="1">20040313 phpBB 2.0.6d &amp;&amp; Earlier Security Issues</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15464" source="XF">phpbb-viewforum-viewtopic-xss(15464)</ref>
      <ref url="http://www.phpbb.com/support/documents.php?mode=changelog#206" source="CONFIRM">http://www.phpbb.com/support/documents.php?mode=changelog#206</ref>
      <ref url="http://www.osvdb.org/4259" source="OSVDB">4259</ref>
      <ref url="http://www.osvdb.org/4257" source="OSVDB">4257</ref>
    </refs>
    <vuln_soft>
      <prod vendor="phpbb_group" name="phpbb">
        <vers num="2.0.0" />
        <vers num="2.0.1" />
        <vers num="2.0.2" />
        <vers num="2.0.3" />
        <vers num="2.0.4" />
        <vers num="2.0.5" />
        <vers num="2.0.6" />
        <vers num="2.0.6c" />
        <vers num="2.0.6d" />
        <vers num="2.0_rc1" />
        <vers num="2.0_rc2" />
        <vers num="2.0_rc3" />
        <vers num="2.0_rc4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1810" published="2004-12-31" name="CVE-2004-1810" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The Javascript engine in Opera 7.23 allows remote attackers to cause a denial of service (crash) by creating a new Array object with a large size value, then writing into that array.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <design />
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/15413" source="XF">safari-array-dos(15413)</ref>
      <ref url="http://www.securityfocus.com/bid/9869" source="BID">9869</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107936810909082&amp;w=2" source="BUGTRAQ">20040314 Opera Array Allocation Managment Exploit</ref>
    </refs>
    <vuln_soft>
      <prod vendor="opera_software" name="opera_web_browser">
        <vers num="7.22" />
        <vers num="7.23" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-1811" published="2004-12-31" name="CVE-2004-1811" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">The SSL HTTP Server in HP Web-enabled Management Software 5.0 through 5.92, with anonymous access enabled, allows remote attackers to compromise the trusted certificates by uploading their own certificates.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <config />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.tru64.org/stories.php?story=04/03/12/0204078" source="HP" patch="1">HPSBMA01003</ref>
      <ref url="http://www.securityfocus.com/bid/9859" source="BID" patch="1">9859</ref>
      <ref url="http://www.ciac.org/ciac/bulletins/o-100.shtml" source="CIAC" patch="1">O-100</ref>
      <ref url="http://www.immunitysec.com/downloads/hp_http.sxw.pdf" source="MISC" adv="1">http://www.immunitysec.com/downloads/hp_http.sxw.pdf</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107936784030214&amp;w=2" source="BUGTRAQ">20040314 Multiple Immunity Advisories</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15466" source="XF">hp-http-certificate-upload(15466)</ref>
      <ref url="http://www.securityfocus.com/advisories/6448" source="COMPAQ">SSRT4679</ref>
      <ref url="http://secunia.com/advisories/11126" source="SECUNIA">11126</ref>
      <ref url="http://archives.neohapsis.com/archives/vulnwatch/2004-q1/0057.html" source="VULNWATCH">20040315 Immunity Advisory: Compaq Web Management vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hp" name="ssl_http_server">
        <vers num="5.0" />
        <vers num="5.92" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-1812" published="2004-12-31" name="CVE-2004-1812" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Multiple stack-based buffer overflows in Agent Common Services (1) cam.exe and (2) awservices.exe in Unicenter TNG 2.4 allow remote attackers to execute arbitrary code.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/15472" source="XF">unicentertng-awservices-cam-bo(15472)</ref>
      <ref url="http://www.securityfocus.com/bid/9863" source="BID">9863</ref>
      <ref url="http://www.immunitysec.com/downloads/awservices.sxw.pdf" source="MISC" adv="1">http://www.immunitysec.com/downloads/awservices.sxw.pdf</ref>
      <ref url="http://www.derkeiler.com/Mailing-Lists/VulnWatch/2004-03/0008.html" source="VULNWATCH">20040315 Immunity Advisory: Computer Associates Unicenter TNG</ref>
      <ref url="http://secunia.com/advisories/11131" source="SECUNIA">11131</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107936784030214&amp;w=2" source="BUGTRAQ">20040314 Multiple Immunity Advisories</ref>
      <ref url="ftp://ftp.ca.com/CAproducts/unicenter/CCS31/nt/qi52764/QI52764.DB0" source="CONFIRM" adv="1">ftp://ftp.ca.com/CAproducts/unicenter/CCS31/nt/qi52764/QI52764.DB0</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ca" name="unicenter_tng">
        <vers num="2.4" />
        <vers num="2.4.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-1813" published="2004-12-31" name="CVE-2004-1813" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">VocalTec VGW4/8 Gateway 8.0 allows remote attackers to bypass authentication via an HTTP request to home.asp with a trailing slash (/).</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/15476" source="XF">vgw48-gateway-directory-traversal(15476)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107936739131657&amp;w=2" source="BUGTRAQ">20040315 VocalTec Gateway 8 Reverse Directory Transversal + Authorization Bypass</ref>
      <ref url="http://www.securityfocus.com/bid/9876" source="BID">9876</ref>
    </refs>
    <vuln_soft>
      <prod vendor="vocaltec" name="vgw4_8_telephony_gateway">
        <vers num="8.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1814" published="2004-12-31" name="CVE-2004-1814" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in VocalTec VGW4/8 Gateway 8.0 allows remote attackers to read protected files via .. (dot dot) sequences in an HTTP request, as demonstrated using home.asp.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/15476" source="XF">vgw48-gateway-directory-traversal(15476)</ref>
      <ref url="http://www.securityfocus.com/bid/9876" source="BID">9876</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107936739131657&amp;w=2" source="BUGTRAQ">20040315 VocalTec Gateway 8 Reverse Directory Transversal + Authorization Bypass</ref>
    </refs>
    <vuln_soft>
      <prod vendor="vocaltec" name="vgw4_8_telephony_gateway">
        <vers num="8.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1815" published="2004-03-15" name="CVE-2004-1815" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Unknown vulnerability in ColdFusion MX 6.0 and 6.1, and JRun 4.0, when a SOAP web service expects an array of objects as an argument, allows remote attackers to cause a denial of service (memory consumption).</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/15473" source="XF" patch="1" adv="1">soap-array-dos(15473)</ref>
      <ref url="http://www.securityfocus.com/bid/9877" source="BID" patch="1" adv="1">9877</ref>
      <ref url="http://www.macromedia.com/devnet/security/security_zone/mpsb04-04.html" source="CONFIRM" patch="1" adv="1">http://www.macromedia.com/devnet/security/security_zone/mpsb04-04.html</ref>
      <ref url="http://secunia.com/advisories/11132" source="SECUNIA" patch="1" adv="1">11132</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107936690702515&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20040315 Multiple Vendor SOAP server array DoS</ref>
    </refs>
    <vuln_soft>
      <prod vendor="macromedia" name="coldfusion">
        <vers num="6.0" />
        <vers num="6.1" />
      </prod>
      <prod vendor="macromedia" name="jrun">
        <vers num="4.0" edition="sp1" />
        <vers num="4.0" edition="sp1a" />
        <vers num="4.0_build_61650" />
      </prod>
      <prod vendor="sun" name="one_application_server">
        <vers num="7.0" edition="" />
        <vers num="7.0" edition=":standard" />
        <vers num="7.0" edition=":platform" />
        <vers num="7.0" edition="ur1" />
        <vers num="7.0" edition="ur1:standard" />
        <vers num="7.0" edition="ur1:platform" />
        <vers num="7.0" edition="ur2" />
        <vers num="7.0" edition="ur2:standard" />
        <vers num="7.0" edition="ur2:platform" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1816" published="2004-03-15" name="CVE-2004-1816" modified="2010-02-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Unknown vulnerability in Sun Java System Application Server 7.0 Update 2 and earlier, when a SOAP web service expects an array of objects as an argument, allows remote attackers to cause a denial of service (memory consumption).</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/15473" source="XF" patch="1" adv="1">soap-array-dos(15473)</ref>
      <ref url="http://www.securityfocus.com/bid/9877" source="BID" patch="1" adv="1">9877</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-57517-1" source="SUNALERT" patch="1" adv="1">57517</ref>
      <ref url="http://secunia.com/advisories/11130" source="SECUNIA" patch="1" adv="1">11130</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107936690702515&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20040315 Multiple Vendor SOAP server array DoS</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-66-201713-1" source="SUNALERT">201713</ref>
    </refs>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1817" published="2004-03-15" name="CVE-2004-1817" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in modules.php in Php-Nuke 7.1.0 allows remote attackers to inject arbitrary web script or HTML via the (1) Your Name field, (2) e-mail field, (3) nicname field, (4) fname parameter, (5) ratenum parameter, or (6) search field.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/15491" source="XF" adv="1">phpnuke-multiple-parameters-xss(15491)</ref>
      <ref url="http://www.securityfocus.com/bid/9879" source="BID" adv="1">9879</ref>
      <ref url="http://secunia.com/advisories/11135" source="SECUNIA" adv="1">11135</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107937752811633&amp;w=2" source="BUGTRAQ" adv="1">20040315 [waraxe-2004-SA#005 - XSS in Php-Nuke 7.1.0 - part 2]</ref>
    </refs>
    <vuln_soft>
      <prod vendor="francisco_burzi" name="php-nuke">
        <vers num="7.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1818" published="2004-03-15" name="CVE-2004-1818" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in nmimage.php in 4nalbum 0.92 for PHP-Nuke 6.5 through 7.0 allows remote attackers to execute arbitrary script as other users by injecting arbitrary script into the z parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/15497" source="XF" adv="1">4nalbum-nmimagephp-xss(15497)</ref>
      <ref url="http://www.securityfocus.com/bid/9881" source="BID" adv="1">9881</ref>
      <ref url="http://www.osvdb.org/4293" source="OSVDB" adv="1">4293</ref>
      <ref url="http://secunia.com/advisories/11134" source="SECUNIA" adv="1">11134</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107937780222514&amp;w=2" source="BUGTRAQ" adv="1">20040315 [waraxe-2004-SA#006 - Multiple vulnerabilities in 4nalbum module for PhpNuke]</ref>
    </refs>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1819" published="2004-03-15" name="CVE-2004-1819" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">4nalbum 0.92 for PHP-Nuke 6.5 through 7.0 allows remote attackers to obtain sensitive information via a direct request to displaycategory.php, which reveals the path in an error message.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/15493" source="XF" adv="1">4nalbum-error path-disclosure(15493)</ref>
      <ref url="http://www.securityfocus.com/bid/9881" source="BID" adv="1">9881</ref>
      <ref url="http://www.osvdb.org/4291" source="OSVDB" adv="1">4291</ref>
      <ref url="http://secunia.com/advisories/11134" source="SECUNIA" adv="1">11134</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107937780222514&amp;w=2" source="BUGTRAQ" adv="1">20040315 [waraxe-2004-SA#006 - Multiple vulnerabilities in 4nalbum module for PhpNuke]</ref>
    </refs>
    <vuln_soft>
      <prod vendor="warpspeed" name="4nalbum_module">
        <vers num="0.92" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-1820" published="2004-03-15" name="CVE-2004-1820" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">PHP remote file inclusion vulnerability in displaycategory.php in 4nalbum 0.92 for PHP-Nuke 6.5 through 7.0 allows remote attackers to execute arbitrary PHP code by modifying the basepath parameter to reference a URL on a remote web server that contains fileFunctions.php.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/11134" source="SECUNIA" patch="1" adv="1">11134</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15496" source="XF" adv="1">4nalbum-displaycategory-file-include(15496)</ref>
      <ref url="http://www.securityfocus.com/bid/9881" source="BID" adv="1">9881</ref>
      <ref url="http://www.osvdb.org/4292" source="OSVDB" adv="1">4292</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107937780222514&amp;w=2" source="BUGTRAQ" adv="1">20040315 [waraxe-2004-SA#006 - Multiple vulnerabilities in 4nalbum module for PhpNuke]</ref>
    </refs>
    <vuln_soft>
      <prod vendor="warpspeed" name="4nalbum_module">
        <vers num="0.92" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-1821" published="2004-03-15" name="CVE-2004-1821" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in 4nalbum 0.92 for PHP-Nuke 6.5 through 7.0 allows remote attackers to gain privileges or perform unauthorized database operations via the gid parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/11134" source="SECUNIA" patch="1" adv="1">11134</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15498" source="XF" adv="1">4nalbum-modulesphp-SQL-injection(15498)</ref>
      <ref url="http://www.securityfocus.com/bid/9881" source="BID" adv="1">9881</ref>
      <ref url="http://www.osvdb.org/4294" source="OSVDB" adv="1">4294</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107937780222514&amp;w=2" source="BUGTRAQ" adv="1">20040315 [waraxe-2004-SA#006 - Multiple vulnerabilities in 4nalbum module for PhpNuke]</ref>
    </refs>
    <vuln_soft>
      <prod vendor="warpspeed" name="4nalbum_module">
        <vers num="0.92" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1822" published="2004-03-15" name="CVE-2004-1822" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in Phorum 3.1 through 5.0.3 beta allow remote attackers to inject arbitrary web script or HTML via the (1) HTTP_REFERER parameter to login.php, (2) HTTP_REFERER parameter to register.php, or (3) target parameter to profile.php.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/9882" source="BID" patch="1" adv="1">9882</ref>
      <ref url="http://secunia.com/advisories/11157" source="SECUNIA" patch="1" adv="1">11157</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15494" source="XF" adv="1">phorum-register-xss(15494)</ref>
      <ref url="http://phorum.org/changelog.txt" source="CONFIRM" adv="1">http://phorum.org/changelog.txt</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107939479713136&amp;w=2" source="BUGTRAQ" adv="1">20040315 Phorum 5.0.3 Beta &amp;&amp; Earlier XSS Issues</ref>
      <ref url="http://www.osvdb.org/4335" source="OSVDB">4335</ref>
      <ref url="http://www.osvdb.org/4334" source="OSVDB">4334</ref>
      <ref url="http://www.osvdb.org/4333" source="OSVDB">4333</ref>
      <ref url="http://securitytracker.com/id?1009433" source="SECTRACK">1009433</ref>
    </refs>
    <vuln_soft>
      <prod vendor="phorum" name="phorum">
        <vers num="3.1" />
        <vers num="3.1.1" />
        <vers num="3.1.1_pre" />
        <vers num="3.1.1_rc2" />
        <vers num="3.1.1a" />
        <vers num="3.1.2" />
        <vers num="3.2" />
        <vers num="3.2.2" />
        <vers num="3.2.3" />
        <vers num="3.2.3a" />
        <vers num="3.2.3b" />
        <vers num="3.2.4" />
        <vers num="3.2.5" />
        <vers num="3.2.6" />
        <vers num="3.2.7" />
        <vers num="3.2.8" />
        <vers num="3.3.1" />
        <vers num="3.3.1a" />
        <vers num="3.3.2" />
        <vers num="3.3.2a" />
        <vers num="3.3.2b3" />
        <vers num="3.4" />
        <vers num="3.4.1" />
        <vers num="3.4.2" />
        <vers num="3.4.3" />
        <vers num="3.4.4" />
        <vers num="3.4.5" />
        <vers num="3.4.6" />
        <vers num="5.0.3_beta" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1823" published="2004-12-31" name="CVE-2004-1823" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in Jelsoft vBulletin 2.0 beta 3 through 3.0 can4 allows remote attackers to inject arbitrary web script or HTML via the (1) page parameter to showthread.php or (2) order parameter to forumdisplay.php.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/11142" source="SECUNIA" patch="1">11142</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15495" source="XF">vbulletin-showthread-xss(15495)</ref>
      <ref url="http://www.securityfocus.com/bid/9889" source="BID">9889</ref>
      <ref url="http://www.securityfocus.com/bid/9888" source="BID">9888</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107945556112453&amp;w=2" source="BUGTRAQ">20040316 JelSoft vBulletin Multiple XSS Vulnerabilities</ref>
      <ref url="http://www.osvdb.org/4311" source="OSVDB">4311</ref>
      <ref url="http://www.osvdb.org/4310" source="OSVDB">4310</ref>
      <ref url="http://securitytracker.com/id?1009440" source="SECTRACK">1009440</ref>
    </refs>
    <vuln_soft>
      <prod vendor="jelsoft" name="vbulletin">
        <vers num="3.0.0" />
        <vers num="3.0.0_can4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1824" published="2004-12-31" name="CVE-2004-1824" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in Jelsoft vBulletin before 3.0 allows remote attackers to inject arbitrary web script or HTML via the what parameter to memberlist.php.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/11142" source="SECUNIA" patch="1">11142</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15495" source="XF">vbulletin-showthread-xss(15495)</ref>
      <ref url="http://www.securityfocus.com/bid/9887" source="BID">9887</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107945556112453&amp;w=2" source="BUGTRAQ">20040316 JelSoft vBulletin Multiple XSS Vulnerabilities</ref>
      <ref url="http://www.securityfocus.com/bid/6226" source="BID">6226</ref>
      <ref url="http://www.osvdb.org/4312" source="OSVDB">4312</ref>
      <ref url="http://www.iss.net/security_center/static/10679.php" source="XF">vbulletin-memberlist-xss(10679)</ref>
      <ref url="http://securitytracker.com/id?1009440" source="SECTRACK">1009440</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2002-11/0276.html" source="BUGTRAQ">20021121 XSS bug in vBulletin</ref>
    </refs>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1825" published="2004-03-16" name="CVE-2004-1825" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in index.php in Mambo Open Source 4.5 stable 1.0.3 and earlier allows remote attackers to inject arbitrary web script or HTML via the (1) return or (2) mos_change_template parameters.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.osvdb.org/4665" source="OSVDB" patch="1" adv="1">4665</ref>
      <ref url="http://secunia.com/advisories/11140" source="SECUNIA" patch="1" adv="1">11140</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107945576020593&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20040316 Mambo Open Source Multiple Vulnerabilities</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15499" source="XF" adv="1">mambo-return-moschangetemplate-xss(15499)</ref>
      <ref url="http://www.securityfocus.com/bid/9890" source="BID" adv="1">9890</ref>
      <ref url="http://www.osvdb.org/4308" source="OSVDB">4308</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mambo" name="mambo_open_source">
        <vers num="4.5_1.0.0" />
        <vers num="4.5_1.0.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-1826" published="2004-03-16" name="CVE-2004-1826" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in index.php in Mambo Open Source 4.5 stable 1.0.3 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.osvdb.org/4307" source="OSVDB" patch="1" adv="1">4307</ref>
      <ref url="http://secunia.com/advisories/11140" source="SECUNIA" patch="1" adv="1">11140</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107945576020593&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20040316 Mambo Open Source Multiple Vulnerabilities</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15500" source="XF" adv="1">mambo-id-sql-injection(15500)</ref>
      <ref url="http://www.securityfocus.com/bid/9891" source="BID" adv="1">9891</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mambo" name="mambo_open_source_4.5">
        <vers num="1.0.0" />
        <vers num="1.0.1" />
        <vers num="1.0.2" />
        <vers num="1.0.3" />
        <vers num="1.0.3beta" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1827" published="2004-03-15" name="CVE-2004-1827" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in YaBB 1 Gold(SP1.3) and YaBB SE 1.5.1 Final allows remote attackers to inject arbitrary web script via the background:url property in (1) glow or (2) shadow tags.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/9873" source="BID" patch="1" adv="1">9873</ref>
      <ref url="http://secunia.com/advisories/11128" source="SECUNIA" patch="1" adv="1">11128</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15488" source="XF" adv="1">yabb-glow-shadow-xss(15488)</ref>
      <ref url="http://www.yabbforum.com/community/YaBB.pl?board=general;action=display;num=1093133233" source="CONFIRM">http://www.yabbforum.com/community/YaBB.pl?board=general;action=display;num=1093133233</ref>
      <ref url="http://securitytracker.com/id?1009427" source="SECTRACK">1009427</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107948064923981&amp;w=2" source="BUGTRAQ">20040316 RE: YaBB/YaBBse Cross Site Scripting Vulnerability</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107936800226430&amp;w=2" source="BUGTRAQ">20040314 YaBB/YaBBse Cross Site Scripting Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="simple_machines" name="simple_machines_smf">
        <vers num="1.0_b" />
      </prod>
      <prod vendor="yabb" name="yabb">
        <vers num="1.5.1" edition="" />
        <vers num="1.5.1" edition=":second_edition" />
        <vers num="1_gold_-_sp_1.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1828" published="2004-12-31" name="CVE-2004-1828" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Vcard 2.9 and possibly other versions does not require authorization to run uninstall.php, which could allow remote attackers to uninstall Vcard and delete database tables via a direct request to uninstall.php.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <config />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/9910" source="BID" patch="1">9910</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107957312531199&amp;w=2" source="BUGTRAQ" patch="1">20040317 Vcard 2.8 uninstall script problem</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15522" source="XF">vcard-uninstall-delete-table(15522)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="belchior_foundry" name="vcard">
        <vers num="2.8" />
        <vers num="2.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1829" published="2004-03-18" name="CVE-2004-1829" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in error.php in Gijza.net Error Manager 2.1 for PHP-Nuke 6.0 allow remote attackers to inject arbitrary web script or HTML via the (1) pagetitle or (2) error parameters, or (3) certain parameters in the error log.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/15530" source="XF" adv="1">errormanager-error-command-execution(15530)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15529" source="XF" adv="1">errormanager-error-xss(15529)</ref>
      <ref url="http://www.securityfocus.com/bid/9911" source="BID" adv="1">9911</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107963064317560&amp;w=2" source="BUGTRAQ" adv="1">20040318 [waraxe-2004-SA#010 - Multiple vulnerabilities in Error Manager</ref>
      <ref url="http://www.osvdb.org/4384" source="OSVDB">4384</ref>
      <ref url="http://secunia.com/advisories/11164" source="SECUNIA">11164</ref>
    </refs>
    <vuln_soft>
      <prod vendor="error_manager" name="php-nuke_module">
        <vers num="2.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1830" published="2004-03-18" name="CVE-2004-1830" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">error.php in Error Manager 2.1 for PHP-Nuke 6.0 allows remote attackers to obtain sensitive information via an invalid (1) language, (2) newlang, or (3) lang parameter, which leaks the pathname in a PHP error message.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/15524" source="XF">errormanager-error-path-disclosure(15524)</ref>
      <ref url="http://www.securityfocus.com/bid/9911" source="BID">9911</ref>
      <ref url="http://www.osvdb.org/4386" source="OSVDB">4386</ref>
      <ref url="http://secunia.com/advisories/11164" source="SECUNIA">11164</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107963064317560&amp;w=2" source="BUGTRAQ" adv="1">20040318 [waraxe-2004-SA#010 - Multiple vulnerabilities in Error Manager</ref>
    </refs>
    <vuln_soft>
      <prod vendor="francisco_burzi" name="php-nuke">
        <vers num="6.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1831" published="2004-12-31" name="CVE-2004-1831" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Buffer overflow in Chrome 1.2.0.0 and earlier allows remote attackers to cause a denial of service (crash) via a packet with a large length value, which leads to a null dereference or out-of-bounds read.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/15535" source="XF">chrome-malloc-memcpy-dos(15535)</ref>
      <ref url="http://www.securityfocus.com/bid/9898" source="BID">9898</ref>
      <ref url="http://aluigi.altervista.org/adv/chrome-boom-adv.txt" source="MISC">http://aluigi.altervista.org/adv/chrome-boom-adv.txt</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107964719614657&amp;w=2" source="BUGTRAQ">20040318 Chrome 1.2.0.0 server crash</ref>
    </refs>
    <vuln_soft>
      <prod vendor="techland" name="chrome">
        <vers num="1.2.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1832" published="2004-12-31" name="CVE-2004-1832" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Buffer overflow in the GUI admin service in Mac OS X Server 10.3 allows remote attackers to cause a denial of service (crash and restart) via a large amount of data to TCP port 660.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/15533" source="XF">macos-admin-servicebo(15533)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107971225327629&amp;w=2" source="BUGTRAQ">20040319 Re: mac osx- admin service buffer overflow</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107965605008575&amp;w=2" source="BUGTRAQ">20040318 mac osx- admin service buffer overflow</ref>
      <ref url="http://www.securityfocus.com/bid/9914" source="BID">9914</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x_server">
        <vers num="10.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-1833" published="2004-03-20" name="CVE-2004-1833" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">The admin.ib file in Borland Interbase 7.1 for Linux has default world writable permissions, which allows local users to gain database administrative privileges.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <config />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/9929" source="BID" patch="1" adv="1">9929</ref>
      <ref url="http://securitytracker.com/id?1009500" source="SECTRACK" patch="1" adv="1">1009500</ref>
      <ref url="http://secunia.com/advisories/11172" source="SECUNIA" patch="1" adv="1">11172</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15546" source="XF" adv="1">interbase-admin-gain-privileges(15546)</ref>
      <ref url="http://www.osvdb.org/4381" source="OSVDB" adv="1">4381</ref>
      <ref url="http://www.idefense.com/application/poi/display?id=80&amp;type=vulnerabilities&amp;flashstatus=true" source="IDEFENSE" adv="1">20040319 Borland Interbase admin.ib Administrative Access Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="borland_software" name="interbase">
        <vers num="4.0" />
        <vers num="5.0" />
        <vers num="6.0" />
        <vers num="6.4" />
        <vers num="6.5" />
        <vers num="7.0" />
        <vers num="7.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2004-1834" published="2004-03-20" name="CVE-2004-1834" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">mod_disk_cache in Apache 2.0 through 2.0.49 stores client headers, including authentication information, on the hard disk, which could allow local users to gain sensitive information.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/15547" source="XF" patch="1" adv="1">apache-moddiskcache-obtain-info(15547)</ref>
      <ref url="http://www.securityfocus.com/bid/9933" source="BID" patch="1" adv="1">9933</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0789" source="VUPEN">ADV-2006-0789</ref>
      <ref url="http://www.osvdb.org/4446" source="OSVDB" adv="1">4446</ref>
      <ref url="http://securitytracker.com/id?1009509" source="SECTRACK" adv="1">1009509</ref>
      <ref url="http://secunia.com/advisories/11176" source="SECUNIA" adv="1">11176</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11133" source="OVAL">oval:org.mitre.oval:def:11133</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107981737322495&amp;w=2" source="BUGTRAQ" adv="1">20040319 Apache mod_disk_cache stores client authentication credentials on disk</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-562.html" source="REDHAT">RHSA-2004:562</ref>
      <ref url="http://support.avaya.com/elmodocs2/security/ASA-2006-081.htm" source="CONFIRM">http://support.avaya.com/elmodocs2/security/ASA-2006-081.htm</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-102198-1" source="SUNALERT">102198</ref>
      <ref url="http://secunia.com/advisories/19072" source="SECUNIA">19072</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apache" name="http_server">
        <vers num="2.0" />
        <vers num="2.0.28" edition="beta" />
        <vers num="2.0.32" />
        <vers num="2.0.35" />
        <vers num="2.0.36" />
        <vers num="2.0.37" />
        <vers num="2.0.38" />
        <vers num="2.0.39" />
        <vers num="2.0.40" />
        <vers num="2.0.41" />
        <vers num="2.0.42" />
        <vers num="2.0.43" />
        <vers num="2.0.44" />
        <vers num="2.0.45" />
        <vers num="2.0.46" />
        <vers num="2.0.47" />
        <vers num="2.0.48" />
        <vers num="2.0.49" />
        <vers num="2.0.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-1835" published="2004-12-31" name="CVE-2004-1835" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple SQL injection vulnerabilities in index.php in Invision Gallery 1.0.1 allow remote attackers to execute arbitrary SQL via the (1) img, (2) cat, (3) sort_key, (4) order_key, (5) user, or (6) album parameters.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/15566" source="XF">invision-gallery-sql-injection(15566)</ref>
      <ref url="http://www.securityfocus.com/bid/9944" source="BID">9944</ref>
      <ref url="http://www.osvdb.org/4472" source="OSVDB">4472</ref>
      <ref url="http://securitytracker.com/id?1009512" source="SECTRACK">1009512</ref>
      <ref url="http://secunia.com/advisories/11194" source="SECUNIA">11194</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107997906500032&amp;w=2" source="BUGTRAQ">20040322 Invision Gallery SQL Injection Vulnerabilities</ref>
    </refs>
    <vuln_soft>
      <prod vendor="invision_power_services" name="invision_gallery">
        <vers num="1.0.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-1836" published="2004-12-31" name="CVE-2004-1836" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in index.php in Invision Power Top Site List 1.1 RC 2 and earlier allows remote attackers to execute arbitrary SQL via the id parameter of the comments action.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/15568" source="XF">invision-id-sql-injection(15568)</ref>
      <ref url="http://www.securityfocus.com/bid/9945" source="BID">9945</ref>
      <ref url="http://securitytracker.com/id?1009511" source="SECTRACK">1009511</ref>
      <ref url="http://secunia.com/advisories/11187" source="SECUNIA">11187</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107997924117652&amp;w=2" source="BUGTRAQ">20040322 Invision Power Top Site List SQL Injection Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="invision_power_services" name="invision_power_top_site_list">
        <vers num="1.0" />
        <vers num="1.1" />
        <vers num="1.1_rc2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1837" published="2004-12-31" name="CVE-2004-1837" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in Mod_survey 3.0.x before 3.0.16-pre2 and 3.2.x before 3.2.0-pre4 allows remote attackers to inject arbitrary web script or HTML via the certain survey fields or error messages for malformed query strings.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/9941" source="BID" patch="1">9941</ref>
      <ref url="http://securitytracker.com/id?1009516" source="SECTRACK" patch="1">1009516</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15582" source="XF">modsurvey-xss(15582)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107997967421972&amp;w=2" source="BUGTRAQ">20040322 Mod_Survey security advisory: Script injection bug</ref>
    </refs>
    <vuln_soft>
      <prod vendor="joel_palmius" name="mod_survey">
        <vers num="3.0.0" />
        <vers num="3.0.1" />
        <vers num="3.0.10" />
        <vers num="3.0.11" />
        <vers num="3.0.12" />
        <vers num="3.0.13" />
        <vers num="3.0.14" />
        <vers num="3.0.14d" />
        <vers num="3.0.14e" />
        <vers num="3.0.15" />
        <vers num="3.0.15_pre1" />
        <vers num="3.0.15_pre2" />
        <vers num="3.0.15_pre3" />
        <vers num="3.0.15_pre4" />
        <vers num="3.0.15_pre5" />
        <vers num="3.0.15_pre6" />
        <vers num="3.0.16_pre1" />
        <vers num="3.0.2" />
        <vers num="3.0.3" />
        <vers num="3.0.4" />
        <vers num="3.0.5" />
        <vers num="3.0.6" />
        <vers num="3.0.9" />
        <vers num="3.2.0_pre1" />
        <vers num="3.2.0_pre2" />
        <vers num="3.2.0_pre3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1838" published="2004-03-22" name="CVE-2004-1838" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in xweb 1.0 allows remote attackers to download arbitrary files via a .. (dot dot) in the URL.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <access />
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/9937" source="BID" patch="1" adv="1">9937</ref>
      <ref url="http://www.autistici.org/fdonato/advisory/xweb1.0-adv.txt" source="MISC" patch="1" adv="1">http://www.autistici.org/fdonato/advisory/xweb1.0-adv.txt</ref>
      <ref url="http://securitytracker.com/id?1009514" source="SECTRACK" patch="1" adv="1">1009514</ref>
      <ref url="http://secunia.com/advisories/11186" source="SECUNIA" patch="1" adv="1">11186</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107997946623770&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20040322 directory traversal in xweb 1.0</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15567" source="XF" adv="1">xweb-dotdot-directory-traversal(15567)</ref>
      <ref url="http://www.osvdb.org/4460" source="OSVDB" adv="1">4460</ref>
    </refs>
    <vuln_soft>
      <prod vendor="xweb" name="xweb">
        <vers num="1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1839" published="2004-03-22" name="CVE-2004-1839" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">MS Analysis module 2.0 for PHP-Nuke allows remote attackers to obtain sensitive information via a direct request to (1) browsers.php, (2) mstrack.php, or (3) title.php, which reveal the full path in a PHP error message.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/9946" source="BID" adv="1">9946</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108006319730976&amp;w=2" source="BUGTRAQ" adv="1">20040322  [waraxe-2004-SA#011 Multiple vulnerabilities in MS Analysis v2.0 module for PhpNuke]</ref>
    </refs>
    <vuln_soft>
      <prod vendor="francisco_burzi" name="php-nuke">
        <vers num="6.5" />
        <vers num="6.5_beta1" />
        <vers num="6.5_final" />
        <vers num="6.5_rc1" />
        <vers num="6.5_rc2" />
        <vers num="6.5_rc3" />
        <vers num="6.6" />
        <vers num="6.7" />
        <vers num="6.9" />
        <vers num="7.0" />
        <vers num="7.0_final" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1840" published="2004-03-22" name="CVE-2004-1840" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in MS Analysis module 2.0 for PHP-Nuke allows remote attackers to inject arbitrary web script or HTML via the (1) screen parameter to modules.php, (2) module_name parameter to title.php, (3) sortby parameter to modules.php, or (4) overview parameter to modules.php.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/15575" source="XF" adv="1">msanalysis-modules-title-xss(15575)</ref>
      <ref url="http://www.securityfocus.com/bid/9947" source="BID" adv="1">9947</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108006319730976&amp;w=2" source="BUGTRAQ" adv="1">20040322  [waraxe-2004-SA#011 Multiple vulnerabilities in MS Analysis v2.0 module for PhpNuke]</ref>
    </refs>
    <vuln_soft>
      <prod vendor="francisco_burzi" name="php-nuke">
        <vers num="6.5" />
        <vers num="6.5_beta1" />
        <vers num="6.5_final" />
        <vers num="6.5_rc1" />
        <vers num="6.5_rc2" />
        <vers num="6.5_rc3" />
        <vers num="6.6" />
        <vers num="6.7" />
        <vers num="6.9" />
        <vers num="7.0" />
        <vers num="7.0_final" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-1841" published="2004-12-31" name="CVE-2004-1841" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in MS Analysis module 2.0 for PHP-Nuke allows remote attackers to execute arbitrary SQL via the referer field in an HTTP request.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/15576" source="XF">msanalysis-referer-sql-injection(15576)</ref>
      <ref url="http://www.securityfocus.com/bid/9948" source="BID">9948</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108006319730976&amp;w=2" source="BUGTRAQ">20040322  [waraxe-2004-SA#011 Multiple vulnerabilities in MS Analysis v2.0 module for PhpNuke]</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ms_analysis" name="website_traffic_analyzer">
        <vers num="2.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-1842" published="2004-12-31" name="CVE-2004-1842" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Cross-site request forgery (CSRF) vulnerability in Php-Nuke 6.x through 7.1.0 allows remote attackers to gain administrative privileges via an img tag with a URL to admin.php.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/15596" source="XF">phpnuke-img-gain-privileges(15596)</ref>
      <ref url="http://www.securityfocus.com/bid/9895" source="BID">9895</ref>
      <ref url="http://secunia.com/advisories/11195" source="SECUNIA">11195</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108006309112075&amp;w=2" source="BUGTRAQ">20040322 [waraxe-2004-SA#008 - easy way to get superadmin rights in PhpNuke 6.x-7.1.0]</ref>
    </refs>
    <vuln_soft>
      <prod vendor="francisco_burzi" name="php-nuke">
        <vers num="6.0" />
        <vers num="6.5" />
        <vers num="6.5_beta1" />
        <vers num="6.5_final" />
        <vers num="6.5_rc1" />
        <vers num="6.5_rc2" />
        <vers num="6.5_rc3" />
        <vers num="6.6" />
        <vers num="6.7" />
        <vers num="6.9" />
        <vers num="7.0" />
        <vers num="7.0_final" />
        <vers num="7.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-1843" published="2004-03-20" name="CVE-2004-1843" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in Member Management System 2.1 allows remote attackers to execute arbitrary SQL via the ID parameter to (1) resend.asp or (2) news_view.asp.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/9931" source="BID" patch="1" adv="1">9931</ref>
      <ref url="http://securitytracker.com/id?1009508" source="SECTRACK" patch="1" adv="1">1009508</ref>
      <ref url="http://secunia.com/advisories/11179" source="SECUNIA" patch="1" adv="1">11179</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107999697625786&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20040322 Vulnerabilities in Member Management System 2.1</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15551" source="XF" adv="1">mms-id-sql-injection(15551)</ref>
    </refs>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1844" published="2004-12-31" name="CVE-2004-1844" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in Member Management System 2.1 allows remote attackers to inject arbitrary web script or HTML via (1) the err parameter to error.asp or (2) register.asp.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/15552" source="XF">mms-xss(15552)</ref>
      <ref url="http://www.securityfocus.com/bid/9932" source="BID">9932</ref>
      <ref url="http://securitytracker.com/id?1009508" source="SECTRACK">1009508</ref>
      <ref url="http://secunia.com/advisories/11179" source="SECUNIA">11179</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107999697625786&amp;w=2" source="BUGTRAQ">20040322 Vulnerabilities in Member Management System 2.1</ref>
    </refs>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1845" published="2004-12-31" name="CVE-2004-1845" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in News Manager Lite 2.5 allow remote attackers to inject arbitrary web script or HTML via the (1) email parameter to comment_add.asp, (2) search parameter to search.asp, or (3) n parameter to category_news_headline.asp.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/15548" source="XF">news-manager-xss(15548)</ref>
      <ref url="http://www.securityfocus.com/bid/9935" source="BID">9935</ref>
      <ref url="http://www.osvdb.org/4494" source="OSVDB">4494</ref>
      <ref url="http://www.osvdb.org/4493" source="OSVDB">4493</ref>
      <ref url="http://www.osvdb.org/4492" source="OSVDB">4492</ref>
      <ref url="http://securitytracker.com/id?1009507" source="SECTRACK">1009507</ref>
      <ref url="http://secunia.com/advisories/11180" source="SECUNIA">11180</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107999733503496&amp;w=2" source="BUGTRAQ">20040322 Vulnerabilities in News Manager Lite 2.5 &amp; News Manager Lite administration</ref>
    </refs>
    <vuln_soft>
      <prod vendor="expinion.net" name="news_manager_lite">
        <vers num="2.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-1846" published="2004-03-20" name="CVE-2004-1846" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple SQL injection vulnerabilities in News Manager Lite 2.5 allow remote attackers to execute arbitrary SQL code via the (1) ID parameter to more.asp, (2) ID parameter to category_news.asp, or (3) filter parameter to news_sort.asp.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/9935" source="BID" patch="1" adv="1">9935</ref>
      <ref url="http://securitytracker.com/id?1009507" source="SECTRACK" patch="1" adv="1">1009507</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15549" source="XF" adv="1">news-manager-sql-injection(15549)</ref>
      <ref url="http://www.osvdb.org/4497" source="OSVDB" adv="1">4497</ref>
      <ref url="http://www.osvdb.org/4496" source="OSVDB" adv="1">4496</ref>
      <ref url="http://www.osvdb.org/4495" source="OSVDB" adv="1">4495</ref>
      <ref url="http://secunia.com/advisories/11180" source="SECUNIA">11180</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107999733503496&amp;w=2" source="BUGTRAQ" adv="1">20040322 Vulnerabilities in News Manager Lite 2.5 &amp; News Manager Lite administration</ref>
    </refs>
    <vuln_soft>
      <prod vendor="expinion.net" name="news_manager_lite">
        <vers num="2.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-1847" published="2004-03-20" name="CVE-2004-1847" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">News Manager Lite 2.5 allows remote attackers to bypass authentication and gain administrator privileges by setting the ADMIN parameter in the NEWS_LOGIN cookie.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/9935" source="BID" patch="1">9935</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15550" source="XF" adv="1">news-manager-admin-access(15550)</ref>
      <ref url="http://securitytracker.com/id?1009507" source="SECTRACK" adv="1">1009507</ref>
      <ref url="http://secunia.com/advisories/11180" source="SECUNIA" adv="1">11180</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107999733503496&amp;w=2" source="BUGTRAQ" adv="1">20040322 Vulnerabilities in News Manager Lite 2.5 &amp; News Manager Lite administration</ref>
    </refs>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1848" published="2004-12-31" name="CVE-2004-1848" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Ipswitch WS_FTP Server 4.0.2 allows remote attackers to cause a denial of service (disk consumption) and bypass file size restrictions via a REST command with a large size argument, followed by a STOR of a smaller file.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <design />
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/11206" source="SECUNIA" patch="1">11206</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/41831" source="XF">wsftp-rest-stor-dos(41831)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15560" source="XF">wsftp-rest-dos(15560)</ref>
      <ref url="http://www.securityfocus.com/bid/9953" source="BID">9953</ref>
      <ref url="http://www.osvdb.org/4542" source="OSVDB">4542</ref>
      <ref url="http://securitytracker.com/id?1009529" source="SECTRACK">1009529</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108006717731989&amp;w=2" source="BUGTRAQ">20040323 How to crash a harddisk - the Ipswitch WS_FTP Server way</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ipswitch" name="ws_ftp_server">
        <vers num="1.0.1" />
        <vers num="1.0.2" />
        <vers num="1.0.3" />
        <vers num="1.0.4" />
        <vers num="1.0.5" />
        <vers num="2.0" />
        <vers num="2.0.1" />
        <vers num="2.0.2" />
        <vers num="2.0.3" />
        <vers num="2.0.4" />
        <vers num="3.0" />
        <vers num="3.0_1" />
        <vers num="3.1" />
        <vers num="3.1.1" />
        <vers num="3.1.2" />
        <vers num="3.1.3" />
        <vers num="3.4" />
        <vers num="4.0" />
        <vers num="4.0.2" />
        <vers num="4.01" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1849" published="2004-03-24" name="CVE-2004-1849" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in cPanel 9.1.0 allow remote attackers to inject arbitrary web script or HTML via the (1) email parameter to dodelautores.html or (2) handle parameter to addhandle.html.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/15517" source="XF" adv="1">cpanel-dodelautores-addhandle-xss(15517)</ref>
      <ref url="http://www.securityfocus.com/bid/9965" source="BID" adv="1">9965</ref>
      <ref url="http://www.osvdb.org/4530" source="OSVDB" adv="1">4530</ref>
      <ref url="http://www.osvdb.org/4529" source="OSVDB" adv="1">4529</ref>
      <ref url="http://securitytracker.com/id?1009541" source="SECTRACK" adv="1">1009541</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108006627005371&amp;w=2" source="BUGTRAQ" adv="1">20040323 More Cpanel Vuls (cross site scripting)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cpanel" name="cpanel">
        <vers num="9.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1850" published="2004-03-23" name="CVE-2004-1850" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The Rage 1.01 and earlier allows remote attackers to cause a denial of service (infinite loop) via a TCP packet with the port and IP address set to zero.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/15584" source="XF" adv="1">therage-packet-dos(15584)</ref>
      <ref url="http://www.securityfocus.com/bid/9961" source="BID" adv="1">9961</ref>
      <ref url="http://securitytracker.com/id?1009540" source="SECTRACK" adv="1">1009540</ref>
      <ref url="http://aluigi.altervista.org/adv/ragefreeze-adv.txt" source="MISC" adv="1">http://aluigi.altervista.org/adv/ragefreeze-adv.txt</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108006680013576&amp;w=2" source="BUGTRAQ">20040323 Server freeze in The Rage 1.01</ref>
    </refs>
    <vuln_soft>
      <prod vendor="fluidgames" name="the_rage">
        <vers num="1.0_1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-1851" published="2004-03-24" name="CVE-2004-1851" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Dameware Mini Remote Control 4.1.0.0 uses insufficiently random data to create the encryption key, which makes it easier for remote attackers to obtain sensitive information via brute force guessing.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/11205" source="SECUNIA" patch="1" adv="1">11205</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15587" source="XF" adv="1">dameware-random-generator-weak(15587)</ref>
      <ref url="http://www.securityfocus.com/bid/9957" source="BID" adv="1">9957</ref>
      <ref url="http://www.osvdb.org/4547" source="OSVDB" adv="1">4547</ref>
      <ref url="http://securitytracker.com/id?1009557" source="SECTRACK" adv="1">1009557</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108016344224973&amp;w=2" source="BUGTRAQ" adv="1">20030323 Dameware Passes Weak File Encryption Key in the Clear</ref>
    </refs>
    <vuln_soft>
      <prod vendor="dameware_development" name="mini_remote_control_server">
        <vers num="4.1_.0.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1852" published="2004-03-23" name="CVE-2004-1852" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">DameWare Mini Remote Control 3.x before 3.74 and 4.x before 4.2 transmits the Blowfish encryption key in plaintext, which allows remote attackers to gain sensitive information.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/15586" source="XF" patch="1" adv="1">dameware-encryption-key-plaintext(15586)</ref>
      <ref url="http://www.securityfocus.com/bid/9959" source="BID" patch="1" adv="1">9959</ref>
      <ref url="http://www.dameware.com/support/security/bulletin.asp?ID=SB3" source="CONFIRM" patch="1" adv="1">http://www.dameware.com/support/security/bulletin.asp?ID=SB3</ref>
      <ref url="http://secunia.com/advisories/11205" source="SECUNIA" patch="1" adv="1">11205</ref>
      <ref url="http://www.osvdb.org/4547" source="OSVDB" adv="1">4547</ref>
      <ref url="http://securitytracker.com/id?1009557" source="SECTRACK" adv="1">1009557</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108016344224973&amp;w=2" source="BUGTRAQ" adv="1">20040323 Dameware Passes Weak File Encryption Key in the Clear</ref>
    </refs>
    <vuln_soft>
      <prod vendor="dameware_development" name="mini_remote_control_server">
        <vers num="3.70_.0.0" />
        <vers num="3.71_.0.0" />
        <vers num="3.72_.0.0" />
        <vers num="3.73_.0.0" />
        <vers num="4.0" />
        <vers num="4.1_.0.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1853" published="2004-03-19" name="CVE-2004-1853" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Buffer overflow in Terminator 3: War of the Machines 1.0 allows remote attackers to cause a denial of service via a long ServerInfo variable.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://securitytracker.com/id?1009498" source="SECTRACK" patch="1" adv="1">1009498</ref>
      <ref url="http://secunia.com/advisories/11182" source="SECUNIA" patch="1" adv="1">11182</ref>
      <ref url="http://aluigi.altervista.org/adv/t3cbof-adv.txt" source="MISC" patch="1" adv="1">http://aluigi.altervista.org/adv/t3cbof-adv.txt</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15542" source="XF" adv="1">terminator3-bo(15542)</ref>
      <ref url="http://www.securityfocus.com/bid/9918" source="BID" adv="1">9918</ref>
      <ref url="http://www.osvdb.org/4447" source="OSVDB" adv="1">4447</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108016076221855&amp;w=2" source="BUGTRAQ">20040323 Broadcast client buffer-overflow in Terminator 3 1.0</ref>
    </refs>
    <vuln_soft>
      <prod vendor="atari" name="terminator_3_war_of_the_machines">
        <vers num="1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-1854" published="2004-03-24" name="CVE-2004-1854" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in the logging function in Picophone 1.63 and earlier allows remote attackers to execute arbitrary code via a large packet.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/15595" source="XF" patch="1" adv="1">picophone-logging-function-bo(15595)</ref>
      <ref url="http://www.securityfocus.com/bid/9969" source="BID" patch="1" adv="1">9969</ref>
      <ref url="http://securitytracker.com/id?1009551" source="SECTRACK" patch="1" adv="1">1009551</ref>
      <ref url="http://secunia.com/advisories/11209" source="SECUNIA" patch="1" adv="1">11209</ref>
      <ref url="http://aluigi.altervista.org/adv/picobof-adv.txt" source="MISC" patch="1" adv="1">http://aluigi.altervista.org/adv/picobof-adv.txt</ref>
      <ref url="http://www.osvdb.org/4550" source="OSVDB" adv="1">4550</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108016032220647&amp;w=2" source="BUGTRAQ">20040324 Buffer overflow in PicoPhone 1.63</ref>
    </refs>
    <vuln_soft>
      <prod vendor="picophone" name="internet_telephone">
        <vers num="1.63" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1855" published="2004-03-23" name="CVE-2004-1855" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Dark Age of Camelot before 1.68 live patch does not sign the RSA public key, which could allow remote malicious servers to gain sensitive information via a man-in-the-middle attack.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/15597" source="XF" adv="1">daoc-login-mitm(15597)</ref>
      <ref url="http://www.securityfocus.com/bid/9960" source="BID" adv="1">9960</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108016932816707&amp;w=2" source="BUGTRAQ" adv="1">20040324 Dark Age of Camelot login client vulnerability to man in the middle</ref>
      <ref url="http://lists.netsys.com/pipermail/full-disclosure/2004-March/019212.html" source="FULLDISC">20040323 Dark Age of Camelot login client vulnerability to man in the middle attack</ref>
      <ref url="http://capnbry.net/daoc/advisory20040323/" source="MISC" adv="1">http://capnbry.net/daoc/advisory20040323/</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mythic_entertainment" name="dark_age_of_camelot">
        <vers num="1.60" />
        <vers num="1.61" />
        <vers num="1.62" />
        <vers num="1.63" />
        <vers num="1.65" />
        <vers num="1.66" />
        <vers num="1.67" />
        <vers num="1.68" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1856" published="2004-03-24" name="CVE-2004-1856" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">devices_update_printer_fw_upload.hts in HP Web JetAdmin 7.5.2546, when no password is set, allows remote attackers to upload arbitrary files to the printer directory.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <access />
      <config />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/15605" source="XF" adv="1">hp-jetadmin-file-upload(15605)</ref>
      <ref url="http://www.securityfocus.com/bid/9971" source="BID" adv="1">9971</ref>
      <ref url="http://www.securityfocus.com/advisories/6492" source="HP">SSRT4700</ref>
      <ref url="http://sh0dan.org/files/hpjadmadv.txt" source="MISC" adv="1">http://sh0dan.org/files/hpjadmadv.txt</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108016019623003&amp;w=2" source="BUGTRAQ" adv="1">20040324 HP Web JetAdmin vulnerabilities.</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hp" name="web_jetadmin">
        <vers num="7.5.2546" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2004-1857" published="2004-03-24" name="CVE-2004-1857" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">Directory traversal vulnerability in setinfo.hts in HP Web Jetadmin 7.5.2546 allows remote authenticated attackers to read arbitrary files via a .. (dot dot) in the setinclude parameter.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <access />
      <input />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/15606" source="XF" adv="1">hp-jetadmin-setinfo-directory-traversal(15606)</ref>
      <ref url="http://www.securityfocus.com/bid/9972" source="BID" adv="1">9972</ref>
      <ref url="http://www.securityfocus.com/advisories/6492" source="HP" adv="1">SSRT4700</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108016019623003&amp;w=2" source="BUGTRAQ" adv="1">20040324 HP Web JetAdmin vulnerabilities.</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hp" name="web_jetadmin">
        <vers num="7.5.2546" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1858" published="2004-12-31" name="CVE-2004-1858" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">HP Web Jetadmin 7.5.2546 allows remote attackers to cause a denial of service (crash) via a malformed request, possibly due to a stricmp() error from an invalid use of the "$" character.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/advisories/6492" source="HP">SSRT4700</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108016019623003&amp;w=2" source="BUGTRAQ">20040324 HP Web JetAdmin vulnerabilities.</ref>
    </refs>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1859" published="2004-03-24" name="CVE-2004-1859" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in Trend Micro Interscan Web Viruswall in InterScan VirusWall 3.5x allows remote attackers to read arbitrary files via a .. (dot dot) in the URL.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <access />
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/15590" source="XF" patch="1" adv="1">interscan-dotdot-directory-traversal(15590)</ref>
      <ref url="http://secunia.com/advisories/11215" source="SECUNIA" patch="1" adv="1">11215</ref>
      <ref url="http://kb.trendmicro.com/solutions/search/main/search/solutionDetail.asp?solutionID=19257" source="CONFIRM" patch="1" adv="1">http://kb.trendmicro.com/solutions/search/main/search/solutionDetail.asp?solutionID=19257</ref>
      <ref url="http://www.securityfocus.com/bid/9966" source="BID" adv="1">9966</ref>
      <ref url="http://www.osvdb.org/4549" source="OSVDB" adv="1">4549</ref>
      <ref url="http://securitytracker.com/id?1009550" source="SECTRACK" adv="1">1009550</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108014604529316&amp;w=2" source="BUGTRAQ" adv="1">20040324 TrendMacro Interscan Viruswall Directory Traversal</ref>
    </refs>
    <vuln_soft>
      <prod vendor="trend_micro" name="interscan_viruswall_for_windows_nt">
        <vers num="3.4" />
        <vers num="3.5" />
        <vers num="3.51" />
        <vers num="3.52" />
        <vers num="3.52_build1466" />
        <vers num="3.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1860" published="2004-12-31" name="CVE-2004-1860" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Buffer overflow in Check Point SmartDashboard in Check Point NG AI R54 and R55 allows remote authenticated users to cause a denial of service (server disconnect) and possibly execute arbitrary code via a large filter on a column when using SmartView Tracker.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/15539" source="XF">fw1-smartdashboard-bo(15539)</ref>
      <ref url="http://securitytracker.com/id?1009490" source="SECTRACK">1009490</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108023281112510&amp;w=2" source="BUGTRAQ">20040325 Check Point SmartDashboard Buffer Overflow</ref>
      <ref url="http://www.securityfocus.com/bid/9870" source="BID">9870</ref>
      <ref url="http://www.osvdb.org/4412" source="OSVDB">4412</ref>
    </refs>
    <vuln_soft>
      <prod vendor="xmb_forum" name="xmb">
        <vers num="1.8_sp3" />
        <vers num="1.9_beta" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1861" published="2004-03-25" name="CVE-2004-1861" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Invision NetSupport School Pro uses a weak encryption algorithm to encrypt passwords, which allows local users to obtain passwords.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/15621" source="XF" adv="1">netsupportschoolpro-weak-encryption(15621)</ref>
      <ref url="http://www.securityfocus.com/bid/9981" source="BID" adv="1">9981</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108032304932321&amp;w=2" source="BUGTRAQ" adv="1">20040326 NetSupport School Pro: Password Encryption Weaknesses</ref>
    </refs>
    <vuln_soft>
      <prod vendor="netsupport" name="netsupport_school">
        <vers num="7.0" />
        <vers num="7.0_1" />
        <vers num="7.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1862" published="2004-03-26" name="CVE-2004-1862" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in Extreme Messageboard (XMB) 1.8 SP3 and 1.9 beta allow remote attackers to inject arbitrary web script or HTML via the (1) xmbuser parameter to xmb.php, (2) folder parameter to u2u.php, (3) viewmost, replymost, or latest parameter to stats.php, (4) message or icons parameter to post.php, (5) threadlist, pagelinks, forumlist, navigation, or (6) forumdisplay parameter to forumdisplay.php.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/15654" source="XF" adv="1">xmb-forum-multiple-xss(15654)</ref>
      <ref url="http://www.securityfocus.com/bid/9983" source="BID" adv="1">9983</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108032355905265&amp;w=2" source="BUGTRAQ" adv="1">20040326 [waraxe-2004-SA#012 - Multiple vulnerabilities in XMB Forum 1.8 Partagium SP3 and 1.9 Nexus Beta]</ref>
      <ref url="http://secunia.com/advisories/11230" source="SECUNIA">11230</ref>
      <ref url="http://osvdb.org/14988" source="OSVDB">14988</ref>
      <ref url="http://osvdb.org/14987" source="OSVDB">14987</ref>
      <ref url="http://osvdb.org/14986" source="OSVDB">14986</ref>
      <ref url="http://osvdb.org/14985" source="OSVDB">14985</ref>
      <ref url="http://osvdb.org/14983" source="OSVDB">14983</ref>
    </refs>
    <vuln_soft>
      <prod vendor="xmb_forum" name="xmb">
        <vers num="1.8_sp3" />
        <vers num="1.9_beta" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1863" published="2004-12-31" name="CVE-2004-1863" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in XMB (aka extreme message board) 1.9 beta (aka Nexus beta) allow remote attackers to inject arbitrary web script or HTML via (1) the u2uheader parameter in editprofile.php, the restrict parameter in (2) member.php, (3) misc.php, and (4) today.php, and (5) an arbitrary parameter in phpinfo.php.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/15654" source="XF">xmb-forum-multiple-xss(15654)</ref>
      <ref url="http://www.securityfocus.com/bid/9983" source="BID">9983</ref>
      <ref url="http://www.osvdb.org/16884" source="OSVDB">16884</ref>
      <ref url="http://www.osvdb.org/14991" source="OSVDB">14991</ref>
      <ref url="http://www.osvdb.org/14989" source="OSVDB">14989</ref>
      <ref url="http://www.osvdb.org/14982" source="OSVDB">14982</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108032355905265&amp;w=2" source="BUGTRAQ">20040326 [waraxe-2004-SA#012 - Multiple vulnerabilities in XMB Forum 1.8 Partagium SP3 and 1.9 Nexus Beta]</ref>
    </refs>
    <vuln_soft>
      <prod vendor="xmb_forum" name="xmb">
        <vers num="1.8_sp3" />
        <vers num="1.9_beta" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-1864" published="2004-03-26" name="CVE-2004-1864" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in Extreme Messageboard (XMB) 1.9 beta allows remote attackers to execute arbitrary SQL commands via the restrict parameter to (1) member.php, (2) misc.php, or (3) today.php.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/15655" source="XF" adv="1">xmb-forum-sql-injection(15655)</ref>
      <ref url="http://www.securityfocus.com/bid/9983" source="BID" adv="1">9983</ref>
      <ref url="http://www.osvdb.org/16886" source="OSVDB">16886</ref>
      <ref url="http://securitytracker.com/id?1009561" source="SECTRACK">1009561</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108032355905265&amp;w=2" source="BUGTRAQ" adv="1">20040326 [waraxe-2004-SA#012 - Multiple vulnerabilities in XMB Forum 1.8 SP3 and 1.9 beta]</ref>
    </refs>
    <vuln_soft>
      <prod vendor="xmb_forum" name="xmb">
        <vers num="1.8_sp3" />
        <vers num="1.9_beta" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2004-1865" published="2004-03-26" name="CVE-2004-1865" modified="2005-10-20" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="1.9" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.4" CVSS_base_score="1.9">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in the administration panel in bBlog 0.7.2 allows remote authenticated users with superuser privileges to inject arbitrary web script or HTML via a blog name ($blogname).  NOTE: if administrators are normally allowed to add HTML by other means, e.g. through Smarty templates, then this issue would not give any additional privileges, and thus would not be considered a vulnerability.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/15635" source="XF" adv="1">bblog-name-xss(15635)</ref>
      <ref url="http://securitytracker.com/id?1009564" source="SECTRACK" adv="1">1009564</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108034226717745&amp;w=2" source="BUGTRAQ" adv="1">20040326 bblog 0.7.2 cross site scripting</ref>
      <ref url="http://www.securityfocus.com/bid/13397" source="BID">13397</ref>
      <ref url="http://www.osvdb.org/10510" source="OSVDB">10510</ref>
    </refs>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1866" published="2004-03-26" name="CVE-2004-1866" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">nstxd in Nstx 1.1 beta3 and earlier allows remote attackers to cause a denial of service (crash) via a large packet, which triggers a null dereference.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/15638" source="XF" patch="1" adv="1">nstx-null-dos(15638)</ref>
      <ref url="http://www.securityfocus.com/bid/9989" source="BID" patch="1" adv="1">9989</ref>
      <ref url="http://securitytracker.com/id?1009567" source="SECTRACK" patch="1" adv="1">1009567</ref>
      <ref url="http://nstx.dereference.de/nstx/nstx-1.1-beta4.tgz" source="CONFIRM" patch="1">http://nstx.dereference.de/nstx/nstx-1.1-beta4.tgz</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108034249916453&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20040326 Nstxd vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="nstx" name="ip_over_dns_utility">
        <vers num="1.0" />
        <vers num="1.1_beta1" />
        <vers num="1.1_beta2" />
        <vers num="1.1_beta3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1867" published="2004-12-31" name="CVE-2004-1867" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in guest.cgi in Fresh Guest Book allows remote attackers to inject arbitrary web script or HTML via the Name field.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/15649" source="XF">freshguestbook-guest-xss(15649)</ref>
      <ref url="http://www.securityfocus.com/bid/9995" source="BID">9995</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108057935827431&amp;w=2" source="BUGTRAQ">20040328 vuln</ref>
    </refs>
    <vuln_soft>
      <prod vendor="web_fresh" name="fresh_guest_book">
        <vers num="1.0" />
        <vers num="2.0" />
        <vers num="2.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-1868" published="2004-03-25" name="CVE-2004-1868" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Stack-based buffer overflow in WinSig.exe in eSignal 7.5 and 7.6 allows remote attackers to execute arbitrary code via a long STREAMQUOTE tag.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/15624" source="XF" patch="1" adv="1">esignal-specs-bo(15624)</ref>
      <ref url="http://www.securityfocus.com/bid/9978" source="BID" patch="1" adv="1">9978</ref>
      <ref url="http://secunia.com/advisories/11222" source="SECUNIA" patch="1" adv="1">11222</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2004-04/0056.html" source="BUGTRAQ" patch="1">20040406 Re: eSignal v7 remote buffer overflow</ref>
      <ref url="http://viziblesoft.com/insect/advisories/vz012004-esignal7.txt" source="MISC" adv="1">http://viziblesoft.com/insect/advisories/vz012004-esignal7.txt</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108025234317408&amp;w=2" source="BUGTRAQ" adv="1">20040325 eSignal v7 remote buffer overflow (exploit)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="esignal" name="esignal">
        <vers num="7.5" />
        <vers num="7.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1869" published="2004-12-31" name="CVE-2004-1869" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Etherlords I 1.07 and earlier and Etherlords II 1.03 and earlier allows remote attackers to cause a denial of service (crash) by sending a packet that specifies the size for the next packet, then sending a larger packet than specified, which causes Etherlords to read unallocated memory.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input bound="1" />
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/15619" source="XF">etherlords2-packet-dos(15619)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15618" source="XF">etherlords1-packet-dos(15618)</ref>
      <ref url="http://www.securityfocus.com/bid/9979" source="BID">9979</ref>
      <ref url="http://aluigi.altervista.org/adv/ethboom-adv.txt" source="MISC">http://aluigi.altervista.org/adv/ethboom-adv.txt</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108024309814423&amp;w=2" source="BUGTRAQ">20040325 Remote crash in Etherlords I 1.07 and II 1.03</ref>
    </refs>
    <vuln_soft>
      <prod vendor="nival_interactive" name="etherlords">
        <vers num="1.0" />
        <vers num="1.0_1" />
        <vers num="1.0_2" />
        <vers num="1.0_3" />
        <vers num="1.0_4" />
        <vers num="1.0_5" />
        <vers num="1.0_6" />
        <vers num="1.0_7" />
      </prod>
      <prod vendor="nival_interactive" name="etherlords_ii">
        <vers num="1.0" />
        <vers num="1.0_1" />
        <vers num="1.0_2" />
        <vers num="1.0_3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-1870" published="2004-03-29" name="CVE-2004-1870" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple SQL injection vulnerabilities in PhotoPost PHP Pro 4.6.x and earlier allow remote attackers to gain users' passwords via the (1) photo parameter to addfav.php, (2) photo parameter to comments.php, (3) credit parameter to comments.php, (4) cat parameter to index.php, (5) ppuser parameter to showgallery.php, (6) cat parameter to showgallery.php, (7) cat parameter to uploadphoto.php, (8) albumid parameter to useralbums.php, or (9) albumid parameter to useralbums.php.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/15642" source="XF" adv="1">photopost-php-sql-injection(15642)</ref>
      <ref url="http://www.securityfocus.com/bid/9994" source="BID" adv="1">9994</ref>
      <ref url="http://securitytracker.com/id?1009571" source="SECTRACK" adv="1">1009571</ref>
      <ref url="http://secunia.com/advisories/11241" source="SECUNIA" adv="1">11241</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108057790723123&amp;w=2" source="BUGTRAQ" adv="1">20040328 PhotoPost PHP Pro Multiple Vulnerabilities</ref>
    </refs>
    <vuln_soft>
      <prod vendor="photopost" name="photopost_php_pro">
        <vers num="3.1" />
        <vers num="3.2" />
        <vers num="3.3" />
        <vers num="4.0" />
        <vers num="4.1" />
        <vers num="4.6" />
        <vers num="4.8.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1871" published="2004-03-29" name="CVE-2004-1871" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in PhotoPost PHP Pro 4.6.x and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) ppuser, (2) password, (3) stype, (4) perpage, (5) sort, (6) page, (7) si, or (8) cat parameters to showmembers.php, or the (9) photo name, (10) photo description, (11) album name, or (12) album description fields.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/9994" source="BID" patch="1" adv="1">9994</ref>
      <ref url="http://secunia.com/advisories/11241" source="SECUNIA" patch="1" adv="1">11241</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108057790723123&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20040328 PhotoPost PHP Pro Multiple Vulnerabilities</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15643" source="XF" adv="1">photopost-php-xss(15643)</ref>
      <ref url="http://securitytracker.com/id?1009571" source="SECTRACK" adv="1">1009571</ref>
    </refs>
    <vuln_soft>
      <prod vendor="photopost" name="photopost_php_pro">
        <vers num="3.1" />
        <vers num="3.2" />
        <vers num="3.3" />
        <vers num="4.0" />
        <vers num="4.1" />
        <vers num="4.6" />
        <vers num="4.8.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1872" published="2004-03-29" name="CVE-2004-1872" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in WebCT Campus Edition 4.1.1.5 allows remote attackers to inject arbitrary web script or HTML via the @import URL function in a CSS style tag.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/15652" source="XF" patch="1" adv="1">webct-import-xss(15652)</ref>
      <ref url="http://www.securityfocus.com/bid/9999" source="BID" patch="1" adv="1">9999</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108057915916365&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20040329 WebCT Campus Edition 4.1 - Cross site scripting using CSS @import</ref>
      <ref url="http://secunia.com/advisories/11242" source="SECUNIA" adv="1">11242</ref>
    </refs>
    <vuln_soft>
      <prod vendor="webct" name="webct">
        <vers num="campus_3.8" />
        <vers num="campus_3.8.4" />
        <vers num="campus_4.0" />
        <vers num="campus_4.1" />
        <vers num="campus_4.1.1.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-1873" published="2004-12-31" name="CVE-2004-1873" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in category.asp in A-CART Pro and A-CART 2.0 allows remote attackers to gain privileges via the catcode parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/15661" source="XF">acart-categoryasp-sql-injection(15661)</ref>
      <ref url="http://www.securityfocus.com/bid/9997" source="BID">9997</ref>
      <ref url="http://secunia.com/advisories/11236" source="SECUNIA">11236</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108057887008983&amp;w=2" source="BUGTRAQ">20040329 A-CART Pro &amp; A-CART 2.0 Input Validation Holes</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/452023/100/0/threaded" source="BUGTRAQ">20061118 Re: A-Cart PRO SQL Injection</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/452006/100/0/threaded" source="BUGTRAQ">20061118 A-Cart PRO SQL Injection</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/452005/100/0/threaded" source="BUGTRAQ">20061118 A-Cart 2.0 SQL Injection</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/451594/100/100/threaded" source="BUGTRAQ">20061114 A-Cart pro[ injection sql (post&amp;get)]</ref>
      <ref url="http://www.aria-security.com/forum/showthread.php?t=32" source="MISC">http://www.aria-security.com/forum/showthread.php?t=32</ref>
      <ref url="http://www.aria-security.com/forum/showthread.php?t=31" source="MISC">http://www.aria-security.com/forum/showthread.php?t=31</ref>
      <ref url="http://s-a-p.ca/index.php?page=OurAdvisories&amp;id=27" source="MISC">http://s-a-p.ca/index.php?page=OurAdvisories&amp;id=27</ref>
    </refs>
    <vuln_soft>
      <prod vendor="alan_ward" name="a-cart">
        <vers num="2.0" edition="" />
        <vers num="2.0" edition=":pro" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1874" published="2004-03-29" name="CVE-2004-1874" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in (1) deliver.asp and (2) billing.asp in A-CART Pro and A-CART 2.0 allow remote attackers to inject arbitrary web script or HTML via the user information forms.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/15660" source="XF" adv="1">acart-deliverasp-billingasp-xss(15660)</ref>
      <ref url="http://www.securityfocus.com/bid/9997" source="BID" adv="1">9997</ref>
      <ref url="http://secunia.com/advisories/11236" source="SECUNIA" adv="1">11236</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108057887008983&amp;w=2" source="BUGTRAQ" adv="1">20040329 A-CART Pro &amp; A-CART 2.0 Input Validation Holes</ref>
    </refs>
    <vuln_soft>
      <prod vendor="alan_ward" name="a-cart">
        <vers num="2.0" edition="" />
        <vers num="2.0" edition=":pro" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-1875" published="2004-03-30" name="CVE-2004-1875" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in cPanel 9.1.0-R85 allow remote attackers to inject arbitrary web script or HTML via the (1) email parameter to testfile.html, (2) file parameter to erredit.html, (3) dns parameter to dnslook.html, (4) account parameter to ignorelist.html, (5) account parameter to showlog.html, (6) db parameter to repairdb.html, (7) login parameter to doaddftp.html (8) account parameter to editmsg.htm, or (9) ip parameter to del.html.  NOTE: the dnslook.html vector was later reported to exist in cPanel 10.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/15671" source="XF" patch="1" adv="1">cpanel-multiple-scripts-xss(15671)</ref>
      <ref url="http://www.cirt.net/advisories/cpanel_xss.shtml" source="MISC" patch="1" adv="1">http://www.cirt.net/advisories/cpanel_xss.shtml</ref>
      <ref url="http://secunia.com/advisories/11244" source="SECUNIA" patch="1" adv="1">11244</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108066561608676&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20040330 Exensive cPanel Cross Site Scripting</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/4658" source="VUPEN" adv="1">ADV-2006-4658</ref>
      <ref url="http://www.securityfocus.com/bid/21142" source="BID">21142</ref>
      <ref url="http://www.securityfocus.com/bid/10002" source="BID" adv="1">10002</ref>
      <ref url="http://www.osvdb.org/4243" source="OSVDB" adv="1">4243</ref>
      <ref url="http://www.osvdb.org/4215" source="OSVDB" adv="1">4215</ref>
      <ref url="http://www.osvdb.org/4214" source="OSVDB" adv="1">4214</ref>
      <ref url="http://www.osvdb.org/4213" source="OSVDB" adv="1">4213</ref>
      <ref url="http://www.osvdb.org/4212" source="OSVDB" adv="1">4212</ref>
      <ref url="http://www.osvdb.org/4211" source="OSVDB">4211</ref>
      <ref url="http://www.osvdb.org/4210" source="OSVDB" adv="1">4210</ref>
      <ref url="http://www.osvdb.org/4209" source="OSVDB" adv="1">4209</ref>
      <ref url="http://www.osvdb.org/4208" source="OSVDB" adv="1">4208</ref>
      <ref url="http://www.aria-security.com/forum/showthread.php?t=30" source="MISC">http://www.aria-security.com/forum/showthread.php?t=30</ref>
      <ref url="http://secunia.com/advisories/22984" source="SECUNIA" adv="1">22984</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cpanel" name="cpanel">
        <vers num="9.1.0_r85" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1876" published="2004-03-30" name="CVE-2004-1876" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">The "%f" feature in the VirusEvent directive in Clam AntiVirus daemon (clamd) before 0.70 allows local users to execute arbitrary commands via shell metacharacters in a file name.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input />
      <exception />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/15692" source="XF" patch="1" adv="1">clamantivirus-virusevent-gain-privileges(15692)</ref>
      <ref url="http://www.securityfocus.com/bid/10007" source="BID" patch="1" adv="1">10007</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200405-03.xml" source="GENTOO" patch="1" adv="1">GLSA-200405-03</ref>
      <ref url="http://secunia.com/advisories/11253" source="SECUNIA" patch="1" adv="1">11253</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108066864608615&amp;w=2" source="BUGTRAQ" adv="1">20040330 clamd - NEVER use "%f" in your "VirusEvent"</ref>
    </refs>
    <vuln_soft>
      <prod vendor="clam_anti-virus" name="clamav">
        <vers num="0.51" />
        <vers num="0.52" />
        <vers num="0.53" />
        <vers num="0.54" />
        <vers num="0.60" />
        <vers num="0.65" />
        <vers num="0.67" />
        <vers num="0.68" />
        <vers num="0.68.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2004-1877" published="2004-03-30" name="CVE-2004-1877" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:N/A:N)" CVSS_score="2.6" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="4.9" CVSS_base_score="2.6">
    <desc>
      <descript source="cve">The p_submit_url value in the sample login form in the Oracle 9i Application Server (9iAS) Single Sign-on Administrators Guide, Release 2(9.0.2) for Oracle SSO allows remote attackers to spoof the login page, which could allow users to inadvertently reveal their username and password.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/15676" source="XF" patch="1" adv="1">oracle-sso-login-spoofing(15676)</ref>
      <ref url="http://www.securityfocus.com/bid/10009" source="BID" patch="1" adv="1">10009</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108067040722235&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20040330 Problem with customized login pages for Oracle SSO</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="application_server">
        <vers num="1.0.2" />
        <vers num="1.0.2.1s" />
        <vers num="1.0.2.2" />
        <vers num="1.0.2.2.2" />
        <vers num="9.0.2" />
        <vers num="9.0.2.0.0" />
        <vers num="9.0.2.0.1" />
        <vers num="9.0.2.1" />
        <vers num="9.0.2.2" />
        <vers num="9.0.2.3" />
        <vers num="9.0.3" />
        <vers num="9.0.3.1" />
      </prod>
      <prod vendor="oracle" name="http_server">
        <vers num="8.1.7" />
        <vers num="9.0.1" />
        <vers num="9.2.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1878" published="2004-03-30" name="CVE-2004-1878" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">LINBOX LIN:BOX allows remote attackers to bypass authentication, obtain sensitive information, or gain access via a direct request to admin/user.pl preceded by // (double leading slash).</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/15677" source="XF" patch="1" adv="1">linbox-slashslash-security-bypass(15677)</ref>
      <ref url="http://www.securityfocus.com/bid/10010" source="BID" patch="1" adv="1">10010</ref>
      <ref url="http://secunia.com/advisories/11264" source="SECUNIA" patch="1" adv="1">11264</ref>
      <ref url="http://www.websec.org/adv/linbit.txt.html" source="MISC" adv="1">http://www.websec.org/adv/linbit.txt.html</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108067245401673&amp;w=2" source="BUGTRAQ" adv="1">20040330 Linbit linbox Multiple Vulnerabilities</ref>
    </refs>
    <vuln_soft>
      <prod vendor="linbit_technologies" name="linbox_officeserver">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1879" published="2004-12-31" name="CVE-2004-1879" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in PHPKIT 1.6.03 allows allows remote attackers to inject arbitrary web script or HTML via forum messages.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/15681" source="XF">phpkit-forum-message-xss(15681)</ref>
      <ref url="http://www.securityfocus.com/bid/10013" source="BID">10013</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108067894822358&amp;w=2" source="BUGTRAQ">20040330 phpkit suffers (reale stupid) XSS vuln.</ref>
    </refs>
    <vuln_soft>
      <prod vendor="phpkit" name="phpkit">
        <vers num="1.6.03" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1880" published="2004-12-31" name="CVE-2004-1880" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Memory leak in the back-bdb backend for OpenLDAP 2.1.12 and earlier allows remote attackers to cause a denial of service (memory consumption).</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/9203" source="SECUNIA" patch="1">9203</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000685" source="CONECTIVA" patch="1">CLSA-2003:685</ref>
      <ref url="http://www.osvdb.org/17000" source="OSVDB">17000</ref>
    </refs>
    <vuln_soft>
      <prod vendor="openldap" name="openldap">
        <vers num="1.0" />
        <vers num="1.0.1" />
        <vers num="1.0.2" />
        <vers num="1.0.3" />
        <vers num="1.1.0" />
        <vers num="1.1.1" />
        <vers num="1.1.2" />
        <vers num="1.1.3" />
        <vers num="1.1.4" />
        <vers num="1.2.0" />
        <vers num="1.2.1" />
        <vers num="1.2.10" />
        <vers num="1.2.11" />
        <vers num="1.2.12" />
        <vers num="1.2.13" />
        <vers num="1.2.2" />
        <vers num="1.2.3" />
        <vers num="1.2.4" />
        <vers num="1.2.5" />
        <vers num="1.2.6" />
        <vers num="1.2.7" />
        <vers num="1.2.8" />
        <vers num="1.2.9" />
        <vers num="2.0.0" />
        <vers num="2.0.1" />
        <vers num="2.0.10" />
        <vers num="2.0.11" />
        <vers num="2.0.12" />
        <vers num="2.0.13" />
        <vers num="2.0.14" />
        <vers num="2.0.15" />
        <vers num="2.0.16" />
        <vers num="2.0.17" />
        <vers num="2.0.18" />
        <vers num="2.0.19" />
        <vers num="2.0.2" />
        <vers num="2.0.20" />
        <vers num="2.0.21" />
        <vers num="2.0.22" />
        <vers num="2.0.23" />
        <vers num="2.0.24" />
        <vers num="2.0.25" />
        <vers num="2.0.26" />
        <vers num="2.0.27" />
        <vers num="2.0.3" />
        <vers num="2.0.4" />
        <vers num="2.0.5" />
        <vers num="2.0.6" />
        <vers num="2.0.7" />
        <vers num="2.0.8" />
        <vers num="2.0.9" />
        <vers num="2.1.10" />
        <vers num="2.1.11" />
        <vers num="2.1.12" />
        <vers num="2.1.2" />
        <vers num="2.1.3" />
        <vers num="2.1.4" />
        <vers num="2.1.5" />
        <vers num="2.1.6" />
        <vers num="2.1.7" />
        <vers num="2.1.8" />
        <vers num="2.1.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-1881" published="2004-12-31" name="CVE-2004-1881" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in (1) mailorder.asp or (2) payonline.asp in CactuShop 5.x allows remote attackers to execute arbitrary SQL commands via the strItems parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/11272" source="SECUNIA" patch="1">11272</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15686" source="XF">cactushop-multiple-sql-injection(15686)</ref>
      <ref url="http://www.securityfocus.com/bid/10019" source="BID">10019</ref>
      <ref url="http://www.s-quadra.com/advisories/Adv-20040331.txt" source="MISC">http://www.s-quadra.com/advisories/Adv-20040331.txt</ref>
      <ref url="http://www.osvdb.org/4786" source="OSVDB">4786</ref>
      <ref url="http://www.osvdb.org/4785" source="OSVDB">4785</ref>
      <ref url="http://securitytracker.com/id?1009601" source="SECTRACK">1009601</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108075059013762&amp;w=2" source="BUGTRAQ">20040331 CactuSoft CactuShop v5.x shopping cart software multiple security</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cactusoft" name="cactushop">
        <vers num="5.0" />
        <vers num="5.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1882" published="2004-12-31" name="CVE-2004-1882" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in popuplargeimage.asp in CactuShop 5.x allows remote attackers to inject arbitrary web script or HTML via the strImageTag parameter.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/11272" source="SECUNIA" patch="1">11272</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15687" source="XF">cactushop-popularlargeimageasp-xss(15687)</ref>
      <ref url="http://www.securityfocus.com/bid/10020" source="BID">10020</ref>
      <ref url="http://www.osvdb.org/4787" source="OSVDB">4787</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108075059013762&amp;w=2" source="BUGTRAQ">20040331 CactuSoft CactuShop v5.x shopping cart software multiple security</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2004-March/019566.html" source="FULLDISC">2004031 CactuSoft CactuShop v5.x shopping cart software multiple security vulnerabilities</ref>
      <ref url="http://securitytracker.com/id?1009601" source="SECTRACK">1009601</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cactusoft" name="cactushop">
        <vers num="5.0" />
        <vers num="5.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-1883" published="2004-12-31" name="CVE-2004-1883" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Multiple buffer overflows in Ipswitch WS_FTP Server 4.0.2 (1) allow remote authenticated users to execute arbitrary code by causing a large error string to be generated by the ALLO handler, or (2) may allow remote FTP administrators to execute arbitrary code by causing a long hostname or username to be inserted into a reply to a STAT command while a file is being transferred.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/11206" source="SECUNIA" patch="1">11206</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15561" source="XF">wsftp-allo-bo(15561)</ref>
      <ref url="http://www.securityfocus.com/bid/9953" source="BID">9953</ref>
      <ref url="http://www.securityfocus.com/archive/1/358361" source="BUGTRAQ">20040323 Think of the buffers! Won't somebody think of the buffers?!</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108006553222397&amp;w=2" source="BUGTRAQ">20040323 ALLO ALLO WS_FTP Server</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ipswitch" name="ws_ftp_server">
        <vers num="4.0.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-1884" published="2004-03-23" name="CVE-2004-1884" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Ipswitch WS_FTP Server 4.0.2 has a backdoor XXSESS_MGRYY username with a default password, which allows remote attackers to gain access.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <config />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/11206" source="SECUNIA" patch="1" adv="1">11206</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15558" source="XF" adv="1">wftp-site-gain-priviliege(15558)</ref>
      <ref url="http://www.securityfocus.com/bid/9953" source="BID" adv="1">9953</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108006581418116&amp;w=2" source="BUGTRAQ" adv="1">20040323 Open the WS_FTP Server backdoor to SYSTEM</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ipswitch" name="ws_ftp_pro">
        <vers num="6.0" />
        <vers num="7.5" />
        <vers num="8.0_2" />
        <vers num="8.0_3" />
      </prod>
      <prod vendor="ipswitch" name="ws_ftp_server">
        <vers num="1.0.1" />
        <vers num="1.0.2" />
        <vers num="1.0.3" />
        <vers num="1.0.4" />
        <vers num="1.0.5" />
        <vers num="2.0" />
        <vers num="2.0.1" />
        <vers num="2.0.2" />
        <vers num="2.0.3" />
        <vers num="2.0.4" />
        <vers num="3.0" />
        <vers num="3.0_1" />
        <vers num="3.1" />
        <vers num="3.1.1" />
        <vers num="3.1.2" />
        <vers num="3.1.3" />
        <vers num="3.4" />
        <vers num="4.0" />
        <vers num="4.0.2" />
        <vers num="4.01" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-1885" published="2004-12-31" name="CVE-2004-1885" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Ipswitch WS_FTP Server 4.0.2 allows remote authenticated users to execute arbitrary programs as SYSTEM by using the SITE command to modify certain iFtpSvc options that are handled by iftpmgr.exe.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/11206" source="SECUNIA" patch="1">11206</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15558" source="XF">wftp-site-gain-priviliege(15558)</ref>
      <ref url="http://www.securityfocus.com/bid/9953" source="BID">9953</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108006581418116&amp;w=2" source="BUGTRAQ">20040323 Open the WS_FTP Server backdoor to SYSTEM</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ipswitch" name="ws_ftp_server">
        <vers num="4.0.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" seq="2004-1886" reject="1" published="2004-03-23" name="CVE-2004-1886" modified="2008-05-21">
    <desc>
      <descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: CVE-2004-1848.  Reason: This candidate is a duplicate of CVE-2004-1848.  Notes: All CVE users should reference CVE-2004-1848 instead of this candidate.  All references and descriptions in this candidate have been removed to prevent accidental usage.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs />
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1887" published="2004-12-31" name="CVE-2004-1887" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Ada Image Server (ImgSvr) 0.4 allows remote attackers to view directories or download files via an HTTP request with a trailing %00 (null).</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/11277" source="SECUNIA" patch="1">11277</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15706" source="XF">imgsvr-obtain-information(15706)</ref>
      <ref url="http://www.securityfocus.com/bid/10027" source="BID">10027</ref>
      <ref url="http://www.securityfocus.com/bid/10026" source="BID">10026</ref>
      <ref url="http://www.autistici.org/fdonato/advisory/imgSvr0.4-adv.txt" source="MISC">http://www.autistici.org/fdonato/advisory/imgSvr0.4-adv.txt</ref>
      <ref url="http://sourceforge.net/project/shownotes.php?release_id=230023" source="CONFIRM">http://sourceforge.net/project/shownotes.php?release_id=230023</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108083813528255&amp;w=2" source="BUGTRAQ">20040401 Index viewing in imgSvr 0.4</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ada" name="imgsvr">
        <vers num="0.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-1888" published="2004-12-31" name="CVE-2004-1888" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">display.cgi in Aborior Encore WebForum allows remote to execute arbitrary commands via shell metacharacters in the file variable.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/15725" source="XF">encore-display-command-execution(15725)</ref>
      <ref url="http://www.securityfocus.com/bid/10040" source="BID">10040</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108100973820868&amp;w=2" source="BUGTRAQ">20040403 Remote Exploit for Aborior's Encore Web Forum</ref>
      <ref url="http://www.securitytracker.com/id?1009652" source="SECTRACK">1009652</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/437978/100/0/threaded" source="BUGTRAQ">20060621 Re: display.cgi</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/437813/100/0/threaded" source="BUGTRAQ">20060620 display.cgi</ref>
      <ref url="http://www.osvdb.org/16831" source="OSVDB">16831</ref>
    </refs>
    <vuln_soft>
      <prod vendor="aborior" name="encore_web_forum">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1889" published="2004-12-31" name="CVE-2004-1889" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Unknown vulnerability in ftpd in SGI IRIX 6.5.20 through 6.5.23 allows remote attackers to cause a denial of service (hang) via a link failure with Microsoft Windows.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/15722" source="XF">irix-ftpd-link-dos(15722)</ref>
      <ref url="http://www.securityfocus.com/bid/10037" source="BID">10037</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/20040401-01-P.asc" source="SGI">20040401-01-P</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sgi" name="irix">
        <vers num="6.5.20" />
        <vers num="6.5.20f" />
        <vers num="6.5.20m" />
        <vers num="6.5.21" />
        <vers num="6.5.21f" />
        <vers num="6.5.21m" />
        <vers num="6.5.22" />
        <vers num="6.5.23" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1890" published="2004-04-02" name="CVE-2004-1890" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Unknown vulnerability in ftpd in SGI IRIX 6.5.20 through 6.5.23 allows remote attackers to cause a denial of service (hang) via the PORT mode.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/15723" source="XF" patch="1" adv="1">irix-ftpd-port-dos(15723)</ref>
      <ref url="http://www.securityfocus.com/bid/10037" source="BID" patch="1" adv="1">10037</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/20040401-01-P.asc" source="SGI" patch="1" adv="1">20040401-01-P</ref>
    </refs>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1891" published="2004-12-31" name="CVE-2004-1891" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The ftp_syslog function in ftpd in SGI IRIX 6.5.20 "doesn't work with anonymous FTP," which has an unknown impact, possibly preventing the actions of anonymous users from being logged.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/20040401-01-P.asc" source="SGI">20040401-01-P</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sgi" name="irix">
        <vers num="6.5.20" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-1892" published="2004-12-31" name="CVE-2004-1892" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Stack-based buffer overflow in DecodeBase16 function, as used in the (1) IRC module and (2) web server in eMule 0.42d, allows remote attackers to execute arbitrary code via a long string.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/10039" source="BID" patch="1" adv="1">10039</ref>
      <ref url="http://www.emule-project.net/home/perl/news.cgi?l=1&amp;cat_id=22" source="CONFIRM" patch="1" adv="1">http://www.emule-project.net/home/perl/news.cgi?l=1&amp;cat_id=22</ref>
      <ref url="http://secunia.com/advisories/11289" source="SECUNIA" patch="1">11289</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15730" source="XF">emule-decodebase16-bo(15730)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108100987429960&amp;w=2" source="BUGTRAQ">20040403 eMule v0.42d Buffer Overflow</ref>
    </refs>
    <vuln_soft>
      <prod vendor="emule" name="emule">
        <vers num="0.42d" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1893" published="2004-12-31" name="CVE-2004-1893" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Dreamweaver MX, when "Using Driver On Testing Server" or "Using DSN on Testing Server" is selected, uploads the mmhttpdb.asp script to the web site but does not require authentication, which allows remote attackers to obtain sensitive information and possibly execute arbitrary SQL commands via a direct request to mmhttpdb.asp.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <config />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/11284" source="SECUNIA" patch="1">11284</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15721" source="XF">dreamweaver-test-script-sql-injection(15721)</ref>
      <ref url="http://www.securityfocus.com/bid/10036" source="BID">10036</ref>
      <ref url="http://www.nextgenss.com/advisories/dreamweaver.txt" source="MISC">http://www.nextgenss.com/advisories/dreamweaver.txt</ref>
      <ref url="http://www.macromedia.com/devnet/security/security_zone/mpsb04-05.html" source="CONFIRM" adv="1">http://www.macromedia.com/devnet/security/security_zone/mpsb04-05.html</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108102481929451&amp;w=2" source="BUGTRAQ">20040403 [securityzone@macromedia.com: New Macromedia Security Zone Bulletin Posted]</ref>
    </refs>
  </entry>
  <entry type="CVE" severity="Low" seq="2004-1894" published="2004-12-31" name="CVE-2004-1894" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">TEXutil in ConTEXt, when executed with the --silent option, allows local users to overwrite arbitrary files via a symlink attack on texutil.log.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <env />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/10042" source="BID" patch="1">10042</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108118755923319&amp;w=2" source="BUGTRAQ" patch="1">20040404 Texutil symlink vulnerability.</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2004-April/019777.html" source="FULLDISC" patch="1">20040404 Texutil symlink vulnerability.</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15728" source="XF">texutil-symlink-attack(15728)</ref>
      <ref url="http://securitytracker.com/id?1009661" source="SECTRACK">1009661</ref>
    </refs>
  </entry>
  <entry type="CVE" severity="Low" seq="2004-1895" published="2004-12-31" name="CVE-2004-1895" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">YaST Online Update (YOU) in SuSE 8.2 and 9.0 allows local users to overwrite arbitrary files via a symlink attack on you-$USER/cookies.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <env />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/15731" source="XF">suse-you-symlink(15731)</ref>
      <ref url="http://www.securityfocus.com/bid/10047" source="BID">10047</ref>
      <ref url="http://www.osvdb.org/4985" source="OSVDB">4985</ref>
      <ref url="http://securitytracker.com/id?1009668" source="SECTRACK">1009668</ref>
      <ref url="http://secunia.com/advisories/11300" source="SECUNIA">11300</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108118395519164&amp;w=2" source="BUGTRAQ">20040405 SuSEs YaST Online Update - possible symlink attack</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2004-04/0058.html" source="BUGTRAQ">20040406 Re: SuSEs YaST Online Update - possible symlink attack</ref>
    </refs>
    <vuln_soft>
      <prod vendor="suse" name="suse_linux">
        <vers num="8.2" />
        <vers num="9.0" edition="" />
        <vers num="9.0" edition=":x86_64" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-1896" published="2004-12-31" name="CVE-2004-1896" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:H/Au:N/C:C/I:C/A:C)" CVSS_score="7.6" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="4.9" CVSS_base_score="7.6">
    <desc>
      <descript source="cve">Heap-based buffer overflow in in_mod.dll in Nullsoft Winamp 2.91 through 5.02 allows remote attackers to execute arbitrary code via a Fasttracker 2 (.xm) mod media file.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/10045" source="BID" patch="1">10045</ref>
      <ref url="http://www.nextgenss.com/advisories/winampheap.txt" source="MISC" patch="1">http://www.nextgenss.com/advisories/winampheap.txt</ref>
      <ref url="http://secunia.com/advisories/11285" source="SECUNIA" patch="1">11285</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108118289208693&amp;w=2" source="BUGTRAQ" patch="1">20040405 NGSSoftware Insight Security Research Advisory</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15727" source="XF">winamp-inmod-bo(15727)</ref>
      <ref url="http://www.osvdb.org/4944" source="OSVDB">4944</ref>
      <ref url="http://securitytracker.com/id?1009660" source="SECTRACK">1009660</ref>
    </refs>
    <vuln_soft>
      <prod vendor="nullsoft" name="winamp">
        <vers num="2.91" />
        <vers num="3.0" />
        <vers num="3.1" />
        <vers num="5.0.1" />
        <vers num="5.0.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1897" published="2004-12-31" name="CVE-2004-1897" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Administration interface in Monit 1.4 through 4.2 allows remote attackers to cause a denial of service (segmentation fault) by sending a Basic Authentication request without a password, which causes Monit to decrement a null pointer and perform an out-of-bounds read.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <access />
      <input />
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/10051" source="BID" patch="1">10051</ref>
      <ref url="http://secunia.com/advisories/11304" source="SECUNIA" patch="1">11304</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108119149103696&amp;w=2" source="BUGTRAQ" patch="1">20040405 Advisory: Multiple Vulnerabilities in Monit</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15734" source="XF">monit-basic-auth-dos(15734)</ref>
    </refs>
  </entry>
  <entry type="CVE" severity="High" seq="2004-1898" published="2004-12-31" name="CVE-2004-1898" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Stack-based buffer overflow in the administration interface in Monit 1.4 through 4.2 allows remote attackers to execute arbitrary code via a long username.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/10051" source="BID" patch="1">10051</ref>
      <ref url="http://secunia.com/advisories/11304" source="SECUNIA" patch="1">11304</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108119149103696&amp;w=2" source="BUGTRAQ" patch="1">20040405 Advisory: Multiple Vulnerabilities in Monit</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15735" source="XF">monit-offbyone-bo(15735)</ref>
      <ref url="http://www.osvdb.org/4981" source="OSVDB">4981</ref>
    </refs>
    <vuln_soft>
      <prod vendor="tildeslash" name="monit">
        <vers num="1.4" />
        <vers num="3.0" />
        <vers num="3.1" />
        <vers num="3.2" />
        <vers num="4.0" />
        <vers num="4.1" />
        <vers num="4.1.1" />
        <vers num="4.2" />
        <vers num="4.3_beta_2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1899" published="2004-12-31" name="CVE-2004-1899" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The administration interface in Monit 1.4 through 4.2 allows remote attackers to cause an off-by-one overflow via a POST that contains 1024 bytes.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/10051" source="BID" patch="1">10051</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108119149103696&amp;w=2" source="BUGTRAQ" patch="1">20040405 Advisory: Multiple Vulnerabilities in Monit</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15736" source="XF">monit-post-offbyone-bo(15736)</ref>
      <ref url="http://secunia.com/advisories/11304" source="SECUNIA">11304</ref>
      <ref url="http://www.osvdb.org/4979" source="OSVDB">4979</ref>
    </refs>
    <vuln_soft>
      <prod vendor="tildeslash" name="monit">
        <vers num="1.4" />
        <vers num="3.0" />
        <vers num="3.1" />
        <vers num="3.2" />
        <vers num="4.0" />
        <vers num="4.1" />
        <vers num="4.1.1" />
        <vers num="4.2" />
        <vers num="4.3_beta_2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-1900" published="2004-12-31" name="CVE-2004-1900" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Format string vulnerability in the logging function in IGI 2 Covert Strike server 1.3 and earlier allows remote attackers to execute arbitrary code via format string specifiers in RCON commands.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/15742" source="XF">igi2covertstrike-rcon-format-string(15742)</ref>
      <ref url="http://www.securityfocus.com/bid/10053" source="BID">10053</ref>
      <ref url="http://secunia.com/advisories/11299" source="SECUNIA">11299</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108120385811815&amp;w=2" source="BUGTRAQ">20040405 Format string bug in IGI 2: Covert Strike 1.3</ref>
      <ref url="http://www.osvdb.org/4966" source="OSVDB">4966</ref>
      <ref url="http://securitytracker.com/id?1009667" source="SECTRACK">1009667</ref>
      <ref url="http://aluigi.altervista.org/adv/igi2fs-adv.txt" source="MISC">http://aluigi.altervista.org/adv/igi2fs-adv.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="pan_vision" name="i.g.i-2_covert_strike">
        <vers num="1.0" />
        <vers num="1.1" />
        <vers num="1.2" />
        <vers num="1.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1901" published="2004-12-31" name="CVE-2004-1901" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Portage before 2.0.50-r3 allows local users to overwrite arbitrary files via a hard link attack on the lockfiles.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <exception />
      <env />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/10060" source="BID" patch="1">10060</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200404-01.xml" source="GENTOO" patch="1">GLSA-200404-01</ref>
      <ref url="http://secunia.com/advisories/11305" source="SECUNIA" patch="1">11305</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15754" source="XF">portage-lockfile-hardlink(15754)</ref>
    </refs>
  </entry>
  <entry type="CVE" severity="Low" seq="2004-1902" published="2004-12-31" name="CVE-2004-1902" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">The Citrix MetaFrame Password Manager 2.0, when a central credential store is not configured, does not encrypt passwords entered immediately after executing the First Time User Wizards, which allows local users to gain sensitive information.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <config />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/10049" source="BID" patch="1">10049</ref>
      <ref url="http://support.citrix.com/kb/entry.jspa?entryID=4062&amp;categoryID=256" source="CONFIRM" patch="1" adv="1">http://support.citrix.com/kb/entry.jspa?entryID=4062&amp;categoryID=256</ref>
      <ref url="http://secunia.com/advisories/11293" source="SECUNIA" patch="1">11293</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15737" source="XF">metaframe-wizard-info-disclosure(15737)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108127948610311&amp;w=2" source="BUGTRAQ">20040406 Foundstone Labs Advisory: Citrix MetaFrame Password Manager 2.0</ref>
      <ref url="http://www.osvdb.org/4942" source="OSVDB">4942</ref>
      <ref url="http://securitytracker.com/id?1009659" source="SECTRACK">1009659</ref>
    </refs>
    <vuln_soft>
      <prod vendor="citrix" name="metaframe_password_manager">
        <vers num="2.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-1903" published="2004-12-31" name="CVE-2004-1903" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Buffer overflow in blaxxun 3D 7.0 allows remote attackers to execute arbitrary code via a long URL property inside an object tag.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/15625" source="XF">blaxxun-applicationxcc3d-bo(15625)</ref>
      <ref url="http://www.securityfocus.com/bid/10064" source="BID">10064</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108127833002955&amp;w=2" source="BUGTRAQ">20040406 blaxxun3D(blaxxun Platform) 7 - Remote Buffer Overflow</ref>
    </refs>
    <vuln_soft>
      <prod vendor="blaxxun" name="contact_3d">
        <vers num="7.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-1904" published="2004-12-31" name="CVE-2004-1904" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in ascontrol.dll in Panda ActiveScan 5.0 allows remote attackers to execute arbitrary code via the Internacional property followed by a long string.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/15764" source="XF">panda-activescan-ascontrol-bo(15764)</ref>
      <ref url="http://www.securityfocus.com/bid/10065" source="BID">10065</ref>
      <ref url="http://theinsider.deep-ice.com/texts/advisory53.txt" source="MISC">http://theinsider.deep-ice.com/texts/advisory53.txt</ref>
      <ref url="http://secunia.com/advisories/11312" source="SECUNIA">11312</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108130573130482&amp;w=2" source="BUGTRAQ">20040406 Panda ActiveScan 5.0 - Remote Buffer Overflow and A Crash(D.O.S)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="panda" name="activescan">
        <vers num="5.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1905" published="2004-12-31" name="CVE-2004-1905" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">ascontrol.dll in Panda ActiveScan 5.0 allows remote attackers to cause a denial of service (crash) by calling the SetSitesFile function.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/15831" source="XF">panda-activescan-ascontrol-dos(15831)</ref>
      <ref url="http://www.securityfocus.com/bid/10067" source="BID">10067</ref>
      <ref url="http://theinsider.deep-ice.com/texts/advisory53.txt" source="MISC">http://theinsider.deep-ice.com/texts/advisory53.txt</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108130573130482&amp;w=2" source="BUGTRAQ">20040406 Panda ActiveScan 5.0 - Remote Buffer Overflow and A Crash(D.O.S)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="panda" name="activescan">
        <vers num="5.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1906" published="2004-12-31" name="CVE-2004-1906" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Mcafee FreeScan allows remote attackers to cause a denial of service and possibly arbitrary code via a long string in the ScanParam property of a COM object, which may trigger a buffer overflow.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/15772" source="XF">freescan-mcfscan-bo(15772)</ref>
      <ref url="http://www.securityfocus.com/bid/10071" source="BID">10071</ref>
      <ref url="http://theinsider.deep-ice.com/texts/advisory54.txt" source="MISC">http://theinsider.deep-ice.com/texts/advisory54.txt</ref>
      <ref url="http://secunia.com/advisories/11313" source="SECUNIA">11313</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108136872711898&amp;w=2" source="BUGTRAQ">20040407 Mcafee FreeScan - Remote Buffer Overflow and Private Information Disclosure</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2004-April/019891.html" source="FULLDISC">20040407 Symantec, McAfee and Panda ActiveX controls</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2004-April/019877.html" source="FULLDISC">20040407 Mcafee FreeScan - Remote Buffer Overflow and Private Information Disclosure</ref>
    </refs>
  </entry>
  <entry type="CVE" severity="Low" seq="2004-1907" published="2004-12-31" name="CVE-2004-1907" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:N/A:P)" CVSS_score="2.6" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="4.9" CVSS_base_score="2.6">
    <desc>
      <descript source="cve">The Web Filtering functionality in Kerio Personal Firewall (KPF) 4.0.13 allows remote attackers to cause a denial of service (crash) by sending hex-encoded URLs containing "%13%12%13".</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
      <exception />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/15821" source="XF">kerio-pf-webfilter-dos(15821)</ref>
      <ref url="http://www.securityfocus.com/bid/10075" source="BID">10075</ref>
      <ref url="http://www.cipher.org.uk/index.php?p=advisories/HEX-Kerio_Personal_Firewall_Remote_DOS_7-04-2004.advisory" source="MISC">http://www.cipher.org.uk/index.php?p=advisories/HEX-Kerio_Personal_Firewall_Remote_DOS_7-04-2004.advisory</ref>
      <ref url="http://secunia.com/advisories/11331" source="SECUNIA">11331</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108137421524251&amp;w=2" source="BUGTRAQ">20040407 Kerio Personal Firewall 4.0.13 - Remote DoS (Crash)</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2004-04/0061.html" source="BUGTRAQ">20040406 Kerio Personal Firewall 4 and IE 6 "Bug"</ref>
    </refs>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1908" published="2004-12-31" name="CVE-2004-1908" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">McFreeScan.CoMcFreeScan.1 ActiveX object in Mcafee FreeScan allows remote attackers to obtain sensitive information via the GetSpecialFolderLocation function with certain parameters.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <access />
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/15782" source="XF">freescan-mcfscan-info-disclosure(15782)</ref>
      <ref url="http://www.securityfocus.com/bid/10077" source="BID">10077</ref>
      <ref url="http://secunia.com/advisories/11313" source="SECUNIA">11313</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108137545531496&amp;w=2" source="BUGTRAQ">20040407 McAfee Freescan ActiveX Information Disclosure [Additional Details &amp; PoC]</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108136872711898&amp;w=2" source="BUGTRAQ">20040407 Mcafee FreeScan - Remote Buffer Overflow and Private Information Disclosure</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2004-April/019891.html" source="FULLDISC">20040407 Symantec, McAfee and Panda ActiveX controls</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2004-April/019877.html" source="FULLDISC">20040407 Mcafee FreeScan - Remote Buffer Overflow and Private Information Disclosure</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mcafee" name="freescan">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2004-1909" published="2004-12-31" name="CVE-2004-1909" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:N/A:P)" CVSS_score="2.6" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="4.9" CVSS_base_score="2.6">
    <desc>
      <descript source="cve">Claim Anti-Virus (ClamAV) 0.68 and earlier allows remote attackers to cause a denial of service (crash) via certain RAR archives, such as those generated by the Beagle/Bagle worm.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/9897" source="BID" patch="1">9897</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200404-07.xml" source="GENTOO" patch="1">GLSA-200404-07</ref>
      <ref url="http://secunia.com/advisories/11177" source="SECUNIA" patch="1">11177</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15553" source="XF">clam-antivirus-rar-dos(15553)</ref>
      <ref url="http://freshmeat.net/projects/clamav/?branch_id=29355&amp;release_id=154462" source="CONFIRM">http://freshmeat.net/projects/clamav/?branch_id=29355&amp;release_id=154462</ref>
    </refs>
    <vuln_soft>
      <prod vendor="clam_anti-virus" name="clamav">
        <vers num="0.65" />
        <vers num="0.67" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1910" published="2004-12-31" name="CVE-2004-1910" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">rufsi.dll in Symantec Virus Detection allows remote attackers to cause a denial of service (crash) via a long string to the GetPrivateProfileString function.  NOTE: this issue was originally reported as a buffer overflow, but that specific claim is disputed by the vendor, although a crash is acknowledged.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input bound="1" />
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/15778" source="XF">symantec-sc-rufsi-bo(15778)</ref>
      <ref url="http://www.securityfocus.com/bid/10069" source="BID">10069</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108143485021721&amp;w=2" source="BUGTRAQ">20040408 Re:  Symantec Virus Detection(Free ActiveX) - Remote Buffer Overflow, Apr 7</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108136901406896&amp;w=2" source="BUGTRAQ">20040407 Symantec Virus Detection(Free ActiveX) - Remote Buffer Overflow</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2004-April/019891.html" source="FULLDISC">20040407 Symantec, McAfee and Panda ActiveX controls</ref>
    </refs>
    <vuln_soft>
      <prod vendor="symantec" name="security_check_virus_detection">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1911" published="2004-12-31" name="CVE-2004-1911" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in AzDGDatingLite 2.1.1 allows remote attackers to inject arbitrary web script or HTML via the (1) l parameter (aka language variable) to index.php or (2) id parameter to view.php.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/15796" source="XF">azdgdating-index-view-xss(15796)</ref>
      <ref url="http://www.securityfocus.com/bid/10084" source="BID">10084</ref>
      <ref url="http://www.osvdb.org/5019" source="OSVDB">5019</ref>
      <ref url="http://www.osvdb.org/5018" source="OSVDB">5018</ref>
      <ref url="http://secunia.com/advisories/11326" source="SECUNIA">11326</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108144342317973&amp;w=2" source="BUGTRAQ">20040408 [waraxe-2004-SA#014 - Cross-Site Scripting aka XSS in AzDGDatingLite]</ref>
    </refs>
    <vuln_soft>
      <prod vendor="azerbaijan_development_group" name="azdgdating">
        <vers num="2.1.1" edition="" />
        <vers num="2.1.1" edition=":lite" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1912" published="2004-12-31" name="CVE-2004-1912" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The (1) modules.php, (2) block-Calendar.php, (3) block-Calendar1.php, (4) block-Calendar_center.php scripts in NukeCalendar 1.1.a, as used in PHP-Nuke, allow remote attackers to obtain sensitive information via a URL with an invalid argument, which reveals the full path in an error message.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/15795" source="XF">nuke-calendar-path-disclosure(15795)</ref>
      <ref url="http://www.securityfocus.com/bid/10082" source="BID">10082</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108144168932458&amp;w=2" source="BUGTRAQ">20040408 [waraxe-2004-SA#015 - Multiple vulnerabilities in NukeCalendar v1.1.a]</ref>
    </refs>
    <vuln_soft>
      <prod vendor="francisco_burzi" name="php-nuke">
        <vers num="8.0_final" />
      </prod>
      <prod vendor="shiba-design" name="nukecalendar">
        <vers num="1.1.a" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1913" published="2004-12-31" name="CVE-2004-1913" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in modules.php in NukeCalendar 1.1.a, as used in PHP-Nuke, allows remote attackers to inject arbitrary web script or HTML via the eid parameter.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/15798" source="XF">nuke-calendar-modulesphp-xss(15798)</ref>
      <ref url="http://www.securityfocus.com/bid/10082" source="BID">10082</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108144168932458&amp;w=2" source="BUGTRAQ">20040408 [waraxe-2004-SA#015 - Multiple vulnerabilities in NukeCalendar v1.1.a]</ref>
    </refs>
    <vuln_soft>
      <prod vendor="francisco_burzi" name="php-nuke">
        <vers num="8.0_final" />
      </prod>
      <prod vendor="shiba-design" name="nukecalendar">
        <vers num="1.1.a" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-1914" published="2004-12-31" name="CVE-2004-1914" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in modules.php in NukeCalendar 1.1.a, as used in PHP-Nuke, allows remote attackers to execute arbitrary SQL commands via the eid parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/15799" source="XF">nukecalendar-modulesphp-sql-injection(15799)</ref>
      <ref url="http://www.securityfocus.com/bid/10082" source="BID">10082</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108144168932458&amp;w=2" source="BUGTRAQ">20040408 [waraxe-2004-SA#015 - Multiple vulnerabilities in NukeCalendar v1.1.a]</ref>
    </refs>
    <vuln_soft>
      <prod vendor="francisco_burzi" name="php-nuke">
        <vers num="8.0_final" />
      </prod>
      <prod vendor="shiba-design" name="nukecalendar">
        <vers num="1.1.a" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-1915" published="2004-04-08" name="CVE-2004-1915" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in the parse_all_client_messages function in LCDproc 0.4.x up to 0.4.4 allows remote attackers to execute arbitrary code via a large number of arguments.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/15803" source="XF" patch="1" adv="1">lcdproc-parseallclientmessages-bo(15803)</ref>
      <ref url="http://www.securityfocus.com/bid/10085" source="BID" patch="1" adv="1">10085</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200404-19.xml" source="GENTOO" patch="1" adv="1">GLSA-200404-19</ref>
      <ref url="http://secunia.com/advisories/11333" source="SECUNIA" patch="1" adv="1">11333</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108145722229810&amp;w=2" source="BUGTRAQ" adv="1">20040408 PSR - #2004-001 Remote - LCDProc</ref>
      <ref url="http://lists.omnipotent.net/pipermail/lcdproc/2004-April/008884.html" source="CONFIRM" adv="1">http://lists.omnipotent.net/pipermail/lcdproc/2004-April/008884.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="lcdproc" name="lcdproc">
        <vers num="0.3" />
        <vers num="0.4" />
        <vers num="0.4.1_r1" />
        <vers num="4.0" />
        <vers num="4.1" />
        <vers num="4.2" />
        <vers num="4.3" />
        <vers num="4.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-1916" published="2004-04-08" name="CVE-2004-1916" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple buffer overflows in LCDProc 0.4.1, and possibly other 0.4.x versions up to 0.4.4, allows remote attackers to execute arbitrary code via (1) a long invalid command to parse_all_client_messages function, or (2) long argv command to test_func_func function.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/10085" source="BID" patch="1" adv="1">10085</ref>
      <ref url="http://secunia.com/advisories/11333" source="SECUNIA" patch="1" adv="1">11333</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15814" source="XF" adv="1">lcdproc-testfuncfunc-bo(15814)</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200404-19.xml" source="GENTOO" adv="1">GLSA-200404-19</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108146376315229&amp;w=2" source="BUGTRAQ" adv="1">20040408 PSR - #2004-002 Remote - LCDProc</ref>
      <ref url="http://lists.omnipotent.net/pipermail/lcdproc/2004-April/008884.html" source="CONFIRM" adv="1">http://lists.omnipotent.net/pipermail/lcdproc/2004-April/008884.html</ref>
    </refs>
  </entry>
  <entry type="CVE" severity="High" seq="2004-1917" published="2004-04-08" name="CVE-2004-1917" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Format string vulnerability in test_func_func in LCDProc 0.4.1 and earlier allows remote attackers to execute arbitrary code via format string specifiers in the str variable.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/10085" source="BID" patch="1" adv="1">10085</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200404-19.xml" source="GENTOO" patch="1" adv="1">GLSA-200404-19</ref>
      <ref url="http://secunia.com/advisories/11333" source="SECUNIA" patch="1" adv="1">11333</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15817" source="XF" adv="1">lcdproc-testfuncfunc-format-string(15817)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108146376315229&amp;w=2" source="BUGTRAQ" adv="1">20040408 PSR - #2004-002 Remote - LCDProc</ref>
      <ref url="http://lists.omnipotent.net/pipermail/lcdproc/2004-April/008884.html" source="CONFIRM" adv="1">http://lists.omnipotent.net/pipermail/lcdproc/2004-April/008884.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="lcdproc" name="lcdproc">
        <vers num="0.3" />
        <vers num="0.4" />
        <vers num="0.4.1_r1" />
        <vers num="4.0" />
        <vers num="4.1" />
        <vers num="4.2" />
        <vers num="4.3" />
        <vers num="4.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1918" published="2004-04-09" name="CVE-2004-1918" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">RSniff 1.0 allows remote attackers to cause a denial of service (connection exhaustion) via a large number of connections with a command other than AUTHENTICATE, or without any data, which prevents the socket from being closed properly.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/10093" source="BID" patch="1" adv="1">10093</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15823" source="XF" adv="1">rsniff-connection-dos(15823)</ref>
      <ref url="http://secunia.com/advisories/11339" source="SECUNIA" adv="1">11339</ref>
      <ref url="http://aluigi.altervista.org/adv/rsniff-adv.txt" source="MISC">http://aluigi.altervista.org/adv/rsniff-adv.txt</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108152508004665&amp;w=2" source="BUGTRAQ">20040409 DoS in Rsniff 1.0</ref>
    </refs>
    <vuln_soft>
      <prod vendor="rsniff" name="rsniff">
        <vers num="1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1919" published="2004-04-09" name="CVE-2004-1919" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The hash_strcmp function in hasch.c in Crackalaka 1.0.8 allows remote attackers to cause a denial of service (crash) via large malformed strings.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/15824" source="XF" adv="1">crackalaka-hashstrcmp-dos(15824)</ref>
      <ref url="http://www.securityfocus.com/bid/10092" source="BID" adv="1">10092</ref>
      <ref url="http://secunia.com/advisories/11340" source="SECUNIA" adv="1">11340</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108152479316967&amp;w=2" source="BUGTRAQ" adv="1">20040409 DoS in Crackalaka 1.0.8</ref>
    </refs>
    <vuln_soft>
      <prod vendor="crackalaka" name="crackalaka">
        <vers num="1.0.8" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-1920" published="2004-04-10" name="CVE-2004-1920" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">X-Micro WLAN 11b Broadband Router 1.2.2, 1.2.2.3, 1.2.2.4, and 1.6.0.0 has a hardcoded "super" username and password, which could allow remote attackers to gain access.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/10095" source="BID" patch="1" adv="1">10095</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108162529229947&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20040410 Backdoor in X-Micro WLAN 11b Broadband Router</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15829" source="XF" adv="1">xmicro-router-default-account(15829)</ref>
      <ref url="http://secunia.com/advisories/11342" source="SECUNIA" adv="1">11342</ref>
    </refs>
    <vuln_soft>
      <prod vendor="x-micro" name="wlan_11b_broadband_router_firmware">
        <vers num="1.2.2" />
        <vers num="1.2.2.3" />
        <vers num="1.2.2.4" />
        <vers num="1.6.0" />
        <vers num="1.6.0.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-1921" published="2004-04-10" name="CVE-2004-1921" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">X-Micro WLAN 11b Broadband Router 1.6.0.1 has a hardcoded "1502" username and password, which could allow remote attackers to gain access.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/15890" source="XF" patch="1" adv="1">xmicro-router-default-login(15890)</ref>
      <ref url="http://www.securityfocus.com/bid/10095" source="BID" patch="1" adv="1">10095</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108223222519855&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20040416 NEW backdoor in X-Micro WLAN 11b Broadband Router</ref>
      <ref url="http://secunia.com/advisories/11342" source="SECUNIA" adv="1">11342</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108213608111111&amp;w=2" source="BUGTRAQ" adv="1">20040416 Re: Backdoor in X-Micro WLAN 11b Broadband Router</ref>
    </refs>
    <vuln_soft>
      <prod vendor="x-micro" name="wlan_11b_broadband_router_firmware">
        <vers num="1.2.2" />
        <vers num="1.2.2.3" />
        <vers num="1.2.2.4" />
        <vers num="1.6.0" />
        <vers num="1.6.0.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2004-1922" published="2004-04-11" name="CVE-2004-1922" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:N/A:P)" CVSS_score="2.6" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="4.9" CVSS_base_score="2.6">
    <desc>
      <descript source="cve">Microsoft Internet Explorer 5.5 and 6.0 allocates memory based on the memory size written in the BMP file instead of the actual BMP file size, which allows remote attackers to cause a denial of service (memory consumption) via a small BMP file with has a large memory size.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108183130827872&amp;w=2" source="BUGTRAQ" adv="1">20040411 Microsoft Internet Explorer BMP file memory DoS vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="ie">
        <vers num="5.5" />
        <vers num="6.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1923" published="2004-04-11" name="CVE-2004-1923" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Tiki CMS/Groupware (TikiWiki) 1.8.1 and earlier allows remote attackers to gain sensitive information via a direct request to (1) banner_click.php, (2) categorize.php, (3) tiki-admin_include_directory.php, (4) tiki-directory_search.php, which reveal the web server path in an error message.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/15847" source="XF" patch="1" adv="1">tikiwiki-path-disclosure(15847)</ref>
      <ref url="http://www.securityfocus.com/bid/10100" source="BID" patch="1" adv="1">10100</ref>
      <ref url="http://tikiwiki.org/tiki-read_article.php?articleId=66" source="CONFIRM" patch="1">http://tikiwiki.org/tiki-read_article.php?articleId=66</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108180073206947&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20040412 Multiple Vulnerabilities In Tiki CMS/Groupware [ TikiWiki ]</ref>
      <ref url="http://secunia.com/advisories/11344" source="SECUNIA" adv="1">11344</ref>
    </refs>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1924" published="2004-04-11" name="CVE-2004-1924" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in Tiki CMS/Groupware (TikiWiki) 1.8.1 and earlier allow remote attackers to inject arbitrary web script or HTML via via the (1) theme parameter to tiki-switch_theme.php, (2) find and priority parameters to messu-mailbox.php, (3) flag, priority, flagval, sort_mode, or find parameters to messu-read.php, (4) articleId parameter to tiki-read_article.php, (5) parentId parameter to tiki-browse_categories.php, (6) comments_threshold parameter to tiki-index.php (7) articleId parameter to tiki-print_article.php, (8) galleryId parameter to tiki-list_file_gallery.php, (9) galleryId parameter to tiki-upload_file.php, (10) faqId parameter to tiki-view_faq.php, (11) chartId parameter to tiki-view_chart.php, or (12) surveyId parameter to tiki-survey_stats_survey.php.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/15846" source="XF" patch="1" adv="1">tikiwiki-xss(15846)</ref>
      <ref url="http://www.securityfocus.com/bid/10100" source="BID" patch="1" adv="1">10100</ref>
      <ref url="http://tikiwiki.org/tiki-read_article.php?articleId=66" source="CONFIRM" patch="1">http://tikiwiki.org/tiki-read_article.php?articleId=66</ref>
      <ref url="http://secunia.com/advisories/11344" source="SECUNIA" adv="1">11344</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108180073206947&amp;w=2" source="BUGTRAQ" adv="1">20040412 Multiple Vulnerabilities In Tiki CMS/Groupware [ TikiWiki ]</ref>
    </refs>
  </entry>
  <entry type="CVE" severity="High" seq="2004-1925" published="2004-04-12" name="CVE-2004-1925" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple SQL injection vulnerabilities in Tiki CMS/Groupware (TikiWiki) 1.8.1 and earlier allow remote attackers to execute arbitrary SQL commands via the sort_mode parameter in (1) tiki-usermenu.php, (2) tiki-list_file_gallery.php, (3) tiki-directory_ranking.php, (4) tiki-browse_categories.php, (5) tiki-index.php, (6) tiki-user_tasks.php, (7) tiki-directory_ranking.php, (8) tiki-directory_search.php, (9) tiki-file_galleries.php, (10) tiki-list_faqs.php, (11) tiki-list_trackers.php, (12) tiki-list_blogs.php, or via the offset parameter in (13) tiki-usermenu.php, (14) tiki-browse_categories.php, (15) tiki-index.php, (16) tiki-user_tasks.php, (17) tiki-list_faqs.php, (18) tiki-list_trackers.php, or (19) tiki-list_blogs.php.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/15845" source="XF" patch="1" adv="1">tikiwiki-sql-injection(15845)</ref>
      <ref url="http://www.securityfocus.com/bid/10100" source="BID" patch="1" adv="1">10100</ref>
      <ref url="http://tikiwiki.org/tiki-read_article.php?articleId=66" source="CONFIRM" patch="1" adv="1">http://tikiwiki.org/tiki-read_article.php?articleId=66</ref>
      <ref url="http://secunia.com/advisories/11344" source="SECUNIA" patch="1" adv="1">11344</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108180073206947&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20040411 Multiple Vulnerabilities In Tiki CMS/Groupware [ TikiWiki ]</ref>
    </refs>
    <vuln_soft>
      <prod vendor="tikiwiki_project" name="tikiwiki">
        <vers num="1.8" />
        <vers num="1.8.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1926" published="2004-04-11" name="CVE-2004-1926" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Tiki CMS/Groupware (TikiWiki) 1.8.1 and earlier allows remote attackers to inject arbitrary code via the (1) Theme, (2) Country, (3) Real Name, or (4) Displayed time zone fields in a User Profile, or the (5) Name, (6) Description, (7) URL, or (8) Country fields in a Directory/Add Site operation.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/10100" source="BID" patch="1" adv="1">10100</ref>
      <ref url="http://tikiwiki.org/tiki-read_article.php?articleId=66" source="CONFIRM" patch="1">http://tikiwiki.org/tiki-read_article.php?articleId=66</ref>
      <ref url="http://secunia.com/advisories/11344" source="SECUNIA" adv="1">11344</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108180073206947&amp;w=2" source="BUGTRAQ" adv="1">20040412 Multiple Vulnerabilities In Tiki CMS/Groupware [ TikiWiki ]</ref>
    </refs>
    <vuln_soft>
      <prod vendor="tikiwiki_project" name="tikiwiki">
        <vers num="1.8" />
        <vers num="1.8.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1927" published="2004-04-11" name="CVE-2004-1927" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in the map feature (tiki-map.phtml) in Tiki CMS/Groupware (TikiWiki) 1.8.1 and earlier allows remote attackers to determine the existence of arbitrary files via .. (dot dot) sequences in the mapfile parameter.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <access />
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/15848" source="XF" patch="1" adv="1">tikiwiki-tikimap-file-disclosure(15848)</ref>
      <ref url="http://www.securityfocus.com/bid/10100" source="BID" patch="1" adv="1">10100</ref>
      <ref url="http://tikiwiki.org/tiki-read_article.php?articleId=66" source="CONFIRM" patch="1">http://tikiwiki.org/tiki-read_article.php?articleId=66</ref>
      <ref url="http://secunia.com/advisories/11344" source="SECUNIA" adv="1">11344</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108180073206947&amp;w=2" source="BUGTRAQ" adv="1">20040412 Multiple Vulnerabilities In Tiki CMS/Groupware [ TikiWiki ]</ref>
    </refs>
    <vuln_soft>
      <prod vendor="tikiwiki_project" name="tikiwiki">
        <vers num="1.8" />
        <vers num="1.8.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-1928" published="2004-04-12" name="CVE-2004-1928" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">The image upload feature in Tiki CMS/Groupware (TikiWiki) 1.8.1 and earlier allows remote attackers to upload and possibly execute arbitrary files via the img/wiki_up URL.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/15849" source="XF" patch="1" adv="1">tikiwiki-file-upload(15849)</ref>
      <ref url="http://www.securityfocus.com/bid/10100" source="BID" patch="1" adv="1">10100</ref>
      <ref url="http://tikiwiki.org/tiki-read_article.php?articleId=66" source="CONFIRM" patch="1" adv="1">http://tikiwiki.org/tiki-read_article.php?articleId=66</ref>
      <ref url="http://secunia.com/advisories/11344" source="SECUNIA" patch="1" adv="1">11344</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108180073206947&amp;w=2" source="BUGTRAQ" adv="1">20040412 Multiple Vulnerabilities In Tiki CMS/Groupware [ TikiWiki ]</ref>
    </refs>
    <vuln_soft>
      <prod vendor="tikiwiki_project" name="tikiwiki">
        <vers num="1.8" />
        <vers num="1.8.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-1929" published="2004-04-13" name="CVE-2004-1929" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in the bblogin function in functions.php in PHP-Nuke 6.x through 7.2 allows remote attackers to bypass authentication and gain access by injecting base64-encoded SQL code into the user parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/15839" source="XF" adv="1">phpnuke-bypass-authentication(15839)</ref>
      <ref url="http://www.waraxe.us/index.php?modname=sa&amp;id=17" source="MISC" adv="1">http://www.waraxe.us/index.php?modname=sa&amp;id=17</ref>
      <ref url="http://www.securityfocus.com/bid/10135" source="BID" adv="1">10135</ref>
      <ref url="http://secunia.com/advisories/11347" source="SECUNIA" adv="1">11347</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108180111826852&amp;w=2" source="BUGTRAQ" adv="1">20040412 [waraxe-2004-SA#017 - User-level authentication bypass in phpnuke 6.x-7.2]</ref>
    </refs>
    <vuln_soft>
      <prod vendor="francisco_burzi" name="php-nuke">
        <vers num="5.5" />
        <vers num="6.0" />
        <vers num="6.5" />
        <vers num="6.5_beta1" />
        <vers num="6.5_final" />
        <vers num="6.5_rc1" />
        <vers num="6.5_rc2" />
        <vers num="6.5_rc3" />
        <vers num="6.6" />
        <vers num="6.7" />
        <vers num="6.9" />
        <vers num="7.0" />
        <vers num="7.0_final" />
        <vers num="7.1" />
        <vers num="7.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1930" published="2004-04-12" name="CVE-2004-1930" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in the cookiedecode function in mainfile.php for PHP-Nuke 6.x through 7.2, when themes are used, allows remote attackers to inject arbitrary web script or HTML via a base64-encoded user parameter or cookie.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/15842" source="XF" adv="1">phpnuke-cookiedecode-xss(15842)</ref>
      <ref url="http://www.waraxe.us/index.php?modname=sa&amp;id=16" source="MISC" adv="1">http://www.waraxe.us/index.php?modname=sa&amp;id=16</ref>
      <ref url="http://www.securityfocus.com/bid/10128" source="BID" adv="1">10128</ref>
      <ref url="http://secunia.com/advisories/11347" source="SECUNIA" adv="1">11347</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108182759214035&amp;w=2" source="BUGTRAQ" adv="1">20040412 [waraxe-2004-SA#016 - Cross-Site Scripting aka XSS in phpnuke 6.x-7.2 part 3]</ref>
    </refs>
    <vuln_soft>
      <prod vendor="francisco_burzi" name="php-nuke">
        <vers num="6.0" />
        <vers num="6.5" />
        <vers num="6.5_beta1" />
        <vers num="6.5_final" />
        <vers num="6.5_rc1" />
        <vers num="6.5_rc2" />
        <vers num="6.5_rc3" />
        <vers num="6.6" />
        <vers num="6.7" />
        <vers num="6.9" />
        <vers num="7.0" />
        <vers num="7.0_final" />
        <vers num="7.1" />
        <vers num="7.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-1932" published="2004-04-12" name="CVE-2004-1932" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in (1) auth.php and (2) admin.php in PHP-Nuke 6.x through 7.2 allows remote attackers to execute arbitrary SQL code and create an administrator account via base64-encoded SQL in the admin parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/15835" source="XF" adv="1">phpnuke-admin-bypass-authentication(15835)</ref>
      <ref url="http://www.waraxe.us/index.php?modname=sa&amp;id=18" source="MISC" adv="1">http://www.waraxe.us/index.php?modname=sa&amp;id=18</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108180334918576&amp;w=2" source="BUGTRAQ" adv="1">20040412 [waraxe-2004-SA#018 - Admin-level authentication bypass in phpnuke 6.x-7.2]</ref>
    </refs>
    <vuln_soft>
      <prod vendor="francisco_burzi" name="php-nuke">
        <vers num="6.0" />
        <vers num="6.5" />
        <vers num="6.5_beta1" />
        <vers num="6.5_final" />
        <vers num="6.5_rc1" />
        <vers num="6.5_rc2" />
        <vers num="6.5_rc3" />
        <vers num="6.6" />
        <vers num="6.7" />
        <vers num="6.9" />
        <vers num="7.0" />
        <vers num="7.0_final" />
        <vers num="7.1" />
        <vers num="7.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2004-1933" published="2004-04-12" name="CVE-2004-1933" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">Citadel/UX 5.00 through 6.14 installs the database directory and files with world-read permissions, which could allow local users to bypass access controls and read unauthorized messages.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <access />
      <config />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/15850" source="XF" patch="1" adv="1">citadel-database-insecure-permissions(15850)</ref>
      <ref url="http://www.securityfocus.com/bid/10102" source="BID" patch="1" adv="1">10102</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108180024428804&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20040412 Citadel/UX 6.20 fixes local permissions vulnerability</ref>
    </refs>
  </entry>
  <entry type="CVE" severity="High" seq="2004-1934" published="2004-04-15" name="CVE-2004-1934" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">PHP remote file inclusion vulnerability in affich.php in Gemitel 3.50 allows remote attackers to execute arbitrary PHP code via the base parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/10156" source="BID" patch="1" adv="1">10156</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108206642725505&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20040415 Include vulnerability in GEMITEL v 3.50</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15887" source="XF" adv="1">gemitel-spturnphpfile-include(15887)</ref>
      <ref url="http://www.osvdb.org/5396" source="OSVDB">5396</ref>
      <ref url="http://securitytracker.com/id?1009824" source="SECTRACK">1009824</ref>
      <ref url="http://secunia.com/advisories/11393" source="SECUNIA" adv="1">11393</ref>
    </refs>
    <vuln_soft>
      <prod vendor="isesam" name="gemitel">
        <vers num="3.50" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1935" published="2004-04-15" name="CVE-2004-1935" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in SCT Campus Pipeline allows remote attackers to inject arbitrary web script or HTML via onload, onmouseover, and other Javascript events in an e-mail attachment.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <exception />
      <config />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/10154" source="BID" patch="1" adv="1">10154</ref>
      <ref url="http://secunia.com/advisories/11396" source="SECUNIA" patch="1" adv="1">11396</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15878" source="XF" adv="1">sct-campus-attachment-xss(15878)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108207280917231&amp;w=2" source="BUGTRAQ" adv="1">20040415 SCT javascript execution vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sct_corporation" name="campus_pipeline">
        <vers num="1.0" />
        <vers num="2.0" />
        <vers num="2.1" />
        <vers num="2.2" />
        <vers num="3.0" />
        <vers num="3.1" />
        <vers num="3.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-1936" published="2004-04-14" name="CVE-2004-1936" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">ZoneAlarm Pro 4.5.538.001 and possibly other versions allows remote attackers to bypass e-mail protection via attachments whose names contain certain non-English characters.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/15884" source="XF">zonealarm-email-bypass-security(15884)</ref>
      <ref url="http://www.securityfocus.com/bid/10148" source="BID">10148</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108248415509417&amp;w=2" source="BUGTRAQ" adv="1">20040420 Re: ZA Security Hole</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108206751931251&amp;w=2" source="BUGTRAQ" adv="1">20040414 ZA Security Hole</ref>
    </refs>
    <vuln_soft>
      <prod vendor="zonelabs" name="zonealarm">
        <vers num="2.4" edition="" />
        <vers num="2.4" edition=":pro" />
        <vers num="2.6" edition="" />
        <vers num="2.6" edition=":pro" />
        <vers num="3.0" edition="" />
        <vers num="3.0" edition=":pro" />
        <vers num="3.1" edition="" />
        <vers num="3.1" edition=":pro" />
        <vers num="4.0" edition="" />
        <vers num="4.0" edition=":pro" />
        <vers num="4.0" edition=":plus" />
        <vers num="4.5" edition="" />
        <vers num="4.5" edition=":pro" />
        <vers num="4.5.538.001" edition="" />
        <vers num="4.5.538.001" edition=":pro" />
        <vers num="4.5.538.001" edition=":plus" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1937" published="2004-12-31" name="CVE-2004-1937" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Multiple directory traversal vulnerabilities in Nuked-KlaN 1.4b and 1.5b allow remote attackers to read or include arbitrary files via .. sequences in (1) the user_langue parameter to index.php or (2) the langue parameter to update.php, or modify arbitrary GLOBAL variables by causing globals.php to be loaded before conf.inc.php via (3) .. sequences in the file parameter with the page parameter set to globals, or (4) ../globals.php in the user_langue parameter, as demonstrated by modifying $nuked[prefix] in the Suggest module.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/10104" source="BID" patch="1">10104</ref>
      <ref url="http://www.phpsecure.info/v2/tutos/frog/Nuked-KlaN.txt" source="MISC" patch="1">http://www.phpsecure.info/v2/tutos/frog/Nuked-KlaN.txt</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15844" source="XF">nuked-klan-configurtion-corruption(15844)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15843" source="XF">nuked-klan-file-include(15843)</ref>
      <ref url="http://secunia.com/advisories/11341" source="SECUNIA">11341</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108222826225823&amp;w=2" source="BUGTRAQ">20040417 [SCSA-028] Nuked-Klan Multiple Vulnerabilities</ref>
    </refs>
    <vuln_soft>
      <prod vendor="nuked-klan" name="nuked-klan">
        <vers num="1.2" />
        <vers num="1.2_beta" />
        <vers num="1.3" />
        <vers num="1.3_beta" />
        <vers num="1.4" />
        <vers num="1.5" />
        <vers num="1.5_sp2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-1938" published="2004-04-19" name="CVE-2004-1938" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in userlogin.php in Phorum 3.4.7 allows remote attackers to execute arbitrary SQL commands via doubly hex-encoded characters such as "%2527", which is translated to "'", as demonstrated using the phorum_uriauth parameter to list.php.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/10173" source="BID" patch="1" adv="1">10173</ref>
      <ref url="http://secunia.com/advisories/11407" source="SECUNIA" patch="1" adv="1">11407</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15894" source="XF" adv="1">phorum-userlogin-sql-injection(15894)</ref>
      <ref url="http://www.waraxe.us/index.php?modname=sa&amp;id=19" source="MISC" adv="1">http://www.waraxe.us/index.php?modname=sa&amp;id=19</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108239796512897&amp;w=2" source="BUGTRAQ" adv="1">20040419 [waraxe-2004-SA#019 - Critical sql injection bug in Phorum 3.4.7]</ref>
    </refs>
    <vuln_soft>
      <prod vendor="phorum" name="phorum">
        <vers num="3.4.7" />
        <vers num="3.4.8" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1939" published="2004-04-14" name="CVE-2004-1939" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in Zaep AntiSpam 2.0 allows remote attackers to inject arbitrary web script or HTML via double encoded slashes (%252F) in the key parameter.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/15858" source="XF" patch="1">zaep-antispam-xss(15858)</ref>
      <ref url="http://www.securityfocus.com/bid/10139" source="BID" patch="1">10139</ref>
      <ref url="http://www.securiteam.com/windowsntfocus/5EP0I15CKK.html" source="MISC" patch="1" adv="1">http://www.securiteam.com/windowsntfocus/5EP0I15CKK.html</ref>
      <ref url="http://secunia.com/advisories/11388" source="SECUNIA" patch="1" adv="1">11388</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108241507812681&amp;w=2" source="BUGTRAQ" adv="1">20040419 Zaep AntiSpam Cross Site Scripting</ref>
    </refs>
    <vuln_soft>
      <prod vendor="rhinosoft" name="zaep_antispam">
        <vers num="2.0" />
        <vers num="2.0_.0.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1940" published="2004-12-31" name="CVE-2004-1940" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">sipclient.cpp in KPhone 4.0.1 and earlier allows remote attackers to cause a denial of service (crash) via a STUN response packet with a large attrLen value that causes an out-of-bounds read.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.wirlab.net/kphone/changes-4.0.2.html" source="CONFIRM" patch="1">http://www.wirlab.net/kphone/changes-4.0.2.html</ref>
      <ref url="http://www.securityfocus.com/bid/10159" source="BID" patch="1">10159</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15874" source="XF">kphone-stun-dos(15874)</ref>
      <ref url="http://www.securiteam.com/unixfocus/5PP0B1FCLY.html" source="MISC">http://www.securiteam.com/unixfocus/5PP0B1FCLY.html</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108244325924859&amp;w=2" source="BUGTRAQ">20040419 KPhone STUN DoS (Malformed STUN Packets)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="kphone" name="kphone">
        <vers num="2.0" />
        <vers num="2.1" />
        <vers num="2.11" />
        <vers num="3.0" />
        <vers num="3.1" />
        <vers num="3.11" />
        <vers num="3.12" />
        <vers num="3.13" />
        <vers num="3.14" />
        <vers num="4.0.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1941" published="2004-04-19" name="CVE-2004-1941" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Fastream NETFile FTP/Web Server 6.5.1.980 allows remote attackers to cause a denial of service via a username that does not exist.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/15899" source="XF" patch="1">fastream-user-pass-dos(15899)</ref>
      <ref url="http://www.securityfocus.com/bid/10169" source="BID" patch="1">10169</ref>
      <ref url="http://secunia.com/advisories/11428" source="SECUNIA" patch="1" adv="1">11428</ref>
      <ref url="http://www.autistici.org/fdonato/advisory/FastreamNETFileFWServer6.5.1.980-adv.txt" source="MISC" adv="1">http://www.autistici.org/fdonato/advisory/FastreamNETFileFWServer6.5.1.980-adv.txt</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108239249613861&amp;w=2" source="BUGTRAQ" adv="1">20040419 DoS in  NETFile FTP/Web Server</ref>
      <ref url="http://www.osvdb.org/5548" source="OSVDB">5548</ref>
      <ref url="http://securitytracker.com/id?1009868" source="SECTRACK">1009868</ref>
    </refs>
    <vuln_soft>
      <prod vendor="fastream" name="netfile_ftp_web_server">
        <vers num="6.5.1.980" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-1942" published="2004-04-19" name="CVE-2004-1942" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">The Solaris 9 patches 113579-02 through 113579-05, and 114342-02 through 114342-05, prevent ypserv and ypxfrd from properly restricting access to secure NIS maps, which allows local users to use ypcat or ypmatch to extract the contents of a secure map such as passwd.adjunct.byname.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/10261" source="BID" patch="1" adv="1">10261</ref>
      <ref url="http://www.ciac.org/ciac/bulletins/o-144.shtml" source="CIAC" patch="1" adv="1">O-144</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-57554-1" source="SUNALERT" patch="1" adv="1">57554</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15908" source="XF" adv="1">solaris-nis-unauth-privileges(15908)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108241638500417&amp;w=2" source="BUGTRAQ" adv="1">20040419 Solaris 9 patch 113579-03 introduces a NIS security bug</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="patch_manager">
        <vers num="113579-02" />
        <vers num="113579-03" />
        <vers num="113579-04" />
        <vers num="113579-05" />
        <vers num="114342-02" />
        <vers num="114342-03" />
        <vers num="114342-04" />
        <vers num="114342-05" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-1943" published="2004-04-19" name="CVE-2004-1943" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">PHP remote file inclusion vulnerability in album_portal.php in phpBB modified by Przemo 1.8 allows remote attackers to execute arbitrary PHP code via the phpbb_root_path parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/10177" source="BID" patch="1" adv="1">10177</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15916" source="XF" adv="1">phpbb-albumportal-file-include(15916)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108244738102532&amp;w=2" source="BUGTRAQ" adv="1">20040419 phpBB modified by Przemo arbitary code execution</ref>
    </refs>
    <vuln_soft>
      <prod vendor="phpbb_group" name="phpbb">
        <vers num="2.0.0" />
        <vers num="2.0.1" />
        <vers num="2.0.2" />
        <vers num="2.0.3" />
        <vers num="2.0.4" />
        <vers num="2.0.5" />
        <vers num="2.0.6" />
        <vers num="2.0.6c" />
        <vers num="2.0.6d" />
        <vers num="2.0.7" />
        <vers num="2.0.7a" />
        <vers num="2.0.8" />
        <vers num="2.0.8a" />
        <vers num="2.0_beta1" />
        <vers num="2.0_rc1" />
        <vers num="2.0_rc2" />
        <vers num="2.0_rc3" />
        <vers num="2.0_rc4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1944" published="2004-04-14" name="CVE-2004-1944" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Eudora 6.1 and 6.0.3 for Windows allows remote attackers to cause a denial of service (crash) via a deeply nested multipart MIME message.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/15857" source="XF" adv="1">eudora-mime-message-dos(15857)</ref>
      <ref url="http://www.securityfocus.com/bid/10137" source="BID" adv="1">10137</ref>
      <ref url="http://secunia.com/advisories/11360" source="SECUNIA" adv="1">11360</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108241694627321&amp;w=2" source="BUGTRAQ" adv="1">20040419 Eudora 6.1 is evil</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2004-April/020075.html" source="FULLDISC" adv="1">20040414 Eudora 6.0.3 nested MIME DoS</ref>
    </refs>
    <vuln_soft>
      <prod vendor="qualcomm" name="eudora">
        <vers num="6.0.3" />
        <vers num="6.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-1945" published="2004-04-20" name="CVE-2004-1945" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in Kinesphere eXchange POP3 allows remote attackers to execute arbitrary code via a long MAIL FROM field.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/10180" source="BID" patch="1" adv="1">10180</ref>
      <ref url="http://secunia.com/advisories/11449" source="SECUNIA" patch="1" adv="1">11449</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15922" source="XF" adv="1">exchange-pop3-smtp-bo(15922)</ref>
      <ref url="http://securitytracker.com/id?1009882" source="SECTRACK" adv="1">1009882</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108568462428096&amp;w=2" source="BUGTRAQ" adv="1">20040527 Re: Exchange pop3 remote exploit</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108247921402458&amp;w=2" source="BUGTRAQ" adv="1">20040419 Exchange pop3 remote exploit</ref>
      <ref url="http://www.osvdb.org/5593" source="OSVDB">5593</ref>
    </refs>
    <vuln_soft>
      <prod vendor="kinesphere_corporation" name="exchange_pop3">
        <vers num="4.0" />
        <vers num="5.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1946" published="2004-04-19" name="CVE-2004-1946" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Format string vulnerability in the PRINT_ERROR function in common.c for Cherokee Web Server 0.4.16 and earlier allows local users to execute arbitrary code via format string specifiers in the -C command line argument.  NOTE: it is not clear whether this issue could be exploited remotely, or if Cherokee is running at escalated privileges. Therefore it might not be a vulnerability.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/15924" source="XF" adv="1">cherokee-printerror-format-string(15924)</ref>
      <ref url="http://www.nosystem.com.ar/advisories/advisory-03.txt" source="MISC" adv="1">http://www.nosystem.com.ar/advisories/advisory-03.txt</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108249818308672&amp;w=2" source="BUGTRAQ" adv="1">20040420 Format String in Cherokee</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cherokee" name="cherokee_httpd">
        <vers num="0.4.16" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1947" published="2004-04-19" name="CVE-2004-1947" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The AVXSCANONLINE.AvxScanOnlineCtrl.1 ActiveX control in BitDefender Scan Online allows remote attackers to (1) obtain sensitive information such as system drives and contents or (2) use the RequestFile method to download and execute arbitrary code via an object codebase that uses bitdefender.cab.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/15911" source="XF" patch="1" adv="1">bitdefender-avxscanonline-code-execution(15911)</ref>
      <ref url="http://www.securityfocus.com/bid/10175" source="BID" patch="1" adv="1">10175</ref>
      <ref url="http://secunia.com/advisories/11427" source="SECUNIA" adv="1">11427</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108248367901616&amp;w=2" source="BUGTRAQ" adv="1">20040420 Re: BitDefender Scan Online(ActiveX) - Remote File Download &amp; Execute &amp; Private Information Disclosure</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108240639427412&amp;w=2" source="BUGTRAQ" adv="1">20040419 BitDefender Scan Online(ActiveX) - Remote File Download &amp; Execute &amp; Private Information Disclosure</ref>
      <ref url="http://www.securityfocus.com/bid/10174" source="BID">10174</ref>
      <ref url="http://www.osvdb.org/5549" source="OSVDB">5549</ref>
      <ref url="http://securitytracker.com/id?1009862" source="SECTRACK">1009862</ref>
    </refs>
    <vuln_soft>
      <prod vendor="softwin" name="bitdefender">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1948" published="2004-04-20" name="CVE-2004-1948" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">NcFTP client 3.1.6 and 3.1.7, when the username and password are included in an FTP URL that is provided on the command line, allows local users to obtain sensitive information via "ps aux," which displays the URL in the process list.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/15919" source="XF" adv="1">ncftp-info-disclosure(15919)</ref>
      <ref url="http://www.securityfocus.com/bid/10182" source="BID" adv="1">10182</ref>
      <ref url="http://secunia.com/advisories/11438" source="SECUNIA" adv="1">11438</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108247943201685&amp;w=2" source="BUGTRAQ" adv="1">20040419 NcFTP - password leaking</ref>
      <ref url="http://www.osvdb.org/5595" source="OSVDB">5595</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ncftp_software" name="ncftp">
        <vers num="3.0.0" />
        <vers num="3.0.1" />
        <vers num="3.0.2" />
        <vers num="3.0.3" />
        <vers num="3.0.4" />
        <vers num="3.1.0" />
        <vers num="3.1.1" />
        <vers num="3.1.2" />
        <vers num="3.1.3" />
        <vers num="3.1.4" />
        <vers num="3.1.5" />
        <vers num="3.1.6" />
        <vers num="3.1.7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-1949" published="2004-12-31" name="CVE-2004-1949" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in PostNuke 7.2.6 and earlier allows remote attackers to execute arbitrary SQL via (1) the sif parameter to index.php in the Comments module or (2) timezoneoffset parameter to changeinfo.php in the Your_Account module.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/10146" source="BID" patch="1">10146</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15875" source="XF">postnuke-changeinfo-sql-injection(15875)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15869" source="XF">postnuke-indexphp-sql-injection(15869)</ref>
      <ref url="http://www.osvdb.org/5369" source="OSVDB">5369</ref>
      <ref url="http://www.osvdb.org/5368" source="OSVDB">5368</ref>
      <ref url="http://securitytracker.com/id?1009801" source="SECTRACK">1009801</ref>
      <ref url="http://secunia.com/advisories/11386" source="SECUNIA">11386</ref>
      <ref url="http://news.postnuke.com/Article2580.html" source="CONFIRM" adv="1">http://news.postnuke.com/Article2580.html</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108256503718978&amp;w=2" source="BUGTRAQ" adv="1">20040420 [PNSA 2004-2] PostNuke Security Advisory PNSA 2004-2</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2004-April/020154.html" source="FULLDISC">20040414 [SCAN Associates Sdn Bhd Security Advisory] Postnuke v 0.726 and below SQL injection</ref>
    </refs>
    <vuln_soft>
      <prod vendor="postnuke_software_foundation" name="postnuke">
        <vers num="0.726" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1950" published="2004-04-19" name="CVE-2004-1950" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">phpBB 2.0.8a and earlier trusts the IP address that is in the X-Forwarded-For in the HTTP header, which allows remote attackers to spoof IP addresses.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <access />
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/15909" source="XF" patch="1" adv="1">phbb-common-ip-spoofing(15909)</ref>
      <ref url="http://www.securityfocus.com/bid/10170" source="BID" patch="1" adv="1">10170</ref>
      <ref url="http://secunia.com/advisories/11434" source="SECUNIA" patch="1" adv="1">11434</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108241122908409&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20040419 Re: phpBB 2.0.8a and lower - IP spoofing vulnerability</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108239864203144&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20040419 phpBB 2.0.8a and lower - IP spoofing vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="phpbb_group" name="phpbb">
        <vers num="2.0.0" />
        <vers num="2.0.1" />
        <vers num="2.0.2" />
        <vers num="2.0.3" />
        <vers num="2.0.4" />
        <vers num="2.0.5" />
        <vers num="2.0.6" />
        <vers num="2.0.6c" />
        <vers num="2.0.6d" />
        <vers num="2.0.7" />
        <vers num="2.0.7a" />
        <vers num="2.0.8" />
        <vers num="2.0.8a" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1951" published="2004-12-31" name="CVE-2004-1951" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">xine 1.x alpha, 1.x beta, and 1.0rc through 1.0rc3a, and xine-ui 0.9.21 to 0.9.23 allows remote attackers to overwrite arbitrary files via the (1) audio.sun_audio_device or (2) dxr3.devicename options in an MRL link.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/10193" source="BID" patch="1">10193</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200404-20.xml" source="GENTOO" patch="1">GLSA-200404-20</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15939" source="XF">xine-mrl-file-overwrite(15939)</ref>
      <ref url="http://www.xinehq.de/index.php/security/XSA-2004-2" source="CONFIRM" adv="1">http://www.xinehq.de/index.php/security/XSA-2004-2</ref>
      <ref url="http://www.xinehq.de/index.php/security/XSA-2004-1" source="CONFIRM" adv="1">http://www.xinehq.de/index.php/security/XSA-2004-1</ref>
      <ref url="http://www.slackware.com/security/viewer.php?l=slackware-security&amp;y=2004&amp;m=slackware-security.372791" source="SLACKWARE">SSA:2004-111</ref>
      <ref url="http://secunia.com/advisories/11433" source="SECUNIA">11433</ref>
      <ref url="http://www.osvdb.org/5739" source="OSVDB">5739</ref>
      <ref url="http://www.osvdb.org/5594" source="OSVDB">5594</ref>
    </refs>
    <vuln_soft>
      <prod vendor="xine" name="xine">
        <vers num="0.9.13" />
        <vers num="0.9.8" />
        <vers num="1_beta1" />
        <vers num="1_beta10" />
        <vers num="1_beta11" />
        <vers num="1_beta12" />
        <vers num="1_beta2" />
        <vers num="1_beta3" />
        <vers num="1_beta4" />
        <vers num="1_beta5" />
        <vers num="1_beta6" />
        <vers num="1_beta7" />
        <vers num="1_beta8" />
        <vers num="1_beta9" />
        <vers num="1_rc0a" />
        <vers num="1_rc1" />
        <vers num="1_rc2" />
        <vers num="1_rc3" />
        <vers num="1_rc3a" />
        <vers num="1_rc3b" />
      </prod>
      <prod vendor="xine" name="xine-lib">
        <vers num="1_rc2" />
        <vers num="1_rc3a" />
        <vers num="1_rc3b" />
        <vers num="1_rc3c" />
      </prod>
      <prod vendor="xine" name="xine-ui">
        <vers num="0.9.21" />
        <vers num="0.9.22" />
        <vers num="0.9.23" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-1952" published="2004-04-23" name="CVE-2004-1952" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in Advanced Guestbook 2.2 allows remote attackers to execute arbitrary SQL commands and gain privileges via the password.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/15892" source="XF" patch="1" adv="1">advancedguestbook-sql-injection(15892)</ref>
      <ref url="http://www.securityfocus.com/bid/10209" source="BID" patch="1" adv="1">10209</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108258046402890&amp;w=2" source="BUGTRAQ" adv="1">20040421 Advanced Guestbook 2.2 -- SQL Injection Exploit</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2005-02/0138.html" source="BUGTRAQ" adv="1">20050212 Re: Advanced Guestbook 2.2 -- SQL Injection Exploit</ref>
    </refs>
    <vuln_soft>
      <prod vendor="advanced_guestbook" name="advanced_guestbook">
        <vers num="2.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1953" published="2004-12-31" name="CVE-2004-1953" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">phProfession 2.5 allows remote attackers to gain sensitive information via a direct HTTP request to upload.php, which reveals the path in a PHP error message.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/15930" source="XF">phprofession-upload-path-disclosure(15930)</ref>
      <ref url="http://www.waraxe.us/index.php?modname=sa&amp;id=21" source="MISC">http://www.waraxe.us/index.php?modname=sa&amp;id=21</ref>
      <ref url="http://www.securityfocus.com/bid/10190" source="BID">10190</ref>
      <ref url="http://www.osvdb.org/5623" source="OSVDB">5623</ref>
      <ref url="http://secunia.com/advisories/11465" source="SECUNIA">11465</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108258931430060&amp;w=2" source="BUGTRAQ">20040421 [waraxe-2004-SA#021 - Multiple vulnerabilities in phprofession 2.5 module for PostNuke]</ref>
    </refs>
    <vuln_soft>
      <prod vendor="phprofession" name="phprofession">
        <vers num="2.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1954" published="2004-04-21" name="CVE-2004-1954" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in modules.php in phProfession 2.5 allows remote attackers to inject arbitrary web script or HTML via the jcode parameter.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/15931" source="XF">phprofession-jcode-xss(15931)</ref>
      <ref url="http://www.waraxe.us/index.php?modname=sa&amp;id=21" source="MISC" adv="1">http://www.waraxe.us/index.php?modname=sa&amp;id=21</ref>
      <ref url="http://www.securityfocus.com/bid/10190" source="BID" adv="1">10190</ref>
      <ref url="http://www.osvdb.org/5624" source="OSVDB" adv="1">5624</ref>
      <ref url="http://secunia.com/advisories/11465" source="SECUNIA" adv="1">11465</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108258931430060&amp;w=2" source="BUGTRAQ" adv="1">20040421 [waraxe-2004-SA#021 - Multiple vulnerabilities in phprofession 2.5 module for PostNuke]</ref>
    </refs>
    <vuln_soft>
      <prod vendor="phprofession" name="phprofession">
        <vers num="2.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-1955" published="2004-12-31" name="CVE-2004-1955" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in modules.php in phProfession 2.5 allows remote attackers to execute arbitrary SQL code via the offset parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/15932" source="XF">phprofession-offset-sql-injection(15932)</ref>
      <ref url="http://www.waraxe.us/index.php?modname=sa&amp;id=21" source="MISC">http://www.waraxe.us/index.php?modname=sa&amp;id=21</ref>
      <ref url="http://www.securityfocus.com/bid/10190" source="BID">10190</ref>
      <ref url="http://www.osvdb.org/5625" source="OSVDB">5625</ref>
      <ref url="http://secunia.com/advisories/11465" source="SECUNIA">11465</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108258931430060&amp;w=2" source="BUGTRAQ">20040421 [waraxe-2004-SA#021 - Multiple vulnerabilities in phprofession 2.5 module for PostNuke]</ref>
    </refs>
    <vuln_soft>
      <prod vendor="phprofession" name="phprofession">
        <vers num="2.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1956" published="2004-04-21" name="CVE-2004-1956" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">PostNuke 0.7.2.6 allows remote attackers to gain information via a direct HTTP request to files in the (1) includes/blocks directory, (2) pnadodb directory, (3) NS-NewUser module, (4) NS-Your_Account, (5) NS-LostPassword module, or (6) NS-User module which reveals the path to the web server in a PHP error message.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/15933" source="XF" adv="1">postnuke-scripts-modules-path-disclosure(15933)</ref>
      <ref url="http://www.waraxe.us/index.php?modname=sa&amp;id=22" source="MISC" adv="1">http://www.waraxe.us/index.php?modname=sa&amp;id=22</ref>
      <ref url="http://www.securityfocus.com/bid/10191" source="BID" adv="1">10191</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108258902000472&amp;w=2" source="BUGTRAQ" adv="1">20040421 [waraxe-2004-SA#022 - Multiple vulnerabilities in PostNuke 0.726 Phoenix - part 2]</ref>
    </refs>
    <vuln_soft>
      <prod vendor="postnuke_software_foundation" name="postnuke">
        <vers num="0.726" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2004-1957" published="2004-04-21" name="CVE-2004-1957" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:P/A:N)" CVSS_score="2.6" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="4.9" CVSS_base_score="2.6">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in PostNuke 0.726 allows remote attackers to inject arbitrary web script or HTML via the (1) lid and query parameters to the Downloads module, (2) query parameter to the Web_links module, or (3) hlpfile parameter to openwindow.php.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/15934" source="XF" adv="1">postnuke-openwindow-xss(15934)</ref>
      <ref url="http://www.waraxe.us/index.php?modname=sa&amp;id=22" source="MISC" adv="1">http://www.waraxe.us/index.php?modname=sa&amp;id=22</ref>
      <ref url="http://www.securityfocus.com/bid/10191" source="BID" adv="1">10191</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108258902000472&amp;w=2" source="BUGTRAQ" adv="1">20040421 [waraxe-2004-SA#022 - Multiple vulnerabilities in PostNuke 0.726 Phoenix - part 2]</ref>
    </refs>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1958" published="2004-12-31" name="CVE-2004-1958" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in manifest.ini in Unreal engine allows remote attackers to overwrite arbitrary files via .. (dot dot) sequences in a UMOD (Unreal MOD) file.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/15942" source="XF">unreal-umod-dotdot-file-overwrite(15942)</ref>
      <ref url="http://www.securityfocus.com/bid/10196" source="BID">10196</ref>
      <ref url="http://aluigi.altervista.org/adv/umod-adv.txt" source="MISC">http://aluigi.altervista.org/adv/umod-adv.txt</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108267310519459&amp;w=2" source="BUGTRAQ">20040422 Arbitrary file overwriting in Unreal engine through UMOD</ref>
    </refs>
    <vuln_soft>
      <prod vendor="epic_games" name="unreal_engine">
        <vers num="433" />
        <vers num="436" />
      </prod>
      <prod vendor="epic_games" name="unreal_tournament">
        <vers num="451b" />
      </prod>
      <prod vendor="epic_games" name="unreal_tournament_2003">
        <vers num="2199_macos" />
        <vers num="2199_win32" />
        <vers num="2225_macos" />
        <vers num="2225_win32" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1959" published="2004-04-23" name="CVE-2004-1959" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">blocker_query.php in Protector System 1.15b1 for PHP-Nuke allows remote attackers to gain sensitive information via a string in the portNum parameter, which reveals the full path in an error message.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/10206" source="BID" patch="1" adv="1">10206</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15963" source="XF" adv="1">protector-blockerquery-path-disclosure(15963)</ref>
      <ref url="http://www.waraxe.us/index.php?modname=sa&amp;id=25" source="MISC" adv="1">http://www.waraxe.us/index.php?modname=sa&amp;id=25</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108276299810121&amp;w=2" source="BUGTRAQ" adv="1">20040423 [waraxe-2004-SA#025 - Multiple vulnerabilities in Protector for PhpNuke]</ref>
    </refs>
    <vuln_soft>
      <prod vendor="protector_system" name="protector_system">
        <vers num="1.15b1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1960" published="2004-12-31" name="CVE-2004-1960" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in blocker_query.php in Protector System 1.15b1 allows remote attackers to inject arbitrary web script or HTML via the (1) target or (2) portNum parameters.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/10206" source="BID" patch="1">10206</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15965" source="XF">protector-blockerquery-xss(15965)</ref>
      <ref url="http://www.waraxe.us/index.php?modname=sa&amp;id=25" source="MISC">http://www.waraxe.us/index.php?modname=sa&amp;id=25</ref>
      <ref url="http://www.securityfocus.com/bid/10206" source="BUGTRAQ">20040423 [waraxe-2004-SA#025 - Multiple vulnerabilities in Protector for PhpNuke]</ref>
    </refs>
    <vuln_soft>
      <prod vendor="protector_system" name="protector_system">
        <vers num="1.15b1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-1961" published="2004-04-23" name="CVE-2004-1961" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">blocker.php in Protector System 1.15b1 allows remote attackers to bypass SQL injection protection and execute limited SQL commands via URL-encoded "'" characters ("%27").</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.waraxe.us/index.php?modname=sa&amp;id=25" source="MISC" patch="1" adv="1">http://www.waraxe.us/index.php?modname=sa&amp;id=25</ref>
      <ref url="http://www.securityfocus.com/bid/10206" source="BID" patch="1" adv="1">10206</ref>
      <ref url="http://www.securityfocus.com/bid/10206" source="BUGTRAQ">20040423 [waraxe-2004-SA#025 - Multiple vulnerabilities in Protector for PhpNuke]</ref>
    </refs>
    <vuln_soft>
      <prod vendor="protector_system" name="protector_system">
        <vers num="1.15b1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-1962" published="2004-12-31" name="CVE-2004-1962" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in index.php in Protector System 1.15b1 allows remote attackers to bypass SQL injection filters by using "/**/" sequences in the targeted fields.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/10206" source="BID" patch="1">10206</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15969" source="XF">protector-sql-filter-bypass(15969)</ref>
      <ref url="http://www.waraxe.us/index.php?modname=sa&amp;id=25" source="MISC">http://www.waraxe.us/index.php?modname=sa&amp;id=25</ref>
      <ref url="http://www.securityfocus.com/bid/10206" source="BUGTRAQ">20040423 [waraxe-2004-SA#025 - Multiple vulnerabilities in Protector for PhpNuke]</ref>
    </refs>
    <vuln_soft>
      <prod vendor="protector_system" name="protector_system">
        <vers num="1.15b1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1963" published="2004-04-23" name="CVE-2004-1963" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">nqt.php in Network Query Tool (NQT) 1.6 allows remote attackers to obtain sensitive information via a string in the portNum parameter, which reveals the full path in an error message.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/15957" source="XF" adv="1">nqt-nqtphp-path-disclosure(15957)</ref>
      <ref url="http://www.waraxe.us/index.php?modname=sa&amp;id=24" source="MISC" adv="1">http://www.waraxe.us/index.php?modname=sa&amp;id=24</ref>
      <ref url="http://secunia.com/advisories/11479" source="SECUNIA" adv="1">11479</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108276405108267&amp;w=2" source="BUGTRAQ" adv="1">20040423 [waraxe-2004-SA#024 - XSS and full path disclosure in Network Query Tool 1.6]</ref>
    </refs>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1964" published="2004-04-23" name="CVE-2004-1964" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in nqt.php in Network Query Tool (NQT) 1.6 allows remote attackers to inject arbitrary web script or HTML via the portNum parameter.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/15929" source="XF" adv="1">nqt-nqtphp-xss(15929)</ref>
      <ref url="http://www.waraxe.us/index.php?modname=sa&amp;id=24" source="MISC">http://www.waraxe.us/index.php?modname=sa&amp;id=24</ref>
      <ref url="http://www.securityfocus.com/bid/10205" source="BID" adv="1">10205</ref>
      <ref url="http://secunia.com/advisories/11479" source="SECUNIA" adv="1">11479</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108276405108267&amp;w=2" source="BUGTRAQ" adv="1">20040423 [waraxe-2004-SA#024 - XSS and full path disclosure in Network Query Tool 1.6]</ref>
    </refs>
    <vuln_soft>
      <prod vendor="freshmeat" name="network_query_tool">
        <vers num="1.0" />
        <vers num="1.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1965" published="2004-04-25" name="CVE-2004-1965" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in Open Bulletin Board (OpenBB) 1.0.6 and earlier allows remote attackers to inject arbitrary web script or HTML via the (1) redirect parameter to member.php, (2) to parameter to myhome.php (3) TID parameter to post.php, or (4) redirect parameter to index.php.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/15966" source="XF" adv="1">openbb-multiple-scripts-xss(15966)</ref>
      <ref url="http://www.securityfocus.com/bid/10214" source="BID" adv="1">10214</ref>
      <ref url="http://securitytracker.com/id?1009935" source="SECTRACK" adv="1">1009935</ref>
      <ref url="http://secunia.com/advisories/11481" source="SECUNIA" adv="1">11481</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108301983206107&amp;w=2" source="BUGTRAQ" adv="1">20040425 Multiple Vulnerabilities In OpenBB</ref>
    </refs>
  </entry>
  <entry type="CVE" severity="High" seq="2004-1966" published="2004-12-31" name="CVE-2004-1966" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple SQL injection vulnerabilities in Open Bulletin Board (OpenBB) 1.0.6 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) FID parameter in board.php, (2) sortorder, perpage, or id parameters in member.php, (3) forums parameter in search.php, or (4) PID or FID parameters in post.php.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/15964" source="XF">openbb-multiplescripts-sql-injection(15964)</ref>
      <ref url="http://www.securityfocus.com/bid/10214" source="BID">10214</ref>
      <ref url="http://securitytracker.com/id?1009935" source="SECTRACK">1009935</ref>
      <ref url="http://secunia.com/advisories/11481" source="SECUNIA">11481</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108301983206107&amp;w=2" source="BUGTRAQ">20040425 Multiple Vulnerabilities In OpenBB</ref>
    </refs>
    <vuln_soft>
      <prod vendor="openbb" name="openbb">
        <vers num="1.0.0_beta1" />
        <vers num="1.0.0_rc1" />
        <vers num="1.0.0_rc2" />
        <vers num="1.0.0_rc3" />
        <vers num="1.0.5" />
        <vers num="1.0.6" />
        <vers num="1.0.8" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-1967" published="2004-04-25" name="CVE-2004-1967" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Cross-site request forgery (CSRF) vulnerabilities in (1) cp_forums.php, (2) cp_usergroup.php, (3) cp_ipbans.php, (4) myhome.php, (5) post.php, or (6) moderator.php in Open Bulletin Board (OpenBB) 1.0.6 and earlier allow remote attackers to execute arbitrary code by including the code in an image tag or a link.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/15967" source="XF" adv="1">openbb-tags-execute-code(15967)</ref>
      <ref url="http://securitytracker.com/id?1009935" source="SECTRACK" adv="1">1009935</ref>
      <ref url="http://secunia.com/advisories/11481" source="SECUNIA" adv="1">11481</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108301983206107&amp;w=2" source="BUGTRAQ" adv="1">20040425 Multiple Vulnerabilities In OpenBB</ref>
    </refs>
    <vuln_soft>
      <prod vendor="openbb" name="openbb">
        <vers num="1.0.0_beta1" />
        <vers num="1.0.0_rc1" />
        <vers num="1.0.0_rc2" />
        <vers num="1.0.0_rc3" />
        <vers num="1.0.5" />
        <vers num="1.0.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1968" published="2004-04-26" name="CVE-2004-1968" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The readmsg action in myhome.php in Open Bulletin Board (OpenBB) 1.0.6 and earlier allows remote attackers to read arbitrary messages by modifying the id parameter.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/15970" source="XF" adv="1">openbb-myhomephp-obtain-information(15970)</ref>
      <ref url="http://www.securityfocus.com/bid/10217" source="BID" adv="1">10217</ref>
      <ref url="http://securitytracker.com/id?1009935" source="SECTRACK" adv="1">1009935</ref>
      <ref url="http://secunia.com/advisories/11481" source="SECUNIA" adv="1">11481</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108301983206107&amp;w=2" source="BUGTRAQ" adv="1">20040425 Multiple Vulnerabilities In OpenBB</ref>
    </refs>
    <vuln_soft>
      <prod vendor="openbb" name="openbb">
        <vers num="1.0_.0_beta1" />
        <vers num="1.0_.0_rc1" />
        <vers num="1.0_.0_rc2" />
        <vers num="1.0_.0_rc3" />
        <vers num="1.0_.5" />
        <vers num="1.0_.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-1969" published="2004-04-25" name="CVE-2004-1969" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">The avatar upload capability in Open Bulletin Board (OpenBB) 1.0.6 and earlier allows remote attackers to execute arbitrary script by uploading files that include scripting code such as Javascript.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/15971" source="XF" adv="1">openbb-file-upload(15971)</ref>
      <ref url="http://www.securityfocus.com/bid/10218" source="BID" adv="1">10218</ref>
      <ref url="http://securitytracker.com/id?1009935" source="SECTRACK" adv="1">1009935</ref>
      <ref url="http://secunia.com/advisories/11481" source="SECUNIA" adv="1">11481</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108301983206107&amp;w=2" source="BUGTRAQ" adv="1">20040425 Multiple Vulnerabilities In OpenBB</ref>
    </refs>
  </entry>
  <entry type="CVE" severity="High" seq="2004-1970" published="2004-04-26" name="CVE-2004-1970" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Samsung SmartEther SS6215S switch, and possibly other Samsung switches, allows remote attackers and local users to gain administrative access by providing the admin username followed by a password that is the maximum allowed length, then pressing the enter key after the resulting error message.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/15973" source="XF" adv="1">samsung-smartether-admin-access(15973)</ref>
      <ref url="http://www.securityfocus.com/bid/10219" source="BID" adv="1">10219</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108300407424571&amp;w=2" source="BUGTRAQ" adv="1">20040426 Samsung SmartEther SS6215S Switch</ref>
    </refs>
    <vuln_soft>
      <prod vendor="securecomputing" name="smartether_ss6215s_switch">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1971" published="2004-04-26" name="CVE-2004-1971" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">modules.php in PHP-Nuke Video Gallery Module 0.1 Beta 5 allows remote attackers to gain sensitive information via an HTTP request with an invalid (1) catid or (2) clipid parameter, which reveals the full path in an error message.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/15978" source="XF" adv="1">video-gallery-error-path-disclosure(15978)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108308660628557&amp;w=2" source="BUGTRAQ" adv="1">20040426 Multiple vulnerabilities PHP-Nuke Video Gallery Module for PHP-Nuke</ref>
    </refs>
  </entry>
  <entry type="CVE" severity="High" seq="2004-1972" published="2004-04-26" name="CVE-2004-1972" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in modules.php in PHP-Nuke Video Gallery Module 0.1 Beta 5 allows remote attackers to execute arbitrary SQL code via the (1) clipid or (2) catid parameters in a viewclip, viewcat, or voteclip action.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/15979" source="XF" adv="1">video-gallery-sql-injection(15979)</ref>
      <ref url="http://www.securityfocus.com/bid/10215" source="BID" adv="1">10215</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108308660628557&amp;w=2" source="BUGTRAQ" adv="1">20040426 Multiple vulnerabilities PHP-Nuke Video Gallery Module for PHP-Nuke</ref>
    </refs>
    <vuln_soft>
      <prod vendor="francisco_burzi" name="php-nuke">
        <vers num="7.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1973" published="2004-04-27" name="CVE-2004-1973" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">DiGi Web Server allows remote attackers to cause a denial of service (CPU consumption) via an HTTP GET request that contains a large number of / (slash) characters, which consumes resources when DiGi converts the slashes to \ (backslash) characters.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/15987" source="XF" patch="1" adv="1">digi-www-slash-dos(15987)</ref>
      <ref url="http://www.securityfocus.com/bid/10228" source="BID" patch="1" adv="1">10228</ref>
      <ref url="http://www.osvdb.org/5702" source="OSVDB" patch="1" adv="1">5702</ref>
      <ref url="http://sourceforge.net/project/shownotes.php?release_id=234261" source="CONFIRM" patch="1">http://sourceforge.net/project/shownotes.php?release_id=234261</ref>
      <ref url="http://secunia.com/advisories/11490" source="SECUNIA" patch="1" adv="1">11490</ref>
      <ref url="http://www.autistici.org/fdonato/advisory/DiGiWwwServerC1-adv.txt" source="MISC">http://www.autistici.org/fdonato/advisory/DiGiWwwServerC1-adv.txt</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108311170018203&amp;w=2" source="BUGTRAQ" adv="1">20040427 resources consumption in DiGi WWW Server</ref>
      <ref url="http://securitytracker.com/alerts/2004/Apr/1009957.html" source="SECTRACK">1009957</ref>
    </refs>
    <vuln_soft>
      <prod vendor="digi" name="www_server">
        <vers num="compieuw" edition="beta1" />
        <vers num="compieuw" edition="beta2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1974" published="2004-04-27" name="CVE-2004-1974" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">paFileDB 3.1 allows remote attackers to gain sensitive information via a direct request to (1) login.php, (2) category.php, (3) search.php, (4) main.php, (5) viewall.php, (6) download.php, (7) email.php, (8) file.php, (9) rate.php, or (10) stats.php, which reveals the path in an error message.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/15990" source="XF" adv="1">pafiledb-loginphp-path-disclosure(15990)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108311096022485&amp;w=2" source="BUGTRAQ" adv="1">20040427 Multiple vulnerabilities paFileDB</ref>
    </refs>
    <vuln_soft>
      <prod vendor="php_arena" name="pafiledb">
        <vers num="3.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1975" published="2004-04-27" name="CVE-2004-1975" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in the category module in pafiledb.php for paFileDB 3.1 allows remote attackers to inject arbitrary web script or HTML via the id parameter, a vulnerability that is closely related to CVE-2004-1551.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/15992" source="XF" adv="1">pafiledb-pafiledbphp-xss(15992)</ref>
      <ref url="http://www.securityfocus.com/bid/10229" source="BID" adv="1">10229</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109613031414184&amp;w=2" source="BUGTRAQ">20040925 New XSS vulnerabilities in paFileDB 3.1 final</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108311096022485&amp;w=2" source="BUGTRAQ" adv="1">20040427 Multiple vulnerabilities paFileDB</ref>
    </refs>
    <vuln_soft>
      <prod vendor="php_arena" name="pafiledb">
        <vers num="3.0" />
        <vers num="3.0_beta_3.1" />
        <vers num="3.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-1976" published="2004-04-28" name="CVE-2004-1976" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SMC Barricade broadband router 7008ABR and 7004VBR enable remote administration by default, which allows remote attackers to gain access by connecting to port 1900.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <config />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/15993" source="XF" patch="1" adv="1">barricade-router-gain-access(15993)</ref>
      <ref url="http://www.securityfocus.com/bid/10232" source="BID" patch="1" adv="1">10232</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2004-06/0101.html" source="BUGTRAQ" patch="1">20040605 SMC 7008ABRv2 and 7004VBRv1 updated firmware corrects port 1900 issue.</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108317929931816&amp;w=2" source="BUGTRAQ" adv="1">20040428 SMC Routers have remote administration enabled by default</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2004-April/020580.html" source="FULLDISC">20040427 SMC Routers have remote administration enabled by default</ref>
    </refs>
    <vuln_soft>
      <prod vendor="smc_networks" name="smc7004vbr">
        <vers num="1.032" />
        <vers num="1.231" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1977" published="2004-04-29" name="CVE-2004-1977" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">3com NBX IP VOIP NetSet Configuration Manager allows remote attackers to cause a denial of service (crash) via a Nessus scan in safeChecks mode.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/16015" source="XF" adv="1">3com-nbx-scan-dos(16015)</ref>
      <ref url="http://www.securityfocus.com/bid/10240" source="BID" adv="1">10240</ref>
      <ref url="http://secunia.com/advisories/11504" source="SECUNIA" adv="1">11504</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108334887408554&amp;w=2" source="BUGTRAQ" adv="1">20040429 3com NBX VOIP NetSet Denial of Service Attack</ref>
    </refs>
    <vuln_soft>
      <prod vendor="3com" name="webbngss3nbxnts">
        <vers num="4.0.17" />
        <vers num="4.1.21" />
        <vers num="4.1.4" />
        <vers num="4.2.7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1978" published="2004-04-30" name="CVE-2004-1978" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in help.php in Moodle before 1.3 allows remote attackers to inject arbitrary HTML and web script via the text parameter.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/16023" source="XF" patch="1" adv="1">moodle-help-xss(16023)</ref>
      <ref url="http://www.securityfocus.com/bid/10251" source="BID" patch="1" adv="1">10251</ref>
      <ref url="http://secunia.com/advisories/11535" source="SECUNIA" patch="1" adv="1">11535</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108335043825605&amp;w=2" source="BUGTRAQ" adv="1">20040430 Cross Site Scripting in Moodle &lt; 1.3</ref>
      <ref url="http://www.osvdb.org/5747" source="OSVDB">5747</ref>
      <ref url="http://securitytracker.com/id?1010008" source="SECTRACK">1010008</ref>
    </refs>
    <vuln_soft>
      <prod vendor="moodle" name="moodle">
        <vers num="1.1.1" />
        <vers num="1.2" />
        <vers num="1.2.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1979" published="2004-04-30" name="CVE-2004-1979" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in do_search.php in PROPS 0.6.1 allows remote attackers to inject arbitrary HTML or web script via the search_string parameter.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/16035" source="XF" patch="1" adv="1">props-dosearch-xss(16035)</ref>
      <ref url="http://www.securityfocus.com/bid/10258" source="BID" patch="1" adv="1">10258</ref>
      <ref url="http://sourceforge.net/project/shownotes.php?group_id=29581&amp;release_id=234433" source="CONFIRM" patch="1">http://sourceforge.net/project/shownotes.php?group_id=29581&amp;release_id=234433</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108342671616155&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20040501 Props 0.6.1 XSS and Remote File Viewing Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="props" name="props">
        <vers num="0.6.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1980" published="2004-04-30" name="CVE-2004-1980" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in glossary.php in PROPS 0.6.1 allows remote attackers to view arbitrary files via a .. (dot dot) in (1) module or (2) format variables.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/16036" source="XF" patch="1" adv="1">props-glossary-obtain-information(16036)</ref>
      <ref url="http://sourceforge.net/project/shownotes.php?group_id=29581&amp;release_id=234433" source="CONFIRM" patch="1">http://sourceforge.net/project/shownotes.php?group_id=29581&amp;release_id=234433</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108342671616155&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20040501 Props 0.6.1 XSS and Remote File Viewing Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="props" name="props">
        <vers num="0.6.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1981" published="2004-05-02" name="CVE-2004-1981" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The web interface for Crystal Reports allows remote attackers to cause a denial of service (disk exhaustion) by repeatedly requesting reports without retrieving the associated image files, which are not cleared from the image file folder.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108671836127360&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20040608 Vulnerability: Arbitrary File Access &amp; DoS in Crystal Reports</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108360413811017&amp;w=2" source="BUGTRAQ" adv="1">20040502 Crystal Reports Vulnerabilities</ref>
    </refs>
    <vuln_soft>
      <prod vendor="businessobjects" name="crystal_enterprise">
        <vers num="10" />
        <vers num="9" />
      </prod>
      <prod vendor="businessobjects" name="crystal_reports">
        <vers num="10" />
        <vers num="9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1982" published="2004-05-03" name="CVE-2004-1982" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Post.pl in YaBB 1 Gold SP 1.2 allows remote attackers to modify records in the board's .txt file via carriage return characters in the subject field.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/16050" source="XF" patch="1" adv="1">yabb-subject-modify-file(16050)</ref>
      <ref url="http://www.securityfocus.com/bid/10263" source="BID" patch="1" adv="1">10263</ref>
      <ref url="http://secunia.com/advisories/12609" source="SECUNIA" patch="1" adv="1">12609</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108360430703935&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20040502 Vulnerability in YaBB forum (Perl version without SQL)</ref>
      <ref url="http://www.yabbforum.com/community/YaBB.pl?board=general;action=display;num=1093133233" source="CONFIRM" adv="1">http://www.yabbforum.com/community/YaBB.pl?board=general;action=display;num=1093133233</ref>
    </refs>
    <vuln_soft>
      <prod vendor="yabb" name="yabb">
        <vers num="1_gold_-_sp_1" />
        <vers num="1_gold_-_sp_1.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2004-1983" published="2004-05-02" name="CVE-2004-1983" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">The arch_get_unmapped_area function in mmap.c in the PaX patches for Linux kernel 2.6, when Address Space Layout Randomization (ASLR) is enabled, allows local users to cause a denial of service (infinite loop) via unknown attack vectors.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
      <config />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/16037" source="XF" patch="1" adv="1">pax-aslr-enabled-dos(16037)</ref>
      <ref url="http://www.securityfocus.com/bid/10264" source="BID" patch="1" adv="1">10264</ref>
      <ref url="http://pax.grsecurity.net/" source="CONFIRM" patch="1">http://pax.grsecurity.net/</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108360001130312&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20040502 PaX Linux Kernel 2.6 Patches DoS Advisory</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200407-02.xml" source="GENTOO" adv="1">GLSA-200407-02</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108420555920369&amp;w=2" source="BUGTRAQ" adv="1">20040509 PaX DoS proof-of-concept</ref>
    </refs>
    <vuln_soft>
      <prod vendor="the_pax_team" name="pax_linux">
        <vers num="2.6.5" />
      </prod>
      <prod vendor="gentoo" name="linux">
        <vers num="1.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1984" published="2004-05-02" name="CVE-2004-1984" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Coppermine Photo Gallery 1.2.2b and 1.2.0 RC4 allows remote attackers to obtain sensitive information via a direct HTTP request to (1) phpinfo.php, (2) addpic.php, (3) config.php, (4) db_input.php, (5) displayecard.php, (6) ecard.php, (7) crop.inc.php, which reveal the full path in a PHP error message.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/16039" source="XF" adv="1">coppermine-multiple-path-disclosure(16039)</ref>
      <ref url="http://www.waraxe.us/index.php?modname=sa&amp;id=26" source="MISC" adv="1">http://www.waraxe.us/index.php?modname=sa&amp;id=26</ref>
      <ref url="http://secunia.com/advisories/11524" source="SECUNIA" adv="1">11524</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108360247732014&amp;w=2" source="BUGTRAQ" adv="1">20040502 [waraxe-2004-SA#026 - Multiple vulnerabilities in Coppermine Photo Gallery for PhpNuke]</ref>
      <ref url="http://www.osvdb.org/6500" source="OSVDB">6500</ref>
      <ref url="http://www.osvdb.org/6499" source="OSVDB">6499</ref>
      <ref url="http://www.osvdb.org/6498" source="OSVDB">6498</ref>
      <ref url="http://www.osvdb.org/6497" source="OSVDB">6497</ref>
      <ref url="http://www.osvdb.org/6496" source="OSVDB">6496</ref>
      <ref url="http://www.osvdb.org/6495" source="OSVDB">6495</ref>
      <ref url="http://www.osvdb.org/5756" source="OSVDB">5756</ref>
      <ref url="http://securitytracker.com/id?1010001" source="SECTRACK">1010001</ref>
    </refs>
    <vuln_soft>
      <prod vendor="coppermine" name="coppermine_photo_gallery">
        <vers num="1.0_rc3" />
        <vers num="1.1_.0" />
        <vers num="1.1_beta_2" />
        <vers num="1.2" />
        <vers num="1.2.1" />
        <vers num="1.2.2_b" />
      </prod>
      <prod vendor="francisco_burzi" name="php-nuke">
        <vers num="6.9" />
        <vers num="7.0" />
        <vers num="7.0_final" />
        <vers num="7.1" />
        <vers num="7.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1985" published="2004-04-30" name="CVE-2004-1985" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in menu.inc.php in Coppermine Photo Gallery 1.2.2b allows remote attackers to inject arbitrary HTML or web script via the CPG_URL parameter.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/16040" source="XF" adv="1">coppermine-menuincpho-xss(16040)</ref>
      <ref url="http://www.waraxe.us/index.php?modname=sa&amp;id=26" source="MISC">http://www.waraxe.us/index.php?modname=sa&amp;id=26</ref>
      <ref url="http://www.securityfocus.com/bid/10253" source="BID" adv="1">10253</ref>
      <ref url="http://secunia.com/advisories/11524" source="SECUNIA" adv="1">11524</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108360247732014&amp;w=2" source="BUGTRAQ" adv="1">20040502 [waraxe-2004-SA#026 - Multiple vulnerabilities in Coppermine Photo Gallery for PhpNuke]</ref>
      <ref url="http://www.osvdb.org/5757" source="OSVDB">5757</ref>
    </refs>
    <vuln_soft>
      <prod vendor="coppermine" name="coppermine_photo_gallery">
        <vers num="1.0_rc3" />
        <vers num="1.1_.0" />
        <vers num="1.1_beta_2" />
        <vers num="1.2" />
        <vers num="1.2.1" />
        <vers num="1.2.2_b" />
      </prod>
      <prod vendor="francisco_burzi" name="php-nuke">
        <vers num="6.9" />
        <vers num="7.0" />
        <vers num="7.0_final" />
        <vers num="7.1" />
        <vers num="7.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1986" published="2004-04-04" name="CVE-2004-1986" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in modules.php in Coppermine Photo Gallery 1.2.2b and 1.2.0 RC4 allows remote attackers with administrative privileges to read arbitrary files via a .. (dot dot) in the startdir parameter.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <access />
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/16042" source="XF" adv="1">coppermine-modulesphp-directory-traversal(16042)</ref>
      <ref url="http://www.waraxe.us/index.php?modname=sa&amp;id=26" source="MISC" adv="1">http://www.waraxe.us/index.php?modname=sa&amp;id=26</ref>
      <ref url="http://www.securityfocus.com/bid/10253" source="BID" adv="1">10253</ref>
      <ref url="http://secunia.com/advisories/11524" source="SECUNIA" adv="1">11524</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108360247732014&amp;w=2" source="BUGTRAQ" adv="1">20040502 [waraxe-2004-SA#026 - Multiple vulnerabilities in Coppermine Photo Gallery for PhpNuke]</ref>
      <ref url="http://www.osvdb.org/5758" source="OSVDB">5758</ref>
      <ref url="http://securitytracker.com/id?1010001" source="SECTRACK">1010001</ref>
    </refs>
    <vuln_soft>
      <prod vendor="coppermine" name="coppermine_photo_gallery">
        <vers num="1.0_rc3" />
        <vers num="1.1_.0" />
        <vers num="1.1_beta_2" />
        <vers num="1.2" />
        <vers num="1.2.1" />
        <vers num="1.2.2_b" />
      </prod>
      <prod vendor="francisco_burzi" name="php-nuke">
        <vers num="6.9" />
        <vers num="7.0" />
        <vers num="7.0_final" />
        <vers num="7.1" />
        <vers num="7.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-1987" published="2004-04-30" name="CVE-2004-1987" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">picmgmtbatch.inc.php in Coppermine Photo Gallery 1.2.2b and 1.2.0 RC4 allows remote attackers with administrative privileges to execute arbitrary commands via shell metacharacters in the (1) $CONFIG['impath'] or (2) $CONFIG['jpeg_qual'] parameters.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/16043" source="XF" adv="1">coppermine-parameters-execute-commands(16043)</ref>
      <ref url="http://www.waraxe.us/index.php?modname=sa&amp;id=26" source="MISC" adv="1">http://www.waraxe.us/index.php?modname=sa&amp;id=26</ref>
      <ref url="http://www.securityfocus.com/bid/10253" source="BID" adv="1">10253</ref>
      <ref url="http://secunia.com/advisories/11524" source="SECUNIA" adv="1">11524</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108360247732014&amp;w=2" source="BUGTRAQ" adv="1">20040502  [waraxe-2004-SA#026 - Multiple vulnerabilities in Coppermine Photo Gallery for PhpNuke]</ref>
      <ref url="http://www.osvdb.org/5759" source="OSVDB">5759</ref>
      <ref url="http://securitytracker.com/id?1010001" source="SECTRACK">1010001</ref>
    </refs>
    <vuln_soft>
      <prod vendor="coppermine" name="coppermine_photo_gallery">
        <vers num="1.0_rc3" />
        <vers num="1.1_.0" />
        <vers num="1.1_beta_2" />
        <vers num="1.2" />
        <vers num="1.2.1" />
        <vers num="1.2.2_b" />
      </prod>
      <prod vendor="francisco_burzi" name="php-nuke">
        <vers num="6.9" />
        <vers num="7.0" />
        <vers num="7.0_final" />
        <vers num="7.1" />
        <vers num="7.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-1988" published="2004-04-30" name="CVE-2004-1988" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">PHP remote file inclusion vulnerability in init.inc.php in Coppermine Photo Gallery 1.2.0 RC4 allows remote attackers to execute arbitrary PHP code by modifying the CPG_M_DIR to reference a URL on a remote web server that contains functions.inc.php.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/16041" source="XF" adv="1">coppermine-multiple-file-include(16041)</ref>
      <ref url="http://www.waraxe.us/index.php?modname=sa&amp;id=26" source="MISC" adv="1">http://www.waraxe.us/index.php?modname=sa&amp;id=26</ref>
      <ref url="http://www.securityfocus.com/bid/10253" source="BID" adv="1">10253</ref>
      <ref url="http://www.osvdb.org/5761" source="OSVDB">5761</ref>
      <ref url="http://securitytracker.com/id?1010001" source="SECTRACK">1010001</ref>
      <ref url="http://secunia.com/advisories/11524" source="SECUNIA" adv="1">11524</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108360247732014&amp;w=2" source="BUGTRAQ" adv="1">20040502 [waraxe-2004-SA#026 - Multiple vulnerabilities in Coppermine Photo Gallery for PhpNuke]</ref>
    </refs>
    <vuln_soft>
      <prod vendor="coppermine" name="coppermine_photo_gallery">
        <vers num="1.0_rc3" />
        <vers num="1.1_.0" />
        <vers num="1.1_beta_2" />
        <vers num="1.2" />
        <vers num="1.2.1" />
        <vers num="1.2.2_b" />
      </prod>
      <prod vendor="francisco_burzi" name="php-nuke">
        <vers num="6.9" />
        <vers num="7.0" />
        <vers num="7.0_final" />
        <vers num="7.1" />
        <vers num="7.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-1989" published="2004-04-30" name="CVE-2004-1989" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">PHP remote file inclusion vulnerability in theme.php in Coppermine Photo Gallery 1.2.2b allows remote attackers to execute arbitrary PHP code by modifying the THEME_DIR parameter to reference a URL on a remote web server that contains user_list_info_box.inc.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/16041" source="XF" adv="1">coppermine-multiple-file-include(16041)</ref>
      <ref url="http://www.waraxe.us/index.php?modname=sa&amp;id=26" source="MISC" adv="1">http://www.waraxe.us/index.php?modname=sa&amp;id=26</ref>
      <ref url="http://www.securityfocus.com/bid/10253" source="BID" adv="1">10253</ref>
      <ref url="http://www.osvdb.org/5912" source="OSVDB">5912</ref>
      <ref url="http://securitytracker.com/id?1010001" source="SECTRACK">1010001</ref>
      <ref url="http://secunia.com/advisories/11524" source="SECUNIA" adv="1">11524</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108360247732014&amp;w=2" source="BUGTRAQ" adv="1">20040502 [waraxe-2004-SA#026 - Multiple vulnerabilities in Coppermine Photo Gallery for PhpNuke]</ref>
    </refs>
    <vuln_soft>
      <prod vendor="coppermine" name="coppermine_photo_gallery">
        <vers num="1.0_rc3" />
        <vers num="1.1_.0" />
        <vers num="1.1_beta_2" />
        <vers num="1.2" />
        <vers num="1.2.1" />
        <vers num="1.2.2_b" />
      </prod>
      <prod vendor="francisco_burzi" name="php-nuke">
        <vers num="6.9" />
        <vers num="7.0" />
        <vers num="7.0_final" />
        <vers num="7.1" />
        <vers num="7.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1990" published="2004-03-03" name="CVE-2004-1990" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Aldo's Web Server (aweb) 1.5 allows remote attackers to gain sensitive information via an arbitrary character, which reveals the full path and the user running the aweb process, possibly due to a malformed request.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/16047" source="XF" adv="1">aweb-path-disclosure(16047)</ref>
      <ref url="http://www.securityfocus.com/bid/10262" source="BID" adv="1">10262</ref>
      <ref url="http://www.oliverkarow.de/research/AldosWebserverMultipleVulns.txt" source="MISC" adv="1">http://www.oliverkarow.de/research/AldosWebserverMultipleVulns.txt</ref>
      <ref url="http://secunia.com/advisories/11542" source="SECUNIA" adv="1">11542</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108360629031227&amp;w=2" source="BUGTRAQ" adv="1">20040503 Multible_Vulnerabilites_in_Aldos_Webserver</ref>
      <ref url="http://www.osvdb.org/5880" source="OSVDB">5880</ref>
    </refs>
    <vuln_soft>
      <prod vendor="aldo_vargas" name="aldos_web_server">
        <vers num="1.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1991" published="2004-05-03" name="CVE-2004-1991" modified="2005-10-20" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in Aldo's Web Server (aweb) 1.5 allows remote attackers to view arbitrary files via a .. (dot dot) in an HTTP GET request.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <access />
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/16048" source="XF" adv="1">aweb-dotdot-directory-traversal(16048)</ref>
      <ref url="http://www.securityfocus.com/bid/10262" source="BID" adv="1">10262</ref>
      <ref url="http://www.oliverkarow.de/research/AldosWebserverMultipleVulns.txt" source="MISC" adv="1">http://www.oliverkarow.de/research/AldosWebserverMultipleVulns.txt</ref>
      <ref url="http://secunia.com/advisories/11542" source="SECUNIA" adv="1">11542</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108360629031227&amp;w=2" source="BUGTRAQ" adv="1">20040503 Multible_Vulnerabilites_in_Aldos_Webserver</ref>
      <ref url="http://www.osvdb.org/5881" source="OSVDB">5881</ref>
    </refs>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1992" published="2004-04-20" name="CVE-2004-1992" modified="2010-04-28" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Buffer overflow in Serv-U FTP server before 5.0.0.6 allows remote attackers to cause a denial of service (crash) via a long -l parameter, which triggers an out-of-bounds read.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/15913" source="XF" patch="1" adv="1">servu-list-command-bo(15913)</ref>
      <ref url="http://secunia.com/advisories/11430" source="SECUNIA" patch="1" adv="1">11430</ref>
      <ref url="http://www.securityfocus.com/bid/10181" source="BID" adv="1">10181</ref>
      <ref url="http://www.securiteam.com/windowsntfocus/5ZP0G2KCKA.html" source="MISC" adv="1">http://www.securiteam.com/windowsntfocus/5ZP0G2KCKA.html</ref>
      <ref url="http://www.osvdb.org/5546" source="OSVDB">5546</ref>
      <ref url="http://securitytracker.com/id?1009869" source="SECTRACK">1009869</ref>
      <ref url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=108359620108234&amp;w=2" source="NTBUGTRAQ" adv="1">20040503 Serv-U LIST -l Parameter Buffer Overflow</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108360377119290&amp;w=2" source="BUGTRAQ" adv="1">20040503 Serv-U LIST -l Parameter Buffer Overflow</ref>
    </refs>
    <vuln_soft>
      <prod vendor="serv-u" name="serv-u">
        <vers num="3.0.0.16" />
        <vers num="3.0.0.17" />
        <vers num="3.1.0.0" />
        <vers num="3.1.0.1" />
        <vers num="3.1.0.3" />
        <vers num="4.0.0.4" />
        <vers num="4.1.0.0" />
        <vers num="4.1.0.3" />
        <vers num="5.0.0.0" />
        <vers prev="1" num="5.0.0.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-1993" published="2004-05-04" name="CVE-2004-1993" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">The patch to the checklogin function in omail.pl for omail webmail 0.98.5 is incomplete, which allows remote attackers to execute arbitrary commands via shell metacharacters such as "`" (backticks) in the password.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/12948" source="XF" patch="1" adv="1">omailwebmail-checklogin-code-execution(12948)</ref>
      <ref url="http://www.securityfocus.com/bid/10274" source="BID" adv="1">10274</ref>
      <ref url="http://secunia.com/advisories/9585" source="SECUNIA" adv="1">9585</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108377215015515&amp;w=2" source="BUGTRAQ" adv="1">20040504 remote root exec vulnerability in omail</ref>
    </refs>
    <vuln_soft>
      <prod vendor="omail" name="omail_webmail">
        <vers num="0.97.3" />
        <vers num="0.98.3" />
        <vers num="0.98.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1994" published="2004-05-05" name="CVE-2004-1994" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">FuseTalk 4.0 allows remote attackers to ban other users via a direct request to banning.cfm.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/16081" source="XF" adv="1">fusetalk-banning-unauth-access(16081)</ref>
      <ref url="http://www.securityfocus.com/bid/10278" source="BID" adv="1">10278</ref>
      <ref url="http://secunia.com/advisories/11555" source="SECUNIA" adv="1">11555</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108377423825478&amp;w=2" source="BUGTRAQ" adv="1">20040505 Fuse Talk Vunerabilities</ref>
      <ref url="http://www.osvdb.org/5894" source="OSVDB">5894</ref>
    </refs>
    <vuln_soft>
      <prod vendor="e-zone_media_inc." name="fusetalk">
        <vers num="2.0" />
        <vers num="3.0" />
        <vers num="4.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-1995" published="2004-12-31" name="CVE-2004-1995" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Cross-Site Request Forgery (CSRF) vulnerability in FuseTalk 2.0 allows remote attackers to create arbitrary accounts via a link to adduser.cfm.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/16080" source="XF" adv="1">fusetalk-get-add-users(16080)</ref>
      <ref url="http://www.securityfocus.com/bid/10276" source="BID" adv="1">10276</ref>
      <ref url="http://secunia.com/advisories/11555" source="SECUNIA" adv="1">11555</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108377423825478&amp;w=2" source="BUGTRAQ" adv="1">20040505 Fuse Talk Vunerabilities</ref>
      <ref url="http://www.osvdb.org/5895" source="OSVDB">5895</ref>
      <ref url="http://securitytracker.com/id?1010080" source="SECTRACK">1010080</ref>
    </refs>
    <vuln_soft>
      <prod vendor="e-zone_media_inc." name="fusetalk">
        <vers num="2.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1996" published="2004-05-05" name="CVE-2004-1996" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in Simple Machines Forum (SMF) 1.0 allows remote attackers to inject arbitrary web script via the size tag.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/16067" source="XF" adv="1">smf-size-html-injection(16067)</ref>
      <ref url="http://www.securityfocus.com/bid/10281" source="BID" adv="1">10281</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108377364615934&amp;w=2" source="BUGTRAQ" adv="1">20040505 SMF SIZE Tag Script Injection Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="simple_machines" name="smf">
        <vers num="1.0_beta4.1" />
        <vers num="1.0_beta4p" />
        <vers num="1.0_beta5p" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1997" published="2004-05-05" name="CVE-2004-1997" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Kolab stores OpenLDAP passwords in plaintext in the slapd.conf file, which may be installed world-readable, which allows local users to gain privileges.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <config />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/16068" source="XF" patch="1" adv="1">kolab-root-password-plaintext(16068)</ref>
      <ref url="http://www.securityfocus.com/bid/10277" source="BID" patch="1" adv="1">10277</ref>
      <ref url="http://secunia.com/advisories/11560" source="SECUNIA" patch="1" adv="1">11560</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108377525924422&amp;w=2" source="OPENPKG" patch="1" adv="1">OpenPKG-SA-2004.019</ref>
      <ref url="http://www.kolab.org/pipermail/kolab-users/2004-April/000215.html" source="MLIST" adv="1">[kolab-users] 20040420 Possible Kolab LDAP configuration information disclosure</ref>
      <ref url="http://www.osvdb.org/5898" source="OSVDB">5898</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2004:052" source="MANDRAKE">MDKSA-2004:052</ref>
      <ref url="http://www.erfrakon.de/projects/kolab/download/kolab-server-1.0/src/Changelog" source="CONFIRM">http://www.erfrakon.de/projects/kolab/download/kolab-server-1.0/src/Changelog</ref>
    </refs>
    <vuln_soft>
      <prod vendor="kolab" name="kolab_groupware_server">
        <vers num="1.0" />
        <vers num="1.0.1" />
        <vers num="1.0.3" />
        <vers num="1.0.5" />
        <vers num="1.0.6" />
        <vers num="1.0.7" />
        <vers num="1.0.8" />
      </prod>
      <prod vendor="openpkg" name="openpkg">
        <vers num="2.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1998" published="2004-05-05" name="CVE-2004-1998" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The Downloads module in Php-Nuke 6.x through 7.2 allows remote attackers to gain sensitive information via an invalid show parameter to modules.php, which reveals the full path in a PHP error message.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.waraxe.us/index.php?modname=sa&amp;id=27" source="MISC" adv="1">http://www.waraxe.us/index.php?modname=sa&amp;id=27</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108378804809891&amp;w=2" source="BUGTRAQ" adv="1">20040505 [waraxe-2004-SA#027 - Once again - critical vulnerabilities in PhpNuke 6.x - 7.2]</ref>
    </refs>
    <vuln_soft>
      <prod vendor="francisco_burzi" name="php-nuke">
        <vers num="6.0" />
        <vers num="6.5" />
        <vers num="6.6" />
        <vers num="6.7" />
        <vers num="6.8" />
        <vers num="6.9" />
        <vers num="7.0" />
        <vers num="7.1" />
        <vers num="7.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-1999" published="2004-05-05" name="CVE-2004-1999" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in the Downloads module in Php-Nuke 6.x through 7.2 allows remote attackers to inject arbitrary HTML and web script via the (1) ttitle or (2) sid parameters to modules.php.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/16073" source="XF" adv="1">phpnuke-ttitle-sid-xss(16073)</ref>
      <ref url="http://www.waraxe.us/index.php?modname=sa&amp;id=27" source="MISC" adv="1">http://www.waraxe.us/index.php?modname=sa&amp;id=27</ref>
      <ref url="http://secunia.com/advisories/11553" source="SECUNIA" adv="1">11553</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108378804809891&amp;w=2" source="BUGTRAQ" adv="1">20040505 [waraxe-2004-SA#027 - Once again - critical vulnerabilities in PhpNuke 6.x - 7.2]</ref>
    </refs>
    <vuln_soft>
      <prod vendor="francisco_burzi" name="php-nuke">
        <vers num="6.0" />
        <vers num="6.5" />
        <vers num="6.6" />
        <vers num="6.7" />
        <vers num="6.8" />
        <vers num="6.9" />
        <vers num="7.0" />
        <vers num="7.1" />
        <vers num="7.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-2000" published="2004-05-05" name="CVE-2004-2000" modified="2009-09-19" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in the Downloads module in Php-Nuke 6.x through 7.2 allows remote attackers to execute arbitrary SQL via the (1) orderby or (2) sid parameters to modules.php.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/16074" source="XF" adv="1">phpnuke-orderby-sid-sql-injection(16074)</ref>
      <ref url="http://www.waraxe.us/index.php?modname=sa&amp;id=27" source="MISC">http://www.waraxe.us/index.php?modname=sa&amp;id=27</ref>
      <ref url="http://www.securityfocus.com/bid/10282" source="BID" adv="1">10282</ref>
      <ref url="http://secunia.com/advisories/11553" source="SECUNIA" adv="1">11553</ref>
      <ref url="http://osvdb.org/52223" source="OSVDB">52223</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108378804809891&amp;w=2" source="BUGTRAQ" adv="1">20040505 [waraxe-2004-SA#027 - Once again - critical vulnerabilities in PhpNuke 6.x - 7.2]</ref>
      <ref url="http://www.securityfocus.com/bid/27932" source="BID">27932</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/488452/100/0/threaded" source="BUGTRAQ">20080221 PHP-Nuke Module Downloads SQL Injection(sid)</ref>
    </refs>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-2001" published="2004-05-05" name="CVE-2004-2001" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">ifconfig "-arp" in SGI IRIX 6.5 through 6.5.22m does not properly disable ARP requests from being sent or received.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/10289" source="BID" patch="1" adv="1">10289</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/20040502-01-P.asc" source="SGI" patch="1" adv="1">20040502-01-P</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sgi" name="irix">
        <vers num="6.5" />
        <vers num="6.5.1" />
        <vers num="6.5.10" />
        <vers num="6.5.11" />
        <vers num="6.5.12" />
        <vers num="6.5.13" />
        <vers num="6.5.14" />
        <vers num="6.5.15" />
        <vers num="6.5.16" />
        <vers num="6.5.17f" />
        <vers num="6.5.17m" />
        <vers num="6.5.18f" />
        <vers num="6.5.18m" />
        <vers num="6.5.19f" />
        <vers num="6.5.19m" />
        <vers num="6.5.2" />
        <vers num="6.5.20f" />
        <vers num="6.5.20m" />
        <vers num="6.5.21f" />
        <vers num="6.5.21m" />
        <vers num="6.5.22m" />
        <vers num="6.5.3" />
        <vers num="6.5.4" />
        <vers num="6.5.5" />
        <vers num="6.5.6" />
        <vers num="6.5.7" />
        <vers num="6.5.8" />
        <vers num="6.5.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-2002" published="2004-05-05" name="CVE-2004-2002" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Unknown vulnerability in SGI IRIX 6.5 through 6.5.22m allows remote attackers to cause a denial of service via a certain UDP packet.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/20040502-01-P.asc" source="SGI" patch="1">20040502-01-P</ref>
      <ref url="http://www.securityfocus.com/bid/10287" source="BID" adv="1">10287</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/16158" source="XF">irix-udp-dos(16158)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sgi" name="irix">
        <vers num="6.5" />
        <vers num="6.5.1" />
        <vers num="6.5.10" />
        <vers num="6.5.10f" />
        <vers num="6.5.10m" />
        <vers num="6.5.11" />
        <vers num="6.5.11f" />
        <vers num="6.5.11m" />
        <vers num="6.5.12" />
        <vers num="6.5.12f" />
        <vers num="6.5.12m" />
        <vers num="6.5.13" />
        <vers num="6.5.13f" />
        <vers num="6.5.13m" />
        <vers num="6.5.14" />
        <vers num="6.5.14f" />
        <vers num="6.5.14m" />
        <vers num="6.5.15" />
        <vers num="6.5.15f" />
        <vers num="6.5.15m" />
        <vers num="6.5.16" />
        <vers num="6.5.16f" />
        <vers num="6.5.16m" />
        <vers num="6.5.17" />
        <vers num="6.5.17f" />
        <vers num="6.5.17m" />
        <vers num="6.5.18" />
        <vers num="6.5.18f" />
        <vers num="6.5.18m" />
        <vers num="6.5.19" />
        <vers num="6.5.19f" />
        <vers num="6.5.19m" />
        <vers num="6.5.2" />
        <vers num="6.5.20" />
        <vers num="6.5.20f" />
        <vers num="6.5.20m" />
        <vers num="6.5.21" />
        <vers num="6.5.21f" />
        <vers num="6.5.21m" />
        <vers num="6.5.22" />
        <vers num="6.5.22m" />
        <vers num="6.5.2f" />
        <vers num="6.5.2m" />
        <vers num="6.5.3" />
        <vers num="6.5.3f" />
        <vers num="6.5.3m" />
        <vers num="6.5.4" />
        <vers num="6.5.4f" />
        <vers num="6.5.4m" />
        <vers num="6.5.5" />
        <vers num="6.5.5f" />
        <vers num="6.5.5m" />
        <vers num="6.5.6" />
        <vers num="6.5.6f" />
        <vers num="6.5.6m" />
        <vers num="6.5.7" />
        <vers num="6.5.7f" />
        <vers num="6.5.7m" />
        <vers num="6.5.8" />
        <vers num="6.5.8f" />
        <vers num="6.5.8m" />
        <vers num="6.5.9" />
        <vers num="6.5.9f" />
        <vers num="6.5.9m" />
        <vers num="6.5_20" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-2003" published="2004-05-06" name="CVE-2004-2003" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in the ssl_prcert function in the SSLway filter (sslway.c) for DeleGate 8.9.2 and earlier allows remote attackers to execute arbitrary code via a certificate with a long (1) subject or (2) issuer name field.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/10295" source="BID" patch="1" adv="1">10295</ref>
      <ref url="http://secunia.com/advisories/11569" source="SECUNIA" patch="1" adv="1">11569</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108386181021070&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20040506 [0xbadc0ded #03] DeleGate (SSL-filter) &lt;= 8.9.2</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/16078" source="XF">delegate-sslway-bo(16078)</ref>
      <ref url="http://www.osvdb.org/5945" source="OSVDB">5945</ref>
    </refs>
    <vuln_soft>
      <prod vendor="delegate" name="delegate">
        <vers num="7.7.0" />
        <vers num="7.7.1" />
        <vers num="7.8.0" />
        <vers num="7.8.1" />
        <vers num="7.8.2" />
        <vers num="7.9.11" />
        <vers num="8.3.3" />
        <vers num="8.3.4" />
        <vers num="8.4.0" />
        <vers num="8.5.0" />
        <vers num="8.9" />
        <vers num="8.9.1" />
        <vers num="8.9.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-2004" published="2004-05-06" name="CVE-2004-2004" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">The Live CD in SUSE LINUX 9.1 Personal edition is configured without a password for root, which allows remote attackers to gain privileges via SSH.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <config />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/10297" source="BID" patch="1" adv="1">10297</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/16084" source="XF">livecd-ssh-gain-access(16084)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="suse" name="suse_linux">
        <vers num="9.1" edition="" />
        <vers num="9.1" edition=":personal" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-2005" published="2004-05-06" name="CVE-2004-2005" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_score="5.1" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="4.9" CVSS_base_score="5.1">
    <desc>
      <descript source="cve">Buffer overflow in Eudora for Windows 5.2.1, 6.0.3, and 6.1 allows remote attackers to execute arbitrary code via an e-mail with (1) a link to a long URL to the C drive or (2) a long attachment name.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/10298" source="BID" patch="1" adv="1">10298</ref>
      <ref url="http://secunia.com/advisories/11568" source="SECUNIA" patch="1" adv="1">11568</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/16086" source="XF" adv="1">eudora-long-url-bo(16086)</ref>
      <ref url="http://www.eudora.com/download/eudora/windows/6.1.1/RelNotes.txt" source="CONFIRM">http://www.eudora.com/download/eudora/windows/6.1.1/RelNotes.txt</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108395487628044&amp;w=2" source="BUGTRAQ" adv="1">20040507 Eudora file URL buffer overflow</ref>
    </refs>
    <vuln_soft>
      <prod vendor="qualcomm" name="eudora">
        <vers num="5.2.1" />
        <vers num="6.0" />
        <vers num="6.0.1" />
        <vers num="6.0.3" />
        <vers num="6.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-2006" published="2004-05-07" name="CVE-2004-2006" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Trend Micro OfficeScan 3.0 - 6.0 has default permissions of "Everyone Full Control" on the installation directory and registry keys, which allows local users to disable virus protection.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <config />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/16092" source="XF" patch="1" adv="1">officescan-configuration-modify(16092)</ref>
      <ref url="http://secunia.com/advisories/11576" source="SECUNIA" patch="1" adv="1">11576</ref>
      <ref url="http://www.securityfocus.com/bid/10300" source="BID" adv="1">10300</ref>
      <ref url="http://www.osvdb.org/5990" source="OSVDB">5990</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108395366909344&amp;w=2" source="BUGTRAQ" adv="1">20040507 Security issue with Trend OfficeScan Corporate Edition</ref>
    </refs>
    <vuln_soft>
      <prod vendor="trend_micro" name="officescan">
        <vers num="3.0" edition="" />
        <vers num="3.0" edition=":corporate" />
        <vers num="corporate_3.11" />
        <vers num="corporate_3.13" />
        <vers num="corporate_3.5" />
        <vers num="corporate_3.54" />
        <vers num="corporate_5.02" />
        <vers num="corporate_5.58" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-2007" published="2004-05-08" name="CVE-2004-2007" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in modules.php in NukeJokes 1.7 and 2 Beta allows remote attackers to inject arbitrary HTML or web script via the (1) cat parameter in a CatView function or (2) jokeid parameter in a JokeView function.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/16096" source="XF" adv="1">nukejokes-modules-xss(16096)</ref>
      <ref url="http://www.securityfocus.com/bid/10306" source="BID" adv="1">10306</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108404714232579&amp;w=2" source="BUGTRAQ" adv="1">20040508 [waraxe-2004-SA#028 - Multiple vulnerabilities in NukeJokes module for PhpNuke]</ref>
    </refs>
    <vuln_soft>
      <prod vendor="adam_webb" name="nukejokes">
        <vers num="1.7" />
        <vers num="2.0_beta" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-2008" published="2004-05-08" name="CVE-2004-2008" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">SQL injection vulnerability in modules.php in NukeJokes 1.7 and 2 Beta allows remote attackers to execute arbitrary SQL via the jokeid parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/16099" source="XF" adv="1">nukejokes-sql-injection(16099)</ref>
      <ref url="http://www.waraxe.us/index.php?modname=sa&amp;id=28" source="MISC" adv="1">http://www.waraxe.us/index.php?modname=sa&amp;id=28</ref>
      <ref url="http://www.securityfocus.com/bid/10306" source="BID" adv="1">10306</ref>
      <ref url="http://secunia.com/advisories/11579" source="SECUNIA" adv="1">11579</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108404714232579&amp;w=2" source="BUGTRAQ" adv="1">20040508 [waraxe-2004-SA#028 - Multiple vulnerabilities in NukeJokes module for PhpNuke]</ref>
    </refs>
    <vuln_soft>
      <prod vendor="adam_webb" name="nukejokes">
        <vers num="1.7" />
        <vers num="2.0_beta" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-2009" published="2004-05-08" name="CVE-2004-2009" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">NukeJokes 1.7 and 2 Beta allows remote attackers to obtain the full path of the server via (1) a direct call to mainfunctions.php, (2) an invalid jokeid parameter in a JokeView function or (3) an invalid cat parameter in a CatView function, which reveals the path in a PHP error message.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/16094" source="XF" adv="1">nukejokes-multiple-path-disclosure(16094)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108404714232579&amp;w=2" source="BUGTRAQ" adv="1">20040508 [waraxe-2004-SA#028 - Multiple vulnerabilities in NukeJokes module for PhpNuke]</ref>
    </refs>
  </entry>
  <entry type="CVE" severity="High" seq="2004-2010" published="2004-12-31" name="CVE-2004-2010" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">PHP remote file inclusion vulnerability in index.php in phpShop 0.7.1 and earlier allows remote attackers to execute arbitrary PHP code by modifying the base_dir parameter to reference a URL on a remote web server that contains phpshop.cfg.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/11587" source="SECUNIA" patch="1">11587</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/16107" source="XF">phpshop-basedir-file-include(16107)</ref>
      <ref url="http://www.securityfocus.com/bid/10313" source="BID">10313</ref>
      <ref url="http://www.fribble.net/advisories/phpshop_29-04-04.txt" source="MISC">http://www.fribble.net/advisories/phpshop_29-04-04.txt</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108420702317870&amp;w=2" source="BUGTRAQ" adv="1">20040509 Arbitrary code inclusion in phpShop</ref>
    </refs>
  </entry>
  <entry type="CVE" severity="Low" seq="2004-2011" published="2004-12-31" name="CVE-2004-2011" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:N/A:P)" CVSS_score="2.6" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="4.9" CVSS_base_score="2.6">
    <desc>
      <descript source="cve">msxml3.dll in Internet Explorer 6.0.2600.0 allows remote attackers to cause a denial of service (crash) via a single &amp; (ampersand) in a &lt;Ref href> link, which triggers a parsing error, possibly due to missing portions of the URI.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/16112" source="XF">msxml3-ampersand-dos(16112)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108422549617947&amp;w=2" source="BUGTRAQ">20040510 msxml3.dll Parsing Error Crashes Internet Explorer Remotely Upon Refresh</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="ie">
        <vers num="6.0.2600" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-2012" published="2004-12-31" name="CVE-2004-2012" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">The systrace_exit function in the systrace utility for NetBSD-current and 2.0 before April 16, 2004, and certain FreeBSD ports, does not verify the owner of the /dec/systrace connection before setting euid to 0, which allows local users to gain root privileges.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/16110" source="XF">systrace-gain-privileges(16110)</ref>
      <ref url="http://www.securityfocus.com/bid/10320" source="BID">10320</ref>
      <ref url="http://secunia.com/advisories/11585" source="SECUNIA">11585</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108432258920570&amp;w=2" source="BUGTRAQ">20040510 Advisory 04/2004: Net(Free)BSD Systrace local root vulnerabilitiy</ref>
    </refs>
    <vuln_soft>
      <prod vendor="niels" name="provos_systrace">
        <vers num="1.1" />
        <vers num="1.2" />
        <vers num="1.3" />
        <vers num="1.4" />
        <vers num="1.5" />
      </prod>
      <prod vendor="vladimir_kotal" name="systrace_port_for_freebsd">
        <vers num="2004-03-09" />
        <vers num="2004-06-02" />
      </prod>
      <prod vendor="netbsd" name="netbsd">
        <vers num="2.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-2013" published="2004-12-31" name="CVE-2004-2013" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Integer overflow in the SCTP_SOCKOPT_DEBUG_NAME SCTP socket option in socket.c in the Linux kernel 2.4.25 and earlier allows local users to execute arbitrary code via an optlen value of -1, which causes kmalloc to allocate 0 bytes of memory.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108456230815842&amp;w=2" source="TRUSTIX" patch="1">2004-0029</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2004-05/0091.html" source="BUGTRAQ" patch="1">20040511 Linux Kernel sctp_setsockopt() Integer Overflow</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/16117" source="XF">linux-sctpsetsockopt-integer-bo(16117)</ref>
      <ref url="http://www.securityfocus.com/bid/10326" source="BID">10326</ref>
    </refs>
    <vuln_soft>
      <prod vendor="linux" name="linux_kernel">
        <vers num="2.0" />
        <vers num="2.0.1" />
        <vers num="2.0.10" />
        <vers num="2.0.11" />
        <vers num="2.0.12" />
        <vers num="2.0.13" />
        <vers num="2.0.14" />
        <vers num="2.0.15" />
        <vers num="2.0.16" />
        <vers num="2.0.17" />
        <vers num="2.0.18" />
        <vers num="2.0.19" />
        <vers num="2.0.2" />
        <vers num="2.0.20" />
        <vers num="2.0.21" />
        <vers num="2.0.22" />
        <vers num="2.0.23" />
        <vers num="2.0.24" />
        <vers num="2.0.25" />
        <vers num="2.0.26" />
        <vers num="2.0.27" />
        <vers num="2.0.28" />
        <vers num="2.0.29" />
        <vers num="2.0.3" />
        <vers num="2.0.30" />
        <vers num="2.0.31" />
        <vers num="2.0.32" />
        <vers num="2.0.33" />
        <vers num="2.0.34" />
        <vers num="2.0.35" />
        <vers num="2.0.36" />
        <vers num="2.0.37" />
        <vers num="2.0.38" />
        <vers num="2.0.39" />
        <vers num="2.0.4" />
        <vers num="2.0.5" />
        <vers num="2.0.6" />
        <vers num="2.0.7" />
        <vers num="2.0.8" />
        <vers num="2.0.9" />
        <vers num="2.1" />
        <vers num="2.1.89" />
        <vers num="2.2.0" />
        <vers num="2.2.1" />
        <vers num="2.2.10" />
        <vers num="2.2.11" />
        <vers num="2.2.12" />
        <vers num="2.2.13" />
        <vers num="2.2.14" />
        <vers num="2.2.15" edition="pre16" />
        <vers num="2.2.15_pre20" />
        <vers num="2.2.16" edition="pre6" />
        <vers num="2.2.17" />
        <vers num="2.2.18" />
        <vers num="2.2.19" />
        <vers num="2.2.2" />
        <vers num="2.2.20" />
        <vers num="2.2.21" />
        <vers num="2.2.22" />
        <vers num="2.2.23" />
        <vers num="2.2.24" />
        <vers num="2.2.25" />
        <vers num="2.2.3" />
        <vers num="2.2.4" />
        <vers num="2.2.5" />
        <vers num="2.2.6" />
        <vers num="2.2.7" />
        <vers num="2.2.8" />
        <vers num="2.2.9" />
        <vers num="2.3.0" />
        <vers num="2.3.99" edition="pre1" />
        <vers num="2.3.99" edition="pre2" />
        <vers num="2.3.99" edition="pre3" />
        <vers num="2.3.99" edition="pre4" />
        <vers num="2.3.99" edition="pre5" />
        <vers num="2.3.99" edition="pre6" />
        <vers num="2.3.99" edition="pre7" />
        <vers num="2.4.0" edition="test1" />
        <vers num="2.4.0" edition="test10" />
        <vers num="2.4.0" edition="test11" />
        <vers num="2.4.0" edition="test12" />
        <vers num="2.4.0" edition="test2" />
        <vers num="2.4.0" edition="test3" />
        <vers num="2.4.0" edition="test4" />
        <vers num="2.4.0" edition="test5" />
        <vers num="2.4.0" edition="test6" />
        <vers num="2.4.0" edition="test7" />
        <vers num="2.4.0" edition="test8" />
        <vers num="2.4.0" edition="test9" />
        <vers num="2.4.1" />
        <vers num="2.4.10" />
        <vers num="2.4.11" />
        <vers num="2.4.12" />
        <vers num="2.4.13" />
        <vers num="2.4.14" />
        <vers num="2.4.15" />
        <vers num="2.4.16" />
        <vers num="2.4.17" />
        <vers num="2.4.18" edition="" />
        <vers num="2.4.18" edition=":x86" />
        <vers num="2.4.18" edition="pre1" />
        <vers num="2.4.18" edition="pre2" />
        <vers num="2.4.18" edition="pre3" />
        <vers num="2.4.18" edition="pre4" />
        <vers num="2.4.18" edition="pre5" />
        <vers num="2.4.18" edition="pre6" />
        <vers num="2.4.18" edition="pre7" />
        <vers num="2.4.18" edition="pre8" />
        <vers num="2.4.19" edition="pre1" />
        <vers num="2.4.19" edition="pre2" />
        <vers num="2.4.19" edition="pre3" />
        <vers num="2.4.19" edition="pre4" />
        <vers num="2.4.19" edition="pre5" />
        <vers num="2.4.19" edition="pre6" />
        <vers num="2.4.2" />
        <vers num="2.4.20" />
        <vers num="2.4.21" edition="pre1" />
        <vers num="2.4.21" edition="pre4" />
        <vers num="2.4.21" edition="pre7" />
        <vers num="2.4.22" />
        <vers num="2.4.23" edition="pre9" />
        <vers num="2.4.23_ow2" />
        <vers num="2.4.24" />
        <vers num="2.4.24_ow1" />
        <vers num="2.4.25" />
        <vers num="2.4.3" />
        <vers num="2.4.4" />
        <vers num="2.4.5" />
        <vers num="2.4.6" />
        <vers num="2.4.7" />
        <vers num="2.4.8" />
        <vers num="2.4.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2004-2014" published="2004-12-31" name="CVE-2004-2014" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:H/Au:N/C:N/I:P/A:P)" CVSS_score="2.6" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="1.9" CVSS_base_score="2.6">
    <desc>
      <descript source="cve">Wget 1.9 and 1.9.1 allows local users to overwrite arbitrary files via a symlink attack on the name of the file being downloaded.</descript>
    </desc>
    <loss_types>
      <avail />
      <int />
    </loss_types>
    <vuln_types>
      <race />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/16167" source="XF">wget-lock-race-condition(16167)</ref>
      <ref url="http://www.securityfocus.com/bid/10361" source="BID">10361</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9830" source="OVAL">oval:org.mitre.oval:def:9830</ref>
      <ref url="http://marc.theaimsgroup.com/?l=wget&amp;m=108483270227139&amp;w=2" source="MLIST">[wget] 20040517 Re: Wget race condition vulnerability (fwd)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=wget&amp;m=108482747906833&amp;w=2" source="MLIST">[wget] 20040517 Wget race condition vulnerability (fwd)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108481268725276&amp;w=2" source="BUGTRAQ">20040516 Wget race condition vulnerability</ref>
      <ref url="http://www.ubuntulinux.org/support/documentation/usn/usn-145-1" source="UBUNTU">USN-145-1</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-771.html" source="REDHAT">RHSA-2005:771</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:204" source="MANDRIVA">MDKSA-2005:204</ref>
      <ref url="http://secunia.com/advisories/17399" source="SECUNIA">17399</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gnu" name="wget">
        <vers num="1.5.3" />
        <vers num="1.6" />
        <vers num="1.7" />
        <vers num="1.7.1" />
        <vers num="1.8" />
        <vers num="1.8.1" />
        <vers num="1.8.2" />
        <vers num="1.9" />
        <vers num="1.9.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-2015" published="2004-12-31" name="CVE-2004-2015" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in WebCT Campus Edition allows remote attackers to inject arbitrary HTML or web script via (1) iframe, (2) img, or (3) object tags.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/16156" source="XF">webct-iframe-img-tags-xss(16156)</ref>
      <ref url="http://www.securityfocus.com/bid/10357" source="BID">10357</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108481256731404&amp;w=2" source="BUGTRAQ">20040517 WebCT: Cross Site Scripting Vulnerability</ref>
      <ref url="http://archives.neohapsis.com/archives/fulldisclosure/2004-05/0851.html" source="FULLDISC">20040516 WebCT: Cross Site Scripting Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="webct" name="webct">
        <vers num="campus_4.0" />
        <vers num="campus_4.0_sp3_hotfix_40833" />
        <vers num="campus_4.1" />
        <vers num="campus_4.1.1.5" />
        <vers num="campus_4.1_sp2_hotfix_40832" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-2016" published="2004-12-31" name="CVE-2004-2016" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Stack-based buffer overflow in the HTTP server in NetChat 7.3 and earlier allows remote attackers to execute arbitrary code via a long GET request.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/10353" source="BID" patch="1">10353</ref>
      <ref url="http://secunia.com/advisories/11637" source="SECUNIA" patch="1">11637</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/16165" source="XF">netchat-sprintf-bo(16165)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108481422130354&amp;w=2" source="BUGTRAQ">20040517 NetChat HTTP Server Stack Overflow</ref>
    </refs>
    <vuln_soft>
      <prod vendor="netchat" name="subnet_chat_application">
        <vers num="7.0" />
        <vers num="7.1" />
        <vers num="7.2" />
        <vers num="7.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-2017" published="2004-12-31" name="CVE-2004-2017" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in Turbo Traffic Trader C (TTT-C) 1.0 allow remote attackers to inject arbitrary HTML or web script, as demonstrated via (1) the link parameter to ttt-out, (2) the X-Forwarded-For header in a GET request to ttt-in, (3) the Referer header in a GET request to ttt-in, or the (4) site name or (5) site URL fields in the main control panel.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/16164" source="XF">turbotraffictraderc-multiple-xss(16164)</ref>
      <ref url="http://www.securityfocus.com/bid/10359" source="BID">10359</ref>
      <ref url="http://secunia.com/advisories/11623" source="SECUNIA">11623</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108481571131866&amp;w=2" source="BUGTRAQ">20040517 Multiple TTT-C XSS vulnerabilities</ref>
      <ref url="http://www.osvdb.org/6344" source="OSVDB">6344</ref>
      <ref url="http://www.osvdb.org/6343" source="OSVDB">6343</ref>
      <ref url="http://www.osvdb.org/6342" source="OSVDB">6342</ref>
      <ref url="http://www.osvdb.org/6341" source="OSVDB">6341</ref>
      <ref url="http://www.osvdb.org/6340" source="OSVDB">6340</ref>
      <ref url="http://www.osvdb.org/6339" source="OSVDB">6339</ref>
    </refs>
    <vuln_soft>
      <prod vendor="turbotraffictrader" name="turbotraffictrader_c">
        <vers num="1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-2018" published="2004-12-31" name="CVE-2004-2018" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">PHP remote file inclusion vulnerability in index.php in Php-Nuke 6.x through 7.3 allows remote attackers to execute arbitrary PHP code by modifying the modpath parameter to reference a URL on a remote web server that contains the code.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/16218" source="XF">phpnuke-modpath-file-include(16218)</ref>
      <ref url="http://www.waraxe.us/index.php?modname=sa&amp;id=29" source="MISC">http://www.waraxe.us/index.php?modname=sa&amp;id=29</ref>
      <ref url="http://www.securityfocus.com/bid/10365" source="BID">10365</ref>
      <ref url="http://www.osvdb.org/6222" source="OSVDB">6222</ref>
      <ref url="http://secunia.com/advisories/11625" source="SECUNIA">11625</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108482888621896&amp;w=2" source="BUGTRAQ">20040517 [waraxe-2004-SA#029 - Possible remote file inclusion in PhpNuke 6.x - 7.3]</ref>
      <ref url="http://archives.neohapsis.com/archives/fulldisclosure/2004-05/0870.html" source="FULLDISC">20040517 [waraxe-2004-SA#029 - Possible remote file inclusion in PhpNuke 6.x - 7.3]</ref>
    </refs>
    <vuln_soft>
      <prod vendor="francisco_burzi" name="php-nuke">
        <vers num="6.0" />
        <vers num="6.5" />
        <vers num="6.5_beta1" />
        <vers num="6.5_final" />
        <vers num="6.5_rc1" />
        <vers num="6.5_rc2" />
        <vers num="6.5_rc3" />
        <vers num="6.6" />
        <vers num="6.7" />
        <vers num="6.9" />
        <vers num="7.0" />
        <vers num="7.0_final" />
        <vers num="7.1" />
        <vers num="7.2" />
        <vers num="7.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-2019" published="2004-12-31" name="CVE-2004-2019" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The WebLinks module in Php-Nuke 6.x through 7.3 allows remote attackers to obtain sensitive information via an invalid show parameter, which displays the full path in a PHP error message.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/16170" source="XF">phpnuke-show-weblink-path-disclosure(16170)</ref>
      <ref url="http://www.waraxe.us/index.php?modname=sa&amp;id=29" source="MISC">http://www.waraxe.us/index.php?modname=sa&amp;id=29</ref>
      <ref url="http://www.securityfocus.com/bid/10367" source="BID">10367</ref>
      <ref url="http://secunia.com/advisories/11625" source="SECUNIA">11625</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108482957715299&amp;w=2" source="BUGTRAQ">20040517 [waraxe-2004-SA#030 - Multiple vulnerabilities in PhpNuke 6.x - 7.3]</ref>
    </refs>
    <vuln_soft>
      <prod vendor="francisco_burzi" name="php-nuke">
        <vers num="6.0" />
        <vers num="6.5" />
        <vers num="6.5_beta1" />
        <vers num="6.5_final" />
        <vers num="6.5_rc1" />
        <vers num="6.5_rc2" />
        <vers num="6.5_rc3" />
        <vers num="6.6" />
        <vers num="6.7" />
        <vers num="6.9" />
        <vers num="7.0" />
        <vers num="7.0_final" />
        <vers num="7.1" />
        <vers num="7.2" />
        <vers num="7.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-2020" published="2004-12-31" name="CVE-2004-2020" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in Php-Nuke 6.x through 7.3 allow remote attackers inject arbitrary HTML or web script into the (1) optionbox parameter in the News module, (2) date parameter in the Statistics module, (3) year, month, and month_1 parameters in the Stories_Archive module, (4) mode, order, and thold parameters in the Surveys module, or (5) a SQL statement to index.php, as processed by mainfile.php.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/16172" source="XF">phpnuke-multi-xss(16172)</ref>
      <ref url="http://www.waraxe.us/index.php?modname=sa&amp;id=29" source="MISC">http://www.waraxe.us/index.php?modname=sa&amp;id=29</ref>
      <ref url="http://www.securityfocus.com/bid/10367" source="BID">10367</ref>
      <ref url="http://secunia.com/advisories/11625" source="SECUNIA">11625</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108482957715299&amp;w=2" source="BUGTRAQ">20040517 [waraxe-2004-SA#030 - Multiple vulnerabilities in PhpNuke 6.x - 7.3]</ref>
      <ref url="http://www.osvdb.org/6226" source="OSVDB">6226</ref>
      <ref url="http://www.osvdb.org/6225" source="OSVDB">6225</ref>
    </refs>
    <vuln_soft>
      <prod vendor="francisco_burzi" name="php-nuke">
        <vers num="6.0" />
        <vers num="6.5" />
        <vers num="6.5_beta1" />
        <vers num="6.5_final" />
        <vers num="6.5_rc1" />
        <vers num="6.5_rc2" />
        <vers num="6.5_rc3" />
        <vers num="6.6" />
        <vers num="6.7" />
        <vers num="6.9" />
        <vers num="7.0" />
        <vers num="7.0_final" />
        <vers num="7.1" />
        <vers num="7.2" />
        <vers num="7.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-2021" published="2004-12-31" name="CVE-2004-2021" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in file_manager.php in osCommerce 2.2 allows remote attackers to view arbitrary files via a .. (dot dot) in the filename argument.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/16174" source="XF">oscommerce-dotdot-directory-traversal(16174)</ref>
      <ref url="http://www.securityfocus.com/bid/10364" source="BID">10364</ref>
      <ref url="http://secunia.com/advisories/11624" source="SECUNIA">11624</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108482902101519&amp;w=2" source="BUGTRAQ">20040517 oscommerce 2.2 file_manager.php file browsing</ref>
      <ref url="http://www.osvdb.org/6308" source="OSVDB">6308</ref>
      <ref url="http://www.excluded.org/advisories/advisory13.txt" source="MISC">http://www.excluded.org/advisories/advisory13.txt</ref>
      <ref url="http://securitytracker.com/id?1010176" source="SECTRACK">1010176</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2005-03/0378.html" source="BUGTRAQ">20050322 osCommerce File Manager Directory Traversal Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oscommerce" name="oscommerce">
        <vers num="2.1" />
        <vers num="2.2_cvs" />
        <vers num="2.2_ms1" />
        <vers num="2.2_ms2" />
        <vers num="2.2_ms3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2004-2022" published="2004-12-31" name="CVE-2004-2022" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">ActivePerl 5.8.x and others, and Larry Wall's Perl 5.6.1 and others, when running on Windows systems, allows attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long argument to the system command, which leads to a stack-based buffer overflow.  NOTE: it is unclear whether this bug is in Perl or the OS API that is used by Perl.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/16169" source="XF">perl-system-bo(16169)</ref>
      <ref url="http://www.securityfocus.com/bid/10375" source="BID">10375</ref>
      <ref url="http://www.perlmonks.org/index.pl?node_id=354145" source="MISC">http://www.perlmonks.org/index.pl?node_id=354145</ref>
      <ref url="http://www.oliverkarow.de/research/ActivePerlSystemBOF.txt" source="MISC">http://www.oliverkarow.de/research/ActivePerlSystemBOF.txt</ref>
      <ref url="http://marc.theaimsgroup.com/?l=full-disclosure&amp;m=108489112131099&amp;w=2" source="FULLDISC">20040518 Re: Buffer Overflow in ActivePerl ?</ref>
      <ref url="http://marc.theaimsgroup.com/?l=full-disclosure&amp;m=108483058514596&amp;w=2" source="FULLDISC">20040517 RE: Buffer Overflow in ActivePerl ?</ref>
      <ref url="http://marc.theaimsgroup.com/?l=full-disclosure&amp;m=108482796105922&amp;w=2" source="FULLDISC">20040517 Buffer Overflow in ActivePerl ?</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108489894009025&amp;w=2" source="BUGTRAQ">20040518 RE: [Full-Disclosure] Re: Buffer Overflow in ActivePerl ?</ref>
      <ref url="http://archives.neohapsis.com/archives/fulldisclosure/2004-05/0905.html" source="FULLDISC">20040518 Re[2]: [Full-Disclosure] Buffer Overflow in ActivePerl ?</ref>
    </refs>
    <vuln_soft>
      <prod vendor="activestate" name="activeperl">
        <vers num="5.6.1" />
        <vers num="5.6.1.630" />
        <vers num="5.6.2" />
        <vers num="5.6.3" />
        <vers num="5.7.1" />
        <vers num="5.7.2" />
        <vers num="5.7.3" />
        <vers num="5.8" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-2023" published="2004-12-31" name="CVE-2004-2023" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in login.php in Zen Cart 1.1.2d, 1.1.4 before patch 1, and possibly other versions allows remote attackers to execute arbitrary SQL via the (1) admin_name or (2) admin_pass parameters.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/16176" source="XF" patch="1">zencart-login-sql-injection(16176)</ref>
      <ref url="http://www.zen-cart.com/modules/mydownloads/viewcat.php?cid=31&amp;orderby=dateD" source="CONFIRM" patch="1">http://www.zen-cart.com/modules/mydownloads/viewcat.php?cid=31&amp;orderby=dateD</ref>
      <ref url="http://secunia.com/advisories/11649" source="SECUNIA" patch="1">11649</ref>
      <ref url="http://www.zen-cart.com/modules/ipb/index.php?showtopic=4835" source="CONFIRM" adv="1">http://www.zen-cart.com/modules/ipb/index.php?showtopic=4835</ref>
      <ref url="http://www.securityfocus.com/bid/10378" source="BID">10378</ref>
      <ref url="http://securitytracker.com/id?1010172" source="SECTRACK">1010172</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108489697219781&amp;w=2" source="BUGTRAQ">20040518 Zen Cart login.php SQL Injection Vulnerability</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/434237/30/4950/threaded" source="BUGTRAQ">20060517 Re: Zen Cart login.php SQL Injection Vulnerability</ref>
      <ref url="http://www.packetstormsecurity.org/0405-advisories/zencart112d.txt" source="MISC">http://www.packetstormsecurity.org/0405-advisories/zencart112d.txt</ref>
      <ref url="http://www.osvdb.org/6298" source="OSVDB">6298</ref>
    </refs>
    <vuln_soft>
      <prod vendor="zen_cart" name="zen_cart">
        <vers num="1.1.2d" />
        <vers num="1.1.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-2024" published="2004-12-31" name="CVE-2004-2024" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">The distribution of Zen Cart 1.1.4 before patch 2 includes certain debugging code in the Admin password retrieval functionality, which allows attackers to gain administrative privileges via password_forgotten.php.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.zen-cart.com/modules/mydownloads/viewcat.php?cid=31&amp;orderby=dateD" source="CONFIRM" patch="1">http://www.zen-cart.com/modules/mydownloads/viewcat.php?cid=31&amp;orderby=dateD</ref>
      <ref url="http://www.zen-cart.com/modules/ipb/index.php?showtopic=4873" source="CONFIRM" adv="1">http://www.zen-cart.com/modules/ipb/index.php?showtopic=4873</ref>
    </refs>
    <vuln_soft>
      <prod vendor="zen_cart" name="zen_cart">
        <vers num="1.1.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-2025" published="2004-12-31" name="CVE-2004-2025" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in application_top.php for Zen Cart 1.1.3 before patch 2 may allow remote attackers to execute arbitrary SQL commands via the products_id parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.zen-cart.com/modules/mydownloads/viewcat.php?cid=31&amp;orderby=dateD" source="CONFIRM" patch="1">http://www.zen-cart.com/modules/mydownloads/viewcat.php?cid=31&amp;orderby=dateD</ref>
      <ref url="http://www.zen-cart.com/modules/ipb/index.php?showtopic=3731" source="CONFIRM">http://www.zen-cart.com/modules/ipb/index.php?showtopic=3731</ref>
    </refs>
    <vuln_soft>
      <prod vendor="zen_cart" name="zen_cart">
        <vers num="1.1.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-2026" published="2004-12-31" name="CVE-2004-2026" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Format string vulnerability in the logmsg function in svc.c for Pound 1.5 and earlier allows remote attackers to execute arbitrary code via format string specifiers in syslog messages.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/10267" source="BID" patch="1">10267</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200405-08.xml" source="GENTOO" patch="1">GLSA-200405-08</ref>
      <ref url="http://secunia.com/advisories/11528" source="SECUNIA" patch="1">11528</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/16033" source="XF">pound-logmsg-format-string(16033)</ref>
      <ref url="http://www.osvdb.org/5746" source="OSVDB">5746</ref>
      <ref url="http://www.apsis.ch/pound/pound_list/archive/2003/2003-12/1070234315000#1070234315000" source="CONFIRM">http://www.apsis.ch/pound/pound_list/archive/2003/2003-12/1070234315000#1070234315000</ref>
      <ref url="http://securitytracker.com/id?1010034" source="SECTRACK">1010034</ref>
      <ref url="http://archives.neohapsis.com/archives/fulldisclosure/2004-05/0343.html" source="FULLDISC">20040507 Pound &lt;=1.5 Remote Exploit (Format string bug)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apsis" name="pound">
        <vers num="1.0" />
        <vers num="1.1" />
        <vers num="1.2" />
        <vers num="1.3" />
        <vers num="1.4" />
        <vers num="1.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-2027" published="2004-05-10" name="CVE-2004-2027" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Buffer overflow in Icecast 2.0.0 and earlier allows remote attackers to cause a denial of service (crash) via a long Basic Authorization header that triggers an out-of-bounds read.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/10311" source="BID" patch="1" adv="1">10311</ref>
      <ref url="http://secunia.com/advisories/11578" source="SECUNIA" patch="1" adv="1">11578</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/16103" source="XF" adv="1">icecast-auth-request-bo(16103)</ref>
      <ref url="http://www.osvdb.org/6075" source="OSVDB" adv="1">6075</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200405-10.xml" source="GENTOO" adv="1">GLSA-200405-10</ref>
      <ref url="http://archives.neohapsis.com/archives/fulldisclosure/2004-05/0378.html" source="FULLDISC" adv="1">20040509 Icecast 2.0.0 preauth overflow</ref>
    </refs>
    <vuln_soft>
      <prod vendor="icecast" name="icecast">
        <vers num="1.3.0" />
        <vers num="1.3.10" />
        <vers num="1.3.10.1" />
        <vers num="1.3.11" />
        <vers num="1.3.12" />
        <vers num="1.3.5" />
        <vers num="1.3.5.1" />
        <vers num="1.3.7" />
        <vers num="1.3.7.1" />
        <vers num="1.3.8" />
        <vers num="1.3.9" />
        <vers num="1.3.9.1" />
        <vers num="1.3.9.2" />
        <vers num="2.0.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-2028" published="2004-05-21" name="CVE-2004-2028" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in stats.php in e107 allows remote attackers to inject arbitrary web script or HTML via the referer parameter to log.php.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/16231" source="XF" adv="1">e107-log-xss(16231)</ref>
      <ref url="http://www.securityfocus.com/bid/10395" source="BID" adv="1">10395</ref>
      <ref url="http://secunia.com/advisories/11693" source="SECUNIA" adv="1">11693</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108515632622796&amp;w=2" source="BUGTRAQ" adv="1">20040521 e107 web portal Referers HTTP Injection</ref>
      <ref url="http://www.osvdb.org/6345" source="OSVDB">6345</ref>
    </refs>
    <vuln_soft>
      <prod vendor="e107" name="e107">
        <vers num="0.545" />
        <vers num="0.554" />
        <vers num="0.555_beta" />
        <vers num="0.603" />
        <vers num="0.6_10" />
        <vers num="0.6_11" />
        <vers num="0.6_12" />
        <vers num="0.6_13" />
        <vers num="0.6_14" />
        <vers num="0.6_15" />
        <vers num="0.6_15a" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-2029" published="2004-05-22" name="CVE-2004-2029" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The Util_DecodeHTTPAuth function in BNBT BitTorrent Tracker Beta 7.5 Release 2 and earlier allows remote attackers to cause a denial of service (crash) via a Basic Authorization HTTP request with a "A==" value.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/16228" source="XF" patch="1" adv="1">bittorrent-http-get-dos(16228)</ref>
      <ref url="http://www.securityfocus.com/bid/10399" source="BID" patch="1" adv="1">10399</ref>
      <ref url="http://secunia.com/advisories/11684" source="SECUNIA" patch="1" adv="1">11684</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108526361421535&amp;w=2" source="BUGTRAQ" adv="1">20040522 BNBT BitTorrent Tracker Denial Of Service</ref>
      <ref url="http://fux0r.phathookups.com/advisory/sp-x12-advisory.txt" source="MISC" adv="1">http://fux0r.phathookups.com/advisory/sp-x12-advisory.txt</ref>
      <ref url="http://www.osvdb.org/6336" source="OSVDB">6336</ref>
      <ref url="http://securitytracker.com/id?1010254" source="SECTRACK">1010254</ref>
    </refs>
    <vuln_soft>
      <prod vendor="trevor_hogan" name="bnbt">
        <vers num="7.5_beta_release2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-2030" published="2004-05-22" name="CVE-2004-2030" modified="2009-04-03" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in index.jsp for Liferay before 2.2.0 release 10/1/2004 allow remote attackers to inject arbitrary web script or HTML, as demonstrated using the message subject.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/16232" source="XF" patch="1" adv="1">liferay-message-xss(16232)</ref>
      <ref url="http://www.securityfocus.com/bid/10402" source="BID" patch="1" adv="1">10402</ref>
      <ref url="http://www.osvdb.org/6346" source="OSVDB" patch="1" adv="1">6346</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110141194202856&amp;w=2" source="BUGTRAQ" patch="1">20041125 Re: Liferay Cross Site Scripting Flaw</ref>
      <ref url="http://sourceforge.net/project/shownotes.php?release_id=252060" source="CONFIRM">http://sourceforge.net/project/shownotes.php?release_id=252060</ref>
      <ref url="http://securitytracker.com/id?1010259" source="SECTRACK">1010259</ref>
      <ref url="http://secunia.com/advisories/11692" source="SECUNIA" adv="1">11692</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108526683823840&amp;w=2" source="BUGTRAQ" adv="1">20040522 Liferay Cross Site Scripting Flaw</ref>
    </refs>
    <vuln_soft>
      <prod vendor="liferay" name="liferay_enterprise_portal">
        <vers num="2.1.0" />
        <vers prev="1" num="2.1.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-2031" published="2004-05-21" name="CVE-2004-2031" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in user.php in e107 allows remote attackers to inject arbitrary web script or HTML via the (1) URL, (2) MSN, or (3) AIM fields.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108541119526279&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20040522 e107 web portal user.php XSS (Cross Site Scripting)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/16241" source="XF" adv="1">e107-user-xss(16241)</ref>
      <ref url="http://www.securityfocus.com/bid/10405" source="BID" adv="1">10405</ref>
      <ref url="http://www.osvdb.org/6410" source="OSVDB" adv="1">6410</ref>
      <ref url="http://secunia.com/advisories/11696" source="SECUNIA" adv="1">11696</ref>
    </refs>
    <vuln_soft>
      <prod vendor="e107" name="e107">
        <vers num="0.545" />
        <vers num="0.554" />
        <vers num="0.555_beta" />
        <vers num="0.603" />
        <vers num="0.610" />
        <vers num="0.611" />
        <vers num="0.612" />
        <vers num="0.613" />
        <vers num="0.614" />
        <vers num="0.615" />
        <vers num="0.615a" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-2032" published="2004-05-24" name="CVE-2004-2032" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Netgear RP114 allows remote attackers to bypass the keyword based URL filtering by requesting a long URL, as demonstrated using a large number of %20 (hex-encoded space) sequences.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <access />
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/16238" source="XF" adv="1">netgearrp114-long-url-filter-bypass(16238)</ref>
      <ref url="http://www.securityfocus.com/bid/10404" source="BID" adv="1">10404</ref>
      <ref url="http://www.osvdb.org/6411" source="OSVDB" adv="1">6411</ref>
      <ref url="http://secunia.com/advisories/11698" source="SECUNIA" adv="1">11698</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108541203427391&amp;w=2" source="BUGTRAQ" adv="1">20040524 Netgear RP114 URL filter fails if URL is too long</ref>
    </refs>
    <vuln_soft>
      <prod vendor="netgear" name="rp114">
        <vers num="3.26" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-2033" published="2004-05-26" name="CVE-2004-2033" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Orenosv 0.5.9f allows remote attackers to cause a denial of service (crash) via a long HTTP GET request.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/16250" source="XF" patch="1" adv="1">orenosv-http-get-dos(16250)</ref>
      <ref url="http://www.securityfocus.com/bid/10420" source="BID" patch="1" adv="1">10420</ref>
      <ref url="http://www.osvdb.org/6419" source="OSVDB" patch="1" adv="1">6419</ref>
      <ref url="http://secunia.com/advisories/11706" source="SECUNIA" patch="1" adv="1">11706</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108559623703422&amp;w=2" source="BUGTRAQ" adv="1">20040526 Orenosv HTTP/FTP Server Denial Of Service</ref>
      <ref url="http://hp.vector.co.jp/authors/VA027031/orenosv/index_en.html" source="CONFIRM" adv="1">http://hp.vector.co.jp/authors/VA027031/orenosv/index_en.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="orenosv" name="orenosv_http_ftp_server">
        <vers num="0.5.9c" />
        <vers num="0.5.9e" />
        <vers num="0.5.9f" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-2034" published="2004-01-29" name="CVE-2004-2034" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in the (1) WTHoster and (2) WebDriver modules in WildTangent Web Driver 4.0 allows remote attackers to execute arbitrary code via a long filename.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/16266" source="XF" patch="1" adv="1">wildtangent-wthoster-webdriver-bo(16266)</ref>
      <ref url="http://www.securityfocus.com/bid/10421" source="BID" patch="1" adv="1">10421</ref>
      <ref url="http://www.osvdb.org/6445" source="OSVDB" patch="1" adv="1">6445</ref>
      <ref url="http://www.ngssoftware.com/advisories/wildtangent.txt" source="MISC" patch="1" adv="1">http://www.ngssoftware.com/advisories/wildtangent.txt</ref>
      <ref url="http://secunia.com/advisories/11727" source="SECUNIA" patch="1" adv="1">11727</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108569235217149&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20040527 WildTangent Web Driver Long FileName Stack Overflow</ref>
    </refs>
    <vuln_soft>
      <prod vendor="wildtangent" name="webdriver">
        <vers num="4.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-2035" published="2004-05-26" name="CVE-2004-2035" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">MiniShare 1.3.2 allows remote attackers to cause a denial of service (crash) via a malformed HTTP GET or HEAD request without the proper number of trailing CRLF sequences.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/10417" source="BID" patch="1" adv="1">10417</ref>
      <ref url="http://www.osvdb.org/6432" source="OSVDB" patch="1" adv="1">6432</ref>
      <ref url="http://sourceforge.net/project/shownotes.php?release_id=241158" source="CONFIRM" patch="1" adv="1">http://sourceforge.net/project/shownotes.php?release_id=241158</ref>
      <ref url="http://secunia.com/advisories/11715" source="SECUNIA" patch="1" adv="1">11715</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/16260" source="XF">minishare-get-head-dos(16260)</ref>
      <ref url="http://www.autistici.org/fdonato/advisory/MiniShare1.3.2-adv.txt" source="MISC" adv="1">http://www.autistici.org/fdonato/advisory/MiniShare1.3.2-adv.txt</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108563992129877&amp;w=2" source="BUGTRAQ" adv="1">20040527 DoS in MiniShare 1.3.2</ref>
    </refs>
    <vuln_soft>
      <prod vendor="minishare" name="minimal_http_server">
        <vers num="1.3.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-2036" published="2004-05-28" name="CVE-2004-2036" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in the art_print function in print.inc.php in unknown versions of jPortal before 2.3.1 allows remote attackers to inject arbitrary SQL commands via the id parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/16272" source="XF" adv="1">jportal-printincphp-sql-injection(16272)</ref>
      <ref url="http://www.securityfocus.com/bid/10430" source="BID" adv="1">10430</ref>
      <ref url="http://www.securiteam.com/unixfocus/5HP020KD5K.html" source="MISC" adv="1">http://www.securiteam.com/unixfocus/5HP020KD5K.html</ref>
      <ref url="http://www.osvdb.org/6503" source="OSVDB" adv="1">6503</ref>
      <ref url="http://securitytracker.com/id?1010327" source="SECTRACK">1010327</ref>
      <ref url="http://secunia.com/advisories/11737" source="SECUNIA" adv="1">11737</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108577011129476&amp;w=2" source="BUGTRAQ" adv="1">20040528 JPortal SQL Injects</ref>
    </refs>
    <vuln_soft>
      <prod vendor="jportal" name="jportal_web_portal">
        <vers num="2.2.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-2037" published="2004-03-24" name="CVE-2004-2037" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in Mollensoft Lightweight FTP Server 3.6 allows remote authenticated users to cause a denial of service (crash) and possibly execute arbitrary code via a long CWD command, as demonstrated in one example by using the "cd" command in an interactive FTP client.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/16237" source="XF" patch="1" adv="1">mollensoft-cwd-command-bo(16237)</ref>
      <ref url="http://www.osvdb.org/6412" source="OSVDB" patch="1" adv="1">6412</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/16303" source="XF" adv="1">mollensoft-cd-bo(16303)</ref>
      <ref url="http://www.securityfocus.com/bid/10429" source="BID" adv="1">10429</ref>
      <ref url="http://www.securityfocus.com/bid/10409" source="BID" adv="1">10409</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108611230015042&amp;w=2" source="BUGTRAQ" adv="1">20040601 Mollensoft Lightweight FTP Server CWD Buffer Overflow</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108577846011604&amp;w=2" source="BUGTRAQ" adv="1">20040528 Mollensoft ftp Server ver 3.6 Buffer overflow</ref>
      <ref url="http://securitytracker.com/id?1010328" source="SECTRACK">1010328</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mollensoft_software" name="lightweight_ftp_server">
        <vers num="3.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-2038" published="2004-05-29" name="CVE-2004-2038" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in Land Down Under (LDU) before LDU 700 allows remote attackers to inject arbitrary web script or HTML via a BBcode img tag in (1) functions.php, (2) header.php or (3) auth.inc.php.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.osvdb.org/6511" source="OSVDB" patch="1" adv="1">6511</ref>
      <ref url="http://www.osvdb.org/6510" source="OSVDB" patch="1" adv="1">6510</ref>
      <ref url="http://www.osvdb.org/6508" source="OSVDB" patch="1" adv="1">6508</ref>
      <ref url="http://secunia.com/advisories/11739" source="SECUNIA" patch="1" adv="1">11739</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/16284" source="XF" adv="1">ldu-bbcode-xss(16284)</ref>
      <ref url="http://www.securityfocus.com/bid/10435" source="BID">10435</ref>
      <ref url="http://securitytracker.com/alerts/2004/May/1010335.html" source="SECTRACK">1010335</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108585789220174&amp;w=2" source="BUGTRAQ" adv="1">20040529 LDU (land down under) xss vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="neocrome" name="land_down_under">
        <vers num="601" />
        <vers num="602" />
        <vers num="700.01" />
        <vers num="700.02" />
        <vers prev="1" num="700.03" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-2039" published="2004-05-29" name="CVE-2004-2039" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">e107 0.615 allows remote attackers to obtain sensitive information via a direct request to (1) alt_news.php, (2) backend_menu.php, (3) clock_menu.php, (4) counter_menu.php, (5) login_menu.php, and other files, which reveal the full path in a PHP error message.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/16277" source="XF" patch="1" adv="1">e107-multiplescripts-path-disclosure(16277)</ref>
      <ref url="http://www.osvdb.org/6525" source="OSVDB" patch="1" adv="1">6525</ref>
      <ref url="http://secunia.com/advisories/11740" source="SECUNIA" patch="1" adv="1">11740</ref>
      <ref url="http://www.waraxe.us/index.php?modname=sa&amp;id=31" source="MISC" adv="1">http://www.waraxe.us/index.php?modname=sa&amp;id=31</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108588043007224&amp;w=2" source="BUGTRAQ" adv="1">20040529 [waraxe-2004-SA#031 - Multiple vulnerabilities in e107 version 0.615]</ref>
      <ref url="http://www.securityfocus.com/bid/10436" source="BID">10436</ref>
      <ref url="http://marc.theaimsgroup.com/?l=full-disclosure&amp;m=108586723116427&amp;w=2" source="FULLDISC">20040529 [waraxe-2004-SA#031 - Multiple vulnerabilities in e107 version 0.615]</ref>
    </refs>
    <vuln_soft>
      <prod vendor="e107" name="e107">
        <vers num="0.6_15" />
        <vers num="0.6_15a" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-2040" published="2004-05-29" name="CVE-2004-2040" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in e107 0.615 allow remote attackers to inject arbitrary web script or HTML via the (1) LAN_407 parameter to clock_menu.php, (2) "email article to a friend" field, (3) "submit news" field, or (4) avmsg parameter to usersettings.php.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/16281" source="XF" patch="1" adv="1">e107-user-setting-xss(16281)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/16280" source="XF" patch="1" adv="1">e107-email-friend-xss(16280)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/16279" source="XF" patch="1" adv="1">e107-clock-menu-xss(16279)</ref>
      <ref url="http://secunia.com/advisories/11740" source="SECUNIA" patch="1" adv="1">11740</ref>
      <ref url="http://www.waraxe.us/index.php?modname=sa&amp;id=31" source="MISC" adv="1">http://www.waraxe.us/index.php?modname=sa&amp;id=31</ref>
      <ref url="http://www.securityfocus.com/bid/10436" source="BID" adv="1">10436</ref>
      <ref url="http://www.osvdb.org/6529" source="OSVDB">6529</ref>
      <ref url="http://www.osvdb.org/6528" source="OSVDB" adv="1">6528</ref>
      <ref url="http://www.osvdb.org/6527" source="OSVDB" adv="1">6527</ref>
      <ref url="http://www.osvdb.org/6526" source="OSVDB" adv="1">6526</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108588043007224&amp;w=2" source="BUGTRAQ" adv="1">20040529 [waraxe-2004-SA#031 - Multiple vulnerabilities in e107 version 0.615]</ref>
      <ref url="http://marc.theaimsgroup.com/?l=full-disclosure&amp;m=108586723116427&amp;w=2" source="FULLDISC">20040529 [waraxe-2004-SA#031 - Multiple vulnerabilities in e107 version 0.615]</ref>
    </refs>
    <vuln_soft>
      <prod vendor="e107" name="e107">
        <vers num="0.6_15" />
        <vers num="0.6_15a" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-2041" published="2004-05-29" name="CVE-2004-2041" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">PHP remote file inclusion vulnerability in secure_img_render.php in e107 0.615 allows remote attackers to execute arbitrary PHP code by modifying the p parameter to reference a URL on a remote web server that contains the code.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/16282" source="XF" patch="1" adv="1">e107-secure-img-render-file-include(16282)</ref>
      <ref url="http://www.waraxe.us/index.php?modname=sa&amp;id=31" source="MISC" adv="1">http://www.waraxe.us/index.php?modname=sa&amp;id=31</ref>
      <ref url="http://www.securityfocus.com/bid/10436" source="BID" adv="1">10436</ref>
      <ref url="http://www.osvdb.org/6530" source="OSVDB" adv="1">6530</ref>
      <ref url="http://secunia.com/advisories/11740" source="SECUNIA">11740</ref>
      <ref url="http://marc.theaimsgroup.com/?l=full-disclosure&amp;m=108586723116427&amp;w=2" source="FULLDISC">20040529 [waraxe-2004-SA#031 - Multiple vulnerabilities in e107 version 0.615]</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108588043007224&amp;w=2" source="BUGTRAQ" adv="1">20040529 [waraxe-2004-SA#031 - Multiple vulnerabilities in e107 version 0.615]</ref>
    </refs>
  </entry>
  <entry type="CVE" severity="High" seq="2004-2042" published="2004-05-29" name="CVE-2004-2042" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple SQL injection vulnerabilities in e107 0.615 allow remote attackers to inject arbitrary SQL code and gain sensitive information via (1) content parameter to content.php, (2) content_id parameter to content.php, or (3) list parameter to news.php.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/16283" source="XF" patch="1" adv="1">e107-content-news-sql-injection(16283)</ref>
      <ref url="http://www.waraxe.us/index.php?modname=sa&amp;id=31" source="MISC" patch="1" adv="1">http://www.waraxe.us/index.php?modname=sa&amp;id=31</ref>
      <ref url="http://www.securityfocus.com/bid/10436" source="BID" patch="1" adv="1">10436</ref>
      <ref url="http://www.osvdb.org/6533" source="OSVDB" patch="1" adv="1">6533</ref>
      <ref url="http://www.osvdb.org/6531" source="OSVDB" patch="1" adv="1">6531</ref>
      <ref url="http://secunia.com/advisories/11740" source="SECUNIA" patch="1" adv="1">11740</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108588043007224&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20040529 [waraxe-2004-SA#031 - Multiple vulnerabilities in e107 version 0.615]</ref>
      <ref url="http://marc.theaimsgroup.com/?l=full-disclosure&amp;m=108586723116427&amp;w=2" source="FULLDISC">20040529 [waraxe-2004-SA#031 - Multiple vulnerabilities in e107 version 0.615]</ref>
      <ref url="http://www.osvdb.org/6532" source="OSVDB" sig="1" adv="1">6532</ref>
    </refs>
    <vuln_soft>
      <prod vendor="e107" name="e107">
        <vers num="0.615" />
        <vers num="0.615a" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-2043" published="2004-05-01" name="CVE-2004-2043" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Buffer overflow in ibserver for Firebird Database 1.0 and other versions before 1.5, and possibly other products that use the InterBase codebase, allows remote attackers to cause a denial of service (crash) via a long database name, as demonstrated using the gsec command.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/11756" source="SECUNIA" patch="1" adv="1">11756</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/16316" source="XF">interbase-database-name-bo(16316)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/16229" source="XF" adv="1">firebird-database-name-bo(16229)</ref>
      <ref url="http://www.securityfocus.com/bid/10446" source="BID" adv="1">10446</ref>
      <ref url="http://www.securiteam.com/unixfocus/5AP0P0UCUO.html" source="MISC" adv="1">http://www.securiteam.com/unixfocus/5AP0P0UCUO.html</ref>
      <ref url="http://www.osvdb.org/6624" source="OSVDB">6624</ref>
      <ref url="http://www.osvdb.org/6408" source="OSVDB" adv="1">6408</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1014" source="DEBIAN">DSA-1014</ref>
      <ref url="http://securitytracker.com/id?1010381" source="SECTRACK">1010381</ref>
      <ref url="http://secunia.com/advisories/19350" source="SECUNIA">19350</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108611386202493&amp;w=2" source="BUGTRAQ" adv="1">20040601 Firebird Database Remote Database Name Overflow</ref>
      <ref url="http://archives.neohapsis.com/archives/fulldisclosure/2004-06/0027.html" source="FULLDISC">20040602 Firebird [ AND Interbase 7 ] Database Remote Database Name Overflow</ref>
    </refs>
    <vuln_soft>
      <prod vendor="borland_software" name="interbase">
        <vers num="4.0" />
        <vers num="5.0" />
        <vers num="6.0" />
        <vers num="6.4" />
        <vers num="6.5" />
        <vers num="7.0" />
        <vers num="7.1" />
      </prod>
      <prod vendor="borland_software" name="interbase_superserver">
        <vers num="6.0" />
      </prod>
      <prod vendor="firebirdsql" name="firebird">
        <vers num="1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-2044" published="2004-06-01" name="CVE-2004-2044" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">PHP-Nuke 7.3, and other products that use the PHP-Nuke codebase such as the Nuke Cops betaNC PHP-Nuke Bundle, OSCNukeLite 3.1, and OSC2Nuke 7x do not properly use the eregi() PHP function with $_SERVER['PHP_SELF'] to identify the calling script, which allows remote attackers to directly access scripts, obtain path information via a PHP error message, and possibly gain access, as demonstrated using an HTTP request that contains the "admin.php" string.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <access />
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/16298" source="XF" adv="1">nukecops-ergei-path-disclosure(16298)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/16297" source="XF">oscnukelite-eregi-path-disclosure(16297)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/16296" source="XF" adv="1">osc2nuke-eregi-path-disclosure(16296)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/16294" source="XF" adv="1">phpnuke-eregi-path-disclosure(16294)</ref>
      <ref url="http://www.securityfocus.com/bid/10447" source="BID" adv="1">10447</ref>
      <ref url="http://www.osvdb.org/6593" source="OSVDB" adv="1">6593</ref>
      <ref url="http://secunia.com/advisories/11766" source="SECUNIA" adv="1">11766</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108662955105757&amp;w=2" source="BUGTRAQ" adv="1">20040606 Re: [Squid 2004-Nuke-001] Inadequate Security Checking in PHPNuke</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108611643614881&amp;w=2" source="BUGTRAQ" adv="1">20040601 [Squid 2004-Nuke-001] Inadequate Security Checking in PHPNuke</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108611606320559&amp;w=2" source="BUGTRAQ">20040601 [Squid 2004-betaNC-001] Inadequate Security Checking in NukeCops</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2004-06/0006.html" source="BUGTRAQ">20040601 [Squid 2004-OSC2Nuke-001] Inadequate Security Checking in OSC2Nuke</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2004-06/0005.html" source="BUGTRAQ">20040601 [Squid 2004-betaNC-001] Inadequate Security Checking in NukeCops betaNC Bundle</ref>
    </refs>
    <vuln_soft>
      <prod vendor="francisco_burzi" name="php-nuke">
        <vers num="5.0" />
        <vers num="5.0.1" />
        <vers num="5.1" />
        <vers num="5.2" />
        <vers num="5.2a" />
        <vers num="5.3.1" />
        <vers num="5.4" />
        <vers num="5.5" />
        <vers num="5.6" />
        <vers num="6.0" />
        <vers num="6.5" />
        <vers num="6.5_beta1" />
        <vers num="6.5_final" />
        <vers num="6.5_rc1" />
        <vers num="6.5_rc2" />
        <vers num="6.5_rc3" />
        <vers num="6.6" />
        <vers num="6.7" />
        <vers num="6.9" />
        <vers num="7.0" />
        <vers num="7.0_final" />
        <vers num="7.1" />
        <vers num="7.2" />
        <vers num="7.3" />
      </prod>
      <prod vendor="oscommerce" name="osc2nuke">
        <vers num="7x_1.0" />
      </prod>
      <prod vendor="paul_laudanski" name="betanc_php-nuke">
        <vers num="bundle" />
      </prod>
      <prod vendor="trustix" name="secure_linux">
        <vers num="2.0" />
        <vers num="2.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-2045" published="2004-12-31" name="CVE-2004-2045" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The HTTP administration interface on Conceptronic CADSLR1 ADSL router running firmware 3.04n allows remote attackers to cause a denial of service (device reboot) via an HTTP request with a long username.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/16746" source="XF">conceptronic-long-username-dos(16746)</ref>
      <ref url="http://www.shellsec.net/leer_advisory.php?id=5" source="MISC">http://www.shellsec.net/leer_advisory.php?id=5</ref>
      <ref url="http://www.securityfocus.com/bid/10769" source="BID">10769</ref>
      <ref url="http://secunia.com/advisories/12110" source="SECUNIA">12110</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109045084522857&amp;w=2" source="BUGTRAQ">20040721 Denial of Service in Conceptronic CADSLR1 Router</ref>
    </refs>
    <vuln_soft>
      <prod vendor="conceptronic" name="cadslr1_adsl_router">
        <vers num="3.04n" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-2046" published="2004-12-31" name="CVE-2004-2046" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Unknown vulnerability in APC PowerChute Business Edition 6.0 through 7.0.1 allows remote attackers to cause a denial of service via unknown attack vectors.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <other />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/10777" source="BID" patch="1">10777</ref>
      <ref url="http://secunia.com/advisories/12124" source="SECUNIA" patch="1">12124</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/16767" source="XF">powerchute-console-dos(16767)</ref>
      <ref url="http://www.osvdb.org/8187" source="OSVDB">8187</ref>
      <ref url="http://securitytracker.com/id?1010745" source="SECTRACK">1010745</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109061480026378&amp;w=2" source="BUGTRAQ">20040721 APC Security Advisory  Denial of Service Vulnerability with PowerChute Business Edition</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apc" name="powerchute">
        <vers num="6.0" edition="" />
        <vers num="6.0" edition=":business" />
        <vers num="7.1" edition="" />
        <vers num="7.1" edition=":business" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-2047" published="2004-07-23" name="CVE-2004-2047" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in EasyWeb FileManager 1.0 RC-1 for PostNuke allows remote attackers to retrieve arbitrary files via a .. (dot dot) in the pathext parameter.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/16806" source="XF" adv="1">filemanager-pathext-view-directory-traversal(16806)</ref>
      <ref url="http://www.securityfocus.com/bid/10792" source="BID" adv="1">10792</ref>
      <ref url="http://www.osvdb.org/8193" source="OSVDB" adv="1">8193</ref>
      <ref url="http://www.cirt.net/advisories/ew_file_manager.shtml" source="MISC" adv="1">http://www.cirt.net/advisories/ew_file_manager.shtml</ref>
      <ref url="http://secunia.com/advisories/12151" source="SECUNIA" adv="1">12151</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109068482605241&amp;w=2" source="BUGTRAQ" adv="1">20040724 EasyWeb FileManager Directory Traversal</ref>
    </refs>
    <vuln_soft>
      <prod vendor="easyweb" name="easyweb_filemanager">
        <vers num="1.0_rc1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-2048" published="2004-12-31" name="CVE-2004-2048" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">radmin in eSeSIX Thintune thin clients running firmware 2.4.38 and earlier starts a process port 25072 that can be accessed with a default "jstwo" password, which allows remote attackers to gain access.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/16790" source="XF">thintune-password-gain-access(16790)</ref>
      <ref url="http://www.securityfocus.com/bid/10794" source="BID">10794</ref>
      <ref url="http://secunia.com/advisories/12154" source="SECUNIA">12154</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109068491801021&amp;w=2" source="BUGTRAQ">20040724 eSeSIX Thintune thin client multiple vulnerabilities</ref>
      <ref url="http://www.osvdb.org/8246" source="OSVDB">8246</ref>
      <ref url="http://securitytracker.com/id?1010770" source="SECTRACK">1010770</ref>
    </refs>
    <vuln_soft>
      <prod vendor="esesix" name="thintune_extreme">
        <vers num="2.4.38" />
      </prod>
      <prod vendor="esesix" name="thintune_l">
        <vers num="2.4.38" />
      </prod>
      <prod vendor="esesix" name="thintune_m">
        <vers num="2.4.38" />
      </prod>
      <prod vendor="esesix" name="thintune_mobile">
        <vers num="2.4.38" />
      </prod>
      <prod vendor="esesix" name="thintune_s">
        <vers num="2.4.38" />
      </prod>
      <prod vendor="esesix" name="thintune_xm">
        <vers num="2.4.38" />
      </prod>
      <prod vendor="esesix" name="thintune_xs">
        <vers num="2.4.38" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-2049" published="2004-12-31" name="CVE-2004-2049" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">eSeSIX Thintune thin clients running firmware 2.4.38 and earlier store sensitive usernames and passwords in cleartext in configuration files for the keeper library, which allows attackers to gain access.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/16795" source="XF">thintune-plaintext-passwords(16795)</ref>
      <ref url="http://www.securityfocus.com/bid/10794" source="BID">10794</ref>
      <ref url="http://secunia.com/advisories/12154" source="SECUNIA">12154</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109068491801021&amp;w=2" source="BUGTRAQ">20040724 eSeSIX Thintune thin client multiple vulnerabilities</ref>
      <ref url="http://www.osvdb.org/8247" source="OSVDB">8247</ref>
      <ref url="http://securitytracker.com/id?1010770" source="SECTRACK">1010770</ref>
    </refs>
    <vuln_soft>
      <prod vendor="esesix" name="thintune_extreme">
        <vers num="2.4.38" />
      </prod>
      <prod vendor="esesix" name="thintune_l">
        <vers num="2.4.38" />
      </prod>
      <prod vendor="esesix" name="thintune_m">
        <vers num="2.4.38" />
      </prod>
      <prod vendor="esesix" name="thintune_mobile">
        <vers num="2.4.38" />
      </prod>
      <prod vendor="esesix" name="thintune_s">
        <vers num="2.4.38" />
      </prod>
      <prod vendor="esesix" name="thintune_xm">
        <vers num="2.4.38" />
      </prod>
      <prod vendor="esesix" name="thintune_xs">
        <vers num="2.4.38" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-2050" published="2004-12-31" name="CVE-2004-2050" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">eSeSIX Thintune thin clients running firmware 2.4.38 and earlier allow local users to gain privileges by pressing CTRL-SHIFT-ALT-DEL and entering the "maertsJ" password, which is hard-coded into lshell.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/16808" source="XF">thintune-password-gain-privileges(16808)</ref>
      <ref url="http://www.securityfocus.com/bid/10794" source="BID">10794</ref>
      <ref url="http://secunia.com/advisories/12154" source="SECUNIA">12154</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109068491801021&amp;w=2" source="BUGTRAQ">20040724 eSeSIX Thintune thin client multiple vulnerabilities</ref>
      <ref url="http://www.osvdb.org/8248" source="OSVDB">8248</ref>
      <ref url="http://securitytracker.com/id?1010770" source="SECTRACK">1010770</ref>
    </refs>
    <vuln_soft>
      <prod vendor="esesix" name="thintune_extreme">
        <vers num="2.4.38" />
      </prod>
      <prod vendor="esesix" name="thintune_l">
        <vers num="2.4.38" />
      </prod>
      <prod vendor="esesix" name="thintune_m">
        <vers num="2.4.38" />
      </prod>
      <prod vendor="esesix" name="thintune_mobile">
        <vers num="2.4.38" />
      </prod>
      <prod vendor="esesix" name="thintune_s">
        <vers num="2.4.38" />
      </prod>
      <prod vendor="esesix" name="thintune_xm">
        <vers num="2.4.38" />
      </prod>
      <prod vendor="esesix" name="thintune_xs">
        <vers num="2.4.38" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-2051" published="2004-07-24" name="CVE-2004-2051" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The Phoenix browser in eSeSIX Thintune thin clients running firmware 2.4.38 and earlier allows local users to read arbitrary files via a file:/// URL.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/16798" source="XF" adv="1">thintune-url-obtain-information(16798)</ref>
      <ref url="http://www.securityfocus.com/bid/10794" source="BID" adv="1">10794</ref>
      <ref url="http://secunia.com/advisories/12154" source="SECUNIA">12154</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109068491801021&amp;w=2" source="BUGTRAQ" adv="1">20040724 eSeSIX Thintune thin client multiple vulnerabilities</ref>
      <ref url="http://www.osvdb.org/8249" source="OSVDB">8249</ref>
      <ref url="http://securitytracker.com/id?1010770" source="SECTRACK">1010770</ref>
    </refs>
    <vuln_soft>
      <prod vendor="esesix" name="thintune_extreme">
        <vers num="2.4.38_firmware" />
      </prod>
      <prod vendor="esesix" name="thintune_l">
        <vers num="2.4.38_firmware" />
      </prod>
      <prod vendor="esesix" name="thintune_m">
        <vers num="2.4.38_firmware" />
      </prod>
      <prod vendor="esesix" name="thintune_mobile">
        <vers num="2.4.38_firmware" />
      </prod>
      <prod vendor="esesix" name="thintune_s">
        <vers num="2.4.38_firmware" />
      </prod>
      <prod vendor="esesix" name="thintune_xm">
        <vers num="2.4.38_firmware" />
      </prod>
      <prod vendor="esesix" name="thintune_xs">
        <vers num="2.4.38_firmware" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-2052" published="2004-12-31" name="CVE-2004-2052" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">eSeSIX Thintune thin clients running firmware 2.4.38 and earlier accept any password that begins with the actual password, which makes it easier for users to conduct brute force password guessing.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109068491801021&amp;w=2" source="BUGTRAQ">20040724 eSeSIX Thintune thin client multiple vulnerabilities</ref>
    </refs>
    <vuln_soft>
      <prod vendor="esesix" name="thintune">
        <vers prev="1" num="2.4.38" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-2053" published="2004-07-24" name="CVE-2004-2053" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">PHP remote file inclusion vulnerability in index.php in EasyIns Stadtportal 4 allows remote attackers to execute arbitrary PHP code via the site parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/16797" source="XF">easyins-php-file-include(16797)</ref>
      <ref url="http://www.securityfocus.com/bid/10795" source="BID">10795</ref>
      <ref url="http://securitytracker.com/id?1010769" source="SECTRACK">1010769</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109069241512694&amp;w=2" source="BUGTRAQ">20040724 Easyins Stadtportal</ref>
      <ref url="http://www.osvdb.org/8233" source="OSVDB">8233</ref>
    </refs>
    <vuln_soft>
      <prod vendor="easyins" name="easyins">
        <vers num="stadtportal_4.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-2054" published="2004-12-31" name="CVE-2004-2054" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">CRLF injection vulnerability in PhpBB 2.0.4 and 2.0.9 allows remote attackers to perform HTTP Response Splitting attacks to modify expected HTML content from the server via (1) the mode parameter to privmsg.php or (2) the redirect parameter to login.php.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/16759" source="XF">phpbb-search-response-splitting(16759)</ref>
      <ref url="http://www.securityfocus.com/bid/10753" source="BID">10753</ref>
      <ref url="http://secunia.com/advisories/12114" source="SECUNIA">12114</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109034476122723&amp;w=2" source="BUGTRAQ">20040720 PhpBB HTTP Response Splitting &amp; Cross Site Scripting vulnerabilities</ref>
    </refs>
    <vuln_soft>
      <prod vendor="phpbb_group" name="phpbb">
        <vers num="2.0.0" />
        <vers num="2.0.1" />
        <vers num="2.0.2" />
        <vers num="2.0.3" />
        <vers num="2.0.4" />
        <vers num="2.0.5" />
        <vers num="2.0.6" />
        <vers num="2.0.6c" />
        <vers num="2.0.6d" />
        <vers num="2.0.7" />
        <vers num="2.0.7a" />
        <vers num="2.0.8" />
        <vers num="2.0.8a" />
        <vers num="2.0.9" />
        <vers num="2.0_beta1" />
        <vers num="2.0_rc1" />
        <vers num="2.0_rc2" />
        <vers num="2.0_rc3" />
        <vers num="2.0_rc4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-2055" published="2004-07-19" name="CVE-2004-2055" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in search.php for PhpBB 2.0.4 and 2.0.9 allows remote attackers to inject arbitrary HTMl or web script via the search_author parameter.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/16758" source="XF">phpbb-search-searchauthor-xss(16758)</ref>
      <ref url="http://www.securityfocus.com/bid/10753" source="BID" adv="1">10753</ref>
      <ref url="http://secunia.com/advisories/12114" source="SECUNIA" adv="1">12114</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109034476122723&amp;w=2" source="BUGTRAQ" adv="1">20040720 PhpBB HTTP Response Splitting &amp; Cross Site Scripting vulnerabilities</ref>
    </refs>
    <vuln_soft>
      <prod vendor="phpbb_group" name="phpbb">
        <vers num="2.0.0" />
        <vers num="2.0.1" />
        <vers num="2.0.2" />
        <vers num="2.0.3" />
        <vers num="2.0.4" />
        <vers num="2.0.5" />
        <vers num="2.0.6" />
        <vers num="2.0.6c" />
        <vers num="2.0.6d" />
        <vers num="2.0.7" />
        <vers num="2.0.7a" />
        <vers num="2.0.8" />
        <vers num="2.0.8a" />
        <vers num="2.0.9" />
        <vers num="2.0_beta1" />
        <vers num="2.0_rc1" />
        <vers num="2.0_rc2" />
        <vers num="2.0_rc3" />
        <vers num="2.0_rc4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-2056" published="2004-12-31" name="CVE-2004-2056" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in action.php in Nucleus CMS 3.01 allows remote attackers execute arbitrary SQL statements via the itemid parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/13136" source="SECUNIA" patch="1">13136</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109087144509299&amp;w=2" source="BUGTRAQ" patch="1">20040725 NucleusCMS 3.01 SQL Injection Vulnerability</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/18002" source="XF">nucleus-sql-injection(18002)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="nucleus_group" name="nucleus_cms">
        <vers num="3.01" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-2057" published="2004-12-31" name="CVE-2004-2057" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in ASPRunner 2.4 allows remote attackers to execute arbitrary SQL statements.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/16799" source="XF">asprunner-sql-injection(16799)</ref>
      <ref url="http://www.securityfocus.com/bid/10799" source="BID">10799</ref>
      <ref url="http://secunia.com/advisories/12164" source="SECUNIA">12164</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109086977330418&amp;w=2" source="BUGTRAQ">20040726 ASPRunner Multiple Vulnerabilities</ref>
      <ref url="http://ferruh.mavituna.com/article/?574" source="MISC">http://ferruh.mavituna.com/article/?574</ref>
      <ref url="http://archives.neohapsis.com/archives/vulnwatch/2004-q3/0011.html" source="VULNWATCH">20040726 ASPRunner Multiple Vulnerabilities</ref>
      <ref url="http://www.osvdb.org/8251" source="OSVDB">8251</ref>
      <ref url="http://securitytracker.com/id?1010777" source="SECTRACK">1010777</ref>
    </refs>
    <vuln_soft>
      <prod vendor="xlinesoft" name="asprunner">
        <vers num="1.0" />
        <vers num="2.0" />
        <vers num="2.1" />
        <vers num="2.2" />
        <vers num="2.3" />
        <vers num="2.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-2058" published="2004-12-31" name="CVE-2004-2058" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">ASPRunner 2.4 allows remote attackers to gain sensitive information via (1) hidden form fields or (2) error messages.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/16800" source="XF">asprunner-information-disclosure(16800)</ref>
      <ref url="http://www.securityfocus.com/bid/10799" source="BID">10799</ref>
      <ref url="http://secunia.com/advisories/12164" source="SECUNIA">12164</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109086977330418&amp;w=2" source="BUGTRAQ">20040726 ASPRunner Multiple Vulnerabilities</ref>
      <ref url="http://ferruh.mavituna.com/article/?574" source="MISC">http://ferruh.mavituna.com/article/?574</ref>
      <ref url="http://archives.neohapsis.com/archives/vulnwatch/2004-q3/0011.html" source="VULNWATCH">20040726 ASPRunner Multiple Vulnerabilities</ref>
      <ref url="http://www.osvdb.org/8252" source="OSVDB">8252</ref>
      <ref url="http://securitytracker.com/id?1010777" source="SECTRACK">1010777</ref>
    </refs>
    <vuln_soft>
      <prod vendor="xlinesoft" name="asprunner">
        <vers num="1.0" />
        <vers num="2.0" />
        <vers num="2.1" />
        <vers num="2.2" />
        <vers num="2.3" />
        <vers num="2.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-2059" published="2004-12-31" name="CVE-2004-2059" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Multiple cross-site scripting vulnerabilities in ASPRunner 2.4 allow remote attackers inject arbitrary web script or HTML via the (1) SearchFor parameter in [TABLE-NAME]_search.asp, (2) SQL parameter in [TABLE-NAME]_edit.asp, (3) SearchFor parameter in [TABLE]_list.asp, or (4) SQL parameter in export.asp.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/16801" source="XF">asprunner-xss(16801)</ref>
      <ref url="http://www.securityfocus.com/bid/10799" source="BID">10799</ref>
      <ref url="http://secunia.com/advisories/12164" source="SECUNIA">12164</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109086977330418&amp;w=2" source="BUGTRAQ">20040726 ASPRunner Multiple Vulnerabilities</ref>
      <ref url="http://ferruh.mavituna.com/article/?574" source="MISC">http://ferruh.mavituna.com/article/?574</ref>
      <ref url="http://archives.neohapsis.com/archives/vulnwatch/2004-q3/0011.html" source="VULNWATCH">20040726 ASPRunner Multiple Vulnerabilities</ref>
      <ref url="http://www.osvdb.org/8257" source="OSVDB">8257</ref>
      <ref url="http://www.osvdb.org/8256" source="OSVDB">8256</ref>
      <ref url="http://www.osvdb.org/8255" source="OSVDB">8255</ref>
      <ref url="http://www.osvdb.org/8254" source="OSVDB">8254</ref>
      <ref url="http://securitytracker.com/id?1010777" source="SECTRACK">1010777</ref>
    </refs>
    <vuln_soft>
      <prod vendor="xlinesoft" name="asprunner">
        <vers num="1.0" />
        <vers num="2.0" />
        <vers num="2.1" />
        <vers num="2.2" />
        <vers num="2.3" />
        <vers num="2.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-2060" published="2004-12-31" name="CVE-2004-2060" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">ASPRunner 2.4 stores the database under the web root in the db directory, which may allow remote attackers to obtain the database via a direct request to the database filename, which is predictable based on table and field names.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/10799" source="BID">10799</ref>
      <ref url="http://secunia.com/advisories/12164" source="SECUNIA">12164</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109086977330418&amp;w=2" source="BUGTRAQ">20040726 ASPRunner Multiple Vulnerabilities</ref>
      <ref url="http://ferruh.mavituna.com/article/?574" source="MISC">http://ferruh.mavituna.com/article/?574</ref>
      <ref url="http://archives.neohapsis.com/archives/vulnwatch/2004-q3/0011.html" source="VULNWATCH">20040726 ASPRunner Multiple Vulnerabilities</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/16802" source="XF">asprunner-database-file-access(16802)</ref>
      <ref url="http://www.osvdb.org/8253" source="OSVDB">8253</ref>
      <ref url="http://securitytracker.com/id?1010777" source="SECTRACK">1010777</ref>
    </refs>
    <vuln_soft>
      <prod vendor="xlinesoft" name="asprunner">
        <vers num="1.0" />
        <vers num="2.0" />
        <vers num="2.1" />
        <vers num="2.2" />
        <vers num="2.3" />
        <vers num="2.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-2061" published="2004-07-27" name="CVE-2004-2061" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">RiSearch 1.0.01 and RiSearch Pro 3.2.06 allows remote attackers to use the show.pl script as an open proxy, or read arbitrary local files, by setting the url parameter to a (1) http://, (2) ftp://, or (3) file:// URL.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <access />
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/16817" source="XF" adv="1">risearch-show-open-proxy(16817)</ref>
      <ref url="http://www.securityfocus.com/bid/10812" source="BID" adv="1">10812</ref>
      <ref url="http://secunia.com/advisories/12173" source="SECUNIA" adv="1">12173</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109095196526490&amp;w=2" source="BUGTRAQ" adv="1">20040727 IRM 009: RiSearch and RiSearch ProPro are vulnerable to open FTP/HTTP proxy, directory listings and file disclosure vulnerabilities</ref>
      <ref url="http://www.osvdb.org/8266" source="OSVDB">8266</ref>
      <ref url="http://www.osvdb.org/8265" source="OSVDB">8265</ref>
      <ref url="http://securitytracker.com/id?1010788" source="SECTRACK">1010788</ref>
    </refs>
    <vuln_soft>
      <prod vendor="risearch_software" name="risearch">
        <vers num="0.99.1" />
        <vers num="0.99.2" />
        <vers num="0.99.3" />
        <vers num="0.99.4" />
        <vers num="0.99.5" />
        <vers num="0.99.6" />
        <vers num="0.99.7" />
        <vers num="0.99.8" />
      </prod>
      <prod vendor="risearch_software" name="risearch_pro">
        <vers num="3.2.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-2062" published="2004-12-31" name="CVE-2004-2062" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in antiboard.php in AntiBoard 0.7.2 and earlier allows remote attackers to execute arbitrary SQL via the (1) thread_id, (2) parent_id, or (3) mode parameters.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/16828" source="XF">antiboard-get-sql-injection(16828)</ref>
      <ref url="http://www.securityfocus.com/bid/10821" source="BID">10821</ref>
      <ref url="http://secunia.com/advisories/12137" source="SECUNIA">12137</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109105610220965&amp;w=2" source="BUGTRAQ">20040728 AntiBoard &lt;= 0.7.2 XSS/SQL Injection</ref>
    </refs>
    <vuln_soft>
      <prod vendor="antiboard" name="antiboard">
        <vers num="0.6" />
        <vers num="0.61" />
        <vers num="0.62" />
        <vers num="0.63" />
        <vers num="0.7" />
        <vers num="0.7.1" />
        <vers num="0.7.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-2063" published="2004-12-31" name="CVE-2004-2063" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in antiboard.php in AntiBoard 0.7.2 and earlier allows remote attackers to inject arbitrary HTML or web script via the feedback parameter.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/16830" source="XF">antiboard-feedback-xss(16830)</ref>
      <ref url="http://www.securityfocus.com/bid/10821" source="BID">10821</ref>
      <ref url="http://secunia.com/advisories/12137" source="SECUNIA">12137</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109105610220965&amp;w=2" source="BUGTRAQ">20040728 AntiBoard &lt;= 0.7.2 XSS/SQL Injection</ref>
      <ref url="http://www.osvdb.org/8269" source="OSVDB">8269</ref>
    </refs>
    <vuln_soft>
      <prod vendor="antiboard" name="antiboard">
        <vers num="0.6" />
        <vers num="0.61" />
        <vers num="0.62" />
        <vers num="0.63" />
        <vers num="0.7" />
        <vers num="0.7.1" />
        <vers num="0.7.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-2064" published="2004-07-29" name="CVE-2004-2064" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in lostBook 1.1 and earlier allows remote attackers to inject arbitrary web script via the (1) Email or (2) Website fields.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/16835" source="XF" adv="1">lostbook-email-website-xss(16835)</ref>
      <ref url="http://www.securityfocus.com/bid/10825" source="BID" adv="1">10825</ref>
      <ref url="http://www.osvdb.org/8271" source="OSVDB">8271</ref>
      <ref url="http://securitytracker.com/id?1010812" source="SECTRACK">1010812</ref>
      <ref url="http://secunia.com/advisories/12190" source="SECUNIA" adv="1">12190</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109112282611808&amp;w=2" source="BUGTRAQ">20040729 lostBook v1.1 Javascript Execution</ref>
    </refs>
    <vuln_soft>
      <prod vendor="verylost" name="lostbook">
        <vers prev="1" num="1.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-2065" published="2004-12-31" name="CVE-2004-2065" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">DansGuardian 2.8 and earlier allows remote attackers to bypass the extension filtering rule via a hex encoded extension or . in the filename.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input />
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/10823" source="BID" patch="1">10823</ref>
      <ref url="http://secunia.com/advisories/12191" source="SECUNIA" patch="1">12191</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/16836" source="XF">dansguardian-filename-bypass-filtering(16836)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109113126217408&amp;w=2" source="BUGTRAQ">20040729 DansGuardian Hex Encoding URL Banned Extension Filter Bypass</ref>
      <ref url="http://dansguardian.org/?page=history" source="CONFIRM">http://dansguardian.org/?page=history</ref>
      <ref url="http://www.osvdb.org/8270" source="OSVDB">8270</ref>
      <ref url="http://securitytracker.com/id?1010817" source="SECTRACK">1010817</ref>
    </refs>
    <vuln_soft>
      <prod vendor="daniel_barron" name="dansguardian">
        <vers num="2.2.10" />
        <vers num="2.2.4" />
        <vers num="2.2.5" />
        <vers num="2.2.6" />
        <vers num="2.2.7" />
        <vers num="2.2.7.1" />
        <vers num="2.2.8" />
        <vers num="2.2.9" />
        <vers num="2.2.9.1" />
        <vers num="2.4.5.1" />
        <vers num="2.6.1.5" />
        <vers num="2.7.3.1" />
        <vers num="2.8" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-2066" published="2004-07-29" name="CVE-2004-2066" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in session.php in LinPHA 0.9.4 allows remote attackers to execute arbitrary SQL code and bypass authentication via the (1) linpha_userid or (2) linpha_password cookies.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/16834" source="XF" adv="1">linpha-cookie-gain-access(16834)</ref>
      <ref url="http://www.securityfocus.com/bid/10827" source="BID" adv="1">10827</ref>
      <ref url="http://secunia.com/advisories/12189" source="SECUNIA" adv="1">12189</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109112246805277&amp;w=2" source="BUGTRAQ" adv="1">20040729 Linpha 0.9.4: authentication bypass</ref>
      <ref url="http://www.osvdb.org/8272" source="OSVDB">8272</ref>
    </refs>
    <vuln_soft>
      <prod vendor="linpha" name="linpha">
        <vers num="0.9.0" />
        <vers num="0.9.1" />
        <vers num="0.9.2" />
        <vers num="0.9.3" />
        <vers num="0.9.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-2067" published="2004-07-29" name="CVE-2004-2067" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in controlpanel.php in Jaws Framework and Content Management System 0.4 allows remote attackers to execute arbitrary SQL and bypass authentication via the (1) user, (2) password, or (3) crypted_password parameters.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/16847" source="XF" adv="1">jaws-controlpanel-sql-injection(16847)</ref>
      <ref url="http://www.securityfocus.com/bid/10826" source="BID" adv="1">10826</ref>
      <ref url="http://www.osvdb.org/8320" source="OSVDB">8320</ref>
      <ref url="http://securitytracker.com/id?1010815" source="SECTRACK">1010815</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109116345930380&amp;w=2" source="BUGTRAQ" adv="1">20040729 Jaws 0.4: authentication bypass</ref>
    </refs>
    <vuln_soft>
      <prod vendor="jaws" name="jaws">
        <vers num="0.2" />
        <vers num="0.3" />
        <vers num="0.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-2068" published="2004-12-31" name="CVE-2004-2068" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">fetchnews in leafnode 1.9.47 and earlier allows remote attackers to cause a denial of service (process hang) via an emptry NNTP news article with missing mandatory headers.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/10590" source="SECUNIA" patch="1">10590</ref>
      <ref url="http://leafnode.sourceforge.net/leafnode-SA-2004-01.txt" source="CONFIRM" patch="1">http://leafnode.sourceforge.net/leafnode-SA-2004-01.txt</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/14189" source="XF">leafnode-fetchnews-nntp-dos(14189)</ref>
      <ref url="http://www.osvdb.org/3441" source="OSVDB">3441</ref>
      <ref url="http://www.derkeiler.com/Mailing-Lists/VulnWatch/2004-01/0009.html" source="VULNWATCH">20040109 leafnode -1.9.47 security announcement SA-2004-01</ref>
    </refs>
    <vuln_soft>
      <prod vendor="leafnode" name="leafnode">
        <vers num="1.9.25" />
        <vers num="1.9.26" />
        <vers num="1.9.27" />
        <vers num="1.9.28" />
        <vers num="1.9.29" />
        <vers num="1.9.30" />
        <vers num="1.9.31" />
        <vers num="1.9.32" />
        <vers num="1.9.33" />
        <vers num="1.9.34" />
        <vers num="1.9.35" />
        <vers num="1.9.36" />
        <vers num="1.9.37" />
        <vers num="1.9.38" />
        <vers num="1.9.39" />
        <vers num="1.9.40" />
        <vers num="1.9.41" />
        <vers num="1.9.42" />
        <vers num="1.9.43" />
        <vers num="1.9.44" />
        <vers num="1.9.45" />
        <vers num="1.9.46" />
        <vers num="1.9.47" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-2069" published="2004-12-31" name="CVE-2004-2069" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">sshd.c in OpenSSH 3.6.1p2 and 3.7.1p2 and possibly other versions, when using privilege separation, does not properly signal the non-privileged process when a session has been terminated after exceeding the LoginGraceTime setting, which leaves the connection open and allows remote attackers to cause a denial of service (connection consumption).</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=openssh-unix-dev&amp;m=107529205602320&amp;w=2" source="MLIST" patch="1">[openssh-unix-dev] 20040128 Re: OpenSSH - Connection problem when LoginGraceTime exceeds time</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/20930" source="XF">openssh-sshdc-logingracetime-dos(20930)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/4502" source="VUPEN">ADV-2006-4502</ref>
      <ref url="http://www.securityfocus.com/bid/14963" source="BID">14963</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/425397/100/0/threaded" source="FEDORA">FLSA-2006:168935</ref>
      <ref url="http://www.osvdb.org/16567" source="OSVDB">16567</ref>
      <ref url="http://support.avaya.com/elmodocs2/security/ASA-2005-223.pdf" source="CONFIRM">http://support.avaya.com/elmodocs2/security/ASA-2005-223.pdf</ref>
      <ref url="http://support.avaya.com/elmodocs2/security/ASA-2005-216.pdf" source="CONFIRM">http://support.avaya.com/elmodocs2/security/ASA-2005-216.pdf</ref>
      <ref url="http://secunia.com/advisories/17252" source="SECUNIA">17252</ref>
      <ref url="http://secunia.com/advisories/17135" source="SECUNIA">17135</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2005-550.html" source="REDHAT">RHSA-2005:550</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11541" source="OVAL">oval:org.mitre.oval:def:11541</ref>
      <ref url="http://marc.theaimsgroup.com/?l=openssh-unix-dev&amp;m=107520317020444&amp;w=2" source="MLIST">[openssh-unix-dev] 20040127 OpenSSH - Connection problem when LoginGraceTime exceeds time</ref>
      <ref url="http://www.vmware.com/support/vi3/doc/esx-9986131-patch.html" source="CONFIRM">http://www.vmware.com/support/vi3/doc/esx-9986131-patch.html</ref>
      <ref url="http://www.vmware.com/support/vi3/doc/esx-3069097-patch.html" source="CONFIRM">http://www.vmware.com/support/vi3/doc/esx-3069097-patch.html</ref>
      <ref url="http://www.vmware.com/download/esx/esx-213-200610-patch.html" source="CONFIRM">http://www.vmware.com/download/esx/esx-213-200610-patch.html</ref>
      <ref url="http://www.vmware.com/download/esx/esx-202-200610-patch.html" source="CONFIRM">http://www.vmware.com/download/esx/esx-202-200610-patch.html</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/451426/100/200/threaded" source="BUGTRAQ">20061113 VMSA-2006-0008 - VMware ESX Server 2.0.2 Upgrade Patch 2</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/451417/100/200/threaded" source="BUGTRAQ">20061113 VMSA-2006-0007 - VMware ESX Server 2.1.3 Upgrade Patch 2</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/451404/100/0/threaded" source="BUGTRAQ">20061113 VMSA-2006-0006 - VMware ESX Server 2.5.3 Upgrade Patch 4</ref>
      <ref url="http://secunia.com/advisories/23680" source="SECUNIA">23680</ref>
      <ref url="http://secunia.com/advisories/22875" source="SECUNIA">22875</ref>
      <ref url="http://secunia.com/advisories/17000" source="SECUNIA">17000</ref>
    </refs>
    <vuln_soft>
      <prod vendor="openbsd" name="openssh">
        <vers num="3.6.1p2" />
        <vers num="3.7.1p2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-2070" published="2004-12-31" name="CVE-2004-2070" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">The Altiris Client Service for Windows 5.6 SP1 Hotfix E (5.6.181) allows local users to execute arbitrary commands by opening the AClient tray icon and using the View Log File option, a different vulnerability than CVE-2005-1590.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/381649" source="BUGTRAQ">20041119 Privilege escalation flaw in AClient Service for Windows (Version 5.6.181).</ref>
    </refs>
  </entry>
  <entry type="CVE" severity="High" seq="2004-2071" published="2004-12-31" name="CVE-2004-2071" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Macallan Mail Solution 2.8.4.6 (Build 260), and possibly earlier versions, allows remote attackers to bypass authentication in the web interface via an HTTP GET request with two slashes ("//") after the server name.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/15194" source="XF">macallan-gain-unauthorized-access(15194)</ref>
      <ref url="http://www.securityfocus.com/bid/9646" source="BID">9646</ref>
      <ref url="http://www.osvdb.org/3926" source="OSVDB">3926</ref>
      <ref url="http://securitytracker.com/id?1009030" source="SECTRACK">1009030</ref>
      <ref url="http://secunia.com/advisories/10861" source="SECUNIA">10861</ref>
    </refs>
    <vuln_soft>
      <prod vendor="macallan" name="mail_solution">
        <vers num="2.8.4.6_build_260" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-2072" published="2004-12-31" name="CVE-2004-2072" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in index.php for Mambo Open Source 4.6, and possibly earlier versions, allows remote attackers to execute script on other clients via the Itemid parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/15062" source="XF">mambo-itemid-xss(15062)</ref>
      <ref url="http://www.systemsecure.org/advisories/ssadvisory06022004.php" source="MISC">http://www.systemsecure.org/advisories/ssadvisory06022004.php</ref>
      <ref url="http://www.securityfocus.com/bid/9588" source="BID">9588</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mambo" name="mambo_open_source">
        <vers num="4.6" edition="" />
        <vers num="4.6" edition=":cvs" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-2073" published="2004-02-06" name="CVE-2004-2073" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Linux-VServer 1.24 allows local users with root privileges on a virtual server to gain access to the filesystem outside the virtual server via a modified chroot-again exploit using the chmod command.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.linux-vserver.org/index.php?page=ChangeLog" source="CONFIRM" patch="1" adv="1">http://www.linux-vserver.org/index.php?page=ChangeLog</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15073" source="XF" adv="1">linux-vserver-gain-privileges(15073)</ref>
      <ref url="http://www.securityfocus.com/bid/9596" source="BID" adv="1">9596</ref>
      <ref url="http://www.securityfocus.com/archive/1/353003" source="BUGTRAQ" adv="1">20040206 Linux 2.4.24 with vserver 1.24 exploit</ref>
      <ref url="http://www.osvdb.org/3875" source="OSVDB">3875</ref>
      <ref url="http://secunia.com/advisories/10816" source="SECUNIA">10816</ref>
    </refs>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-2074" published="2004-12-31" name="CVE-2004-2074" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Format string vulnerability in Dream FTP 1.02 allows local users to cause a denial of service (crash) via format string specifiers in the (1) PASS or (2) RETR commands.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/15380" source="XF">dreamftp-command-format-string(15380)</ref>
      <ref url="http://www.securityfocus.com/bid/9800" source="BID">9800</ref>
      <ref url="http://securitytracker.com/id?1009295" source="SECTRACK">1009295</ref>
    </refs>
    <vuln_soft>
      <prod vendor="bolintech" name="dream_ftp_server">
        <vers num="1.02" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-2075" published="2004-12-31" name="CVE-2004-2075" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Sophos Anti-Virus 3.78 allows remote attackers to cause a denial of service (infinite loop) via a MIME header that is not properly terminated.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input bound="1" />
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/9648" source="BID" patch="1">9648</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15191" source="XF">sophos-mime-header-dos(15191)</ref>
      <ref url="http://www.sophos.com/support/news/#mime-378" source="CONFIRM">http://www.sophos.com/support/news/#mime-378</ref>
      <ref url="http://www.osvdb.org/3925" source="OSVDB">3925</ref>
      <ref url="http://securitytracker.com/id?1009042" source="SECTRACK">1009042</ref>
      <ref url="http://secunia.com/advisories/10855" source="SECUNIA">10855</ref>
    </refs>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-2076" published="2004-12-31" name="CVE-2004-2076" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in search.php for Jelsoft vBulletin 3.0.0 RC4 allows remote attackers to inject arbitrary web script or HTML via the query parameter.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/15208" source="XF">vbulletin-search-xss(15208)</ref>
      <ref url="http://www.securityfocus.com/bid/9656" source="BID">9656</ref>
      <ref url="http://www.securityfocus.com/archive/1/353869" source="BUGTRAQ">20040213 vBulletin PHP Forum Version</ref>
    </refs>
    <vuln_soft>
      <prod vendor="jelsoft" name="vbulletin">
        <vers num="3.0.0_rc4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-2077" published="2004-02-08" name="CVE-2004-2077" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Nadeo Game Engine for Nadeo TrackMania and Nadeo Virtual Skipper 3 allows remote attackers to cause a denial of service (server crash) via malformed data to TCP port 2350, possibly due to long values or incorrect size fields.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/15081" source="XF" adv="1">trackmania-dos(15081)</ref>
      <ref url="http://www.securityfocus.com/bid/9604" source="BID" adv="1">9604</ref>
      <ref url="http://www.securityfocus.com/archive/1/353226" source="BUGTRAQ" adv="1">20040209 Re: TrackMania Demo Denial of Service</ref>
      <ref url="http://www.securityfocus.com/archive/1/353182" source="BUGTRAQ" adv="1">20040208 TrackMania Demo Denial of Service</ref>
      <ref url="http://www.securiteinfo.com/attaques/hacking/trackmaniados.shtml" source="MISC" adv="1">http://www.securiteinfo.com/attaques/hacking/trackmaniados.shtml</ref>
    </refs>
    <vuln_soft>
      <prod vendor="nadeo" name="game_engine">
        <vers num="" />
      </prod>
      <prod vendor="nadeo" name="trackmania">
        <vers num="" />
      </prod>
      <prod vendor="nadeo" name="virtual_skipper">
        <vers num="3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-2078" published="2004-02-09" name="CVE-2004-2078" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Red-M Red-Alert 2.7.5 with software 3.1 build 24 allows remote attackers to cause a denial of service (reboot and loss of logged events) via a long request to TCP port 80, possibly triggering a buffer overflow.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://securitytracker.com/id?1009001" source="SECTRACK" patch="1" adv="1">1009001</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15086" source="XF" adv="1">redalert-long-request-dos(15086)</ref>
      <ref url="http://www.securityfocus.com/bid/9618" source="BID" adv="1">9618</ref>
      <ref url="http://www.securityfocus.com/archive/1/353211" source="BUGTRAQ" adv="1">20040209 Red-M Red-Alert Multiple Vulnerabilities</ref>
      <ref url="http://www.securiteam.com/securitynews/5SP0C0KC0A.html" source="MISC" adv="1">http://www.securiteam.com/securitynews/5SP0C0KC0A.html</ref>
      <ref url="http://www.osvdb.org/3891" source="OSVDB" adv="1">3891</ref>
      <ref url="http://secunia.com/advisories/10832" source="SECUNIA" adv="1">10832</ref>
      <ref url="http://genhex.org/releases/031003.txt" source="MISC" adv="1">http://genhex.org/releases/031003.txt</ref>
      <ref url="http://marc.theaimsgroup.com/?l=full-disclosure&amp;m=107635119005407&amp;w=2" source="FULLDISC">20040209 Red-M Red-Alert Multiple Vulnerabilities</ref>
    </refs>
    <vuln_soft>
      <prod vendor="red-m" name="red-alert">
        <vers num="2.7.5_v3.1_build_24" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-2079" published="2004-02-09" name="CVE-2004-2079" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Red-M Red-Alert 2.7.5 with software 3.1 build 24 binds authentication to IP addresses, which allows remote attackers to bypass authentication by connecting from the same IP address as an active authenticated user.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://securitytracker.com/id?1009001" source="SECTRACK" patch="1" adv="1">1009001</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15088" source="XF" adv="1">redalert-gain-access(15088)</ref>
      <ref url="http://www.securityfocus.com/bid/9618" source="BID" adv="1">9618</ref>
      <ref url="http://www.securityfocus.com/archive/1/353211" source="BUGTRAQ" adv="1">20040209 Red-M Red-Alert Multiple Vulnerabilities</ref>
      <ref url="http://www.securiteam.com/securitynews/5SP0C0KC0A.html" source="MISC" adv="1">http://www.securiteam.com/securitynews/5SP0C0KC0A.html</ref>
      <ref url="http://genhex.org/releases/031003.txt" source="MISC" adv="1">http://genhex.org/releases/031003.txt</ref>
      <ref url="http://www.osvdb.org/3952" source="OSVDB">3952</ref>
      <ref url="http://marc.theaimsgroup.com/?l=full-disclosure&amp;m=107635119005407&amp;w=2" source="FULLDISC">20040209 Red-M Red-Alert Multiple Vulnerabilities</ref>
    </refs>
    <vuln_soft>
      <prod vendor="red-m" name="red-alert">
        <vers num="2.7.5_v3.1_build_24" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-2080" published="2004-02-09" name="CVE-2004-2080" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Red-M Red-Alert 2.7.5 with software 3.1 build 24 converts multiple spaces in a Service Set Identifier (SSID) to a single space, which prevents Red-Alert from correctly identifying the SSID.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://securitytracker.com/id?1009001" source="SECTRACK" patch="1" adv="1">1009001</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15089" source="XF" adv="1">redalert-bypass-security(15089)</ref>
      <ref url="http://www.securityfocus.com/bid/9618" source="BID" adv="1">9618</ref>
      <ref url="http://www.securityfocus.com/archive/1/353211" source="BUGTRAQ" adv="1">20040209 Red-M Red-Alert Multiple Vulnerabilities</ref>
      <ref url="http://www.securiteam.com/securitynews/5SP0C0KC0A.html" source="MISC" adv="1">http://www.securiteam.com/securitynews/5SP0C0KC0A.html</ref>
      <ref url="http://genhex.org/releases/031003.txt" source="MISC" adv="1">http://genhex.org/releases/031003.txt</ref>
      <ref url="http://www.osvdb.org/3953" source="OSVDB">3953</ref>
      <ref url="http://marc.theaimsgroup.com/?l=full-disclosure&amp;m=107635119005407&amp;w=2" source="FULLDISC">20040209 Red-M Red-Alert Multiple Vulnerabilities</ref>
    </refs>
    <vuln_soft>
      <prod vendor="red-m" name="red-alert">
        <vers num="2.7.5_v3.1_build_24" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-2081" published="2004-12-31" name="CVE-2004-2081" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The samiftp.dll library in Sami FTP Server 1.1.3 allows local users to cause a denial of service (pmsystem.exe crash) by issuing (1) a CD command with a tilde (~) character or dot dot (/../) or (2) a GET command for an unavailable file.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.karja.com/samiftp/news.html" source="MISC" patch="1" adv="1">http://www.karja.com/samiftp/news.html</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15204" source="XF" adv="1">sami-cd-get-dos(15204)</ref>
      <ref url="http://www.securityfocus.com/bid/9657" source="BID" adv="1">9657</ref>
      <ref url="http://www.securityfocus.com/archive/1/353753" source="BUGTRAQ">20040213 Sami FTP Server 1.1.3 multiple vulnerabilities</ref>
    </refs>
    <vuln_soft>
      <prod vendor="karjasoft" name="sami_ftp_server">
        <vers num="1.1.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-2082" published="2004-02-13" name="CVE-2004-2082" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The samiftp.dll library in Sami FTP Server 1.1.3 allows remote authenticated users to cause a denial of service (pmsystem.exe crash) via a GET request wit a large number of leading "/" (slash) characters.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.karja.com/samiftp/news.html" source="MISC" patch="1" adv="1">http://www.karja.com/samiftp/news.html</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15204" source="XF" adv="1">sami-cd-get-dos(15204)</ref>
      <ref url="http://www.securityfocus.com/bid/9657" source="BID" adv="1">9657</ref>
      <ref url="http://www.securityfocus.com/archive/1/353753" source="BUGTRAQ">20040213 Sami FTP Server 1.1.3 multiple vulnerabilities</ref>
    </refs>
    <vuln_soft>
      <prod vendor="karjasoft" name="sami_ftp_server">
        <vers num="1.1.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2004-2083" published="2004-02-11" name="CVE-2004-2083" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:P/A:N)" CVSS_score="2.6" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="4.9" CVSS_base_score="2.6">
    <desc>
      <descript source="cve">Opera Web Browser 7.0 through 7.23 allows remote attackers to trick users into executing a malicious file by embedding a CLSID in the file name, which causes the malicious file to appear as a trusted file type, aka "File Download Extension Spoofing."</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/9640" source="BID">9640</ref>
      <ref url="http://secunia.com/Internet_Explorer_File_Download_Extension_Spoofing_Test/" source="MISC" adv="1">http://secunia.com/Internet_Explorer_File_Download_Extension_Spoofing_Test/</ref>
      <ref url="http://secunia.com/advisories/10760" source="SECUNIA" adv="1">10760</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/21698" source="XF">opera-cslid-extension-spoof(21698)</ref>
      <ref url="http://www.osvdb.org/3917" source="OSVDB">3917</ref>
      <ref url="http://www.opera.com/docs/changelogs/windows/750b1/" source="CONFIRM">http://www.opera.com/docs/changelogs/windows/750b1/</ref>
    </refs>
    <vuln_soft>
      <prod vendor="opera_software" name="opera_web_browser">
        <vers num="7.0" edition="" />
        <vers num="7.0" edition=":win32" />
        <vers num="7.0.1" edition="" />
        <vers num="7.0.1" edition=":win32" />
        <vers num="7.0.2" edition="" />
        <vers num="7.0.2" edition=":win32" />
        <vers num="7.0.3" edition="" />
        <vers num="7.0.3" edition=":win32" />
        <vers num="7.0_beta1" edition="" />
        <vers num="7.0_beta1" edition=":win32" />
        <vers num="7.0_beta2" edition="" />
        <vers num="7.0_beta2" edition=":win32" />
        <vers num="7.10" />
        <vers num="7.11" />
        <vers num="7.11b" />
        <vers num="7.11j" />
        <vers num="7.20" />
        <vers num="7.20_beta1_build2981" />
        <vers num="7.21" />
        <vers num="7.22" />
        <vers num="7.23" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-2084" published="2004-02-07" name="CVE-2004-2084" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in search.php in JShop E-Commerce Server allows remote attackers to inject arbitrary web script or HTML via the xSearch parameter.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/15100" source="XF" patch="1" adv="1">jshop-searchphp-xss(15100)</ref>
      <ref url="http://www.osvdb.org/3889" source="OSVDB" patch="1">3889</ref>
      <ref url="http://www.systemsecure.org/advisories/ssadvisory09022004.php" source="MISC" adv="1">http://www.systemsecure.org/advisories/ssadvisory09022004.php</ref>
      <ref url="http://www.securityfocus.com/bid/9609" source="BID" adv="1">9609</ref>
      <ref url="http://securitytracker.com/id?1008988" source="SECTRACK" adv="1">1008988</ref>
      <ref url="http://secunia.com/advisories/10825" source="SECUNIA" adv="1">10825</ref>
    </refs>
    <vuln_soft>
      <prod vendor="jshop_e-commerce" name="jshop_professional">
        <vers num="3.0" />
        <vers num="3.1" />
        <vers num="3.2" />
        <vers num="3.3" />
        <vers num="3.4" />
      </prod>
      <prod vendor="jshop_e-commerce" name="jshop_server">
        <vers num="1.0.1" />
        <vers num="1.0.2" />
        <vers num="1.0.3" />
        <vers num="1.0.4" />
        <vers num="1.1.0" />
        <vers num="1.2.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-2085" published="2004-02-04" name="CVE-2004-2085" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in Brad Fears phpCodeCabinet 0.4 and earlier allow remote attackers to inject arbitrary web script or HTML via multiple parameters, including (1) the sid parameter to comments.php, (2) the cid, cf, or rfd parameters to category.php, or the cid parameter to (3) input.php, (4) browse.php, (5) themes/facade/header.php, or (6) themes/phpcc/header.php.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/15190" source="XF" patch="1" adv="1">phpcodecabinet-multiple-xss(15190)</ref>
      <ref url="http://www.securityfocus.com/bid/9645" source="BID" patch="1" adv="1">9645</ref>
      <ref url="http://www.securityfocus.com/bid/9601" source="BID" patch="1" adv="1">9601</ref>
      <ref url="http://www.osvdb.org/3887" source="OSVDB" patch="1" adv="1">3887</ref>
      <ref url="http://www.osvdb.org/3886" source="OSVDB" patch="1" adv="1">3886</ref>
      <ref url="http://www.osvdb.org/3885" source="OSVDB" adv="1">3885</ref>
      <ref url="http://sourceforge.net/project/shownotes.php?release_id=214860" source="CONFIRM" adv="1">http://sourceforge.net/project/shownotes.php?release_id=214860</ref>
      <ref url="http://cvs.sourceforge.net/viewcvs.py/phpcodecabinet/phpcc/themes/phpcc/header.php?r1=1.4&amp;r2=1.5" source="CONFIRM" adv="1">http://cvs.sourceforge.net/viewcvs.py/phpcodecabinet/phpcc/themes/phpcc/header.php?r1=1.4&amp;r2=1.5</ref>
      <ref url="http://cvs.sourceforge.net/viewcvs.py/phpcodecabinet/phpcc/themes/facade/header.php?r1=1.4&amp;r2=1.5" source="CONFIRM" adv="1">http://cvs.sourceforge.net/viewcvs.py/phpcodecabinet/phpcc/themes/facade/header.php?r1=1.4&amp;r2=1.5</ref>
      <ref url="http://cvs.sourceforge.net/viewcvs.py/phpcodecabinet/phpcc/input.php?r1=1.7&amp;r2=1.8" source="CONFIRM" adv="1">http://cvs.sourceforge.net/viewcvs.py/phpcodecabinet/phpcc/input.php?r1=1.7&amp;r2=1.8</ref>
      <ref url="http://cvs.sourceforge.net/viewcvs.py/phpcodecabinet/phpcc/comments.php?r1=1.1&amp;r2=1.2" source="CONFIRM" adv="1">http://cvs.sourceforge.net/viewcvs.py/phpcodecabinet/phpcc/comments.php?r1=1.1&amp;r2=1.2</ref>
      <ref url="http://cvs.sourceforge.net/viewcvs.py/phpcodecabinet/phpcc/category.php?r1=1.4&amp;r2=1.5" source="CONFIRM" adv="1">http://cvs.sourceforge.net/viewcvs.py/phpcodecabinet/phpcc/category.php?r1=1.4&amp;r2=1.5</ref>
      <ref url="http://cvs.sourceforge.net/viewcvs.py/phpcodecabinet/phpcc/browse.php?r1=1.5&amp;r2=1.6" source="CONFIRM" adv="1">http://cvs.sourceforge.net/viewcvs.py/phpcodecabinet/phpcc/browse.php?r1=1.5&amp;r2=1.6</ref>
      <ref url="http://www.osvdb.org/16711" source="OSVDB">16711</ref>
      <ref url="http://www.osvdb.org/16710" source="OSVDB">16710</ref>
      <ref url="http://securitytracker.com/id?1009012" source="SECTRACK">1009012</ref>
      <ref url="http://secunia.com/advisories/10862" source="SECUNIA">10862</ref>
    </refs>
    <vuln_soft>
      <prod vendor="brad_fears" name="phpcodecabinet">
        <vers num="0.1" />
        <vers num="0.2" />
        <vers num="0.3" />
        <vers num="0.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-2086" published="2004-02-06" name="CVE-2004-2086" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Stack-based buffer overflow in results.stm for Sambar Server before the 6.0 production release allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via an HTTP POST request with a long query parameter.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.sambar.com/security.htm" source="CONFIRM" patch="1" adv="1">http://www.sambar.com/security.htm</ref>
      <ref url="http://www.osvdb.org/5786" source="OSVDB" patch="1" adv="1">5786</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15071" source="XF" adv="1">sambar-http-post-bo(15071)</ref>
      <ref url="http://www.securityfocus.com/bid/9607" source="BID" adv="1">9607</ref>
      <ref url="http://www.securityfocus.com/archive/82/353087" source="VULN-DEV" adv="1">20040207 Sambar 6.0 stack overflow</ref>
      <ref url="http://securitytracker.com/id?1008979" source="SECTRACK" adv="1">1008979</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sambar" name="sambar_server">
        <vers num="6.0" edition="beta3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-2087" published="2004-02-08" name="CVE-2004-2087" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Unknown vulnerability in SandSurfer before 1.7.0 allows remote attackers to gain access as a logged-in user.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/15193" source="XF" patch="1" adv="1">sandsurfer-gain-access(15193)</ref>
      <ref url="http://www.securityfocus.com/bid/9647" source="BID" patch="1" adv="1">9647</ref>
      <ref url="http://sourceforge.net/forum/forum.php?forum_id=351705" source="CONFIRM" patch="1" adv="1">http://sourceforge.net/forum/forum.php?forum_id=351705</ref>
      <ref url="http://securitytracker.com/id?1009110" source="SECTRACK" patch="1" adv="1">1009110</ref>
      <ref url="http://secunia.com/advisories/10829" source="SECUNIA" patch="1" adv="1">10829</ref>
      <ref url="http://www.osvdb.org/3922" source="OSVDB">3922</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sandsurfer" name="sandsurfer">
        <vers num="1.6.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-2088" published="2004-02-12" name="CVE-2004-2088" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Sophos Anti-Virus 3.78 allows remote attackers to bypass virus scanning by using a qmail generated Delivery Status Notification (DSN) where the original email is not included in the bounce message.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/15192" source="XF" patch="1" adv="1">sophos-email-virus-undetected(15192)</ref>
      <ref url="http://www.sophos.com/support/news/#mime-378" source="CONFIRM" patch="1">http://www.sophos.com/support/news/#mime-378</ref>
      <ref url="http://www.securityfocus.com/bid/9650" source="BID" patch="1" adv="1">9650</ref>
      <ref url="http://securitytracker.com/id?1009042" source="SECTRACK">1009042</ref>
      <ref url="http://secunia.com/advisories/10855" source="SECUNIA">10855</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sophos" name="sophos_anti-virus">
        <vers num="3.4.6" />
        <vers num="3.78" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-2089" published="2004-02-06" name="CVE-2004-2089" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Matrix FTP Server allows remote attackers to cause a denial of service (crash) by logging in using four spaces as the username and password and then issuing a LIST command.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <access />
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/15075" source="XF" adv="1">matrixftp-login-list-dos(15075)</ref>
      <ref url="http://securitytracker.com/id?1008970" source="SECTRACK" adv="1">1008970</ref>
    </refs>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-2090" published="2004-02-07" name="CVE-2004-2090" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Microsoft Internet Explorer 5.0.1 through 6.0 allows remote attackers to determine the existence of arbitrary files via the VBScript LoadPicture method, which returns an error code if the file does not exist.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/15078" source="XF" adv="1">ie-error-obtain-information(15078)</ref>
      <ref url="http://www.securityfocus.com/bid/9611" source="BID" adv="1">9611</ref>
      <ref url="http://secunia.com/advisories/10820" source="SECUNIA" adv="1">10820</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2004-February/016881.html" source="FULLDISC" adv="1">20040207 (no subject)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="ie">
        <vers num="5.0.1" edition="sp1" />
        <vers num="5.0.1" edition="sp2" />
        <vers num="5.0.1" edition="sp3" />
        <vers num="5.0.1" edition="sp4" />
        <vers num="5.5" edition="sp1" />
        <vers num="5.5" edition="sp2" />
        <vers num="6.0" edition="sp1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-2091" published="2004-02-10" name="CVE-2004-2091" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Microsoft Baseline Security Analyzer (MBSA) 1.2 does not correctly identify systems that have been patched but remain vulnerable to exploit until the system is rebooted, possibly giving the administrator a false sense of security.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <other />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/9634" source="BID" adv="1">9634</ref>
      <ref url="http://www.securityfocus.com/archive/1/353324" source="BUGTRAQ" adv="1">20040210 Another Low Blow From Microsoft: MBSA Failure!</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="baseline_security_analyzer">
        <vers num="1.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-2092" published="2004-02-09" name="CVE-2004-2092" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">eTrust InoculateIT for Linux 6.0 uses insecure permissions for multiple files and directories, including the application's registry and tmp directories, which allows local users to delete, modify, or examine sensitive information.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/15103" source="XF" adv="1">etrust-inoculateit-insecure-permissions(15103)</ref>
      <ref url="http://www.securityfocus.com/bid/9616" source="BID">9616</ref>
      <ref url="http://www.osvdb.org/3896" source="OSVDB" adv="1">3896</ref>
      <ref url="http://secunia.com/advisories/10833" source="SECUNIA" adv="1">10833</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107635584431518&amp;w=2" source="BUGTRAQ" adv="1">20040209 [local problems] eTrust Virus Protection 6.0 InoculateIT for linux</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ca" name="inoculateit">
        <vers num="6.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-2093" published="2004-02-09" name="CVE-2004-2093" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Buffer overflow in the open_socket_out function in socket.c for rsync 2.5.7 and earlier allows local users to cause a denial of service (crash) and possibly execute arbitrary code via a long RSYNC_PROXY environment variable.  NOTE: since rsync is not setuid, this issue does not provide any additional privileges beyond those that are already available to the user.  Therefore this issue may be REJECTED in the future.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/15108" source="XF" patch="1">linux-rsync-opensocketout-bo(15108)</ref>
      <ref url="http://archives.neohapsis.com/archives/vuln-dev/2004-q1/0091.html" source="VULN-DEV" adv="1">20040209 rsync &lt;= 2.5.7 local buffer overflow (no root today:)</ref>
    </refs>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-2094" published="2004-12-31" name="CVE-2004-2094" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in WebcamXP 1.06.945 allows remote attackers to inject arbitrary HTML or web script as other users via a URL that contains the script.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/14904" source="XF">webcamxp-xss(14904)</ref>
      <ref url="http://www.securityfocus.com/bid/9465" source="BID">9465</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107471195326270&amp;w=2" source="BUGTRAQ">20040121 WebcamXP v1.06.945 Cross Site Scripting Vulnerabillity</ref>
    </refs>
    <vuln_soft>
      <prod vendor="darkwet" name="webcam_xp">
        <vers num="1.6.945" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-2095" published="2004-12-31" name="CVE-2004-2095" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Honeyd before 0.8 replies to TCP packets with the SYN and RST flags set, which allows remote attackers to identify IP addresses that are being simulated by Honeyd.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/14905" source="XF">honeyd-nmap-information-disclosure(14905)</ref>
      <ref url="http://www.securityfocus.com/bid/9464" source="BID">9464</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107473095118505&amp;w=2" source="BUGTRAQ">20040121 [ GLSA 200401-02 ] Honeyd remote detection vulnerability via a probe packet</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107471181426047&amp;w=2" source="BUGTRAQ">20040121 Honeyd Security Advisory 2004-001: Remote Detection Via Simple Probe Packet</ref>
      <ref url="http://www.securitytracker.com/id?1008818" source="SECTRACK">1008818</ref>
      <ref url="http://www.osvdb.org/3690" source="OSVDB">3690</ref>
      <ref url="http://secunia.com/advisories/10695" source="SECUNIA">10695</ref>
      <ref url="http://secunia.com/advisories/10694" source="SECUNIA">10694</ref>
    </refs>
    <vuln_soft>
      <prod vendor="niels_provos" name="honeyd">
        <vers num="0.5" />
        <vers num="0.6" />
        <vers num="0.6a" />
        <vers num="0.7" />
        <vers num="0.7a" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-2096" published="2004-12-31" name="CVE-2004-2096" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in Mephistoles httpd 0.6.0 final allows remote attackers to execute arbitrary script as other users by injecting arbitrary HTML or script into the URL.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/9470" source="BID" patch="1">9470</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107470433714179&amp;w=2" source="BUGTRAQ" patch="1">20040121 Mephistoles Httpd 0.6.0final XSS</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/14899" source="XF">mephistoles-httpd-xss(14899)</ref>
      <ref url="http://www.osvdb.org/3689" source="OSVDB">3689</ref>
      <ref url="http://secunia.com/advisories/10693" source="SECUNIA">10693</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mephistoles_internet_suite" name="mephistoles_httpd">
        <vers num="0.6_final" />
        <vers num="0.6_p1" />
        <vers num="0.6_p2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2004-2097" published="2004-12-31" name="CVE-2004-2097" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">Multiple scripts on SuSE Linux 9.0 allow local users to overwrite arbitrary files via a symlink attack on (1) /tmp/fvwm-bug created by fvwm-bug, (2) /tmp/wmmenu created by wm-oldmenu2new, (3) /tmp/rates created by x11perfcomp, (4) /tmp/xf86debug.1.log created by xf86debug, (5) /tmp/.winpopup-new created by winpopup-send.sh, or (6) /tmp/initrd created by lvmcreate_initrd.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/14963" source="XF">suse-multiple-symlink-attack(14963)</ref>
      <ref url="http://www.securityfocus.com/bid/9457" source="BID">9457</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107478920006258&amp;w=2" source="BUGTRAQ">20040122 Re: [SuSE 9.0] possible symlink attacks in some scripts</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107461582413923&amp;w=2" source="BUGTRAQ">20040121 [SuSE 9.0] possible symlink attacks in some scripts</ref>
      <ref url="http://securitytracker.com/id?1008781" source="SECTRACK">1008781</ref>
    </refs>
    <vuln_soft>
      <prod vendor="suse" name="suse_linux">
        <vers num="9.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-2098" published="2004-12-31" name="CVE-2004-2098" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in the banner engine (TBE) 5.0 allows remote attackers to execute arbitrary script as other users via the HTML banner view/preview capability.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/14911" source="XF">tbe-xss(14911)</ref>
      <ref url="http://www.securityfocus.com/bid/9472" source="BID">9472</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107479071808330&amp;w=2" source="BUGTRAQ">20040122 TBE - the banner engine server-side script execution vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="native_solutions" name="tbe_banner_engine">
        <vers num="4.0" />
        <vers num="5.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-2099" published="2004-12-31" name="CVE-2004-2099" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_score="5.1" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="4.9" CVSS_base_score="5.1">
    <desc>
      <descript source="cve">Buffer overflow in Need for Speed Hot Pursuit 2.0 client (NFSHP2), version 242 and earlier, allows remote attackers (servers) to execute arbitrary code via long (1) gamename, (2) gamever, (3) hostname, (4) gametype, (5) mapname or (6) gamemode commands.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/14909" source="XF">hotpursuit2-bo(14909)</ref>
      <ref url="http://www.securityfocus.com/bid/9473" source="BID">9473</ref>
      <ref url="http://aluigi.altervista.org/adv/nfshp2cbof-adv.txt" source="MISC">http://aluigi.altervista.org/adv/nfshp2cbof-adv.txt</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107479094508691&amp;w=2" source="BUGTRAQ">20040122 Need for Speed Hot pursuit 2 &lt;= 242 client's buffer overflow</ref>
    </refs>
    <vuln_soft>
      <prod vendor="electronic_arts" name="need_for_speed_hot_pursuit_2">
        <vers prev="1" num="242.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-2100" published="2004-12-31" name="CVE-2004-2100" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">GeoHttpServer, when configured to authenticate users, allows remote attackers to bypass authentication and access unauthorized files via a URL that contains %0a%0a (encoded newlines).</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <access />
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107480261825214&amp;w=2" source="BUGTRAQ">20040122 GeoHttpServer Authentification Bypass Vulnerability &amp; D.O.S (Denial Of Service)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="geovision" name="geohttpserver">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-2101" published="2004-12-31" name="CVE-2004-2101" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The sysinfo script in GeoHttpServer allows remote attackers to cause a denial of service (crash) via a long pwd parameter, possibly triggering a buffer overflow.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/14913" source="XF">geohttpserver-long-password-bo(14913)</ref>
      <ref url="http://securitytracker.com/id?1008807" source="SECTRACK">1008807</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107480261825214&amp;w=2" source="BUGTRAQ">20040122 GeoHttpServer Authentification Bypass Vulnerability &amp; D.O.S (Denial Of Service)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="geovision" name="geohttpserver">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-2102" published="2004-12-31" name="CVE-2004-2102" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in FREESCO 2.05, a modified version of thttpd, allows remote attackers to inject arbitrary web script or HTML via the test parameter.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/14916" source="XF">freesco-thttpd-xss(14916)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107480309925905&amp;w=2" source="BUGTRAQ">20040122 FREESCO public http server - Cross Site Scripting Vulnerabillity</ref>
    </refs>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-2103" published="2004-12-31" name="CVE-2004-2103" modified="2009-07-01" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in Novell NetWare Enterprise Web Server 5.1 and 6.0 allows remote attackers to process arbitrary script or HTML as other users via (1) a malformed request for a Perl program with script in the filename, (2) the User.id parameter to the webacc servlet, (3) the GWAP.version parameter to webacc, or (4) a URL request for a .bas file with script in the filename.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/14919" source="XF">netware-enterprise-cgi2perl-xss(14919)</ref>
      <ref url="http://support.novell.com/cgi-bin/search/searchtid.cgi?/10091529.htm" source="CONFIRM">http://support.novell.com/cgi-bin/search/searchtid.cgi?/10091529.htm</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107487862304440&amp;w=2" source="BUGTRAQ">20040123 NetWare-Enterprise-Web-Server/5.1/6.0 Multiple Vulnerabilities</ref>
      <ref url="http://www.osvdb.org/4949" source="OSVDB">4949</ref>
    </refs>
    <vuln_soft>
      <prod vendor="novell" name="netware">
        <vers num="5.1" />
        <vers num="6.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-2104" published="2004-12-31" name="CVE-2004-2104" modified="2009-01-29" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Novell NetWare Enterprise Web Server 5.1 and 6.0 allows remote attackers to obtain sensitive server information, including the internal IP address, via a direct request to (1) snoop.jsp, (2) SnoopServlet, (3) env.bas, or (4) lcgitest.nlm.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.osvdb.org/4952" source="OSVDB">4952</ref>
      <ref url="http://secunia.com/advisories/10711" source="SECUNIA">10711</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107487862304440&amp;w=2" source="BUGTRAQ">20040123 NetWare-Enterprise-Web-Server/5.1/6.0 Multiple Vulnerabilities</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/14921" source="XF">netware-enterprise-path-disclosure(14921)</ref>
      <ref url="http://www.securityfocus.com/bid/9479" source="BID">9479</ref>
      <ref url="http://www.osvdb.org/3722" source="OSVDB">3722</ref>
      <ref url="http://www.osvdb.org/3721" source="OSVDB">3721</ref>
      <ref url="http://www.osvdb.org/3720" source="OSVDB">3720</ref>
      <ref url="http://www.osvdb.org/3715" source="OSVDB">3715</ref>
    </refs>
    <vuln_soft>
      <prod vendor="novell" name="netware">
        <vers num="5.1" />
        <vers num="6.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-2105" published="2004-12-31" name="CVE-2004-2105" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The webacc servlet in Novell NetWare Enterprise Web Server 5.1 and 6.0 allows remote attackers to read arbitrary .htt files via a full pathname in the error parameter.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107487862304440&amp;w=2" source="BUGTRAQ">20040123 NetWare-Enterprise-Web-Server/5.1/6.0 Multiple Vulnerabilities</ref>
    </refs>
    <vuln_soft>
      <prod vendor="novell" name="netware">
        <vers num="5.1" />
        <vers num="6.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-2106" published="2004-12-31" name="CVE-2004-2106" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Novell NetWare Enterprise Web Server 5.1 and 6.0 allows remote attackers to list directories via a direct request to (1) /com/, (2) /com/novell/, (3) /com/novell/webaccess, or (4) /ns-icons/.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107487862304440&amp;w=2" source="BUGTRAQ">20040123 NetWare-Enterprise-Web-Server/5.1/6.0 Multiple Vulnerabilities</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/21749" source="XF">netware-enterprise-directory-disclosure(21749)</ref>
      <ref url="http://www.osvdb.org/13404" source="OSVDB">13404</ref>
      <ref url="http://www.osvdb.org/13403" source="OSVDB">13403</ref>
      <ref url="http://www.osvdb.org/13402" source="OSVDB">13402</ref>
    </refs>
    <vuln_soft>
      <prod vendor="novell" name="netware">
        <vers num="5.1" />
        <vers num="6.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-2107" published="2004-12-31" name="CVE-2004-2107" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Finjan SurfinGate 6.0 and 7.0, when running in proxy mode, does not authenticate FHTTP commands on TCP port 3141, which allows remote attackers to use the finjan-parameter-type header to (1) restart the service, (2) use the getlastmsg command to view log information, or (3) use the online command to force a policy update from the database server.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/9478" source="BID" patch="1">9478</ref>
      <ref url="http://secunia.com/advisories/10714" source="SECUNIA" patch="1">10714</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107522480913629&amp;w=2" source="BUGTRAQ" patch="1">20040126 RE: Finjan SurfinGate Vulnerability</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107487999406339&amp;w=2" source="BUGTRAQ" patch="1">20040123 Finjan SurfinGate Vulnerability</ref>
      <ref url="http://archives.neohapsis.com/archives/fulldisclosure/2004-01/0929.html" source="FULLDISC" patch="1">20040123 Finjan SurfinGate Vulnerability</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/14934" source="XF">finjan-surfingate-execute-commands(14934)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="finjan_software" name="surfingate">
        <vers num="6.0" />
        <vers num="6.0_1" />
        <vers num="6.0_5" />
        <vers num="7.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-2108" published="2004-12-31" name="CVE-2004-2108" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple SQL injection vulnerabilities in QuadComm Q-Shop allow remote attackers to execute arbitrary SQL commands via certain parameters to (1) search.asp, (2) browse.asp, (3) details.asp, (4) showcat.asp, (5) users.asp, (6) addtomylist.asp, (7) modline.asp, (8) cart.asp, or (9) newuser.asp.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/14922" source="XF">qshop-multiple-sql-injection(14922)</ref>
      <ref url="http://www.securityfocus.com/bid/9481" source="BID">9481</ref>
      <ref url="http://www.s-quadra.com/advisories/Adv-20040123.txt" source="MISC">http://www.s-quadra.com/advisories/Adv-20040123.txt</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107488132208229&amp;w=2" source="BUGTRAQ">20040123 QuadComm Q-Shop ASP Shopping Cart Software multiple security vulnerabilities</ref>
      <ref url="http://www.osvdb.org/3706" source="OSVDB">3706</ref>
      <ref url="http://www.osvdb.org/3705" source="OSVDB">3705</ref>
      <ref url="http://www.osvdb.org/3704" source="OSVDB">3704</ref>
      <ref url="http://www.osvdb.org/3703" source="OSVDB">3703</ref>
      <ref url="http://www.osvdb.org/3702" source="OSVDB">3702</ref>
      <ref url="http://www.osvdb.org/3701" source="OSVDB">3701</ref>
      <ref url="http://www.osvdb.org/3700" source="OSVDB">3700</ref>
      <ref url="http://www.osvdb.org/3699" source="OSVDB">3699</ref>
      <ref url="http://www.osvdb.org/3698" source="OSVDB">3698</ref>
      <ref url="http://securitytracker.com/alerts/2004/Jan/1008837.html" source="SECTRACK">1008837</ref>
      <ref url="http://secunia.com/advisories/10704" source="SECUNIA">10704</ref>
    </refs>
    <vuln_soft>
      <prod vendor="quadcomm" name="q-shop">
        <vers num="2.0" />
        <vers num="2.1" />
        <vers num="2.5" />
        <vers num="2.5_beta" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-2109" published="2004-12-31" name="CVE-2004-2109" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in (1) imagezoom.asp or (2) recommend.asp in Q-Shop allow remote attackers to execute arbitrary script and steal the user session ID via Javascript in a URL.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/9480" source="BID" patch="1">9480</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/14923" source="XF">qshop-url-xss(14923)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107488132208229&amp;w=2" source="BUGTRAQ">20040123 QuadComm Q-Shop ASP Shopping Cart Software multiple security vulnerabilities</ref>
      <ref url="http://www.osvdb.org/3697" source="OSVDB">3697</ref>
      <ref url="http://www.osvdb.org/3696" source="OSVDB">3696</ref>
      <ref url="http://secunia.com/advisories/10704" source="SECUNIA">10704</ref>
    </refs>
    <vuln_soft>
      <prod vendor="quadcomm" name="q-shop">
        <vers num="2.0" />
        <vers num="2.1" />
        <vers num="2.5" />
        <vers num="2.5_beta" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-2110" published="2004-12-31" name="CVE-2004-2110" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in register.php in Phorum before 3.4.6 allows remote attackers to execute arbitrary SQL commands via the hide_email parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://phorum.org/" source="CONFIRM">http://phorum.org/</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107487971405960&amp;w=2" source="BUGTRAQ">20040123 Multiple Vulnerabilities in Phorum 3.4.5</ref>
    </refs>
    <vuln_soft>
      <prod vendor="phorum" name="phorum">
        <vers prev="1" num="3.4.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-2111" published="2004-12-31" name="CVE-2004-2111" modified="2010-04-27" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:S/C:C/I:C/A:C)" CVSS_score="8.5" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="6.8" CVSS_base_score="8.5">
    <desc>
      <descript source="cve">Stack-based buffer overflow in the site chmod command in Serv-U FTP Server before 4.2 allows remote attackers to execute arbitrary code via a long filename.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/14931" source="XF">servu-chmodcommand-execute-code(14931)</ref>
      <ref url="http://www.securityfocus.com/bid/9675" source="BID">9675</ref>
      <ref url="http://www.securityfocus.com/bid/9483" source="BID">9483</ref>
      <ref url="http://securitytracker.com/id?1008841" source="SECTRACK">1008841</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107513654005840&amp;w=2" source="BUGTRAQ">20040126 Serv-U ftp 4.2 site chmod long_file_name exploit</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2004-01/0249.html" source="BUGTRAQ">20040124 [SST]ServU MDTM command remote buffero verflow adv</ref>
    </refs>
    <vuln_soft>
      <prod vendor="serv-u" name="serv-u">
        <vers num="3.0.0.16" />
        <vers num="3.0.0.17" />
        <vers num="3.1.0.0" />
        <vers num="3.1.0.1" />
        <vers num="3.1.0.3" />
        <vers num="4.0.0.4" />
        <vers num="4.1.0.0" />
        <vers prev="1" num="4.1.0.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-2112" published="2004-12-31" name="CVE-2004-2112" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in BremsServer 1.2.4 allows remote attackers to read arbitrary files via ".." (dot dot) sequences in the URL.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/14954" source="XF">bremsserver-dotdot-directory-traversal(14954)</ref>
      <ref url="http://www.securityfocus.com/bid/9493" source="BID">9493</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107513747107031&amp;w=2" source="BUGTRAQ">20040126 Directory traversal and XSS in BremsServer 1.2.4</ref>
      <ref url="http://www.securitytracker.com/id?1008853" source="SECTRACK">1008853</ref>
      <ref url="http://www.osvdb.org/3755" source="OSVDB">3755</ref>
      <ref url="http://secunia.com/advisories/10731" source="SECUNIA">10731</ref>
    </refs>
    <vuln_soft>
      <prod vendor="herberlin" name="bremsserver">
        <vers num="1.2.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-2113" published="2004-12-31" name="CVE-2004-2113" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in BremsServer 1.2.4 allows remote attackers to inject arbitrary web script or HTML via the URL.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/14953" source="XF">bremsserver-xss(14953)</ref>
      <ref url="http://www.securityfocus.com/bid/9491" source="BID">9491</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107513747107031&amp;w=2" source="BUGTRAQ">20040126 Directory traversal and XSS in BremsServer 1.2.4</ref>
      <ref url="http://www.securitytracker.com/id?1008853" source="SECTRACK">1008853</ref>
      <ref url="http://www.osvdb.org/3754" source="OSVDB">3754</ref>
      <ref url="http://secunia.com/advisories/10731" source="SECUNIA">10731</ref>
    </refs>
    <vuln_soft>
      <prod vendor="herberlin" name="bremsserver">
        <vers num="1.2.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-2114" published="2004-12-31" name="CVE-2004-2114" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Stack-based and heap-based buffer overflows in ProxyNow! 2.75 and earlier allow remote attackers to execute arbitrary code via a GET request with a long ftp:// URL.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/14955" source="XF">proxynow-get-bo(14955)</ref>
      <ref url="http://www.securityfocus.com/bid/9500" source="BID">9500</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107515550931508&amp;w=2" source="BUGTRAQ">20040126 ProxyNow! 2.x Multiple Overflow Vulnerabilities</ref>
    </refs>
    <vuln_soft>
      <prod vendor="internetnow" name="proxynow">
        <vers num="2.6" />
        <vers num="2.75" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-2115" published="2004-12-31" name="CVE-2004-2115" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in Oracle HTTP Server 1.3.22, based on Apache, allow remote attackers to execute arbitrary script as other users via the (1) action, (2) username, or (3) password parameters in an isqlplus request.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/14930" source="XF">oraclehttpserver-isqlplus-xss(14930)</ref>
      <ref url="http://www.securityfocus.com/bid/9484" source="BID">9484</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107496560106967&amp;w=2" source="BUGTRAQ">20040124 Oracle HTTP Server Cross Site Scripting Vulnerabillity</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="http_server">
        <vers num="8.1.7" />
        <vers num="9.0.1" />
        <vers num="9.2.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-2116" published="2004-12-31" name="CVE-2004-2116" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in Tiny Server 1.1 allows remote attackers to read or download arbitrary files via a .. (dot dot) in the URL.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/14927" source="XF">tinyserver-dotdot-directory-traversal(14927)</ref>
      <ref url="http://www.securityfocus.com/bid/9485" source="BID">9485</ref>
      <ref url="http://www.autistici.org/fdonato/advisory/tinyServer1.1%5B1.0.5%5D-adv.txt" source="MISC">http://www.autistici.org/fdonato/advisory/tinyServer1.1[1.0.5]-adv.txt</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107496530806730&amp;w=2" source="BUGTRAQ">20040124 Tiny Server 1.1 (1.0.5) Multiple Vulnerabilities</ref>
      <ref url="http://www.osvdb.org/3708" source="OSVDB">3708</ref>
      <ref url="http://secunia.com/advisories/10707" source="SECUNIA">10707</ref>
    </refs>
    <vuln_soft>
      <prod vendor="tinyserver" name="tinyserver">
        <vers num="1.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-2117" published="2004-01-24" name="CVE-2004-2117" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Tiny Server 1.1 allows remote attackers to cause a denial of service (crash) via malformed HTTP requests such as (1) a GET request without the HTTP version (HTTP/1.1), or (2) a request without GET or the HTTP version.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/14928" source="XF" adv="1">tinyserver-string-dos(14928)</ref>
      <ref url="http://www.securityfocus.com/bid/9485" source="BID" adv="1">9485</ref>
      <ref url="http://www.autistici.org/fdonato/advisory/tinyServer1.1%5B1.0.5%5D-adv.txt" source="MISC">http://www.autistici.org/fdonato/advisory/tinyServer1.1[1.0.5]-adv.txt</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107496530806730&amp;w=2" source="BUGTRAQ" adv="1">20040124 Tiny Server 1.1 (1.0.5) Multiple Vulnerabilities</ref>
      <ref url="http://www.osvdb.org/3709" source="OSVDB">3709</ref>
      <ref url="http://secunia.com/advisories/10707" source="SECUNIA">10707</ref>
    </refs>
    <vuln_soft>
      <prod vendor="tinyserver" name="tinyserver">
        <vers num="1.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-2118" published="2004-12-31" name="CVE-2004-2118" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Tiny Server 1.1 allows remote attackers to cause a denial of service (crash) via a GET request with a long filename, possibly due to a buffer overflow.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/14928" source="XF">tinyserver-string-dos(14928)</ref>
      <ref url="http://www.securityfocus.com/bid/9485" source="BID">9485</ref>
      <ref url="http://www.autistici.org/fdonato/advisory/tinyServer1.1%5B1.0.5%5D-adv.txt" source="MISC">http://www.autistici.org/fdonato/advisory/tinyServer1.1[1.0.5]-adv.txt</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107496530806730&amp;w=2" source="BUGTRAQ">20040124 Tiny Server 1.1 (1.0.5) Multiple Vulnerabilities</ref>
      <ref url="http://secunia.com/advisories/10707" source="SECUNIA">10707</ref>
    </refs>
    <vuln_soft>
      <prod vendor="tinyserver" name="tinyserver">
        <vers num="1.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-2119" published="2004-12-31" name="CVE-2004-2119" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in Tiny Server 1.1 allows remote attackers to inject arbitrary web script or HTML via the URL.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/14929" source="XF">tinyserver-xss(14929)</ref>
      <ref url="http://www.securityfocus.com/bid/9485" source="BID">9485</ref>
      <ref url="http://www.autistici.org/fdonato/advisory/tinyServer1.1%5B1.0.5%5D-adv.txt" source="MISC">http://www.autistici.org/fdonato/advisory/tinyServer1.1[1.0.5]-adv.txt</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107496530806730&amp;w=2" source="BUGTRAQ">20040124 Tiny Server 1.1 (1.0.5) Multiple Vulnerabilities</ref>
      <ref url="http://www.osvdb.org/3710" source="OSVDB">3710</ref>
      <ref url="http://secunia.com/advisories/10707" source="SECUNIA">10707</ref>
    </refs>
    <vuln_soft>
      <prod vendor="tinyserver" name="tinyserver">
        <vers num="1.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-2120" published="2004-01-23" name="CVE-2004-2120" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Reptile Web Server allows remote attackers to cause a denial of service (CPU consumption) via multiple incomplete GET requests without the HTTP version.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/14932" source="XF" adv="1">reptilewebserver-get-dos(14932)</ref>
      <ref url="http://www.securityfocus.com/bid/9482" source="BID" adv="1">9482</ref>
      <ref url="http://www.autistici.org/fdonato/advisory/reptilewsDailyVersion-adv.txt" source="MISC" adv="1">http://www.autistici.org/fdonato/advisory/reptilewsDailyVersion-adv.txt</ref>
      <ref url="http://securitytracker.com/id?1008842" source="SECTRACK" adv="1">1008842</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107497355713434&amp;w=2" source="BUGTRAQ" adv="1">20040124 Resources consumption in Reptile webserver daily version</ref>
    </refs>
    <vuln_soft>
      <prod vendor="reptile_web_server" name="reptile_web_server">
        <vers num="2002-01-05" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-2121" published="2004-12-31" name="CVE-2004-2121" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Multiple directory traversal vulnerabilities in Borland Web Server (BWS) 1.0b3 and earlier allow remote attackers to read and download arbitrary files via (1) multi-dot "......" sequences, or (2) "%5c%2e%2e" (encoded "\..") sequences, in the URL.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <access />
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/14948" source="XF">bws-directory-traversal(14948)</ref>
      <ref url="http://www.securityfocus.com/bid/9486" source="BID">9486</ref>
      <ref url="http://securitytracker.com/id?1008840" source="SECTRACK">1008840</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107497413413907&amp;w=2" source="BUGTRAQ">20040124 BWS v1.0b3 Directory Transversal Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="borland_software" name="web_server_for_corel_paradox">
        <vers prev="1" num="1.0_b3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-2122" published="2004-01-24" name="CVE-2004-2122" modified="2009-01-29" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in intraforum_db.cgi in Intra Forum allows remote attackers to inject arbitrary web script or HTML via the (1) use_last_read or (2) forum parameters.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/14933" source="XF" adv="1">intraforum-intraforumcgi-xss(14933)</ref>
      <ref url="http://www.securitytracker.com/id?1008839" source="SECTRACK">1008839</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107497803617071&amp;w=2" source="BUGTRAQ" adv="1">20040124 Inrtra Forum Cross Site Scripting Vulnerabillity</ref>
    </refs>
    <vuln_soft>
      <prod vendor="intra_forum" name="intra_forum">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-2123" published="2004-12-31" name="CVE-2004-2123" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in Nextplace.com E-Commerce ASP Engine allow remote attackers to inject arbitrary web script or HTML via the (1) level parameter of productdetail.asp, (2) searchKey parameter of searchresults.asp, and possibly (3) level parameter of ListCategories.asp.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/14952" source="XF">nextplace-multiple-xss(14952)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107513601805018&amp;w=2" source="BUGTRAQ">20040124 NextPlace.com E-Commerce ASP Engine</ref>
    </refs>
    <vuln_soft>
      <prod vendor="nextplace" name="e-commerce_asp_engine">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-2124" published="2004-12-31" name="CVE-2004-2124" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The register_globals simulation capability in Gallery 1.3.1 through 1.4.1 allows remote attackers to modify the HTTP_POST_VARS variable and conduct a PHP remote file inclusion attack via the GALLERY_BASEDIR parameter, a different vulnerability than CVE-2002-1412.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107524414317693&amp;w=2" source="BUGTRAQ" patch="1">20040127 Remote exploit in Gallery 1.3.1, 1.3.2, 1.3.3, 1.4 and 1.4.1</ref>
      <ref url="http://gallery.menalto.com/modules.php?op=modload&amp;name=News&amp;file=index" source="CONFIRM" patch="1">http://gallery.menalto.com/modules.php?op=modload&amp;name=News&amp;file=index</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/14950" source="XF">gallery-gallerybasedir-file-include(14950)</ref>
      <ref url="http://www.securityfocus.com/bid/9490" source="BID">9490</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200402-04.xml" source="GENTOO">GLSA-200402-04</ref>
      <ref url="http://secunia.com/advisories/10712/" source="SECUNIA">10712</ref>
      <ref url="http://www.osvdb.org/3737" source="OSVDB">3737</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gallery_project" name="gallery">
        <vers num="1.3.1" />
        <vers num="1.3.2" />
        <vers num="1.3.3" />
        <vers num="1.4" />
        <vers num="1.4.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-2125" published="2004-12-31" name="CVE-2004-2125" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Buffer overflow in blackd.exe for BlackICE PC Protection 3.6 and other versions before 3.6.ccb, with application protection off, allows local users to gain system privileges by modifying the .INI file to contain a long packetLog.fileprefix value.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <config />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/14965" source="XF" patch="1">blackice-blackdexe-bo(14965)</ref>
      <ref url="http://www.securityfocus.com/bid/9514" source="BID">9514</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107530966524193&amp;w=2" source="BUGTRAQ">20040128 SRT2004-01-17-0227 - BlackICE allows local users to become SYSTEM</ref>
      <ref url="http://www.osvdb.org/3740" source="OSVDB">3740</ref>
      <ref url="http://secunia.com/advisories/10739" source="SECUNIA">10739</ref>
      <ref url="http://archives.neohapsis.com/archives/iss/2004-q1/0157.html" source="MLIST">[ISSForum] 20040128 Third party BlackICE advisory</ref>
    </refs>
    <vuln_soft>
      <prod vendor="iss" name="blackice_agent_server">
        <vers num="3.6eca" />
      </prod>
      <prod vendor="iss" name="blackice_pc_protection">
        <vers num="3.6cbd" />
      </prod>
      <prod vendor="iss" name="blackice_server_protection">
        <vers num="3.6cbz" />
      </prod>
      <prod vendor="iss" name="realsecure_desktop">
        <vers num="3.6eca" />
        <vers num="7.0ebg" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-2126" published="2004-12-31" name="CVE-2004-2126" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">The upgrade for BlackICE PC Protection 3.6 and earlier sets insecure permissions for .INI files such as (1) blackice.ini, (2) firewall.ini, (3) protect.ini, or (4) sigs.ini, which allows local users to modify BlackICE configuration or possibly execute arbitrary code by exploiting vulnerabilities in the .INI parsers.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <config />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/9513" source="BID">9513</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107530966524193&amp;w=2" source="BUGTRAQ">20040128 SRT2004-01-17-0227 - BlackICE allows local users to become SYSTEM</ref>
    </refs>
    <vuln_soft>
      <prod vendor="iss" name="blackice_pc_protection">
        <vers prev="1" num="3.6cbz" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-2127" published="2004-01-20" name="CVE-2004-2127" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in Web Blog 1.1 allows remote attackers to read arbitrary files via a .. (dot dot) in the file variable.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <access />
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/14978" source="XF" patch="1" adv="1">webblog-dotdot-directory-traversal(14978)</ref>
      <ref url="http://www.zone-h.org/en/advisories/read/id=3822/" source="MISC" patch="1" adv="1">http://www.zone-h.org/en/advisories/read/id=3822/</ref>
      <ref url="http://www.securityfocus.com/bid/9517" source="BID" patch="1" adv="1">9517</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107531194527602&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20040128 ZH2004-01SA (security advisory): Web Blog 1.1 Remote arbitrary</ref>
      <ref url="http://www.osvdb.org/3739" source="OSVDB">3739</ref>
      <ref url="http://secunia.com/advisories/10740" source="SECUNIA">10740</ref>
    </refs>
    <vuln_soft>
      <prod vendor="leif_m._wright" name="web_blog">
        <vers num="1.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-2128" published="2004-12-31" name="CVE-2004-2128" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in BRS WebWeaver 1.07 allows remote attackers to execute arbitrary script as other users via the query string to ISAPISkeleton.dll.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/10741" source="SECUNIA" patch="1">10741</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/14977" source="XF">webweaver-isapiskeleton-xss(14977)</ref>
      <ref url="http://www.securityfocus.com/bid/9516" source="BID">9516</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107531020924977&amp;w=2" source="BUGTRAQ">20040128 BRS WebWeaver Webserver Cross Site Scripting Vulnerability</ref>
      <ref url="http://www.securitytracker.com/id?1008880" source="SECTRACK">1008880</ref>
      <ref url="http://www.osvdb.org/3741" source="OSVDB">3741</ref>
      <ref url="http://www.brswebweaver.com/modules.php?op=modload&amp;name=News&amp;file=article&amp;sid=1" source="CONFIRM">http://www.brswebweaver.com/modules.php?op=modload&amp;name=News&amp;file=article&amp;sid=1</ref>
    </refs>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-2129" published="2004-12-31" name="CVE-2004-2129" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">SurfNOW 2.2 allows remote attackers to cause a denial of service (crash) via a series of long HTTP GET requests, possibly triggering a buffer overflow.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/14976" source="XF">surfnow-get-dos(14976)</ref>
      <ref url="http://www.securityfocus.com/bid/9519" source="BID">9519</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107530924723559&amp;w=2" source="BUGTRAQ">20040128 Denial Of Service in SurfNOW 2.2</ref>
    </refs>
    <vuln_soft>
      <prod vendor="loom_software" name="surfnow_professional">
        <vers num="1.2" />
        <vers num="1.4" />
        <vers num="1.5" />
        <vers num="1.6" />
        <vers num="2.0" />
        <vers num="2.1" />
        <vers num="2.2" />
      </prod>
      <prod vendor="loom_software" name="surfnow_standard">
        <vers num="1.2" />
        <vers num="1.4" />
        <vers num="1.5" />
        <vers num="1.6" />
        <vers num="2.0" />
        <vers num="2.1" />
        <vers num="2.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-2130" published="2004-12-23" name="CVE-2004-2130" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in privmsg.php in phpBB 2.0.6 allow remote attackers to execute arbitrary script or HTML via the (1) folder or (2) mode variables.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/9290" source="BID" patch="1" adv="1">9290</ref>
      <ref url="http://www.phpbb.com/phpBB/viewtopic.php?f=14&amp;t=161943" source="CONFIRM" patch="1" adv="1">http://www.phpbb.com/phpBB/viewtopic.php?f=14&amp;t=161943</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107530946123822&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20040128 phpBB privmsg.php XSS vulnerability patch.</ref>
    </refs>
    <vuln_soft>
      <prod vendor="phpbb_group" name="phpbb">
        <vers num="2.0.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-2131" published="2004-01-27" name="CVE-2004-2131" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Stack-based buffer overflow in ontape for IBM Informix Dynamic Server (IDS) 9.40.xC3 and earlier allows local users, with DSA privileges, to execute arbitrary code via a long ONCONFIG environment variable.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/9512" source="BID" patch="1" adv="1">9512</ref>
      <ref url="http://www-1.ibm.com/support/docview.wss?uid=swg21153336" source="CONFIRM" patch="1" adv="1">http://www-1.ibm.com/support/docview.wss?uid=swg21153336</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107539878804074&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20040129 ----------========== OPEN3S-2003-08-08-eng-informix-ontape</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/14970" source="XF" adv="1">informix-ontape-binary-bo(14970)</ref>
      <ref url="http://www.osvdb.org/3759" source="OSVDB">3759</ref>
      <ref url="http://secunia.com/advisories/10737/" source="SECUNIA">10737</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="informix_dynamic_server">
        <vers num="9.40.uc1" />
        <vers num="9.40.uc2" />
      </prod>
      <prod vendor="ibm" name="informix_extended_parallel_server">
        <vers num="8.40_uc1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-2132" published="2004-01-29" name="CVE-2004-2132" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in PJreview_Neo.cgi in PJ CGI Neo review allows remote attackers to read arbitrary files via a ..  (dot dot) in the p parameter.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <access />
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/14980" source="XF" adv="1">pjcgineoreview-dotdot-directory-traversal(14980)</ref>
      <ref url="http://www.zone-h.org/advisories/read/id=3824" source="MISC" adv="1">http://www.zone-h.org/advisories/read/id=3824</ref>
      <ref url="http://www.securityfocus.com/bid/9524" source="BID" adv="1">9524</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107539804702913&amp;w=2" source="BUGTRAQ" adv="1">20040129 ZH2004-02SA (security advisory): PJ CGI Neo review (NeoBoard review) Remote arbitrary file retrieving</ref>
      <ref url="http://www.secunia.com/advisories/10734/" source="SECUNIA">10734</ref>
      <ref url="http://www.osvdb.org/3746" source="OSVDB">3746</ref>
    </refs>
    <vuln_soft>
      <prod vendor="pj_cgi_neo_review" name="pj_cgi_neo_review">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-2133" published="2004-01-29" name="CVE-2004-2133" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Certain third-party packages for CVSup 16.1h, such as SuSE Linux, contain untrusted paths in the ELF RPATH fields of certain executables, which could allow local users to execute arbitrary code by causing cvsup to link against malicious libraries that are created in world-writable directories such as /usr/src/packages.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <config />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/14994" source="XF" patch="1" adv="1">cvsup-rpath-gain-privileges(14994)</ref>
      <ref url="http://www.securityfocus.com/bid/9523" source="BID" patch="1" adv="1">9523</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107539776002450&amp;w=2" source="BUGTRAQ" adv="1">20040129 Security Announcement: untrusted ELF library path in some cvsup binary RPMs</ref>
      <ref url="http://archives.neohapsis.com/archives/vulnwatch/2004-q1/0025.html" source="VULNWATCH" adv="1">20040129 Security Announcement: untrusted ELF library path in some cvsup binary RPMs</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cvsup" name="cvsup">
        <vers num="cvsup-16.1h-2.i386.rpm" />
        <vers num="cvsup-16.1h-36.i586.rpm" />
        <vers num="cvsup-16.1h-43.i586.rpm" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-2134" published="2004-01-28" name="CVE-2004-2134" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Oracle toplink mapping workBench uses a weak encryption algorithm for passwords, which allows local users to decrypt the passwords.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/9515" source="BID" adv="1">9515</ref>
      <ref url="http://www.securityfocus.com/archive/82/351719" source="VULN-DEV" adv="1">20040128 Re: Oracle toplink mapping workbench password algorithm</ref>
      <ref url="http://www.planet-source-code.com/vb/scripts/ShowCode.asp?txtCodeId=803&amp;lngWId=5" source="MISC">http://www.planet-source-code.com/vb/scripts/ShowCode.asp?txtCodeId=803&amp;lngWId=5</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107531028325112&amp;w=2" source="BUGTRAQ" adv="1">20040128 Oracle toplink mapping workbench password algorithm</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/352315/30/21430/threaded" source="BUGTRAQ">20040128 Re: Oracle toplink mapping workbench password algorithm</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="application_server">
        <vers num="9.0.2" />
        <vers num="9.0.2.0.0" />
        <vers num="9.0.2.0.1" />
        <vers num="9.0.2.1" />
        <vers num="9.0.2.2" />
        <vers num="9.0.2.3" />
        <vers num="9.0.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2004-2135" published="2004-05-26" name="CVE-2004-2135" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">cryptoloop on Linux kernel 2.6.x, when used on certain file systems with a block size 1024 or greater, has certain "IV computation" weaknesses that allow watermarked files to be detected without decryption.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
      <env />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/13775" source="BID" adv="1">13775</ref>
      <ref url="http://www.securiteam.com/exploits/5UP0P1PFPM.html" source="MISC" adv="1">http://www.securiteam.com/exploits/5UP0P1PFPM.html</ref>
      <ref url="http://mareichelt.de/pub/notmine/diskenc.pdf" source="MISC">http://mareichelt.de/pub/notmine/diskenc.pdf</ref>
      <ref url="http://marc.theaimsgroup.com/?l=linux-kernel&amp;m=107719798631935&amp;w=2" source="MLIST" adv="1">[linux-kernel] 20040219 Re: Oopsing cryptoapi (or loop device?) on 2.6.*</ref>
    </refs>
    <vuln_soft>
      <prod vendor="linux" name="linux_kernel">
        <vers num="2.4.0" edition="test1" />
        <vers num="2.4.0" edition="test10" />
        <vers num="2.4.0" edition="test11" />
        <vers num="2.4.0" edition="test12" />
        <vers num="2.4.0" edition="test2" />
        <vers num="2.4.0" edition="test3" />
        <vers num="2.4.0" edition="test4" />
        <vers num="2.4.0" edition="test5" />
        <vers num="2.4.0" edition="test6" />
        <vers num="2.4.0" edition="test7" />
        <vers num="2.4.0" edition="test8" />
        <vers num="2.4.0" edition="test9" />
        <vers num="2.4.1" />
        <vers num="2.4.10" />
        <vers num="2.4.11" />
        <vers num="2.4.12" />
        <vers num="2.4.13" />
        <vers num="2.4.14" />
        <vers num="2.4.15" />
        <vers num="2.4.16" />
        <vers num="2.4.17" />
        <vers num="2.4.18" edition="" />
        <vers num="2.4.18" edition=":x86" />
        <vers num="2.4.18" edition="pre1" />
        <vers num="2.4.18" edition="pre2" />
        <vers num="2.4.18" edition="pre3" />
        <vers num="2.4.18" edition="pre4" />
        <vers num="2.4.18" edition="pre5" />
        <vers num="2.4.18" edition="pre6" />
        <vers num="2.4.18" edition="pre7" />
        <vers num="2.4.18" edition="pre8" />
        <vers num="2.4.19" edition="pre1" />
        <vers num="2.4.19" edition="pre2" />
        <vers num="2.4.19" edition="pre3" />
        <vers num="2.4.19" edition="pre4" />
        <vers num="2.4.19" edition="pre5" />
        <vers num="2.4.19" edition="pre6" />
        <vers num="2.4.2" />
        <vers num="2.4.20" />
        <vers num="2.4.21" edition="pre1" />
        <vers num="2.4.21" edition="pre4" />
        <vers num="2.4.21" edition="pre7" />
        <vers num="2.4.22" />
        <vers num="2.4.23" edition="pre9" />
        <vers num="2.4.23_ow2" />
        <vers num="2.4.24" />
        <vers num="2.4.24_ow1" />
        <vers num="2.4.25" />
        <vers num="2.4.26" />
        <vers num="2.4.27" edition="pre1" />
        <vers num="2.4.27" edition="pre2" />
        <vers num="2.4.27" edition="pre3" />
        <vers num="2.4.27" edition="pre4" />
        <vers num="2.4.27" edition="pre5" />
        <vers num="2.4.28" />
        <vers num="2.4.29" edition="rc1" />
        <vers num="2.4.29" edition="rc2" />
        <vers num="2.4.3" />
        <vers num="2.4.30" edition="rc2" />
        <vers num="2.4.30" edition="rc3" />
        <vers num="2.4.31" edition="pre1" />
        <vers num="2.4.4" />
        <vers num="2.4.5" />
        <vers num="2.4.6" />
        <vers num="2.4.7" />
        <vers num="2.4.8" />
        <vers num="2.4.9" />
        <vers num="2.5.0" />
        <vers num="2.5.1" />
        <vers num="2.5.10" />
        <vers num="2.5.11" />
        <vers num="2.5.12" />
        <vers num="2.5.13" />
        <vers num="2.5.14" />
        <vers num="2.5.15" />
        <vers num="2.5.16" />
        <vers num="2.5.17" />
        <vers num="2.5.18" />
        <vers num="2.5.19" />
        <vers num="2.5.2" />
        <vers num="2.5.20" />
        <vers num="2.5.21" />
        <vers num="2.5.22" />
        <vers num="2.5.23" />
        <vers num="2.5.24" />
        <vers num="2.5.25" />
        <vers num="2.5.26" />
        <vers num="2.5.27" />
        <vers num="2.5.28" />
        <vers num="2.5.29" />
        <vers num="2.5.3" />
        <vers num="2.5.30" />
        <vers num="2.5.31" />
        <vers num="2.5.32" />
        <vers num="2.5.33" />
        <vers num="2.5.34" />
        <vers num="2.5.35" />
        <vers num="2.5.36" />
        <vers num="2.5.37" />
        <vers num="2.5.38" />
        <vers num="2.5.39" />
        <vers num="2.5.4" />
        <vers num="2.5.40" />
        <vers num="2.5.41" />
        <vers num="2.5.42" />
        <vers num="2.5.43" />
        <vers num="2.5.44" />
        <vers num="2.5.45" />
        <vers num="2.5.46" />
        <vers num="2.5.47" />
        <vers num="2.5.48" />
        <vers num="2.5.49" />
        <vers num="2.5.5" />
        <vers num="2.5.50" />
        <vers num="2.5.51" />
        <vers num="2.5.52" />
        <vers num="2.5.53" />
        <vers num="2.5.54" />
        <vers num="2.5.55" />
        <vers num="2.5.56" />
        <vers num="2.5.57" />
        <vers num="2.5.58" />
        <vers num="2.5.59" />
        <vers num="2.5.6" />
        <vers num="2.5.60" />
        <vers num="2.5.61" />
        <vers num="2.5.62" />
        <vers num="2.5.63" />
        <vers num="2.5.64" />
        <vers num="2.5.65" />
        <vers num="2.5.66" />
        <vers num="2.5.67" />
        <vers num="2.5.68" />
        <vers num="2.5.69" />
        <vers num="2.5.7" />
        <vers num="2.5.8" />
        <vers num="2.5.9" />
        <vers num="2.6.0" edition="test1" />
        <vers num="2.6.0" edition="test10" />
        <vers num="2.6.0" edition="test11" />
        <vers num="2.6.0" edition="test2" />
        <vers num="2.6.0" edition="test3" />
        <vers num="2.6.0" edition="test4" />
        <vers num="2.6.0" edition="test5" />
        <vers num="2.6.0" edition="test6" />
        <vers num="2.6.0" edition="test7" />
        <vers num="2.6.0" edition="test8" />
        <vers num="2.6.0" edition="test9" />
        <vers num="2.6.1" edition="rc1" />
        <vers num="2.6.1" edition="rc2" />
        <vers num="2.6.10" edition="rc2" />
        <vers num="2.6.11" edition="rc2" />
        <vers num="2.6.11" edition="rc3" />
        <vers num="2.6.11" edition="rc4" />
        <vers num="2.6.11.5" />
        <vers num="2.6.11.6" />
        <vers num="2.6.11.7" />
        <vers num="2.6.11.8" />
        <vers num="2.6.12" edition="rc4" />
        <vers num="2.6.2" />
        <vers num="2.6.3" />
        <vers num="2.6.4" />
        <vers num="2.6.5" />
        <vers num="2.6.6" edition="rc1" />
        <vers num="2.6.7" edition="rc1" />
        <vers num="2.6.8" edition="rc1" />
        <vers num="2.6.8" edition="rc2" />
        <vers num="2.6.8" edition="rc3" />
        <vers num="2.6.9" edition="2.6.20" />
        <vers num="2.6_test9_cvs" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2004-2136" published="2004-02-19" name="CVE-2004-2136" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">dm-crypt on Linux kernel 2.6.x, when used on certain file systems with a block size 1024 or greater, has certain "IV computation" weaknesses that allow watermarked files to be detected without decryption.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
      <other />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securiteam.com/exploits/5UP0P1PFPM.html" source="MISC" adv="1">http://www.securiteam.com/exploits/5UP0P1PFPM.html</ref>
      <ref url="http://mareichelt.de/pub/notmine/diskenc.pdf" source="MISC">http://mareichelt.de/pub/notmine/diskenc.pdf</ref>
      <ref url="http://marc.theaimsgroup.com/?l=linux-kernel&amp;m=107719798631935&amp;w=2" source="MLIST" adv="1">[linux-kernel] 20040219 Re: Oopsing cryptoapi (or loop device?) on 2.6.*</ref>
    </refs>
    <vuln_soft>
      <prod vendor="linux" name="linux_kernel">
        <vers num="2.6.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-2137" published="2004-12-31" name="CVE-2004-2137" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Outlook Express 6.0, when sending multipart e-mail messages using the "Break apart messages larger than" setting, leaks the BCC recipients of the message to the addresses listed in the To and CC fields, which may allow remote attackers to obtain sensitive information.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/17098" source="XF" patch="1">outlook-email-address-disclosure(17098)</ref>
      <ref url="http://www.networksecurity.fi/advisories/outlook-bcc.html" source="MISC" patch="1" adv="1">http://www.networksecurity.fi/advisories/outlook-bcc.html</ref>
      <ref url="http://support.microsoft.com/kb/843555" source="MSKB" patch="1" adv="1">843555</ref>
      <ref url="http://securitytracker.com/id?1011067" source="SECTRACK" patch="1">1011067</ref>
      <ref url="http://secunia.com/advisories/12376" source="SECUNIA" patch="1" adv="1">12376</ref>
      <ref url="http://www.securityfocus.com/bid/11040" source="BID">11040</ref>
      <ref url="http://www.osvdb.org/9167" source="OSVDB">9167</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="outlook_express">
        <vers num="6.0" edition="sp1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-2138" published="2004-12-31" name="CVE-2004-2138" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in AWSguest.php in AllWebScripts MySQLGuest allows remote attackers to inject arbitrary HTML and PHP code via the (1) Name, (2) Email, (3) Homepage or (4) Comments field.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/17462" source="XF">mysqlguest-awsguestphp-xss(17462)</ref>
      <ref url="http://www.securityfocus.com/bid/11234" source="BID">11234</ref>
      <ref url="http://www.computerknights.org/forum_viewtopic.php?2.122" source="MISC">http://www.computerknights.org/forum_viewtopic.php?2.122</ref>
      <ref url="http://securitytracker.com/id?1011376" source="SECTRACK">1011376</ref>
    </refs>
    <vuln_soft>
      <prod vendor="allwebscripts" name="mysqlguest">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-2139" published="2004-12-31" name="CVE-2004-2139" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Unknown vulnerability in Adminedit.pl YaBB 1 Gold before 1.3.2 allows attackers to execute arbitrary code via settings.pl.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/17459" source="XF" patch="1">yabb-admineditpl-xss(17459)</ref>
      <ref url="http://www.yabbforum.com/community/YaBB.pl?board=general;action=display;num=1093133233" source="CONFIRM" patch="1">http://www.yabbforum.com/community/YaBB.pl?board=general;action=display;num=1093133233</ref>
      <ref url="http://secunia.com/advisories/12609/" source="SECUNIA" patch="1" adv="1">12609</ref>
      <ref url="http://www.securityfocus.com/bid/11235" source="BID">11235</ref>
      <ref url="http://www.osvdb.org/10222" source="OSVDB">10222</ref>
    </refs>
    <vuln_soft>
      <prod vendor="yabb" name="yabb">
        <vers num="1_gold_-_sp_1.3" />
        <vers num="1_gold_-_sp_1.3.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-2140" published="2004-12-31" name="CVE-2004-2140" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">CRLF injection vulnerability in YaBB 1 Gold before 1.3.2 allows remote attackers to modify text file contents via the subject variable.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.yabbforum.com/community/YaBB.pl?board=general;action=display;num=1093133233" source="CONFIRM" patch="1">http://www.yabbforum.com/community/YaBB.pl?board=general;action=display;num=1093133233</ref>
      <ref url="http://secunia.com/advisories/12609/" source="SECUNIA" patch="1" adv="1">12609</ref>
    </refs>
    <vuln_soft>
      <prod vendor="yabb" name="yabb">
        <vers num="1_gold_-_sp_1.3" />
        <vers num="1_gold_-_sp_1.3.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" seq="2004-2141" reject="1" published="2004-12-31" name="CVE-2004-2141" modified="2008-09-10">
    <desc>
      <descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: CVE-2004-1827.  Reason: This candidate is a duplicate of CVE-2004-1827.  Notes: All CVE users should reference CVE-2004-1827 instead of this candidate.  All references and descriptions in this candidate have been removed to prevent accidental usage.</descript>
    </desc>
    <vuln_types>
      <input />
    </vuln_types>
    <refs />
  </entry>
  <entry type="CVE" severity="High" seq="2004-2142" published="2004-12-31" name="CVE-2004-2142" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Unknown vulnerability in the remote tape support (remote.c) in the RMT client for Jorg Schilling sdd 1.28 and 1.31 has unknown impact and attack vectors.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/17442" source="XF" patch="1">sdd-rmt(17442)</ref>
      <ref url="http://secunia.com/advisories/12584/" source="SECUNIA" patch="1" adv="1">12584</ref>
      <ref url="ftp://ftp.berlios.de/pub/sdd/AN-1.52" source="CONFIRM">ftp://ftp.berlios.de/pub/sdd/AN-1.52</ref>
    </refs>
    <vuln_soft>
      <prod vendor="jorg_schilling" name="sdd">
        <vers num="1.28" />
        <vers num="1.31" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-2143" published="2004-12-31" name="CVE-2004-2143" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in the ReMOSitory Server add-on module to Mambo Portal 4.5.1 (1.09) and earlier allows remote attackers to execute arbitrary SQL commands via the filecatid parameter in the com_remository option.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.mamboportal.com/content/view/1615/" source="CONFIRM" patch="1" adv="1">http://www.mamboportal.com/content/view/1615/</ref>
      <ref url="http://securitytracker.com/id?1011356" source="SECTRACK" patch="1">1011356</ref>
      <ref url="http://secunia.com/advisories/12597/" source="SECUNIA" patch="1" adv="1">12597</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/17441" source="XF">remository-filecatid-sql-injection(17441)</ref>
      <ref url="http://www.securityfocus.com/bid/11219" source="BID">11219</ref>
      <ref url="http://www.osvdb.org/10040" source="OSVDB">10040</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2004-09/0249.html" source="BUGTRAQ">20040919 Re: Mambo Portal lasted version 4.5.1 (1.09) and lower vesion : SQL injection Vulnerability.</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2004-09/0215.html" source="BUGTRAQ">20040917 Mambo Portal lasted version 4.5.1 (1.09) and lower vesion : SQL injection Vulnerability.</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mambo" name="mambo_portal">
        <vers prev="1" num="4.5.1_1.0.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-2144" published="2004-12-31" name="CVE-2004-2144" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Baal Smart Forms before 3.2 allows remote attackers to bypass authentication and obtain system access via a direct request to regadmin.php.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/17499" source="XF" patch="1">baal-admin-password-modify(17499)</ref>
      <ref url="http://securitytracker.com/id?1011416" source="SECTRACK" patch="1">1011416</ref>
      <ref url="http://secunia.com/advisories/12649/" source="SECUNIA" patch="1" adv="1">12649</ref>
    </refs>
    <vuln_soft>
      <prod vendor="baal_systems" name="baal_smart_forms">
        <vers num="3.0" />
        <vers num="3.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-2145" published="2004-12-31" name="CVE-2004-2145" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in PD9 Software MegaBBS 2 and 2.1 allows remote attackers to execute arbitrary SQL commands via the (1) sortdir or (2) criteria parameter to ladder-log.asp or the (3) memberid or (4) teamid parameter to view-profile.asp.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/17497" source="XF" patch="1">megabbs-sql-injection(17497)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109631200701134&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20040926 Re: HTTP Response Splitting and SQL injection in megabbs forum</ref>
      <ref url="http://archives.neohapsis.com/archives/fulldisclosure/2004-09/0962.html" source="FULLDISC">20040926 HTTP Response Splitting and SQL injection in megabbs forum</ref>
    </refs>
    <vuln_soft>
      <prod vendor="pd9_software" name="megabbs">
        <vers num="2" />
        <vers num="2.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-2146" published="2004-12-31" name="CVE-2004-2146" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">CRLF injection vulnerability in PD9 Software MegaBBS 2 and 2.1 allows attackers to conduct HTTP response splitting attacks via the fid parameter in a writenew action to thread-post.asp.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/17495" source="XF" patch="1">megabbs-response-splitting(17495)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109631200701134&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20040926 Re: HTTP Response Splitting and SQL injection in megabbs forum</ref>
      <ref url="http://archives.neohapsis.com/archives/fulldisclosure/2004-09/0962.html" source="FULLDISC">20040926 HTTP Response Splitting and SQL injection in megabbs forum</ref>
      <ref url="http://www.pd9soft.com/megabbs/forums/thread-view.asp?tid=4924" source="CONFIRM">http://www.pd9soft.com/megabbs/forums/thread-view.asp?tid=4924</ref>
    </refs>
    <vuln_soft>
      <prod vendor="pd9_software" name="megabbs">
        <vers num="2" />
        <vers num="2.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-2147" published="2004-12-31" name="CVE-2004-2147" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Unknown versions of Symantec Norton AntiVirus and Microsoft Outlook allow attackers to cause a denial of service (crash) via malformed e-mail messages (1) without a body or (2) without a carriage return ("\n") separating the headers from the body.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/11259" source="BID">11259</ref>
      <ref url="http://www.securityfocus.com/archive/82/376487/2004-09-24/2004-09-30/0" source="VULN-DEV" adv="1">20040925 No body emails and Norton antivirus</ref>
    </refs>
    <vuln_soft>
      <prod vendor="symantec" name="norton_antivirus">
        <vers num="2.1" edition="" />
        <vers num="2.1" edition=":ms_exchange" />
        <vers num="2001" />
        <vers num="2002" />
        <vers num="2003" />
        <vers num="corporate_7.0" />
        <vers num="corporate_7.2" />
        <vers num="corporate_7.5" />
        <vers num="corporate_7.51" />
        <vers num="corporate_7.6" />
        <vers num="corporate_7.60.build_926" />
        <vers num="corporate_7.61" />
        <vers num="corporate_8.0" />
        <vers num="professional_2001" />
        <vers num="professional_2002" />
        <vers num="professional_2003" />
        <vers num="professional_2004" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-2148" published="2004-12-31" name="CVE-2004-2148" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Unknown local vulnerability in the "change user" feature of Slava Astashonok Fprobe 1.0.5 and earlier has unknown impact and attack vectors.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/17494" source="XF" patch="1">fprobe-change-user(17494)</ref>
      <ref url="http://sourceforge.net/project/shownotes.php?release_id=269807" source="CONFIRM" patch="1">http://sourceforge.net/project/shownotes.php?release_id=269807</ref>
      <ref url="http://securitytracker.com/id?1011417" source="SECTRACK" patch="1">1011417</ref>
      <ref url="http://secunia.com/advisories/12648/" source="SECUNIA" patch="1" adv="1">12648</ref>
      <ref url="http://www.securityfocus.com/bid/11255" source="BID">11255</ref>
    </refs>
    <vuln_soft>
      <prod vendor="slava_astashonok" name="fprobe">
        <vers num="1.0" />
        <vers num="1.0.1" />
        <vers num="1.0.2" />
        <vers num="1.0.3" />
        <vers num="1.0.4" />
        <vers num="1.0.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-2149" published="2004-12-31" name="CVE-2004-2149" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Buffer overflow in the prepared statements API in libmysqlclient for MySQL 4.1.3 beta and 4.1.4 allows remote attackers to cause a denial of service via a large number of placeholders.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/11261" source="BID" patch="1">11261</ref>
      <ref url="http://securitytracker.com/id?1011408" source="SECTRACK" patch="1">1011408</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/17493" source="XF">mysql-libmysqlclient-insert-bo(17493)</ref>
      <ref url="http://www.osvdb.org/10244" source="OSVDB">10244</ref>
      <ref url="http://dev.mysql.com/doc/mysql/en/news-4-1-5.html" source="CONFIRM">http://dev.mysql.com/doc/mysql/en/news-4-1-5.html</ref>
      <ref url="http://bugs.mysql.com/bug.php?id=5194" source="CONFIRM" adv="1">http://bugs.mysql.com/bug.php?id=5194</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mysql" name="mysql">
        <vers num="4.1.3" edition="beta" />
        <vers num="4.1.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-2150" published="2004-12-31" name="CVE-2004-2150" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Nettica Corporation INTELLIPEER Email Server 1.01 displays different error messages for valid and invalid account names, which allows remote attackers to determine valid account names.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/12661/" source="SECUNIA" patch="1" adv="1">12661</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/17510" source="XF">intellipeer-username-obtain-information(17510)</ref>
      <ref url="http://www.securityfocus.com/bid/11257" source="BID">11257</ref>
      <ref url="http://www.osvdb.org/10349" source="OSVDB">10349</ref>
      <ref url="http://securitytracker.com/id?1011425" source="SECTRACK">1011425</ref>
    </refs>
    <vuln_soft>
      <prod vendor="nettica_corporation" name="intellipeer_email_server">
        <vers num="1.01" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-2151" published="2004-12-31" name="CVE-2004-2151" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Chatman 1.1.1 RC1 and earlier allows remote attackers to cause a denial of service (memory consumption or application crash) via a very large data size.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/11263" source="BID">11263</ref>
      <ref url="http://www.securityfocus.com/archive/1/376569" source="BUGTRAQ" adv="1">20040927 Broadcast crash in Chatman 1.5.1 RC1</ref>
      <ref url="http://securitytracker.com/id?1011431" source="SECTRACK">1011431</ref>
      <ref url="http://secunia.com/advisories/12665/" source="SECUNIA" adv="1">12665</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/17513" source="XF">chatman-dos(17513)</ref>
      <ref url="http://www.osvdb.org/10365" source="OSVDB">10365</ref>
    </refs>
    <vuln_soft>
      <prod vendor="virtual_projects" name="chatman">
        <vers num="1.0.1_beta" />
        <vers num="1.0.2_beta" />
        <vers num="1.0.3_beta" />
        <vers num="1.0.4_beta" />
        <vers num="1.1.0_beta" />
        <vers num="1.1.1_beta" />
        <vers num="1.1.2_beta" />
        <vers num="1.1.3_beta" />
        <vers num="1.1.4_beta" />
        <vers num="1.1.5_beta" />
        <vers num="1.2.1_beta" />
        <vers num="1.3.0_beta" />
        <vers num="1.3.1_beta" />
        <vers num="1.4.0_beta" />
        <vers num="1.5.0_rc1" />
        <vers num="1.5.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-2152" published="2004-12-31" name="CVE-2004-2152" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in 'raw' page output mode for MediaWiki 1.3.4 and earlier allows remote attackers to inject arbitrary web script or HTML.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/17578" source="XF" patch="1">mediawiki-raw-output-xss(17578)</ref>
      <ref url="http://www.securityfocus.com/bid/11302" source="BID" patch="1">11302</ref>
      <ref url="http://www.osvdb.org/10454" source="OSVDB" patch="1" adv="1">10454</ref>
      <ref url="http://sourceforge.net/project/shownotes.php?group_id=34373&amp;release_id=271848" source="CONFIRM" patch="1">http://sourceforge.net/project/shownotes.php?group_id=34373&amp;release_id=271848</ref>
      <ref url="http://secunia.com/advisories/12692/" source="SECUNIA" patch="1" adv="1">12692</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mediawiki" name="mediawiki">
        <vers num="1.1.0" />
        <vers num="1.2.0" />
        <vers num="1.2.1" />
        <vers num="1.2.2" />
        <vers num="1.2.3" />
        <vers num="1.2.4" />
        <vers num="1.2.5" />
        <vers num="1.2.6" />
        <vers num="1.3.0" />
        <vers num="1.3.1" />
        <vers num="1.3.2" />
        <vers num="1.3.3" />
        <vers num="1.3.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-2153" published="2004-12-31" name="CVE-2004-2153" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Multiple unknown vulnerabilities in Real Estate Management Software 1.0 have unknown impact and attack vectors.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/17598" source="XF" patch="1">real-estate-management-software(17598)</ref>
      <ref url="http://www.securityfocus.com/bid/11304" source="BID" patch="1">11304</ref>
      <ref url="http://secunia.com/advisories/12721" source="SECUNIA" patch="1" adv="1">12721</ref>
      <ref url="http://www.osvdb.org/10480" source="OSVDB">10480</ref>
      <ref url="http://archives.neohapsis.com/archives/apps/freshmeat/2004-09/0030.html" source="MLIST" adv="1">[fm-news] 20041001 Newsletter for Thursday, September 30th 2004</ref>
    </refs>
    <vuln_soft>
      <prod vendor="real_estate_management_software" name="real_estate_management_software">
        <vers num="1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-2154" published="2004-12-31" name="CVE-2004-2154" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">CUPS before 1.1.21rc1 treats a Location directive in cupsd.conf as case sensitive, which allows attackers to bypass intended ACLs via a printer name containing uppercase or lowercase letters that are different from what is specified in the directive.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.cups.org/str.php?L700" source="CONFIRM" patch="1">http://www.cups.org/str.php?L700</ref>
      <ref url="https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=162405" source="CONFIRM" adv="1">https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=162405</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9940" source="OVAL">oval:org.mitre.oval:def:9940</ref>
      <ref url="https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=163274" source="FEDORA">FLSA:163274</ref>
      <ref url="http://www.ubuntu.com/usn/usn-185-1" source="UBUNTU">USN-185-1</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-571.html" source="REDHAT">RHSA-2005:571</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2005_18_sr.html" source="SUSE">SUSE-SR:2005:018</ref>
    </refs>
    <vuln_soft>
      <prod vendor="easy_software_products" name="cups">
        <vers num="1.0.4" />
        <vers num="1.0.4_8" />
        <vers num="1.1.1" />
        <vers num="1.1.10" />
        <vers num="1.1.12" />
        <vers num="1.1.13" />
        <vers num="1.1.14" />
        <vers num="1.1.15" />
        <vers num="1.1.16" />
        <vers num="1.1.17" />
        <vers num="1.1.18" />
        <vers num="1.1.19" />
        <vers num="1.1.19_rc5" />
        <vers num="1.1.20" />
        <vers num="1.1.4" />
        <vers num="1.1.4_2" />
        <vers num="1.1.4_3" />
        <vers num="1.1.4_5" />
        <vers num="1.1.6" />
        <vers num="1.1.7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-2155" published="2004-12-31" name="CVE-2004-2155" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Online-bookmarks before 0.4.6 allows remote attackers to bypass its authentication mechanism via a direct request to (1) config/*, (2) bookmarks.php, (3) footer.php, (4) main.php, (5) tree.php, or (6) functions.php.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/17602" source="XF" patch="1">online-bookmarks-resrtictions-bypass(17602)</ref>
      <ref url="http://www.securityfocus.com/bid/11305" source="BID" patch="1">11305</ref>
      <ref url="http://secunia.com/advisories/12728/" source="SECUNIA" patch="1" adv="1">12728</ref>
      <ref url="http://freshmeat.net/projects/onlinebookmarks/?branch_id=34962&amp;release_id=174401" source="CONFIRM">http://freshmeat.net/projects/onlinebookmarks/?branch_id=34962&amp;release_id=174401</ref>
    </refs>
  </entry>
  <entry type="CVE" severity="High" seq="2004-2156" published="2004-12-31" name="CVE-2004-2156" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Multiple unknown vulnerabilities in Online Recruitment Agency 1.0 have unknown impact and attack vectors.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/17586" source="XF" patch="1">online-recruitment-agency(17586)</ref>
      <ref url="http://www.securityfocus.com/bid/11306" source="BID" patch="1">11306</ref>
      <ref url="http://secunia.com/advisories/12720/" source="SECUNIA" patch="1" adv="1">12720</ref>
      <ref url="http://archives.neohapsis.com/archives/apps/freshmeat/2004-09/0030.html" source="CONFIRM" patch="1">http://archives.neohapsis.com/archives/apps/freshmeat/2004-09/0030.html</ref>
      <ref url="http://www.osvdb.org/10479" source="OSVDB">10479</ref>
      <ref url="http://securitytracker.com/id?1011539" source="SECTRACK">1011539</ref>
    </refs>
    <vuln_soft>
      <prod vendor="recruitment_agency_software" name="online_recruitment_agency">
        <vers num="1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-2157" published="2004-12-31" name="CVE-2004-2157" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in Comment.php in Serendipity 0.7 beta1, and possibly other versions before 0.7-beta3, allows remote attackers to inject arbitrary HTML and PHP code via the (1) email or (2) username field.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/17536" source="XF" patch="1">serendipity-commentphp-xss(17536)</ref>
      <ref url="http://www.securityfocus.com/bid/11269" source="BID" patch="1">11269</ref>
      <ref url="http://securitytracker.com/id?1011448" source="SECTRACK" patch="1">1011448</ref>
      <ref url="http://secunia.com/advisories/12673/" source="SECUNIA" patch="1" adv="1">12673</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2004-September/026955.html" source="FULLDISC" adv="1">20040928 Serendipity 0.7-beta1 SQL Injection PoC</ref>
    </refs>
    <vuln_soft>
      <prod vendor="s9y" name="serendipity">
        <vers num="0.7_beta1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-2158" published="2004-12-31" name="CVE-2004-2158" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in Serendipity 0.7-beta1 allows remote attackers to execute arbitrary SQL commands via the entry_id parameter to (1) exit.php or (2) comment.php.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/17533" source="XF" patch="1">serendipity-sql-injection(17533)</ref>
      <ref url="http://www.securityfocus.com/bid/11269" source="BID" patch="1">11269</ref>
      <ref url="http://securitytracker.com/id?1011448" source="SECTRACK" patch="1">1011448</ref>
      <ref url="http://secunia.com/advisories/12673/" source="SECUNIA" patch="1" adv="1">12673</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2004-September/026955.html" source="FULLDISC" adv="1">20040928 Serendipity 0.7-beta1 SQL Injection PoC</ref>
      <ref url="http://www.osvdb.org/10371" source="OSVDB">10371</ref>
      <ref url="http://www.osvdb.org/10370" source="OSVDB">10370</ref>
    </refs>
    <vuln_soft>
      <prod vendor="s9y" name="serendipity">
        <vers num="0.7_beta1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-2159" published="2004-12-31" name="CVE-2004-2159" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Multiple buffer overflows in XMLStarlet Command Line XML Toolkit 0.9.3 have unknown impact and attack vectors via (1) xml_elem.c and (2) xml_select.c.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/17580" source="XF" patch="1">xmlstarlet-bo(17580)</ref>
      <ref url="http://www.securityfocus.com/bid/11270" source="BID" patch="1">11270</ref>
      <ref url="http://www.osvdb.org/10074" source="OSVDB" patch="1">10074</ref>
      <ref url="http://sourceforge.net/project/shownotes.php?release_id=268962" source="CONFIRM" patch="1">http://sourceforge.net/project/shownotes.php?release_id=268962</ref>
      <ref url="http://securitytracker.com/id?1011496" source="SECTRACK" patch="1">1011496</ref>
    </refs>
    <vuln_soft>
      <prod vendor="xmlstarlet" name="command_line_xml_toolkit">
        <vers num="0.9.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-2160" published="2004-12-31" name="CVE-2004-2160" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:P)" CVSS_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_base_score="6.4">
    <desc>
      <descript source="cve">Format string vulnerability in xml_elem.c for XMLStarlet Command Line XML Toolkit 0.9.3 may allow attackers to cause a denial of service or execute arbitrary code.</descript>
    </desc>
    <loss_types>
      <avail />
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://sourceforge.net/project/shownotes.php?release_id=268962" source="CONFIRM" patch="1">http://sourceforge.net/project/shownotes.php?release_id=268962</ref>
      <ref url="http://cvs.sourceforge.net/viewcvs.py/xmlstar/xmlstarlet/src/xml_elem.c?r1=1.17&amp;r2=1.18" source="CONFIRM">http://cvs.sourceforge.net/viewcvs.py/xmlstar/xmlstarlet/src/xml_elem.c?r1=1.17&amp;r2=1.18</ref>
    </refs>
    <vuln_soft>
      <prod vendor="xmlstarlet" name="command_line_xml_toolkit">
        <vers num="0.9.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-2161" published="2004-12-31" name="CVE-2004-2161" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in file_overview.php in TUTOS 1.1 allows remote attackers to execute arbitrary SQL commands via the link_id parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/17444" source="XF" patch="1">tutos-sql-injection(17444)</ref>
      <ref url="http://secunia.com/advisories/12606/" source="SECUNIA" patch="1" adv="1">12606</ref>
      <ref url="http://www.securityfocus.com/bid/11221" source="BID">11221</ref>
      <ref url="http://www.securityfocus.com/archive/1/375757" source="BUGTRAQ" adv="1">20040918 Vulnerabilities in TUTOS</ref>
      <ref url="http://cvs.sourceforge.net/viewcvs.py/tutos/tutos/php/file/file_overview.php?r1=1.11.2.1&amp;r2=1.11.2.2" source="CONFIRM">http://cvs.sourceforge.net/viewcvs.py/tutos/tutos/php/file/file_overview.php?r1=1.11.2.1&amp;r2=1.11.2.2</ref>
      <ref url="http://www.osvdb.org/10164" source="OSVDB">10164</ref>
      <ref url="http://www.debian.org/security/2006/dsa-980" source="DEBIAN">DSA-980</ref>
      <ref url="http://securitytracker.com/id?1011363" source="SECTRACK">1011363</ref>
      <ref url="http://secunia.com/advisories/18954" source="SECUNIA">18954</ref>
    </refs>
    <vuln_soft>
      <prod vendor="tutos" name="tutos">
        <vers num="1.1_2004-04-14" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-2162" published="2004-12-31" name="CVE-2004-2162" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in TUTOS 1.1 allow remote attackers to inject arbitrary web script or HTML via (1) the search field of the Address Module or (2) the t parameter to app_new.php.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/17445" source="XF" patch="1">tutos-xss(17445)</ref>
      <ref url="http://secunia.com/advisories/12606/" source="SECUNIA" patch="1" adv="1">12606</ref>
      <ref url="http://www.securityfocus.com/bid/11221" source="BID">11221</ref>
      <ref url="http://www.securityfocus.com/archive/1/375757" source="BUGTRAQ" adv="1">20040918 Vulnerabilities in TUTOS</ref>
      <ref url="http://cvs.sourceforge.net/viewcvs.py/tutos/tutos/php/app_new.php?r1=1.58&amp;r2=1.59" source="CONFIRM">http://cvs.sourceforge.net/viewcvs.py/tutos/tutos/php/app_new.php?r1=1.58&amp;r2=1.59</ref>
      <ref url="http://www.debian.org/security/2006/dsa-980" source="DEBIAN">DSA-980</ref>
      <ref url="http://secunia.com/advisories/18954" source="SECUNIA">18954</ref>
    </refs>
    <vuln_soft>
      <prod vendor="tutos" name="tutos">
        <vers num="1.1_2004-04-14" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-2163" published="2004-12-31" name="CVE-2004-2163" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">login_radius on OpenBSD 3.2, 3.5, and possibly other versions does not verify the shared secret in a response packet from a RADIUS server, which allows remote attackers to bypass authentication by spoofing server replies.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/11227" source="BID" patch="1">11227</ref>
      <ref url="http://www.reseau.nl/advisories/0400-openbsd-radius.txt" source="MISC" patch="1" adv="1">http://www.reseau.nl/advisories/0400-openbsd-radius.txt</ref>
      <ref url="http://www.openbsd.org/errata35.html#radius" source="CONFIRM" patch="1">http://www.openbsd.org/errata35.html#radius</ref>
      <ref url="http://secunia.com/advisories/12617" source="SECUNIA" patch="1" adv="1">12617</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/17456" source="XF">openbsd-radius-auth-bypass(17456)</ref>
      <ref url="http://archives.neohapsis.com/archives/vulnwatch/2004-q3/0058.html" source="VULNWATCH" adv="1">20040921 OpenBSD radius authentication vulnerability</ref>
      <ref url="http://www.osvdb.org/10203" source="OSVDB">10203</ref>
    </refs>
    <vuln_soft>
      <prod vendor="openbsd" name="openbsd">
        <vers num="3.2" />
        <vers num="3.4" />
        <vers num="3.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-2164" published="2004-12-31" name="CVE-2004-2164" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">shoprestoreorder.asp in VP-ASP 5.0 does not close the database connection when a user restores a previous order, which allows remote attackers to cause a denial of service (connection consumption).</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://
