<?xml version='1.0' encoding='UTF-8'?>
<nvd xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns="http://nvd.nist.gov/feeds/cve/1.2" nvd_xml_version="1.2" pub_date="2010-02-09" xsi:schemaLocation="http://nvd.nist.gov/feeds/cve/1.2 http://nvd.nist.gov/schema/nvdcve.xsd">
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" name="CVE-2004-1776" seq="2004-1776" severity="High" type="CVE" published="2001-02-28" CVSS_version="2.0 incomplete approximation" CVSS_score="7.5" modified="2008-09-05">
        <desc>
            <descript source="cve">Cisco IOS 12.1(3) and 12.1(3)T allows remote attackers to read and modify device configuration data via the cable-docsis read-write community string used by the Data Over Cable Service Interface Specification (DOCSIS) standard.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot other="1" />
        </loss_types>
        <vuln_types>
            <design />
            <config />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="CERT-VN" patch="1" url="http://www.kb.cert.org/vuls/id/840665" adv="1">VU#840665</ref>
            <ref source="XF" patch="1" url="http://xforce.iss.net/xforce/xfdb/6180" adv="1">cisco-ios-cable-docsis(6180)</ref>
            <ref source="CISCO" patch="1" url="http://www.cisco.com/warp/public/707/ios-snmp-community-vulns-pub.shtml" adv="1">20041008 Cisco IOS Software Multiple SNMP Community String Vulnerabilities</ref>
        </refs>
        <vuln_soft>
            <prod vendor="cisco" name="ios">
                <vers num="12.1(3)" />
                <vers num="12.1(3)t" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" name="CVE-2004-1784" seq="2004-1784" severity="High" type="CVE" published="2004-01-03" CVSS_version="2.0 incomplete approximation" CVSS_score="7.5" modified="2008-09-05">
        <desc>
            <descript source="cve">Buffer overflow in the web server of Webcam Watchdog 3.63 allows remote attackers to execute arbitrary code via a long HTTP GET request.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot user="1" />
        </loss_types>
        <vuln_types>
            <input buffer="1" />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="SECUNIA" patch="1" url="http://secunia.com/advisories/10527" adv="1">10527</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/14131" adv="1">webcam-watchdog-get-bo(14131)</ref>
            <ref source="MISC" url="http://www.webcamsoft.com/en/watchdog_h.html">http://www.webcamsoft.com/en/watchdog_h.html</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/9351" adv="1">9351</ref>
            <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/348818" adv="1">20040103 Webcam Watchdog Stack Overflow Vulnerability</ref>
            <ref source="OSVDB" url="http://www.osvdb.org/3312" adv="1">3312</ref>
            <ref source="MISC" url="http://www.elitehaven.net/webcamwatchdog.txt">http://www.elitehaven.net/webcamwatchdog.txt</ref>
        </refs>
        <vuln_soft>
            <prod vendor="webcam_corp" name="webcam_watchdog">
                <vers num="1.0" />
                <vers num="1.1" />
                <vers num="3.63" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" name="CVE-2004-1785" seq="2004-1785" severity="High" type="CVE" published="2004-01-03" CVSS_version="2.0 incomplete approximation" CVSS_score="7.5" modified="2008-09-05">
        <desc>
            <descript source="cve">SQL injection vulnerability in calendar.php for Invision Power Board 1.3 allows remote attackers to execute arbitrary SQL commands via the m parameter, which sets the $this->chosen_month variable.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot other="1" />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="BID" patch="1" url="http://www.securityfocus.com/bid/9353" adv="1">9353</ref>
            <ref source="OSVDB" patch="1" url="http://www.osvdb.org/3319" adv="1">3319</ref>
            <ref source="SECUNIA" patch="1" url="http://secunia.com/advisories/10530" adv="1">10530</ref>
            <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/348821" adv="1">20040103 [SCSA-025] Invision Power Board SQL Injection Vulnerability</ref>
            <ref source="SECTRACK" url="http://www.securitytracker.com/id?1008589">1008589</ref>
        </refs>
        <vuln_soft>
            <prod vendor="invision_power_services" name="invision_board">
                <vers num="1.0" />
                <vers num="1.0.1" />
                <vers num="1.1.1" />
                <vers num="1.1.2" />
                <vers num="1.2" />
                <vers num="1.3" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" name="CVE-2004-1786" seq="2004-1786" severity="Medium" type="CVE" published="2004-01-04" CVSS_version="2.0 incomplete approximation" CVSS_score="5.0" modified="2008-09-05">
        <desc>
            <descript source="cve">PortalApp places user credentials under the web root with insufficient access control, which allows remote attackers to gain access to sensitive information via a direct request to 8275.mdb.</descript>
        </desc>
        <loss_types>
            <conf />
        </loss_types>
        <vuln_types>
            <access />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/14169" adv="1">portalapp-url-access-database(14169)</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/9354" adv="1">9354</ref>
            <ref source="SECTRACK" url="http://securitytracker.com/id?1008627" adv="1">1008627</ref>
        </refs>
        <vuln_soft>
            <prod vendor="iatek" name="portalapp">
                <vers num="" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" name="CVE-2004-1000" seq="2004-1000" severity="Low" type="CVE" published="2004-01-10" CVSS_version="2.0 incomplete approximation" CVSS_score="2.1" modified="2008-09-05">
        <desc>
            <descript source="cve">lintian 1.23 and earlier removes the working directory even if it was not created by lintian, which may allow local users to delete arbitrary files or directories via a symlink attack.</descript>
        </desc>
        <loss_types>
            <avail />
        </loss_types>
        <vuln_types>
            <design />
        </vuln_types>
        <range>
            <local />
        </range>
        <refs>
            <ref source="XF" patch="1" url="http://xforce.iss.net/xforce/xfdb/18808" adv="1">lintian-symlink(18808)</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/13771">13771</ref>
        </refs>
        <vuln_soft>
            <prod vendor="debian" name="lintian">
                <vers num="1.2_0.17.1" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" name="CVE-2004-1124" seq="2004-1124" severity="Medium" type="CVE" published="2004-01-14" CVSS_version="2.0 incomplete approximation" CVSS_score="4.6" modified="2008-09-05">
        <desc>
            <descript source="cve">Unknown vulnerability in chroot on SCO UnixWare 7.1.1 through 7.1.4 allows local users to escape the chroot jail and conduct unauthorized activities.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <local />
        </range>
        <refs>
            <ref source="XF" patch="1" url="http://xforce.iss.net/xforce/xfdb/18970" adv="1">chroot-jail-security-bypass(18970)</ref>
            <ref source="SCO" patch="1" url="ftp://ftp.sco.com/pub/updates/UnixWare/SCOSA-2005.2/SCOSA-2005.2.txt" adv="1">SCOSA-2005.2</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/12300">12300</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/15339">15339</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/13915">13915</ref>
            <ref source="SCO" url="ftp://ftp.sco.com/pub/updates/OpenServer/SCOSA-2005.22/SCOSA-2005.22.txt">SCOSA-2005.22</ref>
        </refs>
        <vuln_soft>
            <prod vendor="sco" name="openserver">
                <vers num="5.0.6" />
                <vers num="5.0.7" />
            </prod>
            <prod vendor="sco" name="unixware">
                <vers num="7.1.1" />
                <vers num="7.1.3" />
                <vers num="7.1.4" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" name="CVE-2004-1764" seq="2004-1764" severity="High" type="CVE" published="2004-01-14" CVSS_version="2.0 incomplete approximation" CVSS_score="7.2" modified="2009-03-04">
        <desc>
            <descript source="cve">Buffer overflow in CDE libDtSvc on HP-UX B.11.00, B.11.04, B.11.11, and B.11.22 allows local users to gain root privileges via unknown vectors.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot admin="1" />
        </loss_types>
        <vuln_types>
            <input buffer="1" />
        </vuln_types>
        <range>
            <local />
        </range>
        <refs>
            <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/406406" adv="1">VU#406406</ref>
            <ref source="XF" patch="1" url="http://xforce.iss.net/xforce/xfdb/14828" adv="1">hp-libdtsvc-bo(14828)</ref>
            <ref source="HP" patch="1" url="http://www.securityfocus.com/advisories/6237" adv="1">HPSBUX0401-308</ref>
            <ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/o-057.shtml" adv="1">O-057</ref>
            <ref source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5789">oval:org.mitre.oval:def:5789</ref>
        </refs>
        <vuln_soft>
            <prod vendor="hp" name="hp-ux">
                <vers num="11.00" />
                <vers num="11.11" />
                <vers num="11.22" />
                <vers num="11.4" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" name="CVE-2004-0011" seq="2004-0011" severity="High" type="CVE" published="2004-01-20" CVSS_version="2.0 incomplete approximation" CVSS_score="7.5" modified="2008-09-05">
        <desc>
            <descript source="cve">Buffer overflow in fsp before 2.81.b18 allows remote users to execute arbitrary code.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot other="1" />
        </loss_types>
        <vuln_types>
            <input buffer="1" />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="BID" patch="1" url="http://www.securityfocus.com/bid/9377" adv="1">9377</ref>
            <ref source="DEBIAN" patch="1" url="http://www.debian.org/security/2004/dsa-416" adv="1">DSA-416</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/14155" adv="1">fsp-boundry-error-bo(14155)</ref>
            <ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/o-048.shtml">O-048</ref>
        </refs>
        <vuln_soft>
            <prod vendor="debian" name="fsp">
                <vers num="2.81.b18" prev="1" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" name="CVE-2004-0014" seq="2004-0014" severity="High" type="CVE" published="2004-01-20" CVSS_version="2.0 incomplete approximation" CVSS_score="7.5" modified="2008-09-10">
        <desc>
            <descript source="cve">Multiple buffer overflows in the nd WebDAV interface 0.8.2 and earlier allows remote web servers to execute arbitrary code via certain long strings.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot other="1" />
        </loss_types>
        <vuln_types>
            <input bound="1" />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="BID" patch="1" url="http://www.securityfocus.com/bid/9365" adv="1">9365</ref>
            <ref source="DEBIAN" patch="1" url="http://www.debian.org/security/2004/dsa-412" adv="1">DSA-412</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/14141" adv="1">nd-long-string-bo(14141)</ref>
            <ref source="SECTRACK" url="http://www.securitytracker.com/id?1008616">1008616</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/10550">10550</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/10549">10549</ref>
        </refs>
        <vuln_soft>
            <prod vendor="nd" name="nd">
                <vers num="0.8.2" prev="1" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" name="CVE-2004-0037" seq="2004-0037" severity="High" type="CVE" published="2004-01-20" CVSS_version="2.0 incomplete approximation" CVSS_score="7.5" modified="2008-09-05">
        <desc>
            <descript source="cve">FirstClass Desktop Client 7.1 allows remote attackers to execute arbitrary commands via hyperlinks in FirstClass RTF messages.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot other="1" />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/14151" adv="1">firstclassclient-execute-code(14151)</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/9370" adv="1">9370</ref>
            <ref source="OSVDB" url="http://www.osvdb.org/3442">3442</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/10556">10556</ref>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107340950611167&amp;w=2" adv="1">20040105 FirstClass Client 7.1: Command Execution via Email Web Link</ref>
            <ref source="SECTRACK" url="http://www.securitytracker.com/id?1008609">1008609</ref>
        </refs>
        <vuln_soft>
            <prod vendor="opentext" name="opentext_firstclass_desktop_client">
                <vers num="7.1" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" name="CVE-2004-0036" seq="2004-0036" severity="Medium" type="CVE" published="2004-01-20" CVSS_version="2.0 incomplete approximation" CVSS_score="5.0" modified="2008-09-05">
        <desc>
            <descript source="cve">SQL injection vulnerability in calendar.php for vBulletin Forum 2.3.x before 2.3.4 allows remote attackers to steal sensitive information via the eventid parameter.</descript>
        </desc>
        <loss_types>
            <conf />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="BUGTRAQ" patch="1" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107340358202123&amp;w=2" adv="1">20040105 vBulletin Forum 2.3.xx calendar.php SQL Injection</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/14144" adv="1">vbulletin-calendar-sql-injection(14144)</ref>
            <ref source="CONFIRM" url="http://www.vbulletin.com/forum/showthread.php?postid=588825">http://www.vbulletin.com/forum/showthread.php?postid=588825</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/9360">9360</ref>
            <ref source="OSVDB" url="http://www.osvdb.org/3344">3344</ref>
        </refs>
        <vuln_soft>
            <prod vendor="jelsoft" name="vbulletin">
                <vers num="2.3.0" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" name="CVE-2004-0035" seq="2004-0035" severity="High" type="CVE" published="2004-01-20" CVSS_version="2.0 incomplete approximation" CVSS_score="7.5" modified="2008-09-05">
        <desc>
            <descript source="cve">SQL injection vulnerability in register.php for Phorum 3.4.5 and earlier allows remote attackers to execute arbitrary SQL commands via the hide_email parameter.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot other="1" />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/14146" adv="1">phorum-register-sql-injection(14146)</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/9363" adv="1">9363</ref>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107340481804110&amp;w=2" adv="1">20040105 Multiple Vulnerabilities in Phorum 3.4.5</ref>
            <ref source="OSVDB" url="http://www.osvdb.org/3508">3508</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/10567">10567</ref>
        </refs>
        <vuln_soft>
            <prod vendor="phorum" name="phorum">
                <vers num="3.4.5" prev="1" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" name="CVE-2004-0034" seq="2004-0034" severity="Medium" type="CVE" published="2004-01-20" CVSS_version="2.0 incomplete approximation" CVSS_score="4.3" modified="2008-09-05">
        <desc>
            <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in Phorum 3.4.5 and earlier allow remote attackers to inject arbitrary HTML or web script via (1) the phorum_check_xss function in common.php, (2) the EditError variable in profile.php, and (3) the Error variable in login.php.</descript>
        </desc>
        <loss_types>
            <int />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/14145" adv="1">phorum-common-xss(14145)</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/9361" adv="1">9361</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/10567">10567</ref>
            <ref source="CONFIRM" url="http://phorum.org/" adv="1">http://phorum.org/</ref>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107340481804110&amp;w=2" adv="1">20040105 Multiple Vulnerabilities in Phorum 3.4.5</ref>
            <ref source="SECTRACK" url="http://www.securitytracker.com/id?1008633">1008633</ref>
            <ref source="OSVDB" url="http://www.osvdb.org/3510">3510</ref>
            <ref source="OSVDB" url="http://www.osvdb.org/3506">3506</ref>
            <ref source="OSVDB" url="http://www.osvdb.org/3434">3434</ref>
        </refs>
        <vuln_soft>
            <prod vendor="phorum" name="phorum">
                <vers num="3.4.5" prev="1" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" name="CVE-2004-0033" seq="2004-0033" severity="Medium" type="CVE" published="2004-01-20" CVSS_version="2.0 incomplete approximation" CVSS_score="5.0" modified="2008-09-05">
        <desc>
            <descript source="cve">admin.php in PHPGEDVIEW 2.61 allows remote attackers to obtain sensitive information via an action parameter with a phpinfo command.</descript>
        </desc>
        <loss_types>
            <conf />
        </loss_types>
        <vuln_types>
            <access />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="BUGTRAQ" patch="1" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107340840209453&amp;w=2" adv="1">20040106 Vuln in PHPGEDVIEW 2.61 Multi-Problem</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/14162" adv="1">phpgedview-admin-info-disclosure(14162)</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/9371">9371</ref>
            <ref source="OSVDB" url="http://www.osvdb.org/3404">3404</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/10565">10565</ref>
        </refs>
        <vuln_soft>
            <prod vendor="phpgedview" name="phpgedview">
                <vers num="2.61" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" name="CVE-2004-0032" seq="2004-0032" severity="Medium" type="CVE" published="2004-01-20" CVSS_version="2.0 incomplete approximation" CVSS_score="6.8" modified="2008-09-05">
        <desc>
            <descript source="cve">Cross-site scripting (XSS) vulnerability in search.php in PHPGEDVIEW 2.61 allows remote attackers to inject arbitrary HTML and web script via the firstname parameter.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot other="1" />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="BUGTRAQ" patch="1" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107340840209453&amp;w=2" adv="1">20040106 Vuln in PHPGEDVIEW 2.61 Multi-Problem</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/14160" adv="1">phpgedview-search-xss(14160)</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/9369">9369</ref>
            <ref source="OSVDB" url="http://www.osvdb.org/3402">3402</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/10565">10565</ref>
        </refs>
        <vuln_soft>
            <prod vendor="phpgedview" name="phpgedview">
                <vers num="2.61" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" name="CVE-2004-0031" seq="2004-0031" severity="High" type="CVE" published="2004-01-20" CVSS_version="2.0 incomplete approximation" CVSS_score="7.5" modified="2008-09-05">
        <desc>
            <descript source="cve">PHPGEDVIEW 2.61 allows remote attackers to reinstall the software and change the administrator password via a direct HTTP request to editconfig.php.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot other="1" />
        </loss_types>
        <vuln_types>
            <access />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="BUGTRAQ" patch="1" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107340840209453&amp;w=2" adv="1">20040106 Vuln in PHPGEDVIEW 2.61 Multi-Problem</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/14161" adv="1">phpgedview-modify-admin-password(14161)</ref>
            <ref source="OSVDB" url="http://www.osvdb.org/3403">3403</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/10565">10565</ref>
        </refs>
        <vuln_soft>
            <prod vendor="phpgedview" name="phpgedview">
                <vers num="2.61" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" name="CVE-2004-0030" seq="2004-0030" severity="High" type="CVE" published="2004-01-20" CVSS_version="2.0 incomplete approximation" CVSS_score="7.5" modified="2008-09-05">
        <desc>
            <descript source="cve">PHP remote file inclusion vulnerability in (1) functions.php, (2) authentication_index.php, and (3) config_gedcom.php for PHPGEDVIEW 2.61 allows remote attackers to execute arbitrary PHP code by modifying the PGV_BASE_DIRECTORY parameter to reference a URL on a remote web server that contains the code.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot other="1" />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/14159" adv="1">phpgedview-pgvbasedirectory-file-include(14159)</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/9368">9368</ref>
            <ref source="OSVDB" url="http://www.osvdb.org/3343">3343</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/10565" adv="1">10565</ref>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107340840209453&amp;w=2">20040106 Vuln in PHPGEDVIEW 2.61 Multi-Problem</ref>
            <ref source="SECTRACK" url="http://www.securitytracker.com/id?1008632">1008632</ref>
        </refs>
        <vuln_soft>
            <prod vendor="phpgedview" name="phpgedview">
                <vers num="2.61" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" name="CVE-2004-0029" seq="2004-0029" severity="Medium" type="CVE" published="2004-01-20" CVSS_version="2.0 incomplete approximation" CVSS_score="4.6" modified="2008-09-05">
        <desc>
            <descript source="cve">Lotus Notes Domino 6.0.2 on Linux installs the notes.ini configuration file with world-writable permissions, which allows local users to modify the Notes configuration and gain privileges.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot other="1" />
        </loss_types>
        <vuln_types>
            <config />
        </vuln_types>
        <range>
            <local />
        </range>
        <refs>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/14153" adv="1">lotus-notes-insecure-permissions(14153)</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/9366" adv="1">9366</ref>
            <ref source="SECTRACK" url="http://www.securitytracker.com/id?1008623">1008623</ref>
            <ref source="OSVDB" url="http://www.osvdb.org/3424">3424</ref>
            <ref source="MISC" url="http://www.excluded.org/advisories/advisory05.txt">http://www.excluded.org/advisories/advisory05.txt</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/10566">10566</ref>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107340897710308&amp;w=2">20040106 Lotus Notes Domino 6.0.2 (linux) faulty default permissions</ref>
        </refs>
        <vuln_soft>
            <prod vendor="ibm" name="lotus_domino">
                <vers num="6.0.2" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" name="CVE-2004-1766" seq="2004-1766" severity="Medium" type="CVE" published="2004-01-20" CVSS_version="2.0 incomplete approximation" CVSS_score="5.0" modified="2008-09-05">
        <desc>
            <descript source="cve">The default installation of NetScreen-Security Manager before Feature Pack 1 does not enable encryption for communication with devices running ScreenOS 5.0, which allows remote attackers to obtain sensitive information via sniffing.</descript>
        </desc>
        <loss_types>
            <conf />
        </loss_types>
        <vuln_types>
            <config />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="CONFIRM" url="http://www.kb.cert.org/vuls/id/CRDY-5VEU8N" adv="1">http://www.kb.cert.org/vuls/id/CRDY-5VEU8N</ref>
            <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/927630" adv="1">VU#927630</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/14886" adv="1">netscreen-information-disclosure(14886)</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/9455" adv="1">9455</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/10675" adv="1">10675</ref>
            <ref source="OSVDB" url="http://www.osvdb.org/3613">3613</ref>
            <ref source="CONFIRM" url="http://www.juniper.net/support/security/alerts/58290.txt">http://www.juniper.net/support/security/alerts/58290.txt</ref>
        </refs>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" name="CVE-2004-2127" seq="2004-2127" severity="Medium" type="CVE" published="2004-01-20" CVSS_version="2.0 incomplete approximation" CVSS_score="5.0" modified="2008-09-05">
        <desc>
            <descript source="cve">Directory traversal vulnerability in Web Blog 1.1 allows remote attackers to read arbitrary files via a .. (dot dot) in the file variable.</descript>
        </desc>
        <loss_types>
            <conf />
        </loss_types>
        <vuln_types>
            <access />
            <input />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="XF" patch="1" url="http://xforce.iss.net/xforce/xfdb/14978" adv="1">webblog-dotdot-directory-traversal(14978)</ref>
            <ref source="MISC" patch="1" url="http://www.zone-h.org/en/advisories/read/id=3822/" adv="1">http://www.zone-h.org/en/advisories/read/id=3822/</ref>
            <ref source="BID" patch="1" url="http://www.securityfocus.com/bid/9517" adv="1">9517</ref>
            <ref source="BUGTRAQ" patch="1" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107531194527602&amp;w=2" adv="1">20040128 ZH2004-01SA (security advisory): Web Blog 1.1 Remote arbitrary</ref>
            <ref source="OSVDB" url="http://www.osvdb.org/3739">3739</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/10740">10740</ref>
        </refs>
        <vuln_soft>
            <prod vendor="leif_m._wright" name="web_blog">
                <vers num="1.1" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" name="CVE-2004-1759" seq="2004-1759" severity="Medium" type="CVE" published="2004-01-21" CVSS_version="2.0" CVSS_score="5.0" modified="2008-09-05">
        <desc>
            <descript source="cve">Cisco voice products, when running the IBM Director Agent on IBM servers before OS 2000.2.6, allows remote attackers to cause a denial of service (CPU consumption) via arbitrary packets to TCP port 14247, as demonstrated using port scanning.</descript>
        </desc>
        <loss_types>
            <avail />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="CERT-VN" patch="1" url="http://www.kb.cert.org/vuls/id/721092" adv="1">VU#721092</ref>
            <ref source="BID" patch="1" url="http://www.securityfocus.com/bid/9469" adv="1">9469</ref>
            <ref source="CISCO" patch="1" url="http://www.cisco.com/warp/public/707/cisco-sa-20040121-voice.shtml" adv="1">20040121 Voice Product Vulnerabilities on IBM Servers</ref>
            <ref source="SECUNIA" patch="1" url="http://secunia.com/advisories/10696" adv="1">10696</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/14901" adv="1">ciscovoice-ibmservers-dos(14901)</ref>
            <ref source="SECTRACK" url="http://www.securitytracker.com/id?1008814">1008814</ref>
            <ref source="OSVDB" url="http://www.osvdb.org/3691">3691</ref>
            <ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/o-066.shtml">O-066</ref>
        </refs>
        <vuln_soft>
            <prod vendor="cisco" name="emergency_responder">
                <vers num="1.1" />
            </prod>
            <prod vendor="cisco" name="ip_call_center_express_enhanced">
                <vers num="3.0" />
            </prod>
            <prod vendor="cisco" name="ip_call_center_express_standard">
                <vers num="3.0" />
            </prod>
            <prod vendor="cisco" name="ip_interactive_voice_response">
                <vers num="3.0" />
            </prod>
            <prod vendor="cisco" name="personal_assistant">
                <vers num="1.3(1)" />
                <vers num="1.3(2)" />
                <vers num="1.3(3)" />
                <vers num="1.3(4)" />
                <vers num="1.4(1)" />
                <vers num="1.4(2)" />
            </prod>
            <prod vendor="ibm" name="director_agent">
                <vers num="2.2" />
                <vers num="3.11" />
            </prod>
            <prod vendor="cisco" name="call_manager">
                <vers num="1.0" />
                <vers num="2.0" />
                <vers num="3.0" />
                <vers num="3.1" />
                <vers num="3.1(2)" />
                <vers num="3.1(3a)" />
                <vers num="3.2" />
                <vers num="3.3" />
                <vers num="3.3(3)" />
                <vers num="4.0" />
            </prod>
            <prod vendor="cisco" name="internet_service_node">
                <vers num="" />
            </prod>
            <prod vendor="ibm" name="mcs-7815-1000">
                <vers num="" />
            </prod>
            <prod vendor="ibm" name="mcs-7815i-2.0">
                <vers num="" />
            </prod>
            <prod vendor="ibm" name="mcs-7835i-2.4">
                <vers num="" />
            </prod>
            <prod vendor="ibm" name="mcs-7835i-3.0">
                <vers num="" />
            </prod>
            <prod vendor="ibm" name="x330">
                <vers num="8654" />
                <vers num="8674" />
            </prod>
            <prod vendor="ibm" name="x340">
                <vers num="" />
            </prod>
            <prod vendor="ibm" name="x342">
                <vers num="" />
            </prod>
            <prod vendor="ibm" name="x345">
                <vers num="" />
            </prod>
            <prod vendor="cisco" name="conference_connection">
                <vers num="1.1(1)" />
                <vers num="1.2" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" name="CVE-2004-1760" seq="2004-1760" severity="High" type="CVE" published="2004-01-21" CVSS_version="2.0" CVSS_score="10.0" modified="2008-09-05">
        <desc>
            <descript source="cve">The default installation of Cisco voice products, when running the IBM Director Agent on IBM servers before OS 2000.2.6, does not require authentication, which allows remote attackers to gain administrator privileges by connecting to TCP port 14247.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot admin="1" />
        </loss_types>
        <vuln_types>
            <access />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="CERT-VN" patch="1" url="http://www.kb.cert.org/vuls/id/602734" adv="1">VU#602734</ref>
            <ref source="XF" patch="1" url="http://xforce.iss.net/xforce/xfdb/14900" adv="1">ciscovoice-ibmservers-admin-access(14900)</ref>
            <ref source="BID" patch="1" url="http://www.securityfocus.com/bid/9468" adv="1">9468</ref>
            <ref source="CISCO" patch="1" url="http://www.cisco.com/warp/public/707/cisco-sa-20040121-voice.shtml" adv="1">20040121 Voice Product Vulnerabilities on IBM Servers</ref>
            <ref source="SECUNIA" patch="1" url="http://secunia.com/advisories/10696" adv="1">10696</ref>
            <ref source="SECTRACK" url="http://www.securitytracker.com/id?1008814">1008814</ref>
            <ref source="OSVDB" url="http://www.osvdb.org/3692">3692</ref>
            <ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/o-066.shtml">O-066</ref>
        </refs>
        <vuln_soft>
            <prod vendor="cisco" name="emergency_responder">
                <vers num="1.1" />
            </prod>
            <prod vendor="cisco" name="ip_call_center_express_enhanced">
                <vers num="3.0" />
            </prod>
            <prod vendor="cisco" name="ip_call_center_express_standard">
                <vers num="3.0" />
            </prod>
            <prod vendor="cisco" name="ip_interactive_voice_response">
                <vers num="3.0" />
            </prod>
            <prod vendor="cisco" name="personal_assistant">
                <vers num="1.3(1)" />
                <vers num="1.3(2)" />
                <vers num="1.3(3)" />
                <vers num="1.3(4)" />
                <vers num="1.4(1)" />
                <vers num="1.4(2)" />
            </prod>
            <prod vendor="ibm" name="director_agent">
                <vers num="2.2" />
                <vers num="3.11" />
            </prod>
            <prod vendor="cisco" name="call_manager">
                <vers num="1.0" />
                <vers num="2.0" />
                <vers num="3.0" />
                <vers num="3.1" />
                <vers num="3.1(2)" />
                <vers num="3.1(3a)" />
                <vers num="3.2" />
                <vers num="3.3" />
                <vers num="3.3(3)" />
                <vers num="4.0" />
            </prod>
            <prod vendor="cisco" name="internet_service_node">
                <vers num="" />
            </prod>
            <prod vendor="ibm" name="mcs-7815-1000">
                <vers num="" />
            </prod>
            <prod vendor="ibm" name="mcs-7815i-2.0">
                <vers num="" />
            </prod>
            <prod vendor="ibm" name="mcs-7835i-2.4">
                <vers num="" />
            </prod>
            <prod vendor="ibm" name="mcs-7835i-3.0">
                <vers num="" />
            </prod>
            <prod vendor="ibm" name="x330">
                <vers num="8654" />
                <vers num="8674" />
            </prod>
            <prod vendor="ibm" name="x340">
                <vers num="" />
            </prod>
            <prod vendor="ibm" name="x342">
                <vers num="" />
            </prod>
            <prod vendor="ibm" name="x345">
                <vers num="" />
            </prod>
            <prod vendor="cisco" name="conference_connection">
                <vers num="1.1(1)" />
                <vers num="1.2" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" name="CVE-2004-2120" seq="2004-2120" severity="Medium" type="CVE" published="2004-01-23" CVSS_version="2.0 incomplete approximation" CVSS_score="5.0" modified="2008-09-05">
        <desc>
            <descript source="cve">Reptile Web Server allows remote attackers to cause a denial of service (CPU consumption) via multiple incomplete GET requests without the HTTP version.</descript>
        </desc>
        <loss_types>
            <avail />
        </loss_types>
        <vuln_types>
            <exception />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/14932" adv="1">reptilewebserver-get-dos(14932)</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/9482" adv="1">9482</ref>
            <ref source="MISC" url="http://www.autistici.org/fdonato/advisory/reptilewsDailyVersion-adv.txt" adv="1">http://www.autistici.org/fdonato/advisory/reptilewsDailyVersion-adv.txt</ref>
            <ref source="SECTRACK" url="http://securitytracker.com/id?1008842" adv="1">1008842</ref>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107497355713434&amp;w=2" adv="1">20040124 Resources consumption in Reptile webserver daily version</ref>
        </refs>
        <vuln_soft>
            <prod vendor="reptile_web_server" name="reptile_web_server">
                <vers num="2002-01-05" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" name="CVE-2004-2117" seq="2004-2117" severity="Medium" type="CVE" published="2004-01-24" CVSS_version="2.0 incomplete approximation" CVSS_score="5.0" modified="2008-09-10">
        <desc>
            <descript source="cve">Tiny Server 1.1 allows remote attackers to cause a denial of service (crash) via malformed HTTP requests such as (1) a GET request without the HTTP version (HTTP/1.1), or (2) a request without GET or the HTTP version.</descript>
        </desc>
        <loss_types>
            <avail />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/14928" adv="1">tinyserver-string-dos(14928)</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/9485" adv="1">9485</ref>
            <ref source="MISC" url="http://www.autistici.org/fdonato/advisory/tinyServer1.1%5B1.0.5%5D-adv.txt">http://www.autistici.org/fdonato/advisory/tinyServer1.1[1.0.5]-adv.txt</ref>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107496530806730&amp;w=2" adv="1">20040124 Tiny Server 1.1 (1.0.5) Multiple Vulnerabilities</ref>
            <ref source="OSVDB" url="http://www.osvdb.org/3709">3709</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/10707">10707</ref>
        </refs>
        <vuln_soft>
            <prod vendor="tinyserver" name="tinyserver">
                <vers num="1.1" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" name="CVE-2004-2122" seq="2004-2122" severity="Medium" type="CVE" published="2004-01-24" CVSS_version="2.0 incomplete approximation" CVSS_score="4.3" modified="2009-01-29">
        <desc>
            <descript source="cve">Cross-site scripting (XSS) vulnerability in intraforum_db.cgi in Intra Forum allows remote attackers to inject arbitrary web script or HTML via the (1) use_last_read or (2) forum parameters.</descript>
        </desc>
        <loss_types>
            <int />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/14933" adv="1">intraforum-intraforumcgi-xss(14933)</ref>
            <ref source="SECTRACK" url="http://www.securitytracker.com/id?1008839">1008839</ref>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107497803617071&amp;w=2" adv="1">20040124 Inrtra Forum Cross Site Scripting Vulnerabillity</ref>
        </refs>
        <vuln_soft>
            <prod vendor="intra_forum" name="intra_forum">
                <vers num="" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" name="CVE-2004-2131" seq="2004-2131" severity="High" type="CVE" published="2004-01-27" CVSS_version="2.0 incomplete approximation" CVSS_score="7.2" modified="2008-09-05">
        <desc>
            <descript source="cve">Stack-based buffer overflow in ontape for IBM Informix Dynamic Server (IDS) 9.40.xC3 and earlier allows local users, with DSA privileges, to execute arbitrary code via a long ONCONFIG environment variable.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot admin="1" />
        </loss_types>
        <vuln_types>
            <input buffer="1" />
        </vuln_types>
        <range>
            <local />
        </range>
        <refs>
            <ref source="BID" patch="1" url="http://www.securityfocus.com/bid/9512" adv="1">9512</ref>
            <ref source="CONFIRM" patch="1" url="http://www-1.ibm.com/support/docview.wss?uid=swg21153336" adv="1">http://www-1.ibm.com/support/docview.wss?uid=swg21153336</ref>
            <ref source="BUGTRAQ" patch="1" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107539878804074&amp;w=2" adv="1">20040129 ----------========== OPEN3S-2003-08-08-eng-informix-ontape</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/14970" adv="1">informix-ontape-binary-bo(14970)</ref>
            <ref source="OSVDB" url="http://www.osvdb.org/3759">3759</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/10737/">10737</ref>
        </refs>
        <vuln_soft>
            <prod vendor="ibm" name="informix_dynamic_server">
                <vers num="9.40.uc1" />
                <vers num="9.40.uc2" />
            </prod>
            <prod vendor="ibm" name="informix_extended_parallel_server">
                <vers num="8.40_uc1" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" name="CVE-2004-2134" seq="2004-2134" severity="Medium" type="CVE" published="2004-01-28" CVSS_version="2.0 incomplete approximation" CVSS_score="4.6" modified="2008-09-05">
        <desc>
            <descript source="cve">Oracle toplink mapping workBench uses a weak encryption algorithm for passwords, which allows local users to decrypt the passwords.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot other="1" />
        </loss_types>
        <vuln_types>
            <design />
        </vuln_types>
        <range>
            <local />
        </range>
        <refs>
            <ref source="BID" url="http://www.securityfocus.com/bid/9515" adv="1">9515</ref>
            <ref source="VULN-DEV" url="http://www.securityfocus.com/archive/82/351719" adv="1">20040128 Re: Oracle toplink mapping workbench password algorithm</ref>
            <ref source="MISC" url="http://www.planet-source-code.com/vb/scripts/ShowCode.asp?txtCodeId=803&amp;lngWId=5">http://www.planet-source-code.com/vb/scripts/ShowCode.asp?txtCodeId=803&amp;lngWId=5</ref>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107531028325112&amp;w=2" adv="1">20040128 Oracle toplink mapping workbench password algorithm</ref>
            <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/352315/30/21430/threaded">20040128 Re: Oracle toplink mapping workbench password algorithm</ref>
        </refs>
        <vuln_soft>
            <prod vendor="oracle" name="application_server">
                <vers num="9.0.2" />
                <vers num="9.0.2.0.0" />
                <vers num="9.0.2.0.1" />
                <vers num="9.0.2.1" />
                <vers num="9.0.2.2" />
                <vers num="9.0.2.3" />
                <vers num="9.0.3" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" name="CVE-2004-2034" seq="2004-2034" severity="High" type="CVE" published="2004-01-29" CVSS_version="2.0 incomplete approximation" CVSS_score="7.5" modified="2008-09-05">
        <desc>
            <descript source="cve">Buffer overflow in the (1) WTHoster and (2) WebDriver modules in WildTangent Web Driver 4.0 allows remote attackers to execute arbitrary code via a long filename.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot user="1" />
        </loss_types>
        <vuln_types>
            <input buffer="1" />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="XF" patch="1" url="http://xforce.iss.net/xforce/xfdb/16266" adv="1">wildtangent-wthoster-webdriver-bo(16266)</ref>
            <ref source="BID" patch="1" url="http://www.securityfocus.com/bid/10421" adv="1">10421</ref>
            <ref source="OSVDB" patch="1" url="http://www.osvdb.org/6445" adv="1">6445</ref>
            <ref source="MISC" patch="1" url="http://www.ngssoftware.com/advisories/wildtangent.txt" adv="1">http://www.ngssoftware.com/advisories/wildtangent.txt</ref>
            <ref source="SECUNIA" patch="1" url="http://secunia.com/advisories/11727" adv="1">11727</ref>
            <ref source="BUGTRAQ" patch="1" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108569235217149&amp;w=2" adv="1">20040527 WildTangent Web Driver Long FileName Stack Overflow</ref>
        </refs>
        <vuln_soft>
            <prod vendor="wildtangent" name="webdriver">
                <vers num="4.0" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" name="CVE-2004-2132" seq="2004-2132" severity="Medium" type="CVE" published="2004-01-29" CVSS_version="2.0 incomplete approximation" CVSS_score="5.0" modified="2008-09-05">
        <desc>
            <descript source="cve">Directory traversal vulnerability in PJreview_Neo.cgi in PJ CGI Neo review allows remote attackers to read arbitrary files via a ..  (dot dot) in the p parameter.</descript>
        </desc>
        <loss_types>
            <conf />
        </loss_types>
        <vuln_types>
            <access />
            <input />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/14980" adv="1">pjcgineoreview-dotdot-directory-traversal(14980)</ref>
            <ref source="MISC" url="http://www.zone-h.org/advisories/read/id=3824" adv="1">http://www.zone-h.org/advisories/read/id=3824</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/9524" adv="1">9524</ref>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107539804702913&amp;w=2" adv="1">20040129 ZH2004-02SA (security advisory): PJ CGI Neo review (NeoBoard review) Remote arbitrary file retrieving</ref>
            <ref source="SECUNIA" url="http://www.secunia.com/advisories/10734/">10734</ref>
            <ref source="OSVDB" url="http://www.osvdb.org/3746">3746</ref>
        </refs>
        <vuln_soft>
            <prod vendor="pj_cgi_neo_review" name="pj_cgi_neo_review">
                <vers num="" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" name="CVE-2004-2133" seq="2004-2133" severity="Medium" type="CVE" published="2004-01-29" CVSS_version="2.0 incomplete approximation" CVSS_score="4.6" modified="2008-09-05">
        <desc>
            <descript source="cve">Certain third-party packages for CVSup 16.1h, such as SuSE Linux, contain untrusted paths in the ELF RPATH fields of certain executables, which could allow local users to execute arbitrary code by causing cvsup to link against malicious libraries that are created in world-writable directories such as /usr/src/packages.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot user="1" />
        </loss_types>
        <vuln_types>
            <config />
        </vuln_types>
        <range>
            <local />
        </range>
        <refs>
            <ref source="XF" patch="1" url="http://xforce.iss.net/xforce/xfdb/14994" adv="1">cvsup-rpath-gain-privileges(14994)</ref>
            <ref source="BID" patch="1" url="http://www.securityfocus.com/bid/9523" adv="1">9523</ref>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107539776002450&amp;w=2" adv="1">20040129 Security Announcement: untrusted ELF library path in some cvsup binary RPMs</ref>
            <ref source="VULNWATCH" url="http://archives.neohapsis.com/archives/vulnwatch/2004-q1/0025.html" adv="1">20040129 Security Announcement: untrusted ELF library path in some cvsup binary RPMs</ref>
        </refs>
        <vuln_soft>
            <prod vendor="cvsup" name="cvsup">
                <vers num="cvsup-16.1h-2.i386.rpm" />
                <vers num="cvsup-16.1h-36.i586.rpm" />
                <vers num="cvsup-16.1h-43.i586.rpm" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" name="CVE-2004-0028" seq="2004-0028" severity="High" type="CVE" published="2004-02-03" CVSS_version="2.0 incomplete approximation" CVSS_score="7.5" modified="2008-09-05">
        <desc>
            <descript source="cve">jitterbug 1.6.2 does not properly sanitize inputs, which allows remote authenticated users to execute arbitrary commands.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot other="1" />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="DEBIAN" patch="1" url="http://www.debian.org/security/2004/dsa-420" adv="1">DSA-420</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/9397" adv="1">9397</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/14207">jitterbug-execute-code(14207)</ref>
        </refs>
        <vuln_soft>
            <prod vendor="samba" name="jitterbug">
                <vers num="1.6.2" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" name="CVE-2004-0017" seq="2004-0017" severity="High" type="CVE" published="2004-02-03" CVSS_version="2.0 incomplete approximation" CVSS_score="7.5" modified="2008-09-05">
        <desc>
            <descript source="cve">Multiple SQL injection vulnerabilities in the (1) calendar and (2) infolog modules for phpgroupware 0.9.14 allow remote attackers to perform unauthorized database operations.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot other="1" />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="DEBIAN" patch="1" url="http://www.debian.org/security/2004/dsa-419" adv="1">DSA-419</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/9386" adv="1">9386</ref>
            <ref source="SECTRACK" url="http://www.securitytracker.com/id?1008662">1008662</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/10591">10591</ref>
        </refs>
        <vuln_soft>
            <prod vendor="phpgroupware" name="phpgroupware">
                <vers num="0.9.14" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" name="CVE-2004-0016" seq="2004-0016" severity="High" type="CVE" published="2004-02-03" CVSS_version="2.0 incomplete approximation" CVSS_score="7.5" modified="2008-09-05">
        <desc>
            <descript source="cve">The calendar module for phpgroupware 0.9.14 does not enforce the "save extension" feature for holiday files, which allows remote attackers to create and execute PHP files.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot other="1" />
        </loss_types>
        <vuln_types>
            <design />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="DEBIAN" patch="1" url="http://www.debian.org/security/2004/dsa-419" adv="1">DSA-419</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/9387" adv="1">9387</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/13489">phpgroupware-calendar-file-include(13489)</ref>
            <ref source="OSVDB" url="http://www.osvdb.org/6860">6860</ref>
        </refs>
        <vuln_soft>
            <prod vendor="phpgroupware" name="phpgroupware">
                <vers num="0.9.14" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" name="CVE-2004-0015" seq="2004-0015" severity="High" type="CVE" published="2004-02-03" CVSS_version="2.0 incomplete approximation" CVSS_score="7.2" modified="2008-09-05">
        <desc>
            <descript source="cve">vbox3 0.1.8 and earlier does not properly drop privileges before executing a user-provided TCL script, which allows local users to gain privileges.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot admin="1" />
        </loss_types>
        <vuln_types>
            <design />
        </vuln_types>
        <range>
            <local />
        </range>
        <refs>
            <ref source="DEBIAN" patch="1" url="http://www.debian.org/security/2004/dsa-418" adv="1">DSA-418</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/9381" adv="1">9381</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/14170">vbox3-gain-privileges(14170)</ref>
        </refs>
        <vuln_soft>
            <prod vendor="vbox3" name="vbox3">
                <vers num="0.1.8" prev="1" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" name="CVE-2004-0013" seq="2004-0013" severity="Medium" type="CVE" published="2004-02-03" CVSS_version="2.0 incomplete approximation" CVSS_score="5.0" modified="2008-09-05">
        <desc>
            <descript source="cve">jabber 1.4.2, 1.4.2a, and possibly earlier versions, does not properly handle SSL connections, which allows remote attackers to cause a denial of service (crash).</descript>
        </desc>
        <loss_types>
            <avail />
        </loss_types>
        <vuln_types>
            <other />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="MANDRAKE" patch="1" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2004:005" adv="1">MDKSA-2004:005</ref>
            <ref source="DEBIAN" patch="1" url="http://www.debian.org/security/2004/dsa-414" adv="1">DSA-414</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/14158" adv="1">jabber-ssl-connections-dos(14158)</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/9376" adv="1">9376</ref>
            <ref source="OSVDB" url="http://www.osvdb.org/3345">3345</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/10559">10559</ref>
        </refs>
        <vuln_soft>
            <prod vendor="jabber_software_foundation" name="jabber_server">
                <vers num="1.4.2a" />
                <vers num="1.4.3" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" name="CVE-2004-0046" seq="2004-0046" severity="Medium" type="CVE" published="2004-02-03" CVSS_version="2.0 incomplete approximation" CVSS_score="4.3" modified="2008-09-05">
        <desc>
            <descript source="cve">Cross-site scripting (XSS) vulnerability in SnapStream PVS LITE allows remote attackers to inject arbitrary web script or HTML via a GET request containing a terminating '"' (double quote) character.</descript>
        </desc>
        <loss_types>
            <int />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/14164">snapstream-quotation-xss(14164)</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/9375" adv="1">9375</ref>
            <ref source="OSVDB" url="http://www.osvdb.org/3440">3440</ref>
            <ref source="SECTRACK" url="http://securitytracker.com/id?1008646">1008646</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/10575">10575</ref>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107350313917867&amp;w=2" adv="1">20040106 SnapStream PVS LITE Cross Site Scripting Vulnerabillity</ref>
        </refs>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" name="CVE-2004-0045" seq="2004-0045" severity="High" type="CVE" published="2004-02-03" CVSS_version="2.0 incomplete approximation" CVSS_score="7.5" modified="2008-09-05">
        <desc>
            <descript source="cve">Buffer overflow in the ARTpost function in art.c in the control message handling code for INN 2.4.0 may allow remote attackers to execute arbitrary code.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot user="1" />
        </loss_types>
        <vuln_types>
            <input buffer="1" />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/759020">VU#759020</ref>
            <ref source="BID" patch="1" url="http://www.securityfocus.com/bid/9382" adv="1">9382</ref>
            <ref source="BUGTRAQ" patch="1" url="http://archives.neohapsis.com/archives/bugtraq/2004-01/0064.html" adv="1">20040108 [OpenPKG-SA-2004.001] OpenPKG Security Advisory (inn)</ref>
            <ref source="BUGTRAQ" patch="1" url="http://archives.neohapsis.com/archives/bugtraq/2004-01/0063.html" adv="1">20040107 [SECURITY] INN: Buffer overflow in control message handling</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/14190">inn-artpost-control-message-bo(14190)</ref>
            <ref source="SLACKWARE" url="http://www.slackware.org/security/viewer.php?l=slackware-security&amp;y=2004&amp;m=slackware-security.365791">SSA:2004-014-02</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/10578">10578</ref>
        </refs>
        <vuln_soft>
            <prod vendor="isc" name="inn">
                <vers num="2.4.0" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" name="CVE-2004-0044" seq="2004-0044" severity="High" type="CVE" published="2004-02-03" CVSS_version="2.0 incomplete approximation" CVSS_score="7.5" modified="2008-09-05">
        <desc>
            <descript source="cve">Cisco Personal Assistant 1.4(1) and 1.4(2) disables password authentication when "Allow Only Cisco CallManager Users" is enabled and the Corporate Directory settings refer to the directory service being used by Cisco CallManager, which allows remote attackers to gain access with a valid username.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot other="1" />
        </loss_types>
        <vuln_types>
            <config />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="CISCO" patch="1" url="http://www.cisco.com/warp/public/707/cisco-sa-20040108-pa.shtml" adv="1">20040108 Cisco Personal Assistant User Password Bypass Vulnerability</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/14172">ciscopersonalassistant-config-file-access(14172)</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/9384">9384</ref>
            <ref source="OSVDB" url="http://www.osvdb.org/3430">3430</ref>
        </refs>
        <vuln_soft>
            <prod vendor="cisco" name="personal_assistant">
                <vers num="1.4(1)" />
                <vers num="1.4(2)" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" name="CVE-2004-0043" seq="2004-0043" severity="High" type="CVE" published="2004-02-03" CVSS_version="2.0 incomplete approximation" CVSS_score="7.5" modified="2008-09-05">
        <desc>
            <descript source="cve">Buffer overflow in Yahoo Instant Messenger 5.6.0.1351 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long filename in the download feature.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot other="1" />
        </loss_types>
        <vuln_types>
            <input buffer="1" />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="BID" url="http://www.securityfocus.com/bid/9383">9383</ref>
            <ref source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2004-January/015334.html">20040108 Yahoo Instant Messenger Long Filename Downloading Buffer Overflow</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/14171">yahoo-messenger-filename-bo(14171)</ref>
            <ref source="SECTRACK" url="http://www.securitytracker.com/id?1008651">1008651</ref>
            <ref source="OSVDB" url="http://www.osvdb.org/3437">3437</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/10573">10573</ref>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107357996802255&amp;w=2">20040108 Yahoo Instant Messenger Long Filename Downloading Buffer Overflow</ref>
        </refs>
        <vuln_soft>
            <prod vendor="yahoo" name="messenger">
                <vers num="5.6.0.1351" prev="1" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" name="CVE-2004-0042" seq="2004-0042" severity="Medium" type="CVE" published="2004-02-03" CVSS_version="2.0 incomplete approximation" CVSS_score="5.0" modified="2008-09-10">
        <desc>
            <descript source="cve">vsftpd 1.1.3 generates different error messages depending on whether or not a valid username exists, which allows remote attackers to identify valid usernames.</descript>
        </desc>
        <loss_types>
            <conf />
        </loss_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="SECTRACK" url="http://securitytracker.com/id?1008628">1008628</ref>
        </refs>
        <vuln_soft>
            <prod vendor="beasts" name="vsftpd">
                <vers num="1.1.3" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" name="CVE-2004-0041" seq="2004-0041" severity="High" type="CVE" published="2004-02-03" CVSS_version="2.0" CVSS_score="7.5" modified="2008-09-05">
        <desc>
            <descript source="cve">The mod_auth_shadow module 1.4 and earlier does not properly enforce the expiration of a user account and password, which could allow remote authenticated users to bypass intended access restrictions.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot other="1" />
        </loss_types>
        <vuln_types>
            <design />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="DEBIAN" patch="1" url="http://www.debian.org/security/2004/dsa-421" adv="1">DSA-421</ref>
            <ref source="SECTRACK" url="http://www.securitytracker.com/id?1008675">1008675</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/9404" adv="1">9404</ref>
            <ref source="OSVDB" url="http://www.osvdb.org/3454">3454</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/10612" adv="1">10612</ref>
        </refs>
        <vuln_soft>
            <prod vendor="mod_auth_shadow" name="mod_auth_shadow">
                <vers num="1.0" />
                <vers num="1.1" />
                <vers num="1.2" />
                <vers num="1.3" />
                <vers num="1.4" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" name="CVE-2004-1082" seq="2004-1082" severity="High" type="CVE" published="2004-02-03" CVSS_version="2.0 incomplete approximation" CVSS_score="7.5" modified="2008-09-05">
        <desc>
            <descript source="cve">mod_digest_apple for Apache 1.3.31 and 1.3.32 on Mac OS X Server does not properly verify the nonce of a client response, which allows remote attackers to replay credentials.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot other="1" />
        </loss_types>
        <vuln_types>
            <access />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="XF" patch="1" url="http://xforce.iss.net/xforce/xfdb/18347" adv="1">macos-moddigest-response-replay(18347)</ref>
            <ref source="SECTRACK" patch="1" url="http://www.securitytracker.com/alerts/2004/Dec/1012414.html" adv="1">1012414</ref>
            <ref source="BID" patch="1" url="http://www.securityfocus.com/bid/9571" adv="1">9571</ref>
            <ref source="CIAC" patch="1" url="http://www.ciac.org/ciac/bulletins/p-049.shtml" adv="1">P-049</ref>
            <ref source="APPLE" patch="1" url="http://lists.apple.com/archives/security-announce/2004/Dec/msg00000.html" adv="1">APPLE-SA-2004-12-02</ref>
        </refs>
        <vuln_soft>
            <prod vendor="apache" name="http_server">
                <vers num="1.3" />
                <vers num="1.3.1" />
                <vers num="1.3.11" />
                <vers num="1.3.12" />
                <vers num="1.3.14" />
                <vers num="1.3.17" />
                <vers num="1.3.18" />
                <vers num="1.3.19" />
                <vers num="1.3.20" />
                <vers num="1.3.22" />
                <vers num="1.3.23" />
                <vers num="1.3.24" />
                <vers num="1.3.25" />
                <vers num="1.3.26" />
                <vers num="1.3.27" />
                <vers num="1.3.28" />
                <vers num="1.3.29" />
                <vers num="1.3.3" />
                <vers num="1.3.4" />
                <vers num="1.3.6" />
                <vers edition="" num="1.3.7" />
                <vers edition=":dev" num="1.3.7" />
                <vers num="1.3.9" />
            </prod>
            <prod vendor="apple" name="apache_mod_digest_apple">
                <vers num="" />
            </prod>
            <prod vendor="avaya" name="communication_manager">
                <vers num="1.1" />
                <vers num="1.3.1" />
                <vers num="2.0" />
                <vers num="2.0.1" />
            </prod>
            <prod vendor="avaya" name="intuity_audix_lx">
                <vers num="" />
            </prod>
            <prod vendor="avaya" name="mn100">
                <vers num="" />
            </prod>
            <prod vendor="avaya" name="network_routing">
                <vers num="" />
            </prod>
            <prod vendor="hp" name="virtualvault">
                <vers num="4.5" />
                <vers num="4.6" />
                <vers num="4.7" />
            </prod>
            <prod vendor="hp" name="webproxy">
                <vers num="a.02.00" />
                <vers num="a.02.10" />
            </prod>
            <prod vendor="ibm" name="http_server">
                <vers num="1.3.19" />
            </prod>
            <prod vendor="avaya" name="modular_messaging_message_storage_server">
                <vers num="1.1" />
                <vers num="2.0" />
            </prod>
            <prod vendor="openbsd" name="openbsd">
                <vers num="3.4" />
                <vers num="3.5" />
                <vers num="current" />
            </prod>
            <prod vendor="sco" name="openserver">
                <vers num="5.0.6" />
                <vers num="5.0.7" />
            </prod>
            <prod vendor="sun" name="solaris">
                <vers edition="" num="8.0" />
                <vers edition=":x86" num="8.0" />
                <vers edition="" num="9.0" />
                <vers edition=":sparc" num="9.0" />
                <vers edition=":x86" num="9.0" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" name="CVE-2004-2085" seq="2004-2085" severity="Medium" type="CVE" published="2004-02-04" CVSS_version="2.0 incomplete approximation" CVSS_score="4.3" modified="2008-09-05">
        <desc>
            <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in Brad Fears phpCodeCabinet 0.4 and earlier allow remote attackers to inject arbitrary web script or HTML via multiple parameters, including (1) the sid parameter to comments.php, (2) the cid, cf, or rfd parameters to category.php, or the cid parameter to (3) input.php, (4) browse.php, (5) themes/facade/header.php, or (6) themes/phpcc/header.php.</descript>
        </desc>
        <loss_types>
            <int />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="XF" patch="1" url="http://xforce.iss.net/xforce/xfdb/15190" adv="1">phpcodecabinet-multiple-xss(15190)</ref>
            <ref source="BID" patch="1" url="http://www.securityfocus.com/bid/9645" adv="1">9645</ref>
            <ref source="BID" patch="1" url="http://www.securityfocus.com/bid/9601" adv="1">9601</ref>
            <ref source="OSVDB" patch="1" url="http://www.osvdb.org/3887" adv="1">3887</ref>
            <ref source="OSVDB" patch="1" url="http://www.osvdb.org/3886" adv="1">3886</ref>
            <ref source="OSVDB" url="http://www.osvdb.org/3885" adv="1">3885</ref>
            <ref source="CONFIRM" url="http://sourceforge.net/project/shownotes.php?release_id=214860" adv="1">http://sourceforge.net/project/shownotes.php?release_id=214860</ref>
            <ref source="CONFIRM" url="http://cvs.sourceforge.net/viewcvs.py/phpcodecabinet/phpcc/themes/phpcc/header.php?r1=1.4&amp;r2=1.5" adv="1">http://cvs.sourceforge.net/viewcvs.py/phpcodecabinet/phpcc/themes/phpcc/header.php?r1=1.4&amp;r2=1.5</ref>
            <ref source="CONFIRM" url="http://cvs.sourceforge.net/viewcvs.py/phpcodecabinet/phpcc/themes/facade/header.php?r1=1.4&amp;r2=1.5" adv="1">http://cvs.sourceforge.net/viewcvs.py/phpcodecabinet/phpcc/themes/facade/header.php?r1=1.4&amp;r2=1.5</ref>
            <ref source="CONFIRM" url="http://cvs.sourceforge.net/viewcvs.py/phpcodecabinet/phpcc/input.php?r1=1.7&amp;r2=1.8" adv="1">http://cvs.sourceforge.net/viewcvs.py/phpcodecabinet/phpcc/input.php?r1=1.7&amp;r2=1.8</ref>
            <ref source="CONFIRM" url="http://cvs.sourceforge.net/viewcvs.py/phpcodecabinet/phpcc/comments.php?r1=1.1&amp;r2=1.2" adv="1">http://cvs.sourceforge.net/viewcvs.py/phpcodecabinet/phpcc/comments.php?r1=1.1&amp;r2=1.2</ref>
            <ref source="CONFIRM" url="http://cvs.sourceforge.net/viewcvs.py/phpcodecabinet/phpcc/category.php?r1=1.4&amp;r2=1.5" adv="1">http://cvs.sourceforge.net/viewcvs.py/phpcodecabinet/phpcc/category.php?r1=1.4&amp;r2=1.5</ref>
            <ref source="CONFIRM" url="http://cvs.sourceforge.net/viewcvs.py/phpcodecabinet/phpcc/browse.php?r1=1.5&amp;r2=1.6" adv="1">http://cvs.sourceforge.net/viewcvs.py/phpcodecabinet/phpcc/browse.php?r1=1.5&amp;r2=1.6</ref>
            <ref source="OSVDB" url="http://www.osvdb.org/16711">16711</ref>
            <ref source="OSVDB" url="http://www.osvdb.org/16710">16710</ref>
            <ref source="SECTRACK" url="http://securitytracker.com/id?1009012">1009012</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/10862">10862</ref>
        </refs>
        <vuln_soft>
            <prod vendor="brad_fears" name="phpcodecabinet">
                <vers num="0.1" />
                <vers num="0.2" />
                <vers num="0.3" />
                <vers num="0.4" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" name="CVE-2004-2073" seq="2004-2073" severity="High" type="CVE" published="2004-02-06" CVSS_version="2.0 incomplete approximation" CVSS_score="7.2" modified="2008-09-05">
        <desc>
            <descript source="cve">Linux-VServer 1.24 allows local users with root privileges on a virtual server to gain access to the filesystem outside the virtual server via a modified chroot-again exploit using the chmod command.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot admin="1" />
        </loss_types>
        <vuln_types>
            <exception />
        </vuln_types>
        <range>
            <local />
        </range>
        <refs>
            <ref source="CONFIRM" patch="1" url="http://www.linux-vserver.org/index.php?page=ChangeLog" adv="1">http://www.linux-vserver.org/index.php?page=ChangeLog</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/15073" adv="1">linux-vserver-gain-privileges(15073)</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/9596" adv="1">9596</ref>
            <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/353003" adv="1">20040206 Linux 2.4.24 with vserver 1.24 exploit</ref>
            <ref source="OSVDB" url="http://www.osvdb.org/3875">3875</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/10816">10816</ref>
        </refs>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" name="CVE-2004-2086" seq="2004-2086" severity="Medium" type="CVE" published="2004-02-06" CVSS_version="2.0 incomplete approximation" CVSS_score="5.0" modified="2008-09-05">
        <desc>
            <descript source="cve">Stack-based buffer overflow in results.stm for Sambar Server before the 6.0 production release allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via an HTTP POST request with a long query parameter.</descript>
        </desc>
        <loss_types>
            <avail />
        </loss_types>
        <vuln_types>
            <input buffer="1" />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="CONFIRM" patch="1" url="http://www.sambar.com/security.htm" adv="1">http://www.sambar.com/security.htm</ref>
            <ref source="OSVDB" patch="1" url="http://www.osvdb.org/5786" adv="1">5786</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/15071" adv="1">sambar-http-post-bo(15071)</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/9607" adv="1">9607</ref>
            <ref source="VULN-DEV" url="http://www.securityfocus.com/archive/82/353087" adv="1">20040207 Sambar 6.0 stack overflow</ref>
            <ref source="SECTRACK" url="http://securitytracker.com/id?1008979" adv="1">1008979</ref>
        </refs>
        <vuln_soft>
            <prod vendor="sambar" name="sambar_server">
                <vers edition="beta3" num="6.0" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" name="CVE-2004-2089" seq="2004-2089" severity="Medium" type="CVE" published="2004-02-06" CVSS_version="2.0 incomplete approximation" CVSS_score="5.0" modified="2008-09-05">
        <desc>
            <descript source="cve">Matrix FTP Server allows remote attackers to cause a denial of service (crash) by logging in using four spaces as the username and password and then issuing a LIST command.</descript>
        </desc>
        <loss_types>
            <avail />
        </loss_types>
        <vuln_types>
            <access />
            <design />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/15075" adv="1">matrixftp-login-list-dos(15075)</ref>
            <ref source="SECTRACK" url="http://securitytracker.com/id?1008970" adv="1">1008970</ref>
        </refs>
    </entry>
    <entry CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" name="CVE-2004-2084" seq="2004-2084" severity="Medium" type="CVE" published="2004-02-07" CVSS_version="2.0 incomplete approximation" CVSS_score="4.3" modified="2008-09-05">
        <desc>
            <descript source="cve">Cross-site scripting (XSS) vulnerability in search.php in JShop E-Commerce Server allows remote attackers to inject arbitrary web script or HTML via the xSearch parameter.</descript>
        </desc>
        <loss_types>
            <int />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="XF" patch="1" url="http://xforce.iss.net/xforce/xfdb/15100" adv="1">jshop-searchphp-xss(15100)</ref>
            <ref source="OSVDB" patch="1" url="http://www.osvdb.org/3889">3889</ref>
            <ref source="MISC" url="http://www.systemsecure.org/advisories/ssadvisory09022004.php" adv="1">http://www.systemsecure.org/advisories/ssadvisory09022004.php</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/9609" adv="1">9609</ref>
            <ref source="SECTRACK" url="http://securitytracker.com/id?1008988" adv="1">1008988</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/10825" adv="1">10825</ref>
        </refs>
        <vuln_soft>
            <prod vendor="jshop_e-commerce" name="jshop_professional">
                <vers num="3.0" />
                <vers num="3.1" />
                <vers num="3.2" />
                <vers num="3.3" />
                <vers num="3.4" />
            </prod>
            <prod vendor="jshop_e-commerce" name="jshop_server">
                <vers num="1.0.1" />
                <vers num="1.0.2" />
                <vers num="1.0.3" />
                <vers num="1.0.4" />
                <vers num="1.1.0" />
                <vers num="1.2.0" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" name="CVE-2004-2090" seq="2004-2090" severity="Medium" type="CVE" published="2004-02-07" CVSS_version="2.0 incomplete approximation" CVSS_score="5.0" modified="2008-09-05">
        <desc>
            <descript source="cve">Microsoft Internet Explorer 5.0.1 through 6.0 allows remote attackers to determine the existence of arbitrary files via the VBScript LoadPicture method, which returns an error code if the file does not exist.</descript>
        </desc>
        <loss_types>
            <conf />
        </loss_types>
        <vuln_types>
            <design />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/15078" adv="1">ie-error-obtain-information(15078)</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/9611" adv="1">9611</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/10820" adv="1">10820</ref>
            <ref source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2004-February/016881.html" adv="1">20040207 (no subject)</ref>
        </refs>
        <vuln_soft>
            <prod vendor="microsoft" name="ie">
                <vers edition="sp1" num="5.0.1" />
                <vers edition="sp2" num="5.0.1" />
                <vers edition="sp3" num="5.0.1" />
                <vers edition="sp4" num="5.0.1" />
                <vers edition="sp1" num="5.5" />
                <vers edition="sp2" num="5.5" />
                <vers edition="sp1" num="6.0" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" name="CVE-2004-1244" seq="2004-1244" severity="High" type="CVE" published="2004-02-08" CVSS_version="2.0 incomplete approximation" CVSS_score="7.5" modified="2008-09-10">
        <desc>
            <descript source="cve">Windows Media Player 9 allows remote attackers to execute arbitrary code via a PNG file containing large (1) width or (2) height values, aka the "PNG Processing Vulnerability."</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot user="1" />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="CERT" patch="1" url="http://www.us-cert.gov/cas/techalerts/TA05-039A.html" adv="1">TA05-039A</ref>
            <ref source="CERT-VN" patch="1" url="http://www.kb.cert.org/vuls/id/259890" adv="1">VU#259890</ref>
            <ref source="XF" patch="1" url="http://xforce.iss.net/xforce/xfdb/19096" adv="1">win-ms05kb890261-update(19096)</ref>
            <ref source="MS" patch="1" url="http://www.microsoft.com/technet/security/bulletin/MS05-009.mspx" adv="1">MS05-009</ref>
            <ref source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2379" sig="1">oval:org.mitre.oval:def:2379</ref>
            <ref source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1568" sig="1">oval:org.mitre.oval:def:1568</ref>
            <ref source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1306" sig="1">oval:org.mitre.oval:def:1306</ref>
        </refs>
        <vuln_soft>
            <prod vendor="microsoft" name="windows_media_player">
                <vers num="9" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" name="CVE-2004-2077" seq="2004-2077" severity="Medium" type="CVE" published="2004-02-08" CVSS_version="2.0 incomplete approximation" CVSS_score="5.0" modified="2008-09-05">
        <desc>
            <descript source="cve">Nadeo Game Engine for Nadeo TrackMania and Nadeo Virtual Skipper 3 allows remote attackers to cause a denial of service (server crash) via malformed data to TCP port 2350, possibly due to long values or incorrect size fields.</descript>
        </desc>
        <loss_types>
            <avail />
        </loss_types>
        <vuln_types>
            <input />
            <exception />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/15081" adv="1">trackmania-dos(15081)</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/9604" adv="1">9604</ref>
            <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/353226" adv="1">20040209 Re: TrackMania Demo Denial of Service</ref>
            <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/353182" adv="1">20040208 TrackMania Demo Denial of Service</ref>
            <ref source="MISC" url="http://www.securiteinfo.com/attaques/hacking/trackmaniados.shtml" adv="1">http://www.securiteinfo.com/attaques/hacking/trackmaniados.shtml</ref>
        </refs>
        <vuln_soft>
            <prod vendor="nadeo" name="game_engine">
                <vers num="" />
            </prod>
            <prod vendor="nadeo" name="trackmania">
                <vers num="" />
            </prod>
            <prod vendor="nadeo" name="virtual_skipper">
                <vers num="3" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" name="CVE-2004-2077" seq="2004-2077" severity="Medium" type="CVE" published="2004-02-08" CVSS_version="2.0 incomplete approximation" CVSS_score="5.0" modified="2008-09-05">
        <desc>
            <descript source="cve">Nadeo Game Engine for Nadeo TrackMania and Nadeo Virtual Skipper 3 allows remote attackers to cause a denial of service (server crash) via malformed data to TCP port 2350, possibly due to long values or incorrect size fields.</descript>
        </desc>
        <loss_types>
            <avail />
        </loss_types>
        <vuln_types>
            <input />
            <exception />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/15081" adv="1">trackmania-dos(15081)</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/9604" adv="1">9604</ref>
            <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/353226" adv="1">20040209 Re: TrackMania Demo Denial of Service</ref>
            <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/353182" adv="1">20040208 TrackMania Demo Denial of Service</ref>
            <ref source="MISC" url="http://www.securiteinfo.com/attaques/hacking/trackmaniados.shtml" adv="1">http://www.securiteinfo.com/attaques/hacking/trackmaniados.shtml</ref>
        </refs>
        <vuln_soft>
            <prod vendor="nadeo" name="game_engine">
                <vers num="" />
            </prod>
            <prod vendor="nadeo" name="trackmania">
                <vers num="" />
            </prod>
            <prod vendor="nadeo" name="virtual_skipper">
                <vers num="3" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" name="CVE-2004-2078" seq="2004-2078" severity="Medium" type="CVE" published="2004-02-09" CVSS_version="2.0 incomplete approximation" CVSS_score="5.0" modified="2008-09-05">
        <desc>
            <descript source="cve">Red-M Red-Alert 2.7.5 with software 3.1 build 24 allows remote attackers to cause a denial of service (reboot and loss of logged events) via a long request to TCP port 80, possibly triggering a buffer overflow.</descript>
        </desc>
        <loss_types>
            <avail />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="SECTRACK" patch="1" url="http://securitytracker.com/id?1009001" adv="1">1009001</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/15086" adv="1">redalert-long-request-dos(15086)</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/9618" adv="1">9618</ref>
            <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/353211" adv="1">20040209 Red-M Red-Alert Multiple Vulnerabilities</ref>
            <ref source="MISC" url="http://www.securiteam.com/securitynews/5SP0C0KC0A.html" adv="1">http://www.securiteam.com/securitynews/5SP0C0KC0A.html</ref>
            <ref source="OSVDB" url="http://www.osvdb.org/3891" adv="1">3891</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/10832" adv="1">10832</ref>
            <ref source="MISC" url="http://genhex.org/releases/031003.txt" adv="1">http://genhex.org/releases/031003.txt</ref>
            <ref source="FULLDISC" url="http://marc.theaimsgroup.com/?l=full-disclosure&amp;m=107635119005407&amp;w=2">20040209 Red-M Red-Alert Multiple Vulnerabilities</ref>
        </refs>
        <vuln_soft>
            <prod vendor="red-m" name="red-alert">
                <vers num="2.7.5_v3.1_build_24" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" name="CVE-2004-2079" seq="2004-2079" severity="High" type="CVE" published="2004-02-09" CVSS_version="2.0 incomplete approximation" CVSS_score="7.5" modified="2008-09-10">
        <desc>
            <descript source="cve">Red-M Red-Alert 2.7.5 with software 3.1 build 24 binds authentication to IP addresses, which allows remote attackers to bypass authentication by connecting from the same IP address as an active authenticated user.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot other="1" />
        </loss_types>
        <vuln_types>
            <access />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="SECTRACK" patch="1" url="http://securitytracker.com/id?1009001" adv="1">1009001</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/15088" adv="1">redalert-gain-access(15088)</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/9618" adv="1">9618</ref>
            <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/353211" adv="1">20040209 Red-M Red-Alert Multiple Vulnerabilities</ref>
            <ref source="MISC" url="http://www.securiteam.com/securitynews/5SP0C0KC0A.html" adv="1">http://www.securiteam.com/securitynews/5SP0C0KC0A.html</ref>
            <ref source="MISC" url="http://genhex.org/releases/031003.txt" adv="1">http://genhex.org/releases/031003.txt</ref>
            <ref source="OSVDB" url="http://www.osvdb.org/3952">3952</ref>
            <ref source="FULLDISC" url="http://marc.theaimsgroup.com/?l=full-disclosure&amp;m=107635119005407&amp;w=2">20040209 Red-M Red-Alert Multiple Vulnerabilities</ref>
        </refs>
        <vuln_soft>
            <prod vendor="red-m" name="red-alert">
                <vers num="2.7.5_v3.1_build_24" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" name="CVE-2004-2080" seq="2004-2080" severity="Medium" type="CVE" published="2004-02-09" CVSS_version="2.0 incomplete approximation" CVSS_score="5.0" modified="2008-09-10">
        <desc>
            <descript source="cve">Red-M Red-Alert 2.7.5 with software 3.1 build 24 converts multiple spaces in a Service Set Identifier (SSID) to a single space, which prevents Red-Alert from correctly identifying the SSID.</descript>
        </desc>
        <loss_types>
            <avail />
        </loss_types>
        <vuln_types>
            <exception />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="SECTRACK" patch="1" url="http://securitytracker.com/id?1009001" adv="1">1009001</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/15089" adv="1">redalert-bypass-security(15089)</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/9618" adv="1">9618</ref>
            <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/353211" adv="1">20040209 Red-M Red-Alert Multiple Vulnerabilities</ref>
            <ref source="MISC" url="http://www.securiteam.com/securitynews/5SP0C0KC0A.html" adv="1">http://www.securiteam.com/securitynews/5SP0C0KC0A.html</ref>
            <ref source="MISC" url="http://genhex.org/releases/031003.txt" adv="1">http://genhex.org/releases/031003.txt</ref>
            <ref source="OSVDB" url="http://www.osvdb.org/3953">3953</ref>
            <ref source="FULLDISC" url="http://marc.theaimsgroup.com/?l=full-disclosure&amp;m=107635119005407&amp;w=2">20040209 Red-M Red-Alert Multiple Vulnerabilities</ref>
        </refs>
        <vuln_soft>
            <prod vendor="red-m" name="red-alert">
                <vers num="2.7.5_v3.1_build_24" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" name="CVE-2004-2092" seq="2004-2092" severity="Medium" type="CVE" published="2004-02-09" CVSS_version="2.0 incomplete approximation" CVSS_score="4.6" modified="2008-09-05">
        <desc>
            <descript source="cve">eTrust InoculateIT for Linux 6.0 uses insecure permissions for multiple files and directories, including the application's registry and tmp directories, which allows local users to delete, modify, or examine sensitive information.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot other="1" />
        </loss_types>
        <vuln_types>
            <access />
        </vuln_types>
        <range>
            <local />
        </range>
        <refs>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/15103" adv="1">etrust-inoculateit-insecure-permissions(15103)</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/9616">9616</ref>
            <ref source="OSVDB" url="http://www.osvdb.org/3896" adv="1">3896</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/10833" adv="1">10833</ref>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107635584431518&amp;w=2" adv="1">20040209 [local problems] eTrust Virus Protection 6.0 InoculateIT for linux</ref>
        </refs>
        <vuln_soft>
            <prod vendor="ca" name="inoculateit">
                <vers num="6.0" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" name="CVE-2004-2093" seq="2004-2093" severity="Medium" type="CVE" published="2004-02-09" CVSS_version="2.0 incomplete approximation" CVSS_score="4.6" modified="2008-09-05">
        <desc>
            <descript source="cve">Buffer overflow in the open_socket_out function in socket.c for rsync 2.5.7 and earlier allows local users to cause a denial of service (crash) and possibly execute arbitrary code via a long RSYNC_PROXY environment variable.  NOTE: since rsync is not setuid, this issue does not provide any additional privileges beyond those that are already available to the user.  Therefore this issue may be REJECTED in the future.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot user="1" />
        </loss_types>
        <vuln_types>
            <input buffer="1" />
        </vuln_types>
        <range>
            <local />
        </range>
        <refs>
            <ref source="XF" patch="1" url="http://xforce.iss.net/xforce/xfdb/15108">linux-rsync-opensocketout-bo(15108)</ref>
            <ref source="VULN-DEV" url="http://archives.neohapsis.com/archives/vuln-dev/2004-q1/0091.html" adv="1">20040209 rsync &lt;= 2.5.7 local buffer overflow (no root today:)</ref>
        </refs>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" name="CVE-2004-2091" seq="2004-2091" severity="Medium" type="CVE" published="2004-02-10" CVSS_version="2.0 incomplete approximation" CVSS_score="5.0" modified="2008-09-05">
        <desc>
            <descript source="cve">Microsoft Baseline Security Analyzer (MBSA) 1.2 does not correctly identify systems that have been patched but remain vulnerable to exploit until the system is rebooted, possibly giving the administrator a false sense of security.</descript>
        </desc>
        <loss_types>
            <int />
        </loss_types>
        <vuln_types>
            <other />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="BID" url="http://www.securityfocus.com/bid/9634" adv="1">9634</ref>
            <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/353324" adv="1">20040210 Another Low Blow From Microsoft: MBSA Failure!</ref>
        </refs>
        <vuln_soft>
            <prod vendor="microsoft" name="baseline_security_analyzer">
                <vers num="1.2" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:P/A:N)" CVSS_base_score="2.6" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="2.9" name="CVE-2004-2083" seq="2004-2083" severity="Low" type="CVE" published="2004-02-11" CVSS_version="2.0 incomplete approximation" CVSS_score="2.6" modified="2008-09-05">
        <desc>
            <descript source="cve">Opera Web Browser 7.0 through 7.23 allows remote attackers to trick users into executing a malicious file by embedding a CLSID in the file name, which causes the malicious file to appear as a trusted file type, aka "File Download Extension Spoofing."</descript>
        </desc>
        <loss_types>
            <int />
        </loss_types>
        <vuln_types>
            <design />
        </vuln_types>
        <range>
            <network />
            <user_init />
        </range>
        <refs>
            <ref source="BID" url="http://www.securityfocus.com/bid/9640">9640</ref>
            <ref source="MISC" url="http://secunia.com/Internet_Explorer_File_Download_Extension_Spoofing_Test/" adv="1">http://secunia.com/Internet_Explorer_File_Download_Extension_Spoofing_Test/</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/10760" adv="1">10760</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/21698">opera-cslid-extension-spoof(21698)</ref>
            <ref source="OSVDB" url="http://www.osvdb.org/3917">3917</ref>
            <ref source="CONFIRM" url="http://www.opera.com/docs/changelogs/windows/750b1/">http://www.opera.com/docs/changelogs/windows/750b1/</ref>
        </refs>
        <vuln_soft>
            <prod vendor="opera_software" name="opera_web_browser">
                <vers edition="" num="7.0" />
                <vers edition=":win32" num="7.0" />
                <vers edition="" num="7.0.1" />
                <vers edition=":win32" num="7.0.1" />
                <vers edition="" num="7.0.2" />
                <vers edition=":win32" num="7.0.2" />
                <vers edition="" num="7.0.3" />
                <vers edition=":win32" num="7.0.3" />
                <vers edition="" num="7.0_beta1" />
                <vers edition=":win32" num="7.0_beta1" />
                <vers edition="" num="7.0_beta2" />
                <vers edition=":win32" num="7.0_beta2" />
                <vers num="7.10" />
                <vers num="7.11" />
                <vers num="7.11b" />
                <vers num="7.11j" />
                <vers num="7.20" />
                <vers num="7.20_beta1_build2981" />
                <vers num="7.21" />
                <vers num="7.22" />
                <vers num="7.23" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" name="CVE-2004-2088" seq="2004-2088" severity="Medium" type="CVE" published="2004-02-12" CVSS_version="2.0 incomplete approximation" CVSS_score="5.0" modified="2008-09-05">
        <desc>
            <descript source="cve">Sophos Anti-Virus 3.78 allows remote attackers to bypass virus scanning by using a qmail generated Delivery Status Notification (DSN) where the original email is not included in the bounce message.</descript>
        </desc>
        <loss_types>
            <int />
        </loss_types>
        <vuln_types>
            <exception />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="XF" patch="1" url="http://xforce.iss.net/xforce/xfdb/15192" adv="1">sophos-email-virus-undetected(15192)</ref>
            <ref source="CONFIRM" patch="1" url="http://www.sophos.com/support/news/#mime-378">http://www.sophos.com/support/news/#mime-378</ref>
            <ref source="BID" patch="1" url="http://www.securityfocus.com/bid/9650" adv="1">9650</ref>
            <ref source="SECTRACK" url="http://securitytracker.com/id?1009042">1009042</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/10855">10855</ref>
        </refs>
        <vuln_soft>
            <prod vendor="sophos" name="sophos_anti-virus">
                <vers num="3.4.6" />
                <vers num="3.78" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" name="CVE-2004-2082" seq="2004-2082" severity="Medium" type="CVE" published="2004-02-13" CVSS_version="2.0 incomplete approximation" CVSS_score="5.0" modified="2008-09-05">
        <desc>
            <descript source="cve">The samiftp.dll library in Sami FTP Server 1.1.3 allows remote authenticated users to cause a denial of service (pmsystem.exe crash) via a GET request wit a large number of leading "/" (slash) characters.</descript>
        </desc>
        <loss_types>
            <avail />
        </loss_types>
        <vuln_types>
            <input buffer="1" />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="MISC" patch="1" url="http://www.karja.com/samiftp/news.html" adv="1">http://www.karja.com/samiftp/news.html</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/15204" adv="1">sami-cd-get-dos(15204)</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/9657" adv="1">9657</ref>
            <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/353753">20040213 Sami FTP Server 1.1.3 multiple vulnerabilities</ref>
        </refs>
        <vuln_soft>
            <prod vendor="karjasoft" name="sami_ftp_server">
                <vers num="1.1.3" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" name="CVE-2004-1180" seq="2004-1180" severity="Medium" type="CVE" published="2004-02-16" CVSS_version="2.0 incomplete approximation" CVSS_score="5.0" modified="2008-09-10">
        <desc>
            <descript source="cve">Unknown vulnerability in the rwho daemon (rwhod) before 0.17, on little endian architectures, allows remote attackers to cause a denial of service (application crash).</descript>
        </desc>
        <loss_types>
            <avail />
        </loss_types>
        <vuln_types>
            <other />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="DEBIAN" patch="1" url="http://www.debian.org/security/2005/dsa-678" adv="1">DSA-678</ref>
            <ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:039">MDKSA-2005:039</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/14309">14309</ref>
        </refs>
        <vuln_soft>
            <prod vendor="debian" name="debian_linux">
                <vers edition="" num="3.0" />
                <vers edition=":woody" num="3.0" />
            </prod>
            <prod vendor="mandrakesoft" name="mandrake_linux">
                <vers edition="" num="10.0" />
                <vers edition=":amd64" num="10.0" />
                <vers edition="" num="10.1" />
                <vers edition=":x86_64" num="10.1" />
            </prod>
            <prod vendor="mandrakesoft" name="mandrake_linux_corporate_server">
                <vers edition="" num="2.1" />
                <vers edition=":x86_64" num="2.1" />
            </prod>
            <prod vendor="sun" name="solaris">
                <vers num="9.0" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" name="CVE-2004-0001" seq="2004-0001" severity="High" type="CVE" published="2004-02-17" CVSS_version="2.0 incomplete approximation" CVSS_score="7.2" modified="2008-09-05">
        <desc>
            <descript source="cve">Unknown vulnerability in the eflags checking in the 32-bit ptrace emulation for the Linux kernel on AMD64 systems allows local users to gain privileges.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot admin="1" user="1" />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <local />
        </range>
        <refs>
            <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/337238" adv="1">VU#337238</ref>
            <ref source="REDHAT" patch="1" url="http://www.redhat.com/support/errata/RHSA-2004-017.html" adv="1">RHSA-2004:017</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/14888" adv="1">linux-ptrace-gain-privilege(14888)</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/9429" adv="1">9429</ref>
            <ref source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200402-06.xml">GLSA-200402-06</ref>
            <ref source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:868" sig="1">oval:org.mitre.oval:def:868</ref>
        </refs>
        <vuln_soft>
            <prod vendor="linux" name="linux_kernel">
                <vers num="2.6.20.1" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" name="CVE-2004-0004" seq="2004-0004" severity="High" type="CVE" published="2004-02-17" CVSS_version="2.0 incomplete approximation" CVSS_score="7.5" modified="2008-09-05">
        <desc>
            <descript source="cve">The libCheckSignature function in crypto-utils.lib for OpenCA 0.9.1.6 and earlier only compares the serial of the signer's certificate and the one in the database, which can cause OpenCA to incorrectly accept a signature if the certificate's chain is trusted by OpenCA's chain directory, allowing remote attackers to spoof requests from other users.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot other="1" />
        </loss_types>
        <vuln_types>
            <other />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/336446">VU#336446</ref>
            <ref source="BID" patch="1" url="http://www.securityfocus.com/bid/9435" adv="1">9435</ref>
            <ref source="CONFIRM" patch="1" url="http://www.openca.org/news/CAN-2004-0004.txt" adv="1">http://www.openca.org/news/CAN-2004-0004.txt</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/14847">openca-improper-signature-verification(14847)</ref>
            <ref source="OSVDB" url="http://www.osvdb.org/3615">3615</ref>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107427313700554&amp;w=2">20040116 [OpenCA Advisory] Vulnerability in signature verification</ref>
        </refs>
        <vuln_soft>
            <prod vendor="openca" name="openca">
                <vers num="0.9.1.6" prev="1" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" name="CVE-2004-0054" seq="2004-0054" severity="High" type="CVE" published="2004-02-17" CVSS_version="2.0 incomplete approximation" CVSS_score="7.5" modified="2009-03-04">
        <desc>
            <descript source="cve">Multiple vulnerabilities in the H.323 protocol implementation for Cisco IOS 11.3T through 12.2T allow remote attackers to cause a denial of service and possibly execute arbitrary code, as demonstrated by the NISCC/OUSPG PROTOS test suite for the H.225 protocol.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot other="1" />
        </loss_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="CERT-VN" patch="1" url="http://www.kb.cert.org/vuls/id/749342" adv="1">VU#749342</ref>
            <ref source="CERT" patch="1" url="http://www.cert.org/advisories/CA-2004-01.html" adv="1">CA-2004-01</ref>
            <ref source="CISCO" patch="1" url="http://www.cisco.com/warp/public/707/cisco-sa-20040113-h323.shtml" adv="1">20040113 Vulnerabilities in H.323 Message Processing</ref>
            <ref source="MISC" url="http://www.uniras.gov.uk/vuls/2004/006489/h323.htm">http://www.uniras.gov.uk/vuls/2004/006489/h323.htm</ref>
            <ref source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:4884">oval:org.mitre.oval:def:4884</ref>
            <ref source="SECTRACK" url="http://www.securitytracker.com/id?1008685">1008685</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/9406">9406</ref>
        </refs>
        <vuln_soft>
            <prod vendor="cisco" name="ios">
                <vers num="11.3t" />
                <vers num="12.0" />
                <vers num="12.0s" />
                <vers num="12.0t" />
                <vers num="12.1" />
                <vers num="12.1e" />
                <vers num="12.1t" />
                <vers num="12.2" />
                <vers num="12.2s" />
                <vers num="12.2t" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" name="CVE-2004-0055" seq="2004-0055" severity="Medium" type="CVE" published="2004-02-17" CVSS_version="2.0 incomplete approximation" CVSS_score="5.0" modified="2009-02-06">
        <desc>
            <descript source="cve">The print_attr_string function in print-radius.c for tcpdump 3.8.1 and earlier allows remote attackers to cause a denial of service (segmentation fault) via a RADIUS attribute with a large length value.</descript>
        </desc>
        <loss_types>
            <avail />
        </loss_types>
        <vuln_types>
            <design />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/955526" adv="1">VU#955526</ref>
            <ref source="BID" patch="1" url="http://www.securityfocus.com/bid/7090" adv="1">7090</ref>
            <ref source="REDHAT" patch="1" url="http://www.redhat.com/support/errata/RHSA-2004-008.html" adv="1">RHSA-2004:008</ref>
            <ref source="MLIST" url="http://www.redhat.com/archives/fedora-announce-list/2004-March/msg00015.html">[fedora-announce-list] 20040311 Re: [SECURITY] Fedora Core 1 Update: tcpdump-3.7.2-8.fc1.1</ref>
            <ref source="FEDORA" url="http://www.redhat.com/archives/fedora-announce-list/2004-March/msg00009.html">FEDORA-2004-092</ref>
            <ref source="FEDORA" url="http://www.redhat.com/archives/fedora-announce-list/2004-March/msg00006.html">FEDORA-2004-090</ref>
            <ref source="DEBIAN" url="http://www.debian.org/security/2004/dsa-425">DSA-425</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/12179/">12179</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/11032/">11032</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/11022">11022</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/10718">10718</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/10652">10652</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/10644">10644</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/10639">10639</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/10636">10636</ref>
            <ref source="TRUSTIX" url="http://lwn.net/Alerts/66445/">2004-0004</ref>
            <ref source="APPLE" url="http://lists.apple.com/archives/security-announce/2004/Feb/msg00000.html">APPLE-SA-2004-02-23</ref>
            <ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/20040103-01-U.asc">20040103-01-U</ref>
            <ref source="SCO" url="ftp://ftp.sco.com/pub/updates/UnixWare/SCOSA-2004.9/SCOSA-2004.9.txt">SCOSA-2004.9</ref>
            <ref source="CALDERA" url="ftp://ftp.sco.com/pub/security/OpenLinux/CSSA-2004-008.0.txt">CSSA-2004-008.0</ref>
            <ref source="SECTRACK" url="http://www.securitytracker.com/id?1008735">1008735</ref>
            <ref source="FEDORA" url="http://www.redhat.com/archives/fedora-legacy-list/2004-January/msg00726.html">FLSA:1222</ref>
            <ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2004:008">MDKSA-2004:008</ref>
            <ref source="MLIST" url="http://marc.theaimsgroup.com/?l=tcpdump-workers&amp;m=107325073018070&amp;w=2">[tcpdump-workers] multiple vulnerabilities in tcpdump 3.8.1</ref>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107577418225627&amp;w=2">20040131 [FLSA-2004:1222] Updated tcpdump resolves security vulnerabilites (resend with correct paths)</ref>
            <ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000832">CLSA-2003:832</ref>
            <ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/20040202-01-U.asc">20040202-01-U</ref>
            <ref source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:853" sig="1">oval:org.mitre.oval:def:853</ref>
            <ref source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:850" sig="1">oval:org.mitre.oval:def:850</ref>
        </refs>
        <vuln_soft>
            <prod vendor="lbl" name="tcpdump">
                <vers num="3.5.2" />
                <vers num="3.6.2" />
                <vers num="3.7" />
                <vers num="3.7.1" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" name="CVE-2004-0056" seq="2004-0056" severity="High" type="CVE" published="2004-02-17" CVSS_version="2.0 incomplete approximation" CVSS_score="7.5" modified="2008-09-05">
        <desc>
            <descript source="cve">Multiple vulnerabilities in the H.323 protocol implementation for Nortel Networks Business Communications Manager (BCM), Succession 1000 IP Trunk and IP Peer Networking, and 802.11 Wireless IP Gateway allow remote attackers to cause a denial of service and possibly execute arbitrary code, as demonstrated by the NISCC/OUSPG PROTOS test suite for the H.225 protocol.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot other="1" />
        </loss_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="CERT-VN" patch="1" url="http://www.kb.cert.org/vuls/id/749342" adv="1">VU#749342</ref>
            <ref source="CERT" patch="1" url="http://www.cert.org/advisories/CA-2004-01.html" adv="1">CA-2004-01</ref>
            <ref source="MISC" url="http://www.uniras.gov.uk/vuls/2004/006489/h323.htm">http://www.uniras.gov.uk/vuls/2004/006489/h323.htm</ref>
            <ref source="SECTRACK" url="http://www.securitytracker.com/id?1008687">1008687</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/9406">9406</ref>
        </refs>
        <vuln_soft>
            <prod vendor="nortel" name="business_communications_manager">
                <vers num="" />
            </prod>
            <prod vendor="nortel" name="802.11_wireless_ip_gateway">
                <vers num="" />
            </prod>
            <prod vendor="nortel" name="succession_communication_server_1000">
                <vers num="" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" name="CVE-2004-0057" seq="2004-0057" severity="Medium" type="CVE" published="2004-02-17" CVSS_version="2.0 incomplete approximation" CVSS_score="5.0" modified="2009-02-20">
        <desc>
            <descript source="cve">The rawprint function in the ISAKMP decoding routines (print-isakmp.c) for tcpdump 3.8.1 and earlier allows remote attackers to cause a denial of service (segmentation fault) via malformed ISAKMP packets that cause invalid "len" or "loc" values to be used in a loop, a different vulnerability than CVE-2003-0989.</descript>
        </desc>
        <loss_types>
            <avail />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/174086">VU#174086</ref>
            <ref source="BID" patch="1" url="http://www.securityfocus.com/bid/9423" adv="1">9423</ref>
            <ref source="REDHAT" patch="1" url="http://www.redhat.com/support/errata/RHSA-2004-007.html" adv="1">RHSA-2004:007</ref>
            <ref source="DEBIAN" patch="1" url="http://www.debian.org/security/2004/dsa-425" adv="1">DSA-425</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/14837">tcpdump-rawprint-isakmp-dos(14837)</ref>
            <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/350238/30/21640/threaded">20040119 [ESA-20040119-002] 'tcpdump' multiple vulnerabilities.</ref>
            <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2004-008.html">RHSA-2004:008</ref>
            <ref source="MLIST" url="http://www.redhat.com/archives/fedora-announce-list/2004-March/msg00015.html">[fedora-announce-list] 20040311 Re: [SECURITY] Fedora Core 1 Update: tcpdump-3.7.2-8.fc1.1</ref>
            <ref source="FEDORA" url="http://www.redhat.com/archives/fedora-announce-list/2004-March/msg00009.html">FEDORA-2004-092</ref>
            <ref source="FEDORA" url="http://www.redhat.com/archives/fedora-announce-list/2004-March/msg00006.html">FEDORA-2004-090</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/12179/">12179</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/11032/">11032</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/11022">11022</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/10718">10718</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/10668">10668</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/10652">10652</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/10644">10644</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/10639">10639</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/10636">10636</ref>
            <ref source="MLIST" url="http://marc.theaimsgroup.com/?l=tcpdump-workers&amp;m=107325073018070&amp;w=2" adv="1">[tcpdump-workers] multiple vulnerabilities in tcpdump 3.8.1</ref>
            <ref source="ENGARDE" url="http://lwn.net/Alerts/66805/">ESA-20040119-002</ref>
            <ref source="TRUSTIX" url="http://lwn.net/Alerts/66445/">2004-0004</ref>
            <ref source="APPLE" url="http://lists.apple.com/archives/security-announce/2004/Feb/msg00000.html">APPLE-SA-2004-02-23</ref>
            <ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/20040103-01-U.asc">20040103-01-U</ref>
            <ref source="SCO" url="ftp://ftp.sco.com/pub/updates/UnixWare/SCOSA-2004.9/SCOSA-2004.9.txt">SCOSA-2004.9</ref>
            <ref source="CALDERA" url="ftp://ftp.sco.com/pub/security/OpenLinux/CSSA-2004-008.0.txt">CSSA-2004-008.0</ref>
            <ref source="SECTRACK" url="http://www.securitytracker.com/id?1008716">1008716</ref>
            <ref source="FEDORA" url="http://www.redhat.com/archives/fedora-legacy-list/2004-January/msg00726.html">FLSA:1222</ref>
            <ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2004:008">MDKSA-2004:008</ref>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107577418225627&amp;w=2">20040131 [FLSA-2004:1222] Updated tcpdump resolves security vulnerabilites (resend with correct paths)</ref>
            <ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/20040202-01-U.asc">20040202-01-U</ref>
            <ref source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:854" sig="1">oval:org.mitre.oval:def:854</ref>
            <ref source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:851" sig="1">oval:org.mitre.oval:def:851</ref>
        </refs>
        <vuln_soft>
            <prod vendor="lbl" name="tcpdump">
                <vers num="3.8.1" prev="1" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" name="CVE-2004-0058" seq="2004-0058" severity="Low" type="CVE" published="2004-02-17" CVSS_version="2.0 incomplete approximation" CVSS_score="2.1" modified="2008-09-05">
        <desc>
            <descript source="cve">Antivir / Linux 2.0.9-9, and possibly earlier versions, allows local users to overwrite arbitrary files via a symlink attack on the .pid_antivir_$$ temporary file.</descript>
        </desc>
        <loss_types>
            <int />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <local />
        </range>
        <refs>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/14214">antivir-tmpfile-insecure(14214)</ref>
            <ref source="SECTRACK" url="http://www.securitytracker.com/id?1008702">1008702</ref>
            <ref source="OSVDB" url="http://www.osvdb.org/3496">3496</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/10620">10620</ref>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107402026023763&amp;w=2">20040113 symlink vul for Antivir / Linux Version 2.0.9-9 (maybe lower)</ref>
        </refs>
        <vuln_soft>
            <prod vendor="linux" name="linux_kernel">
                <vers num="2.0.9.9" prev="1" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" name="CVE-2004-0059" seq="2004-0059" severity="Medium" type="CVE" published="2004-02-17" CVSS_version="2.0 incomplete approximation" CVSS_score="5.0" modified="2008-09-05">
        <desc>
            <descript source="cve">Directory traversal vulnerability in upload capability of WWW File Share Pro 2.42 and earlier allows remote attackers to overwrite arbitrary files via .. (dot dot) sequences in the filename parameter of a Content-Disposition: header.</descript>
        </desc>
        <loss_types>
            <int />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="SECTRACK" url="http://www.securitytracker.com/id?1008779">1008779</ref>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107411794303201&amp;w=2">20040114 Multiple vulnerabilities in WWW Fileshare Pro &lt;= 2.42</ref>
        </refs>
        <vuln_soft>
            <prod vendor="lionmax_software" name="www_file_share_pro">
                <vers num="2.42" prev="1" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" name="CVE-2004-0060" seq="2004-0060" severity="Medium" type="CVE" published="2004-02-17" CVSS_version="2.0 incomplete approximation" CVSS_score="5.0" modified="2008-09-05">
        <desc>
            <descript source="cve">WWW File Share Pro 2.42 and earlier allows remote attackers to cause a denial of service (crash) via a large POST request.</descript>
        </desc>
        <loss_types>
            <avail />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="SECTRACK" url="http://www.securitytracker.com/id?1008779">1008779</ref>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107411794303201&amp;w=2">20040114 Multiple vulnerabilities in WWW Fileshare Pro &lt;= 2.42</ref>
        </refs>
        <vuln_soft>
            <prod vendor="lionmax_software" name="www_file_share_pro">
                <vers num="2.42" prev="1" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" name="CVE-2004-0061" seq="2004-0061" severity="High" type="CVE" published="2004-02-17" CVSS_version="2.0 incomplete approximation" CVSS_score="7.5" modified="2008-09-05">
        <desc>
            <descript source="cve">WWW File Share Pro 2.42 and earlier allows remote attackers to bypass directory access restrictions via (1) a URL with a trailing . (dot), or (2) a URI with a leading slash or backslash character.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot other="1" />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="SECTRACK" url="http://www.securitytracker.com/id?1008779">1008779</ref>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107411794303201&amp;w=2">20040114 Multiple vulnerabilities in WWW Fileshare Pro &lt;= 2.42</ref>
        </refs>
        <vuln_soft>
            <prod vendor="lionmax_software" name="www_file_share_pro">
                <vers num="2.42" prev="1" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" name="CVE-2004-0062" seq="2004-0062" severity="High" type="CVE" published="2004-02-17" CVSS_version="2.0 incomplete approximation" CVSS_score="7.5" modified="2008-09-10">
        <desc>
            <descript source="cve">Integer overflow in the rnd arithmetic rounding function for various versions of FishCart before 3.1 allows remote attackers to "cause negative totals" via an order with a large quantity.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot other="1" />
        </loss_types>
        <vuln_types>
            <input bound="1" />
            <design />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107411850203994&amp;w=2" adv="1">20040114 FishCart Integer Overflow / Rounding Error</ref>
            <ref source="SECTRACK" url="http://www.securitytracker.com/id?1008731">1008731</ref>
        </refs>
        <vuln_soft>
            <prod vendor="fishnet" name="fishcart">
                <vers num="3.1" prev="1" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" name="CVE-2004-0063" seq="2004-0063" severity="High" type="CVE" published="2004-02-17" CVSS_version="2.0 incomplete approximation" CVSS_score="7.5" modified="2008-09-05">
        <desc>
            <descript source="cve">The SPP_VerifyPVV function in nCipher payShield SPP library 1.3.12, 1.5.18 and 1.6.18 returns a Status_OK value even if the HSM returns a different status code, which could cause applications to make incorrect security-critical decisions, e.g. by accepting an invalid PIN number.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot other="1" />
        </loss_types>
        <vuln_types>
            <exception />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="CONFIRM" url="http://www.ncipher.com/support/advisories/advisory8_payshield.html" adv="1">http://www.ncipher.com/support/advisories/advisory8_payshield.html</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/14832">payshield-incorrect-request-verification(14832)</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/9422">9422</ref>
            <ref source="OSVDB" url="http://www.osvdb.org/3537">3537</ref>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107411819503569&amp;w=2">20040114 nCipher Advisory #8: payShield library may verify bad requests</ref>
        </refs>
        <vuln_soft>
            <prod vendor="ncipher" name="payshield_spp_library">
                <vers num="1.3.12" />
                <vers num="1.5.18" />
                <vers num="1.6.18" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" name="CVE-2004-0064" seq="2004-0064" severity="Low" type="CVE" published="2004-02-17" CVSS_version="2.0 incomplete approximation" CVSS_score="2.1" modified="2008-09-05">
        <desc>
            <descript source="cve">The SuSEconfig.gnome-filesystem script for YaST in SuSE 9.0 allows local users to overwrite arbitrary files via a symlink attack on files within the tmp.SuSEconfig.gnome-filesystem.$RANDOM temporary directory.</descript>
        </desc>
        <loss_types>
            <int />
        </loss_types>
        <vuln_types>
            <other />
        </vuln_types>
        <range>
            <local />
        </range>
        <refs>
            <ref source="BID" url="http://www.securityfocus.com/bid/9411" adv="1">9411</ref>
            <ref source="SECTRACK" url="http://www.securitytracker.com/id?1008703">1008703</ref>
            <ref source="OSVDB" url="http://www.osvdb.org/3460">3460</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/10623">10623</ref>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107402658600437&amp;w=2">20040113 SuSE linux 9.0 YaST config Skribt [exploit]</ref>
        </refs>
        <vuln_soft>
            <prod vendor="suse" name="suse_linux">
                <vers num="9.0" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" name="CVE-2004-0065" seq="2004-0065" severity="High" type="CVE" published="2004-02-17" CVSS_version="2.0 incomplete approximation" CVSS_score="7.5" modified="2008-09-05">
        <desc>
            <descript source="cve">Multiple SQL injection vulnerabilities in phpGedView before 2.65 allow remote attackers to execute arbitrary SQL via (1) timeline.php and (2) placelist.php.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot other="1" />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="BUGTRAQ" patch="1" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107394912715478&amp;w=2" adv="1">20040112 More phpGedView Vulnerabilities</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/11925">11925</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/11910">11910</ref>
        </refs>
        <vuln_soft>
            <prod vendor="phpgedview" name="phpgedview">
                <vers num="2.65" prev="1" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" name="CVE-2004-0066" seq="2004-0066" severity="Medium" type="CVE" published="2004-02-17" CVSS_version="2.0 incomplete approximation" CVSS_score="5.0" modified="2008-09-05">
        <desc>
            <descript source="cve">phpGedView before 2.65 allows remote attackers to obtain the absolute path of the web server via malformed parameters to (1) indilist.php, (2) famlist.php, (3) placelist.php, (4) imageview.php, (5) timeline.php, (6) clippings.php, (7) login.php, and (8) gdbi.php.</descript>
        </desc>
        <loss_types>
            <conf />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="BUGTRAQ" patch="1" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107394912715478&amp;w=2" adv="1">20040112 More phpGedView Vulnerabilities</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/14215">phpgedview-path-disclosure(14215)</ref>
            <ref source="OSVDB" url="http://www.osvdb.org/3464">3464</ref>
        </refs>
        <vuln_soft>
            <prod vendor="phpgedview" name="phpgedview">
                <vers num="2.65" prev="1" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" name="CVE-2004-0067" seq="2004-0067" severity="Medium" type="CVE" published="2004-02-17" CVSS_version="2.0" CVSS_score="4.3" modified="2009-01-29">
        <desc>
            <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in phpGedView before 2.65 allow remote attackers to inject arbitrary HTML or web script via (1) descendancy.php, (2) index.php, (3) individual.php, (4) login.php, (5) relationship.php, (6) source.php, (7) imageview.php, (8) calendar.php, (9) gedrecord.php, (10) login.php, and (11) gdbi_interface.php.  NOTE: some aspects of vector 10 were later reported to affect 4.1.</descript>
        </desc>
        <loss_types>
            <int />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="BUGTRAQ" patch="1" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107394912715478&amp;w=2" adv="1">20040112 More phpGedView Vulnerabilities</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/36285">phpgedview-login-xss(36285)</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/14212">phpgedview-multiple-xss(14212)</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/11907">11907</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/11906">11906</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/11905">11905</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/11904">11904</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/11903">11903</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/11894">11894</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/11891">11891</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/11890">11890</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/11888">11888</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/11882">11882</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/11880">11880</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/11868">11868</ref>
            <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/477881/100/0/threaded">20070827 PhpGedView login page multiple XSS</ref>
            <ref source="OSVDB" url="http://www.osvdb.org/3479">3479</ref>
            <ref source="OSVDB" url="http://www.osvdb.org/3478">3478</ref>
            <ref source="OSVDB" url="http://www.osvdb.org/3477">3477</ref>
            <ref source="OSVDB" url="http://www.osvdb.org/3476">3476</ref>
            <ref source="OSVDB" url="http://www.osvdb.org/3475">3475</ref>
            <ref source="OSVDB" url="http://www.osvdb.org/3474">3474</ref>
            <ref source="OSVDB" url="http://www.osvdb.org/3473">3473</ref>
            <ref source="VUPEN" url="http://www.frsirt.com/english/advisories/2007/2995" adv="1">ADV-2007-2995</ref>
            <ref source="SECTRACK" url="http://securitytracker.com/id?1018613">1018613</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/26628" adv="1">26628</ref>
        </refs>
        <vuln_soft>
            <prod vendor="phpgedview" name="phpgedview">
                <vers num="2.65" prev="1" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" name="CVE-2004-0068" seq="2004-0068" severity="High" type="CVE" published="2004-02-17" CVSS_version="2.0 incomplete approximation" CVSS_score="7.5" modified="2008-09-05">
        <desc>
            <descript source="cve">PHP remote file inclusion vulnerability in config.php for PhpDig 1.6.5 and earlier allows remote attackers to execute arbitrary PHP code by modifying the $relative_script_path parameter to reference a URL on a remote web server that contains the code.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot other="1" />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="BID" patch="1" url="http://www.securityfocus.com/bid/9424" adv="1">9424</ref>
            <ref source="CONFIRM" patch="1" url="http://www.phpdig.net/showthread.php?s=58bcc71c822830ec3bbdaae6d56846e0&amp;threadid=393">http://www.phpdig.net/showthread.php?s=58bcc71c822830ec3bbdaae6d56846e0&amp;threadid=393</ref>
            <ref source="BUGTRAQ" patch="1" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107412194008671&amp;w=2" adv="1">20040114 PhpDig 1.6.x: remote command execution</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/14826">phpdig-config-file-include(14826)</ref>
        </refs>
        <vuln_soft>
            <prod vendor="phpdig.net" name="phpdig">
                <vers num="1.6.5" prev="1" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" name="CVE-2004-0069" seq="2004-0069" severity="High" type="CVE" published="2004-02-17" CVSS_version="2.0 incomplete approximation" CVSS_score="7.5" modified="2008-09-05">
        <desc>
            <descript source="cve">Format string vulnerability in HD Soft Windows FTP Server 1.6 and earlier allows remote attackers to execute arbitrary code via format string specifiers in the username, which is processed by the wscanf function.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot other="1" />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="BID" url="http://www.securityfocus.com/bid/9385" adv="1">9385</ref>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107401398014761&amp;w=2">20040113 exploit for HD Soft Windows FTP Server 1.6</ref>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107367110805273&amp;w=2" adv="1">20040108 Windows FTP Server Format String Vulnerability</ref>
            <ref source="SECTRACK" url="http://www.securitytracker.com/id?1008658">1008658</ref>
        </refs>
        <vuln_soft>
            <prod vendor="hd_soft" name="windows_ftp_server">
                <vers num="1.6" prev="1" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" name="CVE-2004-0070" seq="2004-0070" severity="High" type="CVE" published="2004-02-17" CVSS_version="2.0 incomplete approximation" CVSS_score="7.5" modified="2008-09-05">
        <desc>
            <descript source="cve">PHP remote file inclusion vulnerability in module.php for ezContents allows remote attackers to execute arbitrary PHP code by modifying the link parameter to reference a URL on a remote web server that contains the code.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot other="1" />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/14199">ezcontents-php-file-include(14199)</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/9396" adv="1">9396</ref>
            <ref source="OSVDB" url="http://www.osvdb.org/6878">6878</ref>
            <ref source="CONFIRM" url="http://www.ezcontents.org/forum/viewtopic.php?t=361">http://www.ezcontents.org/forum/viewtopic.php?t=361</ref>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107392588915627&amp;w=2">20040110 Remote Code Execution in ezContents</ref>
        </refs>
        <vuln_soft>
            <prod vendor="visualshapers" name="ezcontents">
                <vers num="" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" name="CVE-2004-0071" seq="2004-0071" severity="Medium" type="CVE" published="2004-02-17" CVSS_version="2.0 incomplete approximation" CVSS_score="5.0" modified="2005-10-20">
        <desc>
            <descript source="cve">Directory traversal vulnerability in buildManPage in class.manpagelookup.php for PHP Man Page Lookup 1.2.0 allows remote attackers to read arbitrary files via the command parameter ($cmd variable) to index.php.</descript>
        </desc>
        <loss_types>
            <conf />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/14203">manpagelookup-directory-traversal(14203)</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/9395">9395</ref>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107392764118403&amp;w=2" adv="1">20040110 PHP Manpage lookup directory transversal / file disclosing</ref>
            <ref source="SECTRACK" url="http://www.securitytracker.com/id?1008689">1008689</ref>
        </refs>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" name="CVE-2004-0072" seq="2004-0072" severity="Medium" type="CVE" published="2004-02-17" CVSS_version="2.0 incomplete approximation" CVSS_score="5.0" modified="2008-09-05">
        <desc>
            <descript source="cve">Directory traversal vulnerability in Accipiter Direct Server 6.0 allows remote attackers to read arbitrary files via encoded \.. (backslash .., "%5c%2e%2e") sequences in an HTTP request.</descript>
        </desc>
        <loss_types>
            <conf />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="BID" patch="1" url="http://www.securityfocus.com/bid/9389" adv="1">9389</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/14198" adv="1">accipterdirectserver-directory-traversal(14198)</ref>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107392576215418&amp;w=2" adv="1">20040109 Directory Traversal in Accipiter Direct Server 6.0</ref>
            <ref source="FULLDISC" url="http://archives.neohapsis.com/archives/fulldisclosure/2004-01/0274.html">20040109 Directory Traversal in Accipiter Direct Server 6.0</ref>
            <ref source="OSVDB" url="http://www.osvdb.org/3433">3433</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/10600">10600</ref>
        </refs>
        <vuln_soft>
            <prod vendor="accipiter" name="accipiter_direct_server">
                <vers num="6.0" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" name="CVE-2004-0073" seq="2004-0073" severity="High" type="CVE" published="2004-02-17" CVSS_version="2.0 incomplete approximation" CVSS_score="7.5" modified="2008-09-05">
        <desc>
            <descript source="cve">PHP remote file inclusion vulnerability in (1) config.php and (2) config_page.php for EasyDynamicPages 2.0 allows remote attackers to execute arbitrary PHP code by modifying the edp_relative_path parameter to reference a URL on a remote web server that contains a malicious serverdata.php script.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot other="1" />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="BID" patch="1" url="http://www.securityfocus.com/bid/9338" adv="1">9338</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/14136">easydynamicpages-php-file-include(14136)</ref>
            <ref source="OSVDB" url="http://www.osvdb.org/3408">3408</ref>
            <ref source="OSVDB" url="http://www.osvdb.org/3318">3318</ref>
            <ref source="SECTRACK" url="http://securitytracker.com/id?1008584">1008584</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/10535">10535</ref>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107307457327707&amp;w=2">20040102 include() vuln in EasyDynamicPages v.2.0</ref>
        </refs>
        <vuln_soft>
            <prod vendor="stoitsov" name="easydynamicpages">
                <vers num="2.0" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" name="CVE-2004-0074" seq="2004-0074" severity="Medium" type="CVE" published="2004-02-17" CVSS_version="2.0 incomplete approximation" CVSS_score="4.6" modified="2008-09-05">
        <desc>
            <descript source="cve">Multiple buffer overflows in xsok 1.02 allows local users to gain privileges via (1) a long LANG environment variable, or (2) a long -xsokdir command line argument, a different vulnerability than CVE-2003-0949.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot other="1" />
        </loss_types>
        <vuln_types>
            <input buffer="1" />
        </vuln_types>
        <range>
            <local />
        </range>
        <refs>
            <ref source="BID" patch="1" url="http://www.securityfocus.com/bid/9341" adv="1">9341</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/14910">xsok-lang-bo(14910)</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/14906" adv="1">xsok-long-xsokdir-bo(14906)</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/9352" adv="1">9352</ref>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107332542918529&amp;w=2">20040103 xsok local games exploit (2)</ref>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107307407027259&amp;w=2">20040102 xsok local games exploit</ref>
        </refs>
        <vuln_soft>
            <prod vendor="michael_bischoff" name="xsok">
                <vers num="1.02" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:S/C:N/I:N/A:C)" CVSS_base_score="6.8" CVSS_exploit_subscore="8.0" CVSS_impact_subscore="6.9" name="CVE-2004-0049" seq="2004-0049" severity="Medium" type="CVE" published="2004-02-17" CVSS_version="2.0 incomplete approximation" CVSS_score="6.8" modified="2008-09-05">
        <desc>
            <descript source="cve">Helix Universal Server/Proxy 9 and Mobile Server 10 allow remote attackers to cause a denial of service via certain HTTP POST messages to the Administration System port.</descript>
        </desc>
        <loss_types>
            <avail />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="CONFIRM" patch="1" url="http://service.real.com/help/faq/security/040112_dos/" adv="1">http://service.real.com/help/faq/security/040112_dos/</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/9421" adv="1">9421</ref>
            <ref source="CONFIRM" url="http://service.real.com/help/faq/security/security022604.html">http://service.real.com/help/faq/security/security022604.html</ref>
            <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/357834">20040318 ptl-2004-02: RealNetworks Helix Server 9 Administration Server Buffer Overflow</ref>
            <ref source="VULNWATCH" url="http://seclists.org/lists/vulnwatch/2004/Jan-Mar/0057.html">20040318 ptl-2004-02: RealNetworks Helix Server 9 Administration Server Buffer Overflow</ref>
        </refs>
        <vuln_soft>
            <prod vendor="realnetworks" name="helix_universal_mobile_server">
                <vers num="10.1.1.120" prev="1" />
            </prod>
            <prod vendor="realnetworks" name="helix_universal_server">
                <vers num="9.0.2.881" prev="1" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" name="CVE-2004-0095" seq="2004-0095" severity="Medium" type="CVE" published="2004-02-17" CVSS_version="2.0 incomplete approximation" CVSS_score="5.0" modified="2008-09-05">
        <desc>
            <descript source="cve">McAfee ePolicy Orchestrator agent allows remote attackers to cause a denial of service (memory consumption and crash) and possibly execute arbitrary code via an HTTP POST request with an invalid Content-Length value, possibly triggering a buffer overflow.</descript>
        </desc>
        <loss_types>
            <avail />
        </loss_types>
        <vuln_types>
            <input bound="1" />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="BID" url="http://www.securityfocus.com/bid/9476" adv="1">9476</ref>
            <ref source="CONFIRM" url="http://download.nai.com/products/patches/ePO/v3.1.0/EPO3013.zip">http://download.nai.com/products/patches/ePO/v3.1.0/EPO3013.zip</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/14989">epolicy-contentlength-post-dos(14989)</ref>
            <ref source="OSVDB" url="http://www.osvdb.org/3744">3744</ref>
        </refs>
        <vuln_soft>
            <prod vendor="mcafee" name="epolicy_orchestrator">
                <vers num="3.6.0" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" name="CVE-2004-0091" seq="2004-0091" severity="Medium" type="CVE" published="2004-02-17" CVSS_version="2.0 incomplete approximation" CVSS_score="4.3" modified="2008-09-10">
        <desc>
            <descript source="cve">** DISPUTED **  NOTE: this issue has been disputed by the vendor.  Cross-site scripting (XSS) vulnerability in register.php for unknown versions of vBulletin allows remote attackers to inject arbitrary HTML or web script via the reg_site (or possibly regsite) parameter.  NOTE: the vendor has disputed this issue, saying "There is no hidden field called 'reg_site', nor any $reg_site variable anywhere in the vBulletin 2 or vBulletin 3 source code or templates, nor has it ever existed.  We can only assume that this vulnerability was found in a site running code modified from that supplied by Jelsoft."</descript>
        </desc>
        <loss_types>
            <int />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="SECTRACK" url="http://securitytracker.com/id?1008780">1008780</ref>
            <ref source="VULN-DEV" url="http://marc.theaimsgroup.com/?l=vuln-dev&amp;m=107488880317647&amp;w=2" adv="1">20040123 RE: vBulletin Security Vulnerability</ref>
            <ref source="VULN-DEV" url="http://marc.theaimsgroup.com/?l=vuln-dev&amp;m=107478592401619&amp;w=2" adv="1">20040120 Re: vBulletin Security Vulnerability</ref>
            <ref source="VULN-DEV" url="http://marc.theaimsgroup.com/?l=vuln-dev&amp;m=107462499927040&amp;w=2" adv="1">20040120 vBulletin Security Vulnerability</ref>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107462349324945&amp;w=2" adv="1">20040120 vBulletin Security Vulnerability</ref>
        </refs>
        <vuln_soft>
            <prod vendor="jelsoft" name="vbulletin">
                <vers num="3.0_beta_2" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" name="CVE-2004-2136" seq="2004-2136" severity="Low" type="CVE" published="2004-02-19" CVSS_version="2.0 incomplete approximation" CVSS_score="2.1" modified="2008-09-05">
        <desc>
            <descript source="cve">dm-crypt on Linux kernel 2.6.x, when used on certain file systems with a block size 1024 or greater, has certain "IV computation" weaknesses that allow watermarked files to be detected without decryption.</descript>
        </desc>
        <loss_types>
            <conf />
        </loss_types>
        <vuln_types>
            <design />
            <other />
        </vuln_types>
        <range>
            <local />
        </range>
        <refs>
            <ref source="MISC" url="http://www.securiteam.com/exploits/5UP0P1PFPM.html" adv="1">http://www.securiteam.com/exploits/5UP0P1PFPM.html</ref>
            <ref source="MISC" url="http://mareichelt.de/pub/notmine/diskenc.pdf">http://mareichelt.de/pub/notmine/diskenc.pdf</ref>
            <ref source="MLIST" url="http://marc.theaimsgroup.com/?l=linux-kernel&amp;m=107719798631935&amp;w=2" adv="1">[linux-kernel] 20040219 Re: Oopsing cryptoapi (or loop device?) on 2.6.*</ref>
        </refs>
        <vuln_soft>
            <prod vendor="linux" name="linux_kernel">
                <vers num="2.6.0" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" name="CVE-2004-0466" seq="2004-0466" severity="Medium" type="CVE" published="2004-02-21" CVSS_version="2.0 incomplete approximation" CVSS_score="5.0" modified="2008-09-05">
        <desc>
            <descript source="cve">WebConnect 6.5, 6.4.4, and possibly earlier versions allows remote attackers to cause a denial of service (hang) via a URL containing an MS-DOS device name such as (1) AUX, (2) CON, (3) PRN, (4) COM1, or (5) LPT1.</descript>
        </desc>
        <loss_types>
            <avail />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="CONFIRM" patch="1" url="http://www.kb.cert.org/vuls/id/JSHA-69FVMM" adv="1">http://www.kb.cert.org/vuls/id/JSHA-69FVMM</ref>
            <ref source="CERT-VN" patch="1" url="http://www.kb.cert.org/vuls/id/552561" adv="1">VU#552561</ref>
            <ref source="XF" patch="1" url="http://xforce.iss.net/xforce/xfdb/19393" adv="1">webconnect-device-name-dos(19393)</ref>
            <ref source="SECUNIA" patch="1" url="http://secunia.com/advisories/14006/" adv="1">14006</ref>
            <ref source="MISC" url="http://www.cirt.dk/advisories/cirt-29-advisory.pdf" adv="1">http://www.cirt.dk/advisories/cirt-29-advisory.pdf</ref>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110910838600145&amp;w=2" adv="1">20050220 The WebConnect 6.4.4 and 6.5 contains several vulnerabilities</ref>
        </refs>
        <vuln_soft>
            <prod vendor="openconnect" name="webconnect">
                <vers num="6.4.4" />
                <vers num="6.5" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" name="CVE-2004-0322" seq="2004-0322" severity="Medium" type="CVE" published="2004-02-23" CVSS_version="2.0 incomplete approximation" CVSS_score="4.3" modified="2008-09-05">
        <desc>
            <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in XMB 1.8 Final SP2 allow remote attackers to execute arbitrary script as other users via the (1) member parameter in member.php, (2) uid parameter in u2uadmin.php, (3) user parameter in editprofile.php, (4) an onmouseover event in an align tag when bbcode is allowed, or (5) img tag where bbcode is allowed.</descript>
        </desc>
        <loss_types>
            <int />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="XF" patch="1" url="http://xforce.iss.net/xforce/xfdb/15292" adv="1">xmb-multiple-scripts-xss(15292)</ref>
            <ref source="BID" patch="1" url="http://www.securityfocus.com/bid/9726" adv="1">9726</ref>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107756526625179&amp;w=2" adv="1">20040223 [waraxe-2004-SA#004] - Multiple vulnerabilities in XMB 1.8 Partagium Final SP2</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/15294">xmb-bbcode-execute-code(15294)</ref>
            <ref source="CONFIRM" url="http://www.xmbforum.com/community/boards/viewthread.php?tid=746859">http://www.xmbforum.com/community/boards/viewthread.php?tid=746859</ref>
            <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2004-02/0645.html">20040225 Re: [waraxe-2004-SA#004] - Multiple vulnerabilities in XMB 1.8 Partagium Final SP2</ref>
        </refs>
        <vuln_soft>
            <prod vendor="xmb_forum" name="xmb">
                <vers num="1.8" />
                <vers num="1.8_sp1" />
                <vers num="1.8_sp2" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" name="CVE-2004-0324" seq="2004-0324" severity="High" type="CVE" published="2004-02-23" CVSS_version="2.0 incomplete approximation" CVSS_score="7.5" modified="2008-09-05">
        <desc>
            <descript source="cve">Confirm 0.62 and earlier could allow remote attackers to execute arbitrary code via an e-mail header that contains shell metacharacters such as ", `, |, ;, or $.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot user="1" />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="XF" patch="1" url="http://xforce.iss.net/xforce/xfdb/15290" adv="1">confirm-header-gain-access(15290)</ref>
            <ref source="BID" patch="1" url="http://www.securityfocus.com/bid/9728" adv="1">9728</ref>
            <ref source="BUGTRAQ" patch="1" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107757320401858&amp;w=2" adv="1">20040223 Lam3rZ Security Advisory #3/2004: A bug in Confirm leads to remote command execution</ref>
        </refs>
        <vuln_soft>
            <prod vendor="confirm" name="confirm">
                <vers num="0.50" />
                <vers num="0.51" />
                <vers num="0.52" />
                <vers num="0.53" />
                <vers num="0.54" />
                <vers num="0.55" />
                <vers num="0.60" />
                <vers num="0.61" />
                <vers num="0.62" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" name="CVE-2004-1360" seq="2004-1360" severity="Low" type="CVE" published="2004-02-27" CVSS_version="2.0 incomplete approximation" CVSS_score="2.1" modified="2008-09-10">
        <desc>
            <descript source="cve">Unknown vulnerability in conv_fix in Sun Solaris 7 through 9, when invoked by conv_lpd, allows local users to overwrite arbitrary files.</descript>
        </desc>
        <loss_types>
            <int />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <local />
        </range>
        <refs>
            <ref source="CERT-VN" patch="1" url="http://www.kb.cert.org/vuls/id/412566" adv="1">VU#412566</ref>
            <ref source="XF" patch="1" url="http://xforce.iss.net/xforce/xfdb/15331">solaris-covfix-gain-privileges(15331)</ref>
            <ref source="CIAC" patch="1" url="http://www.ciac.org/ciac/bulletins/o-089.shtml" adv="1">O-089</ref>
            <ref source="AUSCERT" patch="1" url="http://www.auscert.org.au/render.html?it=3902" adv="1">ESB-2004.0169</ref>
            <ref source="SUNALERT" patch="1" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-57509-1" adv="1">57509</ref>
            <ref source="SECUNIA" patch="1" url="http://secunia.com/advisories/10991" adv="1">10991</ref>
            <ref source="OSVDB" url="http://www.osvdb.org/displayvuln.php?osvdb_id=4071">4071</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/9759">9759</ref>
            <ref source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1732" sig="1">oval:org.mitre.oval:def:1732</ref>
        </refs>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" name="CVE-2004-0944" seq="2004-0944" severity="Medium" type="CVE" published="2004-02-28" CVSS_version="2.0 incomplete approximation" CVSS_score="5.0" modified="2008-09-05">
        <desc>
            <descript source="cve">The web management interface for Mitel 3300 Integrated Communications Platform (ICP) before 4.2.2.11 generates easily predictable web session IDs, which allows remote attackers to hijack other sessions via the parentsessionid cookie.</descript>
        </desc>
        <loss_types>
            <conf />
        </loss_types>
        <vuln_types>
            <design />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="MISC" patch="1" url="http://www.niscc.gov.uk/niscc/docs/re-20050228-00178.pdf?lang=en" adv="1">http://www.niscc.gov.uk/niscc/docs/re-20050228-00178.pdf?lang=en</ref>
            <ref source="CONFIRM" patch="1" url="http://www.mitel.com/DocController?documentId=14223" adv="1">http://www.mitel.com/DocController?documentId=14223</ref>
            <ref source="MISC" url="http://www.corsaire.com/advisories/c040817-002.txt" adv="1">http://www.corsaire.com/advisories/c040817-002.txt</ref>
        </refs>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" name="CVE-2004-0092" seq="2004-0092" severity="High" type="CVE" published="2004-03-03" CVSS_version="2.0 incomplete approximation" CVSS_score="10.0" modified="2008-09-10">
        <desc>
            <descript source="cve">Unknown vulnerability in Safari web browser in Mac OS X 10.2.8 and 10.3.2, with unknown impact.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
        </loss_types>
        <vuln_types>
            <other />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="BID" url="http://www.securityfocus.com/bid/9504">9504</ref>
            <ref source="APPLE" url="http://lists.apple.com/archives/security-announce/2004/Jan/msg00000.html">APPLE-SA-2004-01-26</ref>
        </refs>
        <vuln_soft>
            <prod vendor="apple" name="mac_os_x">
                <vers num="10.2.8" />
                <vers num="10.3.2" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" name="CVE-2004-0080" seq="2004-0080" severity="Medium" type="CVE" published="2004-03-03" CVSS_version="2.0 incomplete approximation" CVSS_score="5.0" modified="2008-09-05">
        <desc>
            <descript source="cve">The login program in util-linux 2.11 and earlier uses a pointer after it has been freed and reallocated, which could cause login to leak sensitive data.</descript>
        </desc>
        <loss_types>
            <conf />
        </loss_types>
        <vuln_types>
            <design />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/801526">VU#801526</ref>
            <ref source="REDHAT" patch="1" url="http://www.redhat.com/support/errata/RHSA-2004-056.html" adv="1">RHSA-2004:056</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/9558" adv="1">9558</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/15016">utillinux-information-leak(15016)</ref>
            <ref source="OSVDB" url="http://www.osvdb.org/3796">3796</ref>
            <ref source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200404-06.xml">GLSA-200404-06</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/10773">10773</ref>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108144719532385&amp;w=2">20040408 LNSA-#2004-0010: login may leak sensitive data</ref>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108077689801698&amp;w=2">20040331 OpenLinux: util-linux could leak sensitive data</ref>
            <ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/20040406-01-U">20040406-01-U</ref>
            <ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/20040201-01-U.asc">20040201-01-U</ref>
        </refs>
        <vuln_soft>
            <prod vendor="andries_brouwer" name="util-linux">
                <vers num="2.11" prev="1" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" name="CVE-2004-0114" seq="2004-0114" severity="Medium" type="CVE" published="2004-03-03" CVSS_version="2.0 incomplete approximation" CVSS_score="4.6" modified="2008-09-05">
        <desc>
            <descript source="cve">The shmat system call in the System V Shared Memory interface for FreeBSD 5.2 and earlier, NetBSD 1.3 and earlier, and OpenBSD 2.6 and earlier, does not properly decrement a shared memory segment's reference count when the vm_map_find function fails, which could allow local users to gain read or write access to a portion of kernel memory and gain privileges.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot other="1" />
        </loss_types>
        <vuln_types>
            <design />
        </vuln_types>
        <range>
            <local />
        </range>
        <refs>
            <ref source="XF" patch="1" url="http://xforce.iss.net/xforce/xfdb/15061" adv="1">bsd-shmat-gain-privileges(15061)</ref>
            <ref source="BID" patch="1" url="http://www.securityfocus.com/bid/9586" adv="1">9586</ref>
            <ref source="FREEBSD" patch="1" url="ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-04:02.shmat.asc" adv="1">FreeBSD-SA-04:02</ref>
            <ref source="MISC" url="http://www.pine.nl/press/pine-cert-20040201.txt">http://www.pine.nl/press/pine-cert-20040201.txt</ref>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107608375207601&amp;w=2" adv="1">20040205 [PINE-CERT-20040201] reference count overflow in shmat()</ref>
            <ref source="OSVDB" url="http://www.osvdb.org/3836">3836</ref>
            <ref source="CONFIRM" url="http://www.openbsd.org/errata33.html#sysvshm">http://www.openbsd.org/errata33.html#sysvshm</ref>
            <ref source="NETBSD" url="ftp://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2004-004.txt.asc">NetBSD-SA2004-004</ref>
        </refs>
        <vuln_soft>
            <prod vendor="freebsd" name="freebsd">
                <vers num="5.2" prev="1" />
            </prod>
            <prod vendor="netbsd" name="netbsd">
                <vers num="1.3" prev="1" />
            </prod>
            <prod vendor="openbsd" name="openbsd">
                <vers num="2.6" prev="1" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" name="CVE-2004-0115" seq="2004-0115" severity="Medium" type="CVE" published="2004-03-03" CVSS_version="2.0 incomplete approximation" CVSS_score="4.6" modified="2008-09-05">
        <desc>
            <descript source="cve">VirtualPC_Services in Microsoft Virtual PC for Mac 6.0 through 6.1 allows local attackers to truncate and overwrite arbitrary files, and execute arbitrary code, via a symlink attack on the VPCServices_Log temporary file.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot other="1" />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <local />
        </range>
        <refs>
            <ref source="BID" patch="1" url="http://www.securityfocus.com/bid/9632" adv="1">9632</ref>
            <ref source="MS" patch="1" url="http://www.microsoft.com/technet/security/bulletin/ms04-005.asp" adv="1">MS04-005</ref>
            <ref source="ATSTAKE" url="http://www.atstake.com/research/advisories/2004/a021004-1.txt" adv="1">A021004-1</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/15113">virtual-pc-gain-privileges(15113)</ref>
            <ref source="OSVDB" url="http://www.osvdb.org/3893">3893</ref>
            <ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/o-076.shtml">O-076</ref>
        </refs>
        <vuln_soft>
            <prod vendor="microsoft" name="virtual_pc">
                <vers edition="" num="6.0" />
                <vers edition=":mac" num="6.0" />
                <vers edition="" num="6.1" />
                <vers edition=":mac" num="6.1" />
                <vers edition="" num="6.2" />
                <vers edition=":mac" num="6.2" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" name="CVE-2004-0127" seq="2004-0127" severity="High" type="CVE" published="2004-03-03" CVSS_version="2.0 incomplete approximation" CVSS_score="7.5" modified="2008-09-05">
        <desc>
            <descript source="cve">Directory traversal vulnerability in editconfig_gedcom.php for phpGedView 2.65.1 and earlier allows remote attackers to read arbitrary files or execute arbitrary PHP programs on the server via .. (dot dot) sequences in the gedcom_config parameter.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot other="1" />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="BID" patch="1" url="http://www.securityfocus.com/bid/9529" adv="1">9529</ref>
            <ref source="BUGTRAQ" patch="1" url="http://www.securityfocus.com/archive/1/352355" adv="1">20040129 PHP Code Injection Vulnerabilities in phpGedView 2.65.1 and prior</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/15129">phpgedview-editconfig-directory-traversal(15129)</ref>
            <ref source="SECTRACK" url="http://www.securitytracker.com/id?1008892">1008892</ref>
            <ref source="OSVDB" url="http://www.osvdb.org/displayvuln.php?osvdb_id=3768">3768</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/10753/">10753</ref>
        </refs>
        <vuln_soft>
            <prod vendor="phpgedview" name="phpgedview">
                <vers num="2.52.3" />
                <vers num="2.60" />
                <vers num="2.61" />
                <vers num="2.61.1" />
                <vers num="2.65" />
                <vers num="2.65.1" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" name="CVE-2004-0128" seq="2004-0128" severity="High" type="CVE" published="2004-03-03" CVSS_version="2.0 incomplete approximation" CVSS_score="7.5" modified="2008-09-05">
        <desc>
            <descript source="cve">PHP remote file inclusion vulnerability in the GEDCOM configuration script for phpGedView 2.65.1 and earlier allows remote attackers to execute arbitrary PHP code by modifying the PGV_BASE_DIRECTORY parameter to reference a URL on a remote web server that contains a malicious theme.php script.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot other="1" />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="BID" patch="1" url="http://www.securityfocus.com/bid/9531" adv="1">9531</ref>
            <ref source="BUGTRAQ" patch="1" url="http://www.securityfocus.com/archive/1/352355" adv="1">20040129 PHP Code Injection Vulnerabilities in phpGedView 2.65.1 and prior</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/14987">phpgedview-gedfilconf-file-include(14987)</ref>
            <ref source="OSVDB" url="http://www.osvdb.org/3769">3769</ref>
            <ref source="CONFIRM" url="http://sourceforge.net/project/shownotes.php?release_id=141517" adv="1">http://sourceforge.net/project/shownotes.php?release_id=141517</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/10753/">10753</ref>
        </refs>
        <vuln_soft>
            <prod vendor="phpgedview" name="phpgedview">
                <vers num="2.52.3" />
                <vers num="2.60" />
                <vers num="2.61" />
                <vers num="2.61.1" />
                <vers num="2.65" />
                <vers num="2.65.1" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" name="CVE-2004-0129" seq="2004-0129" severity="Medium" type="CVE" published="2004-03-03" CVSS_version="2.0 incomplete approximation" CVSS_score="5.0" modified="2008-09-05">
        <desc>
            <descript source="cve">Directory traversal vulnerability in export.php in phpMyAdmin 2.5.5 and earlier allows remote attackers to read arbitrary files via .. (dot dot) sequences in the what parameter.</descript>
        </desc>
        <loss_types>
            <conf />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="BID" patch="1" url="http://www.securityfocus.com/bid/9564" adv="1">9564</ref>
            <ref source="BUGTRAQ" patch="1" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107582619125932&amp;w=2" adv="1">20040203 Arbitrary File Disclosure Vulnerability in phpMyAdmin 2.5.5-pl1 and prior</ref>
            <ref source="CONFIRM" url="http://www.phpmyadmin.net/home_page/relnotes.php?rel=0">http://www.phpmyadmin.net/home_page/relnotes.php?rel=0</ref>
            <ref source="CONFIRM" url="http://sourceforge.net/forum/forum.php?forum_id=350228">http://sourceforge.net/forum/forum.php?forum_id=350228</ref>
            <ref source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200402-05.xml" adv="1">GLSA-200402-05</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/15021">phpmyadmin-dotdot-directory-traversal(15021)</ref>
            <ref source="OSVDB" url="http://www.osvdb.org/3800">3800</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/10769">10769</ref>
        </refs>
        <vuln_soft>
            <prod vendor="phpmyadmin" name="phpmyadmin">
                <vers num="2.0" />
                <vers num="2.0.1" />
                <vers num="2.0.2" />
                <vers num="2.0.3" />
                <vers num="2.0.4" />
                <vers num="2.0.5" />
                <vers num="2.1" />
                <vers num="2.1.1" />
                <vers num="2.1.2" />
                <vers num="2.2.2" />
                <vers num="2.2.3" />
                <vers num="2.2.4" />
                <vers num="2.2.5" />
                <vers num="2.2.6" />
                <vers num="2.2_pre1" />
                <vers num="2.2_rc1" />
                <vers num="2.2_rc2" />
                <vers num="2.2_rc3" />
                <vers num="2.3.1" />
                <vers num="2.3.2" />
                <vers num="2.4.0" />
                <vers num="2.5.0" />
                <vers num="2.5.1" />
                <vers num="2.5.2" />
                <vers num="2.5.4" />
                <vers num="2.5.5" />
                <vers num="2.5.5_pl1" />
                <vers num="2.5.5_rc1" />
                <vers num="2.5.5_rc2" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" name="CVE-2004-0130" seq="2004-0130" severity="Medium" type="CVE" published="2004-03-03" CVSS_version="2.0 incomplete approximation" CVSS_score="5.0" modified="2008-09-05">
        <desc>
            <descript source="cve">login.php in phpGedView 2.65 and earlier allows remote attackers to obtain sensitive information via an HTTP request to login.php that does not contain the required username or password parameters, which causes the information to be leaked in an error message.</descript>
        </desc>
        <loss_types>
            <conf />
        </loss_types>
        <vuln_types>
            <design />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="MISC" url="http://www.securiteam.com/unixfocus/5NP0M1PBPQ.html" adv="1">http://www.securiteam.com/unixfocus/5NP0M1PBPQ.html</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/15128">phpgedview-loginphp-path-disclosure(15128)</ref>
            <ref source="OSVDB" url="http://www.osvdb.org/6886">6886</ref>
            <ref source="MISC" url="http://www.netvigilance.com/advisory0001">http://www.netvigilance.com/advisory0001</ref>
            <ref source="SECTRACK" url="http://securitytracker.com/alerts/2004/Jan/1008844.html">1008844</ref>
        </refs>
        <vuln_soft>
            <prod vendor="phpgedview" name="phpgedview">
                <vers num="2.65" prev="1" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" name="CVE-2004-0131" seq="2004-0131" severity="Medium" type="CVE" published="2004-03-03" CVSS_version="2.0 incomplete approximation" CVSS_score="5.0" modified="2008-09-10">
        <desc>
            <descript source="cve">The rad_print_request function in logger.c for GNU Radius daemon (radiusd) before 1.2 allows remote atackers to cause a denial of service (crash) via a UDP packet with an Acct-Status-Type attribute without a value and no Acct-Session-Id attribute, which causes a null dereference.</descript>
        </desc>
        <loss_types>
            <avail />
        </loss_types>
        <vuln_types>
            <exception />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/277396" adv="1">VU#277396</ref>
            <ref source="XF" patch="1" url="http://xforce.iss.net/xforce/xfdb/15046" adv="1">radius-radprintrequest-dos(15046)</ref>
            <ref source="BID" patch="1" url="http://www.securityfocus.com/bid/9578" adv="1">9578</ref>
            <ref source="CONFIRM" url="http://ftp.gnu.org/gnu/radius/radius-1.2.tar.gz">http://ftp.gnu.org/gnu/radius/radius-1.2.tar.gz</ref>
            <ref source="OSVDB" url="http://www.osvdb.org/3824">3824</ref>
            <ref source="IDEFENSE" url="http://www.idefense.com/application/poi/display?id=71&amp;type=vulnerabilities&amp;flashstatus=true">20040204 GNU Radius Remote Denial of Service Vulnerability</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/10799">10799</ref>
        </refs>
        <vuln_soft>
            <prod vendor="gnu" name="radius">
                <vers num="1.1" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" name="CVE-2004-0132" seq="2004-0132" severity="High" type="CVE" published="2004-03-03" CVSS_version="2.0 incomplete approximation" CVSS_score="7.5" modified="2008-09-10">
        <desc>
            <descript source="cve">Multiple PHP remote file inclusion vulnerabilities in ezContents 2.0.2 and earlier allow remote attackers to execute arbitrary PHP code from a remote web server, as demonstrated using (1) the GLOBALS[rootdp] parameter to db.php, or (2) the GLOBALS[language_home] parameter to archivednews.php, and a malicious version of lang_admin.php.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot other="1" />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="BUGTRAQ" patch="1" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107651585921958&amp;w=2" adv="1">20040210 PHP Code Injection Vulnerabilities in ezContents 2.0.2 and prior</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/15135" adv="1">ezcontents-multiple-file-include(15135)</ref>
        </refs>
        <vuln_soft>
            <prod vendor="visualshapers" name="ezcontents">
                <vers num="1.40" />
                <vers num="1.41" />
                <vers num="1.42" />
                <vers num="1.43" />
                <vers num="1.44" />
                <vers num="1.45" />
                <vers num="1.45b" />
                <vers num="2.0.1" />
                <vers num="2.0.2" />
                <vers num="2.0_rc1" />
                <vers num="2.0_rc2" />
                <vers num="2.0_rc3" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" name="CVE-2004-0143" seq="2004-0143" severity="Medium" type="CVE" published="2004-03-03" CVSS_version="2.0 incomplete approximation" CVSS_score="5.0" modified="2008-09-05">
        <desc>
            <descript source="cve">Multiple vulnerabilities in Nokia 6310(i) Mobile phones allow remote attackers to cause a denial of service (reset) via malformed Bluetooth OBject EXchange (OBEX) messages, probably triggering buffer overflows.</descript>
        </desc>
        <loss_types>
            <avail />
        </loss_types>
        <vuln_types>
            <input buffer="1" />
            <design />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="XF" patch="1" url="http://xforce.iss.net/xforce/xfdb/15107" adv="1">nokia-obex-dos(15107)</ref>
            <ref source="BID" patch="1" url="http://www.securityfocus.com/bid/9603" adv="1">9603</ref>
            <ref source="MISC" patch="1" url="http://www.pentest.co.uk/documents/ptl-2004-01.html" adv="1">http://www.pentest.co.uk/documents/ptl-2004-01.html</ref>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107634788029065&amp;w=2" adv="1">20040209 ptl-2004-01: Multiple vulnerabilities in Nokia phones</ref>
            <ref source="VULNWATCH" url="http://archives.neohapsis.com/archives/vulnwatch/2004-q1/0034.html">20040209 ptl-2004-01: Multiple vulnerabilities in Nokia phones</ref>
        </refs>
        <vuln_soft>
            <prod vendor="nokia" name="6310i">
                <vers num="" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" name="CVE-2004-0164" seq="2004-0164" severity="Medium" type="CVE" published="2004-03-03" CVSS_version="2.0 incomplete approximation" CVSS_score="5.0" modified="2008-09-10">
        <desc>
            <descript source="cve">KAME IKE daemon (racoon) does not properly handle hash values, which allows remote attackers to delete certificates via (1) a certain delete message that is not properly handled in isakmp.c or isakmp_inf.c, or (2) a certain INITIAL-CONTACT message that is not properly handled in isakmp_inf.c.</descript>
        </desc>
        <loss_types>
            <int />
        </loss_types>
        <vuln_types>
            <access />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="BUGTRAQ" patch="1" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107411758202662&amp;w=2">20040114 Re: unauthorized deletion of IPsec (and ISAKMP) SAs in racoon</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/14118">openbsd-isakmp-initialcontact-delete-sa(14118)</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/14117" adv="1">openbsd-isakmp-invalidspi-delete-sa(14117)</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/9417">9417</ref>
            <ref source="APPLE" url="http://lists.apple.com/archives/security-announce/2004/Feb/msg00000.html">APPLE-SA-2004-02-23</ref>
            <ref source="NETBSD" url="ftp://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2004-001.txt.asc">NetBSD-SA2004-001</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/9416">9416</ref>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107403331309838&amp;w=2">20040113 unauthorized deletion of IPsec (and ISAKMP) SAs in racoon</ref>
            <ref source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:947" sig="1">oval:org.mitre.oval:def:947</ref>
        </refs>
        <vuln_soft>
            <prod vendor="kame" name="racoon">
                <vers num="all_versions" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" name="CVE-2004-0096" seq="2004-0096" severity="Medium" type="CVE" published="2004-03-03" CVSS_version="2.0 incomplete approximation" CVSS_score="5.0" modified="2008-09-05">
        <desc>
            <descript source="cve">Unknown vulnerability in mod_python 2.7.9 allows remote attackers to cause a denial of service (httpd crash) via a certain query string, a variant of CAN-2003-0973.</descript>
        </desc>
        <loss_types>
            <avail />
        </loss_types>
        <vuln_types>
            <other />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="MLIST" patch="1" url="http://www.modpython.org/pipermail/mod_python/2004-January/014879.html" adv="1">[mod_python] 20040122 [ANNOUNCE] Mod_python 2.7.10</ref>
            <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2004-063.html">RHSA-2004:063</ref>
            <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2004-058.html">RHSA-2004:058</ref>
            <ref source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200401-03.xml">GLSA-200401-03</ref>
        </refs>
        <vuln_soft>
            <prod vendor="apache" name="mod_python">
                <vers num="2.7.9" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" name="CVE-2004-0097" seq="2004-0097" severity="High" type="CVE" published="2004-03-03" CVSS_version="2.0 incomplete approximation" CVSS_score="10.0" modified="2008-09-10">
        <desc>
            <descript source="cve">Multiple vulnerabilities in PWLib before 1.6.0 allow remote attackers to cause a denial of service and possibly execute arbitrary code, as demonstrated by the NISCC/OUSPG PROTOS test suite for the H.225 protocol.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot admin="1" user="1" />
        </loss_types>
        <vuln_types>
            <other />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="CERT-VN" patch="1" url="http://www.kb.cert.org/vuls/id/749342" adv="1">VU#749342</ref>
            <ref source="CERT" patch="1" url="http://www.cert.org/advisories/CA-2004-01.html" adv="1">CA-2004-01</ref>
            <ref source="REDHAT" patch="1" url="http://www.redhat.com/support/errata/RHSA-2004-047.html" adv="1">RHSA-2004:047</ref>
            <ref source="DEBIAN" patch="1" url="http://www.debian.org/security/2004/dsa-448" adv="1">DSA-448</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/15202" adv="1">pwlib-message-dos(15202)</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/9406">9406</ref>
            <ref source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:826" sig="1">oval:org.mitre.oval:def:826</ref>
            <ref source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:803" sig="1">oval:org.mitre.oval:def:803</ref>
        </refs>
        <vuln_soft>
            <prod vendor="openh323_project" name="pwlib">
                <vers num="1.6.0" prev="1" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" name="CVE-2004-0099" seq="2004-0099" severity="Medium" type="CVE" published="2004-03-03" CVSS_version="2.0 incomplete approximation" CVSS_score="4.6" modified="2008-09-05">
        <desc>
            <descript source="cve">mksnap_ffs in FreeBSD 5.1 and 5.2 only sets the snapshot flag when creating a snapshot for a file system, which causes default values for other flags to be used, possibly disabling security-critical settings and allowing a local user to bypass intended access restrictions.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot other="1" />
        </loss_types>
        <vuln_types>
            <design />
        </vuln_types>
        <range>
            <local />
        </range>
        <refs>
            <ref source="BID" patch="1" url="http://www.securityfocus.com/bid/9533" adv="1">9533</ref>
            <ref source="FREEBSD" patch="1" url="ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-04:01.mksnap_ffs.asc" adv="1">FreeBSD-SA-04:01</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/15005">freebsd-mksnapffs-bypass-security(15005)</ref>
            <ref source="OSVDB" url="http://www.osvdb.org/3790">3790</ref>
        </refs>
        <vuln_soft>
            <prod vendor="freebsd" name="freebsd">
                <vers edition="release" num="5.1" />
                <vers edition="release" num="5.2.1" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" name="CVE-2004-0103" seq="2004-0103" severity="Medium" type="CVE" published="2004-03-03" CVSS_version="2.0 incomplete approximation" CVSS_score="4.6" modified="2008-09-05">
        <desc>
            <descript source="cve">crawl before 4.0.0 beta23 does not properly "apply a size check" when copying a certain environment variable, which may allow local users to gain privileges, possibly as a result of a buffer overflow.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot other="1" />
        </loss_types>
        <vuln_types>
            <input bound="1" />
        </vuln_types>
        <range>
            <local />
        </range>
        <refs>
            <ref source="DEBIAN" patch="1" url="http://www.debian.org/security/2004/dsa-432" adv="1">DSA-432</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/15032">crawl-long-environment-bo(15032)</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/9566">9566</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/10788/">10788</ref>
        </refs>
        <vuln_soft>
            <prod vendor="linley_henzell" name="crawl">
                <vers num="4.0.0_b23" prev="1" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" name="CVE-2004-0104" seq="2004-0104" severity="High" type="CVE" published="2004-03-03" CVSS_version="2.0 incomplete approximation" CVSS_score="7.5" modified="2008-09-10">
        <desc>
            <descript source="cve">Multiple format string vulnerabilities in Metamail 2.7 and earlier allow remote attackers to execute arbitrary code.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot other="1" />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/518518">VU#518518</ref>
            <ref source="BID" patch="1" url="http://www.securityfocus.com/bid/9692" adv="1">9692</ref>
            <ref source="REDHAT" patch="1" url="http://www.redhat.com/support/errata/RHSA-2004-073.html" adv="1">RHSA-2004:073</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/15259" adv="1">metamail-printheader-format-string(15259)</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/15245">metamail-contenttype-format-string(15245)</ref>
            <ref source="DEBIAN" url="http://www.debian.org/security/2004/dsa-449">DSA-449</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/10908">10908</ref>
            <ref source="VULNWATCH" url="http://archives.neohapsis.com/archives/vulnwatch/2004-q1/0041.html">20040218 metamail format string bugs and buffer overflows</ref>
            <ref source="SLACKWARE" url="http://www.slackware.com/security/viewer.php?l=slackware-security&amp;y=2004&amp;m=slackware-security.404734">SSA:2004-049</ref>
            <ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2004:014">MDKSA-2004:014</ref>
            <ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/o-083.shtml">O-083</ref>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107713476911429&amp;w=2">20040218 metamail format string bugs and buffer overflows</ref>
        </refs>
        <vuln_soft>
            <prod vendor="metamail_corporation" name="metamail">
                <vers num="2.7" prev="1" />
            </prod>
            <prod vendor="sgi" name="propack">
                <vers num="2.3" />
                <vers num="2.4" />
            </prod>
            <prod vendor="redhat" name="enterprise_linux">
                <vers edition="" num="2.1" />
                <vers edition=":workstation" num="2.1" />
                <vers edition=":enterprise_server" num="2.1" />
                <vers edition=":advanced_server" num="2.1" />
            </prod>
            <prod vendor="redhat" name="linux_advanced_workstation">
                <vers edition="" num="2.1" />
                <vers edition=":itanium_processor" num="2.1" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" name="CVE-2004-0105" seq="2004-0105" severity="High" type="CVE" published="2004-03-03" CVSS_version="2.0 incomplete approximation" CVSS_score="7.5" modified="2008-09-10">
        <desc>
            <descript source="cve">Multiple buffer overflows in Metamail 2.7 and earlier allow remote attackers to execute arbitrary code.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot other="1" />
        </loss_types>
        <vuln_types>
            <input buffer="1" />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/513062">VU#513062</ref>
            <ref source="REDHAT" patch="1" url="http://www.redhat.com/support/errata/RHSA-2004-073.html" adv="1">RHSA-2004:073</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/15258" adv="1">metamail-splitmail-subject-bo(15258)</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/15247">metamail-printheader-nonascii-bo(15247)</ref>
            <ref source="DEBIAN" url="http://www.debian.org/security/2004/dsa-449">DSA-449</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/10908">10908</ref>
            <ref source="VULNWATCH" url="http://archives.neohapsis.com/archives/vulnwatch/2004-q1/0041.html">20040218 metamail format string bugs and buffer overflows</ref>
            <ref source="SLACKWARE" url="http://www.slackware.com/security/viewer.php?l=slackware-security&amp;y=2004&amp;m=slackware-security.404734">SSA:2004-049</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/9692">9692</ref>
            <ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2004:014">MDKSA-2004:014</ref>
            <ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/o-083.shtml">O-083</ref>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107713476911429&amp;w=2">20040218 metamail format string bugs and buffer overflows</ref>
        </refs>
        <vuln_soft>
            <prod vendor="metamail_corporation" name="metamail">
                <vers num="2.7" prev="1" />
            </prod>
            <prod vendor="sgi" name="propack">
                <vers num="2.3" />
                <vers num="2.4" />
            </prod>
            <prod vendor="redhat" name="enterprise_linux">
                <vers edition="" num="2.1" />
                <vers edition=":workstation" num="2.1" />
                <vers edition=":enterprise_server" num="2.1" />
                <vers edition=":advanced_server" num="2.1" />
            </prod>
            <prod vendor="redhat" name="linux_advanced_workstation">
                <vers edition="" num="2.1" />
                <vers edition=":itanium_processor" num="2.1" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" name="CVE-2004-0106" seq="2004-0106" severity="High" type="CVE" published="2004-03-03" CVSS_version="2.0 incomplete approximation" CVSS_score="7.2" modified="2008-09-10">
        <desc>
            <descript source="cve">Multiple unknown vulnerabilities in XFree86 4.1.0 to 4.3.0, related to improper handling of font files, a different set of vulnerabilities than CVE-2004-0083 and CVE-2004-0084.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot admin="1" />
        </loss_types>
        <vuln_types>
            <other />
        </vuln_types>
        <range>
            <local />
        </range>
        <refs>
            <ref source="SLACKWARE" patch="1" url="http://www.slackware.com/security/viewer.php?l=slackware-security&amp;y=2004&amp;m=slackware-security.405053" adv="1">SSA:2004-043</ref>
            <ref source="REDHAT" patch="1" url="http://www.redhat.com/support/errata/RHSA-2004-061.html" adv="1">RHSA-2004:061</ref>
            <ref source="REDHAT" patch="1" url="http://www.redhat.com/support/errata/RHSA-2004-060.html" adv="1">RHSA-2004:060</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/15206" adv="1">xfree86-multiple-font-improper-handling(15206)</ref>
            <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2004-059.html">RHSA-2004:059</ref>
            <ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2004_06_xf86.html">SuSE-SA:2004:006</ref>
            <ref source="DEBIAN" url="http://www.debian.org/security/2004/dsa-443">DSA-443</ref>
            <ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2004:012">MDKSA-2004:012</ref>
            <ref source="FEDORA" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110979666528890&amp;w=2">FLSA:2314</ref>
            <ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000821">CLA-2004:821</ref>
            <ref source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:832" sig="1">oval:org.mitre.oval:def:832</ref>
            <ref source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:809" sig="1">oval:org.mitre.oval:def:809</ref>
        </refs>
        <vuln_soft>
            <prod vendor="xfree86_project" name="x11r6">
                <vers num="4.1.0" />
                <vers num="4.1.11" />
                <vers num="4.1.12" />
                <vers num="4.2.0" />
                <vers edition="" num="4.2.1" />
                <vers edition=":errata" num="4.2.1" />
                <vers num="4.3.0" />
            </prod>
            <prod vendor="openbsd" name="openbsd">
                <vers num="3.3" />
                <vers num="3.4" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" name="CVE-2004-0082" seq="2004-0082" severity="High" type="CVE" published="2004-03-03" CVSS_version="2.0 incomplete approximation" CVSS_score="7.5" modified="2008-09-05">
        <desc>
            <descript source="cve">The mksmbpasswd shell script (mksmbpasswd.sh) in Samba 3.0.0 and 3.0.1, when creating an account but marking it as disabled, may overwrite the user password with an uninitialized buffer, which could enable the account with a more easily guessable password.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot other="1" />
        </loss_types>
        <vuln_types>
            <design />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="BID" patch="1" url="http://www.securityfocus.com/bid/9637" adv="1">9637</ref>
            <ref source="REDHAT" patch="1" url="http://www.redhat.com/support/errata/RHSA-2004-064.html" adv="1">RHSA-2004:064</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/15132" adv="1">samba-mksmbpasswd-gain-access(15132)</ref>
            <ref source="CONFIRM" url="http://www.vuxml.org/freebsd/3388eff9-5d6e-11d8-80e3-0020ed76ef5a.html">http://www.vuxml.org/freebsd/3388eff9-5d6e-11d8-80e3-0020ed76ef5a.html</ref>
            <ref source="CONFIRM" url="http://us1.samba.org/samba/ftp/WHATSNEW-3.0.2a.txt">http://us1.samba.org/samba/ftp/WHATSNEW-3.0.2a.txt</ref>
            <ref source="OSVDB" url="http://www.osvdb.org/3919">3919</ref>
            <ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/o-078.shtml">O-078</ref>
            <ref source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:827" sig="1">oval:org.mitre.oval:def:827</ref>
        </refs>
        <vuln_soft>
            <prod vendor="samba" name="samba">
                <vers num="3.0" />
                <vers num="3.0.0" />
                <vers num="3.0.1" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" name="CVE-2004-0083" seq="2004-0083" severity="High" type="CVE" published="2004-03-03" CVSS_version="2.0 incomplete approximation" CVSS_score="10.0" modified="2008-09-10">
        <desc>
            <descript source="cve">Buffer overflow in ReadFontAlias from dirfile.c of XFree86 4.1.0 through 4.3.0 allows local users and remote attackers to execute arbitrary code via a font alias file (font.alias) with a long token, a different vulnerability than CVE-2004-0084 and CVE-2004-0106.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot admin="1" />
        </loss_types>
        <vuln_types>
            <input buffer="1" />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/820006">VU#820006</ref>
            <ref source="BID" patch="1" url="http://www.securityfocus.com/bid/9636" adv="1">9636</ref>
            <ref source="BUGTRAQ" patch="1" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107644835523678&amp;w=2" adv="1">20040210 iDEFENSESecurityAdvisory02.10.04: XFree86FontInformationFileBufferOverflow</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/15130" adv="1">xfree86-fontalias-bo(15130)</ref>
            <ref source="CONFIRM" url="http://www.xfree86.org/cvs/changes" adv="1">http://www.xfree86.org/cvs/changes</ref>
            <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2004-061.html">RHSA-2004:061</ref>
            <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2004-060.html">RHSA-2004:060</ref>
            <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2004-059.html">RHSA-2004:059</ref>
            <ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2004_06_xf86.html">SuSE-SA:2004:006</ref>
            <ref source="MISC" url="http://www.idefense.com/application/poi/display?id=72">http://www.idefense.com/application/poi/display?id=72</ref>
            <ref source="DEBIAN" url="http://www.debian.org/security/2004/dsa-443">DSA-443</ref>
            <ref source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200402-02.xml" adv="1">GLSA-200402-02</ref>
            <ref source="SLACKWARE" url="http://www.slackware.com/security/viewer.php?l=slackware-security&amp;y=2004&amp;m=slackware-security.405053">SSA:2004-043</ref>
            <ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2004:012">MDKSA-2004:012</ref>
            <ref source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-57768-1">57768</ref>
            <ref source="FEDORA" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110979666528890&amp;w=2">FLSA:2314</ref>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107653324115914&amp;w=2">20040211 XFree86 vulnerability exploit</ref>
            <ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000821">CLA-2004:821</ref>
            <ref source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:830" sig="1">oval:org.mitre.oval:def:830</ref>
            <ref source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:806" sig="1">oval:org.mitre.oval:def:806</ref>
        </refs>
        <vuln_soft>
            <prod vendor="xfree86_project" name="x11r6">
                <vers num="4.1.0" />
                <vers num="4.1.11" />
                <vers num="4.1.12" />
                <vers num="4.2.0" />
                <vers edition="" num="4.2.1" />
                <vers edition=":errata" num="4.2.1" />
                <vers num="4.3.0" />
            </prod>
            <prod vendor="openbsd" name="openbsd">
                <vers num="3.3" />
                <vers num="3.4" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" name="CVE-2004-0084" seq="2004-0084" severity="High" type="CVE" published="2004-03-03" CVSS_version="2.0 incomplete approximation" CVSS_score="10.0" modified="2008-09-10">
        <desc>
            <descript source="cve">Buffer overflow in the ReadFontAlias function in XFree86 4.1.0 to 4.3.0, when using the CopyISOLatin1Lowered function, allows local or remote authenticated users to execute arbitrary code via a malformed entry in the font alias (font.alias) file, a different vulnerability than CVE-2004-0083 and CVE-2004-0106.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot admin="1" />
        </loss_types>
        <vuln_types>
            <input buffer="1" />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/667502">VU#667502</ref>
            <ref source="BID" patch="1" url="http://www.securityfocus.com/bid/9652" adv="1">9652</ref>
            <ref source="REDHAT" patch="1" url="http://www.redhat.com/support/errata/RHSA-2004-061.html" adv="1">RHSA-2004:061</ref>
            <ref source="REDHAT" patch="1" url="http://www.redhat.com/support/errata/RHSA-2004-060.html" adv="1">RHSA-2004:060</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/15200" adv="1">xfree86-copyisolatin1lLowered-bo(15200)</ref>
            <ref source="SLACKWARE" url="http://www.slackware.com/security/viewer.php?l=slackware-security&amp;y=2004&amp;m=slackware-security.405053">SSA:2004-043</ref>
            <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2004-059.html">RHSA-2004:059</ref>
            <ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2004_06_xf86.html">SuSE-SA:2004:006</ref>
            <ref source="MISC" url="http://www.idefense.com/application/poi/display?id=73">http://www.idefense.com/application/poi/display?id=73</ref>
            <ref source="DEBIAN" url="http://www.debian.org/security/2004/dsa-443">DSA-443</ref>
            <ref source="FEDORA" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110979666528890&amp;w=2">FLSA:2314</ref>
            <ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000821">CLA-2004:821</ref>
            <ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2004:012">MDKSA-2004:012</ref>
            <ref source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-57768-1">57768</ref>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107662833512775&amp;w=2">20040212 iDEFENSE Security Advisory 02.11.04: XFree86 Font Information File Buffer Overflow II</ref>
            <ref source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:831" sig="1">oval:org.mitre.oval:def:831</ref>
            <ref source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:807" sig="1">oval:org.mitre.oval:def:807</ref>
        </refs>
        <vuln_soft>
            <prod vendor="xfree86_project" name="x11r6">
                <vers num="4.1.0" />
                <vers num="4.1.11" />
                <vers num="4.1.12" />
                <vers num="4.2.0" />
                <vers edition="" num="4.2.1" />
                <vers edition=":errata" num="4.2.1" />
                <vers num="4.3.0" />
            </prod>
            <prod vendor="openbsd" name="openbsd">
                <vers num="3.3" />
                <vers num="3.4" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" name="CVE-2004-0085" seq="2004-0085" severity="Medium" type="CVE" published="2004-03-03" CVSS_version="2.0 incomplete approximation" CVSS_score="5.0" modified="2008-09-10">
        <desc>
            <descript source="cve">Unknown vulnerability in the Mail application for Mac OS X 10.1.5 and 10.2.8 with unknown impact, a different vulnerability than CVE-2004-0086.</descript>
        </desc>
        <loss_types>
            <conf />
        </loss_types>
        <vuln_types>
            <other />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="XF" patch="1" url="http://xforce.iss.net/xforce/xfdb/14992" adv="1">macosx-mail-undisclosed(14992)</ref>
            <ref source="BID" patch="1" url="http://www.securityfocus.com/bid/9504" adv="1">9504</ref>
            <ref source="APPLE" url="http://lists.apple.com/archives/security-announce/2004/Jan/msg00000.html">APPLE-SA-2004-01-26</ref>
        </refs>
        <vuln_soft>
            <prod vendor="apple" name="mac_os_x">
                <vers num="10.1.5" />
                <vers num="10.2.8" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" name="CVE-2004-0086" seq="2004-0086" severity="Medium" type="CVE" published="2004-03-03" CVSS_version="2.0 incomplete approximation" CVSS_score="5.0" modified="2008-09-10">
        <desc>
            <descript source="cve">Unknown vulnerability in the Mail application for Mac OS X 10.3.2 has unknown impact and attack vectors, a different vulnerability than CVE-2004-0085.</descript>
        </desc>
        <loss_types>
            <conf />
        </loss_types>
        <vuln_types>
            <other />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="BID" url="http://www.securityfocus.com/bid/9504">9504</ref>
            <ref source="APPLE" url="http://lists.apple.com/archives/security-announce/2004/Jan/msg00000.html">APPLE-SA-2004-01-26</ref>
        </refs>
        <vuln_soft>
            <prod vendor="apple" name="mac_os_x">
                <vers num="10.3.2" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" name="CVE-2004-0087" seq="2004-0087" severity="Low" type="CVE" published="2004-03-03" CVSS_version="2.0 incomplete approximation" CVSS_score="2.1" modified="2008-09-10">
        <desc>
            <descript source="cve">The System Configuration subsystem in Mac OS 10.2.8 and 10.3.2 allows local users to modify network settings, a different vulnerability than CVE-2004-0088.</descript>
        </desc>
        <loss_types>
            <int />
        </loss_types>
        <vuln_types>
            <config />
        </vuln_types>
        <range>
            <local />
        </range>
        <refs>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/14997">macosx-configd-file-manipulation(14997)</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/9504">9504</ref>
            <ref source="OSVDB" url="http://www.osvdb.org/6819">6819</ref>
            <ref source="APPLE" url="http://lists.apple.com/archives/security-announce/2004/Jan/msg00000.html">APPLE-SA-2004-01-26</ref>
        </refs>
        <vuln_soft>
            <prod vendor="apple" name="mac_os_x">
                <vers num="10.2.8" />
                <vers num="10.3.2" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" name="CVE-2004-0088" seq="2004-0088" severity="Low" type="CVE" published="2004-03-03" CVSS_version="2.0 incomplete approximation" CVSS_score="2.1" modified="2008-09-10">
        <desc>
            <descript source="cve">The System Configuration subsystem in Mac OS 10.2.8 allows local users to modify network settings, a different vulnerability than CVE-2004-0087.</descript>
        </desc>
        <loss_types>
            <int />
        </loss_types>
        <vuln_types>
            <config />
        </vuln_types>
        <range>
            <local />
        </range>
        <refs>
            <ref source="BID" url="http://www.securityfocus.com/bid/9504">9504</ref>
            <ref source="OSVDB" url="http://www.osvdb.org/6820">6820</ref>
            <ref source="APPLE" url="http://lists.apple.com/archives/security-announce/2004/Jan/msg00000.html">APPLE-SA-2004-01-26</ref>
        </refs>
        <vuln_soft>
            <prod vendor="apple" name="mac_os_x">
                <vers num="10.2.8" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" name="CVE-2004-0089" seq="2004-0089" severity="Medium" type="CVE" published="2004-03-03" CVSS_version="2.0 incomplete approximation" CVSS_score="4.6" modified="2008-09-10">
        <desc>
            <descript source="cve">Buffer overflow in TruBlueEnvironment in Mac OS X 10.3.x and 10.2.x allows local users to gain privileges via a long environment variable.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot other="1" />
        </loss_types>
        <vuln_types>
            <input buffer="1" />
        </vuln_types>
        <range>
            <local />
        </range>
        <refs>
            <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/902374">VU#902374</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/9509" adv="1">9509</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/14968">macosx-trublue-environmentvariable-bo(14968)</ref>
            <ref source="OSVDB" url="http://www.osvdb.org/6821">6821</ref>
            <ref source="ATSTAKE" url="http://www.atstake.com/research/advisories/2004/a012704-1.txt">A012704-1</ref>
            <ref source="APPLE" url="http://lists.apple.com/archives/security-announce/2004/Jan/msg00000.html">APPLE-SA-2004-01-26</ref>
        </refs>
        <vuln_soft>
            <prod vendor="apple" name="mac_os_x">
                <vers num="10.2.8" />
                <vers num="10.3.9" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" name="CVE-2004-0039" seq="2004-0039" severity="High" type="CVE" published="2004-03-03" CVSS_version="2.0 incomplete approximation" CVSS_score="10.0" modified="2008-09-05">
        <desc>
            <descript source="cve">Multiple format string vulnerabilities in HTTP Application Intelligence (AI) component in Check Point Firewall-1 NG-AI R55 and R54, and Check Point Firewall-1 HTTP Security Server included with NG FP1, FP2, and FP3 allows remote attackers to execute arbitrary code via HTTP requests that cause format string specifiers to be used in an error message, as demonstrated using the scheme of a URI.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot admin="1" />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="CERT-VN" patch="1" url="http://www.kb.cert.org/vuls/id/790771" adv="1">VU#790771</ref>
            <ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA04-036A.html">TA04-036A</ref>
            <ref source="XF" patch="1" url="http://xforce.iss.net/xforce/xfdb/14149" adv="1">fw1-format-string(14149)</ref>
            <ref source="BID" patch="1" url="http://www.securityfocus.com/bid/9581" adv="1">9581</ref>
            <ref source="ISS" url="http://xforce.iss.net/xforce/alerts/id/162">20040204 Checkpoint Firewall-1 HTTP Parsing Format String Vulnerabilities</ref>
            <ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/o-072.shtml">O-072</ref>
            <ref source="CONFIRM" url="http://www.checkpoint.com/techsupport/alerts/security_server.html">http://www.checkpoint.com/techsupport/alerts/security_server.html</ref>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107604682227031&amp;w=2">20040205 Two checkpoint fw-1/vpn-1 vulns</ref>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107604682227031&amp;w=2" adv="1">20040205 Two checkpoint fw-1/vpn-1 vulns</ref>
        </refs>
        <vuln_soft>
            <prod vendor="checkpoint" name="firewall-1">
                <vers num="" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" name="CVE-2004-0040" seq="2004-0040" severity="High" type="CVE" published="2004-03-03" CVSS_version="2.0 incomplete approximation" CVSS_score="10.0" modified="2008-09-10">
        <desc>
            <descript source="cve">Stack-based buffer overflow in Check Point VPN-1 Server 4.1 through 4.1 SP6 and Check Point SecuRemote/SecureClient 4.1 through 4.1 build 4200 allows remote attackers to execute arbitrary code via an ISAKMP packet with a large Certificate Request packet.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot admin="1" />
        </loss_types>
        <vuln_types>
            <input buffer="1" />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="CERT-VN" patch="1" url="http://www.kb.cert.org/vuls/id/873334" adv="1">VU#873334</ref>
            <ref source="BID" patch="1" url="http://www.securityfocus.com/bid/9582" adv="1">9582</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/14150" adv="1">vpn1-ike-bo(14150)</ref>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107604682227031&amp;w=2" adv="1">20040205 Two checkpoint fw-1/vpn-1 vulns</ref>
            <ref source="ISS" url="http://xforce.iss.net/xforce/alerts/id/163">20040204 Checkpoint VPN-1/SecureClient ISAKMP Buffer Overflow</ref>
            <ref source="OSVDB" url="http://www.osvdb.org/4432">4432</ref>
            <ref source="OSVDB" url="http://www.osvdb.org/3821">3821</ref>
            <ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/o-073.shtml">O-073</ref>
        </refs>
        <vuln_soft>
            <prod vendor="checkpoint" name="firewall-1">
                <vers edition="sp1" num="4.1" />
                <vers edition="sp2" num="4.1" />
                <vers edition="sp3" num="4.1" />
                <vers edition="sp4" num="4.1" />
                <vers edition="sp5" num="4.1" />
                <vers edition="sp5a" num="4.1" />
                <vers num="next_generation_fp0" />
                <vers num="next_generation_fp1" />
            </prod>
            <prod vendor="checkpoint" name="vpn-1">
                <vers edition="sp5a" num="4.1" />
                <vers num="next_generation_fp0" />
                <vers num="next_generation_fp1" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" name="CVE-2004-0077" seq="2004-0077" severity="High" type="CVE" published="2004-03-03" CVSS_version="2.0 incomplete approximation" CVSS_score="7.2" modified="2008-09-05">
        <desc>
            <descript source="cve">The do_mremap function for the mremap system call in Linux 2.2 to 2.2.25, 2.4 to 2.4.24, and 2.6 to 2.6.2, does not properly check the return value from the do_munmap function when the maximum number of VMA descriptors is exceeded, which allows local users to gain root privileges, a different vulnerability than CAN-2003-0985.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot admin="1" />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <local />
        </range>
        <refs>
            <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/981222">VU#981222</ref>
            <ref source="BID" patch="1" url="http://www.securityfocus.com/bid/9686" adv="1">9686</ref>
            <ref source="DEBIAN" patch="1" url="http://www.debian.org/security/2004/dsa-439" adv="1">DSA-439</ref>
            <ref source="GENTOO" patch="1" url="http://security.gentoo.org/glsa/glsa-200403-02.xml" adv="1">GLSA-200403-02</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/15244" adv="1">linux-mremap-gain-privileges(15244)</ref>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107711762014175&amp;w=2" adv="1">20040218 Second critical mremap() bug found in all Linux kernels</ref>
            <ref source="MISC" url="http://isec.pl/vulnerabilities/isec-0014-mremap-unmap.txt">http://isec.pl/vulnerabilities/isec-0014-mremap-unmap.txt</ref>
            <ref source="SLACKWARE" url="http://www.slackware.com/security/viewer.php?l=slackware-security&amp;y=2004&amp;m=slackware-security.404734">SSA:2004-049</ref>
            <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2004-106.html">RHSA-2004:106</ref>
            <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2004-069.html">RHSA-2004:069</ref>
            <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2004-066.html">RHSA-2004:066</ref>
            <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2004-065.html">RHSA-2004:065</ref>
            <ref source="OSVDB" url="http://www.osvdb.org/3986">3986</ref>
            <ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2004_05_linux_kernel.html">SuSE-SA:2004:005</ref>
            <ref source="DEBIAN" url="http://www.debian.org/security/2004/dsa-514">DSA-514</ref>
            <ref source="DEBIAN" url="http://www.debian.org/security/2004/dsa-475">DSA-475</ref>
            <ref source="DEBIAN" url="http://www.debian.org/security/2004/dsa-470">DSA-470</ref>
            <ref source="DEBIAN" url="http://www.debian.org/security/2004/dsa-466">DSA-466</ref>
            <ref source="DEBIAN" url="http://www.debian.org/security/2004/dsa-456">DSA-456</ref>
            <ref source="DEBIAN" url="http://www.debian.org/security/2004/dsa-454">DSA-454</ref>
            <ref source="DEBIAN" url="http://www.debian.org/security/2004/dsa-453">DSA-453</ref>
            <ref source="DEBIAN" url="http://www.debian.org/security/2004/dsa-450">DSA-450</ref>
            <ref source="DEBIAN" url="http://www.debian.org/security/2004/dsa-444">DSA-444</ref>
            <ref source="DEBIAN" url="http://www.debian.org/security/2004/dsa-442">DSA-442</ref>
            <ref source="DEBIAN" url="http://www.debian.org/security/2004/dsa-441">DSA-441</ref>
            <ref source="DEBIAN" url="http://www.debian.org/security/2004/dsa-440">DSA-440</ref>
            <ref source="DEBIAN" url="http://www.debian.org/security/2004/dsa-438">DSA-438</ref>
            <ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/o-082.shtml">O-082</ref>
            <ref source="TRUSTIX" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107755871932680&amp;w=2">2004-0008</ref>
            <ref source="TRUSTIX" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107712137732553&amp;w=2">2004-0007</ref>
            <ref source="MANDRAKE" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2004:015">MDKSA-2004:015</ref>
            <ref source="FEDORA" url="http://fedoranews.org/updates/FEDORA-2004-079.shtml">FEDORA-2004-079</ref>
            <ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000820">CLA-2004:820</ref>
            <ref source="VULNWATCH" url="http://archives.neohapsis.com/archives/vulnwatch/2004-q1/0040.html">20040218 Second critical mremap() bug found in all Linux kernels</ref>
            <ref source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:837" sig="1">oval:org.mitre.oval:def:837</ref>
            <ref source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:825" sig="1">oval:org.mitre.oval:def:825</ref>
        </refs>
        <vuln_soft>
            <prod vendor="redhat" name="bigmem_kernel">
                <vers edition="" num="2.4.20-8" />
                <vers edition=":i686" num="2.4.20-8" />
            </prod>
            <prod vendor="redhat" name="kernel">
                <vers edition="" num="2.4.20-8" />
                <vers edition=":athlon" num="2.4.20-8" />
                <vers edition=":i686" num="2.4.20-8" />
                <vers edition=":i686_smp" num="2.4.20-8" />
                <vers edition=":i386" num="2.4.20-8" />
                <vers edition=":athlon_smp" num="2.4.20-8" />
            </prod>
            <prod vendor="redhat" name="kernel_doc">
                <vers edition="" num="2.4.20-8" />
                <vers edition=":i386" num="2.4.20-8" />
            </prod>
            <prod vendor="redhat" name="kernel_source">
                <vers edition="" num="2.4.20-8" />
                <vers edition=":i386_src" num="2.4.20-8" />
            </prod>
            <prod vendor="linux" name="linux_kernel">
                <vers num="2.2.0" />
                <vers num="2.2.1" />
                <vers num="2.2.10" />
                <vers num="2.2.11" />
                <vers num="2.2.12" />
                <vers num="2.2.13" />
                <vers num="2.2.14" />
                <vers edition="pre16" num="2.2.15" />
                <vers num="2.2.15_pre20" />
                <vers edition="pre6" num="2.2.16" />
                <vers num="2.2.17" />
                <vers num="2.2.18" />
                <vers num="2.2.19" />
                <vers num="2.2.2" />
                <vers num="2.2.20" />
                <vers num="2.2.21" />
                <vers num="2.2.22" />
                <vers num="2.2.23" />
                <vers num="2.2.24" />
                <vers num="2.2.3" />
                <vers num="2.2.4" />
                <vers num="2.2.5" />
                <vers num="2.2.6" />
                <vers num="2.2.7" />
                <vers num="2.2.8" />
                <vers num="2.2.9" />
                <vers edition="test1" num="2.4.0" />
                <vers edition="test10" num="2.4.0" />
                <vers edition="test11" num="2.4.0" />
                <vers edition="test12" num="2.4.0" />
                <vers edition="test2" num="2.4.0" />
                <vers edition="test3" num="2.4.0" />
                <vers edition="test4" num="2.4.0" />
                <vers edition="test5" num="2.4.0" />
                <vers edition="test6" num="2.4.0" />
                <vers edition="test7" num="2.4.0" />
                <vers edition="test8" num="2.4.0" />
                <vers edition="test9" num="2.4.0" />
                <vers num="2.4.1" />
                <vers num="2.4.10" />
                <vers num="2.4.11" />
                <vers num="2.4.12" />
                <vers num="2.4.13" />
                <vers num="2.4.14" />
                <vers num="2.4.15" />
                <vers num="2.4.16" />
                <vers num="2.4.17" />
                <vers edition="" num="2.4.18" />
                <vers edition=":x86" num="2.4.18" />
                <vers edition="pre1" num="2.4.18" />
                <vers edition="pre2" num="2.4.18" />
                <vers edition="pre3" num="2.4.18" />
                <vers edition="pre4" num="2.4.18" />
                <vers edition="pre5" num="2.4.18" />
                <vers edition="pre6" num="2.4.18" />
                <vers edition="pre7" num="2.4.18" />
                <vers edition="pre8" num="2.4.18" />
                <vers edition="pre1" num="2.4.19" />
                <vers edition="pre2" num="2.4.19" />
                <vers edition="pre3" num="2.4.19" />
                <vers edition="pre4" num="2.4.19" />
                <vers edition="pre5" num="2.4.19" />
                <vers edition="pre6" num="2.4.19" />
                <vers num="2.4.2" />
                <vers num="2.4.20" />
                <vers edition="pre1" num="2.4.21" />
                <vers edition="pre4" num="2.4.21" />
                <vers edition="pre7" num="2.4.21" />
                <vers num="2.4.22" />
                <vers edition="pre9" num="2.4.23" />
                <vers num="2.4.24" />
                <vers num="2.4.3" />
                <vers num="2.4.4" />
                <vers num="2.4.5" />
                <vers num="2.4.6" />
                <vers num="2.4.7" />
                <vers num="2.4.8" />
                <vers num="2.4.9" />
                <vers edition="test1" num="2.6.0" />
                <vers edition="test10" num="2.6.0" />
                <vers edition="test11" num="2.6.0" />
                <vers edition="test2" num="2.6.0" />
                <vers edition="test3" num="2.6.0" />
                <vers edition="test4" num="2.6.0" />
                <vers edition="test5" num="2.6.0" />
                <vers edition="test6" num="2.6.0" />
                <vers edition="test7" num="2.6.0" />
                <vers edition="test8" num="2.6.0" />
                <vers edition="test9" num="2.6.0" />
                <vers edition="rc1" num="2.6.1" />
                <vers edition="rc2" num="2.6.1" />
                <vers num="2.6.2" />
                <vers num="2.6_test9_cvs" />
            </prod>
            <prod vendor="netwosix" name="netwosix_linux">
                <vers num="1.0" />
            </prod>
            <prod vendor="trustix" name="secure_linux">
                <vers num="1.5" />
                <vers num="2.0" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" name="CVE-2004-0078" seq="2004-0078" severity="High" type="CVE" published="2004-03-03" CVSS_version="2.0 incomplete approximation" CVSS_score="7.5" modified="2008-09-10">
        <desc>
            <descript source="cve">Buffer overflow in the index menu code (menu_pad_string of menu.c) for Mutt 1.4.1 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via certain mail messages.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot user="1" />
        </loss_types>
        <vuln_types>
            <input buffer="1" />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="BID" patch="1" url="http://www.securityfocus.com/bid/9641" adv="1">9641</ref>
            <ref source="REDHAT" patch="1" url="http://www.redhat.com/support/errata/RHSA-2004-051.html" adv="1">RHSA-2004:051</ref>
            <ref source="REDHAT" patch="1" url="http://www.redhat.com/support/errata/RHSA-2004-050.html" adv="1">RHSA-2004:050</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/15134" adv="1">mutt-index-menu-bo(15134)</ref>
            <ref source="CONFIRM" url="http://bugs.debian.org/126336">http://bugs.debian.org/126336</ref>
            <ref source="SLACKWARE" url="http://www.slackware.com/security/viewer.php?l=slackware-security&amp;y=2004&amp;m=slackware-security.405053">SSA:2004-043</ref>
            <ref source="OSVDB" url="http://www.osvdb.org/3918">3918</ref>
            <ref source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2004:010">MDKSA-2004:010</ref>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107884956930903&amp;w=2">20040309 [OpenPKG-SA-2004.005] OpenPKG Security Advisory (mutt)</ref>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107696262905039&amp;w=2">20040215 LNSA-#2004-0001: mutt remote crash</ref>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107651677817933&amp;w=2">20040211 Mutt-1.4.2 fixes buffer overflow.</ref>
            <ref source="CALDERA" url="ftp://ftp.caldera.com/pub/security/OpenLinux/CSSA-2004-013.0.txt">CSSA-2004-013.0</ref>
            <ref source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:838" sig="1">oval:org.mitre.oval:def:838</ref>
            <ref source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:811" sig="1">oval:org.mitre.oval:def:811</ref>
        </refs>
        <vuln_soft>
            <prod vendor="mutt" name="mutt">
                <vers num="1.2.1" />
                <vers num="1.2.5" />
                <vers num="1.2.5.1" />
                <vers num="1.2.5.12" />
                <vers num="1.2.5.12_ol" />
                <vers num="1.2.5.4" />
                <vers num="1.2.5.5" />
                <vers num="1.3.12" />
                <vers num="1.3.12.1" />
                <vers num="1.3.16" />
                <vers num="1.3.17" />
                <vers num="1.3.22" />
                <vers num="1.3.24" />
                <vers num="1.3.25" />
                <vers num="1.3.27" />
                <vers num="1.3.28" />
                <vers num="1.4.0" />
                <vers num="1.4.1" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" name="CVE-2004-0047" seq="2004-0047" severity="Medium" type="CVE" published="2004-03-03" CVSS_version="2.0 incomplete approximation" CVSS_score="4.6" modified="2008-09-05">
        <desc>
            <descript source="cve">Multiple programs in trr19 1.0 do not properly drop privileges before executing a system command, which could allow local users to gain privileges.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot other="1" />
        </loss_types>
        <vuln_types>
            <design />
        </vuln_types>
        <range>
            <local />
        </range>
        <refs>
            <ref source="DEBIAN" patch="1" url="http://www.debian.org/security/2004/dsa-430" adv="1">DSA-430</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/14975">trr19-gain-privileges(14975)</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/9520" adv="1">9520</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/10744/">10744</ref>
            <ref source="SECTRACK" url="http://www.securitytracker.com/id?1008875">1008875</ref>
            <ref source="OSVDB" url="http://www.osvdb.org/3747">3747</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/10745">10745</ref>
        </refs>
        <vuln_soft>
            <prod vendor="yamamoto_hirotaka" name="trr19">
                <vers num="1.0" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" name="CVE-2004-0005" seq="2004-0005" severity="High" type="CVE" published="2004-03-03" CVSS_version="2.0 incomplete approximation" CVSS_score="7.5" modified="2008-09-05">
        <desc>
            <descript source="cve">Multiple buffer overflows in Gaim 0.75 allow remote attackers to cause a denial of service and possibly execute arbitrary code via (1) octal encoding in yahoo_decode that causes a null byte to be written beyond the buffer, (2) octal encoding in yahoo_decode that causes a pointer to reference memory beyond the terminating null byte, (3) a quoted printable string to the gaim_quotedp_decode MIME decoder that causes a null byte to be written beyond the buffer, and (4) quoted printable encoding in gaim_quotedp_decode that causes a pointer to reference memory beyond the terminating null byte.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot other="1" />
        </loss_types>
        <vuln_types>
            <input buffer="1" />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/655974">VU#655974</ref>
            <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/404470">VU#404470</ref>
            <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/226974">VU#226974</ref>
            <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/190366">VU#190366</ref>
            <ref source="DEBIAN" patch="1" url="http://www.debian.org/security/2004/dsa-434" adv="1">DSA-434</ref>
            <ref source="MISC" patch="1" url="http://security.e-matters.de/advisories/012004.html" adv="1">http://security.e-matters.de/advisories/012004.html</ref>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107513690306318&amp;w=2" adv="1">20040126 Advisory 01/2004: 12 x Gaim remote overflows</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/14944">gaim-mime-decoder-oob(14944)</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/14942">gaim-mime-decoder-bo(14942)</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/14938">gaim-sscanf-oob(14938)</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/14935">gaim-yahoodecode-offbyone-bo(14935)</ref>
            <ref source="SLACKWARE" url="http://www.slackware.com/security/viewer.php?l=slackware-security&amp;y=2004&amp;m=slackware-security.361158">SSA:2004-026</ref>
            <ref source="SECTRACK" url="http://www.securitytracker.com/id?1008850">1008850</ref>
            <ref source="OSVDB" url="http://www.osvdb.org/3736">3736</ref>
            <ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2004_04_gaim.html">SuSE-SA:2004:004</ref>
            <ref source="GENTOO" url="http://www.linuxsecurity.com/content/view/105690/104/">GLSA-200401-04</ref>
            <ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000813">CLA-2004:813</ref>
            <ref source="FULLDISC" url="http://archives.neohapsis.com/archives/fulldisclosure/2004-01/0994.html">20040126 Advisory 01/2004: 12 x Gaim remote overflows</ref>
        </refs>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" name="CVE-2004-0006" seq="2004-0006" severity="High" type="CVE" published="2004-03-03" CVSS_version="2.0 incomplete approximation" CVSS_score="7.5" modified="2008-09-10">
        <desc>
            <descript source="cve">Multiple buffer overflows in Gaim 0.75 and earlier, and Ultramagnetic before 0.81, allow remote attackers to cause a denial of service and possibly execute arbitrary code via (1) cookies in a Yahoo web connection, (2) a long name parameter in the Yahoo login web page, (3) a long value parameter in the Yahoo login page, (4) a YMSG packet, (5) the URL parser, and (6) HTTP proxy connect.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot other="1" />
        </loss_types>
        <vuln_types>
            <input buffer="1" />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/871838">VU#871838</ref>
            <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/527142">VU#527142</ref>
            <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/503030">VU#503030</ref>
            <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/444158">VU#444158</ref>
            <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/371382">VU#371382</ref>
            <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/297198">VU#297198</ref>
            <ref source="REDHAT" patch="1" url="http://www.redhat.com/support/errata/RHSA-2004-032.html" adv="1">RHSA-2004:032</ref>
            <ref source="CONFIRM" patch="1" url="http://ultramagnetic.sourceforge.net/advisories/001.html" adv="1">http://ultramagnetic.sourceforge.net/advisories/001.html</ref>
            <ref source="MISC" patch="1" url="http://security.e-matters.de/advisories/012004.html" adv="1">http://security.e-matters.de/advisories/012004.html</ref>
            <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2004-045.html">RHSA-2004:045</ref>
            <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2004-033.html">RHSA-2004:033</ref>
            <ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2004_04_gaim.html">SuSE-SA:2004:004</ref>
            <ref source="DEBIAN" url="http://www.debian.org/security/2004/dsa-434">DSA-434</ref>
            <ref source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200401-04.xml" adv="1">GLSA-200401-04</ref>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107513690306318&amp;w=2" adv="1">20040126 Advisory 01/2004: 12 x Gaim remote overflows</ref>
            <ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/20040201-01-U.asc">20040201-01-U</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/14947">gaim-http-proxy-bo(14947)</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/14945">gaim-urlparser-bo(14945)</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/14943">gaim-yahoopacketread-keyname-bo(14943)</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/14941">gaim-login-value-bo(14941)</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/14940">gaim-login-name-bo(14940)</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/14939">gaim-yahoowebpending-cookie-bo(14939)</ref>
            <ref source="SLACKWARE" url="http://www.slackware.com/security/viewer.php?l=slackware-security&amp;y=2004&amp;m=slackware-security.361158">SSA:2004-026</ref>
            <ref source="SECTRACK" url="http://www.securitytracker.com/id?1008850">1008850</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/9489">9489</ref>
            <ref source="OSVDB" url="http://www.osvdb.org/3732">3732</ref>
            <ref source="OSVDB" url="http://www.osvdb.org/3731">3731</ref>
            <ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2004:006">MDKSA-2004:006</ref>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107522432613022&amp;w=2">20040127 Ultramagnetic Advisory #001:  Multiple vulnerabilities in Gaim code</ref>
            <ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000813">CLA-2004:813</ref>
            <ref source="FULLDISC" url="http://archives.neohapsis.com/archives/fulldisclosure/2004-01/0994.html">20040126 Advisory 01/2004: 12 x Gaim remote overflows</ref>
            <ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/20040202-01-U.asc">20040202-01-U</ref>
            <ref source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:818" sig="1">oval:org.mitre.oval:def:818</ref>
        </refs>
        <vuln_soft>
            <prod vendor="rob_flynn" name="gaim">
                <vers num="0.75" prev="1" />
            </prod>
            <prod vendor="ultramagnetic" name="ultramagnetic">
                <vers num="0.81" prev="1" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" name="CVE-2004-0007" seq="2004-0007" severity="High" type="CVE" published="2004-03-03" CVSS_version="2.0 incomplete approximation" CVSS_score="7.5" modified="2008-09-10">
        <desc>
            <descript source="cve">Buffer overflow in the Extract Info Field Function for (1) MSN and (2) YMSG protocol handlers in Gaim 0.74 and earlier, and Ultramagnetic before 0.81, allows remote attackers to cause a denial of service and possibly execute arbitrary code.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot other="1" />
        </loss_types>
        <vuln_types>
            <input buffer="1" />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/197142">VU#197142</ref>
            <ref source="REDHAT" patch="1" url="http://www.redhat.com/support/errata/RHSA-2004-033.html" adv="1">RHSA-2004:033</ref>
            <ref source="DEBIAN" patch="1" url="http://www.debian.org/security/2004/dsa-434" adv="1">DSA-434</ref>
            <ref source="CONFIRM" patch="1" url="http://ultramagnetic.sourceforge.net/advisories/001.html" adv="1">http://ultramagnetic.sourceforge.net/advisories/001.html</ref>
            <ref source="MISC" patch="1" url="http://security.e-matters.de/advisories/012004.html" adv="1">http://security.e-matters.de/advisories/012004.html</ref>
            <ref source="BUGTRAQ" patch="1" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107522432613022&amp;w=2" adv="1">20040127 Ultramagnetic Advisory #001:  Multiple vulnerabilities in Gaim code</ref>
            <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2004-032.html">RHSA-2004:032</ref>
            <ref source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200401-04.xml">GLSA-200401-04</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/14946">gaim-extractinfo-bo(14946)</ref>
            <ref source="SLACKWARE" url="http://www.slackware.com/security/viewer.php?l=slackware-security&amp;y=2004&amp;m=slackware-security.361158">SSA:2004-026</ref>
            <ref source="SECTRACK" url="http://www.securitytracker.com/id?1008850">1008850</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/9489">9489</ref>
            <ref source="SUSE" url="http://www.securityfocus.com/advisories/6281">SuSE-SA:2004:004</ref>
            <ref source="OSVDB" url="http://www.osvdb.org/3733">3733</ref>
            <ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2004:006">MDKSA-2004:006</ref>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107513690306318&amp;w=2">20040126 Advisory 01/2004: 12 x Gaim remote overflows</ref>
            <ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000813">CLA-2004:813</ref>
            <ref source="FULLDISC" url="http://archives.neohapsis.com/archives/fulldisclosure/2004-01/0994.html">20040126 Advisory 01/2004: 12 x Gaim remote overflows</ref>
            <ref source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:819" sig="1">oval:org.mitre.oval:def:819</ref>
        </refs>
        <vuln_soft>
            <prod vendor="rob_flynn" name="gaim">
                <vers num="0.74" prev="1" />
            </prod>
            <prod vendor="ultramagnetic" name="ultramagnetic">
                <vers num="0.81" prev="1" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" name="CVE-2004-0008" seq="2004-0008" severity="High" type="CVE" published="2004-03-03" CVSS_version="2.0 incomplete approximation" CVSS_score="7.5" modified="2008-09-10">
        <desc>
            <descript source="cve">Integer overflow in Gaim 0.74 and earlier, and Ultramagnetic before 0.81, allows remote attackers to cause a denial of service and possibly execute arbitrary code via a directIM packet that triggers a heap-based buffer overflow.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot other="1" />
        </loss_types>
        <vuln_types>
            <input buffer="1" />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/779614" adv="1">VU#779614</ref>
            <ref source="REDHAT" patch="1" url="http://www.redhat.com/support/errata/RHSA-2004-032.html" adv="1">RHSA-2004:032</ref>
            <ref source="CONFIRM" patch="1" url="http://ultramagnetic.sourceforge.net/advisories/001.html" adv="1">http://ultramagnetic.sourceforge.net/advisories/001.html</ref>
            <ref source="MISC" patch="1" url="http://security.e-matters.de/advisories/012004.html" adv="1">http://security.e-matters.de/advisories/012004.html</ref>
            <ref source="BUGTRAQ" patch="1" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107522432613022&amp;w=2" adv="1">20040127 Ultramagnetic Advisory #001:  Multiple vulnerabilities in Gaim code</ref>
            <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2004-045.html">RHSA-2004:045</ref>
            <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2004-033.html">RHSA-2004:033</ref>
            <ref source="DEBIAN" url="http://www.debian.org/security/2004/dsa-434">DSA-434</ref>
            <ref source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200401-04.xml">GLSA-200401-04</ref>
            <ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/20040201-01-U.asc">20040201-01-U</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/14937">gaim-directim-bo(14937)</ref>
            <ref source="SECTRACK" url="http://www.securitytracker.com/id?1008850">1008850</ref>
            <ref source="OSVDB" url="http://www.osvdb.org/3734">3734</ref>
            <ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2004:006">MDKSA-2004:006</ref>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107522338611564&amp;w=2">20040127 [slackware-security]  GAIM security update (SSA:2004-026-01)</ref>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107513690306318&amp;w=2">20040126 Advisory 01/2004: 12 x Gaim remote overflows</ref>
            <ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000813">CLA-2004:813</ref>
            <ref source="FULLDISC" url="http://archives.neohapsis.com/archives/fulldisclosure/2004-01/0994.html">20040126 Advisory 01/2004: 12 x Gaim remote overflows</ref>
            <ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/20040202-01-U.asc">20040202-01-U</ref>
            <ref source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:820" sig="1">oval:org.mitre.oval:def:820</ref>
        </refs>
        <vuln_soft>
            <prod vendor="rob_flynn" name="gaim">
                <vers num="0.74" prev="1" />
            </prod>
            <prod vendor="ultramagnetic" name="ultramagnetic">
                <vers num="0.81" prev="1" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" name="CVE-2004-0009" seq="2004-0009" severity="High" type="CVE" published="2004-03-03" CVSS_version="2.0 incomplete approximation" CVSS_score="7.5" modified="2008-09-05">
        <desc>
            <descript source="cve">Apache-SSL 1.3.28+1.52 and earlier, with SSLVerifyClient set to 1 or 3 and SSLFakeBasicAuth enabled, allows remote attackers to forge a client certificate by using basic authentication with the "one-line DN" of the target user.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot other="1" />
        </loss_types>
        <vuln_types>
            <design />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="BUGTRAQ" patch="1" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107619127531765&amp;w=2" adv="1">20040206 Apache-SSL security advisory - apache_1.3.28+ssl_1.52 and prior</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/15065" adv="1">apachessl-default-password(15065)</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/9590" adv="1">9590</ref>
            <ref source="CONFIRM" url="http://www.apache-ssl.org/advisory-20040206.txt">http://www.apache-ssl.org/advisory-20040206.txt</ref>
            <ref source="OSVDB" url="http://www.osvdb.org/3877">3877</ref>
            <ref source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2004-February/016870.html">20040206 [apache-ssl] Apache-SSL security advisory - apache_1.3.28+ssl_1.52 and prior</ref>
        </refs>
        <vuln_soft>
            <prod vendor="apache-ssl" name="apache-ssl">
                <vers num="1.3.28_1.52" prev="1" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" name="CVE-2004-0010" seq="2004-0010" severity="High" type="CVE" published="2004-03-03" CVSS_version="2.0 incomplete approximation" CVSS_score="7.2" modified="2008-09-10">
        <desc>
            <descript source="cve">Stack-based buffer overflow in the ncp_lookup function for ncpfs in Linux kernel 2.4.x allows local users to gain privileges.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot admin="1" />
        </loss_types>
        <vuln_types>
            <input buffer="1" />
        </vuln_types>
        <range>
            <local />
        </range>
        <refs>
            <ref source="BID" patch="1" url="http://www.securityfocus.com/bid/9691" adv="1">9691</ref>
            <ref source="REDHAT" patch="1" url="http://www.redhat.com/support/errata/RHSA-2004-069.html" adv="1">RHSA-2004:069</ref>
            <ref source="DEBIAN" patch="1" url="http://www.debian.org/security/2004/dsa-479" adv="1">DSA-479</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/15250" adv="1">linux-ncplookup-gain-privileges(15250)</ref>
            <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2004-188.html">RHSA-2004:188</ref>
            <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2004-065.html">RHSA-2004:065</ref>
            <ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2004_05_linux_kernel.html">SuSE-SA:2004:005</ref>
            <ref source="DEBIAN" url="http://www.debian.org/security/2004/dsa-495">DSA-495</ref>
            <ref source="DEBIAN" url="http://www.debian.org/security/2004/dsa-491">DSA-491</ref>
            <ref source="DEBIAN" url="http://www.debian.org/security/2004/dsa-489">DSA-489</ref>
            <ref source="DEBIAN" url="http://www.debian.org/security/2004/dsa-482">DSA-482</ref>
            <ref source="DEBIAN" url="http://www.debian.org/security/2004/dsa-481">DSA-481</ref>
            <ref source="DEBIAN" url="http://www.debian.org/security/2004/dsa-480">DSA-480</ref>
            <ref source="TURBO" url="http://www.securityfocus.com/advisories/6759">TLSA-2004-05</ref>
            <ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2004:015">MDKSA-2004:015</ref>
            <ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/o-082.shtml">O-082</ref>
            <ref source="FEDORA" url="http://fedoranews.org/updates/FEDORA-2004-079.shtml">FEDORA-2004-079</ref>
            <ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000820">CLA-2004:820</ref>
            <ref source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:835" sig="1">oval:org.mitre.oval:def:835</ref>
            <ref source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1035" sig="1">oval:org.mitre.oval:def:1035</ref>
        </refs>
        <vuln_soft>
            <prod vendor="linux" name="linux_kernel">
                <vers edition="test1" num="2.4.0" />
                <vers edition="test10" num="2.4.0" />
                <vers edition="test11" num="2.4.0" />
                <vers edition="test12" num="2.4.0" />
                <vers edition="test2" num="2.4.0" />
                <vers edition="test3" num="2.4.0" />
                <vers edition="test4" num="2.4.0" />
                <vers edition="test5" num="2.4.0" />
                <vers edition="test6" num="2.4.0" />
                <vers edition="test7" num="2.4.0" />
                <vers edition="test8" num="2.4.0" />
                <vers edition="test9" num="2.4.0" />
                <vers num="2.4.1" />
                <vers num="2.4.10" />
                <vers num="2.4.11" />
                <vers num="2.4.12" />
                <vers num="2.4.13" />
                <vers num="2.4.14" />
                <vers num="2.4.15" />
                <vers num="2.4.16" />
                <vers num="2.4.17" />
                <vers edition="" num="2.4.18" />
                <vers edition=":x86" num="2.4.18" />
                <vers edition="pre1" num="2.4.18" />
                <vers edition="pre2" num="2.4.18" />
                <vers edition="pre3" num="2.4.18" />
                <vers edition="pre4" num="2.4.18" />
                <vers edition="pre5" num="2.4.18" />
                <vers edition="pre6" num="2.4.18" />
                <vers edition="pre7" num="2.4.18" />
                <vers edition="pre8" num="2.4.18" />
                <vers edition="pre1" num="2.4.19" />
                <vers edition="pre2" num="2.4.19" />
                <vers edition="pre3" num="2.4.19" />
                <vers edition="pre4" num="2.4.19" />
                <vers edition="pre5" num="2.4.19" />
                <vers edition="pre6" num="2.4.19" />
                <vers num="2.4.2" />
                <vers num="2.4.20" />
                <vers edition="pre1" num="2.4.21" />
                <vers edition="pre4" num="2.4.21" />
                <vers edition="pre7" num="2.4.21" />
                <vers num="2.4.22" />
                <vers edition="pre9" num="2.4.23" />
                <vers num="2.4.24" />
                <vers num="2.4.3" />
                <vers num="2.4.4" />
                <vers num="2.4.5" />
                <vers num="2.4.6" />
                <vers num="2.4.7" />
                <vers num="2.4.8" />
                <vers num="2.4.9" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" name="CVE-2004-0002" seq="2004-0002" severity="High" type="CVE" published="2004-03-03" CVSS_version="2.0" CVSS_score="10.0" modified="2008-09-10">
        <desc>
            <descript source="cve">The TCP MSS (maximum segment size) functionality in netinet allows remote attackers to cause a denial of service (resource exhaustion) via (1) a low MTU, which causes a large number of small packets to be produced, or (2) via a large number of packets with a small TCP payload, which cause a large number of calls to the resource-intensive sowakeup function.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
        </loss_types>
        <vuln_types>
            <exception />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="CONFIRM" patch="1" url="http://lists.freebsd.org/pipermail/cvs-src/2004-January/016271.html" adv="1">http://lists.freebsd.org/pipermail/cvs-src/2004-January/016271.html</ref>
        </refs>
        <vuln_soft>
            <prod vendor="freebsd" name="freebsd">
                <vers edition="releng" num="3.0" />
                <vers num="3.1" />
                <vers num="3.2" />
                <vers num="3.3" />
                <vers num="3.4" />
                <vers edition="stable" num="3.5" />
                <vers edition="release" num="3.5.1" />
                <vers edition="stable" num="3.5.1" />
                <vers edition="alpha" num="4.0" />
                <vers edition="releng" num="4.0" />
                <vers num="4.1" />
                <vers edition="release" num="4.1.1" />
                <vers edition="stable" num="4.1.1" />
                <vers edition="stable" num="4.2" />
                <vers edition="release" num="4.3" />
                <vers edition="release_p38" num="4.3" />
                <vers edition="releng" num="4.3" />
                <vers edition="stable" num="4.3" />
                <vers edition="release_p42" num="4.4" />
                <vers edition="releng" num="4.4" />
                <vers edition="stable" num="4.4" />
                <vers edition="release" num="4.5" />
                <vers edition="release_p32" num="4.5" />
                <vers edition="releng" num="4.5" />
                <vers edition="stable" num="4.5" />
                <vers edition="release" num="4.6" />
                <vers edition="release_p20" num="4.6" />
                <vers edition="releng" num="4.6" />
                <vers edition="stable" num="4.6" />
                <vers num="4.6.2" />
                <vers edition="release" num="4.7" />
                <vers edition="release_p17" num="4.7" />
                <vers edition="releng" num="4.7" />
                <vers edition="stable" num="4.7" />
                <vers edition="pre-release" num="4.8" />
                <vers edition="release_p6" num="4.8" />
                <vers edition="releng" num="4.8" />
                <vers edition="pre-release" num="4.9" />
                <vers edition="alpha" num="5.0" />
                <vers edition="release_p14" num="5.0" />
                <vers edition="releng" num="5.0" />
                <vers edition="release_p5" num="5.1" />
                <vers edition="releng" num="5.1" />
                <vers num="5.2" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" name="CVE-2004-0003" seq="2004-0003" severity="Medium" type="CVE" published="2004-03-03" CVSS_version="2.0 incomplete approximation" CVSS_score="4.6" modified="2008-09-10">
        <desc>
            <descript source="cve">Unknown vulnerability in Linux kernel before 2.4.22 allows local users to gain privileges, related to "R128 DRI limits checking."</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot other="1" />
        </loss_types>
        <vuln_types>
            <input bound="1" />
        </vuln_types>
        <range>
            <local />
        </range>
        <refs>
            <ref source="REDHAT" patch="1" url="http://www.redhat.com/support/errata/RHSA-2004-044.html" adv="1">RHSA-2004:044</ref>
            <ref source="CONFIRM" patch="1" url="http://www.linuxcompatible.org/print25630.html" adv="1">http://www.linuxcompatible.org/print25630.html</ref>
            <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2004-065.html">RHSA-2004:065</ref>
            <ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2004_05_linux_kernel.html">SuSE-SA:2004:005</ref>
            <ref source="DEBIAN" url="http://www.debian.org/security/2004/dsa-495">DSA-495</ref>
            <ref source="DEBIAN" url="http://www.debian.org/security/2004/dsa-491">DSA-491</ref>
            <ref source="DEBIAN" url="http://www.debian.org/security/2004/dsa-489">DSA-489</ref>
            <ref source="DEBIAN" url="http://www.debian.org/security/2004/dsa-482">DSA-482</ref>
            <ref source="DEBIAN" url="http://www.debian.org/security/2004/dsa-481">DSA-481</ref>
            <ref source="DEBIAN" url="http://www.debian.org/security/2004/dsa-480">DSA-480</ref>
            <ref source="DEBIAN" url="http://www.debian.org/security/2004/dsa-479">DSA-479</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/15029">linux-r128-gain-priviliges(15029)</ref>
            <ref source="TURBO" url="http://www.turbolinux.com/security/2004/TLSA-2004-14.txt">TLSA-2004-14</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/9570">9570</ref>
            <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2004-166.html">RHSA-2004:166</ref>
            <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2004-106.html">RHSA-2004:106</ref>
            <ref source="MANDRAKE" url="http://www.mandrakesecure.net/en/advisories/advisory.php?name=MDKSA-2004:029">MDKSA-2004:029</ref>
            <ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/o-145.shtml">O-145</ref>
            <ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/o-127.shtml">O-127</ref>
            <ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/o-126.shtml">O-126</ref>
            <ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/o-121.shtml">O-121</ref>
            <ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/o-082.shtml">O-082</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/12075">12075</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/11891">11891</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/11464">11464</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/11376">11376</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/11370">11370</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/11369">11369</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/11362">11362</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/11361">11361</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/11202">11202</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/10912">10912</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/10911">10911</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/10782">10782</ref>
            <ref source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:834" sig="1">oval:org.mitre.oval:def:834</ref>
            <ref source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1017" sig="1">oval:org.mitre.oval:def:1017</ref>
        </refs>
        <vuln_soft>
            <prod vendor="linux" name="linux_kernel">
                <vers num="2.4.22" prev="1" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" name="CVE-2004-1990" seq="2004-1990" severity="Medium" type="CVE" published="2004-03-03" CVSS_version="2.0 incomplete approximation" CVSS_score="5.0" modified="2008-09-05">
        <desc>
            <descript source="cve">Aldo's Web Server (aweb) 1.5 allows remote attackers to gain sensitive information via an arbitrary character, which reveals the full path and the user running the aweb process, possibly due to a malformed request.</descript>
        </desc>
        <loss_types>
            <conf />
        </loss_types>
        <vuln_types>
            <input />
            <exception />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/16047" adv="1">aweb-path-disclosure(16047)</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/10262" adv="1">10262</ref>
            <ref source="MISC" url="http://www.oliverkarow.de/research/AldosWebserverMultipleVulns.txt" adv="1">http://www.oliverkarow.de/research/AldosWebserverMultipleVulns.txt</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/11542" adv="1">11542</ref>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108360629031227&amp;w=2" adv="1">20040503 Multible_Vulnerabilites_in_Aldos_Webserver</ref>
            <ref source="OSVDB" url="http://www.osvdb.org/5880">5880</ref>
        </refs>
        <vuln_soft>
            <prod vendor="aldo_vargas" name="aldos_web_server">
                <vers num="1.5" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" name="CVE-2004-1359" seq="2004-1359" severity="Medium" type="CVE" published="2004-03-04" CVSS_version="2.0 incomplete approximation" CVSS_score="4.6" modified="2008-09-10">
        <desc>
            <descript source="cve">Multiple buffer overflows in uucp for Sun Solaris 2.6, 7, 8, and 9 allow local users to execute arbitrary code as the uucp user.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot user="1" />
        </loss_types>
        <vuln_types>
            <input buffer="1" />
        </vuln_types>
        <range>
            <local />
        </range>
        <refs>
            <ref source="XF" patch="1" url="http://xforce.iss.net/xforce/xfdb/15425">solaris-uucp-multiple-bo(15425)</ref>
            <ref source="AUSCERT" patch="1" url="http://www.auscert.org.au/render.html?it=3935" adv="1">ESB-2004.0201</ref>
            <ref source="SUNALERT" patch="1" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-57508-1" adv="1">57508</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/9837">9837</ref>
            <ref source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1127" sig="1">oval:org.mitre.oval:def:1127</ref>
        </refs>
        <vuln_soft>
            <prod vendor="sun" name="solaris">
                <vers edition="" num="2.6" />
                <vers edition=":x86" num="2.6" />
                <vers edition="" num="7.0" />
                <vers edition=":x86" num="7.0" />
                <vers edition="" num="8.0" />
                <vers edition=":x86" num="8.0" />
                <vers edition="" num="9.0" />
                <vers edition=":x86" num="9.0" />
                <vers edition=":sparc" num="9.0" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" name="CVE-2004-1769" seq="2004-1769" severity="High" type="CVE" published="2004-03-11" CVSS_version="2.0 incomplete approximation" CVSS_score="10.0" modified="2008-09-05">
        <desc>
            <descript source="cve">The "Allow cPanel users to reset their password via email" feature in cPanel 9.1.0 build 34 and earlier, including 8.x, allows remote attackers to execute arbitrary code via the user parameter to resetpass.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot admin="1" />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/831534" adv="1">VU#831534</ref>
            <ref source="XF" patch="1" url="http://xforce.iss.net/xforce/xfdb/15443" adv="1">cpanel-resetpass-execute-commands(15443)</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/9848" adv="1">9848</ref>
            <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/357064/2004-03-08/2004-03-14/0" adv="1">20040311 Cpanel 8.*.* have a problem ?</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/11111" adv="1">11111</ref>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107904890724201&amp;w=2" adv="1">20040311 cPanel Secuirty Advisory CPANEL-2004:01-01</ref>
        </refs>
        <vuln_soft>
            <prod vendor="cpanel" name="cpanel">
                <vers num="5.0" />
                <vers num="5.3" />
                <vers num="6.0" />
                <vers num="6.2" />
                <vers num="6.4" />
                <vers num="6.4.1" />
                <vers num="6.4.2" />
                <vers num="6.4.2_stable_48" />
                <vers num="7.0" />
                <vers num="8.0" />
                <vers num="9.0" />
                <vers num="9.1" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" name="CVE-2004-1770" seq="2004-1770" severity="High" type="CVE" published="2004-03-11" CVSS_version="2.0 incomplete approximation" CVSS_score="10.0" modified="2008-09-05">
        <desc>
            <descript source="cve">The login page for cPanel 9.1.0, and possibly other versions, allows remote attackers to execute arbitrary code via shell metacharacters in the user parameter.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot admin="1" />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="CERT-VN" patch="1" url="http://www.kb.cert.org/vuls/id/831534" adv="1">VU#831534</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/15486" adv="1">cpanel-login-execute-commands(15486)</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/9855" adv="1">9855</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/11124" adv="1">11124</ref>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107911581732035&amp;w=2">20040312 Cpanel 9.1.0 have a problem ?</ref>
        </refs>
        <vuln_soft>
            <prod vendor="cpanel" name="cpanel">
                <vers num="5.0" />
                <vers num="5.3" />
                <vers num="6.0" />
                <vers num="6.2" />
                <vers num="6.4" />
                <vers num="6.4.1" />
                <vers num="6.4.2" />
                <vers num="6.4.2_stable_48" />
                <vers num="7.0" />
                <vers num="8.0" />
                <vers num="9.0" />
                <vers num="9.1" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" name="CVE-2004-1358" seq="2004-1358" severity="Medium" type="CVE" published="2004-03-12" CVSS_version="2.0 incomplete approximation" CVSS_score="5.0" modified="2008-09-10">
        <desc>
            <descript source="cve">The patches (1) 114332-08 and (2) 114929-06 for Sun Solaris 9 disable the auditing functionality of the Basic Security Module (BSM), which allows attackers to avoid having their activity logged.</descript>
        </desc>
        <loss_types>
            <int />
        </loss_types>
        <vuln_types>
            <design />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="XF" patch="1" url="http://xforce.iss.net/xforce/xfdb/14918">solaris-patches-disable-bsm(14918)</ref>
            <ref source="BID" patch="1" url="http://www.securityfocus.com/bid/9852">9852</ref>
            <ref source="CIAC" patch="1" url="http://www.ciac.org/ciac/bulletins/o-099.shtml" adv="1">O-099</ref>
            <ref source="AUSCERT" patch="1" url="http://www.auscert.org.au/render.html?it=3788" adv="1">ESB-2004.0069</ref>
            <ref source="SUNALERT" patch="1" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-57478-1&amp;searchclause=%22category:security%22%20%20114332-08" adv="1">57478</ref>
            <ref source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:3567" sig="1">oval:org.mitre.oval:def:3567</ref>
        </refs>
        <vuln_soft>
            <prod vendor="sun" name="solaris">
                <vers edition="" num="9.0" />
                <vers edition=":x86" num="9.0" />
                <vers edition=":sparc" num="9.0" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" name="CVE-2004-0075" seq="2004-0075" severity="Low" type="CVE" published="2004-03-15" CVSS_version="2.0 incomplete approximation" CVSS_score="2.1" modified="2008-09-05">
        <desc>
            <descript source="cve">The Vicam USB driver in Linux before 2.4.25 does not use the copy_from_user function when copying data from userspace to kernel space, which crosses security boundaries and allows local users to cause a denial of service.</descript>
        </desc>
        <loss_types>
            <avail />
        </loss_types>
        <vuln_types>
            <design />
        </vuln_types>
        <range>
            <local />
        </range>
        <refs>
            <ref source="BID" patch="1" url="http://www.securityfocus.com/bid/9690" adv="1">9690</ref>
            <ref source="REDHAT" patch="1" url="http://www.redhat.com/support/errata/RHSA-2004-065.html" adv="1">RHSA-2004:065</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/15246" adv="1">linux-vicam-dos(15246)</ref>
            <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-293.html">RHSA-2005:293</ref>
            <ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2004_05_linux_kernel.html">SuSE-SA:2004:005</ref>
            <ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/o-082.shtml">O-082</ref>
            <ref source="MANDRAKE" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2004:015">MDKSA-2004:015</ref>
            <ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000846">CLA-2004:846</ref>
            <ref source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:836" sig="1">oval:org.mitre.oval:def:836</ref>
        </refs>
        <vuln_soft>
            <prod vendor="linux" name="linux_kernel">
                <vers edition="test1" num="2.4.0" />
                <vers edition="test10" num="2.4.0" />
                <vers edition="test11" num="2.4.0" />
                <vers edition="test12" num="2.4.0" />
                <vers edition="test2" num="2.4.0" />
                <vers edition="test3" num="2.4.0" />
                <vers edition="test4" num="2.4.0" />
                <vers edition="test5" num="2.4.0" />
                <vers edition="test6" num="2.4.0" />
                <vers edition="test7" num="2.4.0" />
                <vers edition="test8" num="2.4.0" />
                <vers edition="test9" num="2.4.0" />
                <vers num="2.4.1" />
                <vers num="2.4.10" />
                <vers num="2.4.11" />
                <vers num="2.4.12" />
                <vers num="2.4.13" />
                <vers num="2.4.14" />
                <vers num="2.4.15" />
                <vers num="2.4.16" />
                <vers num="2.4.17" />
                <vers edition="" num="2.4.18" />
                <vers edition=":x86" num="2.4.18" />
                <vers edition="pre1" num="2.4.18" />
                <vers edition="pre2" num="2.4.18" />
                <vers edition="pre3" num="2.4.18" />
                <vers edition="pre4" num="2.4.18" />
                <vers edition="pre5" num="2.4.18" />
                <vers edition="pre6" num="2.4.18" />
                <vers edition="pre7" num="2.4.18" />
                <vers edition="pre8" num="2.4.18" />
                <vers edition="pre1" num="2.4.19" />
                <vers edition="pre2" num="2.4.19" />
                <vers edition="pre3" num="2.4.19" />
                <vers edition="pre4" num="2.4.19" />
                <vers edition="pre5" num="2.4.19" />
                <vers edition="pre6" num="2.4.19" />
                <vers num="2.4.2" />
                <vers num="2.4.20" />
                <vers edition="pre1" num="2.4.21" />
                <vers edition="pre4" num="2.4.21" />
                <vers edition="pre7" num="2.4.21" />
                <vers num="2.4.22" />
                <vers edition="pre9" num="2.4.23" />
                <vers num="2.4.23_ow2" />
                <vers num="2.4.24" />
                <vers num="2.4.24_ow1" />
                <vers num="2.4.3" />
                <vers num="2.4.4" />
                <vers num="2.4.5" />
                <vers num="2.4.6" />
                <vers num="2.4.7" />
                <vers num="2.4.8" />
                <vers num="2.4.9" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" name="CVE-2004-0165" seq="2004-0165" severity="Medium" type="CVE" published="2004-03-15" CVSS_version="2.0 incomplete approximation" CVSS_score="5.0" modified="2008-09-10">
        <desc>
            <descript source="cve">Format string vulnerability in Point-to-Point Protocol (PPP) daemon (pppd) 2.4.0 for Mac OS X 10.3.2 and earlier allows remote attackers to read arbitrary pppd process data, including PAP or CHAP authentication credentials, to gain privileges.</descript>
        </desc>
        <loss_types>
            <conf />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/841742" adv="1">VU#841742</ref>
            <ref source="BID" patch="1" url="http://www.securityfocus.com/bid/9730" adv="1">9730</ref>
            <ref source="ATSTAKE" patch="1" url="http://www.atstake.com/research/advisories/2004/a022304-1.txt" adv="1">A022304-1</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/15297" adv="1">macos-pppd-format-string(15297)</ref>
            <ref source="OSVDB" url="http://www.osvdb.org/6822">6822</ref>
            <ref source="APPLE" url="http://lists.apple.com/archives/security-announce/2004/Feb/msg00000.html">APPLE-SA-2004-02-23</ref>
        </refs>
        <vuln_soft>
            <prod vendor="apple" name="mac_os_x">
                <vers num="10.1" />
                <vers num="10.1.1" />
                <vers num="10.1.2" />
                <vers num="10.1.3" />
                <vers num="10.1.4" />
                <vers num="10.1.5" />
                <vers num="10.2" />
                <vers num="10.2.1" />
                <vers num="10.2.2" />
                <vers num="10.2.3" />
                <vers num="10.2.4" />
                <vers num="10.2.5" />
                <vers num="10.2.6" />
                <vers num="10.2.7" />
                <vers num="10.2.8" />
                <vers num="10.3" />
                <vers num="10.3.1" />
                <vers num="10.3.2" />
            </prod>
            <prod vendor="apple" name="mac_os_x_server">
                <vers num="10.1" />
                <vers num="10.1.1" />
                <vers num="10.1.2" />
                <vers num="10.1.3" />
                <vers num="10.1.4" />
                <vers num="10.1.5" />
                <vers num="10.2" />
                <vers num="10.2.1" />
                <vers num="10.2.2" />
                <vers num="10.2.3" />
                <vers num="10.2.4" />
                <vers num="10.2.5" />
                <vers num="10.2.6" />
                <vers num="10.2.7" />
                <vers num="10.2.8" />
                <vers num="10.3" />
                <vers num="10.3.1" />
                <vers num="10.3.2" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" name="CVE-2004-0166" seq="2004-0166" severity="Medium" type="CVE" published="2004-03-15" CVSS_version="2.0 incomplete approximation" CVSS_score="5.0" modified="2008-09-10">
        <desc>
            <descript source="cve">Unknown vulnerability in Safari web browser for Mac OS X 10.2.8 related to "the display of URLs in the status bar."</descript>
        </desc>
        <loss_types>
            <conf />
        </loss_types>
        <vuln_types>
            <other />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="CERT-VN" patch="1" url="http://www.kb.cert.org/vuls/id/194238" adv="1">VU#194238</ref>
            <ref source="XF" patch="1" url="http://xforce.iss.net/xforce/xfdb/14993" adv="1">macosx-safari-unknown(14993)</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/14993">macosx-safari-unknown(14993)</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/10959">10959</ref>
            <ref source="APPLE" url="http://lists.apple.com/archives/security-announce/2004/Feb/msg00000.html">APPLE-SA-2004-02-23</ref>
        </refs>
        <vuln_soft>
            <prod vendor="apple" name="mac_os_x">
                <vers num="10.2.8" />
            </prod>
            <prod vendor="apple" name="mac_os_x_server">
                <vers num="10.2.8" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" name="CVE-2004-0167" seq="2004-0167" severity="High" type="CVE" published="2004-03-15" CVSS_version="2.0 incomplete approximation" CVSS_score="7.5" modified="2008-09-10">
        <desc>
            <descript source="cve">DiskArbitration in Mac OS X 10.2.8 and 10.3.2 does not properly initialize writeable removable media.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot other="1" />
        </loss_types>
        <vuln_types>
            <other />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/578886">VU#578886</ref>
            <ref source="XF" patch="1" url="http://xforce.iss.net/xforce/xfdb/15300" adv="1">macos-diskarbitration-unknown(15300)</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/15300">macos-diskarbitration-unknown(15300)</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/9731">9731</ref>
            <ref source="OSVDB" url="http://www.osvdb.org/6824">6824</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/10959">10959</ref>
            <ref source="APPLE" url="http://lists.apple.com/archives/security-announce/2004/Feb/msg00000.html">APPLE-SA-2004-02-23</ref>
        </refs>
        <vuln_soft>
            <prod vendor="apple" name="mac_os_x">
                <vers num="10.2.8" prev="1" />
                <vers num="10.3.2" prev="1" />
            </prod>
            <prod vendor="apple" name="mac_os_x_server">
                <vers num="10.2.8" prev="1" />
                <vers num="10.3.2" prev="1" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" name="CVE-2004-0168" seq="2004-0168" severity="High" type="CVE" published="2004-03-15" CVSS_version="2.0 incomplete approximation" CVSS_score="10.0" modified="2008-09-10">
        <desc>
            <descript source="cve">Unknown vulnerability in CoreFoundation for Mac OS X 10.3.2, related to "notification logging."</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
        </loss_types>
        <vuln_types>
            <other />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="XF" patch="1" url="http://xforce.iss.net/xforce/xfdb/15299" adv="1">macos-corefoundation-unknown(15299)</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/15299">macos-corefoundation-unknown(15299)</ref>
            <ref source="APPLE" url="http://lists.apple.com/archives/security-announce/2004/Feb/msg00000.html">APPLE-SA-2004-02-23</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/10959/">10959</ref>
        </refs>
        <vuln_soft>
            <prod vendor="apple" name="mac_os_x">
                <vers num="10.2.8" prev="1" />
                <vers num="10.3.2" prev="1" />
            </prod>
            <prod vendor="apple" name="mac_os_x_server">
                <vers num="10.2.8" prev="1" />
                <vers num="10.3.2" prev="1" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" name="CVE-2004-0169" seq="2004-0169" severity="Medium" type="CVE" published="2004-03-15" CVSS_version="2.0 incomplete approximation" CVSS_score="5.0" modified="2008-09-10">
        <desc>
            <descript source="cve">QuickTime Streaming Server in MacOS X 10.2.8 and 10.3.2 allows remote attackers to cause a denial of service (crash) via DESCRIBE requests with long User-Agent fields, which causes an Assert error to be triggered in the BufferIsFull function.</descript>
        </desc>
        <loss_types>
            <avail />
        </loss_types>
        <vuln_types>
            <exception />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/460350" adv="1">VU#460350</ref>
            <ref source="BID" patch="1" url="http://www.securityfocus.com/bid/9735" adv="1">9735</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/15291" adv="1">darwin-describe-request-dos(15291)</ref>
            <ref source="OSVDB" url="http://www.osvdb.org/6837">6837</ref>
            <ref source="OSVDB" url="http://www.osvdb.org/6826">6826</ref>
            <ref source="IDEFENSE" url="http://www.idefense.com/application/poi/display?id=75&amp;type=vulnerabilities">20040223 Darwin Streaming Server Remote Denial of Service Vulnerability</ref>
            <ref source="APPLE" url="http://lists.apple.com/archives/security-announce/2004/Feb/msg00000.html">APPLE-SA-2004-02-23</ref>
        </refs>
        <vuln_soft>
            <prod vendor="apple" name="darwin_streaming_server">
                <vers num="4.1.3" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" name="CVE-2004-0171" seq="2004-0171" severity="Medium" type="CVE" published="2004-03-15" CVSS_version="2.0 incomplete approximation" CVSS_score="5.0" modified="2008-09-05">
        <desc>
            <descript source="cve">FreeBSD 5.1 and earlier, and Mac OS X before 10.3.4, allows remote attackers to cause a denial of service (resource exhaustion of memory buffers and system crash) via a large number of out-of-sequence TCP packets, which prevents the operating system from creating new connections.</descript>
        </desc>
        <loss_types>
            <avail />
        </loss_types>
        <vuln_types>
            <exception />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/395670">VU#395670</ref>
            <ref source="BID" patch="1" url="http://www.securityfocus.com/bid/9792" adv="1">9792</ref>
            <ref source="IDEFENSE" patch="1" url="http://www.idefense.com/application/poi/display?id=78&amp;type=vulnerabilities" adv="1">20040302 FreeBSD Memory Buffer Exhaustion Denial of Service Vulnerability</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/15369" adv="1">freebsd-mbuf-dos(15369)</ref>
            <ref source="OSVDB" url="http://www.osvdb.org/4124">4124</ref>
            <ref source="APPLE" url="http://lists.seifried.org/pipermail/security/2004-May/003743.html">APPLE-SA-2004-05-28</ref>
            <ref source="FREEBSD" url="ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-04:04.tcp.asc">FreeBSD-SA-04:04</ref>
        </refs>
        <vuln_soft>
            <prod vendor="freebsd" name="freebsd">
                <vers num="4.6.2" />
                <vers num="4.7" />
                <vers num="4.8" />
                <vers num="4.9" />
                <vers num="5.0" />
                <vers num="5.1" />
                <vers num="5.2" />
            </prod>
            <prod vendor="openbsd" name="openbsd">
                <vers num="3.3" />
                <vers num="3.4" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" name="CVE-2004-0172" seq="2004-0172" severity="High" type="CVE" published="2004-03-15" CVSS_version="2.0 incomplete approximation" CVSS_score="7.2" modified="2008-09-10">
        <desc>
            <descript source="cve">Heap-based buffer overflow in the search_for_command function of ltrace 0.3.10, if it is installed setuid, could allow local users to execute arbitrary code via a long filename.  NOTE: It is unclear whether there are any packages that install ltrace as a setuid program, so this candidate might be REJECTed.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot admin="1" />
        </loss_types>
        <vuln_types>
            <input bound="1" />
        </vuln_types>
        <range>
            <local />
        </range>
        <refs>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/13389" adv="1">ltrace-searchforcommand-bo(13389)</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/8790" adv="1">8790</ref>
            <ref source="SECTRACK" url="http://securitytracker.com/id?1007896">1007896</ref>
            <ref source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2003-October/011610.html">20031008 ltrace bug</ref>
            <ref source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2003-October/011600.html">20031008 ltrace bug</ref>
        </refs>
        <vuln_soft>
            <prod vendor="juan_cespedes" name="ltrace">
                <vers num="0.3.10" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" name="CVE-2004-0159" seq="2004-0159" severity="High" type="CVE" published="2004-03-15" CVSS_version="2.0 incomplete approximation" CVSS_score="7.5" modified="2008-09-10">
        <desc>
            <descript source="cve">Format string vulnerability in hsftp 1.11 allows remote authenticated users to cause a denial of service and possibly execute arbitrary code via file names containing format string characters that are not properly handled when executing an "ls" command.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot user="1" />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="BID" patch="1" url="http://www.securityfocus.com/bid/9715" adv="1">9715</ref>
            <ref source="DEBIAN" patch="1" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107755803218677&amp;w=2" adv="1">DSA-447</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/15276" adv="1">hsftp-format-string(15276)</ref>
            <ref source="OSVDB" url="http://www.osvdb.org/4029">4029</ref>
            <ref source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2004-February/017737.html">20040223 Re: [SECURITY] [DSA 447-1] New hsftp packages fix format string vulnerability</ref>
        </refs>
        <vuln_soft>
            <prod vendor="samhain_labs" name="hsftp">
                <vers num="1.10" />
                <vers num="1.11" />
                <vers num="1.4" />
                <vers num="1.5" />
                <vers num="1.6" />
                <vers num="1.7" />
                <vers num="1.9" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" name="CVE-2004-0185" seq="2004-0185" severity="High" type="CVE" published="2004-03-15" CVSS_version="2.0 incomplete approximation" CVSS_score="10.0" modified="2008-09-05">
        <desc>
            <descript source="cve">Buffer overflow in the skey_challenge function in ftpd.c for wu-ftp daemon (wu-ftpd) 2.6.2 allows remote attackers to cause a denial of service and possibly execute arbitrary code via a s/key (SKEY) request with a long name.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot admin="1" />
        </loss_types>
        <vuln_types>
            <input buffer="1" />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="MISC" patch="1" url="http://www.securiteam.com/unixfocus/6X00Q1P8KC.html" adv="1">http://www.securiteam.com/unixfocus/6X00Q1P8KC.html</ref>
            <ref source="REDHAT" patch="1" url="http://www.redhat.com/support/errata/RHSA-2004-096.html" adv="1">RHSA-2004:096</ref>
            <ref source="DEBIAN" patch="1" url="http://www.debian.org/security/2004/dsa-457" adv="1">DSA-457</ref>
            <ref source="CONFIRM" patch="1" url="ftp://ftp.wu-ftpd.org/pub/wu-ftpd/patches/apply_to_2.6.2/skeychallenge.patch">ftp://ftp.wu-ftpd.org/pub/wu-ftpd/patches/apply_to_2.6.2/skeychallenge.patch</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/13518" adv="1">wuftpd-skey-bo(13518)</ref>
            <ref source="MISC" url="http://unixpunx.org/txt/exploits_archive/packetstorm/0310-advisories/wuftpd-skey.txt">http://unixpunx.org/txt/exploits_archive/packetstorm/0310-advisories/wuftpd-skey.txt</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/8893">8893</ref>
        </refs>
        <vuln_soft>
            <prod vendor="washington_university" name="wu-ftpd">
                <vers num="2.6.2" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" name="CVE-2004-0186" seq="2004-0186" severity="High" type="CVE" published="2004-03-15" CVSS_version="2.0 incomplete approximation" CVSS_score="7.2" modified="2008-09-05">
        <desc>
            <descript source="cve">smbmnt in Samba 2.x and 3.x on Linux 2.6, when installed setuid, allows local users to gain root privileges by mounting a Samba share that contains a setuid root program, whose setuid attributes are not cleared when the share is mounted.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot admin="1" />
        </loss_types>
        <vuln_types>
            <access />
        </vuln_types>
        <range>
            <local />
        </range>
        <refs>
            <ref source="XF" patch="1" url="http://xforce.iss.net/xforce/xfdb/15131" adv="1">samba-smbmnt-gain-privileges(15131)</ref>
            <ref source="BID" patch="1" url="http://www.securityfocus.com/bid/9619" adv="1">9619</ref>
            <ref source="DEBIAN" patch="1" url="http://www.debian.org/security/2004/dsa-463" adv="1">DSA-463</ref>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107636290906296&amp;w=2">20040209 Samba 3.x + kernel 2.6.x local root vulnerability</ref>
            <ref source="OSVDB" url="http://www.osvdb.org/3916">3916</ref>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107657505718743&amp;w=2">20040211 Re: Samba 3.x + kernel 2.6.x local root vulnerability</ref>
        </refs>
        <vuln_soft>
            <prod vendor="samba" name="samba">
                <vers num="2.0" />
                <vers num="3.0.0" />
            </prod>
            <prod vendor="linux" name="linux_kernel">
                <vers edition="test1" num="2.6.0" />
                <vers edition="test10" num="2.6.0" />
                <vers edition="test11" num="2.6.0" />
                <vers edition="test2" num="2.6.0" />
                <vers edition="test3" num="2.6.0" />
                <vers edition="test4" num="2.6.0" />
                <vers edition="test5" num="2.6.0" />
                <vers edition="test6" num="2.6.0" />
                <vers edition="test7" num="2.6.0" />
                <vers edition="test8" num="2.6.0" />
                <vers edition="test9" num="2.6.0" />
                <vers edition="rc1" num="2.6.1" />
                <vers edition="rc2" num="2.6.1" />
                <vers num="2.6_test9_cvs" />
            </prod>
        </vuln_soft>
    </entry>
    <entry reject="1" name="CVE-2004-0187" seq="2004-0187" type="CVE" published="2004-03-15" modified="2008-09-10">
        <desc>
            <descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: CVE-2004-0185.  Reason: This candidate is a reservation duplicate of CVE-2004-0185.  Notes: All CVE users should reference CVE-2004-0185 instead of this candidate.  All references and descriptions in this candidate have been removed to prevent accidental usage.</descript>
        </desc>
        <refs />
    </entry>
    <entry CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" name="CVE-2004-0188" seq="2004-0188" severity="High" type="CVE" published="2004-03-15" CVSS_version="2.0 incomplete approximation" CVSS_score="7.2" modified="2008-09-05">
        <desc>
            <descript source="cve">Heap-based buffer overflow in Calife 2.8.5 and earlier may allow local users to execute arbitrary code via a long password.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot admin="1" />
        </loss_types>
        <vuln_types>
            <input bound="1" />
        </vuln_types>
        <range>
            <local />
        </range>
        <refs>
            <ref source="BID" patch="1" url="http://www.securityfocus.com/bid/9756" adv="1">9756</ref>
            <ref source="DEBIAN" patch="1" url="http://www.debian.org/security/2004/dsa-461" adv="1">DSA-461</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/15335" adv="1">calife-long-password-bo(15335)</ref>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107789737832092&amp;w=2" adv="1">20040227 Calife heap corrupt / potential local root exploit</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/9776">9776</ref>
        </refs>
        <vuln_soft>
            <prod vendor="calife" name="calife">
                <vers num="2.8.4_c" />
                <vers num="2.8.5" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" name="CVE-2004-0189" seq="2004-0189" severity="High" type="CVE" published="2004-03-15" CVSS_version="2.0 incomplete approximation" CVSS_score="7.5" modified="2008-09-05">
        <desc>
            <descript source="cve">The "%xx" URL decoding function in Squid 2.5STABLE4 and earlier allows remote attackers to bypass url_regex ACLs via a URL with a NULL ("%00") characterm, which causes Squid to use only a portion of the requested URL when comparing it against the access control lists.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot other="1" />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="CONFIRM" patch="1" url="http://www.squid-cache.org/Advisories/SQUID-2004_1.txt" adv="1">http://www.squid-cache.org/Advisories/SQUID-2004_1.txt</ref>
            <ref source="BID" patch="1" url="http://www.securityfocus.com/bid/9778" adv="1">9778</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/15366" adv="1">squid-urlregex-acl-bypass(15366)</ref>
            <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2004-134.html">RHSA-2004:134</ref>
            <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2004-133.html">RHSA-2004:133</ref>
            <ref source="OSVDB" url="http://www.osvdb.org/5916">5916</ref>
            <ref source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2004:025">MDKSA-2004:025</ref>
            <ref source="DEBIAN" url="http://www.debian.org/security/2004/dsa-474">DSA-474</ref>
            <ref source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200403-11.xml">GLSA-200403-11</ref>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108084935904110&amp;w=2">20040401 [OpenPKG-SA-2004.008] OpenPKG Security  Advisory (squid)</ref>
            <ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000838">CLA-2004:838</ref>
            <ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/20040404-01-U.asc">20040404-01-U</ref>
            <ref source="SCO" url="ftp://ftp.sco.com/pub/updates/UnixWare/SCOSA-2005.16/SCOSA-2005.16.txt">SCOSA-2005.16</ref>
            <ref source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:941" sig="1">oval:org.mitre.oval:def:941</ref>
            <ref source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:877" sig="1">oval:org.mitre.oval:def:877</ref>
        </refs>
        <vuln_soft>
            <prod vendor="squid" name="squid">
                <vers num="2.0_patch2" />
                <vers num="2.1_patch2" />
                <vers num="2.3_stable5" />
                <vers num="2.4" />
                <vers num="2.4_stable7" />
                <vers num="2.5_stable3" />
                <vers num="2.5_stable4" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" name="CVE-2004-0190" seq="2004-0190" severity="High" type="CVE" published="2004-03-15" CVSS_version="2.0 incomplete approximation" CVSS_score="7.5" modified="2008-09-10">
        <desc>
            <descript source="cve">Symantec FireWall/VPN Appliance model 200 records a cleartext password for the password administration page, which may be cached on the administrator's local system or in a proxy, which allows attackers to steal the password and gain privileges.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot other="1" />
        </loss_types>
        <vuln_types>
            <design />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="BID" patch="1" url="http://www.securityfocus.com/bid/9784" adv="1">9784</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/15212" adv="1">symantec-firewallvpn-password-plaintext(15212)</ref>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107694794031839&amp;w=2" adv="1">20040216 Symantec FireWall/VPN Appliance model 200 leak of security</ref>
            <ref source="OSVDB" url="http://www.osvdb.org/4117">4117</ref>
            <ref source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2004-February/017414.html">20040216 Symantec FireWall/VPN Appliance model 200 leak of security</ref>
        </refs>
        <vuln_soft>
            <prod vendor="symantec" name="firewall_vpn_appliance_100">
                <vers num="" />
            </prod>
            <prod vendor="symantec" name="firewall_vpn_appliance_200">
                <vers num="" />
            </prod>
            <prod vendor="symantec" name="firewall_vpn_appliance_200r">
                <vers num="" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" name="CVE-2004-0191" seq="2004-0191" severity="Medium" type="CVE" published="2004-03-15" CVSS_version="2.0 incomplete approximation" CVSS_score="6.8" modified="2008-09-05">
        <desc>
            <descript source="cve">Mozilla before 1.4.2 executes Javascript events in the context of a new page while it is being loaded, allowing it to interact with the previous page (zombie document) and enable cross-domain and cross-site scripting (XSS) attacks, as demonstrated using onmousemove events.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot other="1" />
        </loss_types>
        <vuln_types>
            <design />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/15322" adv="1">mozilla-event-handler-xss(15322)</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/9747" adv="1">9747</ref>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107774710729469&amp;w=2" adv="1">20040225 Sandblad #13: Cross-domain exploit on zombie document with event handlers</ref>
            <ref source="CONFIRM" url="http://bugzilla.mozilla.org/show_bug.cgi?id=227417" adv="1">http://bugzilla.mozilla.org/show_bug.cgi?id=227417</ref>
            <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2004-112.html">RHSA-2004:112</ref>
            <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2004-110.html">RHSA-2004:110</ref>
            <ref source="OSVDB" url="http://www.osvdb.org/4062">4062</ref>
            <ref source="HP" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108448379429944&amp;w=2">SSRT4722</ref>
            <ref source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:937" sig="1">oval:org.mitre.oval:def:937</ref>
            <ref source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:874" sig="1">oval:org.mitre.oval:def:874</ref>
        </refs>
        <vuln_soft>
            <prod vendor="mozilla" name="mozilla">
                <vers num="0.8" />
                <vers num="0.9.2" />
                <vers num="0.9.2.1" />
                <vers num="0.9.3" />
                <vers num="0.9.35" />
                <vers num="0.9.4" />
                <vers num="0.9.4.1" />
                <vers num="0.9.48" />
                <vers num="0.9.5" />
                <vers num="0.9.6" />
                <vers num="0.9.7" />
                <vers num="0.9.8" />
                <vers num="0.9.9" />
                <vers edition="rc1" num="1.0" />
                <vers edition="rc2" num="1.0" />
                <vers num="1.0.1" />
                <vers num="1.0.2" />
                <vers edition="alpha" num="1.1" />
                <vers edition="beta" num="1.1" />
                <vers edition="alpha" num="1.2" />
                <vers edition="beta" num="1.2" />
                <vers num="1.2.1" />
                <vers num="1.3" />
                <vers num="1.3.1" />
                <vers edition="alpha" num="1.4" />
                <vers edition="beta" num="1.4" />
                <vers num="1.4.1" />
                <vers num="1.5" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" name="CVE-2004-0192" seq="2004-0192" severity="Medium" type="CVE" published="2004-03-15" CVSS_version="2.0 incomplete approximation" CVSS_score="6.8" modified="2008-09-05">
        <desc>
            <descript source="cve">Cross-site scripting (XSS) vulnerability in the Management Service for Symantec Gateway Security 2.0 allows remote attackers to steal cookies and hijack a management session via a /sgmi URL that contains malicious script, which is not quoted in the resulting error page.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot other="1" />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="BID" patch="1" url="http://www.securityfocus.com/bid/9755" adv="1">9755</ref>
            <ref source="BUGTRAQ" patch="1" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107790684732458&amp;w=2" adv="1">20040227 Symantec Gateway Security Management Service Cross Site Scripting</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/15330" adv="1">symantecgateway-error-xss(15330)</ref>
        </refs>
        <vuln_soft>
            <prod vendor="symantec" name="gateway_security_5400">
                <vers num="2.0" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" name="CVE-2004-0193" seq="2004-0193" severity="High" type="CVE" published="2004-03-15" CVSS_version="2.0 incomplete approximation" CVSS_score="7.5" modified="2008-09-05">
        <desc>
            <descript source="cve">Heap-based buffer overflow in the ISS Protocol Analysis Module (PAM), as used in certain versions of RealSecure Network 7.0 and Server Sensor 7.0, Proventia A, G, and M Series, RealSecure Desktop 7.0 and 3.6, RealSecure Guard 3.6, RealSecure Sentry 3.6, BlackICE PC Protection 3.6, and BlackICE Server Protection 3.6, allows remote attackers to execute arbitrary code via an SMB packet containing an authentication request with a long username.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot other="1" />
        </loss_types>
        <vuln_types>
            <input buffer="1" />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="CERT-VN" patch="1" url="http://www.kb.cert.org/vuls/id/150326" adv="1">VU#150326</ref>
            <ref source="ISS" patch="1" url="http://xforce.iss.net/xforce/alerts/id/165" adv="1">20040226 Vulnerability in SMB Parsing in ISS Products</ref>
            <ref source="MISC" url="http://www.eeye.com/html/Research/Upcoming/20040213.html" adv="1">http://www.eeye.com/html/Research/Upcoming/20040213.html</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/15207">pam-smb-protocol-bo(15207)</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/9752">9752</ref>
            <ref source="OSVDB" url="http://www.osvdb.org/4072">4072</ref>
            <ref source="EEYE" url="http://www.eeye.com/html/Research/Advisories/AD20040226.html">AD20040226</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/10988">10988</ref>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107789851117176&amp;w=2">20040227 EEYE: RealSecure/BlackICE Server Message Block (SMB) Processing Overflow</ref>
        </refs>
        <vuln_soft>
            <prod vendor="iss" name="blackice_agent_server">
                <vers num="3.6eca" />
            </prod>
            <prod vendor="iss" name="blackice_pc_protection">
                <vers num="3.6cbd" />
            </prod>
            <prod vendor="iss" name="blackice_server_protection">
                <vers num="3.6cbz" />
            </prod>
            <prod vendor="iss" name="realsecure_desktop">
                <vers num="3.6eca" />
                <vers num="3.6ecf" />
                <vers num="7.0ebg" />
                <vers num="7.0epk" />
            </prod>
            <prod vendor="iss" name="realsecure_guard">
                <vers num="3.6ecb" />
            </prod>
            <prod vendor="iss" name="realsecure_network">
                <vers edition="xpu_20.15" num="7.0" />
            </prod>
            <prod vendor="iss" name="realsecure_sentry">
                <vers num="3.6ecf" />
            </prod>
            <prod vendor="iss" name="realsecure_server_sensor">
                <vers edition="xpu20.16" num="7.0" />
            </prod>
            <prod vendor="iss" name="proventia_a_series_xpu">
                <vers num="20.15" />
            </prod>
            <prod vendor="iss" name="proventia_g_series_xpu">
                <vers num="22.3" />
            </prod>
            <prod vendor="iss" name="proventia_m_series_xpu">
                <vers num="1.30" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" name="CVE-2004-0110" seq="2004-0110" severity="High" type="CVE" published="2004-03-15" CVSS_version="2.0 incomplete approximation" CVSS_score="7.5" modified="2008-09-10">
        <desc>
            <descript source="cve">Buffer overflow in the (1) nanohttp or (2) nanoftp modules in XMLSoft Libxml 2 (Libxml2) 2.6.0 through 2.6.5 allow remote attackers to execute arbitrary code via a long URL.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot other="1" />
        </loss_types>
        <vuln_types>
            <input buffer="1" />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/493966">VU#493966</ref>
            <ref source="XF" patch="1" url="http://xforce.iss.net/xforce/xfdb/15301" adv="1">libxml2-nanohttp-bo(15301)</ref>
            <ref source="BID" patch="1" url="http://www.securityfocus.com/bid/9718" adv="1">9718</ref>
            <ref source="REDHAT" patch="1" url="http://rhn.redhat.com/errata/RHSA-2004-090.html" adv="1">RHSA-2004:090</ref>
            <ref source="BUGTRAQ" patch="1" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107851606605420&amp;w=2" adv="1">20040305 [OpenPKG-SA-2004.003] OpenPKG Security Advisory (libxml)</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/15302">libxml2-nanoftp-bo(15302)</ref>
            <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2004-091.html">RHSA-2004:091</ref>
            <ref source="DEBIAN" url="http://www.debian.org/security/2004/dsa-455">DSA-455</ref>
            <ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/o-086.shtml">O-086</ref>
            <ref source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200403-01.xml">GLSA-200403-01</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/10958/">10958</ref>
            <ref source="CONFIRM" url="http://www.xmlsoft.org/news.html">http://www.xmlsoft.org/news.html</ref>
            <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2004-650.html">RHSA-2004:650</ref>
            <ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2005_01_sr.html">SUSE-SR:2005:001</ref>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107860178228804&amp;w=2">20040306 TSLSA-2004-0010 - libxml2</ref>
            <ref source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:875" sig="1">oval:org.mitre.oval:def:875</ref>
            <ref source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:833" sig="1">oval:org.mitre.oval:def:833</ref>
        </refs>
        <vuln_soft>
            <prod vendor="sgi" name="propack">
                <vers num="2.3" />
                <vers num="2.4" />
            </prod>
            <prod vendor="xmlsoft" name="libxml">
                <vers num="1.8.17" />
            </prod>
            <prod vendor="xmlsoft" name="libxml2">
                <vers num="2.4.19" />
                <vers num="2.4.23" />
                <vers num="2.5.10" />
                <vers num="2.5.11" />
                <vers num="2.5.4" />
                <vers num="2.6.0" />
                <vers num="2.6.1" />
                <vers num="2.6.2" />
                <vers num="2.6.3" />
                <vers num="2.6.4" />
                <vers num="2.6.5" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" name="CVE-2004-0093" seq="2004-0093" severity="High" type="CVE" published="2004-03-15" CVSS_version="2.0 incomplete approximation" CVSS_score="7.5" modified="2008-09-05">
        <desc>
            <descript source="cve">XFree86 4.1.0 allows remote attackers to cause a denial of service and possibly execute arbitrary code via an out-of-bounds array index when using the GLX extension and Direct Rendering Infrastructure (DRI).</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot other="1" />
        </loss_types>
        <vuln_types>
            <input bound="1" />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="DEBIAN" patch="1" url="http://www.debian.org/security/2004/dsa-443" adv="1">DSA-443</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/15272" adv="1">xfree86-glx-array-dos(15272)</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/9701" adv="1">9701</ref>
            <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2004-152.html">RHSA-2004:152</ref>
            <ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000824">CLSA-2004:824</ref>
            <ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/20040406-01-U">20040406-01-U</ref>
        </refs>
        <vuln_soft>
            <prod vendor="xfree86_project" name="x11r6">
                <vers num="4.1.0" />
                <vers num="4.1.11" />
                <vers num="4.1.12" />
                <vers num="4.2.0" />
                <vers edition="" num="4.2.1" />
                <vers edition=":errata" num="4.2.1" />
                <vers num="4.3.0" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" name="CVE-2004-0094" seq="2004-0094" severity="High" type="CVE" published="2004-03-15" CVSS_version="2.0 incomplete approximation" CVSS_score="7.5" modified="2008-09-05">
        <desc>
            <descript source="cve">Integer signedness errors in XFree86 4.1.0 allow remote attackers to cause a denial of service and possibly execute arbitrary code when using the GLX extension and Direct Rendering Infrastructure (DRI).</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot other="1" />
        </loss_types>
        <vuln_types>
            <input bound="1" />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="DEBIAN" patch="1" url="http://www.debian.org/security/2004/dsa-443" adv="1">DSA-443</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/15273" adv="1">xfree86-glx-integer-dos(15273)</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/9701">9701</ref>
            <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2004-152.html">RHSA-2004:152</ref>
            <ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000824">CLSA-2004:824</ref>
            <ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/20040406-01-U">20040406-01-U</ref>
        </refs>
        <vuln_soft>
            <prod vendor="xfree86_project" name="x11r6">
                <vers num="4.1.0" />
                <vers num="4.1.11" />
                <vers num="4.1.12" />
                <vers num="4.2.0" />
                <vers edition="" num="4.2.1" />
                <vers edition=":errata" num="4.2.1" />
                <vers num="4.3.0" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" name="CVE-2004-1815" seq="2004-1815" severity="Medium" type="CVE" published="2004-03-15" CVSS_version="2.0 incomplete approximation" CVSS_score="5.0" modified="2008-09-05">
        <desc>
            <descript source="cve">Unknown vulnerability in ColdFusion MX 6.0 and 6.1, and JRun 4.0, when a SOAP web service expects an array of objects as an argument, allows remote attackers to cause a denial of service (memory consumption).</descript>
        </desc>
        <loss_types>
            <avail />
        </loss_types>
        <vuln_types>
            <exception />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="XF" patch="1" url="http://xforce.iss.net/xforce/xfdb/15473" adv="1">soap-array-dos(15473)</ref>
            <ref source="BID" patch="1" url="http://www.securityfocus.com/bid/9877" adv="1">9877</ref>
            <ref source="CONFIRM" patch="1" url="http://www.macromedia.com/devnet/security/security_zone/mpsb04-04.html" adv="1">http://www.macromedia.com/devnet/security/security_zone/mpsb04-04.html</ref>
            <ref source="SECUNIA" patch="1" url="http://secunia.com/advisories/11132" adv="1">11132</ref>
            <ref source="BUGTRAQ" patch="1" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107936690702515&amp;w=2" adv="1">20040315 Multiple Vendor SOAP server array DoS</ref>
        </refs>
        <vuln_soft>
            <prod vendor="macromedia" name="coldfusion">
                <vers num="6.0" />
                <vers num="6.1" />
            </prod>
            <prod vendor="macromedia" name="jrun">
                <vers edition="sp1" num="4.0" />
                <vers edition="sp1a" num="4.0" />
                <vers num="4.0_build_61650" />
            </prod>
            <prod vendor="sun" name="one_application_server">
                <vers edition="" num="7.0" />
                <vers edition=":standard" num="7.0" />
                <vers edition=":platform" num="7.0" />
                <vers edition="ur1" num="7.0" />
                <vers edition="ur1:platform" num="7.0" />
                <vers edition="ur1:standard" num="7.0" />
                <vers edition="ur2" num="7.0" />
                <vers edition="ur2:standard" num="7.0" />
                <vers edition="ur2:platform" num="7.0" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" name="CVE-2004-1816" seq="2004-1816" severity="Medium" type="CVE" published="2004-03-15" CVSS_version="2.0 incomplete approximation" CVSS_score="5.0" modified="2008-09-05">
        <desc>
            <descript source="cve">Unknown vulnerability in Sun Java System Application Server 7.0 Update 2 and earlier, when a SOAP web service expects an array of objects as an argument, allows remote attackers to cause a denial of service (memory consumption).</descript>
        </desc>
        <loss_types>
            <avail />
        </loss_types>
        <vuln_types>
            <exception />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="XF" patch="1" url="http://xforce.iss.net/xforce/xfdb/15473" adv="1">soap-array-dos(15473)</ref>
            <ref source="BID" patch="1" url="http://www.securityfocus.com/bid/9877" adv="1">9877</ref>
            <ref source="SUNALERT" patch="1" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-57517-1" adv="1">57517</ref>
            <ref source="SECUNIA" patch="1" url="http://secunia.com/advisories/11130" adv="1">11130</ref>
            <ref source="BUGTRAQ" patch="1" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107936690702515&amp;w=2" adv="1">20040315 Multiple Vendor SOAP server array DoS</ref>
        </refs>
    </entry>
    <entry CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" name="CVE-2004-1817" seq="2004-1817" severity="Medium" type="CVE" published="2004-03-15" CVSS_version="2.0 incomplete approximation" CVSS_score="4.3" modified="2008-09-05">
        <desc>
            <descript source="cve">Cross-site scripting (XSS) vulnerability in modules.php in Php-Nuke 7.1.0 allows remote attackers to inject arbitrary web script or HTML via the (1) Your Name field, (2) e-mail field, (3) nicname field, (4) fname parameter, (5) ratenum parameter, or (6) search field.</descript>
        </desc>
        <loss_types>
            <int />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/15491" adv="1">phpnuke-multiple-parameters-xss(15491)</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/9879" adv="1">9879</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/11135" adv="1">11135</ref>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107937752811633&amp;w=2" adv="1">20040315 [waraxe-2004-SA#005 - XSS in Php-Nuke 7.1.0 - part 2]</ref>
        </refs>
        <vuln_soft>
            <prod vendor="francisco_burzi" name="php-nuke">
                <vers num="7.1" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" name="CVE-2004-1818" seq="2004-1818" severity="Medium" type="CVE" published="2004-03-15" CVSS_version="2.0 incomplete approximation" CVSS_score="6.8" modified="2008-09-05">
        <desc>
            <descript source="cve">Cross-site scripting (XSS) vulnerability in nmimage.php in 4nalbum 0.92 for PHP-Nuke 6.5 through 7.0 allows remote attackers to execute arbitrary script as other users by injecting arbitrary script into the z parameter.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/15497" adv="1">4nalbum-nmimagephp-xss(15497)</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/9881" adv="1">9881</ref>
            <ref source="OSVDB" url="http://www.osvdb.org/4293" adv="1">4293</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/11134" adv="1">11134</ref>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107937780222514&amp;w=2" adv="1">20040315 [waraxe-2004-SA#006 - Multiple vulnerabilities in 4nalbum module for PhpNuke]</ref>
        </refs>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" name="CVE-2004-1819" seq="2004-1819" severity="Medium" type="CVE" published="2004-03-15" CVSS_version="2.0 incomplete approximation" CVSS_score="5.0" modified="2008-09-05">
        <desc>
            <descript source="cve">4nalbum 0.92 for PHP-Nuke 6.5 through 7.0 allows remote attackers to obtain sensitive information via a direct request to displaycategory.php, which reveals the path in an error message.</descript>
        </desc>
        <loss_types>
            <conf />
        </loss_types>
        <vuln_types>
            <exception />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/15493" adv="1">4nalbum-error path-disclosure(15493)</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/9881" adv="1">9881</ref>
            <ref source="OSVDB" url="http://www.osvdb.org/4291" adv="1">4291</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/11134" adv="1">11134</ref>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107937780222514&amp;w=2" adv="1">20040315 [waraxe-2004-SA#006 - Multiple vulnerabilities in 4nalbum module for PhpNuke]</ref>
        </refs>
        <vuln_soft>
            <prod vendor="warpspeed" name="4nalbum_module">
                <vers num="0.92" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" name="CVE-2004-1820" seq="2004-1820" severity="High" type="CVE" published="2004-03-15" CVSS_version="2.0 incomplete approximation" CVSS_score="7.5" modified="2008-09-05">
        <desc>
            <descript source="cve">PHP remote file inclusion vulnerability in displaycategory.php in 4nalbum 0.92 for PHP-Nuke 6.5 through 7.0 allows remote attackers to execute arbitrary PHP code by modifying the basepath parameter to reference a URL on a remote web server that contains fileFunctions.php.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot other="1" />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="SECUNIA" patch="1" url="http://secunia.com/advisories/11134" adv="1">11134</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/15496" adv="1">4nalbum-displaycategory-file-include(15496)</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/9881" adv="1">9881</ref>
            <ref source="OSVDB" url="http://www.osvdb.org/4292" adv="1">4292</ref>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107937780222514&amp;w=2" adv="1">20040315 [waraxe-2004-SA#006 - Multiple vulnerabilities in 4nalbum module for PhpNuke]</ref>
        </refs>
        <vuln_soft>
            <prod vendor="warpspeed" name="4nalbum_module">
                <vers num="0.92" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" name="CVE-2004-1821" seq="2004-1821" severity="High" type="CVE" published="2004-03-15" CVSS_version="2.0 incomplete approximation" CVSS_score="7.5" modified="2008-09-05">
        <desc>
            <descript source="cve">SQL injection vulnerability in 4nalbum 0.92 for PHP-Nuke 6.5 through 7.0 allows remote attackers to gain privileges or perform unauthorized database operations via the gid parameter.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot other="1" />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="SECUNIA" patch="1" url="http://secunia.com/advisories/11134" adv="1">11134</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/15498" adv="1">4nalbum-modulesphp-SQL-injection(15498)</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/9881" adv="1">9881</ref>
            <ref source="OSVDB" url="http://www.osvdb.org/4294" adv="1">4294</ref>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107937780222514&amp;w=2" adv="1">20040315 [waraxe-2004-SA#006 - Multiple vulnerabilities in 4nalbum module for PhpNuke]</ref>
        </refs>
        <vuln_soft>
            <prod vendor="warpspeed" name="4nalbum_module">
                <vers num="0.92" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" name="CVE-2004-1822" seq="2004-1822" severity="Medium" type="CVE" published="2004-03-15" CVSS_version="2.0 incomplete approximation" CVSS_score="4.3" modified="2008-09-05">
        <desc>
            <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in Phorum 3.1 through 5.0.3 beta allow remote attackers to inject arbitrary web script or HTML via the (1) HTTP_REFERER parameter to login.php, (2) HTTP_REFERER parameter to register.php, or (3) target parameter to profile.php.</descript>
        </desc>
        <loss_types>
            <int />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="BID" patch="1" url="http://www.securityfocus.com/bid/9882" adv="1">9882</ref>
            <ref source="SECUNIA" patch="1" url="http://secunia.com/advisories/11157" adv="1">11157</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/15494" adv="1">phorum-register-xss(15494)</ref>
            <ref source="CONFIRM" url="http://phorum.org/changelog.txt" adv="1">http://phorum.org/changelog.txt</ref>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107939479713136&amp;w=2" adv="1">20040315 Phorum 5.0.3 Beta &amp;&amp; Earlier XSS Issues</ref>
            <ref source="OSVDB" url="http://www.osvdb.org/4335">4335</ref>
            <ref source="OSVDB" url="http://www.osvdb.org/4334">4334</ref>
            <ref source="OSVDB" url="http://www.osvdb.org/4333">4333</ref>
            <ref source="SECTRACK" url="http://securitytracker.com/id?1009433">1009433</ref>
        </refs>
        <vuln_soft>
            <prod vendor="phorum" name="phorum">
                <vers num="3.1" />
                <vers num="3.1.1" />
                <vers num="3.1.1_pre" />
                <vers num="3.1.1_rc2" />
                <vers num="3.1.1a" />
                <vers num="3.1.2" />
                <vers num="3.2" />
                <vers num="3.2.2" />
                <vers num="3.2.3" />
                <vers num="3.2.3a" />
                <vers num="3.2.3b" />
                <vers num="3.2.4" />
                <vers num="3.2.5" />
                <vers num="3.2.6" />
                <vers num="3.2.7" />
                <vers num="3.2.8" />
                <vers num="3.3.1" />
                <vers num="3.3.1a" />
                <vers num="3.3.2" />
                <vers num="3.3.2a" />
                <vers num="3.3.2b3" />
                <vers num="3.4" />
                <vers num="3.4.1" />
                <vers num="3.4.2" />
                <vers num="3.4.3" />
                <vers num="3.4.4" />
                <vers num="3.4.5" />
                <vers num="3.4.6" />
                <vers num="5.0.3_beta" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" name="CVE-2004-1827" seq="2004-1827" severity="Medium" type="CVE" published="2004-03-15" CVSS_version="2.0 incomplete approximation" CVSS_score="4.3" modified="2008-09-05">
        <desc>
            <descript source="cve">Cross-site scripting (XSS) vulnerability in YaBB 1 Gold(SP1.3) and YaBB SE 1.5.1 Final allows remote attackers to inject arbitrary web script via the background:url property in (1) glow or (2) shadow tags.</descript>
        </desc>
        <loss_types>
            <int />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="BID" patch="1" url="http://www.securityfocus.com/bid/9873" adv="1">9873</ref>
            <ref source="SECUNIA" patch="1" url="http://secunia.com/advisories/11128" adv="1">11128</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/15488" adv="1">yabb-glow-shadow-xss(15488)</ref>
            <ref source="CONFIRM" url="http://www.yabbforum.com/community/YaBB.pl?board=general;action=display;num=1093133233">http://www.yabbforum.com/community/YaBB.pl?board=general;action=display;num=1093133233</ref>
            <ref source="SECTRACK" url="http://securitytracker.com/id?1009427">1009427</ref>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107948064923981&amp;w=2">20040316 RE: YaBB/YaBBse Cross Site Scripting Vulnerability</ref>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107936800226430&amp;w=2">20040314 YaBB/YaBBse Cross Site Scripting Vulnerability</ref>
        </refs>
        <vuln_soft>
            <prod vendor="simple_machines" name="simple_machines_smf">
                <vers num="1.0_b" />
            </prod>
            <prod vendor="yabb" name="yabb">
                <vers edition="" num="1.5.1" />
                <vers edition=":second_edition" num="1.5.1" />
                <vers num="1_gold_-_sp_1.3" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" name="CVE-2004-1825" seq="2004-1825" severity="Medium" type="CVE" published="2004-03-16" CVSS_version="2.0 incomplete approximation" CVSS_score="4.3" modified="2008-09-05">
        <desc>
            <descript source="cve">Cross-site scripting (XSS) vulnerability in index.php in Mambo Open Source 4.5 stable 1.0.3 and earlier allows remote attackers to inject arbitrary web script or HTML via the (1) return or (2) mos_change_template parameters.</descript>
        </desc>
        <loss_types>
            <int />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="OSVDB" patch="1" url="http://www.osvdb.org/4665" adv="1">4665</ref>
            <ref source="SECUNIA" patch="1" url="http://secunia.com/advisories/11140" adv="1">11140</ref>
            <ref source="BUGTRAQ" patch="1" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107945576020593&amp;w=2" adv="1">20040316 Mambo Open Source Multiple Vulnerabilities</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/15499" adv="1">mambo-return-moschangetemplate-xss(15499)</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/9890" adv="1">9890</ref>
            <ref source="OSVDB" url="http://www.osvdb.org/4308">4308</ref>
        </refs>
        <vuln_soft>
            <prod vendor="mambo" name="mambo_open_source">
                <vers num="4.5_1.0.0" />
                <vers num="4.5_1.0.1" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" name="CVE-2004-1826" seq="2004-1826" severity="High" type="CVE" published="2004-03-16" CVSS_version="2.0 incomplete approximation" CVSS_score="7.5" modified="2008-09-05">
        <desc>
            <descript source="cve">SQL injection vulnerability in index.php in Mambo Open Source 4.5 stable 1.0.3 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot other="1" />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="OSVDB" patch="1" url="http://www.osvdb.org/4307" adv="1">4307</ref>
            <ref source="SECUNIA" patch="1" url="http://secunia.com/advisories/11140" adv="1">11140</ref>
            <ref source="BUGTRAQ" patch="1" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107945576020593&amp;w=2" adv="1">20040316 Mambo Open Source Multiple Vulnerabilities</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/15500" adv="1">mambo-id-sql-injection(15500)</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/9891" adv="1">9891</ref>
        </refs>
        <vuln_soft>
            <prod vendor="mambo" name="mambo_open_source_4.5">
                <vers num="1.0.0" />
                <vers num="1.0.1" />
                <vers num="1.0.2" />
                <vers num="1.0.3" />
                <vers num="1.0.3beta" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" name="CVE-2004-1829" seq="2004-1829" severity="Medium" type="CVE" published="2004-03-18" CVSS_version="2.0 incomplete approximation" CVSS_score="4.3" modified="2008-09-05">
        <desc>
            <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in error.php in Gijza.net Error Manager 2.1 for PHP-Nuke 6.0 allow remote attackers to inject arbitrary web script or HTML via the (1) pagetitle or (2) error parameters, or (3) certain parameters in the error log.</descript>
        </desc>
        <loss_types>
            <int />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/15530" adv="1">errormanager-error-command-execution(15530)</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/15529" adv="1">errormanager-error-xss(15529)</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/9911" adv="1">9911</ref>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107963064317560&amp;w=2" adv="1">20040318 [waraxe-2004-SA#010 - Multiple vulnerabilities in Error Manager</ref>
            <ref source="OSVDB" url="http://www.osvdb.org/4384">4384</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/11164">11164</ref>
        </refs>
        <vuln_soft>
            <prod vendor="error_manager" name="php-nuke_module">
                <vers num="2.1" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" name="CVE-2004-1830" seq="2004-1830" severity="Medium" type="CVE" published="2004-03-18" CVSS_version="2.0 incomplete approximation" CVSS_score="5.0" modified="2008-09-05">
        <desc>
            <descript source="cve">error.php in Error Manager 2.1 for PHP-Nuke 6.0 allows remote attackers to obtain sensitive information via an invalid (1) language, (2) newlang, or (3) lang parameter, which leaks the pathname in a PHP error message.</descript>
        </desc>
        <loss_types>
            <conf />
        </loss_types>
        <vuln_types>
            <exception />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/15524">errormanager-error-path-disclosure(15524)</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/9911">9911</ref>
            <ref source="OSVDB" url="http://www.osvdb.org/4386">4386</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/11164">11164</ref>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107963064317560&amp;w=2" adv="1">20040318 [waraxe-2004-SA#010 - Multiple vulnerabilities in Error Manager</ref>
        </refs>
        <vuln_soft>
            <prod vendor="francisco_burzi" name="php-nuke">
                <vers num="6.0" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" name="CVE-2004-1853" seq="2004-1853" severity="Medium" type="CVE" published="2004-03-19" CVSS_version="2.0 incomplete approximation" CVSS_score="5.0" modified="2008-09-05">
        <desc>
            <descript source="cve">Buffer overflow in Terminator 3: War of the Machines 1.0 allows remote attackers to cause a denial of service via a long ServerInfo variable.</descript>
        </desc>
        <loss_types>
            <avail />
        </loss_types>
        <vuln_types>
            <input buffer="1" />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="SECTRACK" patch="1" url="http://securitytracker.com/id?1009498" adv="1">1009498</ref>
            <ref source="SECUNIA" patch="1" url="http://secunia.com/advisories/11182" adv="1">11182</ref>
            <ref source="MISC" patch="1" url="http://aluigi.altervista.org/adv/t3cbof-adv.txt" adv="1">http://aluigi.altervista.org/adv/t3cbof-adv.txt</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/15542" adv="1">terminator3-bo(15542)</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/9918" adv="1">9918</ref>
            <ref source="OSVDB" url="http://www.osvdb.org/4447" adv="1">4447</ref>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108016076221855&amp;w=2">20040323 Broadcast client buffer-overflow in Terminator 3 1.0</ref>
        </refs>
        <vuln_soft>
            <prod vendor="atari" name="terminator_3_war_of_the_machines">
                <vers num="1.0" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" name="CVE-2004-1833" seq="2004-1833" severity="High" type="CVE" published="2004-03-20" CVSS_version="2.0 incomplete approximation" CVSS_score="7.5" modified="2008-09-05">
        <desc>
            <descript source="cve">The admin.ib file in Borland Interbase 7.1 for Linux has default world writable permissions, which allows local users to gain database administrative privileges.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot other="1" />
        </loss_types>
        <vuln_types>
            <config />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="BID" patch="1" url="http://www.securityfocus.com/bid/9929" adv="1">9929</ref>
            <ref source="SECTRACK" patch="1" url="http://securitytracker.com/id?1009500" adv="1">1009500</ref>
            <ref source="SECUNIA" patch="1" url="http://secunia.com/advisories/11172" adv="1">11172</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/15546" adv="1">interbase-admin-gain-privileges(15546)</ref>
            <ref source="OSVDB" url="http://www.osvdb.org/4381" adv="1">4381</ref>
            <ref source="IDEFENSE" url="http://www.idefense.com/application/poi/display?id=80&amp;type=vulnerabilities&amp;flashstatus=true" adv="1">20040319 Borland Interbase admin.ib Administrative Access Vulnerability</ref>
        </refs>
        <vuln_soft>
            <prod vendor="borland_software" name="interbase">
                <vers num="4.0" />
                <vers num="5.0" />
                <vers num="6.0" />
                <vers num="6.4" />
                <vers num="6.5" />
                <vers num="7.0" />
                <vers num="7.1" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" name="CVE-2004-1834" seq="2004-1834" severity="Low" type="CVE" published="2004-03-20" CVSS_version="2.0 incomplete approximation" CVSS_score="2.1" modified="2008-09-05">
        <desc>
            <descript source="cve">mod_disk_cache in Apache 2.0 through 2.0.49 stores client headers, including authentication information, on the hard disk, which could allow local users to gain sensitive information.</descript>
        </desc>
        <loss_types>
            <conf />
        </loss_types>
        <vuln_types>
            <design />
        </vuln_types>
        <range>
            <local />
        </range>
        <refs>
            <ref source="XF" patch="1" url="http://xforce.iss.net/xforce/xfdb/15547" adv="1">apache-moddiskcache-obtain-info(15547)</ref>
            <ref source="BID" patch="1" url="http://www.securityfocus.com/bid/9933" adv="1">9933</ref>
            <ref source="OSVDB" url="http://www.osvdb.org/4446" adv="1">4446</ref>
            <ref source="SECTRACK" url="http://securitytracker.com/id?1009509" adv="1">1009509</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/11176" adv="1">11176</ref>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107981737322495&amp;w=2" adv="1">20040319 Apache mod_disk_cache stores client authentication credentials on disk</ref>
            <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2004-562.html">RHSA-2004:562</ref>
            <ref source="VUPEN" url="http://www.frsirt.com/english/advisories/2006/0789">ADV-2006-0789</ref>
            <ref source="CONFIRM" url="http://support.avaya.com/elmodocs2/security/ASA-2006-081.htm">http://support.avaya.com/elmodocs2/security/ASA-2006-081.htm</ref>
            <ref source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-102198-1">102198</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/19072">19072</ref>
        </refs>
        <vuln_soft>
            <prod vendor="apache" name="http_server">
                <vers num="2.0" />
                <vers edition="beta" num="2.0.28" />
                <vers num="2.0.32" />
                <vers num="2.0.35" />
                <vers num="2.0.36" />
                <vers num="2.0.37" />
                <vers num="2.0.38" />
                <vers num="2.0.39" />
                <vers num="2.0.40" />
                <vers num="2.0.41" />
                <vers num="2.0.42" />
                <vers num="2.0.43" />
                <vers num="2.0.44" />
                <vers num="2.0.45" />
                <vers num="2.0.46" />
                <vers num="2.0.47" />
                <vers num="2.0.48" />
                <vers num="2.0.49" />
                <vers num="2.0.9" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" name="CVE-2004-1843" seq="2004-1843" severity="High" type="CVE" published="2004-03-20" CVSS_version="2.0 incomplete approximation" CVSS_score="7.5" modified="2008-09-05">
        <desc>
            <descript source="cve">SQL injection vulnerability in Member Management System 2.1 allows remote attackers to execute arbitrary SQL via the ID parameter to (1) resend.asp or (2) news_view.asp.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot other="1" />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="BID" patch="1" url="http://www.securityfocus.com/bid/9931" adv="1">9931</ref>
            <ref source="SECTRACK" patch="1" url="http://securitytracker.com/id?1009508" adv="1">1009508</ref>
            <ref source="SECUNIA" patch="1" url="http://secunia.com/advisories/11179" adv="1">11179</ref>
            <ref source="BUGTRAQ" patch="1" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107999697625786&amp;w=2" adv="1">20040322 Vulnerabilities in Member Management System 2.1</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/15551" adv="1">mms-id-sql-injection(15551)</ref>
        </refs>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" name="CVE-2004-1846" seq="2004-1846" severity="High" type="CVE" published="2004-03-20" CVSS_version="2.0 incomplete approximation" CVSS_score="7.5" modified="2008-09-05">
        <desc>
            <descript source="cve">Multiple SQL injection vulnerabilities in News Manager Lite 2.5 allow remote attackers to execute arbitrary SQL code via the (1) ID parameter to more.asp, (2) ID parameter to category_news.asp, or (3) filter parameter to news_sort.asp.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot other="1" />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="BID" patch="1" url="http://www.securityfocus.com/bid/9935" adv="1">9935</ref>
            <ref source="SECTRACK" patch="1" url="http://securitytracker.com/id?1009507" adv="1">1009507</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/15549" adv="1">news-manager-sql-injection(15549)</ref>
            <ref source="OSVDB" url="http://www.osvdb.org/4497" adv="1">4497</ref>
            <ref source="OSVDB" url="http://www.osvdb.org/4496" adv="1">4496</ref>
            <ref source="OSVDB" url="http://www.osvdb.org/4495" adv="1">4495</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/11180">11180</ref>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107999733503496&amp;w=2" adv="1">20040322 Vulnerabilities in News Manager Lite 2.5 &amp; News Manager Lite administration</ref>
        </refs>
        <vuln_soft>
            <prod vendor="expinion.net" name="news_manager_lite">
                <vers num="2.5" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" name="CVE-2004-1847" seq="2004-1847" severity="High" type="CVE" published="2004-03-20" CVSS_version="2.0 incomplete approximation" CVSS_score="7.5" modified="2008-09-05">
        <desc>
            <descript source="cve">News Manager Lite 2.5 allows remote attackers to bypass authentication and gain administrator privileges by setting the ADMIN parameter in the NEWS_LOGIN cookie.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot other="1" />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="BID" patch="1" url="http://www.securityfocus.com/bid/9935">9935</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/15550" adv="1">news-manager-admin-access(15550)</ref>
            <ref source="SECTRACK" url="http://securitytracker.com/id?1009507" adv="1">1009507</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/11180" adv="1">11180</ref>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107999733503496&amp;w=2" adv="1">20040322 Vulnerabilities in News Manager Lite 2.5 &amp; News Manager Lite administration</ref>
        </refs>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" name="CVE-2004-1838" seq="2004-1838" severity="Medium" type="CVE" published="2004-03-22" CVSS_version="2.0 incomplete approximation" CVSS_score="5.0" modified="2008-09-05">
        <desc>
            <descript source="cve">Directory traversal vulnerability in xweb 1.0 allows remote attackers to download arbitrary files via a .. (dot dot) in the URL.</descript>
        </desc>
        <loss_types>
            <conf />
        </loss_types>
        <vuln_types>
            <access />
            <input />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="BID" patch="1" url="http://www.securityfocus.com/bid/9937" adv="1">9937</ref>
            <ref source="MISC" patch="1" url="http://www.autistici.org/fdonato/advisory/xweb1.0-adv.txt" adv="1">http://www.autistici.org/fdonato/advisory/xweb1.0-adv.txt</ref>
            <ref source="SECTRACK" patch="1" url="http://securitytracker.com/id?1009514" adv="1">1009514</ref>
            <ref source="SECUNIA" patch="1" url="http://secunia.com/advisories/11186" adv="1">11186</ref>
            <ref source="BUGTRAQ" patch="1" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107997946623770&amp;w=2" adv="1">20040322 directory traversal in xweb 1.0</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/15567" adv="1">xweb-dotdot-directory-traversal(15567)</ref>
            <ref source="OSVDB" url="http://www.osvdb.org/4460" adv="1">4460</ref>
        </refs>
        <vuln_soft>
            <prod vendor="xweb" name="xweb">
                <vers num="1.0" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" name="CVE-2004-1839" seq="2004-1839" severity="Medium" type="CVE" published="2004-03-22" CVSS_version="2.0 incomplete approximation" CVSS_score="5.0" modified="2008-09-05">
        <desc>
            <descript source="cve">MS Analysis module 2.0 for PHP-Nuke allows remote attackers to obtain sensitive information via a direct request to (1) browsers.php, (2) mstrack.php, or (3) title.php, which reveal the full path in a PHP error message.</descript>
        </desc>
        <loss_types>
            <conf />
        </loss_types>
        <vuln_types>
            <exception />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="BID" url="http://www.securityfocus.com/bid/9946" adv="1">9946</ref>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108006319730976&amp;w=2" adv="1">20040322  [waraxe-2004-SA#011 Multiple vulnerabilities in MS Analysis v2.0 module for PhpNuke]</ref>
        </refs>
        <vuln_soft>
            <prod vendor="francisco_burzi" name="php-nuke">
                <vers num="6.5" />
                <vers num="6.5_beta1" />
                <vers num="6.5_final" />
                <vers num="6.5_rc1" />
                <vers num="6.5_rc2" />
                <vers num="6.5_rc3" />
                <vers num="6.6" />
                <vers num="6.7" />
                <vers num="6.9" />
                <vers num="7.0" />
                <vers num="7.0_final" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" name="CVE-2004-1840" seq="2004-1840" severity="Medium" type="CVE" published="2004-03-22" CVSS_version="2.0 incomplete approximation" CVSS_score="4.3" modified="2008-09-05">
        <desc>
            <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in MS Analysis module 2.0 for PHP-Nuke allows remote attackers to inject arbitrary web script or HTML via the (1) screen parameter to modules.php, (2) module_name parameter to title.php, (3) sortby parameter to modules.php, or (4) overview parameter to modules.php.</descript>
        </desc>
        <loss_types>
            <int />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/15575" adv="1">msanalysis-modules-title-xss(15575)</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/9947" adv="1">9947</ref>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108006319730976&amp;w=2" adv="1">20040322  [waraxe-2004-SA#011 Multiple vulnerabilities in MS Analysis v2.0 module for PhpNuke]</ref>
        </refs>
        <vuln_soft>
            <prod vendor="francisco_burzi" name="php-nuke">
                <vers num="6.5" />
                <vers num="6.5_beta1" />
                <vers num="6.5_final" />
                <vers num="6.5_rc1" />
                <vers num="6.5_rc2" />
                <vers num="6.5_rc3" />
                <vers num="6.6" />
                <vers num="6.7" />
                <vers num="6.9" />
                <vers num="7.0" />
                <vers num="7.0_final" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" name="CVE-2004-1850" seq="2004-1850" severity="Medium" type="CVE" published="2004-03-23" CVSS_version="2.0 incomplete approximation" CVSS_score="5.0" modified="2008-09-05">
        <desc>
            <descript source="cve">The Rage 1.01 and earlier allows remote attackers to cause a denial of service (infinite loop) via a TCP packet with the port and IP address set to zero.</descript>
        </desc>
        <loss_types>
            <avail />
        </loss_types>
        <vuln_types>
            <exception />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/15584" adv="1">therage-packet-dos(15584)</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/9961" adv="1">9961</ref>
            <ref source="SECTRACK" url="http://securitytracker.com/id?1009540" adv="1">1009540</ref>
            <ref source="MISC" url="http://aluigi.altervista.org/adv/ragefreeze-adv.txt" adv="1">http://aluigi.altervista.org/adv/ragefreeze-adv.txt</ref>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108006680013576&amp;w=2">20040323 Server freeze in The Rage 1.01</ref>
        </refs>
        <vuln_soft>
            <prod vendor="fluidgames" name="the_rage">
                <vers num="1.0_1" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" name="CVE-2004-1855" seq="2004-1855" severity="Medium" type="CVE" published="2004-03-23" CVSS_version="2.0 incomplete approximation" CVSS_score="5.0" modified="2008-09-05">
        <desc>
            <descript source="cve">Dark Age of Camelot before 1.68 live patch does not sign the RSA public key, which could allow remote malicious servers to gain sensitive information via a man-in-the-middle attack.</descript>
        </desc>
        <loss_types>
            <conf />
        </loss_types>
        <vuln_types>
            <design />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/15597" adv="1">daoc-login-mitm(15597)</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/9960" adv="1">9960</ref>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108016932816707&amp;w=2" adv="1">20040324 Dark Age of Camelot login client vulnerability to man in the middle</ref>
            <ref source="FULLDISC" url="http://lists.netsys.com/pipermail/full-disclosure/2004-March/019212.html">20040323 Dark Age of Camelot login client vulnerability to man in the middle attack</ref>
            <ref source="MISC" url="http://capnbry.net/daoc/advisory20040323/" adv="1">http://capnbry.net/daoc/advisory20040323/</ref>
        </refs>
        <vuln_soft>
            <prod vendor="mythic_entertainment" name="dark_age_of_camelot">
                <vers num="1.60" />
                <vers num="1.61" />
                <vers num="1.62" />
                <vers num="1.63" />
                <vers num="1.65" />
                <vers num="1.66" />
                <vers num="1.67" />
                <vers num="1.68" />
            </prod>
        </vuln_soft>
    </entry>
    <entry reject="1" name="CVE-2004-1886" seq="2004-1886" type="CVE" published="2004-03-23" modified="2008-05-21">
        <desc>
            <descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: CVE-2004-1848.  Reason: This candidate is a duplicate of CVE-2004-1848.  Notes: All CVE users should reference CVE-2004-1848 instead of this candidate.  All references and descriptions in this candidate have been removed to prevent accidental usage.</descript>
        </desc>
        <loss_types>
            <avail />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs />
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" name="CVE-2004-1884" seq="2004-1884" severity="High" type="CVE" published="2004-03-23" CVSS_version="2.0 incomplete approximation" CVSS_score="7.5" modified="2008-09-05">
        <desc>
            <descript source="cve">Ipswitch WS_FTP Server 4.0.2 has a backdoor XXSESS_MGRYY username with a default password, which allows remote attackers to gain access.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot other="1" />
        </loss_types>
        <vuln_types>
            <config />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="SECUNIA" patch="1" url="http://secunia.com/advisories/11206" adv="1">11206</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/15558" adv="1">wftp-site-gain-priviliege(15558)</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/9953" adv="1">9953</ref>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108006581418116&amp;w=2" adv="1">20040323 Open the WS_FTP Server backdoor to SYSTEM</ref>
        </refs>
        <vuln_soft>
            <prod vendor="ipswitch" name="ws_ftp_pro">
                <vers num="6.0" />
                <vers num="7.5" />
                <vers num="8.0_2" />
                <vers num="8.0_3" />
            </prod>
            <prod vendor="ipswitch" name="ws_ftp_server">
                <vers num="1.0.1" />
                <vers num="1.0.2" />
                <vers num="1.0.3" />
                <vers num="1.0.4" />
                <vers num="1.0.5" />
                <vers num="2.0" />
                <vers num="2.0.1" />
                <vers num="2.0.2" />
                <vers num="2.0.3" />
                <vers num="2.0.4" />
                <vers num="3.0" />
                <vers num="3.0_1" />
                <vers num="3.1" />
                <vers num="3.1.1" />
                <vers num="3.1.2" />
                <vers num="3.1.3" />
                <vers num="3.4" />
                <vers num="4.0" />
                <vers num="4.0.2" />
                <vers num="4.01" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" name="CVE-2004-1852" seq="2004-1852" severity="Medium" type="CVE" published="2004-03-23" CVSS_version="2.0 incomplete approximation" CVSS_score="5.0" modified="2008-09-05">
        <desc>
            <descript source="cve">DameWare Mini Remote Control 3.x before 3.74 and 4.x before 4.2 transmits the Blowfish encryption key in plaintext, which allows remote attackers to gain sensitive information.</descript>
        </desc>
        <loss_types>
            <conf />
        </loss_types>
        <vuln_types>
            <design />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="XF" patch="1" url="http://xforce.iss.net/xforce/xfdb/15586" adv="1">dameware-encryption-key-plaintext(15586)</ref>
            <ref source="BID" patch="1" url="http://www.securityfocus.com/bid/9959" adv="1">9959</ref>
            <ref source="CONFIRM" patch="1" url="http://www.dameware.com/support/security/bulletin.asp?ID=SB3" adv="1">http://www.dameware.com/support/security/bulletin.asp?ID=SB3</ref>
            <ref source="SECUNIA" patch="1" url="http://secunia.com/advisories/11205" adv="1">11205</ref>
            <ref source="OSVDB" url="http://www.osvdb.org/4547" adv="1">4547</ref>
            <ref source="SECTRACK" url="http://securitytracker.com/id?1009557" adv="1">1009557</ref>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108016344224973&amp;w=2" adv="1">20040323 Dameware Passes Weak File Encryption Key in the Clear</ref>
        </refs>
        <vuln_soft>
            <prod vendor="dameware_development" name="mini_remote_control_server">
                <vers num="3.70_.0.0" />
                <vers num="3.71_.0.0" />
                <vers num="3.72_.0.0" />
                <vers num="3.73_.0.0" />
                <vers num="4.0" />
                <vers num="4.1_.0.0" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" name="CVE-2004-2037" seq="2004-2037" severity="High" type="CVE" published="2004-03-24" CVSS_version="2.0 incomplete approximation" CVSS_score="7.5" modified="2008-09-05">
        <desc>
            <descript source="cve">Buffer overflow in Mollensoft Lightweight FTP Server 3.6 allows remote authenticated users to cause a denial of service (crash) and possibly execute arbitrary code via a long CWD command, as demonstrated in one example by using the "cd" command in an interactive FTP client.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot user="1" />
        </loss_types>
        <vuln_types>
            <input buffer="1" />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="XF" patch="1" url="http://xforce.iss.net/xforce/xfdb/16237" adv="1">mollensoft-cwd-command-bo(16237)</ref>
            <ref source="OSVDB" patch="1" url="http://www.osvdb.org/6412" adv="1">6412</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/16303" adv="1">mollensoft-cd-bo(16303)</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/10429" adv="1">10429</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/10409" adv="1">10409</ref>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108611230015042&amp;w=2" adv="1">20040601 Mollensoft Lightweight FTP Server CWD Buffer Overflow</ref>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108577846011604&amp;w=2" adv="1">20040528 Mollensoft ftp Server ver 3.6 Buffer overflow</ref>
            <ref source="SECTRACK" url="http://securitytracker.com/id?1010328">1010328</ref>
        </refs>
        <vuln_soft>
            <prod vendor="mollensoft_software" name="lightweight_ftp_server">
                <vers num="3.6" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" name="CVE-2004-1856" seq="2004-1856" severity="Medium" type="CVE" published="2004-03-24" CVSS_version="2.0 incomplete approximation" CVSS_score="5.0" modified="2008-09-05">
        <desc>
            <descript source="cve">devices_update_printer_fw_upload.hts in HP Web JetAdmin 7.5.2546, when no password is set, allows remote attackers to upload arbitrary files to the printer directory.</descript>
        </desc>
        <loss_types>
            <int />
        </loss_types>
        <vuln_types>
            <access />
            <config />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/15605" adv="1">hp-jetadmin-file-upload(15605)</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/9971" adv="1">9971</ref>
            <ref source="HP" url="http://www.securityfocus.com/advisories/6492">SSRT4700</ref>
            <ref source="MISC" url="http://sh0dan.org/files/hpjadmadv.txt" adv="1">http://sh0dan.org/files/hpjadmadv.txt</ref>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108016019623003&amp;w=2" adv="1">20040324 HP Web JetAdmin vulnerabilities.</ref>
        </refs>
        <vuln_soft>
            <prod vendor="hp" name="web_jetadmin">
                <vers num="7.5.2546" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" name="CVE-2004-1857" seq="2004-1857" severity="Low" type="CVE" published="2004-03-24" CVSS_version="2.0 incomplete approximation" CVSS_score="2.1" modified="2008-09-05">
        <desc>
            <descript source="cve">Directory traversal vulnerability in setinfo.hts in HP Web Jetadmin 7.5.2546 allows remote authenticated attackers to read arbitrary files via a .. (dot dot) in the setinclude parameter.</descript>
        </desc>
        <loss_types>
            <conf />
        </loss_types>
        <vuln_types>
            <access />
            <input />
        </vuln_types>
        <range>
            <local />
        </range>
        <refs>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/15606" adv="1">hp-jetadmin-setinfo-directory-traversal(15606)</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/9972" adv="1">9972</ref>
            <ref source="HP" url="http://www.securityfocus.com/advisories/6492" adv="1">SSRT4700</ref>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108016019623003&amp;w=2" adv="1">20040324 HP Web JetAdmin vulnerabilities.</ref>
        </refs>
        <vuln_soft>
            <prod vendor="hp" name="web_jetadmin">
                <vers num="7.5.2546" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" name="CVE-2004-1851" seq="2004-1851" severity="High" type="CVE" published="2004-03-24" CVSS_version="2.0 incomplete approximation" CVSS_score="7.5" modified="2008-09-05">
        <desc>
            <descript source="cve">Dameware Mini Remote Control 4.1.0.0 uses insufficiently random data to create the encryption key, which makes it easier for remote attackers to obtain sensitive information via brute force guessing.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
        </loss_types>
        <vuln_types>
            <design />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="SECUNIA" patch="1" url="http://secunia.com/advisories/11205" adv="1">11205</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/15587" adv="1">dameware-random-generator-weak(15587)</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/9957" adv="1">9957</ref>
            <ref source="OSVDB" url="http://www.osvdb.org/4547" adv="1">4547</ref>
            <ref source="SECTRACK" url="http://securitytracker.com/id?1009557" adv="1">1009557</ref>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108016344224973&amp;w=2" adv="1">20030323 Dameware Passes Weak File Encryption Key in the Clear</ref>
        </refs>
        <vuln_soft>
            <prod vendor="dameware_development" name="mini_remote_control_server">
                <vers num="4.1_.0.0" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" name="CVE-2004-1849" seq="2004-1849" severity="Medium" type="CVE" published="2004-03-24" CVSS_version="2.0 incomplete approximation" CVSS_score="4.3" modified="2008-09-05">
        <desc>
            <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in cPanel 9.1.0 allow remote attackers to inject arbitrary web script or HTML via the (1) email parameter to dodelautores.html or (2) handle parameter to addhandle.html.</descript>
        </desc>
        <loss_types>
            <int />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/15517" adv="1">cpanel-dodelautores-addhandle-xss(15517)</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/9965" adv="1">9965</ref>
            <ref source="OSVDB" url="http://www.osvdb.org/4530" adv="1">4530</ref>
            <ref source="OSVDB" url="http://www.osvdb.org/4529" adv="1">4529</ref>
            <ref source="SECTRACK" url="http://securitytracker.com/id?1009541" adv="1">1009541</ref>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108006627005371&amp;w=2" adv="1">20040323 More Cpanel Vuls (cross site scripting)</ref>
        </refs>
        <vuln_soft>
            <prod vendor="cpanel" name="cpanel">
                <vers num="9.1" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" name="CVE-2004-1854" seq="2004-1854" severity="High" type="CVE" published="2004-03-24" CVSS_version="2.0 incomplete approximation" CVSS_score="7.5" modified="2008-09-05">
        <desc>
            <descript source="cve">Buffer overflow in the logging function in Picophone 1.63 and earlier allows remote attackers to execute arbitrary code via a large packet.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot user="1" />
        </loss_types>
        <vuln_types>
            <input buffer="1" />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="XF" patch="1" url="http://xforce.iss.net/xforce/xfdb/15595" adv="1">picophone-logging-function-bo(15595)</ref>
            <ref source="BID" patch="1" url="http://www.securityfocus.com/bid/9969" adv="1">9969</ref>
            <ref source="SECTRACK" patch="1" url="http://securitytracker.com/id?1009551" adv="1">1009551</ref>
            <ref source="SECUNIA" patch="1" url="http://secunia.com/advisories/11209" adv="1">11209</ref>
            <ref source="MISC" patch="1" url="http://aluigi.altervista.org/adv/picobof-adv.txt" adv="1">http://aluigi.altervista.org/adv/picobof-adv.txt</ref>
            <ref source="OSVDB" url="http://www.osvdb.org/4550" adv="1">4550</ref>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108016032220647&amp;w=2">20040324 Buffer overflow in PicoPhone 1.63</ref>
        </refs>
        <vuln_soft>
            <prod vendor="picophone" name="internet_telephone">
                <vers num="1.63" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" name="CVE-2004-1859" seq="2004-1859" severity="Medium" type="CVE" published="2004-03-24" CVSS_version="2.0 incomplete approximation" CVSS_score="5.0" modified="2008-09-05">
        <desc>
            <descript source="cve">Directory traversal vulnerability in Trend Micro Interscan Web Viruswall in InterScan VirusWall 3.5x allows remote attackers to read arbitrary files via a .. (dot dot) in the URL.</descript>
        </desc>
        <loss_types>
            <conf />
        </loss_types>
        <vuln_types>
            <access />
            <input />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="XF" patch="1" url="http://xforce.iss.net/xforce/xfdb/15590" adv="1">interscan-dotdot-directory-traversal(15590)</ref>
            <ref source="SECUNIA" patch="1" url="http://secunia.com/advisories/11215" adv="1">11215</ref>
            <ref source="CONFIRM" patch="1" url="http://kb.trendmicro.com/solutions/search/main/search/solutionDetail.asp?solutionID=19257" adv="1">http://kb.trendmicro.com/solutions/search/main/search/solutionDetail.asp?solutionID=19257</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/9966" adv="1">9966</ref>
            <ref source="OSVDB" url="http://www.osvdb.org/4549" adv="1">4549</ref>
            <ref source="SECTRACK" url="http://securitytracker.com/id?1009550" adv="1">1009550</ref>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108014604529316&amp;w=2" adv="1">20040324 TrendMacro Interscan Viruswall Directory Traversal</ref>
        </refs>
        <vuln_soft>
            <prod vendor="trend_micro" name="interscan_viruswall_for_windows_nt">
                <vers num="3.4" />
                <vers num="3.5" />
                <vers num="3.51" />
                <vers num="3.52" />
                <vers num="3.52_build1466" />
                <vers num="3.6" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" name="CVE-2004-1861" seq="2004-1861" severity="Medium" type="CVE" published="2004-03-25" CVSS_version="2.0 incomplete approximation" CVSS_score="4.6" modified="2008-09-05">
        <desc>
            <descript source="cve">Invision NetSupport School Pro uses a weak encryption algorithm to encrypt passwords, which allows local users to obtain passwords.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot other="1" />
        </loss_types>
        <vuln_types>
            <design />
        </vuln_types>
        <range>
            <local />
        </range>
        <refs>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/15621" adv="1">netsupportschoolpro-weak-encryption(15621)</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/9981" adv="1">9981</ref>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108032304932321&amp;w=2" adv="1">20040326 NetSupport School Pro: Password Encryption Weaknesses</ref>
        </refs>
        <vuln_soft>
            <prod vendor="netsupport" name="netsupport_school">
                <vers num="7.0" />
                <vers num="7.0_1" />
                <vers num="7.5" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" name="CVE-2004-1868" seq="2004-1868" severity="High" type="CVE" published="2004-03-25" CVSS_version="2.0 incomplete approximation" CVSS_score="7.5" modified="2008-09-05">
        <desc>
            <descript source="cve">Stack-based buffer overflow in WinSig.exe in eSignal 7.5 and 7.6 allows remote attackers to execute arbitrary code via a long STREAMQUOTE tag.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot user="1" />
        </loss_types>
        <vuln_types>
            <input buffer="1" />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="XF" patch="1" url="http://xforce.iss.net/xforce/xfdb/15624" adv="1">esignal-specs-bo(15624)</ref>
            <ref source="BID" patch="1" url="http://www.securityfocus.com/bid/9978" adv="1">9978</ref>
            <ref source="SECUNIA" patch="1" url="http://secunia.com/advisories/11222" adv="1">11222</ref>
            <ref source="BUGTRAQ" patch="1" url="http://archives.neohapsis.com/archives/bugtraq/2004-04/0056.html">20040406 Re: eSignal v7 remote buffer overflow</ref>
            <ref source="MISC" url="http://viziblesoft.com/insect/advisories/vz012004-esignal7.txt" adv="1">http://viziblesoft.com/insect/advisories/vz012004-esignal7.txt</ref>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108025234317408&amp;w=2" adv="1">20040325 eSignal v7 remote buffer overflow (exploit)</ref>
        </refs>
        <vuln_soft>
            <prod vendor="esignal" name="esignal">
                <vers num="7.5" />
                <vers num="7.6" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" name="CVE-2004-1862" seq="2004-1862" severity="Medium" type="CVE" published="2004-03-26" CVSS_version="2.0 incomplete approximation" CVSS_score="4.3" modified="2008-09-05">
        <desc>
            <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in Extreme Messageboard (XMB) 1.8 SP3 and 1.9 beta allow remote attackers to inject arbitrary web script or HTML via the (1) xmbuser parameter to xmb.php, (2) folder parameter to u2u.php, (3) viewmost, replymost, or latest parameter to stats.php, (4) message or icons parameter to post.php, (5) threadlist, pagelinks, forumlist, navigation, or (6) forumdisplay parameter to forumdisplay.php.</descript>
        </desc>
        <loss_types>
            <int />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/15654" adv="1">xmb-forum-multiple-xss(15654)</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/9983" adv="1">9983</ref>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108032355905265&amp;w=2" adv="1">20040326 [waraxe-2004-SA#012 - Multiple vulnerabilities in XMB Forum 1.8 Partagium SP3 and 1.9 Nexus Beta]</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/11230">11230</ref>
            <ref source="OSVDB" url="http://osvdb.org/14988">14988</ref>
            <ref source="OSVDB" url="http://osvdb.org/14987">14987</ref>
            <ref source="OSVDB" url="http://osvdb.org/14986">14986</ref>
            <ref source="OSVDB" url="http://osvdb.org/14985">14985</ref>
            <ref source="OSVDB" url="http://osvdb.org/14983">14983</ref>
        </refs>
        <vuln_soft>
            <prod vendor="xmb_forum" name="xmb">
                <vers num="1.8_sp3" />
                <vers num="1.9_beta" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" name="CVE-2004-1864" seq="2004-1864" severity="High" type="CVE" published="2004-03-26" CVSS_version="2.0 incomplete approximation" CVSS_score="7.5" modified="2008-09-10">
        <desc>
            <descript source="cve">SQL injection vulnerability in Extreme Messageboard (XMB) 1.9 beta allows remote attackers to execute arbitrary SQL commands via the restrict parameter to (1) member.php, (2) misc.php, or (3) today.php.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot other="1" />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/15655" adv="1">xmb-forum-sql-injection(15655)</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/9983" adv="1">9983</ref>
            <ref source="OSVDB" url="http://www.osvdb.org/16886">16886</ref>
            <ref source="SECTRACK" url="http://securitytracker.com/id?1009561">1009561</ref>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108032355905265&amp;w=2" adv="1">20040326 [waraxe-2004-SA#012 - Multiple vulnerabilities in XMB Forum 1.8 SP3 and 1.9 beta]</ref>
        </refs>
        <vuln_soft>
            <prod vendor="xmb_forum" name="xmb">
                <vers num="1.8_sp3" />
                <vers num="1.9_beta" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:L/AC:M/Au:N/C:N/I:P/A:N)" CVSS_base_score="1.9" CVSS_exploit_subscore="3.4" CVSS_impact_subscore="2.9" name="CVE-2004-1865" seq="2004-1865" severity="Low" type="CVE" published="2004-03-26" CVSS_version="2.0 incomplete approximation" CVSS_score="1.9" modified="2005-10-20">
        <desc>
            <descript source="cve">Cross-site scripting (XSS) vulnerability in the administration panel in bBlog 0.7.2 allows remote authenticated users with superuser privileges to inject arbitrary web script or HTML via a blog name ($blogname).  NOTE: if administrators are normally allowed to add HTML by other means, e.g. through Smarty templates, then this issue would not give any additional privileges, and thus would not be considered a vulnerability.</descript>
        </desc>
        <loss_types>
            <int />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <local />
        </range>
        <refs>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/15635" adv="1">bblog-name-xss(15635)</ref>
            <ref source="SECTRACK" url="http://securitytracker.com/id?1009564" adv="1">1009564</ref>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108034226717745&amp;w=2" adv="1">20040326 bblog 0.7.2 cross site scripting</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/13397">13397</ref>
            <ref source="OSVDB" url="http://www.osvdb.org/10510">10510</ref>
        </refs>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" name="CVE-2004-1866" seq="2004-1866" severity="Medium" type="CVE" published="2004-03-26" CVSS_version="2.0 incomplete approximation" CVSS_score="5.0" modified="2008-09-05">
        <desc>
            <descript source="cve">nstxd in Nstx 1.1 beta3 and earlier allows remote attackers to cause a denial of service (crash) via a large packet, which triggers a null dereference.</descript>
        </desc>
        <loss_types>
            <avail />
        </loss_types>
        <vuln_types>
            <exception />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="XF" patch="1" url="http://xforce.iss.net/xforce/xfdb/15638" adv="1">nstx-null-dos(15638)</ref>
            <ref source="BID" patch="1" url="http://www.securityfocus.com/bid/9989" adv="1">9989</ref>
            <ref source="SECTRACK" patch="1" url="http://securitytracker.com/id?1009567" adv="1">1009567</ref>
            <ref source="CONFIRM" patch="1" url="http://nstx.dereference.de/nstx/nstx-1.1-beta4.tgz">http://nstx.dereference.de/nstx/nstx-1.1-beta4.tgz</ref>
            <ref source="BUGTRAQ" patch="1" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108034249916453&amp;w=2" adv="1">20040326 Nstxd vulnerability</ref>
        </refs>
        <vuln_soft>
            <prod vendor="nstx" name="ip_over_dns_utility">
                <vers num="1.0" />
                <vers num="1.1_beta1" />
                <vers num="1.1_beta2" />
                <vers num="1.1_beta3" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" name="CVE-2004-0113" seq="2004-0113" severity="Medium" type="CVE" published="2004-03-29" CVSS_version="2.0 incomplete approximation" CVSS_score="5.0" modified="2008-09-10">
        <desc>
            <descript source="cve">Memory leak in ssl_engine_io.c for mod_ssl in Apache 2 before 2.0.49 allows remote attackers to cause a denial of service (memory consumption) via plain HTTP requests to the SSL port of an SSL-enabled server.</descript>
        </desc>
        <loss_types>
            <avail />
        </loss_types>
        <vuln_types>
            <design />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="BID" patch="1" url="http://www.securityfocus.com/bid/9826" adv="1">9826</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/15419" adv="1">apache-modssl-plain-dos(15419)</ref>
            <ref source="CONFIRM" url="http://www.apacheweek.com/features/security-20" adv="1">http://www.apacheweek.com/features/security-20</ref>
            <ref source="MLIST" url="http://marc.theaimsgroup.com/?l=apache-cvs&amp;m=107869699329638" adv="1">[apache-cvs] 20040307 cvs commit: httpd-2.0/modules/ssl ssl_engine_io.c</ref>
            <ref source="TRUSTIX" url="http://www.trustix.org/errata/2004/0017">2004-0017</ref>
            <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2004-182.html">RHSA-2004:182</ref>
            <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2004-084.html">RHSA-2004:084</ref>
            <ref source="OSVDB" url="http://www.osvdb.org/4182">4182</ref>
            <ref source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2004:043">MDKSA-2004:043</ref>
            <ref source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200403-04.xml">GLSA-200403-04</ref>
            <ref source="HP" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108731648532365&amp;w=2">SSRT4717</ref>
            <ref source="APPLE" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108369640424244&amp;w=2">APPLE-SA-2004-05-03</ref>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108034113406858&amp;w=2">20040325 LNSA-#2004-0006: bug workaround for Apache 2.0.48</ref>
            <ref source="MISC" url="http://issues.apache.org/bugzilla/show_bug.cgi?id=27106">http://issues.apache.org/bugzilla/show_bug.cgi?id=27106</ref>
            <ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000839">CLSA-2004:839</ref>
            <ref source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:876" sig="1">oval:org.mitre.oval:def:876</ref>
        </refs>
        <vuln_soft>
            <prod vendor="apache" name="http_server">
                <vers num="2.0.35" />
                <vers num="2.0.36" />
                <vers num="2.0.37" />
                <vers num="2.0.38" />
                <vers num="2.0.39" />
                <vers num="2.0.40" />
                <vers num="2.0.41" />
                <vers num="2.0.42" />
                <vers num="2.0.43" />
                <vers num="2.0.44" />
                <vers num="2.0.45" />
                <vers num="2.0.46" />
                <vers num="2.0.47" />
                <vers num="2.0.48" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" name="CVE-2004-0126" seq="2004-0126" severity="Medium" type="CVE" published="2004-03-29" CVSS_version="2.0 incomplete approximation" CVSS_score="4.6" modified="2008-09-05">
        <desc>
            <descript source="cve">The jail_attach system call in FreeBSD 5.1 and 5.2 changes the directory of a calling process even if the process doesn't have permission to change directory, which allows local users to gain read/write privileges to files and directories within another jail.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot other="1" />
        </loss_types>
        <vuln_types>
            <access />
        </vuln_types>
        <range>
            <local />
        </range>
        <refs>
            <ref source="BID" patch="1" url="http://www.securityfocus.com/bid/9762" adv="1">9762</ref>
            <ref source="FREEBSD" patch="1" url="ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-04:03.jail.asc" adv="1">FreeBSD-SA-04:03</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/15344" adv="1">freebsd-jailattach-gain-privileges(15344)</ref>
            <ref source="OSVDB" url="http://www.osvdb.org/4101">4101</ref>
        </refs>
        <vuln_soft>
            <prod vendor="freebsd" name="freebsd">
                <vers edition="release" num="5.1" />
                <vers num="5.2" />
                <vers edition="release" num="5.2.1" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" name="CVE-2004-0194" seq="2004-0194" severity="High" type="CVE" published="2004-03-29" CVSS_version="2.0 incomplete approximation" CVSS_score="7.5" modified="2008-09-05">
        <desc>
            <descript source="cve">Stack-based buffer overflow in the OutputDebugString function for Adobe Acrobat Reader 5.1 allows remote attackers to execute arbitrary code via a PDF document with XML Forms Data Format (XFDF) data.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot other="1" />
        </loss_types>
        <vuln_types>
            <input buffer="1" />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="BID" patch="1" url="http://www.securityfocus.com/bid/9802" adv="1">9802</ref>
            <ref source="MISC" patch="1" url="http://www.nextgenss.com/advisories/adobexfdf.txt" adv="1">http://www.nextgenss.com/advisories/adobexfdf.txt</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/15384" adv="1">acrobatreader-xfdf-bo(15384)</ref>
            <ref source="OSVDB" url="http://www.osvdb.org/4135">4135</ref>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107842545022724&amp;w=2">20040303 Abobe Reader 5.1 XFDF Buffer Overflow Vulnerability</ref>
            <ref source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2004-March/018227.html">20040303 Adobe Acrobat Reader XML Forms Data Format Buffer Overflow</ref>
        </refs>
        <vuln_soft>
            <prod vendor="adobe" name="acrobat_reader">
                <vers num="5.1" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" name="CVE-2004-0158" seq="2004-0158" severity="Medium" type="CVE" published="2004-03-29" CVSS_version="2.0 incomplete approximation" CVSS_score="4.6" modified="2008-09-05">
        <desc>
            <descript source="cve">Buffer overflow in lbreakout2 allows local users to gain 'games' group privileges via a large HOME environment variable to (1) editor.c, (2) theme.c, (3) manager.c, (4) config.c, (5) game.c, (6) levels.c, or (7) main.c.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot other="1" />
        </loss_types>
        <vuln_types>
            <input bound="1" />
        </vuln_types>
        <range>
            <local />
        </range>
        <refs>
            <ref source="XF" patch="1" url="http://xforce.iss.net/xforce/xfdb/15229" adv="1">breakout2-home-bo(15229)</ref>
            <ref source="BID" patch="1" url="http://www.securityfocus.com/bid/9712" adv="1">9712</ref>
            <ref source="DEBIAN" patch="1" url="http://www.debian.org/security/2004/dsa-445" adv="1">DSA-445</ref>
            <ref source="CONFIRM" url="http://security.debian.org/pool/updates/main/l/lbreakout2/lbreakout2_2.2.2-1woody1.diff.gz">http://security.debian.org/pool/updates/main/l/lbreakout2/lbreakout2_2.2.2-1woody1.diff.gz</ref>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107755821705356&amp;w=2">20040222 lbreakout2 &lt; 2.4beta-2 local exploit</ref>
        </refs>
        <vuln_soft>
            <prod vendor="lgames" name="lbreakout2">
                <vers num="2.0" />
                <vers num="2.0.1" />
                <vers num="2.1" />
                <vers num="2.1.1" />
                <vers num="2.1.2" />
                <vers num="2.2" />
                <vers num="2.2.1" />
                <vers num="2.2.2" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" name="CVE-2004-0160" seq="2004-0160" severity="High" type="CVE" published="2004-03-29" CVSS_version="2.0 incomplete approximation" CVSS_score="7.2" modified="2008-09-05">
        <desc>
            <descript source="cve">Synaesthesia 2.2 and earlier allows local users to execute arbitrary code via a symlink attack on the configuration file.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot admin="1" />
        </loss_types>
        <vuln_types>
            <env />
        </vuln_types>
        <range>
            <local />
        </range>
        <refs>
            <ref source="XF" patch="1" url="http://xforce.iss.net/xforce/xfdb/15279" adv="1">synaesthesia-configuration-symlink-attack(15279)</ref>
            <ref source="BID" patch="1" url="http://www.securityfocus.com/bid/9713" adv="1">9713</ref>
            <ref source="DEBIAN" patch="1" url="http://www.debian.org/security/2004/dsa-446" adv="1">DSA-446</ref>
        </refs>
        <vuln_soft>
            <prod vendor="synaesthesia" name="synaesthesia">
                <vers num="2.1.0" />
                <vers num="2.1.1" />
                <vers num="2.1.2" />
                <vers num="2.2" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" name="CVE-2004-1870" seq="2004-1870" severity="High" type="CVE" published="2004-03-29" CVSS_version="2.0 incomplete approximation" CVSS_score="7.5" modified="2008-09-05">
        <desc>
            <descript source="cve">Multiple SQL injection vulnerabilities in PhotoPost PHP Pro 4.6.x and earlier allow remote attackers to gain users' passwords via the (1) photo parameter to addfav.php, (2) photo parameter to comments.php, (3) credit parameter to comments.php, (4) cat parameter to index.php, (5) ppuser parameter to showgallery.php, (6) cat parameter to showgallery.php, (7) cat parameter to uploadphoto.php, (8) albumid parameter to useralbums.php, or (9) albumid parameter to useralbums.php.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot other="1" />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/15642" adv="1">photopost-php-sql-injection(15642)</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/9994" adv="1">9994</ref>
            <ref source="SECTRACK" url="http://securitytracker.com/id?1009571" adv="1">1009571</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/11241" adv="1">11241</ref>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108057790723123&amp;w=2" adv="1">20040328 PhotoPost PHP Pro Multiple Vulnerabilities</ref>
        </refs>
        <vuln_soft>
            <prod vendor="photopost" name="photopost_php_pro">
                <vers num="3.1" />
                <vers num="3.2" />
                <vers num="3.3" />
                <vers num="4.0" />
                <vers num="4.1" />
                <vers num="4.6" />
                <vers num="4.8.1" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" name="CVE-2004-1871" seq="2004-1871" severity="Medium" type="CVE" published="2004-03-29" CVSS_version="2.0 incomplete approximation" CVSS_score="4.3" modified="2008-09-05">
        <desc>
            <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in PhotoPost PHP Pro 4.6.x and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) ppuser, (2) password, (3) stype, (4) perpage, (5) sort, (6) page, (7) si, or (8) cat parameters to showmembers.php, or the (9) photo name, (10) photo description, (11) album name, or (12) album description fields.</descript>
        </desc>
        <loss_types>
            <int />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="BID" patch="1" url="http://www.securityfocus.com/bid/9994" adv="1">9994</ref>
            <ref source="SECUNIA" patch="1" url="http://secunia.com/advisories/11241" adv="1">11241</ref>
            <ref source="BUGTRAQ" patch="1" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108057790723123&amp;w=2" adv="1">20040328 PhotoPost PHP Pro Multiple Vulnerabilities</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/15643" adv="1">photopost-php-xss(15643)</ref>
            <ref source="SECTRACK" url="http://securitytracker.com/id?1009571" adv="1">1009571</ref>
        </refs>
        <vuln_soft>
            <prod vendor="photopost" name="photopost_php_pro">
                <vers num="3.1" />
                <vers num="3.2" />
                <vers num="3.3" />
                <vers num="4.0" />
                <vers num="4.1" />
                <vers num="4.6" />
                <vers num="4.8.1" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" name="CVE-2004-1872" seq="2004-1872" severity="Medium" type="CVE" published="2004-03-29" CVSS_version="2.0 incomplete approximation" CVSS_score="4.3" modified="2008-09-05">
        <desc>
            <descript source="cve">Cross-site scripting (XSS) vulnerability in WebCT Campus Edition 4.1.1.5 allows remote attackers to inject arbitrary web script or HTML via the @import URL function in a CSS style tag.</descript>
        </desc>
        <loss_types>
            <int />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="XF" patch="1" url="http://xforce.iss.net/xforce/xfdb/15652" adv="1">webct-import-xss(15652)</ref>
            <ref source="BID" patch="1" url="http://www.securityfocus.com/bid/9999" adv="1">9999</ref>
            <ref source="BUGTRAQ" patch="1" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108057915916365&amp;w=2" adv="1">20040329 WebCT Campus Edition 4.1 - Cross site scripting using CSS @import</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/11242" adv="1">11242</ref>
        </refs>
        <vuln_soft>
            <prod vendor="webct" name="webct">
                <vers num="campus_3.8" />
                <vers num="campus_3.8.4" />
                <vers num="campus_4.0" />
                <vers num="campus_4.1" />
                <vers num="campus_4.1.1.5" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" name="CVE-2004-1874" seq="2004-1874" severity="Medium" type="CVE" published="2004-03-29" CVSS_version="2.0 incomplete approximation" CVSS_score="4.3" modified="2008-09-05">
        <desc>
            <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in (1) deliver.asp and (2) billing.asp in A-CART Pro and A-CART 2.0 allow remote attackers to inject arbitrary web script or HTML via the user information forms.</descript>
        </desc>
        <loss_types>
            <int />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/15660" adv="1">acart-deliverasp-billingasp-xss(15660)</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/9997" adv="1">9997</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/11236" adv="1">11236</ref>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108057887008983&amp;w=2" adv="1">20040329 A-CART Pro &amp; A-CART 2.0 Input Validation Holes</ref>
        </refs>
        <vuln_soft>
            <prod vendor="alan_ward" name="a-cart">
                <vers edition="" num="2.0" />
                <vers edition=":pro" num="2.0" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_base_score="9.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="10.0" name="CVE-2004-1875" seq="2004-1875" severity="High" type="CVE" published="2004-03-30" CVSS_version="2.0 incomplete approximation" CVSS_score="9.3" modified="2008-09-05">
        <desc>
            <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in cPanel 9.1.0-R85 allow remote attackers to inject arbitrary web script or HTML via the (1) email parameter to testfile.html, (2) file parameter to erredit.html, (3) dns parameter to dnslook.html, (4) account parameter to ignorelist.html, (5) account parameter to showlog.html, (6) db parameter to repairdb.html, (7) login parameter to doaddftp.html (8) account parameter to editmsg.htm, or (9) ip parameter to del.html.  NOTE: the dnslook.html vector was later reported to exist in cPanel 10.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="XF" patch="1" url="http://xforce.iss.net/xforce/xfdb/15671" adv="1">cpanel-multiple-scripts-xss(15671)</ref>
            <ref source="MISC" patch="1" url="http://www.cirt.net/advisories/cpanel_xss.shtml" adv="1">http://www.cirt.net/advisories/cpanel_xss.shtml</ref>
            <ref source="SECUNIA" patch="1" url="http://secunia.com/advisories/11244" adv="1">11244</ref>
            <ref source="BUGTRAQ" patch="1" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108066561608676&amp;w=2" adv="1">20040330 Exensive cPanel Cross Site Scripting</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/21142">21142</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/10002" adv="1">10002</ref>
            <ref source="OSVDB" url="http://www.osvdb.org/4243" adv="1">4243</ref>
            <ref source="OSVDB" url="http://www.osvdb.org/4215" adv="1">4215</ref>
            <ref source="OSVDB" url="http://www.osvdb.org/4214" adv="1">4214</ref>
            <ref source="OSVDB" url="http://www.osvdb.org/4213" adv="1">4213</ref>
            <ref source="OSVDB" url="http://www.osvdb.org/4212" adv="1">4212</ref>
            <ref source="OSVDB" url="http://www.osvdb.org/4211">4211</ref>
            <ref source="OSVDB" url="http://www.osvdb.org/4210" adv="1">4210</ref>
            <ref source="OSVDB" url="http://www.osvdb.org/4209" adv="1">4209</ref>
            <ref source="OSVDB" url="http://www.osvdb.org/4208" adv="1">4208</ref>
            <ref source="VUPEN" url="http://www.frsirt.com/english/advisories/2006/4658">ADV-2006-4658</ref>
            <ref source="MISC" url="http://www.aria-security.com/forum/showthread.php?t=30">http://www.aria-security.com/forum/showthread.php?t=30</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/22984">22984</ref>
        </refs>
        <vuln_soft>
            <prod vendor="cpanel" name="cpanel">
                <vers num="9.1.0_r85" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" name="CVE-2004-1876" seq="2004-1876" severity="Medium" type="CVE" published="2004-03-30" CVSS_version="2.0 incomplete approximation" CVSS_score="4.6" modified="2008-09-05">
        <desc>
            <descript source="cve">The "%f" feature in the VirusEvent directive in Clam AntiVirus daemon (clamd) before 0.70 allows local users to execute arbitrary commands via shell metacharacters in a file name.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot user="1" />
        </loss_types>
        <vuln_types>
            <input />
            <exception />
        </vuln_types>
        <range>
            <local />
        </range>
        <refs>
            <ref source="XF" patch="1" url="http://xforce.iss.net/xforce/xfdb/15692" adv="1">clamantivirus-virusevent-gain-privileges(15692)</ref>
            <ref source="BID" patch="1" url="http://www.securityfocus.com/bid/10007" adv="1">10007</ref>
            <ref source="GENTOO" patch="1" url="http://security.gentoo.org/glsa/glsa-200405-03.xml" adv="1">GLSA-200405-03</ref>
            <ref source="SECUNIA" patch="1" url="http://secunia.com/advisories/11253" adv="1">11253</ref>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108066864608615&amp;w=2" adv="1">20040330 clamd - NEVER use "%f" in your "VirusEvent"</ref>
        </refs>
        <vuln_soft>
            <prod vendor="clam_anti-virus" name="clamav">
                <vers num="0.51" />
                <vers num="0.52" />
                <vers num="0.53" />
                <vers num="0.54" />
                <vers num="0.60" />
                <vers num="0.65" />
                <vers num="0.67" />
                <vers num="0.68" />
                <vers num="0.68.1" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:N/A:N)" CVSS_base_score="2.6" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="2.9" name="CVE-2004-1877" seq="2004-1877" severity="Low" type="CVE" published="2004-03-30" CVSS_version="2.0 incomplete approximation" CVSS_score="2.6" modified="2008-09-05">
        <desc>
            <descript source="cve">The p_submit_url value in the sample login form in the Oracle 9i Application Server (9iAS) Single Sign-on Administrators Guide, Release 2(9.0.2) for Oracle SSO allows remote attackers to spoof the login page, which could allow users to inadvertently reveal their username and password.</descript>
        </desc>
        <loss_types>
            <conf />
        </loss_types>
        <vuln_types>
            <design />
        </vuln_types>
        <range>
            <network />
            <user_init />
        </range>
        <refs>
            <ref source="XF" patch="1" url="http://xforce.iss.net/xforce/xfdb/15676" adv="1">oracle-sso-login-spoofing(15676)</ref>
            <ref source="BID" patch="1" url="http://www.securityfocus.com/bid/10009" adv="1">10009</ref>
            <ref source="BUGTRAQ" patch="1" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108067040722235&amp;w=2" adv="1">20040330 Problem with customized login pages for Oracle SSO</ref>
        </refs>
        <vuln_soft>
            <prod vendor="oracle" name="application_server">
                <vers num="1.0.2" />
                <vers num="1.0.2.1s" />
                <vers num="1.0.2.2" />
                <vers num="1.0.2.2.2" />
                <vers num="9.0.2" />
                <vers num="9.0.2.0.0" />
                <vers num="9.0.2.0.1" />
                <vers num="9.0.2.1" />
                <vers num="9.0.2.2" />
                <vers num="9.0.2.3" />
                <vers num="9.0.3" />
                <vers num="9.0.3.1" />
            </prod>
            <prod vendor="oracle" name="http_server">
                <vers num="8.1.7" />
                <vers num="9.0.1" />
                <vers num="9.2.0" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" name="CVE-2004-1878" seq="2004-1878" severity="Medium" type="CVE" published="2004-03-30" CVSS_version="2.0 incomplete approximation" CVSS_score="5.0" modified="2008-09-05">
        <desc>
            <descript source="cve">LINBOX LIN:BOX allows remote attackers to bypass authentication, obtain sensitive information, or gain access via a direct request to admin/user.pl preceded by // (double leading slash).</descript>
        </desc>
        <loss_types>
            <conf />
        </loss_types>
        <vuln_types>
            <access />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="XF" patch="1" url="http://xforce.iss.net/xforce/xfdb/15677" adv="1">linbox-slashslash-security-bypass(15677)</ref>
            <ref source="BID" patch="1" url="http://www.securityfocus.com/bid/10010" adv="1">10010</ref>
            <ref source="SECUNIA" patch="1" url="http://secunia.com/advisories/11264" adv="1">11264</ref>
            <ref source="MISC" url="http://www.websec.org/adv/linbit.txt.html" adv="1">http://www.websec.org/adv/linbit.txt.html</ref>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108067245401673&amp;w=2" adv="1">20040330 Linbit linbox Multiple Vulnerabilities</ref>
        </refs>
        <vuln_soft>
            <prod vendor="linbit_technologies" name="linbox_officeserver">
                <vers num="" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" name="CVE-2004-1890" seq="2004-1890" severity="Medium" type="CVE" published="2004-04-02" CVSS_version="2.0 incomplete approximation" CVSS_score="5.0" modified="2008-09-05">
        <desc>
            <descript source="cve">Unknown vulnerability in ftpd in SGI IRIX 6.5.20 through 6.5.23 allows remote attackers to cause a denial of service (hang) via the PORT mode.</descript>
        </desc>
        <loss_types>
            <avail />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="XF" patch="1" url="http://xforce.iss.net/xforce/xfdb/15723" adv="1">irix-ftpd-port-dos(15723)</ref>
            <ref source="BID" patch="1" url="http://www.securityfocus.com/bid/10037" adv="1">10037</ref>
            <ref source="SGI" patch="1" url="ftp://patches.sgi.com/support/free/security/advisories/20040401-01-P.asc" adv="1">20040401-01-P</ref>
        </refs>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" name="CVE-2004-1986" seq="2004-1986" severity="Medium" type="CVE" published="2004-04-04" CVSS_version="2.0 incomplete approximation" CVSS_score="5.0" modified="2008-09-05">
        <desc>
            <descript source="cve">Directory traversal vulnerability in modules.php in Coppermine Photo Gallery 1.2.2b and 1.2.0 RC4 allows remote attackers with administrative privileges to read arbitrary files via a .. (dot dot) in the startdir parameter.</descript>
        </desc>
        <loss_types>
            <conf />
        </loss_types>
        <vuln_types>
            <access />
            <input />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/16042" adv="1">coppermine-modulesphp-directory-traversal(16042)</ref>
            <ref source="MISC" url="http://www.waraxe.us/index.php?modname=sa&amp;id=26" adv="1">http://www.waraxe.us/index.php?modname=sa&amp;id=26</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/10253" adv="1">10253</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/11524" adv="1">11524</ref>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108360247732014&amp;w=2" adv="1">20040502 [waraxe-2004-SA#026 - Multiple vulnerabilities in Coppermine Photo Gallery for PhpNuke]</ref>
            <ref source="OSVDB" url="http://www.osvdb.org/5758">5758</ref>
            <ref source="SECTRACK" url="http://securitytracker.com/id?1010001">1010001</ref>
        </refs>
        <vuln_soft>
            <prod vendor="coppermine" name="coppermine_photo_gallery">
                <vers num="1.0_rc3" />
                <vers num="1.1_.0" />
                <vers num="1.1_beta_2" />
                <vers num="1.2" />
                <vers num="1.2.1" />
                <vers num="1.2.2_b" />
            </prod>
            <prod vendor="francisco_burzi" name="php-nuke">
                <vers num="6.9" />
                <vers num="7.0" />
                <vers num="7.0_final" />
                <vers num="7.1" />
                <vers num="7.2" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" name="CVE-2004-1357" seq="2004-1357" severity="Medium" type="CVE" published="2004-04-07" CVSS_version="2.0 incomplete approximation" CVSS_score="5.0" modified="2008-09-10">
        <desc>
            <descript source="cve">The Secure Shell (SSH) Daemon (SSHD) in Sun Solaris 9 does not properly log IP addresses when SSHD is configured with the ListenAddress as 0.0.0.0, which makes it easier for remote attackers to hide the source of their activities.</descript>
        </desc>
        <loss_types>
            <int />
        </loss_types>
        <vuln_types>
            <config />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="CERT-VN" patch="1" url="http://www.kb.cert.org/vuls/id/737548" adv="1">VU#737548</ref>
            <ref source="XF" patch="1" url="http://xforce.iss.net/xforce/xfdb/15784">solaris-sshd-log-bypass(15784)</ref>
            <ref source="BID" patch="1" url="http://www.securityfocus.com/bid/10080">10080</ref>
            <ref source="AUSCERT" patch="1" url="http://www.auscert.org.au/render.html?it=4003" adv="1">ESB-2004.0263</ref>
            <ref source="SUNALERT" patch="1" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-57538-1" adv="1">57538</ref>
            <ref source="SECUNIA" patch="1" url="http://secunia.com/advisories/11316/" adv="1">11316</ref>
            <ref source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:3505" sig="1">oval:org.mitre.oval:def:3505</ref>
        </refs>
        <vuln_soft>
            <prod vendor="sun" name="solaris">
                <vers edition="" num="9.0" />
                <vers edition=":x86" num="9.0" />
                <vers edition=":sparc" num="9.0" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" name="CVE-2004-1915" seq="2004-1915" severity="High" type="CVE" published="2004-04-08" CVSS_version="2.0 incomplete approximation" CVSS_score="7.5" modified="2008-09-05">
        <desc>
            <descript source="cve">Buffer overflow in the parse_all_client_messages function in LCDproc 0.4.x up to 0.4.4 allows remote attackers to execute arbitrary code via a large number of arguments.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot user="1" />
        </loss_types>
        <vuln_types>
            <input buffer="1" />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="XF" patch="1" url="http://xforce.iss.net/xforce/xfdb/15803" adv="1">lcdproc-parseallclientmessages-bo(15803)</ref>
            <ref source="BID" patch="1" url="http://www.securityfocus.com/bid/10085" adv="1">10085</ref>
            <ref source="GENTOO" patch="1" url="http://security.gentoo.org/glsa/glsa-200404-19.xml" adv="1">GLSA-200404-19</ref>
            <ref source="SECUNIA" patch="1" url="http://secunia.com/advisories/11333" adv="1">11333</ref>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108145722229810&amp;w=2" adv="1">20040408 PSR - #2004-001 Remote - LCDProc</ref>
            <ref source="CONFIRM" url="http://lists.omnipotent.net/pipermail/lcdproc/2004-April/008884.html" adv="1">http://lists.omnipotent.net/pipermail/lcdproc/2004-April/008884.html</ref>
        </refs>
        <vuln_soft>
            <prod vendor="lcdproc" name="lcdproc">
                <vers num="0.3" />
                <vers num="0.4" />
                <vers num="0.4.1_r1" />
                <vers num="4.0" />
                <vers num="4.1" />
                <vers num="4.2" />
                <vers num="4.3" />
                <vers num="4.4" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" name="CVE-2004-1916" seq="2004-1916" severity="High" type="CVE" published="2004-04-08" CVSS_version="2.0 incomplete approximation" CVSS_score="7.5" modified="2008-09-05">
        <desc>
            <descript source="cve">Multiple buffer overflows in LCDProc 0.4.1, and possibly other 0.4.x versions up to 0.4.4, allows remote attackers to execute arbitrary code via (1) a long invalid command to parse_all_client_messages function, or (2) long argv command to test_func_func function.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot user="1" />
        </loss_types>
        <vuln_types>
            <input buffer="1" />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="BID" patch="1" url="http://www.securityfocus.com/bid/10085" adv="1">10085</ref>
            <ref source="SECUNIA" patch="1" url="http://secunia.com/advisories/11333" adv="1">11333</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/15814" adv="1">lcdproc-testfuncfunc-bo(15814)</ref>
            <ref source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200404-19.xml" adv="1">GLSA-200404-19</ref>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108146376315229&amp;w=2" adv="1">20040408 PSR - #2004-002 Remote - LCDProc</ref>
            <ref source="CONFIRM" url="http://lists.omnipotent.net/pipermail/lcdproc/2004-April/008884.html" adv="1">http://lists.omnipotent.net/pipermail/lcdproc/2004-April/008884.html</ref>
        </refs>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" name="CVE-2004-1917" seq="2004-1917" severity="High" type="CVE" published="2004-04-08" CVSS_version="2.0 incomplete approximation" CVSS_score="7.5" modified="2008-09-05">
        <desc>
            <descript source="cve">Format string vulnerability in test_func_func in LCDProc 0.4.1 and earlier allows remote attackers to execute arbitrary code via format string specifiers in the str variable.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot user="1" />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="BID" patch="1" url="http://www.securityfocus.com/bid/10085" adv="1">10085</ref>
            <ref source="GENTOO" patch="1" url="http://security.gentoo.org/glsa/glsa-200404-19.xml" adv="1">GLSA-200404-19</ref>
            <ref source="SECUNIA" patch="1" url="http://secunia.com/advisories/11333" adv="1">11333</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/15817" adv="1">lcdproc-testfuncfunc-format-string(15817)</ref>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108146376315229&amp;w=2" adv="1">20040408 PSR - #2004-002 Remote - LCDProc</ref>
            <ref source="CONFIRM" url="http://lists.omnipotent.net/pipermail/lcdproc/2004-April/008884.html" adv="1">http://lists.omnipotent.net/pipermail/lcdproc/2004-April/008884.html</ref>
        </refs>
        <vuln_soft>
            <prod vendor="lcdproc" name="lcdproc">
                <vers num="0.3" />
                <vers num="0.4" />
                <vers num="0.4.1_r1" />
                <vers num="4.0" />
                <vers num="4.1" />
                <vers num="4.2" />
                <vers num="4.3" />
                <vers num="4.4" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" name="CVE-2004-1918" seq="2004-1918" severity="Medium" type="CVE" published="2004-04-09" CVSS_version="2.0 incomplete approximation" CVSS_score="5.0" modified="2008-09-05">
        <desc>
            <descript source="cve">RSniff 1.0 allows remote attackers to cause a denial of service (connection exhaustion) via a large number of connections with a command other than AUTHENTICATE, or without any data, which prevents the socket from being closed properly.</descript>
        </desc>
        <loss_types>
            <avail />
        </loss_types>
        <vuln_types>
            <exception />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="BID" patch="1" url="http://www.securityfocus.com/bid/10093" adv="1">10093</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/15823" adv="1">rsniff-connection-dos(15823)</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/11339" adv="1">11339</ref>
            <ref source="MISC" url="http://aluigi.altervista.org/adv/rsniff-adv.txt">http://aluigi.altervista.org/adv/rsniff-adv.txt</ref>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108152508004665&amp;w=2">20040409 DoS in Rsniff 1.0</ref>
        </refs>
        <vuln_soft>
            <prod vendor="rsniff" name="rsniff">
                <vers num="1.0" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" name="CVE-2004-1919" seq="2004-1919" severity="Medium" type="CVE" published="2004-04-09" CVSS_version="2.0 incomplete approximation" CVSS_score="5.0" modified="2008-09-05">
        <desc>
            <descript source="cve">The hash_strcmp function in hasch.c in Crackalaka 1.0.8 allows remote attackers to cause a denial of service (crash) via large malformed strings.</descript>
        </desc>
        <loss_types>
            <avail />
        </loss_types>
        <vuln_types>
            <input bound="1" />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/15824" adv="1">crackalaka-hashstrcmp-dos(15824)</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/10092" adv="1">10092</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/11340" adv="1">11340</ref>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108152479316967&amp;w=2" adv="1">20040409 DoS in Crackalaka 1.0.8</ref>
        </refs>
        <vuln_soft>
            <prod vendor="crackalaka" name="crackalaka">
                <vers num="1.0.8" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" name="CVE-2004-1920" seq="2004-1920" severity="High" type="CVE" published="2004-04-10" CVSS_version="2.0 incomplete approximation" CVSS_score="7.5" modified="2008-09-05">
        <desc>
            <descript source="cve">X-Micro WLAN 11b Broadband Router 1.2.2, 1.2.2.3, 1.2.2.4, and 1.6.0.0 has a hardcoded "super" username and password, which could allow remote attackers to gain access.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot other="1" />
        </loss_types>
        <vuln_types>
            <design />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="BID" patch="1" url="http://www.securityfocus.com/bid/10095" adv="1">10095</ref>
            <ref source="BUGTRAQ" patch="1" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108162529229947&amp;w=2" adv="1">20040410 Backdoor in X-Micro WLAN 11b Broadband Router</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/15829" adv="1">xmicro-router-default-account(15829)</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/11342" adv="1">11342</ref>
        </refs>
        <vuln_soft>
            <prod vendor="x-micro" name="wlan_11b_broadband_router_firmware">
                <vers num="1.2.2" />
                <vers num="1.2.2.3" />
                <vers num="1.2.2.4" />
                <vers num="1.6.0" />
                <vers num="1.6.0.1" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" name="CVE-2004-1921" seq="2004-1921" severity="High" type="CVE" published="2004-04-10" CVSS_version="2.0 incomplete approximation" CVSS_score="7.5" modified="2008-09-05">
        <desc>
            <descript source="cve">X-Micro WLAN 11b Broadband Router 1.6.0.1 has a hardcoded "1502" username and password, which could allow remote attackers to gain access.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot other="1" />
        </loss_types>
        <vuln_types>
            <design />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="XF" patch="1" url="http://xforce.iss.net/xforce/xfdb/15890" adv="1">xmicro-router-default-login(15890)</ref>
            <ref source="BID" patch="1" url="http://www.securityfocus.com/bid/10095" adv="1">10095</ref>
            <ref source="BUGTRAQ" patch="1" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108223222519855&amp;w=2" adv="1">20040416 NEW backdoor in X-Micro WLAN 11b Broadband Router</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/11342" adv="1">11342</ref>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108213608111111&amp;w=2" adv="1">20040416 Re: Backdoor in X-Micro WLAN 11b Broadband Router</ref>
        </refs>
        <vuln_soft>
            <prod vendor="x-micro" name="wlan_11b_broadband_router_firmware">
                <vers num="1.2.2" />
                <vers num="1.2.2.3" />
                <vers num="1.2.2.4" />
                <vers num="1.6.0" />
                <vers num="1.6.0.1" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:N/A:P)" CVSS_base_score="2.6" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="2.9" name="CVE-2004-1922" seq="2004-1922" severity="Low" type="CVE" published="2004-04-11" CVSS_version="2.0 incomplete approximation" CVSS_score="2.6" modified="2008-09-05">
        <desc>
            <descript source="cve">Microsoft Internet Explorer 5.5 and 6.0 allocates memory based on the memory size written in the BMP file instead of the actual BMP file size, which allows remote attackers to cause a denial of service (memory consumption) via a small BMP file with has a large memory size.</descript>
        </desc>
        <loss_types>
            <avail />
        </loss_types>
        <vuln_types>
            <design />
        </vuln_types>
        <range>
            <network />
            <user_init />
        </range>
        <refs>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108183130827872&amp;w=2" adv="1">20040411 Microsoft Internet Explorer BMP file memory DoS vulnerability</ref>
        </refs>
        <vuln_soft>
            <prod vendor="microsoft" name="ie">
                <vers num="5.5" />
                <vers num="6.0" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" name="CVE-2004-1923" seq="2004-1923" severity="Medium" type="CVE" published="2004-04-11" CVSS_version="2.0 incomplete approximation" CVSS_score="5.0" modified="2008-09-05">
        <desc>
            <descript source="cve">Tiki CMS/Groupware (TikiWiki) 1.8.1 and earlier allows remote attackers to gain sensitive information via a direct request to (1) banner_click.php, (2) categorize.php, (3) tiki-admin_include_directory.php, (4) tiki-directory_search.php, which reveal the web server path in an error message.</descript>
        </desc>
        <loss_types>
            <conf />
        </loss_types>
        <vuln_types>
            <input />
            <exception />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="XF" patch="1" url="http://xforce.iss.net/xforce/xfdb/15847" adv="1">tikiwiki-path-disclosure(15847)</ref>
            <ref source="BID" patch="1" url="http://www.securityfocus.com/bid/10100" adv="1">10100</ref>
            <ref source="CONFIRM" patch="1" url="http://tikiwiki.org/tiki-read_article.php?articleId=66">http://tikiwiki.org/tiki-read_article.php?articleId=66</ref>
            <ref source="BUGTRAQ" patch="1" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108180073206947&amp;w=2" adv="1">20040412 Multiple Vulnerabilities In Tiki CMS/Groupware [ TikiWiki ]</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/11344" adv="1">11344</ref>
        </refs>
    </entry>
    <entry CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" name="CVE-2004-1924" seq="2004-1924" severity="Medium" type="CVE" published="2004-04-11" CVSS_version="2.0 incomplete approximation" CVSS_score="4.3" modified="2008-09-05">
        <desc>
            <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in Tiki CMS/Groupware (TikiWiki) 1.8.1 and earlier allow remote attackers to inject arbitrary web script or HTML via via the (1) theme parameter to tiki-switch_theme.php, (2) find and priority parameters to messu-mailbox.php, (3) flag, priority, flagval, sort_mode, or find parameters to messu-read.php, (4) articleId parameter to tiki-read_article.php, (5) parentId parameter to tiki-browse_categories.php, (6) comments_threshold parameter to tiki-index.php (7) articleId parameter to tiki-print_article.php, (8) galleryId parameter to tiki-list_file_gallery.php, (9) galleryId parameter to tiki-upload_file.php, (10) faqId parameter to tiki-view_faq.php, (11) chartId parameter to tiki-view_chart.php, or (12) surveyId parameter to tiki-survey_stats_survey.php.</descript>
        </desc>
        <loss_types>
            <int />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="XF" patch="1" url="http://xforce.iss.net/xforce/xfdb/15846" adv="1">tikiwiki-xss(15846)</ref>
            <ref source="BID" patch="1" url="http://www.securityfocus.com/bid/10100" adv="1">10100</ref>
            <ref source="CONFIRM" patch="1" url="http://tikiwiki.org/tiki-read_article.php?articleId=66">http://tikiwiki.org/tiki-read_article.php?articleId=66</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/11344" adv="1">11344</ref>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108180073206947&amp;w=2" adv="1">20040412 Multiple Vulnerabilities In Tiki CMS/Groupware [ TikiWiki ]</ref>
        </refs>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" name="CVE-2004-1926" seq="2004-1926" severity="Medium" type="CVE" published="2004-04-11" CVSS_version="2.0 incomplete approximation" CVSS_score="5.0" modified="2008-09-05">
        <desc>
            <descript source="cve">Tiki CMS/Groupware (TikiWiki) 1.8.1 and earlier allows remote attackers to inject arbitrary code via the (1) Theme, (2) Country, (3) Real Name, or (4) Displayed time zone fields in a User Profile, or the (5) Name, (6) Description, (7) URL, or (8) Country fields in a Directory/Add Site operation.</descript>
        </desc>
        <loss_types>
            <int />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="BID" patch="1" url="http://www.securityfocus.com/bid/10100" adv="1">10100</ref>
            <ref source="CONFIRM" patch="1" url="http://tikiwiki.org/tiki-read_article.php?articleId=66">http://tikiwiki.org/tiki-read_article.php?articleId=66</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/11344" adv="1">11344</ref>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108180073206947&amp;w=2" adv="1">20040412 Multiple Vulnerabilities In Tiki CMS/Groupware [ TikiWiki ]</ref>
        </refs>
        <vuln_soft>
            <prod vendor="tikiwiki_project" name="tikiwiki">
                <vers num="1.8" />
                <vers num="1.8.1" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" name="CVE-2004-1927" seq="2004-1927" severity="Medium" type="CVE" published="2004-04-11" CVSS_version="2.0 incomplete approximation" CVSS_score="5.0" modified="2008-09-05">
        <desc>
            <descript source="cve">Directory traversal vulnerability in the map feature (tiki-map.phtml) in Tiki CMS/Groupware (TikiWiki) 1.8.1 and earlier allows remote attackers to determine the existence of arbitrary files via .. (dot dot) sequences in the mapfile parameter.</descript>
        </desc>
        <loss_types>
            <conf />
        </loss_types>
        <vuln_types>
            <access />
            <input />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="XF" patch="1" url="http://xforce.iss.net/xforce/xfdb/15848" adv="1">tikiwiki-tikimap-file-disclosure(15848)</ref>
            <ref source="BID" patch="1" url="http://www.securityfocus.com/bid/10100" adv="1">10100</ref>
            <ref source="CONFIRM" patch="1" url="http://tikiwiki.org/tiki-read_article.php?articleId=66">http://tikiwiki.org/tiki-read_article.php?articleId=66</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/11344" adv="1">11344</ref>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108180073206947&amp;w=2" adv="1">20040412 Multiple Vulnerabilities In Tiki CMS/Groupware [ TikiWiki ]</ref>
        </refs>
        <vuln_soft>
            <prod vendor="tikiwiki_project" name="tikiwiki">
                <vers num="1.8" />
                <vers num="1.8.1" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" name="CVE-2004-1060" seq="2004-1060" severity="Medium" type="CVE" published="2004-04-12" CVSS_version="2.0 incomplete approximation" CVSS_score="5.0" modified="2009-03-04">
        <desc>
            <descript source="cve">Multiple TCP/IP and ICMP implementations, when using Path MTU (PMTU) discovery (PMTUD), allow remote attackers to cause a denial of service (network throughput reduction for TCP connections) via forged ICMP ("Fragmentation Needed and Don't Fragment was Set") packets with a low next-hop MTU value, aka the "Path MTU discovery attack."  NOTE: CVE-2004-0790, CVE-2004-0791, and CVE-2004-1060 have been SPLIT based on different attacks; CVE-2005-0065, CVE-2005-0066, CVE-2005-0067, and CVE-2005-0068 are related identifiers that are SPLIT based on the underlying vulnerability.  While CVE normally SPLITs based on vulnerability, the attack-based identifiers exist due to the variety and number of affected implementations and solutions that address the attacks instead of the underlying vulnerabilities.</descript>
        </desc>
        <loss_types>
            <avail />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="MS" patch="1" url="http://www.microsoft.com/technet/security/bulletin/ms05-019.mspx" adv="1">MS05-019</ref>
            <ref source="MISC" url="http://www.uniras.gov.uk/niscc/docs/al-20050412-00308.html?lang=en" adv="1">http://www.uniras.gov.uk/niscc/docs/al-20050412-00308.html?lang=en</ref>
            <ref source="MISC" url="http://www.gont.com.ar/drafts/icmp-attacks-against-tcp.html" adv="1">http://www.gont.com.ar/drafts/icmp-attacks-against-tcp.html</ref>
            <ref source="CISCO" url="http://www.cisco.com/warp/public/707/cisco-sa-20050412-icmp.shtml" adv="1">20050412 Crafted ICMP Messages Can Cause Denial of Service</ref>
            <ref source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5386">oval:org.mitre.oval:def:5386</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/13124">13124</ref>
            <ref source="HP" url="http://www.securityfocus.com/archive/1/archive/1/418882/100/0/threaded">HPSBUX01164</ref>
            <ref source="SREASON" url="http://securityreason.com/securityalert/57">57</ref>
            <ref source="SREASON" url="http://securityreason.com/securityalert/19">19</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/18317">18317</ref>
            <ref source="HP" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112861397904255&amp;w=2">SSRT4884</ref>
            <ref source="SCO" url="ftp://ftp.sco.com/pub/updates/OpenServer/SCOSA-2006.4/SCOSA-2006.4.txt">SCOSA-2006.4</ref>
            <ref source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:899" sig="1">oval:org.mitre.oval:def:899</ref>
            <ref source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:780" sig="1">oval:org.mitre.oval:def:780</ref>
            <ref source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:651" sig="1">oval:org.mitre.oval:def:651</ref>
            <ref source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:405" sig="1">oval:org.mitre.oval:def:405</ref>
            <ref source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:3826" sig="1">oval:org.mitre.oval:def:3826</ref>
            <ref source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2188" sig="1">oval:org.mitre.oval:def:2188</ref>
            <ref source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:196" sig="1">oval:org.mitre.oval:def:196</ref>
            <ref source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:181" sig="1">oval:org.mitre.oval:def:181</ref>
        </refs>
        <vuln_soft>
            <prod vendor="icmp" name="icmp">
                <vers num="" />
            </prod>
            <prod vendor="tcp" name="tcp">
                <vers num="" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" name="CVE-2004-1928" seq="2004-1928" severity="High" type="CVE" published="2004-04-12" CVSS_version="2.0 incomplete approximation" CVSS_score="7.5" modified="2008-09-05">
        <desc>
            <descript source="cve">The image upload feature in Tiki CMS/Groupware (TikiWiki) 1.8.1 and earlier allows remote attackers to upload and possibly execute arbitrary files via the img/wiki_up URL.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="XF" patch="1" url="http://xforce.iss.net/xforce/xfdb/15849" adv="1">tikiwiki-file-upload(15849)</ref>
            <ref source="BID" patch="1" url="http://www.securityfocus.com/bid/10100" adv="1">10100</ref>
            <ref source="CONFIRM" patch="1" url="http://tikiwiki.org/tiki-read_article.php?articleId=66" adv="1">http://tikiwiki.org/tiki-read_article.php?articleId=66</ref>
            <ref source="SECUNIA" patch="1" url="http://secunia.com/advisories/11344" adv="1">11344</ref>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108180073206947&amp;w=2" adv="1">20040412 Multiple Vulnerabilities In Tiki CMS/Groupware [ TikiWiki ]</ref>
        </refs>
        <vuln_soft>
            <prod vendor="tikiwiki_project" name="tikiwiki">
                <vers num="1.8" />
                <vers num="1.8.1" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" name="CVE-2004-1930" seq="2004-1930" severity="Medium" type="CVE" published="2004-04-12" CVSS_version="2.0 incomplete approximation" CVSS_score="4.3" modified="2008-09-05">
        <desc>
            <descript source="cve">Cross-site scripting (XSS) vulnerability in the cookiedecode function in mainfile.php for PHP-Nuke 6.x through 7.2, when themes are used, allows remote attackers to inject arbitrary web script or HTML via a base64-encoded user parameter or cookie.</descript>
        </desc>
        <loss_types>
            <int />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/15842" adv="1">phpnuke-cookiedecode-xss(15842)</ref>
            <ref source="MISC" url="http://www.waraxe.us/index.php?modname=sa&amp;id=16" adv="1">http://www.waraxe.us/index.php?modname=sa&amp;id=16</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/10128" adv="1">10128</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/11347" adv="1">11347</ref>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108182759214035&amp;w=2" adv="1">20040412 [waraxe-2004-SA#016 - Cross-Site Scripting aka XSS in phpnuke 6.x-7.2 part 3]</ref>
        </refs>
        <vuln_soft>
            <prod vendor="francisco_burzi" name="php-nuke">
                <vers num="6.0" />
                <vers num="6.5" />
                <vers num="6.5_beta1" />
                <vers num="6.5_final" />
                <vers num="6.5_rc1" />
                <vers num="6.5_rc2" />
                <vers num="6.5_rc3" />
                <vers num="6.6" />
                <vers num="6.7" />
                <vers num="6.9" />
                <vers num="7.0" />
                <vers num="7.0_final" />
                <vers num="7.1" />
                <vers num="7.2" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" name="CVE-2004-1932" seq="2004-1932" severity="High" type="CVE" published="2004-04-12" CVSS_version="2.0 incomplete approximation" CVSS_score="7.5" modified="2008-09-05">
        <desc>
            <descript source="cve">SQL injection vulnerability in (1) auth.php and (2) admin.php in PHP-Nuke 6.x through 7.2 allows remote attackers to execute arbitrary SQL code and create an administrator account via base64-encoded SQL in the admin parameter.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot other="1" />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/15835" adv="1">phpnuke-admin-bypass-authentication(15835)</ref>
            <ref source="MISC" url="http://www.waraxe.us/index.php?modname=sa&amp;id=18" adv="1">http://www.waraxe.us/index.php?modname=sa&amp;id=18</ref>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108180334918576&amp;w=2" adv="1">20040412 [waraxe-2004-SA#018 - Admin-level authentication bypass in phpnuke 6.x-7.2]</ref>
        </refs>
        <vuln_soft>
            <prod vendor="francisco_burzi" name="php-nuke">
                <vers num="6.0" />
                <vers num="6.5" />
                <vers num="6.5_beta1" />
                <vers num="6.5_final" />
                <vers num="6.5_rc1" />
                <vers num="6.5_rc2" />
                <vers num="6.5_rc3" />
                <vers num="6.6" />
                <vers num="6.7" />
                <vers num="6.9" />
                <vers num="7.0" />
                <vers num="7.0_final" />
                <vers num="7.1" />
                <vers num="7.2" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" name="CVE-2004-1933" seq="2004-1933" severity="Low" type="CVE" published="2004-04-12" CVSS_version="2.0 incomplete approximation" CVSS_score="2.1" modified="2008-09-05">
        <desc>
            <descript source="cve">Citadel/UX 5.00 through 6.14 installs the database directory and files with world-read permissions, which could allow local users to bypass access controls and read unauthorized messages.</descript>
        </desc>
        <loss_types>
            <conf />
        </loss_types>
        <vuln_types>
            <access />
            <config />
        </vuln_types>
        <range>
            <local />
        </range>
        <refs>
            <ref source="XF" patch="1" url="http://xforce.iss.net/xforce/xfdb/15850" adv="1">citadel-database-insecure-permissions(15850)</ref>
            <ref source="BID" patch="1" url="http://www.securityfocus.com/bid/10102" adv="1">10102</ref>
            <ref source="BUGTRAQ" patch="1" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108180024428804&amp;w=2" adv="1">20040412 Citadel/UX 6.20 fixes local permissions vulnerability</ref>
        </refs>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" name="CVE-2004-1925" seq="2004-1925" severity="High" type="CVE" published="2004-04-12" CVSS_version="2.0 incomplete approximation" CVSS_score="7.5" modified="2008-09-05">
        <desc>
            <descript source="cve">Multiple SQL injection vulnerabilities in Tiki CMS/Groupware (TikiWiki) 1.8.1 and earlier allow remote attackers to execute arbitrary SQL commands via the sort_mode parameter in (1) tiki-usermenu.php, (2) tiki-list_file_gallery.php, (3) tiki-directory_ranking.php, (4) tiki-browse_categories.php, (5) tiki-index.php, (6) tiki-user_tasks.php, (7) tiki-directory_ranking.php, (8) tiki-directory_search.php, (9) tiki-file_galleries.php, (10) tiki-list_faqs.php, (11) tiki-list_trackers.php, (12) tiki-list_blogs.php, or via the offset parameter in (13) tiki-usermenu.php, (14) tiki-browse_categories.php, (15) tiki-index.php, (16) tiki-user_tasks.php, (17) tiki-list_faqs.php, (18) tiki-list_trackers.php, or (19) tiki-list_blogs.php.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot other="1" />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="XF" patch="1" url="http://xforce.iss.net/xforce/xfdb/15845" adv="1">tikiwiki-sql-injection(15845)</ref>
            <ref source="BID" patch="1" url="http://www.securityfocus.com/bid/10100" adv="1">10100</ref>
            <ref source="CONFIRM" patch="1" url="http://tikiwiki.org/tiki-read_article.php?articleId=66" adv="1">http://tikiwiki.org/tiki-read_article.php?articleId=66</ref>
            <ref source="SECUNIA" patch="1" url="http://secunia.com/advisories/11344" adv="1">11344</ref>
            <ref source="BUGTRAQ" patch="1" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108180073206947&amp;w=2" adv="1">20040411 Multiple Vulnerabilities In Tiki CMS/Groupware [ TikiWiki ]</ref>
        </refs>
        <vuln_soft>
            <prod vendor="tikiwiki_project" name="tikiwiki">
                <vers num="1.8" />
                <vers num="1.8.1" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" name="CVE-2004-1929" seq="2004-1929" severity="High" type="CVE" published="2004-04-13" CVSS_version="2.0 incomplete approximation" CVSS_score="7.5" modified="2008-09-05">
        <desc>
            <descript source="cve">SQL injection vulnerability in the bblogin function in functions.php in PHP-Nuke 6.x through 7.2 allows remote attackers to bypass authentication and gain access by injecting base64-encoded SQL code into the user parameter.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot other="1" />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/15839" adv="1">phpnuke-bypass-authentication(15839)</ref>
            <ref source="MISC" url="http://www.waraxe.us/index.php?modname=sa&amp;id=17" adv="1">http://www.waraxe.us/index.php?modname=sa&amp;id=17</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/10135" adv="1">10135</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/11347" adv="1">11347</ref>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108180111826852&amp;w=2" adv="1">20040412 [waraxe-2004-SA#017 - User-level authentication bypass in phpnuke 6.x-7.2]</ref>
        </refs>
        <vuln_soft>
            <prod vendor="francisco_burzi" name="php-nuke">
                <vers num="5.5" />
                <vers num="6.0" />
                <vers num="6.5" />
                <vers num="6.5_beta1" />
                <vers num="6.5_final" />
                <vers num="6.5_rc1" />
                <vers num="6.5_rc2" />
                <vers num="6.5_rc3" />
                <vers num="6.6" />
                <vers num="6.7" />
                <vers num="6.9" />
                <vers num="7.0" />
                <vers num="7.0_final" />
                <vers num="7.1" />
                <vers num="7.2" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" name="CVE-2004-1756" seq="2004-1756" severity="Medium" type="CVE" published="2004-04-13" CVSS_version="2.0 incomplete approximation" CVSS_score="5.0" modified="2008-09-05">
        <desc>
            <descript source="cve">BEA WebLogic Server and WebLogic Express 8.1 SP2 and earlier, and 7.0 SP4 and earlier, when using 2-way SSL with a custom trust manager, may accept a certificate chain even if the trust manager rejects it, which allows remote attackers to spoof other users or servers.</descript>
        </desc>
        <loss_types>
            <int />
        </loss_types>
        <vuln_types>
            <access />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="CERT-VN" patch="1" url="http://www.kb.cert.org/vuls/id/566390" adv="1">VU#566390</ref>
            <ref source="XF" patch="1" url="http://xforce.iss.net/xforce/xfdb/15862" adv="1">weblogic-trust-certificate-spoofing(15862)</ref>
            <ref source="BID" patch="1" url="http://www.securityfocus.com/bid/10132" adv="1">10132</ref>
            <ref source="SECTRACK" patch="1" url="http://securitytracker.com/id?1009765" adv="1">1009765</ref>
            <ref source="SECUNIA" patch="1" url="http://secunia.com/advisories/11358" adv="1">11358</ref>
            <ref source="CONFIRM" patch="1" url="http://dev2dev.bea.com/resourcelibrary/advisoriesnotifications/BEA04_54.00.jsp" adv="1">http://dev2dev.bea.com/resourcelibrary/advisoriesnotifications/BEA04_54.00.jsp</ref>
        </refs>
        <vuln_soft>
            <prod vendor="bea" name="weblogic_server">
                <vers edition="" num="7.0" />
                <vers edition=":win32" num="7.0" />
                <vers edition=":express" num="7.0" />
                <vers edition="sp1" num="7.0" />
                <vers edition="sp1:express" num="7.0" />
                <vers edition="sp2" num="7.0" />
                <vers edition="sp2:express" num="7.0" />
                <vers edition="sp3" num="7.0" />
                <vers edition="sp3:express" num="7.0" />
                <vers edition="sp4" num="7.0" />
                <vers edition="sp4:win32" num="7.0" />
                <vers edition="sp4:express" num="7.0" />
                <vers edition="" num="8.1" />
                <vers edition=":express" num="8.1" />
                <vers edition=":win32" num="8.1" />
                <vers edition="sp1" num="8.1" />
                <vers edition="sp1:express" num="8.1" />
                <vers edition="sp1:win32" num="8.1" />
                <vers edition="sp2" num="8.1" />
                <vers edition="sp2:win32" num="8.1" />
                <vers edition="sp2:express" num="8.1" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" name="CVE-2004-1758" seq="2004-1758" severity="Medium" type="CVE" published="2004-04-13" CVSS_version="2.0 incomplete approximation" CVSS_score="4.6" modified="2008-09-05">
        <desc>
            <descript source="cve">BEA WebLogic Server and WebLogic Express version 8.1 up to SP2, 7.0 up to SP4, and 6.1 up to SP6 may store the database username and password for an untargeted JDBC connection pool in plaintext in config.xml, which allows local users to gain privileges.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
        </loss_types>
        <vuln_types>
            <design />
        </vuln_types>
        <range>
            <local />
        </range>
        <refs>
            <ref source="CERT-VN" patch="1" url="http://www.kb.cert.org/vuls/id/920238" adv="1">VU#920238</ref>
            <ref source="XF" patch="1" url="http://xforce.iss.net/xforce/xfdb/15860" adv="1">bea-configxml-plaintext-password(15860)</ref>
            <ref source="BID" patch="1" url="http://www.securityfocus.com/bid/10131" adv="1">10131</ref>
            <ref source="CONFIRM" patch="1" url="http://dev2dev.bea.com/resourcelibrary/advisoriesnotifications/BEA04_53.00.jsp" adv="1">http://dev2dev.bea.com/resourcelibrary/advisoriesnotifications/BEA04_53.00.jsp</ref>
            <ref source="OSVDB" url="http://www.osvdb.org/5297">5297</ref>
            <ref source="SECTRACK" url="http://securitytracker.com/id?1009764">1009764</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/11357">11357</ref>
        </refs>
        <vuln_soft>
            <prod vendor="bea" name="weblogic_server">
                <vers edition="" num="6.1" />
                <vers edition=":express" num="6.1" />
                <vers edition=":win32" num="6.1" />
                <vers edition="sp1" num="6.1" />
                <vers edition="sp1:express" num="6.1" />
                <vers edition="sp1:win32" num="6.1" />
                <vers edition="sp2" num="6.1" />
                <vers edition="sp2:win32" num="6.1" />
                <vers edition="sp2:express" num="6.1" />
                <vers edition="sp3" num="6.1" />
                <vers edition="sp3:express" num="6.1" />
                <vers edition="sp4" num="6.1" />
                <vers edition="sp4:express" num="6.1" />
                <vers edition="sp5" num="6.1" />
                <vers edition="sp5:express" num="6.1" />
                <vers edition="sp6" num="6.1" />
                <vers edition="" num="7.0" />
                <vers edition=":express" num="7.0" />
                <vers edition=":win32" num="7.0" />
                <vers edition="sp1" num="7.0" />
                <vers edition="sp1:express" num="7.0" />
                <vers edition="sp2" num="7.0" />
                <vers edition="sp2:express" num="7.0" />
                <vers edition="sp3" num="7.0" />
                <vers edition="sp3:express" num="7.0" />
                <vers edition="sp4" num="7.0" />
                <vers edition="sp4:express" num="7.0" />
                <vers edition="sp4:win32" num="7.0" />
                <vers edition="" num="8.1" />
                <vers edition=":express" num="8.1" />
                <vers edition=":win32" num="8.1" />
                <vers edition="sp1" num="8.1" />
                <vers edition="sp1:win32" num="8.1" />
                <vers edition="sp1:express" num="8.1" />
                <vers edition="sp2" num="8.1" />
                <vers edition="sp2:win32" num="8.1" />
                <vers edition="sp2:express" num="8.1" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" name="CVE-2004-1936" seq="2004-1936" severity="High" type="CVE" published="2004-04-14" CVSS_version="2.0 incomplete approximation" CVSS_score="7.5" modified="2008-09-05">
        <desc>
            <descript source="cve">ZoneAlarm Pro 4.5.538.001 and possibly other versions allows remote attackers to bypass e-mail protection via attachments whose names contain certain non-English characters.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
        </loss_types>
        <vuln_types>
            <exception />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/15884">zonealarm-email-bypass-security(15884)</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/10148">10148</ref>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108248415509417&amp;w=2" adv="1">20040420 Re: ZA Security Hole</ref>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108206751931251&amp;w=2" adv="1">20040414 ZA Security Hole</ref>
        </refs>
        <vuln_soft>
            <prod vendor="zonelabs" name="zonealarm">
                <vers edition="" num="2.4" />
                <vers edition=":pro" num="2.4" />
                <vers edition="" num="2.6" />
                <vers edition=":pro" num="2.6" />
                <vers edition="" num="3.0" />
                <vers edition=":pro" num="3.0" />
                <vers edition="" num="3.1" />
                <vers edition=":pro" num="3.1" />
                <vers edition="" num="4.0" />
                <vers edition=":pro" num="4.0" />
                <vers edition=":plus" num="4.0" />
                <vers edition="" num="4.5" />
                <vers edition=":pro" num="4.5" />
                <vers edition="" num="4.5.538.001" />
                <vers edition=":pro" num="4.5.538.001" />
                <vers edition=":plus" num="4.5.538.001" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" name="CVE-2004-1939" seq="2004-1939" severity="Medium" type="CVE" published="2004-04-14" CVSS_version="2.0 incomplete approximation" CVSS_score="4.3" modified="2008-09-05">
        <desc>
            <descript source="cve">Cross-site scripting (XSS) vulnerability in Zaep AntiSpam 2.0 allows remote attackers to inject arbitrary web script or HTML via double encoded slashes (%252F) in the key parameter.</descript>
        </desc>
        <loss_types>
            <int />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="XF" patch="1" url="http://xforce.iss.net/xforce/xfdb/15858">zaep-antispam-xss(15858)</ref>
            <ref source="BID" patch="1" url="http://www.securityfocus.com/bid/10139">10139</ref>
            <ref source="MISC" patch="1" url="http://www.securiteam.com/windowsntfocus/5EP0I15CKK.html" adv="1">http://www.securiteam.com/windowsntfocus/5EP0I15CKK.html</ref>
            <ref source="SECUNIA" patch="1" url="http://secunia.com/advisories/11388" adv="1">11388</ref>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108241507812681&amp;w=2" adv="1">20040419 Zaep AntiSpam Cross Site Scripting</ref>
        </refs>
        <vuln_soft>
            <prod vendor="rhinosoft" name="zaep_antispam">
                <vers num="2.0" />
                <vers num="2.0_.0.1" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" name="CVE-2004-1944" seq="2004-1944" severity="Medium" type="CVE" published="2004-04-14" CVSS_version="2.0 incomplete approximation" CVSS_score="5.0" modified="2008-09-05">
        <desc>
            <descript source="cve">Eudora 6.1 and 6.0.3 for Windows allows remote attackers to cause a denial of service (crash) via a deeply nested multipart MIME message.</descript>
        </desc>
        <loss_types>
            <avail />
        </loss_types>
        <vuln_types>
            <exception />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/15857" adv="1">eudora-mime-message-dos(15857)</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/10137" adv="1">10137</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/11360" adv="1">11360</ref>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108241694627321&amp;w=2" adv="1">20040419 Eudora 6.1 is evil</ref>
            <ref source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2004-April/020075.html" adv="1">20040414 Eudora 6.0.3 nested MIME DoS</ref>
        </refs>
        <vuln_soft>
            <prod vendor="qualcomm" name="eudora">
                <vers num="6.0.3" />
                <vers num="6.1" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" name="CVE-2004-0150" seq="2004-0150" severity="High" type="CVE" published="2004-04-15" CVSS_version="2.0 incomplete approximation" CVSS_score="7.5" modified="2008-09-10">
        <desc>
            <descript source="cve">Buffer overflow in the getaddrinfo function in Python 2.2 before 2.2.2, when IPv6 support is disabled, allows remote attackers to execute arbitrary code via an IPv6 address that is obtained using DNS.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot other="1" />
        </loss_types>
        <vuln_types>
            <input bound="1" />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="BID" patch="1" url="http://www.securityfocus.com/bid/9836" adv="1">9836</ref>
            <ref source="DEBIAN" patch="1" url="http://www.debian.org/security/2004/dsa-458" adv="1">DSA-458</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/15409">python-getaddrinfo-bo(15409)</ref>
            <ref source="OSVDB" url="http://www.osvdb.org/4172">4172</ref>
            <ref source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2004:019">MDKSA-2004:019</ref>
            <ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200409-03.xml">GLSA-200409-03</ref>
        </refs>
        <vuln_soft>
            <prod vendor="python_software_foundation" name="python">
                <vers num="2.2" />
                <vers num="2.2.1" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" name="CVE-2004-0151" seq="2004-0151" severity="High" type="CVE" published="2004-04-15" CVSS_version="2.0 incomplete approximation" CVSS_score="7.2" modified="2008-09-05">
        <desc>
            <descript source="cve">Unknown vulnerability in xitalk 1.1.11 and earlier allows local users to execute arbitrary commands.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot admin="1" />
        </loss_types>
        <vuln_types>
            <design />
        </vuln_types>
        <range>
            <local />
        </range>
        <refs>
            <ref source="XF" patch="1" url="http://xforce.iss.net/xforce/xfdb/15456" adv="1">xitalk-gain-privileges(15456)</ref>
            <ref source="BID" patch="1" url="http://www.securityfocus.com/bid/9851" adv="1">9851</ref>
            <ref source="DEBIAN" patch="1" url="http://www.debian.org/security/2004/dsa-462" adv="1">DSA-462</ref>
            <ref source="MISC" url="http://shellcode.org/Advisories/XITALK.txt">http://shellcode.org/Advisories/XITALK.txt</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/11114/">11114</ref>
        </refs>
        <vuln_soft>
            <prod vendor="xintercepttalk" name="xitalk">
                <vers num="1.1.11" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" name="CVE-2004-0152" seq="2004-0152" severity="High" type="CVE" published="2004-04-15" CVSS_version="2.0 incomplete approximation" CVSS_score="7.5" modified="2008-09-05">
        <desc>
            <descript source="cve">Multiple stack-based buffer overflows in (1) the encode_mime function, (2) the encode_uuencode function, (3) or the decode_uuencode function for emil 2.1.0 and earlier allow remote attackers to execute arbitrary code via e-mail messages containing attachments with filenames.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot other="1" />
        </loss_types>
        <vuln_types>
            <input buffer="1" />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="DEBIAN" patch="1" url="http://www.debian.org/security/2004/dsa-468" adv="1">DSA-468</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/15601" adv="1">emil-email-bo(15601)</ref>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108024939827236&amp;w=2" adv="1">20040325 Re: [SECURITY] [DSA 468-1] New emil packages fix multiple vulnerabilities</ref>
        </refs>
        <vuln_soft>
            <prod vendor="emil" name="emil">
                <vers num="2.0.4" />
                <vers num="2.0.5" />
                <vers num="2.1.0_beta9" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" name="CVE-2004-0153" seq="2004-0153" severity="High" type="CVE" published="2004-04-15" CVSS_version="2.0 incomplete approximation" CVSS_score="7.5" modified="2008-09-05">
        <desc>
            <descript source="cve">Multiple format string vulnerabilities in emil 2.1.0 and earlier may allow remote attackers to execute arbitrary code by triggering certain error messages.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot other="1" />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="DEBIAN" patch="1" url="http://www.debian.org/security/2004/dsa-468" adv="1">DSA-468</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/15602" adv="1">emil-format-string(15602)</ref>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108024939827236&amp;w=2" adv="1">20040325 Re: [SECURITY] [DSA 468-1] New emil packages fix multiple vulnerabilities</ref>
        </refs>
        <vuln_soft>
            <prod vendor="emil" name="emil">
                <vers num="2.0.4" />
                <vers num="2.0.5" />
                <vers num="2.1.0_beta9" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" name="CVE-2004-0173" seq="2004-0173" severity="Medium" type="CVE" published="2004-04-15" CVSS_version="2.0 incomplete approximation" CVSS_score="5.0" modified="2008-09-10">
        <desc>
            <descript source="cve">Directory traversal vulnerability in Apache 1.3.29 and earlier, and Apache 2.0.48 and earlier, when running on Cygwin, allows remote attackers to read arbitrary files via a URL containing "..%5C" (dot dot encoded backslash) sequences.</descript>
        </desc>
        <loss_types>
            <conf />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="XF" patch="1" url="http://xforce.iss.net/xforce/xfdb/15293" adv="1">apache-cygwin-directory-traversal(15293)</ref>
            <ref source="BID" patch="1" url="http://www.securityfocus.com/bid/9733" adv="1">9733</ref>
            <ref source="CONFIRM" url="http://www.apacheweek.com/issues/04-03-12">http://www.apacheweek.com/issues/04-03-12</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/10962">10962</ref>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107765545431387&amp;w=2">20040224 STG Security Advisory: [SSA-20040217-06] Apache for cygwin</ref>
            <ref source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2004-February/017740.html">20040224 STG Security Advisory: [SSA-20040217-06] Apache for cygwin directory traversal vulnerability</ref>
            <ref source="CONFIRM" url="http://issues.apache.org/bugzilla/show_bug.cgi?id=26152">http://issues.apache.org/bugzilla/show_bug.cgi?id=26152</ref>
        </refs>
        <vuln_soft>
            <prod vendor="apache" name="http_server">
                <vers num="0.8.11" />
                <vers num="0.8.14" />
                <vers num="1.0" />
                <vers num="1.0.2" />
                <vers num="1.0.3" />
                <vers num="1.0.5" />
                <vers num="1.1" />
                <vers num="1.1.1" />
                <vers num="1.2" />
                <vers num="1.2.5" />
                <vers num="1.3" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" name="CVE-2004-0148" seq="2004-0148" severity="High" type="CVE" published="2004-04-15" CVSS_version="2.0 incomplete approximation" CVSS_score="7.2" modified="2008-09-05">
        <desc>
            <descript source="cve">wu-ftpd 2.6.2 and earlier, with the restricted-gid option enabled, allows local users to bypass access restrictions by changing the permissions to prevent access to their home directory, which causes wu-ftpd to use the root directory instead.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot admin="1" />
        </loss_types>
        <vuln_types>
            <access />
        </vuln_types>
        <range>
            <local />
        </range>
        <refs>
            <ref source="BID" patch="1" url="http://www.securityfocus.com/bid/9832" adv="1">9832</ref>
            <ref source="REDHAT" patch="1" url="http://www.redhat.com/support/errata/RHSA-2004-096.html" adv="1">RHSA-2004:096</ref>
            <ref source="DEBIAN" patch="1" url="http://www.debian.org/security/2004/dsa-457" adv="1">DSA-457</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/15423">wuftpd-restrictedgid-gain-access(15423)</ref>
            <ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1867">ADV-2006-1867</ref>
            <ref source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-102356-1">102356</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/20168">20168</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/11055">11055</ref>
            <ref source="HP" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108999466902690&amp;w=2">SSRT4704</ref>
            <ref source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:648" sig="1">oval:org.mitre.oval:def:648</ref>
            <ref source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1637" sig="1">oval:org.mitre.oval:def:1637</ref>
            <ref source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1636" sig="1">oval:org.mitre.oval:def:1636</ref>
            <ref source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1147" sig="1">oval:org.mitre.oval:def:1147</ref>
        </refs>
        <vuln_soft>
            <prod vendor="sgi" name="propack">
                <vers num="2.3" />
                <vers num="2.4" />
            </prod>
            <prod vendor="washington_university" name="wu-ftpd">
                <vers num="2.4.1" />
                <vers edition="" num="2.4.2_beta18" />
                <vers edition=":academ" num="2.4.2_beta18" />
                <vers num="2.4.2_beta18_vr10" />
                <vers num="2.4.2_beta18_vr11" />
                <vers num="2.4.2_beta18_vr12" />
                <vers num="2.4.2_beta18_vr13" />
                <vers num="2.4.2_beta18_vr14" />
                <vers num="2.4.2_beta18_vr15" />
                <vers num="2.4.2_beta18_vr4" />
                <vers num="2.4.2_beta18_vr5" />
                <vers num="2.4.2_beta18_vr6" />
                <vers num="2.4.2_beta18_vr7" />
                <vers num="2.4.2_beta18_vr8" />
                <vers num="2.4.2_beta18_vr9" />
                <vers edition="" num="2.4.2_beta2" />
                <vers edition=":academ" num="2.4.2_beta2" />
                <vers num="2.4.2_vr16" />
                <vers num="2.4.2_vr17" />
                <vers num="2.5.0" />
                <vers num="2.6.0" />
                <vers num="2.6.1" />
                <vers num="2.6.2" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" name="CVE-2004-0111" seq="2004-0111" severity="Medium" type="CVE" published="2004-04-15" CVSS_version="2.0 incomplete approximation" CVSS_score="5.0" modified="2008-09-10">
        <desc>
            <descript source="cve">gdk-pixbuf before 0.20 allows attackers to cause a denial of service (crash) via a malformed bitmap (BMP) file.</descript>
        </desc>
        <loss_types>
            <avail />
        </loss_types>
        <vuln_types>
            <other />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="BID" patch="1" url="http://www.securityfocus.com/bid/9842" adv="1">9842</ref>
            <ref source="REDHAT" patch="1" url="http://www.redhat.com/support/errata/RHSA-2004-103.html" adv="1">RHSA-2004:103</ref>
            <ref source="FEDORA" url="https://bugzilla.fedora.us/show_bug.cgi?id=2005">FLSA:2005</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/15426">gdk-pixbuf-bitmap-dos(15426)</ref>
            <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2004-102.html">RHSA-2004:102</ref>
            <ref source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2004:020">MDKSA-2004:020</ref>
            <ref source="DEBIAN" url="http://www.debian.org/security/2004/dsa-464">DSA-464</ref>
            <ref source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:846" sig="1">oval:org.mitre.oval:def:846</ref>
            <ref source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:845" sig="1">oval:org.mitre.oval:def:845</ref>
        </refs>
        <vuln_soft>
            <prod vendor="gnome" name="gdkpixbuf">
                <vers num="0.18" />
                <vers num="0.20" />
            </prod>
            <prod vendor="redhat" name="gdk_pixbuf">
                <vers edition="" num="0.18.0-7" />
                <vers edition=":i386_dev" num="0.18.0-7" />
                <vers edition=":i386_gnome" num="0.18.0-7" />
                <vers edition=":i386" num="0.18.0-7" />
            </prod>
            <prod vendor="sgi" name="propack">
                <vers num="2.3" />
                <vers num="2.4" />
            </prod>
            <prod vendor="redhat" name="enterprise_linux">
                <vers edition="" num="2.1" />
                <vers edition=":enterprise_server" num="2.1" />
                <vers edition=":workstation" num="2.1" />
                <vers edition=":advanced_server" num="2.1" />
                <vers edition="" num="3.0" />
                <vers edition=":workstation" num="3.0" />
                <vers edition=":enterprise_server" num="3.0" />
                <vers edition=":advanced_servers" num="3.0" />
            </prod>
            <prod vendor="redhat" name="linux_advanced_workstation">
                <vers edition="" num="2.1" />
                <vers edition=":itanium_processor" num="2.1" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" name="CVE-2004-0121" seq="2004-0121" severity="High" type="CVE" published="2004-04-15" CVSS_version="2.0 incomplete approximation" CVSS_score="7.5" modified="2008-09-05">
        <desc>
            <descript source="cve">Argument injection vulnerability in Microsoft Outlook 2002 does not sufficiently filter parameters of mailto: URLs when using them as arguments when calling OUTLOOK.EXE, which allows remote attackers to use script code in the Local Machine zone and execute arbitrary programs.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot other="1" />
        </loss_types>
        <vuln_types>
            <design />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA04-070A.html">TA04-070A</ref>
            <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/305206">VU#305206</ref>
            <ref source="BID" patch="1" url="http://www.securityfocus.com/bid/9827" adv="1">9827</ref>
            <ref source="MS" patch="1" url="http://www.microsoft.com/technet/security/bulletin/ms04-009.asp" adv="1">MS04-009</ref>
            <ref source="IDEFENSE" patch="1" url="http://www.idefense.com/application/poi/displ