<?xml version='1.0' encoding='UTF-8'?>
<nvd xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns="http://nvd.nist.gov/feeds/cve/1.2" nvd_xml_version="1.2" pub_date="2013-05-25" xsi:schemaLocation="http://nvd.nist.gov/feeds/cve/1.2 http://nvd.nist.gov/schema/nvdcve.xsd">
  <entry type="CVE" severity="High" seq="2004-0001" published="2004-02-17" name="CVE-2004-0001" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Unknown vulnerability in the eflags checking in the 32-bit ptrace emulation for the Linux kernel on AMD64 systems allows local users to gain privileges.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1" admin="1"/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/337238" source="CERT-VN" adv="1">VU#337238</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-017.html" source="REDHAT" patch="1" adv="1">RHSA-2004:017</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/14888" source="XF" adv="1">linux-ptrace-gain-privilege(14888)</ref>
      <ref url="http://www.securityfocus.com/bid/9429" source="BID" adv="1">9429</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200402-06.xml" source="GENTOO">GLSA-200402-06</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:868" source="OVAL" sig="1">oval:org.mitre.oval:def:868</ref>
    </refs>
    <vuln_soft>
      <prod vendor="linux" name="linux_kernel">
        <vers num="2.6.20.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0002" published="2004-03-03" name="CVE-2004-0002" modified="2008-09-10" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">The TCP MSS (maximum segment size) functionality in netinet allows remote attackers to cause a denial of service (resource exhaustion) via (1) a low MTU, which causes a large number of small packets to be produced, or (2) via a large number of packets with a small TCP payload, which cause a large number of calls to the resource-intensive sowakeup function.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <vuln_types>
      <exception/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://lists.freebsd.org/pipermail/cvs-src/2004-January/016271.html" source="CONFIRM" patch="1" adv="1">http://lists.freebsd.org/pipermail/cvs-src/2004-January/016271.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="freebsd" name="freebsd">
        <vers num="3.0" edition="releng"/>
        <vers num="3.1"/>
        <vers num="3.2"/>
        <vers num="3.3"/>
        <vers num="3.4"/>
        <vers num="3.5" edition="stable"/>
        <vers num="3.5.1" edition="release"/>
        <vers num="3.5.1" edition="stable"/>
        <vers num="4.0" edition="alpha"/>
        <vers num="4.0" edition="releng"/>
        <vers num="4.1"/>
        <vers num="4.1.1" edition="release"/>
        <vers num="4.1.1" edition="stable"/>
        <vers num="4.2" edition="stable"/>
        <vers num="4.3" edition="release"/>
        <vers num="4.3" edition="release_p38"/>
        <vers num="4.3" edition="releng"/>
        <vers num="4.3" edition="stable"/>
        <vers num="4.4" edition="release_p42"/>
        <vers num="4.4" edition="releng"/>
        <vers num="4.4" edition="stable"/>
        <vers num="4.5" edition="release"/>
        <vers num="4.5" edition="release_p32"/>
        <vers num="4.5" edition="releng"/>
        <vers num="4.5" edition="stable"/>
        <vers num="4.6" edition="release"/>
        <vers num="4.6" edition="release_p20"/>
        <vers num="4.6" edition="releng"/>
        <vers num="4.6" edition="stable"/>
        <vers num="4.6.2"/>
        <vers num="4.7" edition="release"/>
        <vers num="4.7" edition="release_p17"/>
        <vers num="4.7" edition="releng"/>
        <vers num="4.7" edition="stable"/>
        <vers num="4.8" edition="pre-release"/>
        <vers num="4.8" edition="release_p6"/>
        <vers num="4.8" edition="releng"/>
        <vers num="4.9" edition="pre-release"/>
        <vers num="5.0" edition="alpha"/>
        <vers num="5.0" edition="release_p14"/>
        <vers num="5.0" edition="releng"/>
        <vers num="5.1" edition="release_p5"/>
        <vers num="5.1" edition="releng"/>
        <vers num="5.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0003" published="2004-03-03" name="CVE-2004-0003" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Unknown vulnerability in Linux kernel before 2.4.22 allows local users to gain privileges, related to "R128 DRI limits checking."</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input bound="1"/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-044.html" source="REDHAT" patch="1" adv="1">RHSA-2004:044</ref>
      <ref url="http://www.linuxcompatible.org/print25630.html" source="CONFIRM" patch="1" adv="1">http://www.linuxcompatible.org/print25630.html</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-065.html" source="REDHAT">RHSA-2004:065</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2004_05_linux_kernel.html" source="SUSE">SuSE-SA:2004:005</ref>
      <ref url="http://www.debian.org/security/2004/dsa-495" source="DEBIAN">DSA-495</ref>
      <ref url="http://www.debian.org/security/2004/dsa-491" source="DEBIAN">DSA-491</ref>
      <ref url="http://www.debian.org/security/2004/dsa-489" source="DEBIAN">DSA-489</ref>
      <ref url="http://www.debian.org/security/2004/dsa-482" source="DEBIAN">DSA-482</ref>
      <ref url="http://www.debian.org/security/2004/dsa-481" source="DEBIAN">DSA-481</ref>
      <ref url="http://www.debian.org/security/2004/dsa-480" source="DEBIAN">DSA-480</ref>
      <ref url="http://www.debian.org/security/2004/dsa-479" source="DEBIAN">DSA-479</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9204" source="OVAL">oval:org.mitre.oval:def:9204</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15029" source="XF">linux-r128-gain-priviliges(15029)</ref>
      <ref url="http://www.turbolinux.com/security/2004/TLSA-2004-14.txt" source="TURBO">TLSA-2004-14</ref>
      <ref url="http://www.securityfocus.com/bid/9570" source="BID">9570</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-166.html" source="REDHAT">RHSA-2004:166</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-106.html" source="REDHAT">RHSA-2004:106</ref>
      <ref url="http://www.mandrakesecure.net/en/advisories/advisory.php?name=MDKSA-2004:029" source="MANDRAKE">MDKSA-2004:029</ref>
      <ref url="http://www.ciac.org/ciac/bulletins/o-145.shtml" source="CIAC">O-145</ref>
      <ref url="http://www.ciac.org/ciac/bulletins/o-127.shtml" source="CIAC">O-127</ref>
      <ref url="http://www.ciac.org/ciac/bulletins/o-126.shtml" source="CIAC">O-126</ref>
      <ref url="http://www.ciac.org/ciac/bulletins/o-121.shtml" source="CIAC">O-121</ref>
      <ref url="http://www.ciac.org/ciac/bulletins/o-082.shtml" source="CIAC">O-082</ref>
      <ref url="http://secunia.com/advisories/12075" source="SECUNIA">12075</ref>
      <ref url="http://secunia.com/advisories/11891" source="SECUNIA">11891</ref>
      <ref url="http://secunia.com/advisories/11464" source="SECUNIA">11464</ref>
      <ref url="http://secunia.com/advisories/11376" source="SECUNIA">11376</ref>
      <ref url="http://secunia.com/advisories/11370" source="SECUNIA">11370</ref>
      <ref url="http://secunia.com/advisories/11369" source="SECUNIA">11369</ref>
      <ref url="http://secunia.com/advisories/11362" source="SECUNIA">11362</ref>
      <ref url="http://secunia.com/advisories/11361" source="SECUNIA">11361</ref>
      <ref url="http://secunia.com/advisories/11202" source="SECUNIA">11202</ref>
      <ref url="http://secunia.com/advisories/10912" source="SECUNIA">10912</ref>
      <ref url="http://secunia.com/advisories/10911" source="SECUNIA">10911</ref>
      <ref url="http://secunia.com/advisories/10782" source="SECUNIA">10782</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:834" source="OVAL" sig="1">oval:org.mitre.oval:def:834</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1017" source="OVAL" sig="1">oval:org.mitre.oval:def:1017</ref>
    </refs>
    <vuln_soft>
      <prod vendor="linux" name="linux_kernel">
        <vers prev="1" num="2.4.22"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0004" published="2004-02-17" name="CVE-2004-0004" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">The libCheckSignature function in crypto-utils.lib for OpenCA 0.9.1.6 and earlier only compares the serial of the signer's certificate and the one in the database, which can cause OpenCA to incorrectly accept a signature if the certificate's chain is trusted by OpenCA's chain directory, allowing remote attackers to spoof requests from other users.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <other/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/336446" source="CERT-VN">VU#336446</ref>
      <ref url="http://www.securityfocus.com/bid/9435" source="BID" patch="1" adv="1">9435</ref>
      <ref url="http://www.openca.org/news/CAN-2004-0004.txt" source="CONFIRM" patch="1" adv="1">http://www.openca.org/news/CAN-2004-0004.txt</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/14847" source="XF">openca-improper-signature-verification(14847)</ref>
      <ref url="http://www.osvdb.org/3615" source="OSVDB">3615</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107427313700554&amp;w=2" source="BUGTRAQ">20040116 [OpenCA Advisory] Vulnerability in signature verification</ref>
    </refs>
    <vuln_soft>
      <prod vendor="openca" name="openca">
        <vers prev="1" num="0.9.1.6"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0005" published="2004-03-03" name="CVE-2004-0005" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple buffer overflows in Gaim 0.75 allow remote attackers to cause a denial of service and possibly execute arbitrary code via (1) octal encoding in yahoo_decode that causes a null byte to be written beyond the buffer, (2) octal encoding in yahoo_decode that causes a pointer to reference memory beyond the terminating null byte, (3) a quoted printable string to the gaim_quotedp_decode MIME decoder that causes a null byte to be written beyond the buffer, and (4) quoted printable encoding in gaim_quotedp_decode that causes a pointer to reference memory beyond the terminating null byte.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input buffer="1"/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/655974" source="CERT-VN">VU#655974</ref>
      <ref url="http://www.kb.cert.org/vuls/id/404470" source="CERT-VN">VU#404470</ref>
      <ref url="http://www.kb.cert.org/vuls/id/226974" source="CERT-VN">VU#226974</ref>
      <ref url="http://www.kb.cert.org/vuls/id/190366" source="CERT-VN">VU#190366</ref>
      <ref url="http://www.debian.org/security/2004/dsa-434" source="DEBIAN" patch="1" adv="1">DSA-434</ref>
      <ref url="http://security.e-matters.de/advisories/012004.html" source="MISC" patch="1" adv="1">http://security.e-matters.de/advisories/012004.html</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107513690306318&amp;w=2" source="BUGTRAQ" adv="1">20040126 Advisory 01/2004: 12 x Gaim remote overflows</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/14944" source="XF">gaim-mime-decoder-oob(14944)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/14942" source="XF">gaim-mime-decoder-bo(14942)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/14938" source="XF">gaim-sscanf-oob(14938)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/14935" source="XF">gaim-yahoodecode-offbyone-bo(14935)</ref>
      <ref url="http://www.slackware.com/security/viewer.php?l=slackware-security&amp;y=2004&amp;m=slackware-security.361158" source="SLACKWARE">SSA:2004-026</ref>
      <ref url="http://www.securitytracker.com/id?1008850" source="SECTRACK">1008850</ref>
      <ref url="http://www.osvdb.org/3736" source="OSVDB">3736</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2004_04_gaim.html" source="SUSE">SuSE-SA:2004:004</ref>
      <ref url="http://www.linuxsecurity.com/content/view/105690/104/" source="GENTOO">GLSA-200401-04</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000813" source="CONECTIVA">CLA-2004:813</ref>
      <ref url="http://archives.neohapsis.com/archives/fulldisclosure/2004-01/0994.html" source="FULLDISC">20040126 Advisory 01/2004: 12 x Gaim remote overflows</ref>
    </refs>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0006" published="2004-03-03" name="CVE-2004-0006" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple buffer overflows in Gaim 0.75 and earlier, and Ultramagnetic before 0.81, allow remote attackers to cause a denial of service and possibly execute arbitrary code via (1) cookies in a Yahoo web connection, (2) a long name parameter in the Yahoo login web page, (3) a long value parameter in the Yahoo login page, (4) a YMSG packet, (5) the URL parser, and (6) HTTP proxy connect.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input buffer="1"/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/871838" source="CERT-VN">VU#871838</ref>
      <ref url="http://www.kb.cert.org/vuls/id/527142" source="CERT-VN">VU#527142</ref>
      <ref url="http://www.kb.cert.org/vuls/id/503030" source="CERT-VN">VU#503030</ref>
      <ref url="http://www.kb.cert.org/vuls/id/444158" source="CERT-VN">VU#444158</ref>
      <ref url="http://www.kb.cert.org/vuls/id/371382" source="CERT-VN">VU#371382</ref>
      <ref url="http://www.kb.cert.org/vuls/id/297198" source="CERT-VN">VU#297198</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-032.html" source="REDHAT" patch="1" adv="1">RHSA-2004:032</ref>
      <ref url="http://ultramagnetic.sourceforge.net/advisories/001.html" source="CONFIRM" patch="1" adv="1">http://ultramagnetic.sourceforge.net/advisories/001.html</ref>
      <ref url="http://security.e-matters.de/advisories/012004.html" source="MISC" patch="1" adv="1">http://security.e-matters.de/advisories/012004.html</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-045.html" source="REDHAT">RHSA-2004:045</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-033.html" source="REDHAT">RHSA-2004:033</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2004_04_gaim.html" source="SUSE">SuSE-SA:2004:004</ref>
      <ref url="http://www.debian.org/security/2004/dsa-434" source="DEBIAN">DSA-434</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200401-04.xml" source="GENTOO" adv="1">GLSA-200401-04</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10222" source="OVAL">oval:org.mitre.oval:def:10222</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107513690306318&amp;w=2" source="BUGTRAQ" adv="1">20040126 Advisory 01/2004: 12 x Gaim remote overflows</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/20040201-01-U.asc" source="SGI">20040201-01-U</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/14947" source="XF">gaim-http-proxy-bo(14947)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/14945" source="XF">gaim-urlparser-bo(14945)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/14943" source="XF">gaim-yahoopacketread-keyname-bo(14943)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/14941" source="XF">gaim-login-value-bo(14941)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/14940" source="XF">gaim-login-name-bo(14940)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/14939" source="XF">gaim-yahoowebpending-cookie-bo(14939)</ref>
      <ref url="http://www.slackware.com/security/viewer.php?l=slackware-security&amp;y=2004&amp;m=slackware-security.361158" source="SLACKWARE">SSA:2004-026</ref>
      <ref url="http://www.securitytracker.com/id?1008850" source="SECTRACK">1008850</ref>
      <ref url="http://www.securityfocus.com/bid/9489" source="BID">9489</ref>
      <ref url="http://www.osvdb.org/3732" source="OSVDB">3732</ref>
      <ref url="http://www.osvdb.org/3731" source="OSVDB">3731</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2004:006" source="MANDRAKE">MDKSA-2004:006</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107522432613022&amp;w=2" source="BUGTRAQ">20040127 Ultramagnetic Advisory #001:  Multiple vulnerabilities in Gaim code</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000813" source="CONECTIVA">CLA-2004:813</ref>
      <ref url="http://archives.neohapsis.com/archives/fulldisclosure/2004-01/0994.html" source="FULLDISC">20040126 Advisory 01/2004: 12 x Gaim remote overflows</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/20040202-01-U.asc" source="SGI">20040202-01-U</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:818" source="OVAL" sig="1">oval:org.mitre.oval:def:818</ref>
    </refs>
    <vuln_soft>
      <prod vendor="rob_flynn" name="gaim">
        <vers prev="1" num="0.75"/>
      </prod>
      <prod vendor="ultramagnetic" name="ultramagnetic">
        <vers prev="1" num="0.81"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0007" published="2004-03-03" name="CVE-2004-0007" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in the Extract Info Field Function for (1) MSN and (2) YMSG protocol handlers in Gaim 0.74 and earlier, and Ultramagnetic before 0.81, allows remote attackers to cause a denial of service and possibly execute arbitrary code.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input buffer="1"/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/197142" source="CERT-VN">VU#197142</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-033.html" source="REDHAT" patch="1" adv="1">RHSA-2004:033</ref>
      <ref url="http://www.debian.org/security/2004/dsa-434" source="DEBIAN" patch="1" adv="1">DSA-434</ref>
      <ref url="http://ultramagnetic.sourceforge.net/advisories/001.html" source="CONFIRM" patch="1" adv="1">http://ultramagnetic.sourceforge.net/advisories/001.html</ref>
      <ref url="http://security.e-matters.de/advisories/012004.html" source="MISC" patch="1" adv="1">http://security.e-matters.de/advisories/012004.html</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107522432613022&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20040127 Ultramagnetic Advisory #001:  Multiple vulnerabilities in Gaim code</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-032.html" source="REDHAT">RHSA-2004:032</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200401-04.xml" source="GENTOO">GLSA-200401-04</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9906" source="OVAL">oval:org.mitre.oval:def:9906</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/14946" source="XF">gaim-extractinfo-bo(14946)</ref>
      <ref url="http://www.slackware.com/security/viewer.php?l=slackware-security&amp;y=2004&amp;m=slackware-security.361158" source="SLACKWARE">SSA:2004-026</ref>
      <ref url="http://www.securitytracker.com/id?1008850" source="SECTRACK">1008850</ref>
      <ref url="http://www.securityfocus.com/bid/9489" source="BID">9489</ref>
      <ref url="http://www.securityfocus.com/advisories/6281" source="SUSE">SuSE-SA:2004:004</ref>
      <ref url="http://www.osvdb.org/3733" source="OSVDB">3733</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2004:006" source="MANDRAKE">MDKSA-2004:006</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107513690306318&amp;w=2" source="BUGTRAQ">20040126 Advisory 01/2004: 12 x Gaim remote overflows</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000813" source="CONECTIVA">CLA-2004:813</ref>
      <ref url="http://archives.neohapsis.com/archives/fulldisclosure/2004-01/0994.html" source="FULLDISC">20040126 Advisory 01/2004: 12 x Gaim remote overflows</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:819" source="OVAL" sig="1">oval:org.mitre.oval:def:819</ref>
    </refs>
    <vuln_soft>
      <prod vendor="rob_flynn" name="gaim">
        <vers prev="1" num="0.74"/>
      </prod>
      <prod vendor="ultramagnetic" name="ultramagnetic">
        <vers prev="1" num="0.81"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0008" published="2004-03-03" name="CVE-2004-0008" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Integer overflow in Gaim 0.74 and earlier, and Ultramagnetic before 0.81, allows remote attackers to cause a denial of service and possibly execute arbitrary code via a directIM packet that triggers a heap-based buffer overflow.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input buffer="1"/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/779614" source="CERT-VN" adv="1">VU#779614</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-032.html" source="REDHAT" patch="1" adv="1">RHSA-2004:032</ref>
      <ref url="http://ultramagnetic.sourceforge.net/advisories/001.html" source="CONFIRM" patch="1" adv="1">http://ultramagnetic.sourceforge.net/advisories/001.html</ref>
      <ref url="http://security.e-matters.de/advisories/012004.html" source="MISC" patch="1" adv="1">http://security.e-matters.de/advisories/012004.html</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107522432613022&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20040127 Ultramagnetic Advisory #001:  Multiple vulnerabilities in Gaim code</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-045.html" source="REDHAT">RHSA-2004:045</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-033.html" source="REDHAT">RHSA-2004:033</ref>
      <ref url="http://www.debian.org/security/2004/dsa-434" source="DEBIAN">DSA-434</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200401-04.xml" source="GENTOO">GLSA-200401-04</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9469" source="OVAL">oval:org.mitre.oval:def:9469</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/20040201-01-U.asc" source="SGI">20040201-01-U</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/14937" source="XF">gaim-directim-bo(14937)</ref>
      <ref url="http://www.securitytracker.com/id?1008850" source="SECTRACK">1008850</ref>
      <ref url="http://www.osvdb.org/3734" source="OSVDB">3734</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2004:006" source="MANDRAKE">MDKSA-2004:006</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107522338611564&amp;w=2" source="BUGTRAQ">20040127 [slackware-security]  GAIM security update (SSA:2004-026-01)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107513690306318&amp;w=2" source="BUGTRAQ">20040126 Advisory 01/2004: 12 x Gaim remote overflows</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000813" source="CONECTIVA">CLA-2004:813</ref>
      <ref url="http://archives.neohapsis.com/archives/fulldisclosure/2004-01/0994.html" source="FULLDISC">20040126 Advisory 01/2004: 12 x Gaim remote overflows</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/20040202-01-U.asc" source="SGI">20040202-01-U</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:820" source="OVAL" sig="1">oval:org.mitre.oval:def:820</ref>
    </refs>
    <vuln_soft>
      <prod vendor="rob_flynn" name="gaim">
        <vers prev="1" num="0.74"/>
      </prod>
      <prod vendor="ultramagnetic" name="ultramagnetic">
        <vers prev="1" num="0.81"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0009" published="2004-03-03" name="CVE-2004-0009" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Apache-SSL 1.3.28+1.52 and earlier, with SSLVerifyClient set to 1 or 3 and SSLFakeBasicAuth enabled, allows remote attackers to forge a client certificate by using basic authentication with the "one-line DN" of the target user.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <design/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107619127531765&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20040206 Apache-SSL security advisory - apache_1.3.28+ssl_1.52 and prior</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15065" source="XF" adv="1">apachessl-default-password(15065)</ref>
      <ref url="http://www.securityfocus.com/bid/9590" source="BID" adv="1">9590</ref>
      <ref url="http://www.apache-ssl.org/advisory-20040206.txt" source="CONFIRM">http://www.apache-ssl.org/advisory-20040206.txt</ref>
      <ref url="http://www.osvdb.org/3877" source="OSVDB">3877</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2004-February/016870.html" source="FULLDISC">20040206 [apache-ssl] Apache-SSL security advisory - apache_1.3.28+ssl_1.52 and prior</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apache-ssl" name="apache-ssl">
        <vers prev="1" num="1.3.28_1.52"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0010" published="2004-03-03" name="CVE-2004-0010" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Stack-based buffer overflow in the ncp_lookup function for ncpfs in Linux kernel 2.4.x allows local users to gain privileges.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <vuln_types>
      <input buffer="1"/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/9691" source="BID" patch="1" adv="1">9691</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-069.html" source="REDHAT" patch="1" adv="1">RHSA-2004:069</ref>
      <ref url="http://www.debian.org/security/2004/dsa-479" source="DEBIAN" patch="1" adv="1">DSA-479</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15250" source="XF" adv="1">linux-ncplookup-gain-privileges(15250)</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-188.html" source="REDHAT">RHSA-2004:188</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-065.html" source="REDHAT">RHSA-2004:065</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2004_05_linux_kernel.html" source="SUSE">SuSE-SA:2004:005</ref>
      <ref url="http://www.debian.org/security/2004/dsa-495" source="DEBIAN">DSA-495</ref>
      <ref url="http://www.debian.org/security/2004/dsa-491" source="DEBIAN">DSA-491</ref>
      <ref url="http://www.debian.org/security/2004/dsa-489" source="DEBIAN">DSA-489</ref>
      <ref url="http://www.debian.org/security/2004/dsa-482" source="DEBIAN">DSA-482</ref>
      <ref url="http://www.debian.org/security/2004/dsa-481" source="DEBIAN">DSA-481</ref>
      <ref url="http://www.debian.org/security/2004/dsa-480" source="DEBIAN">DSA-480</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11388" source="OVAL">oval:org.mitre.oval:def:11388</ref>
      <ref url="http://www.securityfocus.com/advisories/6759" source="TURBO">TLSA-2004-05</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2004:015" source="MANDRAKE">MDKSA-2004:015</ref>
      <ref url="http://www.ciac.org/ciac/bulletins/o-082.shtml" source="CIAC">O-082</ref>
      <ref url="http://fedoranews.org/updates/FEDORA-2004-079.shtml" source="FEDORA">FEDORA-2004-079</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000820" source="CONECTIVA">CLA-2004:820</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:835" source="OVAL" sig="1">oval:org.mitre.oval:def:835</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1035" source="OVAL" sig="1">oval:org.mitre.oval:def:1035</ref>
    </refs>
    <vuln_soft>
      <prod vendor="linux" name="linux_kernel">
        <vers num="2.4.0" edition="test1"/>
        <vers num="2.4.0" edition="test10"/>
        <vers num="2.4.0" edition="test11"/>
        <vers num="2.4.0" edition="test12"/>
        <vers num="2.4.0" edition="test2"/>
        <vers num="2.4.0" edition="test3"/>
        <vers num="2.4.0" edition="test4"/>
        <vers num="2.4.0" edition="test5"/>
        <vers num="2.4.0" edition="test6"/>
        <vers num="2.4.0" edition="test7"/>
        <vers num="2.4.0" edition="test8"/>
        <vers num="2.4.0" edition="test9"/>
        <vers num="2.4.1"/>
        <vers num="2.4.10"/>
        <vers num="2.4.11"/>
        <vers num="2.4.12"/>
        <vers num="2.4.13"/>
        <vers num="2.4.14"/>
        <vers num="2.4.15"/>
        <vers num="2.4.16"/>
        <vers num="2.4.17"/>
        <vers num="2.4.18" edition=""/>
        <vers num="2.4.18" edition=":x86"/>
        <vers num="2.4.18" edition="pre1"/>
        <vers num="2.4.18" edition="pre2"/>
        <vers num="2.4.18" edition="pre3"/>
        <vers num="2.4.18" edition="pre4"/>
        <vers num="2.4.18" edition="pre5"/>
        <vers num="2.4.18" edition="pre6"/>
        <vers num="2.4.18" edition="pre7"/>
        <vers num="2.4.18" edition="pre8"/>
        <vers num="2.4.19" edition="pre1"/>
        <vers num="2.4.19" edition="pre2"/>
        <vers num="2.4.19" edition="pre3"/>
        <vers num="2.4.19" edition="pre4"/>
        <vers num="2.4.19" edition="pre5"/>
        <vers num="2.4.19" edition="pre6"/>
        <vers num="2.4.2"/>
        <vers num="2.4.20"/>
        <vers num="2.4.21" edition="pre1"/>
        <vers num="2.4.21" edition="pre4"/>
        <vers num="2.4.21" edition="pre7"/>
        <vers num="2.4.22"/>
        <vers num="2.4.23" edition="pre9"/>
        <vers num="2.4.24"/>
        <vers num="2.4.3"/>
        <vers num="2.4.4"/>
        <vers num="2.4.5"/>
        <vers num="2.4.6"/>
        <vers num="2.4.7"/>
        <vers num="2.4.8"/>
        <vers num="2.4.9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0011" published="2004-01-20" name="CVE-2004-0011" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in fsp before 2.81.b18 allows remote users to execute arbitrary code.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input buffer="1"/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/9377" source="BID" patch="1" adv="1">9377</ref>
      <ref url="http://www.debian.org/security/2004/dsa-416" source="DEBIAN" patch="1" adv="1">DSA-416</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/14155" source="XF" adv="1">fsp-boundry-error-bo(14155)</ref>
      <ref url="http://www.ciac.org/ciac/bulletins/o-048.shtml" source="CIAC">O-048</ref>
    </refs>
    <vuln_soft>
      <prod vendor="debian" name="fsp">
        <vers prev="1" num="2.81.b18"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0013" published="2004-02-03" name="CVE-2004-0013" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">jabber 1.4.2, 1.4.2a, and possibly earlier versions, does not properly handle SSL connections, which allows remote attackers to cause a denial of service (crash).</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <vuln_types>
      <other/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2004:005" source="MANDRAKE" patch="1" adv="1">MDKSA-2004:005</ref>
      <ref url="http://www.debian.org/security/2004/dsa-414" source="DEBIAN" patch="1" adv="1">DSA-414</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/14158" source="XF" adv="1">jabber-ssl-connections-dos(14158)</ref>
      <ref url="http://www.securityfocus.com/bid/9376" source="BID" adv="1">9376</ref>
      <ref url="http://www.osvdb.org/3345" source="OSVDB">3345</ref>
      <ref url="http://secunia.com/advisories/10559" source="SECUNIA">10559</ref>
    </refs>
    <vuln_soft>
      <prod vendor="jabber_software_foundation" name="jabber_server">
        <vers num="1.4.2a"/>
        <vers num="1.4.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0014" published="2004-01-20" name="CVE-2004-0014" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple buffer overflows in the nd WebDAV interface 0.8.2 and earlier allows remote web servers to execute arbitrary code via certain long strings.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input bound="1"/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/9365" source="BID" patch="1" adv="1">9365</ref>
      <ref url="http://www.debian.org/security/2004/dsa-412" source="DEBIAN" patch="1" adv="1">DSA-412</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/14141" source="XF" adv="1">nd-long-string-bo(14141)</ref>
      <ref url="http://www.securitytracker.com/id?1008616" source="SECTRACK">1008616</ref>
      <ref url="http://secunia.com/advisories/10550" source="SECUNIA">10550</ref>
      <ref url="http://secunia.com/advisories/10549" source="SECUNIA">10549</ref>
    </refs>
    <vuln_soft>
      <prod vendor="nd" name="nd">
        <vers prev="1" num="0.8.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0015" published="2004-02-03" name="CVE-2004-0015" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">vbox3 0.1.8 and earlier does not properly drop privileges before executing a user-provided TCL script, which allows local users to gain privileges.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <vuln_types>
      <design/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://www.debian.org/security/2004/dsa-418" source="DEBIAN" patch="1" adv="1">DSA-418</ref>
      <ref url="http://www.securityfocus.com/bid/9381" source="BID" adv="1">9381</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/14170" source="XF">vbox3-gain-privileges(14170)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="vbox3" name="vbox3">
        <vers prev="1" num="0.1.8"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0016" published="2004-02-03" name="CVE-2004-0016" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">The calendar module for phpgroupware 0.9.14 does not enforce the "save extension" feature for holiday files, which allows remote attackers to create and execute PHP files.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <design/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.debian.org/security/2004/dsa-419" source="DEBIAN" patch="1" adv="1">DSA-419</ref>
      <ref url="http://www.securityfocus.com/bid/9387" source="BID" adv="1">9387</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/13489" source="XF">phpgroupware-calendar-file-include(13489)</ref>
      <ref url="http://www.osvdb.org/6860" source="OSVDB">6860</ref>
    </refs>
    <vuln_soft>
      <prod vendor="phpgroupware" name="phpgroupware">
        <vers num="0.9.14"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0017" published="2004-02-03" name="CVE-2004-0017" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple SQL injection vulnerabilities in the (1) calendar and (2) infolog modules for phpgroupware 0.9.14 allow remote attackers to perform unauthorized database operations.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.debian.org/security/2004/dsa-419" source="DEBIAN" patch="1" adv="1">DSA-419</ref>
      <ref url="http://www.securityfocus.com/bid/9386" source="BID" adv="1">9386</ref>
      <ref url="http://www.securitytracker.com/id?1008662" source="SECTRACK">1008662</ref>
      <ref url="http://secunia.com/advisories/10591" source="SECUNIA">10591</ref>
    </refs>
    <vuln_soft>
      <prod vendor="phpgroupware" name="phpgroupware">
        <vers num="0.9.14"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0028" published="2004-02-03" name="CVE-2004-0028" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">jitterbug 1.6.2 does not properly sanitize inputs, which allows remote authenticated users to execute arbitrary commands.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.debian.org/security/2004/dsa-420" source="DEBIAN" patch="1" adv="1">DSA-420</ref>
      <ref url="http://www.securityfocus.com/bid/9397" source="BID" adv="1">9397</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/14207" source="XF">jitterbug-execute-code(14207)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="samba" name="jitterbug">
        <vers num="1.6.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0029" published="2004-01-20" name="CVE-2004-0029" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Lotus Notes Domino 6.0.2 on Linux installs the notes.ini configuration file with world-writable permissions, which allows local users to modify the Notes configuration and gain privileges.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <config/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/14153" source="XF" adv="1">lotus-notes-insecure-permissions(14153)</ref>
      <ref url="http://www.securityfocus.com/bid/9366" source="BID" adv="1">9366</ref>
      <ref url="http://www.securitytracker.com/id?1008623" source="SECTRACK">1008623</ref>
      <ref url="http://www.osvdb.org/3424" source="OSVDB">3424</ref>
      <ref url="http://www.excluded.org/advisories/advisory05.txt" source="MISC">http://www.excluded.org/advisories/advisory05.txt</ref>
      <ref url="http://secunia.com/advisories/10566" source="SECUNIA">10566</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107340897710308&amp;w=2" source="BUGTRAQ">20040106 Lotus Notes Domino 6.0.2 (linux) faulty default permissions</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="lotus_domino">
        <vers num="6.0.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0030" published="2004-01-20" name="CVE-2004-0030" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">PHP remote file inclusion vulnerability in (1) functions.php, (2) authentication_index.php, and (3) config_gedcom.php for PHPGEDVIEW 2.61 allows remote attackers to execute arbitrary PHP code by modifying the PGV_BASE_DIRECTORY parameter to reference a URL on a remote web server that contains the code.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/14159" source="XF" adv="1">phpgedview-pgvbasedirectory-file-include(14159)</ref>
      <ref url="http://www.securityfocus.com/bid/9368" source="BID">9368</ref>
      <ref url="http://www.osvdb.org/3343" source="OSVDB">3343</ref>
      <ref url="http://secunia.com/advisories/10565" source="SECUNIA" adv="1">10565</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107340840209453&amp;w=2" source="BUGTRAQ">20040106 Vuln in PHPGEDVIEW 2.61 Multi-Problem</ref>
      <ref url="http://www.securitytracker.com/id?1008632" source="SECTRACK">1008632</ref>
    </refs>
    <vuln_soft>
      <prod vendor="phpgedview" name="phpgedview">
        <vers num="2.61"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0031" published="2004-01-20" name="CVE-2004-0031" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">PHPGEDVIEW 2.61 allows remote attackers to reinstall the software and change the administrator password via a direct HTTP request to editconfig.php.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <access/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107340840209453&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20040106 Vuln in PHPGEDVIEW 2.61 Multi-Problem</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/14161" source="XF" adv="1">phpgedview-modify-admin-password(14161)</ref>
      <ref url="http://www.osvdb.org/3403" source="OSVDB">3403</ref>
      <ref url="http://secunia.com/advisories/10565" source="SECUNIA">10565</ref>
    </refs>
    <vuln_soft>
      <prod vendor="phpgedview" name="phpgedview">
        <vers num="2.61"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0032" published="2004-01-20" name="CVE-2004-0032" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in search.php in PHPGEDVIEW 2.61 allows remote attackers to inject arbitrary HTML and web script via the firstname parameter.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107340840209453&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20040106 Vuln in PHPGEDVIEW 2.61 Multi-Problem</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/14160" source="XF" adv="1">phpgedview-search-xss(14160)</ref>
      <ref url="http://www.securityfocus.com/bid/9369" source="BID">9369</ref>
      <ref url="http://www.osvdb.org/3402" source="OSVDB">3402</ref>
      <ref url="http://secunia.com/advisories/10565" source="SECUNIA">10565</ref>
    </refs>
    <vuln_soft>
      <prod vendor="phpgedview" name="phpgedview">
        <vers num="2.61"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0033" published="2004-01-20" name="CVE-2004-0033" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">admin.php in PHPGEDVIEW 2.61 allows remote attackers to obtain sensitive information via an action parameter with a phpinfo command.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <vuln_types>
      <access/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107340840209453&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20040106 Vuln in PHPGEDVIEW 2.61 Multi-Problem</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/14162" source="XF" adv="1">phpgedview-admin-info-disclosure(14162)</ref>
      <ref url="http://www.securityfocus.com/bid/9371" source="BID">9371</ref>
      <ref url="http://www.osvdb.org/3404" source="OSVDB">3404</ref>
      <ref url="http://secunia.com/advisories/10565" source="SECUNIA">10565</ref>
    </refs>
    <vuln_soft>
      <prod vendor="phpgedview" name="phpgedview">
        <vers num="2.61"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0034" published="2004-01-20" name="CVE-2004-0034" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in Phorum 3.4.5 and earlier allow remote attackers to inject arbitrary HTML or web script via (1) the phorum_check_xss function in common.php, (2) the EditError variable in profile.php, and (3) the Error variable in login.php.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/14145" source="XF" adv="1">phorum-common-xss(14145)</ref>
      <ref url="http://www.securityfocus.com/bid/9361" source="BID" adv="1">9361</ref>
      <ref url="http://secunia.com/advisories/10567" source="SECUNIA">10567</ref>
      <ref url="http://phorum.org/" source="CONFIRM" adv="1">http://phorum.org/</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107340481804110&amp;w=2" source="BUGTRAQ" adv="1">20040105 Multiple Vulnerabilities in Phorum 3.4.5</ref>
      <ref url="http://www.securitytracker.com/id?1008633" source="SECTRACK">1008633</ref>
      <ref url="http://www.osvdb.org/3510" source="OSVDB">3510</ref>
      <ref url="http://www.osvdb.org/3506" source="OSVDB">3506</ref>
      <ref url="http://www.osvdb.org/3434" source="OSVDB">3434</ref>
    </refs>
    <vuln_soft>
      <prod vendor="phorum" name="phorum">
        <vers prev="1" num="3.4.5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0035" published="2004-01-20" name="CVE-2004-0035" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in register.php for Phorum 3.4.5 and earlier allows remote attackers to execute arbitrary SQL commands via the hide_email parameter.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/14146" source="XF" adv="1">phorum-register-sql-injection(14146)</ref>
      <ref url="http://www.securityfocus.com/bid/9363" source="BID" adv="1">9363</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107340481804110&amp;w=2" source="BUGTRAQ" adv="1">20040105 Multiple Vulnerabilities in Phorum 3.4.5</ref>
      <ref url="http://www.osvdb.org/3508" source="OSVDB">3508</ref>
      <ref url="http://secunia.com/advisories/10567" source="SECUNIA">10567</ref>
    </refs>
    <vuln_soft>
      <prod vendor="phorum" name="phorum">
        <vers prev="1" num="3.4.5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0036" published="2004-01-20" name="CVE-2004-0036" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">SQL injection vulnerability in calendar.php for vBulletin Forum 2.3.x before 2.3.4 allows remote attackers to steal sensitive information via the eventid parameter.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107340358202123&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20040105 vBulletin Forum 2.3.xx calendar.php SQL Injection</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/14144" source="XF" adv="1">vbulletin-calendar-sql-injection(14144)</ref>
      <ref url="http://www.vbulletin.com/forum/showthread.php?postid=588825" source="CONFIRM">http://www.vbulletin.com/forum/showthread.php?postid=588825</ref>
      <ref url="http://www.securityfocus.com/bid/9360" source="BID">9360</ref>
      <ref url="http://www.osvdb.org/3344" source="OSVDB">3344</ref>
    </refs>
    <vuln_soft>
      <prod vendor="jelsoft" name="vbulletin">
        <vers num="2.3.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0037" published="2004-01-20" name="CVE-2004-0037" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">FirstClass Desktop Client 7.1 allows remote attackers to execute arbitrary commands via hyperlinks in FirstClass RTF messages.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/14151" source="XF" adv="1">firstclassclient-execute-code(14151)</ref>
      <ref url="http://www.securityfocus.com/bid/9370" source="BID" adv="1">9370</ref>
      <ref url="http://www.osvdb.org/3442" source="OSVDB">3442</ref>
      <ref url="http://secunia.com/advisories/10556" source="SECUNIA">10556</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107340950611167&amp;w=2" source="BUGTRAQ" adv="1">20040105 FirstClass Client 7.1: Command Execution via Email Web Link</ref>
      <ref url="http://www.securitytracker.com/id?1008609" source="SECTRACK">1008609</ref>
    </refs>
    <vuln_soft>
      <prod vendor="opentext" name="opentext_firstclass_desktop_client">
        <vers num="7.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0038" published="2004-06-14" name="CVE-2004-0038" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">McAfee ePolicy Orchestrator (ePO) 2.5.1 Patch 13 and 3.0 SP2a Patch 3 allows remote attackers to execute arbitrary commands via certain HTTP POST requests to the spipe/file handler on ePO TCP port 81.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <exception/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/14166" source="XF" patch="1" adv="1">epolicy-execute-commands(14166)</ref>
      <ref url="http://xforce.iss.net/xforce/alerts/id/173" source="ISS" patch="1" adv="1">20040510 McAfee ePolicy Orchestrator Remote Compromise Vulnerability</ref>
      <ref url="http://www.securityfocus.com/bid/10200" source="BID" patch="1" adv="1">10200</ref>
      <ref url="http://www.osvdb.org/5626" source="MISC" patch="1" adv="1">http://www.osvdb.org/5626</ref>
      <ref url="http://download.nai.com/products/patches/ePO/v2.x/Patch14.txt" source="CONFIRM" adv="1">http://download.nai.com/products/patches/ePO/v2.x/Patch14.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mcafee" name="epolicy_orchestrator">
        <vers num="2.5" edition="sp1"/>
        <vers num="2.5.1"/>
        <vers num="3.0" edition="sp2a"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0039" published="2004-03-03" name="CVE-2004-0039" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Multiple format string vulnerabilities in HTTP Application Intelligence (AI) component in Check Point Firewall-1 NG-AI R55 and R54, and Check Point Firewall-1 HTTP Security Server included with NG FP1, FP2, and FP3 allows remote attackers to execute arbitrary code via HTTP requests that cause format string specifiers to be used in an error message, as demonstrated using the scheme of a URI.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/790771" source="CERT-VN" patch="1" adv="1">VU#790771</ref>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA04-036A.html" source="CERT">TA04-036A</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/14149" source="XF" patch="1" adv="1">fw1-format-string(14149)</ref>
      <ref url="http://www.securityfocus.com/bid/9581" source="BID" patch="1" adv="1">9581</ref>
      <ref url="http://xforce.iss.net/xforce/alerts/id/162" source="ISS">20040204 Checkpoint Firewall-1 HTTP Parsing Format String Vulnerabilities</ref>
      <ref url="http://www.ciac.org/ciac/bulletins/o-072.shtml" source="CIAC">O-072</ref>
      <ref url="http://www.checkpoint.com/techsupport/alerts/security_server.html" source="CONFIRM">http://www.checkpoint.com/techsupport/alerts/security_server.html</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107604682227031&amp;w=2" source="BUGTRAQ">20040205 Two checkpoint fw-1/vpn-1 vulns</ref>
    </refs>
    <vuln_soft>
      <prod vendor="checkpoint" name="firewall-1">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0040" published="2004-03-03" name="CVE-2004-0040" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Stack-based buffer overflow in Check Point VPN-1 Server 4.1 through 4.1 SP6 and Check Point SecuRemote/SecureClient 4.1 through 4.1 build 4200 allows remote attackers to execute arbitrary code via an ISAKMP packet with a large Certificate Request packet.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <vuln_types>
      <input buffer="1"/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/873334" source="CERT-VN" patch="1" adv="1">VU#873334</ref>
      <ref url="http://www.securityfocus.com/bid/9582" source="BID" patch="1" adv="1">9582</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/14150" source="XF" adv="1">vpn1-ike-bo(14150)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107604682227031&amp;w=2" source="BUGTRAQ" adv="1">20040205 Two checkpoint fw-1/vpn-1 vulns</ref>
      <ref url="http://xforce.iss.net/xforce/alerts/id/163" source="ISS">20040204 Checkpoint VPN-1/SecureClient ISAKMP Buffer Overflow</ref>
      <ref url="http://www.osvdb.org/4432" source="OSVDB">4432</ref>
      <ref url="http://www.osvdb.org/3821" source="OSVDB">3821</ref>
      <ref url="http://www.ciac.org/ciac/bulletins/o-073.shtml" source="CIAC">O-073</ref>
    </refs>
    <vuln_soft>
      <prod vendor="checkpoint" name="firewall-1">
        <vers num="4.1" edition="sp1"/>
        <vers num="4.1" edition="sp2"/>
        <vers num="4.1" edition="sp3"/>
        <vers num="4.1" edition="sp4"/>
        <vers num="4.1" edition="sp5"/>
        <vers num="4.1" edition="sp5a"/>
        <vers num="next_generation_fp0"/>
        <vers num="next_generation_fp1"/>
      </prod>
      <prod vendor="checkpoint" name="vpn-1">
        <vers num="4.1" edition="sp5a"/>
        <vers num="next_generation_fp0"/>
        <vers num="next_generation_fp1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0041" published="2004-02-03" name="CVE-2004-0041" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">The mod_auth_shadow module 1.4 and earlier does not properly enforce the expiration of a user account and password, which could allow remote authenticated users to bypass intended access restrictions.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <design/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.debian.org/security/2004/dsa-421" source="DEBIAN" patch="1" adv="1">DSA-421</ref>
      <ref url="http://www.securitytracker.com/id?1008675" source="SECTRACK">1008675</ref>
      <ref url="http://www.securityfocus.com/bid/9404" source="BID" adv="1">9404</ref>
      <ref url="http://www.osvdb.org/3454" source="OSVDB">3454</ref>
      <ref url="http://secunia.com/advisories/10612" source="SECUNIA" adv="1">10612</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mod_auth_shadow" name="mod_auth_shadow">
        <vers num="1.0"/>
        <vers num="1.1"/>
        <vers num="1.2"/>
        <vers num="1.3"/>
        <vers num="1.4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0042" published="2004-02-03" name="CVE-2004-0042" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">vsftpd 1.1.3 generates different error messages depending on whether or not a valid username exists, which allows remote attackers to identify valid usernames.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://securitytracker.com/id?1008628" source="SECTRACK">1008628</ref>
    </refs>
    <vuln_soft>
      <prod vendor="beasts" name="vsftpd">
        <vers num="1.1.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0043" published="2004-02-03" name="CVE-2004-0043" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in Yahoo Instant Messenger 5.6.0.1351 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long filename in the download feature.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input buffer="1"/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/9383" source="BID">9383</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2004-January/015334.html" source="FULLDISC">20040108 Yahoo Instant Messenger Long Filename Downloading Buffer Overflow</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/14171" source="XF">yahoo-messenger-filename-bo(14171)</ref>
      <ref url="http://www.securitytracker.com/id?1008651" source="SECTRACK">1008651</ref>
      <ref url="http://www.osvdb.org/3437" source="OSVDB">3437</ref>
      <ref url="http://secunia.com/advisories/10573" source="SECUNIA">10573</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107357996802255&amp;w=2" source="BUGTRAQ">20040108 Yahoo Instant Messenger Long Filename Downloading Buffer Overflow</ref>
    </refs>
    <vuln_soft>
      <prod vendor="yahoo" name="messenger">
        <vers prev="1" num="5.6.0.1351"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0044" published="2004-02-03" name="CVE-2004-0044" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Cisco Personal Assistant 1.4(1) and 1.4(2) disables password authentication when "Allow Only Cisco CallManager Users" is enabled and the Corporate Directory settings refer to the directory service being used by Cisco CallManager, which allows remote attackers to gain access with a valid username.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <config/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.cisco.com/warp/public/707/cisco-sa-20040108-pa.shtml" source="CISCO" patch="1" adv="1">20040108 Cisco Personal Assistant User Password Bypass Vulnerability</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/14172" source="XF">ciscopersonalassistant-config-file-access(14172)</ref>
      <ref url="http://www.securityfocus.com/bid/9384" source="BID">9384</ref>
      <ref url="http://www.osvdb.org/3430" source="OSVDB">3430</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="personal_assistant">
        <vers num="1.4(1)"/>
        <vers num="1.4(2)"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0045" published="2004-02-03" name="CVE-2004-0045" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in the ARTpost function in art.c in the control message handling code for INN 2.4.0 may allow remote attackers to execute arbitrary code.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <vuln_types>
      <input buffer="1"/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/759020" source="CERT-VN">VU#759020</ref>
      <ref url="http://www.securityfocus.com/bid/9382" source="BID" patch="1" adv="1">9382</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2004-01/0064.html" source="BUGTRAQ" patch="1" adv="1">20040108 [OpenPKG-SA-2004.001] OpenPKG Security Advisory (inn)</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2004-01/0063.html" source="BUGTRAQ" patch="1" adv="1">20040107 [SECURITY] INN: Buffer overflow in control message handling</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/14190" source="XF">inn-artpost-control-message-bo(14190)</ref>
      <ref url="http://www.slackware.org/security/viewer.php?l=slackware-security&amp;y=2004&amp;m=slackware-security.365791" source="SLACKWARE">SSA:2004-014-02</ref>
      <ref url="http://secunia.com/advisories/10578" source="SECUNIA">10578</ref>
    </refs>
    <vuln_soft>
      <prod vendor="isc" name="inn">
        <vers num="2.4.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0046" published="2004-02-03" name="CVE-2004-0046" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in SnapStream PVS LITE allows remote attackers to inject arbitrary web script or HTML via a GET request containing a terminating '"' (double quote) character.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/14164" source="XF">snapstream-quotation-xss(14164)</ref>
      <ref url="http://www.securityfocus.com/bid/9375" source="BID" adv="1">9375</ref>
      <ref url="http://www.osvdb.org/3440" source="OSVDB">3440</ref>
      <ref url="http://securitytracker.com/id?1008646" source="SECTRACK">1008646</ref>
      <ref url="http://secunia.com/advisories/10575" source="SECUNIA">10575</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107350313917867&amp;w=2" source="BUGTRAQ" adv="1">20040106 SnapStream PVS LITE Cross Site Scripting Vulnerabillity</ref>
    </refs>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0047" published="2004-03-03" name="CVE-2004-0047" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Multiple programs in trr19 1.0 do not properly drop privileges before executing a system command, which could allow local users to gain privileges.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <design/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://www.debian.org/security/2004/dsa-430" source="DEBIAN" patch="1" adv="1">DSA-430</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/14975" source="XF">trr19-gain-privileges(14975)</ref>
      <ref url="http://www.securityfocus.com/bid/9520" source="BID" adv="1">9520</ref>
      <ref url="http://secunia.com/advisories/10744/" source="SECUNIA">10744</ref>
      <ref url="http://www.securitytracker.com/id?1008875" source="SECTRACK">1008875</ref>
      <ref url="http://www.osvdb.org/3747" source="OSVDB">3747</ref>
      <ref url="http://secunia.com/advisories/10745" source="SECUNIA">10745</ref>
    </refs>
    <vuln_soft>
      <prod vendor="yamamoto_hirotaka" name="trr19">
        <vers num="1.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0049" published="2004-02-17" name="CVE-2004-0049" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:S/C:N/I:N/A:C)" CVSS_score="6.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="8.0" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Helix Universal Server/Proxy 9 and Mobile Server 10 allow remote attackers to cause a denial of service via certain HTTP POST messages to the Administration System port.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://service.real.com/help/faq/security/040112_dos/" source="CONFIRM" patch="1" adv="1">http://service.real.com/help/faq/security/040112_dos/</ref>
      <ref url="http://www.securityfocus.com/bid/9421" source="BID" adv="1">9421</ref>
      <ref url="http://service.real.com/help/faq/security/security022604.html" source="CONFIRM">http://service.real.com/help/faq/security/security022604.html</ref>
      <ref url="http://www.securityfocus.com/archive/1/357834" source="BUGTRAQ">20040318 ptl-2004-02: RealNetworks Helix Server 9 Administration Server Buffer Overflow</ref>
      <ref url="http://seclists.org/lists/vulnwatch/2004/Jan-Mar/0057.html" source="VULNWATCH">20040318 ptl-2004-02: RealNetworks Helix Server 9 Administration Server Buffer Overflow</ref>
    </refs>
    <vuln_soft>
      <prod vendor="realnetworks" name="helix_universal_mobile_server">
        <vers prev="1" num="10.1.1.120"/>
      </prod>
      <prod vendor="realnetworks" name="helix_universal_server">
        <vers prev="1" num="9.0.2.881"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0050" published="2004-06-14" name="CVE-2004-0050" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Verity Ultraseek before 5.2.2 allows remote attackers to obtain the full pathname of the document root via an MS-DOS device name in the web search option, such as (1) NUL, (2) CON, (3) AUX, (4) COM1, (5) COM2, and others.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <vuln_types>
      <exception/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/16066" source="XF" patch="1" adv="1">ultraseek-error-path-disclosure(16066)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108377388114888&amp;w=2" source="BUGTRAQ" adv="1">20040505 Corsaire Security Advisory - Verity Ultraseek path disclosure issue</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2004-May/020952.html" source="FULLDISC">20040505 Corsaire Security Advisory - Verity Ultraseek path disclosure issue</ref>
      <ref url="http://archives.neohapsis.com/archives/vulnwatch/2004-q2/0024.html" source="VULNWATCH" adv="1">20040505 Corsaire Security Advisory - Verity Ultraseek path disclosure issue</ref>
    </refs>
    <vuln_soft>
      <prod vendor="verity" name="ultraseek">
        <vers prev="1" num="5.2.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0051" published="2004-10-20" name="CVE-2004-0051" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple content security gateway and antivirus products allow remote attackers to bypass content restrictions via MIME messages that use non-standard but frequently supported Content-Transfer-Encoding values such as (1) uuencode, (2) mac-binhex40, and (3) yenc, which may be interpreted differently by mail clients.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <exception/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/17337" source="XF">mime-contenttransfer-filter-bypass(17337)</ref>
      <ref url="http://www.uniras.gov.uk/vuls/2004/380375/mime.htm" source="MISC" adv="1">http://www.uniras.gov.uk/vuls/2004/380375/mime.htm</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109517788100063&amp;w=2" source="BUGTRAQ" adv="1">20040914 Corsaire Security Advisory - Multiple vendor MIME Content-Transfer-Encoding mechanism issue</ref>
    </refs>
    <vuln_soft>
      <prod vendor="clearswift" name="mailsweeper">
        <vers num="4.3.10"/>
        <vers num="4.3.11"/>
        <vers num="4.3.13"/>
        <vers num="4.3.14"/>
        <vers num="4.3.15"/>
        <vers num="4.3.7"/>
        <vers num="4.3.8"/>
      </prod>
      <prod vendor="f-secure" name="internet_gatekeeper">
        <vers num="6.3"/>
        <vers num="6.31"/>
        <vers num="6.32"/>
        <vers num="6.4"/>
      </prod>
      <prod vendor="paul_l_daniels" name="ripmime">
        <vers num="1.2.0"/>
        <vers num="1.2.1"/>
        <vers num="1.2.2"/>
        <vers num="1.2.3"/>
        <vers num="1.2.4"/>
        <vers num="1.2.5"/>
        <vers num="1.2.6"/>
        <vers num="1.2.7"/>
        <vers num="1.3.2.0"/>
        <vers num="1.3.2.2"/>
        <vers num="1.3.2.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0052" published="2004-10-20" name="CVE-2004-0052" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple content security gateway and antivirus products allow remote attackers to bypass content restrictions via MIME messages that use non-standard separator characters, or use standard separators incorrectly, within MIME headers, fields, parameters, or values, which may be interpreted differently by mail clients.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <exception/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/17334" source="XF">mime-separator-filtering-bypass(17334)</ref>
      <ref url="http://www.uniras.gov.uk/vuls/2004/380375/mime.htm" source="MISC" adv="1">http://www.uniras.gov.uk/vuls/2004/380375/mime.htm</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109517669115891&amp;w=2" source="BUGTRAQ" adv="1">20040914 Corsaire Security Advisory - Multiple vendor MIME separator issue</ref>
    </refs>
    <vuln_soft>
      <prod vendor="clearswift" name="mailsweeper">
        <vers num="4.3.10"/>
        <vers num="4.3.11"/>
        <vers num="4.3.13"/>
        <vers num="4.3.14"/>
        <vers num="4.3.15"/>
        <vers num="4.3.7"/>
        <vers num="4.3.8"/>
      </prod>
      <prod vendor="f-secure" name="internet_gatekeeper">
        <vers num="6.3"/>
        <vers num="6.31"/>
        <vers num="6.32"/>
        <vers num="6.4"/>
      </prod>
      <prod vendor="paul_l_daniels" name="ripmime">
        <vers num="1.2.0"/>
        <vers num="1.2.1"/>
        <vers num="1.2.2"/>
        <vers num="1.2.3"/>
        <vers num="1.2.4"/>
        <vers num="1.2.5"/>
        <vers num="1.2.6"/>
        <vers num="1.2.7"/>
        <vers num="1.3.2.0"/>
        <vers num="1.3.2.2"/>
        <vers num="1.3.2.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0053" published="2004-10-20" name="CVE-2004-0053" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple content security gateway and antivirus products allow remote attackers to bypass content restrictions via MIME messages that use fields that use RFC2047 encoding, which may be interpreted differently by mail clients.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <exception/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/17331" source="XF">mime-rfc2047-filtering-bypass(17331)</ref>
      <ref url="http://www.uniras.gov.uk/vuls/2004/380375/mime.htm" source="MISC" adv="1">http://www.uniras.gov.uk/vuls/2004/380375/mime.htm</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109520704408739&amp;w=2" source="BUGTRAQ" adv="1">20040914 Corsaire Security Advisory - Multiple vendor MIME RFC2047 encoding issue</ref>
    </refs>
    <vuln_soft>
      <prod vendor="clearswift" name="mailsweeper">
        <vers num="4.3.10"/>
        <vers num="4.3.11"/>
        <vers num="4.3.13"/>
        <vers num="4.3.14"/>
        <vers num="4.3.15"/>
        <vers num="4.3.7"/>
        <vers num="4.3.8"/>
      </prod>
      <prod vendor="f-secure" name="internet_gatekeeper">
        <vers num="6.3"/>
        <vers num="6.31"/>
        <vers num="6.32"/>
        <vers num="6.4"/>
      </prod>
      <prod vendor="paul_l_daniels" name="ripmime">
        <vers num="1.2.0"/>
        <vers num="1.2.1"/>
        <vers num="1.2.2"/>
        <vers num="1.2.3"/>
        <vers num="1.2.4"/>
        <vers num="1.2.5"/>
        <vers num="1.2.6"/>
        <vers num="1.2.7"/>
        <vers num="1.3.2.0"/>
        <vers num="1.3.2.2"/>
        <vers num="1.3.2.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0054" published="2004-02-17" name="CVE-2004-0054" modified="2009-03-04" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple vulnerabilities in the H.323 protocol implementation for Cisco IOS 11.3T through 12.2T allow remote attackers to cause a denial of service and possibly execute arbitrary code, as demonstrated by the NISCC/OUSPG PROTOS test suite for the H.225 protocol.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/749342" source="CERT-VN" patch="1" adv="1">VU#749342</ref>
      <ref url="http://www.cert.org/advisories/CA-2004-01.html" source="CERT" patch="1" adv="1">CA-2004-01</ref>
      <ref url="http://www.cisco.com/warp/public/707/cisco-sa-20040113-h323.shtml" source="CISCO" patch="1" adv="1">20040113 Vulnerabilities in H.323 Message Processing</ref>
      <ref url="http://www.uniras.gov.uk/vuls/2004/006489/h323.htm" source="MISC">http://www.uniras.gov.uk/vuls/2004/006489/h323.htm</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:4884" source="OVAL">oval:org.mitre.oval:def:4884</ref>
      <ref url="http://www.securitytracker.com/id?1008685" source="SECTRACK">1008685</ref>
      <ref url="http://www.securityfocus.com/bid/9406" source="BID">9406</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="ios">
        <vers num="11.3t"/>
        <vers num="12.0"/>
        <vers num="12.0s"/>
        <vers num="12.0t"/>
        <vers num="12.1"/>
        <vers num="12.1e"/>
        <vers num="12.1t"/>
        <vers num="12.2"/>
        <vers num="12.2s"/>
        <vers num="12.2t"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0055" published="2004-02-17" name="CVE-2004-0055" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The print_attr_string function in print-radius.c for tcpdump 3.8.1 and earlier allows remote attackers to cause a denial of service (segmentation fault) via a RADIUS attribute with a large length value.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <vuln_types>
      <design/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/955526" source="CERT-VN" adv="1">VU#955526</ref>
      <ref url="http://www.securityfocus.com/bid/7090" source="BID" patch="1" adv="1">7090</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-008.html" source="REDHAT" patch="1" adv="1">RHSA-2004:008</ref>
      <ref url="http://www.redhat.com/archives/fedora-announce-list/2004-March/msg00015.html" source="MLIST">[fedora-announce-list] 20040311 Re: [SECURITY] Fedora Core 1 Update: tcpdump-3.7.2-8.fc1.1</ref>
      <ref url="http://www.redhat.com/archives/fedora-announce-list/2004-March/msg00009.html" source="FEDORA">FEDORA-2004-092</ref>
      <ref url="http://www.redhat.com/archives/fedora-announce-list/2004-March/msg00006.html" source="FEDORA">FEDORA-2004-090</ref>
      <ref url="http://www.debian.org/security/2004/dsa-425" source="DEBIAN">DSA-425</ref>
      <ref url="http://secunia.com/advisories/12179/" source="SECUNIA">12179</ref>
      <ref url="http://secunia.com/advisories/11032/" source="SECUNIA">11032</ref>
      <ref url="http://secunia.com/advisories/11022" source="SECUNIA">11022</ref>
      <ref url="http://secunia.com/advisories/10718" source="SECUNIA">10718</ref>
      <ref url="http://secunia.com/advisories/10652" source="SECUNIA">10652</ref>
      <ref url="http://secunia.com/advisories/10644" source="SECUNIA">10644</ref>
      <ref url="http://secunia.com/advisories/10639" source="SECUNIA">10639</ref>
      <ref url="http://secunia.com/advisories/10636" source="SECUNIA">10636</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9989" source="OVAL">oval:org.mitre.oval:def:9989</ref>
      <ref url="http://lwn.net/Alerts/66445/" source="TRUSTIX">2004-0004</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2004/Feb/msg00000.html" source="APPLE">APPLE-SA-2004-02-23</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/20040103-01-U.asc" source="SGI">20040103-01-U</ref>
      <ref url="ftp://ftp.sco.com/pub/updates/UnixWare/SCOSA-2004.9/SCOSA-2004.9.txt" source="SCO">SCOSA-2004.9</ref>
      <ref url="ftp://ftp.sco.com/pub/security/OpenLinux/CSSA-2004-008.0.txt" source="CALDERA">CSSA-2004-008.0</ref>
      <ref url="http://www.securitytracker.com/id?1008735" source="SECTRACK">1008735</ref>
      <ref url="http://www.redhat.com/archives/fedora-legacy-list/2004-January/msg00726.html" source="FEDORA">FLSA:1222</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2004:008" source="MANDRAKE">MDKSA-2004:008</ref>
      <ref url="http://marc.theaimsgroup.com/?l=tcpdump-workers&amp;m=107325073018070&amp;w=2" source="MLIST">[tcpdump-workers] multiple vulnerabilities in tcpdump 3.8.1</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107577418225627&amp;w=2" source="BUGTRAQ">20040131 [FLSA-2004:1222] Updated tcpdump resolves security vulnerabilites (resend with correct paths)</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000832" source="CONECTIVA">CLSA-2003:832</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/20040202-01-U.asc" source="SGI">20040202-01-U</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:853" source="OVAL" sig="1">oval:org.mitre.oval:def:853</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:850" source="OVAL" sig="1">oval:org.mitre.oval:def:850</ref>
    </refs>
    <vuln_soft>
      <prod vendor="lbl" name="tcpdump">
        <vers num="3.5.2"/>
        <vers num="3.6.2"/>
        <vers num="3.7"/>
        <vers num="3.7.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0056" published="2004-02-17" name="CVE-2004-0056" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple vulnerabilities in the H.323 protocol implementation for Nortel Networks Business Communications Manager (BCM), Succession 1000 IP Trunk and IP Peer Networking, and 802.11 Wireless IP Gateway allow remote attackers to cause a denial of service and possibly execute arbitrary code, as demonstrated by the NISCC/OUSPG PROTOS test suite for the H.225 protocol.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/749342" source="CERT-VN" patch="1" adv="1">VU#749342</ref>
      <ref url="http://www.cert.org/advisories/CA-2004-01.html" source="CERT" patch="1" adv="1">CA-2004-01</ref>
      <ref url="http://www.uniras.gov.uk/vuls/2004/006489/h323.htm" source="MISC">http://www.uniras.gov.uk/vuls/2004/006489/h323.htm</ref>
      <ref url="http://www.securitytracker.com/id?1008687" source="SECTRACK">1008687</ref>
      <ref url="http://www.securityfocus.com/bid/9406" source="BID">9406</ref>
    </refs>
    <vuln_soft>
      <prod vendor="nortel" name="business_communications_manager">
        <vers num=""/>
      </prod>
      <prod vendor="nortel" name="802.11_wireless_ip_gateway">
        <vers num=""/>
      </prod>
      <prod vendor="nortel" name="succession_communication_server_1000">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0057" published="2004-02-17" name="CVE-2004-0057" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The rawprint function in the ISAKMP decoding routines (print-isakmp.c) for tcpdump 3.8.1 and earlier allows remote attackers to cause a denial of service (segmentation fault) via malformed ISAKMP packets that cause invalid "len" or "loc" values to be used in a loop, a different vulnerability than CVE-2003-0989.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/174086" source="CERT-VN">VU#174086</ref>
      <ref url="http://www.securityfocus.com/bid/9423" source="BID" patch="1" adv="1">9423</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-007.html" source="REDHAT" patch="1" adv="1">RHSA-2004:007</ref>
      <ref url="http://www.debian.org/security/2004/dsa-425" source="DEBIAN" patch="1" adv="1">DSA-425</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/14837" source="XF">tcpdump-rawprint-isakmp-dos(14837)</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/350238/30/21640/threaded" source="BUGTRAQ">20040119 [ESA-20040119-002] 'tcpdump' multiple vulnerabilities.</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-008.html" source="REDHAT">RHSA-2004:008</ref>
      <ref url="http://www.redhat.com/archives/fedora-announce-list/2004-March/msg00015.html" source="MLIST">[fedora-announce-list] 20040311 Re: [SECURITY] Fedora Core 1 Update: tcpdump-3.7.2-8.fc1.1</ref>
      <ref url="http://www.redhat.com/archives/fedora-announce-list/2004-March/msg00009.html" source="FEDORA">FEDORA-2004-092</ref>
      <ref url="http://www.redhat.com/archives/fedora-announce-list/2004-March/msg00006.html" source="FEDORA">FEDORA-2004-090</ref>
      <ref url="http://secunia.com/advisories/12179/" source="SECUNIA">12179</ref>
      <ref url="http://secunia.com/advisories/11032/" source="SECUNIA">11032</ref>
      <ref url="http://secunia.com/advisories/11022" source="SECUNIA">11022</ref>
      <ref url="http://secunia.com/advisories/10718" source="SECUNIA">10718</ref>
      <ref url="http://secunia.com/advisories/10668" source="SECUNIA">10668</ref>
      <ref url="http://secunia.com/advisories/10652" source="SECUNIA">10652</ref>
      <ref url="http://secunia.com/advisories/10644" source="SECUNIA">10644</ref>
      <ref url="http://secunia.com/advisories/10639" source="SECUNIA">10639</ref>
      <ref url="http://secunia.com/advisories/10636" source="SECUNIA">10636</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11197" source="OVAL">oval:org.mitre.oval:def:11197</ref>
      <ref url="http://marc.theaimsgroup.com/?l=tcpdump-workers&amp;m=107325073018070&amp;w=2" source="MLIST" adv="1">[tcpdump-workers] multiple vulnerabilities in tcpdump 3.8.1</ref>
      <ref url="http://lwn.net/Alerts/66805/" source="ENGARDE">ESA-20040119-002</ref>
      <ref url="http://lwn.net/Alerts/66445/" source="TRUSTIX">2004-0004</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2004/Feb/msg00000.html" source="APPLE">APPLE-SA-2004-02-23</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/20040103-01-U.asc" source="SGI">20040103-01-U</ref>
      <ref url="ftp://ftp.sco.com/pub/updates/UnixWare/SCOSA-2004.9/SCOSA-2004.9.txt" source="SCO">SCOSA-2004.9</ref>
      <ref url="ftp://ftp.sco.com/pub/security/OpenLinux/CSSA-2004-008.0.txt" source="CALDERA">CSSA-2004-008.0</ref>
      <ref url="http://www.securitytracker.com/id?1008716" source="SECTRACK">1008716</ref>
      <ref url="http://www.redhat.com/archives/fedora-legacy-list/2004-January/msg00726.html" source="FEDORA">FLSA:1222</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2004:008" source="MANDRAKE">MDKSA-2004:008</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107577418225627&amp;w=2" source="BUGTRAQ">20040131 [FLSA-2004:1222] Updated tcpdump resolves security vulnerabilites (resend with correct paths)</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/20040202-01-U.asc" source="SGI">20040202-01-U</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:854" source="OVAL" sig="1">oval:org.mitre.oval:def:854</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:851" source="OVAL" sig="1">oval:org.mitre.oval:def:851</ref>
    </refs>
    <vuln_soft>
      <prod vendor="lbl" name="tcpdump">
        <vers prev="1" num="3.8.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2004-0058" published="2004-02-17" name="CVE-2004-0058" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">Antivir / Linux 2.0.9-9, and possibly earlier versions, allows local users to overwrite arbitrary files via a symlink attack on the .pid_antivir_$$ temporary file.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/14214" source="XF">antivir-tmpfile-insecure(14214)</ref>
      <ref url="http://www.securitytracker.com/id?1008702" source="SECTRACK">1008702</ref>
      <ref url="http://www.osvdb.org/3496" source="OSVDB">3496</ref>
      <ref url="http://secunia.com/advisories/10620" source="SECUNIA">10620</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107402026023763&amp;w=2" source="BUGTRAQ">20040113 symlink vul for Antivir / Linux Version 2.0.9-9 (maybe lower)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="linux" name="linux_kernel">
        <vers prev="1" num="2.0.9.9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0059" published="2004-02-17" name="CVE-2004-0059" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in upload capability of WWW File Share Pro 2.42 and earlier allows remote attackers to overwrite arbitrary files via .. (dot dot) sequences in the filename parameter of a Content-Disposition: header.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securitytracker.com/id?1008779" source="SECTRACK">1008779</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107411794303201&amp;w=2" source="BUGTRAQ">20040114 Multiple vulnerabilities in WWW Fileshare Pro &lt;= 2.42</ref>
    </refs>
    <vuln_soft>
      <prod vendor="lionmax_software" name="www_file_share_pro">
        <vers prev="1" num="2.42"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0060" published="2004-02-17" name="CVE-2004-0060" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">WWW File Share Pro 2.42 and earlier allows remote attackers to cause a denial of service (crash) via a large POST request.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securitytracker.com/id?1008779" source="SECTRACK">1008779</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107411794303201&amp;w=2" source="BUGTRAQ">20040114 Multiple vulnerabilities in WWW Fileshare Pro &lt;= 2.42</ref>
    </refs>
    <vuln_soft>
      <prod vendor="lionmax_software" name="www_file_share_pro">
        <vers prev="1" num="2.42"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0061" published="2004-02-17" name="CVE-2004-0061" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">WWW File Share Pro 2.42 and earlier allows remote attackers to bypass directory access restrictions via (1) a URL with a trailing . (dot), or (2) a URI with a leading slash or backslash character.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securitytracker.com/id?1008779" source="SECTRACK">1008779</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107411794303201&amp;w=2" source="BUGTRAQ">20040114 Multiple vulnerabilities in WWW Fileshare Pro &lt;= 2.42</ref>
    </refs>
    <vuln_soft>
      <prod vendor="lionmax_software" name="www_file_share_pro">
        <vers prev="1" num="2.42"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0062" published="2004-02-17" name="CVE-2004-0062" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Integer overflow in the rnd arithmetic rounding function for various versions of FishCart before 3.1 allows remote attackers to "cause negative totals" via an order with a large quantity.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input bound="1"/>
      <design/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107411850203994&amp;w=2" source="BUGTRAQ" adv="1">20040114 FishCart Integer Overflow / Rounding Error</ref>
      <ref url="http://www.securitytracker.com/id?1008731" source="SECTRACK">1008731</ref>
    </refs>
    <vuln_soft>
      <prod vendor="fishnet" name="fishcart">
        <vers prev="1" num="3.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0063" published="2004-02-17" name="CVE-2004-0063" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">The SPP_VerifyPVV function in nCipher payShield SPP library 1.3.12, 1.5.18 and 1.6.18 returns a Status_OK value even if the HSM returns a different status code, which could cause applications to make incorrect security-critical decisions, e.g. by accepting an invalid PIN number.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <exception/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.ncipher.com/support/advisories/advisory8_payshield.html" source="CONFIRM" adv="1">http://www.ncipher.com/support/advisories/advisory8_payshield.html</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/14832" source="XF">payshield-incorrect-request-verification(14832)</ref>
      <ref url="http://www.securityfocus.com/bid/9422" source="BID">9422</ref>
      <ref url="http://www.osvdb.org/3537" source="OSVDB">3537</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107411819503569&amp;w=2" source="BUGTRAQ">20040114 nCipher Advisory #8: payShield library may verify bad requests</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ncipher" name="payshield_spp_library">
        <vers num="1.3.12"/>
        <vers num="1.5.18"/>
        <vers num="1.6.18"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2004-0064" published="2004-02-17" name="CVE-2004-0064" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">The SuSEconfig.gnome-filesystem script for YaST in SuSE 9.0 allows local users to overwrite arbitrary files via a symlink attack on files within the tmp.SuSEconfig.gnome-filesystem.$RANDOM temporary directory.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <vuln_types>
      <other/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/9411" source="BID" adv="1">9411</ref>
      <ref url="http://www.securitytracker.com/id?1008703" source="SECTRACK">1008703</ref>
      <ref url="http://www.osvdb.org/3460" source="OSVDB">3460</ref>
      <ref url="http://secunia.com/advisories/10623" source="SECUNIA">10623</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107402658600437&amp;w=2" source="BUGTRAQ">20040113 SuSE linux 9.0 YaST config Skribt [exploit]</ref>
    </refs>
    <vuln_soft>
      <prod vendor="suse" name="suse_linux">
        <vers num="9.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0065" published="2004-02-17" name="CVE-2004-0065" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple SQL injection vulnerabilities in phpGedView before 2.65 allow remote attackers to execute arbitrary SQL via (1) timeline.php and (2) placelist.php.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107394912715478&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20040112 More phpGedView Vulnerabilities</ref>
      <ref url="http://www.securityfocus.com/bid/11925" source="BID">11925</ref>
      <ref url="http://www.securityfocus.com/bid/11910" source="BID">11910</ref>
    </refs>
    <vuln_soft>
      <prod vendor="phpgedview" name="phpgedview">
        <vers prev="1" num="2.65"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0066" published="2004-02-17" name="CVE-2004-0066" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">phpGedView before 2.65 allows remote attackers to obtain the absolute path of the web server via malformed parameters to (1) indilist.php, (2) famlist.php, (3) placelist.php, (4) imageview.php, (5) timeline.php, (6) clippings.php, (7) login.php, and (8) gdbi.php.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107394912715478&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20040112 More phpGedView Vulnerabilities</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/14215" source="XF">phpgedview-path-disclosure(14215)</ref>
      <ref url="http://www.osvdb.org/3464" source="OSVDB">3464</ref>
    </refs>
    <vuln_soft>
      <prod vendor="phpgedview" name="phpgedview">
        <vers prev="1" num="2.65"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0067" published="2004-02-17" name="CVE-2004-0067" modified="2011-09-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in phpGedView before 2.65 allow remote attackers to inject arbitrary HTML or web script via (1) descendancy.php, (2) index.php, (3) individual.php, (4) login.php, (5) relationship.php, (6) source.php, (7) imageview.php, (8) calendar.php, (9) gedrecord.php, (10) login.php, and (11) gdbi_interface.php.  NOTE: some aspects of vector 10 were later reported to affect 4.1.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107394912715478&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20040112 More phpGedView Vulnerabilities</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/36285" source="XF">phpgedview-login-xss(36285)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/14212" source="XF">phpgedview-multiple-xss(14212)</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/2995" source="VUPEN" adv="1">ADV-2007-2995</ref>
      <ref url="http://www.securityfocus.com/bid/11907" source="BID">11907</ref>
      <ref url="http://www.securityfocus.com/bid/11906" source="BID">11906</ref>
      <ref url="http://www.securityfocus.com/bid/11905" source="BID">11905</ref>
      <ref url="http://www.securityfocus.com/bid/11904" source="BID">11904</ref>
      <ref url="http://www.securityfocus.com/bid/11903" source="BID">11903</ref>
      <ref url="http://www.securityfocus.com/bid/11894" source="BID">11894</ref>
      <ref url="http://www.securityfocus.com/bid/11891" source="BID">11891</ref>
      <ref url="http://www.securityfocus.com/bid/11890" source="BID">11890</ref>
      <ref url="http://www.securityfocus.com/bid/11888" source="BID">11888</ref>
      <ref url="http://www.securityfocus.com/bid/11882" source="BID">11882</ref>
      <ref url="http://www.securityfocus.com/bid/11880" source="BID">11880</ref>
      <ref url="http://www.securityfocus.com/bid/11868" source="BID">11868</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/477881/100/0/threaded" source="BUGTRAQ">20070827 PhpGedView login page multiple XSS</ref>
      <ref url="http://www.osvdb.org/3479" source="OSVDB">3479</ref>
      <ref url="http://www.osvdb.org/3478" source="OSVDB">3478</ref>
      <ref url="http://www.osvdb.org/3477" source="OSVDB">3477</ref>
      <ref url="http://www.osvdb.org/3476" source="OSVDB">3476</ref>
      <ref url="http://www.osvdb.org/3475" source="OSVDB">3475</ref>
      <ref url="http://www.osvdb.org/3474" source="OSVDB">3474</ref>
      <ref url="http://www.osvdb.org/3473" source="OSVDB">3473</ref>
      <ref url="http://securitytracker.com/id?1018613" source="SECTRACK">1018613</ref>
      <ref url="http://secunia.com/advisories/26628" source="SECUNIA" adv="1">26628</ref>
    </refs>
    <vuln_soft>
      <prod vendor="phpgedview" name="phpgedview">
        <vers prev="1" num="2.65"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0068" published="2004-02-17" name="CVE-2004-0068" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">PHP remote file inclusion vulnerability in config.php for PhpDig 1.6.5 and earlier allows remote attackers to execute arbitrary PHP code by modifying the $relative_script_path parameter to reference a URL on a remote web server that contains the code.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/9424" source="BID" patch="1" adv="1">9424</ref>
      <ref url="http://www.phpdig.net/showthread.php?s=58bcc71c822830ec3bbdaae6d56846e0&amp;threadid=393" source="CONFIRM" patch="1">http://www.phpdig.net/showthread.php?s=58bcc71c822830ec3bbdaae6d56846e0&amp;threadid=393</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107412194008671&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20040114 PhpDig 1.6.x: remote command execution</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/14826" source="XF">phpdig-config-file-include(14826)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="phpdig.net" name="phpdig">
        <vers prev="1" num="1.6.5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0069" published="2004-02-17" name="CVE-2004-0069" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Format string vulnerability in HD Soft Windows FTP Server 1.6 and earlier allows remote attackers to execute arbitrary code via format string specifiers in the username, which is processed by the wscanf function.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/9385" source="BID" adv="1">9385</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107401398014761&amp;w=2" source="BUGTRAQ">20040113 exploit for HD Soft Windows FTP Server 1.6</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107367110805273&amp;w=2" source="BUGTRAQ" adv="1">20040108 Windows FTP Server Format String Vulnerability</ref>
      <ref url="http://www.securitytracker.com/id?1008658" source="SECTRACK">1008658</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hd_soft" name="windows_ftp_server">
        <vers prev="1" num="1.6"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0070" published="2004-02-17" name="CVE-2004-0070" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">PHP remote file inclusion vulnerability in module.php for ezContents allows remote attackers to execute arbitrary PHP code by modifying the link parameter to reference a URL on a remote web server that contains the code.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/14199" source="XF">ezcontents-php-file-include(14199)</ref>
      <ref url="http://www.securityfocus.com/bid/9396" source="BID" adv="1">9396</ref>
      <ref url="http://www.osvdb.org/6878" source="OSVDB">6878</ref>
      <ref url="http://www.ezcontents.org/forum/viewtopic.php?t=361" source="CONFIRM">http://www.ezcontents.org/forum/viewtopic.php?t=361</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107392588915627&amp;w=2" source="BUGTRAQ">20040110 Remote Code Execution in ezContents</ref>
    </refs>
    <vuln_soft>
      <prod vendor="visualshapers" name="ezcontents">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0071" published="2004-02-17" name="CVE-2004-0071" modified="2005-10-20" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in buildManPage in class.manpagelookup.php for PHP Man Page Lookup 1.2.0 allows remote attackers to read arbitrary files via the command parameter ($cmd variable) to index.php.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/14203" source="XF">manpagelookup-directory-traversal(14203)</ref>
      <ref url="http://www.securityfocus.com/bid/9395" source="BID">9395</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107392764118403&amp;w=2" source="BUGTRAQ" adv="1">20040110 PHP Manpage lookup directory transversal / file disclosing</ref>
      <ref url="http://www.securitytracker.com/id?1008689" source="SECTRACK">1008689</ref>
    </refs>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0072" published="2004-02-17" name="CVE-2004-0072" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in Accipiter Direct Server 6.0 allows remote attackers to read arbitrary files via encoded \.. (backslash .., "%5c%2e%2e") sequences in an HTTP request.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/9389" source="BID" patch="1" adv="1">9389</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/14198" source="XF" adv="1">accipterdirectserver-directory-traversal(14198)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107392576215418&amp;w=2" source="BUGTRAQ" adv="1">20040109 Directory Traversal in Accipiter Direct Server 6.0</ref>
      <ref url="http://archives.neohapsis.com/archives/fulldisclosure/2004-01/0274.html" source="FULLDISC">20040109 Directory Traversal in Accipiter Direct Server 6.0</ref>
      <ref url="http://www.osvdb.org/3433" source="OSVDB">3433</ref>
      <ref url="http://secunia.com/advisories/10600" source="SECUNIA">10600</ref>
    </refs>
    <vuln_soft>
      <prod vendor="accipiter" name="accipiter_direct_server">
        <vers num="6.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0073" published="2004-02-17" name="CVE-2004-0073" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">PHP remote file inclusion vulnerability in (1) config.php and (2) config_page.php for EasyDynamicPages 2.0 allows remote attackers to execute arbitrary PHP code by modifying the edp_relative_path parameter to reference a URL on a remote web server that contains a malicious serverdata.php script.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/9338" source="BID" patch="1" adv="1">9338</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/14136" source="XF">easydynamicpages-php-file-include(14136)</ref>
      <ref url="http://www.osvdb.org/3408" source="OSVDB">3408</ref>
      <ref url="http://www.osvdb.org/3318" source="OSVDB">3318</ref>
      <ref url="http://securitytracker.com/id?1008584" source="SECTRACK">1008584</ref>
      <ref url="http://secunia.com/advisories/10535" source="SECUNIA">10535</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107307457327707&amp;w=2" source="BUGTRAQ">20040102 include() vuln in EasyDynamicPages v.2.0</ref>
    </refs>
    <vuln_soft>
      <prod vendor="stoitsov" name="easydynamicpages">
        <vers num="2.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0074" published="2004-02-17" name="CVE-2004-0074" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Multiple buffer overflows in xsok 1.02 allows local users to gain privileges via (1) a long LANG environment variable, or (2) a long -xsokdir command line argument, a different vulnerability than CVE-2003-0949.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input buffer="1"/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/9341" source="BID" patch="1" adv="1">9341</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/14910" source="XF">xsok-lang-bo(14910)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/14906" source="XF" adv="1">xsok-long-xsokdir-bo(14906)</ref>
      <ref url="http://www.securityfocus.com/bid/9352" source="BID" adv="1">9352</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107332542918529&amp;w=2" source="BUGTRAQ">20040103 xsok local games exploit (2)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107307407027259&amp;w=2" source="BUGTRAQ">20040102 xsok local games exploit</ref>
    </refs>
    <vuln_soft>
      <prod vendor="michael_bischoff" name="xsok">
        <vers num="1.02"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2004-0075" published="2004-03-15" name="CVE-2004-0075" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">The Vicam USB driver in Linux before 2.4.25 does not use the copy_from_user function when copying data from userspace to kernel space, which crosses security boundaries and allows local users to cause a denial of service.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <vuln_types>
      <design/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/9690" source="BID" patch="1" adv="1">9690</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-065.html" source="REDHAT" patch="1" adv="1">RHSA-2004:065</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15246" source="XF" adv="1">linux-vicam-dos(15246)</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-293.html" source="REDHAT">RHSA-2005:293</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2004_05_linux_kernel.html" source="SUSE">SuSE-SA:2004:005</ref>
      <ref url="http://www.ciac.org/ciac/bulletins/o-082.shtml" source="CIAC">O-082</ref>
      <ref url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2004:015" source="MANDRAKE">MDKSA-2004:015</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000846" source="CONECTIVA">CLA-2004:846</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:836" source="OVAL" sig="1">oval:org.mitre.oval:def:836</ref>
    </refs>
    <vuln_soft>
      <prod vendor="linux" name="linux_kernel">
        <vers num="2.4.0" edition="test1"/>
        <vers num="2.4.0" edition="test10"/>
        <vers num="2.4.0" edition="test11"/>
        <vers num="2.4.0" edition="test12"/>
        <vers num="2.4.0" edition="test2"/>
        <vers num="2.4.0" edition="test3"/>
        <vers num="2.4.0" edition="test4"/>
        <vers num="2.4.0" edition="test5"/>
        <vers num="2.4.0" edition="test6"/>
        <vers num="2.4.0" edition="test7"/>
        <vers num="2.4.0" edition="test8"/>
        <vers num="2.4.0" edition="test9"/>
        <vers num="2.4.1"/>
        <vers num="2.4.10"/>
        <vers num="2.4.11"/>
        <vers num="2.4.12"/>
        <vers num="2.4.13"/>
        <vers num="2.4.14"/>
        <vers num="2.4.15"/>
        <vers num="2.4.16"/>
        <vers num="2.4.17"/>
        <vers num="2.4.18" edition=""/>
        <vers num="2.4.18" edition=":x86"/>
        <vers num="2.4.18" edition="pre1"/>
        <vers num="2.4.18" edition="pre2"/>
        <vers num="2.4.18" edition="pre3"/>
        <vers num="2.4.18" edition="pre4"/>
        <vers num="2.4.18" edition="pre5"/>
        <vers num="2.4.18" edition="pre6"/>
        <vers num="2.4.18" edition="pre7"/>
        <vers num="2.4.18" edition="pre8"/>
        <vers num="2.4.19" edition="pre1"/>
        <vers num="2.4.19" edition="pre2"/>
        <vers num="2.4.19" edition="pre3"/>
        <vers num="2.4.19" edition="pre4"/>
        <vers num="2.4.19" edition="pre5"/>
        <vers num="2.4.19" edition="pre6"/>
        <vers num="2.4.2"/>
        <vers num="2.4.20"/>
        <vers num="2.4.21" edition="pre1"/>
        <vers num="2.4.21" edition="pre4"/>
        <vers num="2.4.21" edition="pre7"/>
        <vers num="2.4.22"/>
        <vers num="2.4.23" edition="pre9"/>
        <vers num="2.4.23_ow2"/>
        <vers num="2.4.24"/>
        <vers num="2.4.24_ow1"/>
        <vers num="2.4.3"/>
        <vers num="2.4.4"/>
        <vers num="2.4.5"/>
        <vers num="2.4.6"/>
        <vers num="2.4.7"/>
        <vers num="2.4.8"/>
        <vers num="2.4.9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" seq="2004-0076" reject="1" published="2004-08-18" name="CVE-2004-0076" modified="2008-09-10">
    <desc>
      <descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: none.  Reason: This candidate was removed from consideration by its Candidate Numbering Authority.  Notes: none.</descript>
    </desc>
    <refs/>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0077" published="2004-03-03" name="CVE-2004-0077" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">The do_mremap function for the mremap system call in Linux 2.2 to 2.2.25, 2.4 to 2.4.24, and 2.6 to 2.6.2, does not properly check the return value from the do_munmap function when the maximum number of VMA descriptors is exceeded, which allows local users to gain root privileges, a different vulnerability than CAN-2003-0985.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/981222" source="CERT-VN">VU#981222</ref>
      <ref url="http://www.securityfocus.com/bid/9686" source="BID" patch="1" adv="1">9686</ref>
      <ref url="http://www.debian.org/security/2004/dsa-439" source="DEBIAN" patch="1" adv="1">DSA-439</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200403-02.xml" source="GENTOO" patch="1" adv="1">GLSA-200403-02</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15244" source="XF" adv="1">linux-mremap-gain-privileges(15244)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107711762014175&amp;w=2" source="BUGTRAQ" adv="1">20040218 Second critical mremap() bug found in all Linux kernels</ref>
      <ref url="http://isec.pl/vulnerabilities/isec-0014-mremap-unmap.txt" source="MISC">http://isec.pl/vulnerabilities/isec-0014-mremap-unmap.txt</ref>
      <ref url="http://www.slackware.com/security/viewer.php?l=slackware-security&amp;y=2004&amp;m=slackware-security.404734" source="SLACKWARE">SSA:2004-049</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-106.html" source="REDHAT">RHSA-2004:106</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-069.html" source="REDHAT">RHSA-2004:069</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-066.html" source="REDHAT">RHSA-2004:066</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-065.html" source="REDHAT">RHSA-2004:065</ref>
      <ref url="http://www.osvdb.org/3986" source="OSVDB">3986</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2004_05_linux_kernel.html" source="SUSE">SuSE-SA:2004:005</ref>
      <ref url="http://www.debian.org/security/2004/dsa-514" source="DEBIAN">DSA-514</ref>
      <ref url="http://www.debian.org/security/2004/dsa-475" source="DEBIAN">DSA-475</ref>
      <ref url="http://www.debian.org/security/2004/dsa-470" source="DEBIAN">DSA-470</ref>
      <ref url="http://www.debian.org/security/2004/dsa-466" source="DEBIAN">DSA-466</ref>
      <ref url="http://www.debian.org/security/2004/dsa-456" source="DEBIAN">DSA-456</ref>
      <ref url="http://www.debian.org/security/2004/dsa-454" source="DEBIAN">DSA-454</ref>
      <ref url="http://www.debian.org/security/2004/dsa-453" source="DEBIAN">DSA-453</ref>
      <ref url="http://www.debian.org/security/2004/dsa-450" source="DEBIAN">DSA-450</ref>
      <ref url="http://www.debian.org/security/2004/dsa-444" source="DEBIAN">DSA-444</ref>
      <ref url="http://www.debian.org/security/2004/dsa-442" source="DEBIAN">DSA-442</ref>
      <ref url="http://www.debian.org/security/2004/dsa-441" source="DEBIAN">DSA-441</ref>
      <ref url="http://www.debian.org/security/2004/dsa-440" source="DEBIAN">DSA-440</ref>
      <ref url="http://www.debian.org/security/2004/dsa-438" source="DEBIAN">DSA-438</ref>
      <ref url="http://www.ciac.org/ciac/bulletins/o-082.shtml" source="CIAC">O-082</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107755871932680&amp;w=2" source="TRUSTIX">2004-0008</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107712137732553&amp;w=2" source="TRUSTIX">2004-0007</ref>
      <ref url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2004:015" source="MANDRAKE">MDKSA-2004:015</ref>
      <ref url="http://fedoranews.org/updates/FEDORA-2004-079.shtml" source="FEDORA">FEDORA-2004-079</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000820" source="CONECTIVA">CLA-2004:820</ref>
      <ref url="http://archives.neohapsis.com/archives/vulnwatch/2004-q1/0040.html" source="VULNWATCH">20040218 Second critical mremap() bug found in all Linux kernels</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:837" source="OVAL" sig="1">oval:org.mitre.oval:def:837</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:825" source="OVAL" sig="1">oval:org.mitre.oval:def:825</ref>
    </refs>
    <vuln_soft>
      <prod vendor="redhat" name="bigmem_kernel">
        <vers num="2.4.20-8" edition=""/>
        <vers num="2.4.20-8" edition=":i686"/>
      </prod>
      <prod vendor="redhat" name="kernel">
        <vers num="2.4.20-8" edition=""/>
        <vers num="2.4.20-8" edition=":athlon"/>
        <vers num="2.4.20-8" edition=":athlon_smp"/>
        <vers num="2.4.20-8" edition=":i686_smp"/>
        <vers num="2.4.20-8" edition=":i686"/>
        <vers num="2.4.20-8" edition=":i386"/>
      </prod>
      <prod vendor="redhat" name="kernel_doc">
        <vers num="2.4.20-8" edition=""/>
        <vers num="2.4.20-8" edition=":i386"/>
      </prod>
      <prod vendor="redhat" name="kernel_source">
        <vers num="2.4.20-8" edition=""/>
        <vers num="2.4.20-8" edition=":i386_src"/>
      </prod>
      <prod vendor="linux" name="linux_kernel">
        <vers num="2.2.0"/>
        <vers num="2.2.1"/>
        <vers num="2.2.10"/>
        <vers num="2.2.11"/>
        <vers num="2.2.12"/>
        <vers num="2.2.13"/>
        <vers num="2.2.14"/>
        <vers num="2.2.15" edition="pre16"/>
        <vers num="2.2.15_pre20"/>
        <vers num="2.2.16" edition="pre6"/>
        <vers num="2.2.17"/>
        <vers num="2.2.18"/>
        <vers num="2.2.19"/>
        <vers num="2.2.2"/>
        <vers num="2.2.20"/>
        <vers num="2.2.21"/>
        <vers num="2.2.22"/>
        <vers num="2.2.23"/>
        <vers num="2.2.24"/>
        <vers num="2.2.3"/>
        <vers num="2.2.4"/>
        <vers num="2.2.5"/>
        <vers num="2.2.6"/>
        <vers num="2.2.7"/>
        <vers num="2.2.8"/>
        <vers num="2.2.9"/>
        <vers num="2.4.0" edition="test1"/>
        <vers num="2.4.0" edition="test10"/>
        <vers num="2.4.0" edition="test11"/>
        <vers num="2.4.0" edition="test12"/>
        <vers num="2.4.0" edition="test2"/>
        <vers num="2.4.0" edition="test3"/>
        <vers num="2.4.0" edition="test4"/>
        <vers num="2.4.0" edition="test5"/>
        <vers num="2.4.0" edition="test6"/>
        <vers num="2.4.0" edition="test7"/>
        <vers num="2.4.0" edition="test8"/>
        <vers num="2.4.0" edition="test9"/>
        <vers num="2.4.1"/>
        <vers num="2.4.10"/>
        <vers num="2.4.11"/>
        <vers num="2.4.12"/>
        <vers num="2.4.13"/>
        <vers num="2.4.14"/>
        <vers num="2.4.15"/>
        <vers num="2.4.16"/>
        <vers num="2.4.17"/>
        <vers num="2.4.18" edition=""/>
        <vers num="2.4.18" edition=":x86"/>
        <vers num="2.4.18" edition="pre1"/>
        <vers num="2.4.18" edition="pre2"/>
        <vers num="2.4.18" edition="pre3"/>
        <vers num="2.4.18" edition="pre4"/>
        <vers num="2.4.18" edition="pre5"/>
        <vers num="2.4.18" edition="pre6"/>
        <vers num="2.4.18" edition="pre7"/>
        <vers num="2.4.18" edition="pre8"/>
        <vers num="2.4.19" edition="pre1"/>
        <vers num="2.4.19" edition="pre2"/>
        <vers num="2.4.19" edition="pre3"/>
        <vers num="2.4.19" edition="pre4"/>
        <vers num="2.4.19" edition="pre5"/>
        <vers num="2.4.19" edition="pre6"/>
        <vers num="2.4.2"/>
        <vers num="2.4.20"/>
        <vers num="2.4.21" edition="pre1"/>
        <vers num="2.4.21" edition="pre4"/>
        <vers num="2.4.21" edition="pre7"/>
        <vers num="2.4.22"/>
        <vers num="2.4.23" edition="pre9"/>
        <vers num="2.4.24"/>
        <vers num="2.4.3"/>
        <vers num="2.4.4"/>
        <vers num="2.4.5"/>
        <vers num="2.4.6"/>
        <vers num="2.4.7"/>
        <vers num="2.4.8"/>
        <vers num="2.4.9"/>
        <vers num="2.6.0" edition="test1"/>
        <vers num="2.6.0" edition="test10"/>
        <vers num="2.6.0" edition="test11"/>
        <vers num="2.6.0" edition="test2"/>
        <vers num="2.6.0" edition="test3"/>
        <vers num="2.6.0" edition="test4"/>
        <vers num="2.6.0" edition="test5"/>
        <vers num="2.6.0" edition="test6"/>
        <vers num="2.6.0" edition="test7"/>
        <vers num="2.6.0" edition="test8"/>
        <vers num="2.6.0" edition="test9"/>
        <vers num="2.6.1" edition="rc1"/>
        <vers num="2.6.1" edition="rc2"/>
        <vers num="2.6.2"/>
        <vers num="2.6_test9_cvs"/>
      </prod>
      <prod vendor="netwosix" name="netwosix_linux">
        <vers num="1.0"/>
      </prod>
      <prod vendor="trustix" name="secure_linux">
        <vers num="1.5"/>
        <vers num="2.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0078" published="2004-03-03" name="CVE-2004-0078" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in the index menu code (menu_pad_string of menu.c) for Mutt 1.4.1 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via certain mail messages.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <vuln_types>
      <input buffer="1"/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/9641" source="BID" patch="1" adv="1">9641</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-051.html" source="REDHAT" patch="1" adv="1">RHSA-2004:051</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-050.html" source="REDHAT" patch="1" adv="1">RHSA-2004:050</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15134" source="XF" adv="1">mutt-index-menu-bo(15134)</ref>
      <ref url="http://bugs.debian.org/126336" source="CONFIRM">http://bugs.debian.org/126336</ref>
      <ref url="http://www.slackware.com/security/viewer.php?l=slackware-security&amp;y=2004&amp;m=slackware-security.405053" source="SLACKWARE">SSA:2004-043</ref>
      <ref url="http://www.osvdb.org/3918" source="OSVDB">3918</ref>
      <ref url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2004:010" source="MANDRAKE">MDKSA-2004:010</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107884956930903&amp;w=2" source="BUGTRAQ">20040309 [OpenPKG-SA-2004.005] OpenPKG Security Advisory (mutt)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107696262905039&amp;w=2" source="BUGTRAQ">20040215 LNSA-#2004-0001: mutt remote crash</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107651677817933&amp;w=2" source="BUGTRAQ">20040211 Mutt-1.4.2 fixes buffer overflow.</ref>
      <ref url="ftp://ftp.caldera.com/pub/security/OpenLinux/CSSA-2004-013.0.txt" source="CALDERA">CSSA-2004-013.0</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:838" source="OVAL" sig="1">oval:org.mitre.oval:def:838</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:811" source="OVAL" sig="1">oval:org.mitre.oval:def:811</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mutt" name="mutt">
        <vers num="1.2.1"/>
        <vers num="1.2.5"/>
        <vers num="1.2.5.1"/>
        <vers num="1.2.5.12"/>
        <vers num="1.2.5.12_ol"/>
        <vers num="1.2.5.4"/>
        <vers num="1.2.5.5"/>
        <vers num="1.3.12"/>
        <vers num="1.3.12.1"/>
        <vers num="1.3.16"/>
        <vers num="1.3.17"/>
        <vers num="1.3.22"/>
        <vers num="1.3.24"/>
        <vers num="1.3.25"/>
        <vers num="1.3.27"/>
        <vers num="1.3.28"/>
        <vers num="1.4.0"/>
        <vers num="1.4.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0079" published="2004-11-23" name="CVE-2004-0079" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The do_change_cipher_spec function in OpenSSL 0.9.6c to 0.9.6k, and 0.9.7a to 0.9.7c, allows remote attackers to cause a denial of service (crash) via a crafted SSL/TLS handshake that triggers a null dereference.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <vuln_types>
      <input/>
      <exception/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA04-078A.html" source="CERT" adv="1">TA04-078A</ref>
      <ref url="http://www.kb.cert.org/vuls/id/288574" source="CERT-VN">VU#288574</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15505" source="XF" adv="1">openssl-dochangecipherspec-dos(15505)</ref>
      <ref url="http://www.uniras.gov.uk/vuls/2004/224012/index.htm" source="MISC">http://www.uniras.gov.uk/vuls/2004/224012/index.htm</ref>
      <ref url="http://www.trustix.org/errata/2004/0012" source="TRUSTIX">2004-0012</ref>
      <ref url="http://www.slackware.org/security/viewer.php?l=slackware-security&amp;y=2004&amp;m=slackware-security.455961" source="SLACKWARE">SSA:2004-077</ref>
      <ref url="http://www.securityfocus.com/bid/9899" source="BID" adv="1">9899</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-830.html" source="REDHAT">RHSA-2005:830</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-829.html" source="REDHAT">RHSA-2005:829</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-139.html" source="REDHAT">RHSA-2004:139</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-121.html" source="REDHAT">RHSA-2004:121</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-120.html" source="REDHAT">RHSA-2004:120</ref>
      <ref url="http://www.redhat.com/archives/fedora-announce-list/2005-October/msg00087.html" source="FEDORA">FEDORA-2005-1042</ref>
      <ref url="http://www.openssl.org/news/secadv_20040317.txt" source="CONFIRM">http://www.openssl.org/news/secadv_20040317.txt</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2004_07_openssl.html" source="SUSE">SuSE-SA:2004:007</ref>
      <ref url="http://www.linuxsecurity.com/advisories/engarde_advisory-4135.html" source="ENGARDE">ESA-20040317-003</ref>
      <ref url="http://www.debian.org/security/2004/dsa-465" source="DEBIAN">DSA-465</ref>
      <ref url="http://www.cisco.com/warp/public/707/cisco-sa-20040317-openssl.shtml" source="CISCO">20040317 Cisco OpenSSL Implementation Vulnerability</ref>
      <ref url="http://www.ciac.org/ciac/bulletins/o-101.shtml" source="CIAC">O-101</ref>
      <ref url="http://support.lexmark.com/index?page=content&amp;id=TE88&amp;locale=EN&amp;userlocale=EN_US" source="CONFIRM">http://support.lexmark.com/index?page=content&amp;id=TE88&amp;locale=EN&amp;userlocale=EN_US</ref>
      <ref url="http://support.avaya.com/elmodocs2/security/ASA-2005-239.htm" source="CONFIRM">http://support.avaya.com/elmodocs2/security/ASA-2005-239.htm</ref>
      <ref url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doc=fsalert/57524" source="SUNALERT">57524</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200403-03.xml" source="GENTOO">GLSA-200403-03</ref>
      <ref url="http://secunia.com/advisories/18247" source="SECUNIA">18247</ref>
      <ref url="http://secunia.com/advisories/17401" source="SECUNIA">17401</ref>
      <ref url="http://secunia.com/advisories/17398" source="SECUNIA">17398</ref>
      <ref url="http://secunia.com/advisories/17381" source="SECUNIA">17381</ref>
      <ref url="http://secunia.com/advisories/11139" source="SECUNIA">11139</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9779" source="OVAL">oval:org.mitre.oval:def:9779</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5770" source="OVAL">oval:org.mitre.oval:def:5770</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108403806509920&amp;w=2" source="HP">SSRT4717</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107953412903636&amp;w=2" source="BUGTRAQ">20040317 New OpenSSL releases fix denial of service attacks [17 March 2004]</ref>
      <ref url="http://lists.apple.com/mhonarc/security-announce/msg00045.html" source="CONFIRM">http://lists.apple.com/mhonarc/security-announce/msg00045.html</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2005/Aug/msg00000.html" source="APPLE">APPLE-SA-2005-08-15</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2005//Aug/msg00001.html" source="APPLE">APPLE-SA-2005-08-17</ref>
      <ref url="http://fedoranews.org/updates/FEDORA-2004-095.shtml" source="FEDORA">FEDORA-2004-095</ref>
      <ref url="http://docs.info.apple.com/article.html?artnum=61798" source="CONFIRM">http://docs.info.apple.com/article.html?artnum=61798</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000834" source="CONECTIVA">CLA-2004:834</ref>
      <ref url="ftp://ftp.sco.com/pub/updates/OpenServer/SCOSA-2004.10/SCOSA-2004.10.txt" source="SCO">SCOSA-2004.10</ref>
      <ref url="ftp://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2004-005.txt.asc" source="NETBSD">NetBSD-SA2004-005</ref>
      <ref url="ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-04:05.openssl.asc" source="FREEBSD">FreeBSD-SA-04:05</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2004:023" source="MANDRAKE">MDKSA-2004:023</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:975" source="OVAL" sig="1">oval:org.mitre.oval:def:975</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:870" source="OVAL" sig="1">oval:org.mitre.oval:def:870</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2621" source="OVAL" sig="1">oval:org.mitre.oval:def:2621</ref>
    </refs>
    <vuln_soft>
      <prod vendor="4d" name="webstar">
        <vers num="4.0"/>
        <vers num="5.2"/>
        <vers num="5.2.1"/>
        <vers num="5.2.2"/>
        <vers num="5.2.3"/>
        <vers num="5.2.4"/>
        <vers num="5.3"/>
        <vers num="5.3.1"/>
      </prod>
      <prod vendor="avaya" name="intuity_audix">
        <vers num="" edition=":lx"/>
        <vers num="5.1.46"/>
        <vers num="s3210"/>
        <vers num="s3400"/>
      </prod>
      <prod vendor="avaya" name="vsu">
        <vers num="10000_r2.0.1"/>
        <vers num="100_r2.0.1"/>
        <vers num="2000_r2.0.1"/>
        <vers num="5"/>
        <vers num="500"/>
        <vers num="5000_r2.0.1"/>
        <vers num="5x"/>
        <vers num="7500_r2.0.1"/>
      </prod>
      <prod vendor="checkpoint" name="firewall-1">
        <vers num="" edition=":vsx-ng-ai"/>
        <vers num="2.0" edition=""/>
        <vers num="2.0" edition=":gx"/>
        <vers num="next_generation_fp0"/>
        <vers num="next_generation_fp1"/>
        <vers num="next_generation_fp2"/>
      </prod>
      <prod vendor="checkpoint" name="provider-1">
        <vers num="4.1" edition="sp1"/>
        <vers num="4.1" edition="sp2"/>
        <vers num="4.1" edition="sp3"/>
        <vers num="4.1" edition="sp4"/>
      </prod>
      <prod vendor="checkpoint" name="vpn-1">
        <vers num="next_generation_fp0"/>
        <vers num="next_generation_fp1"/>
        <vers num="next_generation_fp2"/>
        <vers num="vsx_ng_with_application_intelligence"/>
      </prod>
      <prod vendor="cisco" name="access_registrar">
        <vers num=""/>
      </prod>
      <prod vendor="cisco" name="application_and_content_networking_software">
        <vers num=""/>
      </prod>
      <prod vendor="cisco" name="ciscoworks_common_management_foundation">
        <vers num="2.1"/>
      </prod>
      <prod vendor="cisco" name="ciscoworks_common_services">
        <vers num="2.2"/>
      </prod>
      <prod vendor="cisco" name="css11000_content_services_switch">
        <vers num=""/>
      </prod>
      <prod vendor="cisco" name="css_secure_content_accelerator">
        <vers num="1.0"/>
        <vers num="2.0"/>
      </prod>
      <prod vendor="cisco" name="okena_stormwatch">
        <vers num="3.2"/>
      </prod>
      <prod vendor="cisco" name="pix_firewall">
        <vers num="6.2.2_.111"/>
      </prod>
      <prod vendor="cisco" name="threat_response">
        <vers num=""/>
      </prod>
      <prod vendor="cisco" name="webns">
        <vers num="6.10"/>
        <vers num="6.10_b4"/>
        <vers num="7.10"/>
        <vers num="7.10_.0.06s"/>
        <vers num="7.1_0.1.02"/>
        <vers num="7.1_0.2.06"/>
        <vers num="7.2_0.0.03"/>
      </prod>
      <prod vendor="hp" name="wbem">
        <vers num="a.01.05.08"/>
        <vers num="a.02.00.00"/>
        <vers num="a.02.00.01"/>
      </prod>
      <prod vendor="lite" name="speed_technologies_litespeed_web_server">
        <vers num="1.0.1"/>
        <vers num="1.0.2"/>
        <vers num="1.0.3"/>
        <vers num="1.1"/>
        <vers num="1.1.1"/>
        <vers num="1.2.1"/>
        <vers num="1.2.2"/>
        <vers num="1.2_rc1"/>
        <vers num="1.2_rc2"/>
        <vers num="1.3"/>
        <vers num="1.3.1"/>
        <vers num="1.3_rc1"/>
        <vers num="1.3_rc2"/>
        <vers num="1.3_rc3"/>
      </prod>
      <prod vendor="neoteris" name="instant_virtual_extranet">
        <vers num="3.0"/>
        <vers num="3.1"/>
        <vers num="3.2"/>
        <vers num="3.3"/>
        <vers num="3.3.1"/>
      </prod>
      <prod vendor="novell" name="edirectory">
        <vers num="8.0"/>
        <vers num="8.5"/>
        <vers num="8.5.12a"/>
        <vers num="8.5.27"/>
        <vers num="8.6.2"/>
        <vers num="8.7"/>
        <vers num="8.7.1" edition="sp1"/>
      </prod>
      <prod vendor="novell" name="imanager">
        <vers num="1.5"/>
        <vers num="2.0"/>
      </prod>
      <prod vendor="openssl" name="openssl">
        <vers num="0.9.6c"/>
        <vers num="0.9.6d"/>
        <vers num="0.9.6e"/>
        <vers num="0.9.6f"/>
        <vers num="0.9.6g"/>
        <vers num="0.9.6h"/>
        <vers num="0.9.6i"/>
        <vers num="0.9.6j"/>
        <vers num="0.9.6k"/>
        <vers num="0.9.7" edition="beta1"/>
        <vers num="0.9.7" edition="beta2"/>
        <vers num="0.9.7" edition="beta3"/>
        <vers num="0.9.7a"/>
        <vers num="0.9.7b"/>
        <vers num="0.9.7c"/>
      </prod>
      <prod vendor="redhat" name="openssl">
        <vers num="0.9.6-15" edition=""/>
        <vers num="0.9.6-15" edition=":i386"/>
        <vers num="0.9.6b-3" edition=""/>
        <vers num="0.9.6b-3" edition=":i386"/>
        <vers num="0.9.7a-2" edition=""/>
        <vers num="0.9.7a-2" edition=":i386_dev"/>
        <vers num="0.9.7a-2" edition=":i386"/>
        <vers num="0.9.7a-2" edition=":i386_perl"/>
      </prod>
      <prod vendor="rsa" name="bsafe_ssl-j_sdk">
        <vers num="3.0"/>
        <vers num="3.0.1"/>
        <vers num="3.1"/>
      </prod>
      <prod vendor="sgi" name="propack">
        <vers num="2.3"/>
        <vers num="2.4"/>
        <vers num="3.0"/>
      </prod>
      <prod vendor="stonesoft" name="servercluster">
        <vers num="2.5"/>
        <vers num="2.5.2"/>
      </prod>
      <prod vendor="stonesoft" name="stonebeat_fullcluster">
        <vers num="1_2.0"/>
        <vers num="1_3.0"/>
        <vers num="2.0"/>
        <vers num="2.5"/>
        <vers num="3.0"/>
      </prod>
      <prod vendor="stonesoft" name="stonebeat_securitycluster">
        <vers num="2.0"/>
        <vers num="2.5"/>
      </prod>
      <prod vendor="stonesoft" name="stonebeat_webcluster">
        <vers num="2.0"/>
        <vers num="2.5"/>
      </prod>
      <prod vendor="stonesoft" name="stonegate">
        <vers num="1.5.17"/>
        <vers num="1.5.18"/>
        <vers num="1.6.2"/>
        <vers num="1.6.3"/>
        <vers num="1.7"/>
        <vers num="1.7.1"/>
        <vers num="1.7.2"/>
        <vers num="2.0.1"/>
        <vers num="2.0.4"/>
        <vers num="2.0.5"/>
        <vers num="2.0.6"/>
        <vers num="2.0.7"/>
        <vers num="2.0.8"/>
        <vers num="2.0.9"/>
        <vers num="2.1"/>
        <vers num="2.2"/>
        <vers num="2.2.1"/>
        <vers num="2.2.4"/>
      </prod>
      <prod vendor="stonesoft" name="stonegate_vpn_client">
        <vers num="1.7"/>
        <vers num="1.7.2"/>
        <vers num="2.0"/>
        <vers num="2.0.7"/>
        <vers num="2.0.8"/>
        <vers num="2.0.9"/>
      </prod>
      <prod vendor="tarantella" name="tarantella_enterprise">
        <vers num="3.20"/>
        <vers num="3.30"/>
        <vers num="3.40"/>
      </prod>
      <prod vendor="vmware" name="gsx_server">
        <vers num="2.0"/>
        <vers num="2.0.1_build_2129"/>
        <vers num="2.5.1"/>
        <vers num="2.5.1_build_5336"/>
        <vers num="3.0_build_7592"/>
      </prod>
      <prod vendor="avaya" name="converged_communications_server">
        <vers num="2.0"/>
      </prod>
      <prod vendor="avaya" name="s8300">
        <vers num="r2.0.0"/>
        <vers num="r2.0.1"/>
      </prod>
      <prod vendor="avaya" name="s8500">
        <vers num="r2.0.0"/>
        <vers num="r2.0.1"/>
      </prod>
      <prod vendor="avaya" name="s8700">
        <vers num="r2.0.0"/>
        <vers num="r2.0.1"/>
      </prod>
      <prod vendor="avaya" name="sg200">
        <vers num="4.31.29"/>
        <vers num="4.4"/>
      </prod>
      <prod vendor="avaya" name="sg203">
        <vers num="4.31.29"/>
        <vers num="4.4"/>
      </prod>
      <prod vendor="avaya" name="sg208">
        <vers num="4.4"/>
      </prod>
      <prod vendor="avaya" name="sg5">
        <vers num="4.2"/>
        <vers num="4.3"/>
        <vers num="4.4"/>
      </prod>
      <prod vendor="bluecoat" name="proxysg">
        <vers num=""/>
      </prod>
      <prod vendor="cisco" name="call_manager">
        <vers num=""/>
      </prod>
      <prod vendor="cisco" name="content_services_switch_11500">
        <vers num=""/>
      </prod>
      <prod vendor="cisco" name="firewall_services_module">
        <vers num="1.1.2"/>
        <vers num="1.1.3"/>
        <vers num="1.1_(3.005)"/>
        <vers num="2.1_(0.208)"/>
      </prod>
      <prod vendor="cisco" name="gss_4480_global_site_selector">
        <vers num=""/>
      </prod>
      <prod vendor="cisco" name="gss_4490_global_site_selector">
        <vers num=""/>
      </prod>
      <prod vendor="cisco" name="mds_9000">
        <vers num=""/>
      </prod>
      <prod vendor="cisco" name="secure_content_accelerator">
        <vers num="10000"/>
      </prod>
      <prod vendor="hp" name="aaa_server">
        <vers num=""/>
      </prod>
      <prod vendor="hp" name="apache-based_web_server">
        <vers num="2.0.43.00"/>
        <vers num="2.0.43.04"/>
      </prod>
      <prod vendor="securecomputing" name="sidewinder">
        <vers num="5.2"/>
        <vers num="5.2.0.01"/>
        <vers num="5.2.0.02"/>
        <vers num="5.2.0.03"/>
        <vers num="5.2.0.04"/>
        <vers num="5.2.1"/>
        <vers num="5.2.1.02"/>
      </prod>
      <prod vendor="sun" name="crypto_accelerator_4000">
        <vers num="1.0"/>
      </prod>
      <prod vendor="symantec" name="clientless_vpn_gateway_4400">
        <vers num="5.0"/>
      </prod>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.3.3"/>
      </prod>
      <prod vendor="apple" name="mac_os_x_server">
        <vers num="10.3.3"/>
      </prod>
      <prod vendor="bluecoat" name="cacheos_ca_sa">
        <vers num="4.1.10"/>
        <vers num="4.1.12"/>
      </prod>
      <prod vendor="cisco" name="ios">
        <vers num="12.1(11)e"/>
        <vers num="12.1(11b)e"/>
        <vers num="12.1(11b)e12"/>
        <vers num="12.1(11b)e14"/>
        <vers num="12.1(13)e9"/>
        <vers num="12.1(19)e1"/>
        <vers num="12.2(14)sy"/>
        <vers num="12.2(14)sy1"/>
        <vers num="12.2sy"/>
        <vers num="12.2za"/>
      </prod>
      <prod vendor="cisco" name="pix_firewall">
        <vers num="6.0"/>
        <vers num="6.0(1)"/>
        <vers num="6.0(2)"/>
        <vers num="6.0(3)"/>
        <vers num="6.0(4)"/>
        <vers num="6.0(4.101)"/>
        <vers num="6.1"/>
        <vers num="6.1(1)"/>
        <vers num="6.1(2)"/>
        <vers num="6.1(3)"/>
        <vers num="6.1(4)"/>
        <vers num="6.1(5)"/>
        <vers num="6.2"/>
        <vers num="6.2(1)"/>
        <vers num="6.2(2)"/>
        <vers num="6.2(3)"/>
        <vers num="6.2(3.100)"/>
        <vers num="6.3"/>
        <vers num="6.3(1)"/>
        <vers num="6.3(2)"/>
        <vers num="6.3(3.102)"/>
        <vers num="6.3(3.109)"/>
      </prod>
      <prod vendor="freebsd" name="freebsd">
        <vers num="4.8" edition="releng"/>
        <vers num="4.9"/>
        <vers num="5.1" edition="release"/>
        <vers num="5.1" edition="releng"/>
        <vers num="5.2"/>
        <vers num="5.2.1" edition="release"/>
      </prod>
      <prod vendor="hp" name="hp-ux">
        <vers num="11.00"/>
        <vers num="11.11"/>
        <vers num="11.23"/>
        <vers num="8.05"/>
      </prod>
      <prod vendor="openbsd" name="openbsd">
        <vers num="3.3"/>
        <vers num="3.4"/>
      </prod>
      <prod vendor="redhat" name="enterprise_linux">
        <vers num="3.0" edition=""/>
        <vers num="3.0" edition=":workstation_server"/>
        <vers num="3.0" edition=":advanced_server"/>
        <vers num="3.0" edition=":enterprise_server"/>
      </prod>
      <prod vendor="redhat" name="enterprise_linux_desktop">
        <vers num="3.0"/>
      </prod>
      <prod vendor="redhat" name="linux">
        <vers num="7.2"/>
        <vers num="7.3"/>
        <vers num="8.0"/>
      </prod>
      <prod vendor="sco" name="openserver">
        <vers num="5.0.6"/>
        <vers num="5.0.7"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0080" published="2004-03-03" name="CVE-2004-0080" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The login program in util-linux 2.11 and earlier uses a pointer after it has been freed and reallocated, which could cause login to leak sensitive data.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <vuln_types>
      <design/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/801526" source="CERT-VN">VU#801526</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-056.html" source="REDHAT" patch="1" adv="1">RHSA-2004:056</ref>
      <ref url="http://www.securityfocus.com/bid/9558" source="BID" adv="1">9558</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15016" source="XF">utillinux-information-leak(15016)</ref>
      <ref url="http://www.osvdb.org/3796" source="OSVDB">3796</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200404-06.xml" source="GENTOO">GLSA-200404-06</ref>
      <ref url="http://secunia.com/advisories/10773" source="SECUNIA">10773</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108144719532385&amp;w=2" source="BUGTRAQ">20040408 LNSA-#2004-0010: login may leak sensitive data</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108077689801698&amp;w=2" source="BUGTRAQ">20040331 OpenLinux: util-linux could leak sensitive data</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/20040406-01-U" source="SGI">20040406-01-U</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/20040201-01-U.asc" source="SGI">20040201-01-U</ref>
    </refs>
    <vuln_soft>
      <prod vendor="andries_brouwer" name="util-linux">
        <vers prev="1" num="2.11"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0081" published="2004-11-23" name="CVE-2004-0081" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">OpenSSL 0.9.6 before 0.9.6d does not properly handle unknown message types, which allows remote attackers to cause a denial of service (infinite loop), as demonstrated using the Codenomicon TLS Test Tool.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <vuln_types>
      <exception/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA04-078A.html" source="CERT">TA04-078A</ref>
      <ref url="http://www.kb.cert.org/vuls/id/465542" source="CERT-VN" adv="1">VU#465542</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15509" source="XF" adv="1">openssl-tls-dos(15509)</ref>
      <ref url="http://www.uniras.gov.uk/vuls/2004/224012/index.htm" source="MISC">http://www.uniras.gov.uk/vuls/2004/224012/index.htm</ref>
      <ref url="http://www.trustix.org/errata/2004/0012" source="TRUSTIX">2004-0012</ref>
      <ref url="http://www.securityfocus.com/bid/9899" source="BID" adv="1">9899</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-139.html" source="REDHAT">RHSA-2004:139</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-121.html" source="REDHAT">RHSA-2004:121</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-120.html" source="REDHAT">RHSA-2004:120</ref>
      <ref url="http://www.linuxsecurity.com/advisories/engarde_advisory-4135.html" source="ENGARDE">ESA-20040317-003</ref>
      <ref url="http://www.debian.org/security/2004/dsa-465" source="DEBIAN">DSA-465</ref>
      <ref url="http://www.cisco.com/warp/public/707/cisco-sa-20040317-openssl.shtml" source="CISCO">20040317 Cisco OpenSSL Implementation Vulnerability</ref>
      <ref url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doc=fsalert/57524" source="SUNALERT">57524</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200403-03.xml" source="GENTOO">GLSA-200403-03</ref>
      <ref url="http://secunia.com/advisories/11139" source="SECUNIA">11139</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2004-119.html" source="REDHAT">RHSA-2004:119</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11755" source="OVAL">oval:org.mitre.oval:def:11755</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108403850228012&amp;w=2" source="BUGTRAQ">20040508 [FLSA-2004:1395] Updated OpenSSL resolves security vulnerability</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107955049331965&amp;w=2" source="BUGTRAQ">20040317 Re: New OpenSSL releases fix denial of service attacks [17  March 2004]</ref>
      <ref url="http://fedoranews.org/updates/FEDORA-2004-095.shtml" source="FEDORA">FEDORA-2004-095</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000834" source="CONECTIVA">CLA-2004:834</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/20040304-01-U.asc" source="SGI">20040304-01-U</ref>
      <ref url="ftp://ftp.sco.com/pub/updates/OpenServer/SCOSA-2004.10/SCOSA-2004.10.txt" source="SCO">SCOSA-2004.10</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:902" source="OVAL" sig="1">oval:org.mitre.oval:def:902</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:871" source="OVAL" sig="1">oval:org.mitre.oval:def:871</ref>
    </refs>
    <vuln_soft>
      <prod vendor="4d" name="webstar">
        <vers num="4.0"/>
        <vers num="5.2"/>
        <vers num="5.2.1"/>
        <vers num="5.2.2"/>
        <vers num="5.2.3"/>
        <vers num="5.2.4"/>
        <vers num="5.3"/>
        <vers num="5.3.1"/>
      </prod>
      <prod vendor="avaya" name="intuity_audix">
        <vers num="" edition=":lx"/>
        <vers num="5.1.46"/>
        <vers num="s3210"/>
        <vers num="s3400"/>
      </prod>
      <prod vendor="avaya" name="vsu">
        <vers num="10000_r2.0.1"/>
        <vers num="100_r2.0.1"/>
        <vers num="2000_r2.0.1"/>
        <vers num="5"/>
        <vers num="500"/>
        <vers num="5000_r2.0.1"/>
        <vers num="5x"/>
        <vers num="7500_r2.0.1"/>
      </prod>
      <prod vendor="checkpoint" name="firewall-1">
        <vers num="" edition=":vsx-ng-ai"/>
        <vers num="2.0" edition=""/>
        <vers num="2.0" edition=":gx"/>
        <vers num="next_generation_fp0"/>
        <vers num="next_generation_fp1"/>
        <vers num="next_generation_fp2"/>
      </prod>
      <prod vendor="checkpoint" name="provider-1">
        <vers num="4.1" edition="sp1"/>
        <vers num="4.1" edition="sp2"/>
        <vers num="4.1" edition="sp3"/>
        <vers num="4.1" edition="sp4"/>
      </prod>
      <prod vendor="checkpoint" name="vpn-1">
        <vers num="next_generation"/>
        <vers num="next_generation_fp0"/>
        <vers num="next_generation_fp1"/>
        <vers num="vsx_ng_with_application_intelligence"/>
      </prod>
      <prod vendor="cisco" name="access_registrar">
        <vers num=""/>
      </prod>
      <prod vendor="cisco" name="application_and_content_networking_software">
        <vers num=""/>
      </prod>
      <prod vendor="cisco" name="ciscoworks_common_management_foundation">
        <vers num="2.1"/>
      </prod>
      <prod vendor="cisco" name="ciscoworks_common_services">
        <vers num="2.2"/>
      </prod>
      <prod vendor="cisco" name="css11000_content_services_switch">
        <vers num=""/>
      </prod>
      <prod vendor="cisco" name="css_secure_content_accelerator">
        <vers num="1.0"/>
        <vers num="2.0"/>
      </prod>
      <prod vendor="cisco" name="okena_stormwatch">
        <vers num="3.2"/>
      </prod>
      <prod vendor="cisco" name="pix_firewall">
        <vers num="6.2.2_.111"/>
      </prod>
      <prod vendor="cisco" name="threat_response">
        <vers num=""/>
      </prod>
      <prod vendor="cisco" name="webns">
        <vers num="6.10"/>
        <vers num="6.10_b4"/>
        <vers num="7.10"/>
        <vers num="7.10_.0.06s"/>
        <vers num="7.1_0.1.02"/>
        <vers num="7.1_0.2.06"/>
        <vers num="7.2_0.0.03"/>
      </prod>
      <prod vendor="hp" name="wbem">
        <vers num="a.01.05.08"/>
        <vers num="a.02.00.00"/>
        <vers num="a.02.00.01"/>
      </prod>
      <prod vendor="lite" name="speed_technologies_litespeed_web_server">
        <vers num="1.0.1"/>
        <vers num="1.0.2"/>
        <vers num="1.0.3"/>
        <vers num="1.1"/>
        <vers num="1.1.1"/>
        <vers num="1.2.1"/>
        <vers num="1.2.2"/>
        <vers num="1.2_rc1"/>
        <vers num="1.2_rc2"/>
        <vers num="1.3"/>
        <vers num="1.3.1"/>
        <vers num="1.3_rc1"/>
        <vers num="1.3_rc2"/>
        <vers num="1.3_rc3"/>
      </prod>
      <prod vendor="neoteris" name="instant_virtual_extranet">
        <vers num="3.0"/>
        <vers num="3.1"/>
        <vers num="3.2"/>
        <vers num="3.3"/>
        <vers num="3.3.1"/>
      </prod>
      <prod vendor="novell" name="edirectory">
        <vers num="8.0"/>
        <vers num="8.5"/>
        <vers num="8.5.12a"/>
        <vers num="8.5.27"/>
        <vers num="8.6.2"/>
        <vers num="8.7"/>
        <vers num="8.7.1" edition="sp1"/>
      </prod>
      <prod vendor="novell" name="imanager">
        <vers num="1.5"/>
        <vers num="2.0"/>
      </prod>
      <prod vendor="openssl" name="openssl">
        <vers num="0.9.6c"/>
        <vers num="0.9.6d"/>
        <vers num="0.9.6e"/>
        <vers num="0.9.6f"/>
        <vers num="0.9.6g"/>
        <vers num="0.9.6h"/>
        <vers num="0.9.6i"/>
        <vers num="0.9.6j"/>
        <vers num="0.9.6k"/>
        <vers num="0.9.7" edition="beta1"/>
        <vers num="0.9.7" edition="beta2"/>
        <vers num="0.9.7" edition="beta3"/>
        <vers num="0.9.7a"/>
        <vers num="0.9.7b"/>
        <vers num="0.9.7c"/>
      </prod>
      <prod vendor="redhat" name="openssl">
        <vers num="0.9.6-15" edition=""/>
        <vers num="0.9.6-15" edition=":i386"/>
        <vers num="0.9.6b-3" edition=""/>
        <vers num="0.9.6b-3" edition=":i386"/>
        <vers num="0.9.7a-2" edition=""/>
        <vers num="0.9.7a-2" edition=":i386_dev"/>
        <vers num="0.9.7a-2" edition=":i386"/>
        <vers num="0.9.7a-2" edition=":i386_perl"/>
      </prod>
      <prod vendor="rsa" name="bsafe_ssl-j_sdk">
        <vers num="3.0"/>
        <vers num="3.0.1"/>
        <vers num="3.1"/>
      </prod>
      <prod vendor="sgi" name="propack">
        <vers num="2.3"/>
        <vers num="2.4"/>
        <vers num="3.0"/>
      </prod>
      <prod vendor="stonesoft" name="servercluster">
        <vers num="2.5"/>
        <vers num="2.5.2"/>
      </prod>
      <prod vendor="stonesoft" name="stonebeat_fullcluster">
        <vers num="1_2.0"/>
        <vers num="1_3.0"/>
        <vers num="2.0"/>
        <vers num="2.5"/>
        <vers num="3.0"/>
      </prod>
      <prod vendor="stonesoft" name="stonebeat_securitycluster">
        <vers num="2.0"/>
        <vers num="2.5"/>
      </prod>
      <prod vendor="stonesoft" name="stonebeat_webcluster">
        <vers num="2.0"/>
        <vers num="2.5"/>
      </prod>
      <prod vendor="stonesoft" name="stonegate">
        <vers num="1.5.17"/>
        <vers num="1.5.18"/>
        <vers num="1.6.2"/>
        <vers num="1.6.3"/>
        <vers num="1.7"/>
        <vers num="1.7.1"/>
        <vers num="1.7.2"/>
        <vers num="2.0.1"/>
        <vers num="2.0.4"/>
        <vers num="2.0.5"/>
        <vers num="2.0.6"/>
        <vers num="2.0.7"/>
        <vers num="2.0.8"/>
        <vers num="2.0.9"/>
        <vers num="2.1"/>
        <vers num="2.2"/>
        <vers num="2.2.1"/>
        <vers num="2.2.4"/>
      </prod>
      <prod vendor="stonesoft" name="stonegate_vpn_client">
        <vers num="1.7"/>
        <vers num="1.7.2"/>
        <vers num="2.0"/>
        <vers num="2.0.7"/>
        <vers num="2.0.8"/>
        <vers num="2.0.9"/>
      </prod>
      <prod vendor="tarantella" name="tarantella_enterprise">
        <vers num="3.20"/>
        <vers num="3.30"/>
        <vers num="3.40"/>
      </prod>
      <prod vendor="vmware" name="gsx_server">
        <vers num="2.0"/>
        <vers num="2.0.1_build_2129"/>
        <vers num="2.5.1"/>
        <vers num="2.5.1_build_5336"/>
        <vers num="3.0_build_7592"/>
      </prod>
      <prod vendor="avaya" name="converged_communications_server">
        <vers num="2.0"/>
      </prod>
      <prod vendor="avaya" name="s8300">
        <vers num="r2.0.0"/>
        <vers num="r2.0.1"/>
      </prod>
      <prod vendor="avaya" name="s8500">
        <vers num="r2.0.0"/>
        <vers num="r2.0.1"/>
      </prod>
      <prod vendor="avaya" name="s8700">
        <vers num="r2.0.0"/>
        <vers num="r2.0.1"/>
      </prod>
      <prod vendor="avaya" name="sg200">
        <vers num="4.31.29"/>
        <vers num="4.4"/>
      </prod>
      <prod vendor="avaya" name="sg203">
        <vers num="4.31.29"/>
        <vers num="4.4"/>
      </prod>
      <prod vendor="avaya" name="sg208">
        <vers num="4.4"/>
      </prod>
      <prod vendor="avaya" name="sg5">
        <vers num="4.2"/>
        <vers num="4.3"/>
        <vers num="4.4"/>
      </prod>
      <prod vendor="bluecoat" name="proxysg">
        <vers num=""/>
      </prod>
      <prod vendor="cisco" name="call_manager">
        <vers num=""/>
      </prod>
      <prod vendor="cisco" name="content_services_switch_11500">
        <vers num=""/>
      </prod>
      <prod vendor="cisco" name="firewall_services_module">
        <vers num="1.1.2"/>
        <vers num="1.1.3"/>
        <vers num="1.1_(3.005)"/>
        <vers num="2.1_(0.208)"/>
      </prod>
      <prod vendor="cisco" name="gss_4480_global_site_selector">
        <vers num=""/>
      </prod>
      <prod vendor="cisco" name="gss_4490_global_site_selector">
        <vers num=""/>
      </prod>
      <prod vendor="cisco" name="mds_9000">
        <vers num=""/>
      </prod>
      <prod vendor="cisco" name="secure_content_accelerator">
        <vers num="10000"/>
      </prod>
      <prod vendor="hp" name="aaa_server">
        <vers num=""/>
      </prod>
      <prod vendor="hp" name="apache-based_web_server">
        <vers num="2.0.43.00"/>
        <vers num="2.0.43.04"/>
      </prod>
      <prod vendor="securecomputing" name="sidewinder">
        <vers num="5.2"/>
        <vers num="5.2.0.01"/>
        <vers num="5.2.0.02"/>
        <vers num="5.2.0.03"/>
        <vers num="5.2.0.04"/>
        <vers num="5.2.1"/>
        <vers num="5.2.1.02"/>
      </prod>
      <prod vendor="sun" name="crypto_accelerator_4000">
        <vers num="1.0"/>
      </prod>
      <prod vendor="symantec" name="clientless_vpn_gateway_4400">
        <vers num="5.0"/>
      </prod>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.3.3"/>
      </prod>
      <prod vendor="apple" name="mac_os_x_server">
        <vers num="10.3.3"/>
      </prod>
      <prod vendor="bluecoat" name="cacheos_ca_sa">
        <vers num="4.1.10"/>
        <vers num="4.1.12"/>
      </prod>
      <prod vendor="cisco" name="ios">
        <vers num="12.1(11)e"/>
        <vers num="12.1(11b)e"/>
        <vers num="12.1(11b)e12"/>
        <vers num="12.1(11b)e14"/>
        <vers num="12.1(13)e9"/>
        <vers num="12.1(19)e1"/>
        <vers num="12.2(14)sy"/>
        <vers num="12.2(14)sy1"/>
        <vers num="12.2sy"/>
        <vers num="12.2za"/>
      </prod>
      <prod vendor="cisco" name="pix_firewall">
        <vers num="6.0"/>
        <vers num="6.0(1)"/>
        <vers num="6.0(2)"/>
        <vers num="6.0(3)"/>
        <vers num="6.0(4)"/>
        <vers num="6.0(4.101)"/>
        <vers num="6.1"/>
        <vers num="6.1(1)"/>
        <vers num="6.1(2)"/>
        <vers num="6.1(3)"/>
        <vers num="6.1(4)"/>
        <vers num="6.1(5)"/>
        <vers num="6.2"/>
        <vers num="6.2(1)"/>
        <vers num="6.2(2)"/>
        <vers num="6.2(3)"/>
        <vers num="6.2(3.100)"/>
        <vers num="6.3"/>
        <vers num="6.3(1)"/>
        <vers num="6.3(2)"/>
        <vers num="6.3(3.102)"/>
        <vers num="6.3(3.109)"/>
      </prod>
      <prod vendor="freebsd" name="freebsd">
        <vers num="4.8" edition="releng"/>
        <vers num="4.9"/>
        <vers num="5.1" edition="release"/>
        <vers num="5.1" edition="releng"/>
        <vers num="5.2"/>
        <vers num="5.2.1" edition="release"/>
      </prod>
      <prod vendor="hp" name="hp-ux">
        <vers num="11.00"/>
        <vers num="11.11"/>
        <vers num="11.23"/>
        <vers num="8.05"/>
      </prod>
      <prod vendor="openbsd" name="openbsd">
        <vers num="3.3"/>
        <vers num="3.4"/>
      </prod>
      <prod vendor="redhat" name="enterprise_linux">
        <vers num="3.0" edition=""/>
        <vers num="3.0" edition=":workstation_server"/>
        <vers num="3.0" edition=":advanced_server"/>
        <vers num="3.0" edition=":enterprise_server"/>
      </prod>
      <prod vendor="redhat" name="enterprise_linux_desktop">
        <vers num="3.0"/>
      </prod>
      <prod vendor="redhat" name="linux">
        <vers num="7.2"/>
        <vers num="7.3"/>
        <vers num="8.0"/>
      </prod>
      <prod vendor="sco" name="openserver">
        <vers num="5.0.6"/>
        <vers num="5.0.7"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0082" published="2004-03-03" name="CVE-2004-0082" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">The mksmbpasswd shell script (mksmbpasswd.sh) in Samba 3.0.0 and 3.0.1, when creating an account but marking it as disabled, may overwrite the user password with an uninitialized buffer, which could enable the account with a more easily guessable password.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <design/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/9637" source="BID" patch="1" adv="1">9637</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-064.html" source="REDHAT" patch="1" adv="1">RHSA-2004:064</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15132" source="XF" adv="1">samba-mksmbpasswd-gain-access(15132)</ref>
      <ref url="http://www.vuxml.org/freebsd/3388eff9-5d6e-11d8-80e3-0020ed76ef5a.html" source="CONFIRM">http://www.vuxml.org/freebsd/3388eff9-5d6e-11d8-80e3-0020ed76ef5a.html</ref>
      <ref url="http://us1.samba.org/samba/ftp/WHATSNEW-3.0.2a.txt" source="CONFIRM">http://us1.samba.org/samba/ftp/WHATSNEW-3.0.2a.txt</ref>
      <ref url="http://www.osvdb.org/3919" source="OSVDB">3919</ref>
      <ref url="http://www.ciac.org/ciac/bulletins/o-078.shtml" source="CIAC">O-078</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:827" source="OVAL" sig="1">oval:org.mitre.oval:def:827</ref>
    </refs>
    <vuln_soft>
      <prod vendor="samba" name="samba">
        <vers num="3.0"/>
        <vers num="3.0.0"/>
        <vers num="3.0.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0083" published="2004-03-03" name="CVE-2004-0083" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Buffer overflow in ReadFontAlias from dirfile.c of XFree86 4.1.0 through 4.3.0 allows local users and remote attackers to execute arbitrary code via a font alias file (font.alias) with a long token, a different vulnerability than CVE-2004-0084 and CVE-2004-0106.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <vuln_types>
      <input buffer="1"/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/820006" source="CERT-VN">VU#820006</ref>
      <ref url="http://www.securityfocus.com/bid/9636" source="BID" patch="1" adv="1">9636</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107644835523678&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20040210 iDEFENSESecurityAdvisory02.10.04: XFree86FontInformationFileBufferOverflow</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15130" source="XF" adv="1">xfree86-fontalias-bo(15130)</ref>
      <ref url="http://www.xfree86.org/cvs/changes" source="CONFIRM" adv="1">http://www.xfree86.org/cvs/changes</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-061.html" source="REDHAT">RHSA-2004:061</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-060.html" source="REDHAT">RHSA-2004:060</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-059.html" source="REDHAT">RHSA-2004:059</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2004_06_xf86.html" source="SUSE">SuSE-SA:2004:006</ref>
      <ref url="http://www.idefense.com/application/poi/display?id=72" source="MISC">http://www.idefense.com/application/poi/display?id=72</ref>
      <ref url="http://www.debian.org/security/2004/dsa-443" source="DEBIAN">DSA-443</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200402-02.xml" source="GENTOO" adv="1">GLSA-200402-02</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9612" source="OVAL">oval:org.mitre.oval:def:9612</ref>
      <ref url="http://www.slackware.com/security/viewer.php?l=slackware-security&amp;y=2004&amp;m=slackware-security.405053" source="SLACKWARE">SSA:2004-043</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2004:012" source="MANDRAKE">MDKSA-2004:012</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-57768-1" source="SUNALERT">57768</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110979666528890&amp;w=2" source="FEDORA">FLSA:2314</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107653324115914&amp;w=2" source="BUGTRAQ">20040211 XFree86 vulnerability exploit</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000821" source="CONECTIVA">CLA-2004:821</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:830" source="OVAL" sig="1">oval:org.mitre.oval:def:830</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:806" source="OVAL" sig="1">oval:org.mitre.oval:def:806</ref>
    </refs>
    <vuln_soft>
      <prod vendor="xfree86_project" name="x11r6">
        <vers num="4.1.0"/>
        <vers num="4.1.11"/>
        <vers num="4.1.12"/>
        <vers num="4.2.0"/>
        <vers num="4.2.1" edition=""/>
        <vers num="4.2.1" edition=":errata"/>
        <vers num="4.3.0"/>
      </prod>
      <prod vendor="openbsd" name="openbsd">
        <vers num="3.3"/>
        <vers num="3.4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0084" published="2004-03-03" name="CVE-2004-0084" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Buffer overflow in the ReadFontAlias function in XFree86 4.1.0 to 4.3.0, when using the CopyISOLatin1Lowered function, allows local or remote authenticated users to execute arbitrary code via a malformed entry in the font alias (font.alias) file, a different vulnerability than CVE-2004-0083 and CVE-2004-0106.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <vuln_types>
      <input buffer="1"/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/667502" source="CERT-VN">VU#667502</ref>
      <ref url="http://www.securityfocus.com/bid/9652" source="BID" patch="1" adv="1">9652</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-061.html" source="REDHAT" patch="1" adv="1">RHSA-2004:061</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-060.html" source="REDHAT" patch="1" adv="1">RHSA-2004:060</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15200" source="XF" adv="1">xfree86-copyisolatin1lLowered-bo(15200)</ref>
      <ref url="http://www.slackware.com/security/viewer.php?l=slackware-security&amp;y=2004&amp;m=slackware-security.405053" source="SLACKWARE">SSA:2004-043</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-059.html" source="REDHAT">RHSA-2004:059</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2004_06_xf86.html" source="SUSE">SuSE-SA:2004:006</ref>
      <ref url="http://www.idefense.com/application/poi/display?id=73" source="MISC">http://www.idefense.com/application/poi/display?id=73</ref>
      <ref url="http://www.debian.org/security/2004/dsa-443" source="DEBIAN">DSA-443</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10405" source="OVAL">oval:org.mitre.oval:def:10405</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110979666528890&amp;w=2" source="FEDORA">FLSA:2314</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000821" source="CONECTIVA">CLA-2004:821</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2004:012" source="MANDRAKE">MDKSA-2004:012</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-57768-1" source="SUNALERT">57768</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107662833512775&amp;w=2" source="BUGTRAQ">20040212 iDEFENSE Security Advisory 02.11.04: XFree86 Font Information File Buffer Overflow II</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:831" source="OVAL" sig="1">oval:org.mitre.oval:def:831</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:807" source="OVAL" sig="1">oval:org.mitre.oval:def:807</ref>
    </refs>
    <vuln_soft>
      <prod vendor="xfree86_project" name="x11r6">
        <vers num="4.1.0"/>
        <vers num="4.1.11"/>
        <vers num="4.1.12"/>
        <vers num="4.2.0"/>
        <vers num="4.2.1" edition=""/>
        <vers num="4.2.1" edition=":errata"/>
        <vers num="4.3.0"/>
      </prod>
      <prod vendor="openbsd" name="openbsd">
        <vers num="3.3"/>
        <vers num="3.4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0085" published="2004-03-03" name="CVE-2004-0085" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Unknown vulnerability in the Mail application for Mac OS X 10.1.5 and 10.2.8 with unknown impact, a different vulnerability than CVE-2004-0086.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <vuln_types>
      <other/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/14992" source="XF" patch="1" adv="1">macosx-mail-undisclosed(14992)</ref>
      <ref url="http://www.securityfocus.com/bid/9504" source="BID" patch="1" adv="1">9504</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2004/Jan/msg00000.html" source="APPLE">APPLE-SA-2004-01-26</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.1.5"/>
        <vers num="10.2.8"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0086" published="2004-03-03" name="CVE-2004-0086" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Unknown vulnerability in the Mail application for Mac OS X 10.3.2 has unknown impact and attack vectors, a different vulnerability than CVE-2004-0085.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <vuln_types>
      <other/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/9504" source="BID">9504</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2004/Jan/msg00000.html" source="APPLE">APPLE-SA-2004-01-26</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.3.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2004-0087" published="2004-03-03" name="CVE-2004-0087" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">The System Configuration subsystem in Mac OS 10.2.8 and 10.3.2 allows local users to modify network settings, a different vulnerability than CVE-2004-0088.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <vuln_types>
      <config/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/14997" source="XF">macosx-configd-file-manipulation(14997)</ref>
      <ref url="http://www.securityfocus.com/bid/9504" source="BID">9504</ref>
      <ref url="http://www.osvdb.org/6819" source="OSVDB">6819</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2004/Jan/msg00000.html" source="APPLE">APPLE-SA-2004-01-26</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.2.8"/>
        <vers num="10.3.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2004-0088" published="2004-03-03" name="CVE-2004-0088" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">The System Configuration subsystem in Mac OS 10.2.8 allows local users to modify network settings, a different vulnerability than CVE-2004-0087.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <vuln_types>
      <config/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/9504" source="BID">9504</ref>
      <ref url="http://www.osvdb.org/6820" source="OSVDB">6820</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2004/Jan/msg00000.html" source="APPLE">APPLE-SA-2004-01-26</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.2.8"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0089" published="2004-03-03" name="CVE-2004-0089" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Buffer overflow in TruBlueEnvironment in Mac OS X 10.3.x and 10.2.x allows local users to gain privileges via a long environment variable.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input buffer="1"/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/902374" source="CERT-VN">VU#902374</ref>
      <ref url="http://www.securityfocus.com/bid/9509" source="BID" adv="1">9509</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/14968" source="XF">macosx-trublue-environmentvariable-bo(14968)</ref>
      <ref url="http://www.osvdb.org/6821" source="OSVDB">6821</ref>
      <ref url="http://www.atstake.com/research/advisories/2004/a012704-1.txt" source="ATSTAKE">A012704-1</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2004/Jan/msg00000.html" source="APPLE">APPLE-SA-2004-01-26</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.2.8"/>
        <vers num="10.3.9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0090" published="2004-12-31" name="CVE-2004-0090" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Unknown vulnerability in Windows File Sharing for Mac OS X 10.1.5 through 10.3.2 does not "shutdown properly," which has unknown impact and attack vectors.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/9504" source="BID" patch="1">9504</ref>
      <ref url="http://secunia.com/advisories/10723/" source="SECUNIA" patch="1" adv="1">10723</ref>
      <ref url="http://www.auscert.org.au/render.html?it=3791&amp;cid=1" source="AUSCERT" adv="1">ESB-2004.0072</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2004/Jan/msg00000.html" source="APPLE" adv="1">APPLE-SA-2004-01-26</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.1.5"/>
        <vers num="10.2"/>
        <vers num="10.2.1"/>
        <vers num="10.2.2"/>
        <vers num="10.2.3"/>
        <vers num="10.2.4"/>
        <vers num="10.2.5"/>
        <vers num="10.2.6"/>
        <vers num="10.2.7"/>
        <vers num="10.2.8"/>
        <vers num="10.3"/>
        <vers num="10.3.1"/>
        <vers num="10.3.2"/>
      </prod>
      <prod vendor="apple" name="mac_os_x_server">
        <vers num="10.1.5"/>
        <vers num="10.2"/>
        <vers num="10.2.1"/>
        <vers num="10.2.2"/>
        <vers num="10.2.3"/>
        <vers num="10.2.4"/>
        <vers num="10.2.5"/>
        <vers num="10.2.6"/>
        <vers num="10.2.7"/>
        <vers num="10.2.8"/>
        <vers num="10.3"/>
        <vers num="10.3.1"/>
        <vers num="10.3.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0091" published="2004-02-17" name="CVE-2004-0091" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">** DISPUTED **  NOTE: this issue has been disputed by the vendor.  Cross-site scripting (XSS) vulnerability in register.php for unknown versions of vBulletin allows remote attackers to inject arbitrary HTML or web script via the reg_site (or possibly regsite) parameter.  NOTE: the vendor has disputed this issue, saying "There is no hidden field called 'reg_site', nor any $reg_site variable anywhere in the vBulletin 2 or vBulletin 3 source code or templates, nor has it ever existed.  We can only assume that this vulnerability was found in a site running code modified from that supplied by Jelsoft."</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://securitytracker.com/id?1008780" source="SECTRACK">1008780</ref>
      <ref url="http://marc.theaimsgroup.com/?l=vuln-dev&amp;m=107488880317647&amp;w=2" source="VULN-DEV" adv="1">20040123 RE: vBulletin Security Vulnerability</ref>
      <ref url="http://marc.theaimsgroup.com/?l=vuln-dev&amp;m=107478592401619&amp;w=2" source="VULN-DEV" adv="1">20040120 Re: vBulletin Security Vulnerability</ref>
      <ref url="http://marc.theaimsgroup.com/?l=vuln-dev&amp;m=107462499927040&amp;w=2" source="VULN-DEV" adv="1">20040120 vBulletin Security Vulnerability</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107462349324945&amp;w=2" source="BUGTRAQ" adv="1">20040120 vBulletin Security Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="jelsoft" name="vbulletin">
        <vers num="3.0_beta_2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0092" published="2004-03-03" name="CVE-2004-0092" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Unknown vulnerability in Safari web browser in Mac OS X 10.2.8 and 10.3.2, with unknown impact.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <vuln_types>
      <other/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/9504" source="BID">9504</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2004/Jan/msg00000.html" source="APPLE">APPLE-SA-2004-01-26</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.2.8"/>
        <vers num="10.3.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0093" published="2004-03-15" name="CVE-2004-0093" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">XFree86 4.1.0 allows remote attackers to cause a denial of service and possibly execute arbitrary code via an out-of-bounds array index when using the GLX extension and Direct Rendering Infrastructure (DRI).</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input bound="1"/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.debian.org/security/2004/dsa-443" source="DEBIAN" patch="1" adv="1">DSA-443</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15272" source="XF" adv="1">xfree86-glx-array-dos(15272)</ref>
      <ref url="http://www.securityfocus.com/bid/9701" source="BID" adv="1">9701</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-152.html" source="REDHAT">RHSA-2004:152</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000824" source="CONECTIVA">CLSA-2004:824</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/20040406-01-U" source="SGI">20040406-01-U</ref>
    </refs>
    <vuln_soft>
      <prod vendor="xfree86_project" name="x11r6">
        <vers num="4.1.0"/>
        <vers num="4.1.11"/>
        <vers num="4.1.12"/>
        <vers num="4.2.0"/>
        <vers num="4.2.1" edition=""/>
        <vers num="4.2.1" edition=":errata"/>
        <vers num="4.3.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0094" published="2004-03-15" name="CVE-2004-0094" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Integer signedness errors in XFree86 4.1.0 allow remote attackers to cause a denial of service and possibly execute arbitrary code when using the GLX extension and Direct Rendering Infrastructure (DRI).</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input bound="1"/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.debian.org/security/2004/dsa-443" source="DEBIAN" patch="1" adv="1">DSA-443</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15273" source="XF" adv="1">xfree86-glx-integer-dos(15273)</ref>
      <ref url="http://www.securityfocus.com/bid/9701" source="BID">9701</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-152.html" source="REDHAT">RHSA-2004:152</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000824" source="CONECTIVA">CLSA-2004:824</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/20040406-01-U" source="SGI">20040406-01-U</ref>
    </refs>
    <vuln_soft>
      <prod vendor="xfree86_project" name="x11r6">
        <vers num="4.1.0"/>
        <vers num="4.1.11"/>
        <vers num="4.1.12"/>
        <vers num="4.2.0"/>
        <vers num="4.2.1" edition=""/>
        <vers num="4.2.1" edition=":errata"/>
        <vers num="4.3.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0095" published="2004-02-17" name="CVE-2004-0095" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">McAfee ePolicy Orchestrator agent allows remote attackers to cause a denial of service (memory consumption and crash) and possibly execute arbitrary code via an HTTP POST request with an invalid Content-Length value, possibly triggering a buffer overflow.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <vuln_types>
      <input bound="1"/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/9476" source="BID" adv="1">9476</ref>
      <ref url="http://download.nai.com/products/patches/ePO/v3.1.0/EPO3013.zip" source="CONFIRM">http://download.nai.com/products/patches/ePO/v3.1.0/EPO3013.zip</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/14989" source="XF">epolicy-contentlength-post-dos(14989)</ref>
      <ref url="http://www.osvdb.org/3744" source="OSVDB">3744</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mcafee" name="epolicy_orchestrator">
        <vers num="3.6.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0096" published="2004-03-03" name="CVE-2004-0096" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Unknown vulnerability in mod_python 2.7.9 allows remote attackers to cause a denial of service (httpd crash) via a certain query string, a variant of CAN-2003-0973.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <vuln_types>
      <other/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.modpython.org/pipermail/mod_python/2004-January/014879.html" source="MLIST" patch="1" adv="1">[mod_python] 20040122 [ANNOUNCE] Mod_python 2.7.10</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-063.html" source="REDHAT">RHSA-2004:063</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-058.html" source="REDHAT">RHSA-2004:058</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200401-03.xml" source="GENTOO">GLSA-200401-03</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apache" name="mod_python">
        <vers num="2.7.9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0097" published="2004-03-03" name="CVE-2004-0097" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Multiple vulnerabilities in PWLib before 1.6.0 allow remote attackers to cause a denial of service and possibly execute arbitrary code, as demonstrated by the NISCC/OUSPG PROTOS test suite for the H.225 protocol.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1" admin="1"/>
    </loss_types>
    <vuln_types>
      <other/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/749342" source="CERT-VN" patch="1" adv="1">VU#749342</ref>
      <ref url="http://www.cert.org/advisories/CA-2004-01.html" source="CERT" patch="1" adv="1">CA-2004-01</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-047.html" source="REDHAT" patch="1" adv="1">RHSA-2004:047</ref>
      <ref url="http://www.debian.org/security/2004/dsa-448" source="DEBIAN" patch="1" adv="1">DSA-448</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15202" source="XF" adv="1">pwlib-message-dos(15202)</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10056" source="OVAL">oval:org.mitre.oval:def:10056</ref>
      <ref url="http://www.securityfocus.com/bid/9406" source="BID">9406</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:826" source="OVAL" sig="1">oval:org.mitre.oval:def:826</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:803" source="OVAL" sig="1">oval:org.mitre.oval:def:803</ref>
    </refs>
    <vuln_soft>
      <prod vendor="openh323_project" name="pwlib">
        <vers prev="1" num="1.6.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0099" published="2004-03-03" name="CVE-2004-0099" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">mksnap_ffs in FreeBSD 5.1 and 5.2 only sets the snapshot flag when creating a snapshot for a file system, which causes default values for other flags to be used, possibly disabling security-critical settings and allowing a local user to bypass intended access restrictions.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <design/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/9533" source="BID" patch="1" adv="1">9533</ref>
      <ref url="ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-04:01.mksnap_ffs.asc" source="FREEBSD" patch="1" adv="1">FreeBSD-SA-04:01</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15005" source="XF">freebsd-mksnapffs-bypass-security(15005)</ref>
      <ref url="http://www.osvdb.org/3790" source="OSVDB">3790</ref>
    </refs>
    <vuln_soft>
      <prod vendor="freebsd" name="freebsd">
        <vers num="5.1" edition="release"/>
        <vers num="5.2.1" edition="release"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0103" published="2004-03-03" name="CVE-2004-0103" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">crawl before 4.0.0 beta23 does not properly "apply a size check" when copying a certain environment variable, which may allow local users to gain privileges, possibly as a result of a buffer overflow.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input bound="1"/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://www.debian.org/security/2004/dsa-432" source="DEBIAN" patch="1" adv="1">DSA-432</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15032" source="XF">crawl-long-environment-bo(15032)</ref>
      <ref url="http://www.securityfocus.com/bid/9566" source="BID">9566</ref>
      <ref url="http://secunia.com/advisories/10788/" source="SECUNIA">10788</ref>
    </refs>
    <vuln_soft>
      <prod vendor="linley_henzell" name="crawl">
        <vers prev="1" num="4.0.0_b23"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0104" published="2004-03-03" name="CVE-2004-0104" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple format string vulnerabilities in Metamail 2.7 and earlier allow remote attackers to execute arbitrary code.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/518518" source="CERT-VN">VU#518518</ref>
      <ref url="http://www.securityfocus.com/bid/9692" source="BID" patch="1" adv="1">9692</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-073.html" source="REDHAT" patch="1" adv="1">RHSA-2004:073</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15259" source="XF" adv="1">metamail-printheader-format-string(15259)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15245" source="XF">metamail-contenttype-format-string(15245)</ref>
      <ref url="http://www.debian.org/security/2004/dsa-449" source="DEBIAN">DSA-449</ref>
      <ref url="http://secunia.com/advisories/10908" source="SECUNIA">10908</ref>
      <ref url="http://archives.neohapsis.com/archives/vulnwatch/2004-q1/0041.html" source="VULNWATCH">20040218 metamail format string bugs and buffer overflows</ref>
      <ref url="http://www.slackware.com/security/viewer.php?l=slackware-security&amp;y=2004&amp;m=slackware-security.404734" source="SLACKWARE">SSA:2004-049</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2004:014" source="MANDRAKE">MDKSA-2004:014</ref>
      <ref url="http://www.ciac.org/ciac/bulletins/o-083.shtml" source="CIAC">O-083</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107713476911429&amp;w=2" source="BUGTRAQ">20040218 metamail format string bugs and buffer overflows</ref>
    </refs>
    <vuln_soft>
      <prod vendor="metamail_corporation" name="metamail">
        <vers prev="1" num="2.7"/>
      </prod>
      <prod vendor="sgi" name="propack">
        <vers num="2.3"/>
        <vers num="2.4"/>
      </prod>
      <prod vendor="redhat" name="enterprise_linux">
        <vers num="2.1" edition=""/>
        <vers num="2.1" edition=":workstation"/>
        <vers num="2.1" edition=":advanced_server"/>
        <vers num="2.1" edition=":enterprise_server"/>
      </prod>
      <prod vendor="redhat" name="linux_advanced_workstation">
        <vers num="2.1" edition=""/>
        <vers num="2.1" edition=":itanium_processor"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0105" published="2004-03-03" name="CVE-2004-0105" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple buffer overflows in Metamail 2.7 and earlier allow remote attackers to execute arbitrary code.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input buffer="1"/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/513062" source="CERT-VN">VU#513062</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-073.html" source="REDHAT" patch="1" adv="1">RHSA-2004:073</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15258" source="XF" adv="1">metamail-splitmail-subject-bo(15258)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15247" source="XF">metamail-printheader-nonascii-bo(15247)</ref>
      <ref url="http://www.debian.org/security/2004/dsa-449" source="DEBIAN">DSA-449</ref>
      <ref url="http://secunia.com/advisories/10908" source="SECUNIA">10908</ref>
      <ref url="http://archives.neohapsis.com/archives/vulnwatch/2004-q1/0041.html" source="VULNWATCH">20040218 metamail format string bugs and buffer overflows</ref>
      <ref url="http://www.slackware.com/security/viewer.php?l=slackware-security&amp;y=2004&amp;m=slackware-security.404734" source="SLACKWARE">SSA:2004-049</ref>
      <ref url="http://www.securityfocus.com/bid/9692" source="BID">9692</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2004:014" source="MANDRAKE">MDKSA-2004:014</ref>
      <ref url="http://www.ciac.org/ciac/bulletins/o-083.shtml" source="CIAC">O-083</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107713476911429&amp;w=2" source="BUGTRAQ">20040218 metamail format string bugs and buffer overflows</ref>
    </refs>
    <vuln_soft>
      <prod vendor="metamail_corporation" name="metamail">
        <vers prev="1" num="2.7"/>
      </prod>
      <prod vendor="sgi" name="propack">
        <vers num="2.3"/>
        <vers num="2.4"/>
      </prod>
      <prod vendor="redhat" name="enterprise_linux">
        <vers num="2.1" edition=""/>
        <vers num="2.1" edition=":workstation"/>
        <vers num="2.1" edition=":advanced_server"/>
        <vers num="2.1" edition=":enterprise_server"/>
      </prod>
      <prod vendor="redhat" name="linux_advanced_workstation">
        <vers num="2.1" edition=""/>
        <vers num="2.1" edition=":itanium_processor"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0106" published="2004-03-03" name="CVE-2004-0106" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Multiple unknown vulnerabilities in XFree86 4.1.0 to 4.3.0, related to improper handling of font files, a different set of vulnerabilities than CVE-2004-0083 and CVE-2004-0084.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <vuln_types>
      <other/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://www.slackware.com/security/viewer.php?l=slackware-security&amp;y=2004&amp;m=slackware-security.405053" source="SLACKWARE" patch="1" adv="1">SSA:2004-043</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-061.html" source="REDHAT" patch="1" adv="1">RHSA-2004:061</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-060.html" source="REDHAT" patch="1" adv="1">RHSA-2004:060</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15206" source="XF" adv="1">xfree86-multiple-font-improper-handling(15206)</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-059.html" source="REDHAT">RHSA-2004:059</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2004_06_xf86.html" source="SUSE">SuSE-SA:2004:006</ref>
      <ref url="http://www.debian.org/security/2004/dsa-443" source="DEBIAN">DSA-443</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11111" source="OVAL">oval:org.mitre.oval:def:11111</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2004:012" source="MANDRAKE">MDKSA-2004:012</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110979666528890&amp;w=2" source="FEDORA">FLSA:2314</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000821" source="CONECTIVA">CLA-2004:821</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:832" source="OVAL" sig="1">oval:org.mitre.oval:def:832</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:809" source="OVAL" sig="1">oval:org.mitre.oval:def:809</ref>
    </refs>
    <vuln_soft>
      <prod vendor="xfree86_project" name="x11r6">
        <vers num="4.1.0"/>
        <vers num="4.1.11"/>
        <vers num="4.1.12"/>
        <vers num="4.2.0"/>
        <vers num="4.2.1" edition=""/>
        <vers num="4.2.1" edition=":errata"/>
        <vers num="4.3.0"/>
      </prod>
      <prod vendor="openbsd" name="openbsd">
        <vers num="3.3"/>
        <vers num="3.4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0107" published="2004-04-15" name="CVE-2004-0107" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">The (1) post and (2) trigger scripts in sysstat 4.0.7 and earlier allow local users to overwrite arbitrary files via symlink attacks on temporary files, a different vulnerability than CVE-2004-0108.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <design/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/9838" source="BID" patch="1" adv="1">9838</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-053.html" source="REDHAT" patch="1" adv="1">RHSA-2004:053</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/20040302-01-U.asc" source="SGI" patch="1">20040302-01-U</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15428" source="XF">sysstat-post-trigger-symlink(15428)</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-093.html" source="REDHAT">RHSA-2004:093</ref>
      <ref url="http://www.osvdb.org/6884" source="OSVDB">6884</ref>
      <ref url="http://www.ciac.org/ciac/bulletins/o-097.shtml" source="CIAC">O-097</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10737" source="OVAL">oval:org.mitre.oval:def:10737</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:862" source="OVAL" sig="1">oval:org.mitre.oval:def:862</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:849" source="OVAL" sig="1">oval:org.mitre.oval:def:849</ref>
    </refs>
    <vuln_soft>
      <prod vendor="redhat" name="sysstat">
        <vers num="4.0.7-3" edition=""/>
        <vers num="4.0.7-3" edition=":i386"/>
      </prod>
      <prod vendor="sgi" name="propack">
        <vers num="2.3"/>
        <vers num="2.4"/>
      </prod>
      <prod vendor="sysstat" name="sysstat">
        <vers num="4.0.7"/>
        <vers num="4.1.1"/>
        <vers num="4.1.2"/>
        <vers num="4.1.3"/>
        <vers num="4.1.4"/>
        <vers num="4.1.5"/>
        <vers num="4.1.6"/>
        <vers num="4.1.7"/>
        <vers num="5.0.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0108" published="2004-04-15" name="CVE-2004-0108" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">The isag utility, which processes sysstat data, allows local users to overwrite arbitrary files via a symlink attack on temporary files, a different vulnerability than CAN-2004-0107.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <design/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/9844" source="BID" patch="1" adv="1">9844</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-053.html" source="REDHAT" patch="1" adv="1">RHSA-2004:053</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/20040302-01-U.asc" source="SGI" patch="1">20040302-01-U</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15437" source="XF">sysstat-isag-symlink(15437)</ref>
      <ref url="http://www.debian.org/security/2004/dsa-460" source="DEBIAN">DSA-460</ref>
    </refs>
    <vuln_soft>
      <prod vendor="redhat" name="sysstat">
        <vers num="4.0.7-3" edition=""/>
        <vers num="4.0.7-3" edition=":i386"/>
      </prod>
      <prod vendor="sgi" name="propack">
        <vers num="2.3"/>
        <vers num="2.4"/>
      </prod>
      <prod vendor="sysstat" name="sysstat">
        <vers num="4.0.7"/>
        <vers num="4.1.1"/>
        <vers num="4.1.2"/>
        <vers num="4.1.3"/>
        <vers num="4.1.4"/>
        <vers num="4.1.5"/>
        <vers num="4.1.6"/>
        <vers num="4.1.7"/>
        <vers num="5.0.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0109" published="2004-06-01" name="CVE-2004-0109" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Buffer overflow in the ISO9660 file system component for Linux kernel 2.4.x, 2.5.x and 2.6.x, allows local users with physical access to overflow kernel memory and execute arbitrary code via a malformed CD containing a long symbolic link entry.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input buffer="1"/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://www.linuxsecurity.com/advisories/engarde_advisory-4285.html" source="ENGARDE" patch="1" adv="1">ESA-20040428-004</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2004-166.html" source="REDHAT" patch="1" adv="1">RHSA-2004:166</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108213675028441&amp;w=2" source="TRUSTIX" patch="1" adv="1">2004-0020</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/20040405-01-U.asc" source="SGI" patch="1" adv="1">20040405-01-U</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15866" source="XF">linux-iso9660-bo(15866)</ref>
      <ref url="http://www.turbolinux.com/security/2004/TLSA-2004-14.txt" source="TURBO">TLSA-2004-14</ref>
      <ref url="http://www.securityfocus.com/bid/10141" source="BID">10141</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-183.html" source="REDHAT">RHSA-2004:183</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-106.html" source="REDHAT">RHSA-2004:106</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-105.html" source="REDHAT">RHSA-2004:105</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2004_09_kernel.html" source="SUSE">SuSE-SA:2004:009</ref>
      <ref url="http://www.idefense.com/application/poi/display?id=101&amp;type=vulnerabilities" source="MISC" adv="1">http://www.idefense.com/application/poi/display?id=101&amp;type=vulnerabilities</ref>
      <ref url="http://www.debian.org/security/2004/dsa-495" source="DEBIAN">DSA-495</ref>
      <ref url="http://www.debian.org/security/2004/dsa-491" source="DEBIAN">DSA-491</ref>
      <ref url="http://www.debian.org/security/2004/dsa-489" source="DEBIAN">DSA-489</ref>
      <ref url="http://www.debian.org/security/2004/dsa-482" source="DEBIAN">DSA-482</ref>
      <ref url="http://www.debian.org/security/2004/dsa-481" source="DEBIAN">DSA-481</ref>
      <ref url="http://www.debian.org/security/2004/dsa-480" source="DEBIAN">DSA-480</ref>
      <ref url="http://www.debian.org/security/2004/dsa-479" source="DEBIAN">DSA-479</ref>
      <ref url="http://www.ciac.org/ciac/bulletins/o-127.shtml" source="CIAC">O-127</ref>
      <ref url="http://www.ciac.org/ciac/bulletins/o-121.shtml" source="CIAC">O-121</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200407-02.xml" source="GENTOO">GLSA-200407-02</ref>
      <ref url="http://secunia.com/advisories/12003" source="SECUNIA">12003</ref>
      <ref url="http://secunia.com/advisories/11986" source="SECUNIA">11986</ref>
      <ref url="http://secunia.com/advisories/11891" source="SECUNIA">11891</ref>
      <ref url="http://secunia.com/advisories/11861" source="SECUNIA">11861</ref>
      <ref url="http://secunia.com/advisories/11626" source="SECUNIA">11626</ref>
      <ref url="http://secunia.com/advisories/11518" source="SECUNIA">11518</ref>
      <ref url="http://secunia.com/advisories/11494" source="SECUNIA">11494</ref>
      <ref url="http://secunia.com/advisories/11486" source="SECUNIA">11486</ref>
      <ref url="http://secunia.com/advisories/11470" source="SECUNIA">11470</ref>
      <ref url="http://secunia.com/advisories/11469" source="SECUNIA">11469</ref>
      <ref url="http://secunia.com/advisories/11464" source="SECUNIA">11464</ref>
      <ref url="http://secunia.com/advisories/11373" source="SECUNIA">11373</ref>
      <ref url="http://secunia.com/advisories/11362" source="SECUNIA">11362</ref>
      <ref url="http://secunia.com/advisories/11361" source="SECUNIA">11361</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10733" source="OVAL">oval:org.mitre.oval:def:10733</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000846" source="CONECTIVA">CLA-2004:846</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/20040504-01-U.asc" source="SGI">20040504-01-U</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2004:029" source="MANDRAKE">MDKSA-2004:029</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:940" source="OVAL" sig="1">oval:org.mitre.oval:def:940</ref>
    </refs>
    <vuln_soft>
      <prod vendor="linux" name="linux_kernel">
        <vers num="2.4.0"/>
        <vers num="2.5.0"/>
        <vers num="2.6.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0110" published="2004-03-15" name="CVE-2004-0110" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in the (1) nanohttp or (2) nanoftp modules in XMLSoft Libxml 2 (Libxml2) 2.6.0 through 2.6.5 allow remote attackers to execute arbitrary code via a long URL.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input buffer="1"/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/493966" source="CERT-VN">VU#493966</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15301" source="XF" patch="1" adv="1">libxml2-nanohttp-bo(15301)</ref>
      <ref url="http://www.securityfocus.com/bid/9718" source="BID" patch="1" adv="1">9718</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2004-090.html" source="REDHAT" patch="1" adv="1">RHSA-2004:090</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107851606605420&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20040305 [OpenPKG-SA-2004.003] OpenPKG Security Advisory (libxml)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15302" source="XF">libxml2-nanoftp-bo(15302)</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-091.html" source="REDHAT">RHSA-2004:091</ref>
      <ref url="http://www.debian.org/security/2004/dsa-455" source="DEBIAN">DSA-455</ref>
      <ref url="http://www.ciac.org/ciac/bulletins/o-086.shtml" source="CIAC">O-086</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200403-01.xml" source="GENTOO">GLSA-200403-01</ref>
      <ref url="http://secunia.com/advisories/10958/" source="SECUNIA">10958</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11626" source="OVAL">oval:org.mitre.oval:def:11626</ref>
      <ref url="http://www.xmlsoft.org/news.html" source="CONFIRM">http://www.xmlsoft.org/news.html</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-650.html" source="REDHAT">RHSA-2004:650</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2005_01_sr.html" source="SUSE">SUSE-SR:2005:001</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107860178228804&amp;w=2" source="BUGTRAQ">20040306 TSLSA-2004-0010 - libxml2</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:875" source="OVAL" sig="1">oval:org.mitre.oval:def:875</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:833" source="OVAL" sig="1">oval:org.mitre.oval:def:833</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sgi" name="propack">
        <vers num="2.3"/>
        <vers num="2.4"/>
      </prod>
      <prod vendor="xmlsoft" name="libxml">
        <vers num="1.8.17"/>
      </prod>
      <prod vendor="xmlsoft" name="libxml2">
        <vers num="2.4.19"/>
        <vers num="2.4.23"/>
        <vers num="2.5.10"/>
        <vers num="2.5.11"/>
        <vers num="2.5.4"/>
        <vers num="2.6.0"/>
        <vers num="2.6.1"/>
        <vers num="2.6.2"/>
        <vers num="2.6.3"/>
        <vers num="2.6.4"/>
        <vers num="2.6.5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0111" published="2004-04-15" name="CVE-2004-0111" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">gdk-pixbuf before 0.20 allows attackers to cause a denial of service (crash) via a malformed bitmap (BMP) file.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <vuln_types>
      <other/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/9842" source="BID" patch="1" adv="1">9842</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-103.html" source="REDHAT" patch="1" adv="1">RHSA-2004:103</ref>
      <ref url="https://bugzilla.fedora.us/show_bug.cgi?id=2005" source="FEDORA">FLSA:2005</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15426" source="XF">gdk-pixbuf-bitmap-dos(15426)</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-102.html" source="REDHAT">RHSA-2004:102</ref>
      <ref url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2004:020" source="MANDRAKE">MDKSA-2004:020</ref>
      <ref url="http://www.debian.org/security/2004/dsa-464" source="DEBIAN">DSA-464</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:846" source="OVAL" sig="1">oval:org.mitre.oval:def:846</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:845" source="OVAL" sig="1">oval:org.mitre.oval:def:845</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gnome" name="gdkpixbuf">
        <vers num="0.18"/>
        <vers num="0.20"/>
      </prod>
      <prod vendor="redhat" name="gdk_pixbuf">
        <vers num="0.18.0-7" edition=""/>
        <vers num="0.18.0-7" edition=":i386_dev"/>
        <vers num="0.18.0-7" edition=":i386"/>
        <vers num="0.18.0-7" edition=":i386_gnome"/>
      </prod>
      <prod vendor="sgi" name="propack">
        <vers num="2.3"/>
        <vers num="2.4"/>
      </prod>
      <prod vendor="redhat" name="enterprise_linux">
        <vers num="2.1" edition=""/>
        <vers num="2.1" edition=":workstation"/>
        <vers num="2.1" edition=":advanced_server"/>
        <vers num="2.1" edition=":enterprise_server"/>
        <vers num="3.0" edition=""/>
        <vers num="3.0" edition=":workstation"/>
        <vers num="3.0" edition=":advanced_servers"/>
        <vers num="3.0" edition=":enterprise_server"/>
      </prod>
      <prod vendor="redhat" name="linux_advanced_workstation">
        <vers num="2.1" edition=""/>
        <vers num="2.1" edition=":itanium_processor"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0112" published="2004-11-23" name="CVE-2004-0112" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The SSL/TLS handshaking code in OpenSSL 0.9.7a, 0.9.7b, and 0.9.7c, when using Kerberos ciphersuites, does not properly check the length of Kerberos tickets during a handshake, which allows remote attackers to cause a denial of service (crash) via a crafted SSL/TLS handshake that causes an out-of-bounds read.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <vuln_types>
      <input bound="1"/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA04-078A.html" source="CERT" adv="1">TA04-078A</ref>
      <ref url="http://www.kb.cert.org/vuls/id/484726" source="CERT-VN">VU#484726</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15508" source="XF" adv="1">openssl-kerberos-ciphersuites-dos(15508)</ref>
      <ref url="http://www.uniras.gov.uk/vuls/2004/224012/index.htm" source="MISC">http://www.uniras.gov.uk/vuls/2004/224012/index.htm</ref>
      <ref url="http://www.trustix.org/errata/2004/0012" source="TRUSTIX">2004-0012</ref>
      <ref url="http://www.slackware.org/security/viewer.php?l=slackware-security&amp;y=2004&amp;m=slackware-security.455961" source="SLACKWARE">SSA:2004-077</ref>
      <ref url="http://www.securityfocus.com/bid/9899" source="BID" adv="1">9899</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-121.html" source="REDHAT">RHSA-2004:121</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-120.html" source="REDHAT">RHSA-2004:120</ref>
      <ref url="http://www.openssl.org/news/secadv_20040317.txt" source="CONFIRM">http://www.openssl.org/news/secadv_20040317.txt</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2004_07_openssl.html" source="SUSE">SuSE-SA:2004:007</ref>
      <ref url="http://www.cisco.com/warp/public/707/cisco-sa-20040317-openssl.shtml" source="CISCO">20040317 Cisco OpenSSL Implementation Vulnerability</ref>
      <ref url="http://www.ciac.org/ciac/bulletins/o-101.shtml" source="CIAC">O-101</ref>
      <ref url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doc=fsalert/57524" source="SUNALERT">57524</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200403-03.xml" source="GENTOO">GLSA-200403-03</ref>
      <ref url="http://secunia.com/advisories/11139" source="SECUNIA">11139</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9580" source="OVAL">oval:org.mitre.oval:def:9580</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108403806509920&amp;w=2" source="HP">SSRT4717</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107953412903636&amp;w=2" source="BUGTRAQ">20040317 New OpenSSL releases fix denial of service attacks [17 March 2004]</ref>
      <ref url="http://lists.apple.com/mhonarc/security-announce/msg00045.html" source="CONFIRM">http://lists.apple.com/mhonarc/security-announce/msg00045.html</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2005/Aug/msg00000.html" source="APPLE">APPLE-SA-2005-08-15</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2005//Aug/msg00001.html" source="APPLE">APPLE-SA-2005-08-17</ref>
      <ref url="http://docs.info.apple.com/article.html?artnum=61798" source="CONFIRM">http://docs.info.apple.com/article.html?artnum=61798</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000834" source="CONECTIVA">CLA-2004:834</ref>
      <ref url="ftp://ftp.sco.com/pub/updates/OpenServer/SCOSA-2004.10/SCOSA-2004.10.txt" source="SCO">SCOSA-2004.10</ref>
      <ref url="ftp://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2004-005.txt.asc" source="NETBSD">NetBSD-SA2004-005</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2004:023" source="MANDRAKE">MDKSA-2004:023</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:928" source="OVAL" sig="1">oval:org.mitre.oval:def:928</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1049" source="OVAL" sig="1">oval:org.mitre.oval:def:1049</ref>
    </refs>
    <vuln_soft>
      <prod vendor="4d" name="webstar">
        <vers num="4.0"/>
        <vers num="5.2"/>
        <vers num="5.2.1"/>
        <vers num="5.2.2"/>
        <vers num="5.2.3"/>
        <vers num="5.2.4"/>
        <vers num="5.3"/>
        <vers num="5.3.1"/>
      </prod>
      <prod vendor="avaya" name="intuity_audix">
        <vers num="" edition=":lx"/>
        <vers num="5.1.46"/>
        <vers num="s3210"/>
        <vers num="s3400"/>
      </prod>
      <prod vendor="avaya" name="vsu">
        <vers num="10000_r2.0.1"/>
        <vers num="100_r2.0.1"/>
        <vers num="2000_r2.0.1"/>
        <vers num="5"/>
        <vers num="500"/>
        <vers num="5000_r2.0.1"/>
        <vers num="5x"/>
        <vers num="7500_r2.0.1"/>
      </prod>
      <prod vendor="checkpoint" name="firewall-1">
        <vers num="" edition=":vsx-ng-ai"/>
        <vers num="2.0" edition=""/>
        <vers num="2.0" edition=":gx"/>
        <vers num="next_generation_fp0"/>
        <vers num="next_generation_fp1"/>
        <vers num="next_generation_fp2"/>
      </prod>
      <prod vendor="checkpoint" name="provider-1">
        <vers num="4.1" edition="sp1"/>
        <vers num="4.1" edition="sp2"/>
        <vers num="4.1" edition="sp3"/>
        <vers num="4.1" edition="sp4"/>
      </prod>
      <prod vendor="checkpoint" name="vpn-1">
        <vers num="next_generation_fp0"/>
        <vers num="next_generation_fp1"/>
        <vers num="next_generation_fp2"/>
        <vers num="vsx_ng_with_application_intelligence"/>
      </prod>
      <prod vendor="cisco" name="access_registrar">
        <vers num=""/>
      </prod>
      <prod vendor="cisco" name="application_and_content_networking_software">
        <vers num=""/>
      </prod>
      <prod vendor="cisco" name="ciscoworks_common_management_foundation">
        <vers num="2.1"/>
      </prod>
      <prod vendor="cisco" name="ciscoworks_common_services">
        <vers num="2.2"/>
      </prod>
      <prod vendor="cisco" name="css11000_content_services_switch">
        <vers num=""/>
      </prod>
      <prod vendor="cisco" name="css_secure_content_accelerator">
        <vers num="1.0"/>
        <vers num="2.0"/>
      </prod>
      <prod vendor="cisco" name="okena_stormwatch">
        <vers num="3.2"/>
      </prod>
      <prod vendor="cisco" name="pix_firewall">
        <vers num="6.2.2_.111"/>
      </prod>
      <prod vendor="cisco" name="threat_response">
        <vers num=""/>
      </prod>
      <prod vendor="cisco" name="webns">
        <vers num="6.10"/>
        <vers num="6.10_b4"/>
        <vers num="7.10"/>
        <vers num="7.10_.0.06s"/>
        <vers num="7.1_0.1.02"/>
        <vers num="7.1_0.2.06"/>
        <vers num="7.2_0.0.03"/>
      </prod>
      <prod vendor="hp" name="wbem">
        <vers num="a.01.05.08"/>
        <vers num="a.02.00.00"/>
        <vers num="a.02.00.01"/>
      </prod>
      <prod vendor="lite" name="speed_technologies_litespeed_web_server">
        <vers num="1.0.1"/>
        <vers num="1.0.2"/>
        <vers num="1.0.3"/>
        <vers num="1.1"/>
        <vers num="1.1.1"/>
        <vers num="1.2.1"/>
        <vers num="1.2.2"/>
        <vers num="1.2_rc1"/>
        <vers num="1.2_rc2"/>
        <vers num="1.3"/>
        <vers num="1.3.1"/>
        <vers num="1.3_rc1"/>
        <vers num="1.3_rc2"/>
        <vers num="1.3_rc3"/>
      </prod>
      <prod vendor="neoteris" name="instant_virtual_extranet">
        <vers num="3.0"/>
        <vers num="3.1"/>
        <vers num="3.2"/>
        <vers num="3.3"/>
        <vers num="3.3.1"/>
      </prod>
      <prod vendor="novell" name="edirectory">
        <vers num="8.0"/>
        <vers num="8.5"/>
        <vers num="8.5.12a"/>
        <vers num="8.5.27"/>
        <vers num="8.6.2"/>
        <vers num="8.7"/>
        <vers num="8.7.1" edition="sp1"/>
      </prod>
      <prod vendor="novell" name="imanager">
        <vers num="1.5"/>
        <vers num="2.0"/>
      </prod>
      <prod vendor="openssl" name="openssl">
        <vers num="0.9.6c"/>
        <vers num="0.9.6d"/>
        <vers num="0.9.6e"/>
        <vers num="0.9.6f"/>
        <vers num="0.9.6g"/>
        <vers num="0.9.6h"/>
        <vers num="0.9.6i"/>
        <vers num="0.9.6j"/>
        <vers num="0.9.6k"/>
        <vers num="0.9.7" edition="beta1"/>
        <vers num="0.9.7" edition="beta2"/>
        <vers num="0.9.7" edition="beta3"/>
        <vers num="0.9.7a"/>
        <vers num="0.9.7b"/>
        <vers num="0.9.7c"/>
      </prod>
      <prod vendor="redhat" name="openssl">
        <vers num="0.9.6-15" edition=""/>
        <vers num="0.9.6-15" edition=":i386"/>
        <vers num="0.9.6b-3" edition=""/>
        <vers num="0.9.6b-3" edition=":i386"/>
        <vers num="0.9.7a-2" edition=""/>
        <vers num="0.9.7a-2" edition=":i386_dev"/>
        <vers num="0.9.7a-2" edition=":i386"/>
        <vers num="0.9.7a-2" edition=":i386_perl"/>
      </prod>
      <prod vendor="rsa" name="bsafe_ssl-j_sdk">
        <vers num="3.0"/>
        <vers num="3.0.1"/>
        <vers num="3.1"/>
      </prod>
      <prod vendor="sgi" name="propack">
        <vers num="2.3"/>
        <vers num="2.4"/>
        <vers num="3.0"/>
      </prod>
      <prod vendor="stonesoft" name="servercluster">
        <vers num="2.5"/>
        <vers num="2.5.2"/>
      </prod>
      <prod vendor="stonesoft" name="stonebeat_fullcluster">
        <vers num="1_2.0"/>
        <vers num="1_3.0"/>
        <vers num="2.0"/>
        <vers num="2.5"/>
        <vers num="3.0"/>
      </prod>
      <prod vendor="stonesoft" name="stonebeat_securitycluster">
        <vers num="2.0"/>
        <vers num="2.5"/>
      </prod>
      <prod vendor="stonesoft" name="stonebeat_webcluster">
        <vers num="2.0"/>
        <vers num="2.5"/>
      </prod>
      <prod vendor="stonesoft" name="stonegate">
        <vers num="1.5.17"/>
        <vers num="1.5.18"/>
        <vers num="1.6.2"/>
        <vers num="1.6.3"/>
        <vers num="1.7"/>
        <vers num="1.7.1"/>
        <vers num="1.7.2"/>
        <vers num="2.0.1"/>
        <vers num="2.0.4"/>
        <vers num="2.0.5"/>
        <vers num="2.0.6"/>
        <vers num="2.0.7"/>
        <vers num="2.0.8"/>
        <vers num="2.0.9"/>
        <vers num="2.1"/>
        <vers num="2.2"/>
        <vers num="2.2.1"/>
        <vers num="2.2.4"/>
      </prod>
      <prod vendor="tarantella" name="tarantella_enterprise">
        <vers num="3.20"/>
        <vers num="3.30"/>
        <vers num="3.40"/>
      </prod>
      <prod vendor="vmware" name="gsx_server">
        <vers num="2.0"/>
        <vers num="2.0.1_build_2129"/>
        <vers num="2.5.1"/>
        <vers num="2.5.1_build_5336"/>
        <vers num="3.0_build_7592"/>
      </prod>
      <prod vendor="avaya" name="converged_communications_server">
        <vers num="2.0"/>
      </prod>
      <prod vendor="avaya" name="s8300">
        <vers num="r2.0.0"/>
        <vers num="r2.0.1"/>
      </prod>
      <prod vendor="avaya" name="s8500">
        <vers num="r2.0.0"/>
        <vers num="r2.0.1"/>
      </prod>
      <prod vendor="avaya" name="s8700">
        <vers num="r2.0.0"/>
        <vers num="r2.0.1"/>
      </prod>
      <prod vendor="avaya" name="sg200">
        <vers num="4.31.29"/>
        <vers num="4.4"/>
      </prod>
      <prod vendor="avaya" name="sg203">
        <vers num="4.31.29"/>
        <vers num="4.4"/>
      </prod>
      <prod vendor="avaya" name="sg208">
        <vers num="4.4"/>
      </prod>
      <prod vendor="avaya" name="sg5">
        <vers num="4.2"/>
        <vers num="4.3"/>
        <vers num="4.4"/>
      </prod>
      <prod vendor="bluecoat" name="proxysg">
        <vers num=""/>
      </prod>
      <prod vendor="cisco" name="call_manager">
        <vers num=""/>
      </prod>
      <prod vendor="cisco" name="content_services_switch_11500">
        <vers num=""/>
      </prod>
      <prod vendor="cisco" name="firewall_services_module">
        <vers num="1.1.2"/>
        <vers num="1.1.3"/>
        <vers num="1.1_(3.005)"/>
        <vers num="2.1_(0.208)"/>
      </prod>
      <prod vendor="cisco" name="gss_4480_global_site_selector">
        <vers num=""/>
      </prod>
      <prod vendor="cisco" name="gss_4490_global_site_selector">
        <vers num=""/>
      </prod>
      <prod vendor="cisco" name="mds_9000">
        <vers num=""/>
      </prod>
      <prod vendor="cisco" name="secure_content_accelerator">
        <vers num="10000"/>
      </prod>
      <prod vendor="hp" name="aaa_server">
        <vers num=""/>
      </prod>
      <prod vendor="hp" name="apache-based_web_server">
        <vers num="2.0.43.00"/>
        <vers num="2.0.43.04"/>
      </prod>
      <prod vendor="securecomputing" name="sidewinder">
        <vers num="5.2"/>
        <vers num="5.2.0.01"/>
        <vers num="5.2.0.02"/>
        <vers num="5.2.0.03"/>
        <vers num="5.2.0.04"/>
        <vers num="5.2.1"/>
        <vers num="5.2.1.02"/>
      </prod>
      <prod vendor="sun" name="crypto_accelerator_4000">
        <vers num="1.0"/>
      </prod>
      <prod vendor="symantec" name="clientless_vpn_gateway_4400">
        <vers num="5.0"/>
      </prod>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.3.3"/>
      </prod>
      <prod vendor="apple" name="mac_os_x_server">
        <vers num="10.3.3"/>
      </prod>
      <prod vendor="bluecoat" name="cacheos_ca_sa">
        <vers num="4.1.10"/>
        <vers num="4.1.12"/>
      </prod>
      <prod vendor="cisco" name="ios">
        <vers num="12.1(11)e"/>
        <vers num="12.1(11b)e"/>
        <vers num="12.1(11b)e12"/>
        <vers num="12.1(11b)e14"/>
        <vers num="12.1(13)e9"/>
        <vers num="12.1(19)e1"/>
        <vers num="12.2(14)sy"/>
        <vers num="12.2(14)sy1"/>
        <vers num="12.2sy"/>
        <vers num="12.2za"/>
      </prod>
      <prod vendor="cisco" name="pix_firewall">
        <vers num="6.0"/>
        <vers num="6.0(1)"/>
        <vers num="6.0(2)"/>
        <vers num="6.0(3)"/>
        <vers num="6.0(4)"/>
        <vers num="6.0(4.101)"/>
        <vers num="6.1"/>
        <vers num="6.1(1)"/>
        <vers num="6.1(2)"/>
        <vers num="6.1(3)"/>
        <vers num="6.1(4)"/>
        <vers num="6.1(5)"/>
        <vers num="6.2"/>
        <vers num="6.2(1)"/>
        <vers num="6.2(2)"/>
        <vers num="6.2(3)"/>
        <vers num="6.2(3.100)"/>
        <vers num="6.3"/>
        <vers num="6.3(1)"/>
        <vers num="6.3(2)"/>
        <vers num="6.3(3.102)"/>
        <vers num="6.3(3.109)"/>
      </prod>
      <prod vendor="freebsd" name="freebsd">
        <vers num="4.8" edition="releng"/>
        <vers num="4.9"/>
        <vers num="5.1" edition="release"/>
        <vers num="5.1" edition="releng"/>
        <vers num="5.2"/>
        <vers num="5.2.1" edition="release"/>
      </prod>
      <prod vendor="hp" name="hp-ux">
        <vers num="11.00"/>
        <vers num="11.11"/>
        <vers num="11.23"/>
        <vers num="8.05"/>
      </prod>
      <prod vendor="openbsd" name="openbsd">
        <vers num="3.3"/>
        <vers num="3.4"/>
      </prod>
      <prod vendor="redhat" name="enterprise_linux">
        <vers num="3.0" edition=""/>
        <vers num="3.0" edition=":workstation_server"/>
        <vers num="3.0" edition=":advanced_server"/>
        <vers num="3.0" edition=":enterprise_server"/>
      </prod>
      <prod vendor="redhat" name="enterprise_linux_desktop">
        <vers num="3.0"/>
      </prod>
      <prod vendor="redhat" name="linux">
        <vers num="7.2"/>
        <vers num="7.3"/>
        <vers num="8.0"/>
      </prod>
      <prod vendor="sco" name="openserver">
        <vers num="5.0.6"/>
        <vers num="5.0.7"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0113" published="2004-03-29" name="CVE-2004-0113" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Memory leak in ssl_engine_io.c for mod_ssl in Apache 2 before 2.0.49 allows remote attackers to cause a denial of service (memory consumption) via plain HTTP requests to the SSL port of an SSL-enabled server.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <vuln_types>
      <design/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/9826" source="BID" patch="1" adv="1">9826</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15419" source="XF" adv="1">apache-modssl-plain-dos(15419)</ref>
      <ref url="http://www.apacheweek.com/features/security-20" source="CONFIRM" adv="1">http://www.apacheweek.com/features/security-20</ref>
      <ref url="http://marc.theaimsgroup.com/?l=apache-cvs&amp;m=107869699329638" source="MLIST" adv="1">[apache-cvs] 20040307 cvs commit: httpd-2.0/modules/ssl ssl_engine_io.c</ref>
      <ref url="http://www.trustix.org/errata/2004/0017" source="TRUSTIX">2004-0017</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-182.html" source="REDHAT">RHSA-2004:182</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-084.html" source="REDHAT">RHSA-2004:084</ref>
      <ref url="http://www.osvdb.org/4182" source="OSVDB">4182</ref>
      <ref url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2004:043" source="MANDRAKE">MDKSA-2004:043</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200403-04.xml" source="GENTOO">GLSA-200403-04</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108731648532365&amp;w=2" source="HP">SSRT4717</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108369640424244&amp;w=2" source="APPLE">APPLE-SA-2004-05-03</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108034113406858&amp;w=2" source="BUGTRAQ">20040325 LNSA-#2004-0006: bug workaround for Apache 2.0.48</ref>
      <ref url="http://issues.apache.org/bugzilla/show_bug.cgi?id=27106" source="MISC">http://issues.apache.org/bugzilla/show_bug.cgi?id=27106</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000839" source="CONECTIVA">CLSA-2004:839</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:876" source="OVAL" sig="1">oval:org.mitre.oval:def:876</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apache" name="http_server">
        <vers num="2.0.35"/>
        <vers num="2.0.36"/>
        <vers num="2.0.37"/>
        <vers num="2.0.38"/>
        <vers num="2.0.39"/>
        <vers num="2.0.40"/>
        <vers num="2.0.41"/>
        <vers num="2.0.42"/>
        <vers num="2.0.43"/>
        <vers num="2.0.44"/>
        <vers num="2.0.45"/>
        <vers num="2.0.46"/>
        <vers num="2.0.47"/>
        <vers num="2.0.48"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0114" published="2004-03-03" name="CVE-2004-0114" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">The shmat system call in the System V Shared Memory interface for FreeBSD 5.2 and earlier, NetBSD 1.3 and earlier, and OpenBSD 2.6 and earlier, does not properly decrement a shared memory segment's reference count when the vm_map_find function fails, which could allow local users to gain read or write access to a portion of kernel memory and gain privileges.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <design/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/15061" source="XF" patch="1" adv="1">bsd-shmat-gain-privileges(15061)</ref>
      <ref url="http://www.securityfocus.com/bid/9586" source="BID" patch="1" adv="1">9586</ref>
      <ref url="ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-04:02.shmat.asc" source="FREEBSD" patch="1" adv="1">FreeBSD-SA-04:02</ref>
      <ref url="http://www.pine.nl/press/pine-cert-20040201.txt" source="MISC">http://www.pine.nl/press/pine-cert-20040201.txt</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107608375207601&amp;w=2" source="BUGTRAQ" adv="1">20040205 [PINE-CERT-20040201] reference count overflow in shmat()</ref>
      <ref url="http://www.osvdb.org/3836" source="OSVDB">3836</ref>
      <ref url="http://www.openbsd.org/errata33.html#sysvshm" source="CONFIRM">http://www.openbsd.org/errata33.html#sysvshm</ref>
      <ref url="ftp://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2004-004.txt.asc" source="NETBSD">NetBSD-SA2004-004</ref>
    </refs>
    <vuln_soft>
      <prod vendor="freebsd" name="freebsd">
        <vers prev="1" num="5.2"/>
      </prod>
      <prod vendor="netbsd" name="netbsd">
        <vers prev="1" num="1.3"/>
      </prod>
      <prod vendor="openbsd" name="openbsd">
        <vers prev="1" num="2.6"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0115" published="2004-03-03" name="CVE-2004-0115" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">VirtualPC_Services in Microsoft Virtual PC for Mac 6.0 through 6.1 allows local attackers to truncate and overwrite arbitrary files, and execute arbitrary code, via a symlink attack on the VPCServices_Log temporary file.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/9632" source="BID" patch="1" adv="1">9632</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms04-005.asp" source="MS" patch="1" adv="1">MS04-005</ref>
      <ref url="http://www.atstake.com/research/advisories/2004/a021004-1.txt" source="ATSTAKE" adv="1">A021004-1</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15113" source="XF">virtual-pc-gain-privileges(15113)</ref>
      <ref url="http://www.osvdb.org/3893" source="OSVDB">3893</ref>
      <ref url="http://www.ciac.org/ciac/bulletins/o-076.shtml" source="CIAC">O-076</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="virtual_pc">
        <vers num="6.0" edition=""/>
        <vers num="6.0" edition=":mac"/>
        <vers num="6.1" edition=""/>
        <vers num="6.1" edition=":mac"/>
        <vers num="6.2" edition=""/>
        <vers num="6.2" edition=":mac"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0116" published="2004-06-01" name="CVE-2004-0116" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">An Activation function in the RPCSS Service involved with DCOM activation for Microsoft Windows 2000, XP, and 2003 allows remote attackers to cause a denial of service (memory consumption) via an activation request with a large length field.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <vuln_types>
      <input bound="1"/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/417052" source="CERT-VN" patch="1" adv="1">VU#417052</ref>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA04-104A.html" source="CERT" adv="1">TA04-104A</ref>
      <ref url="http://www.eeye.com/html/Research/Advisories/AD20040413A.html" source="EEYE" patch="1" adv="1">AD20040413A</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms04-012.asp" source="MS">MS04-012</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15708" source="XF">win-rpcss-rpcmessage-dos(15708)</ref>
      <ref url="http://www.securityfocus.com/bid/10127" source="BID">10127</ref>
      <ref url="http://www.ciac.org/ciac/bulletins/o-115.shtml" source="CIAC">O-115</ref>
      <ref url="http://securitytracker.com/alerts/2004/Apr/1009758.html" source="SECTRACK">1009758</ref>
      <ref url="http://secunia.com/advisories/11065/" source="SECUNIA">11065</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:958" source="OVAL" sig="1">oval:org.mitre.oval:def:958</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:957" source="OVAL" sig="1">oval:org.mitre.oval:def:957</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:955" source="OVAL" sig="1">oval:org.mitre.oval:def:955</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_2000">
        <vers num=""/>
      </prod>
      <prod vendor="microsoft" name="windows_2003_server">
        <vers num="r2"/>
      </prod>
      <prod vendor="microsoft" name="windows_xp">
        <vers num="" edition="gold"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0117" published="2004-06-01" name="CVE-2004-0117" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Unknown vulnerability in the H.323 protocol implementation in Windows 98, Windows 2000, Windows XP, and Windows Server 2003 allows remote attackers to execute arbitrary code.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input buffer="1"/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/353956" source="CERT-VN" patch="1" adv="1">VU#353956</ref>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA04-104A.html" source="CERT" adv="1">TA04-104A</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms04-011.asp" source="MS">MS04-011</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15710" source="XF">win-h323-bo(15710)</ref>
      <ref url="http://www.ciac.org/ciac/bulletins/o-114.shtml" source="CIAC">O-114</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:964" source="OVAL" sig="1">oval:org.mitre.oval:def:964</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:946" source="OVAL" sig="1">oval:org.mitre.oval:def:946</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:907" source="OVAL" sig="1">oval:org.mitre.oval:def:907</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="netmeeting">
        <vers prev="1" num="3"/>
      </prod>
      <prod vendor="microsoft" name="windows_2000">
        <vers num=""/>
      </prod>
      <prod vendor="microsoft" name="windows_2003_server">
        <vers num="r2"/>
      </prod>
      <prod vendor="microsoft" name="windows_98">
        <vers num="" edition="gold"/>
      </prod>
      <prod vendor="microsoft" name="windows_me">
        <vers num=""/>
      </prod>
      <prod vendor="microsoft" name="windows_xp">
        <vers num="" edition="gold"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0118" published="2004-06-01" name="CVE-2004-0118" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">The component for the Virtual DOS Machine (VDM) subsystem in Windows NT 4.0 and Windows 2000 does not properly validate system structures, which allows local users to access protected kernel memory and execute arbitrary code.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1" other="1" admin="1"/>
    </loss_types>
    <vuln_types>
      <exception/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/783748" source="CERT-VN" patch="1" adv="1">VU#783748</ref>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA04-104A.html" source="CERT" adv="1">TA04-104A</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms04-011.asp" source="MS" patch="1" adv="1">MS04-011</ref>
      <ref url="http://www.eeye.com/html/Research/Advisories/AD20040413E.html" source="EEYE" patch="1" adv="1">AD20040413E</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2004-April/020070.html" source="FULLDISC">20040413 EEYE: Windows VDM TIB Local Privilege Escalation</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15714" source="XF">win-vdm-gain-privileges(15714)</ref>
      <ref url="http://www.securityfocus.com/bid/10117" source="BID">10117</ref>
      <ref url="http://www.ciac.org/ciac/bulletins/o-114.shtml" source="CIAC">O-114</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1718" source="OVAL" sig="1">oval:org.mitre.oval:def:1718</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1512" source="OVAL" sig="1">oval:org.mitre.oval:def:1512</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_2000">
        <vers num=""/>
      </prod>
      <prod vendor="microsoft" name="windows_nt">
        <vers num="4.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0119" published="2004-06-01" name="CVE-2004-0119" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">The Negotiate Security Software Provider (SSP) interface in Windows 2000, Windows XP, and Windows Server 2003, allows remote attackers to cause a denial of service (crash from null dereference) or execute arbitrary code via a crafted SPNEGO NegTokenInit request during authentication protocol selection.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <exception/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/638548" source="CERT-VN" patch="1" adv="1">VU#638548</ref>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA04-104A.html" source="CERT" adv="1">TA04-104A</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms04-011.asp" source="MS">MS04-011</ref>
      <ref url="http://archives.neohapsis.com/archives/vulnwatch/2004-q1/0081.html" source="VULNWATCH">20040414 NSFOCUS SA2004-01 : DoS Vulnerability in Microsoft Windows SPNEGO Protocol Decoding</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15715" source="XF">win-spp-bo(15715)</ref>
      <ref url="http://www.securityfocus.com/bid/10113" source="BID">10113</ref>
      <ref url="http://www.ciac.org/ciac/bulletins/o-114.shtml" source="CIAC">O-114</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1997" source="OVAL" sig="1">oval:org.mitre.oval:def:1997</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1962" source="OVAL" sig="1">oval:org.mitre.oval:def:1962</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1808" source="OVAL" sig="1">oval:org.mitre.oval:def:1808</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="internet_information_server">
        <vers num=""/>
      </prod>
      <prod vendor="microsoft" name="windows_2000">
        <vers num=""/>
      </prod>
      <prod vendor="microsoft" name="windows_2003_server">
        <vers num="r2"/>
      </prod>
      <prod vendor="microsoft" name="windows_xp">
        <vers num="" edition="gold"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0120" published="2004-06-01" name="CVE-2004-0120" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The Microsoft Secure Sockets Layer (SSL) library, as used in Windows 2000, Windows XP, and Windows Server 2003, allows remote attackers to cause a denial of service via malformed SSL messages.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/150236" source="CERT-VN" patch="1" adv="1">VU#150236</ref>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA04-104A.html" source="CERT" adv="1">TA04-104A</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms04-011.asp" source="MS">MS04-011</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15712" source="XF">ssl-message-dos(15712)</ref>
      <ref url="http://www.securityfocus.com/bid/10115" source="BID">10115</ref>
      <ref url="http://www.ciac.org/ciac/bulletins/o-114.shtml" source="CIAC">O-114</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:892" source="OVAL" sig="1">oval:org.mitre.oval:def:892</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:886" source="OVAL" sig="1">oval:org.mitre.oval:def:886</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:885" source="OVAL" sig="1">oval:org.mitre.oval:def:885</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_2000">
        <vers num=""/>
      </prod>
      <prod vendor="microsoft" name="windows_2003_server">
        <vers num="r2"/>
      </prod>
      <prod vendor="microsoft" name="windows_xp">
        <vers num="" edition="gold"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0121" published="2004-04-15" name="CVE-2004-0121" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Argument injection vulnerability in Microsoft Outlook 2002 does not sufficiently filter parameters of mailto: URLs when using them as arguments when calling OUTLOOK.EXE, which allows remote attackers to use script code in the Local Machine zone and execute arbitrary programs.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <design/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA04-070A.html" source="CERT">TA04-070A</ref>
      <ref url="http://www.kb.cert.org/vuls/id/305206" source="CERT-VN">VU#305206</ref>
      <ref url="http://www.securityfocus.com/bid/9827" source="BID" patch="1" adv="1">9827</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms04-009.asp" source="MS" patch="1" adv="1">MS04-009</ref>
      <ref url="http://www.idefense.com/application/poi/display?id=79&amp;type=vulnerabilities" source="IDEFENSE" patch="1" adv="1">20040309 Microsoft Outlook "mailto:" Parameter Passing Vulnerability</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15429" source="XF">outlook-ms04009-patch(15429)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15414" source="XF">outlook-mailtourl-execute-code(15414)</ref>
      <ref url="http://www.ciac.org/ciac/bulletins/o-096.shtml" source="CIAC">O-096</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107893704602842&amp;w=2" source="BUGTRAQ">20040310 Outlook mailto: URL argument injection vulnerability</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:843" source="OVAL" sig="1">oval:org.mitre.oval:def:843</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="office">
        <vers num="xp" edition="sp1"/>
        <vers num="xp" edition="sp2"/>
      </prod>
      <prod vendor="microsoft" name="outlook">
        <vers num="2002" edition="sp1"/>
        <vers num="2002" edition="sp2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0122" published="2004-04-15" name="CVE-2004-0122" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Microsoft MSN Messenger 6.0 and 6.1 does not properly handle certain requests, which allows remote attackers to read arbitrary files.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <vuln_types>
      <design/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/688094" source="CERT-VN">VU#688094</ref>
      <ref url="http://www.securityfocus.com/bid/9828" source="BID" patch="1" adv="1">9828</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms04-010.asp" source="MS" patch="1" adv="1">MS04-010</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15427" source="XF">msn-ms04010-patch(15427)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15415" source="XF">msn-request-view-files(15415)</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:844" source="OVAL" sig="1">oval:org.mitre.oval:def:844</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="msn_messenger">
        <vers num="6.0"/>
        <vers num="6.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0123" published="2004-06-01" name="CVE-2004-0123" modified="2008-09-10" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Double free vulnerability in the ASN.1 library as used in Windows NT 4.0, Windows 2000, Windows XP, and Windows Server 2003, allows remote attackers to cause a denial of service and possibly execute arbitrary code.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input/>
      <exception/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/255924" source="CERT-VN" patch="1" adv="1">VU#255924</ref>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA04-104A.html" source="CERT" adv="1">TA04-104A</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15713" source="XF">win-asn1-double-free(15713)</ref>
      <ref url="http://www.securityfocus.com/bid/10118" source="BID">10118</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms04-011.asp" source="MS">MS04-011</ref>
      <ref url="http://www.ciac.org/ciac/bulletins/o-114.shtml" source="CIAC">O-114</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:924" source="OVAL" sig="1">oval:org.mitre.oval:def:924</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1076" source="OVAL" sig="1">oval:org.mitre.oval:def:1076</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1007" source="OVAL" sig="1">oval:org.mitre.oval:def:1007</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_2000">
        <vers num=""/>
      </prod>
      <prod vendor="microsoft" name="windows_2003_server">
        <vers num="r2"/>
      </prod>
      <prod vendor="microsoft" name="windows_98">
        <vers num="" edition="gold"/>
      </prod>
      <prod vendor="microsoft" name="windows_98se">
        <vers num=""/>
      </prod>
      <prod vendor="microsoft" name="windows_me">
        <vers num=""/>
      </prod>
      <prod vendor="microsoft" name="windows_nt">
        <vers num="4.0"/>
      </prod>
      <prod vendor="microsoft" name="windows_xp">
        <vers num="" edition="gold"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2004-0124" published="2004-06-01" name="CVE-2004-0124" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:N/A:N)" CVSS_score="2.6" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="4.9" CVSS_base_score="2.6">
    <desc>
      <descript source="cve">The DCOM RPC interface for Microsoft Windows NT 4.0, 2000, XP, and Server 2003 allows remote attackers to cause network communications via an "alter context" call that contains additional data, aka the "Object Identity Vulnerability."</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <vuln_types>
      <design/>
      <race/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/212892" source="CERT-VN" patch="1" adv="1">VU#212892</ref>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA04-104A.html" source="CERT" adv="1">TA04-104A</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15711" source="XF">win-objectidentifier-open-port(15711)</ref>
      <ref url="http://www.securityfocus.com/bid/10121" source="BID">10121</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms04-012.asp" source="MS">MS04-012</ref>
      <ref url="http://www.ciac.org/ciac/bulletins/o-115.shtml" source="CIAC">O-115</ref>
      <ref url="http://secunia.com/advisories/11065/" source="SECUNIA">11065</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1072" source="OVAL" sig="1">oval:org.mitre.oval:def:1072</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1066" source="OVAL" sig="1">oval:org.mitre.oval:def:1066</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1062" source="OVAL" sig="1">oval:org.mitre.oval:def:1062</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1041" source="OVAL" sig="1">oval:org.mitre.oval:def:1041</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_2000">
        <vers num=""/>
      </prod>
      <prod vendor="microsoft" name="windows_2003_server">
        <vers num="r2"/>
      </prod>
      <prod vendor="microsoft" name="windows_nt">
        <vers num="4.0" edition=""/>
        <vers num="4.0" edition=":terminal_server"/>
        <vers num="4.0" edition=":workstation"/>
        <vers num="4.0" edition=":server"/>
      </prod>
      <prod vendor="microsoft" name="windows_xp">
        <vers num="" edition="gold"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0125" published="2004-08-06" name="CVE-2004-0125" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">The jail system call in FreeBSD 4.x before 4.10-RELEASE does not verify that an attempt to manipulate routing tables originated from a non-jailed process, which could allow local users to modify the routing table.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <vuln_types>
      <access/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/10485" source="BID" patch="1" adv="1">10485</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/16342" source="XF" adv="1">freebsd-jailed-table-modify(16342)</ref>
      <ref url="ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-04:12.jailroute.asc" source="FREEBSD">FreeBSD-SA-04:12</ref>
    </refs>
    <vuln_soft>
      <prod vendor="freebsd" name="freebsd">
        <vers num="4.0" edition="alpha"/>
        <vers num="4.0" edition="releng"/>
        <vers num="4.1"/>
        <vers num="4.1.1" edition="release"/>
        <vers num="4.1.1" edition="stable"/>
        <vers num="4.10"/>
        <vers num="4.2" edition="stable"/>
        <vers num="4.3" edition="release"/>
        <vers num="4.3" edition="release_p38"/>
        <vers num="4.3" edition="releng"/>
        <vers num="4.3" edition="stable"/>
        <vers num="4.4" edition="release_p42"/>
        <vers num="4.4" edition="releng"/>
        <vers num="4.4" edition="stable"/>
        <vers num="4.5" edition="release"/>
        <vers num="4.5" edition="release_p32"/>
        <vers num="4.5" edition="releng"/>
        <vers num="4.5" edition="stable"/>
        <vers num="4.6" edition="release"/>
        <vers num="4.6" edition="release_p20"/>
        <vers num="4.6" edition="releng"/>
        <vers num="4.6" edition="stable"/>
        <vers num="4.6.2"/>
        <vers num="4.7" edition="release"/>
        <vers num="4.7" edition="release_p17"/>
        <vers num="4.7" edition="releng"/>
        <vers num="4.7" edition="stable"/>
        <vers num="4.8" edition="pre-release"/>
        <vers num="4.8" edition="release_p6"/>
        <vers num="4.8" edition="releng"/>
        <vers num="4.9" edition="pre-release"/>
        <vers num="4.9" edition="releng"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0126" published="2004-03-29" name="CVE-2004-0126" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">The jail_attach system call in FreeBSD 5.1 and 5.2 changes the directory of a calling process even if the process doesn't have permission to change directory, which allows local users to gain read/write privileges to files and directories within another jail.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <access/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/9762" source="BID" patch="1" adv="1">9762</ref>
      <ref url="ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-04:03.jail.asc" source="FREEBSD" patch="1" adv="1">FreeBSD-SA-04:03</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15344" source="XF" adv="1">freebsd-jailattach-gain-privileges(15344)</ref>
      <ref url="http://www.osvdb.org/4101" source="OSVDB">4101</ref>
    </refs>
    <vuln_soft>
      <prod vendor="freebsd" name="freebsd">
        <vers num="5.1" edition="release"/>
        <vers num="5.2"/>
        <vers num="5.2.1" edition="release"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0127" published="2004-03-03" name="CVE-2004-0127" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Directory traversal vulnerability in editconfig_gedcom.php for phpGedView 2.65.1 and earlier allows remote attackers to read arbitrary files or execute arbitrary PHP programs on the server via .. (dot dot) sequences in the gedcom_config parameter.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/9529" source="BID" patch="1" adv="1">9529</ref>
      <ref url="http://www.securityfocus.com/archive/1/352355" source="BUGTRAQ" patch="1" adv="1">20040129 PHP Code Injection Vulnerabilities in phpGedView 2.65.1 and prior</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15129" source="XF">phpgedview-editconfig-directory-traversal(15129)</ref>
      <ref url="http://www.securitytracker.com/id?1008892" source="SECTRACK">1008892</ref>
      <ref url="http://www.osvdb.org/displayvuln.php?osvdb_id=3768" source="OSVDB">3768</ref>
      <ref url="http://secunia.com/advisories/10753/" source="SECUNIA">10753</ref>
    </refs>
    <vuln_soft>
      <prod vendor="phpgedview" name="phpgedview">
        <vers num="2.52.3"/>
        <vers num="2.60"/>
        <vers num="2.61"/>
        <vers num="2.61.1"/>
        <vers num="2.65"/>
        <vers num="2.65.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0128" published="2004-03-03" name="CVE-2004-0128" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">PHP remote file inclusion vulnerability in the GEDCOM configuration script for phpGedView 2.65.1 and earlier allows remote attackers to execute arbitrary PHP code by modifying the PGV_BASE_DIRECTORY parameter to reference a URL on a remote web server that contains a malicious theme.php script.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/9531" source="BID" patch="1" adv="1">9531</ref>
      <ref url="http://www.securityfocus.com/archive/1/352355" source="BUGTRAQ" patch="1" adv="1">20040129 PHP Code Injection Vulnerabilities in phpGedView 2.65.1 and prior</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/14987" source="XF">phpgedview-gedfilconf-file-include(14987)</ref>
      <ref url="http://www.osvdb.org/3769" source="OSVDB">3769</ref>
      <ref url="http://sourceforge.net/project/shownotes.php?release_id=141517" source="CONFIRM" adv="1">http://sourceforge.net/project/shownotes.php?release_id=141517</ref>
      <ref url="http://secunia.com/advisories/10753/" source="SECUNIA">10753</ref>
    </refs>
    <vuln_soft>
      <prod vendor="phpgedview" name="phpgedview">
        <vers num="2.52.3"/>
        <vers num="2.60"/>
        <vers num="2.61"/>
        <vers num="2.61.1"/>
        <vers num="2.65"/>
        <vers num="2.65.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0129" published="2004-03-03" name="CVE-2004-0129" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in export.php in phpMyAdmin 2.5.5 and earlier allows remote attackers to read arbitrary files via .. (dot dot) sequences in the what parameter.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/9564" source="BID" patch="1" adv="1">9564</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107582619125932&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20040203 Arbitrary File Disclosure Vulnerability in phpMyAdmin 2.5.5-pl1 and prior</ref>
      <ref url="http://www.phpmyadmin.net/home_page/relnotes.php?rel=0" source="CONFIRM">http://www.phpmyadmin.net/home_page/relnotes.php?rel=0</ref>
      <ref url="http://sourceforge.net/forum/forum.php?forum_id=350228" source="CONFIRM">http://sourceforge.net/forum/forum.php?forum_id=350228</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200402-05.xml" source="GENTOO" adv="1">GLSA-200402-05</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15021" source="XF">phpmyadmin-dotdot-directory-traversal(15021)</ref>
      <ref url="http://www.osvdb.org/3800" source="OSVDB">3800</ref>
      <ref url="http://secunia.com/advisories/10769" source="SECUNIA">10769</ref>
    </refs>
    <vuln_soft>
      <prod vendor="phpmyadmin" name="phpmyadmin">
        <vers num="2.0"/>
        <vers num="2.0.1"/>
        <vers num="2.0.2"/>
        <vers num="2.0.3"/>
        <vers num="2.0.4"/>
        <vers num="2.0.5"/>
        <vers num="2.1"/>
        <vers num="2.1.1"/>
        <vers num="2.1.2"/>
        <vers num="2.2.2"/>
        <vers num="2.2.3"/>
        <vers num="2.2.4"/>
        <vers num="2.2.5"/>
        <vers num="2.2.6"/>
        <vers num="2.2_pre1"/>
        <vers num="2.2_rc1"/>
        <vers num="2.2_rc2"/>
        <vers num="2.2_rc3"/>
        <vers num="2.3.1"/>
        <vers num="2.3.2"/>
        <vers num="2.4.0"/>
        <vers num="2.5.0"/>
        <vers num="2.5.1"/>
        <vers num="2.5.2"/>
        <vers num="2.5.4"/>
        <vers num="2.5.5"/>
        <vers num="2.5.5_pl1"/>
        <vers num="2.5.5_rc1"/>
        <vers num="2.5.5_rc2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0130" published="2004-03-03" name="CVE-2004-0130" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">login.php in phpGedView 2.65 and earlier allows remote attackers to obtain sensitive information via an HTTP request to login.php that does not contain the required username or password parameters, which causes the information to be leaked in an error message.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <vuln_types>
      <design/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securiteam.com/unixfocus/5NP0M1PBPQ.html" source="MISC" adv="1">http://www.securiteam.com/unixfocus/5NP0M1PBPQ.html</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15128" source="XF">phpgedview-loginphp-path-disclosure(15128)</ref>
      <ref url="http://www.osvdb.org/6886" source="OSVDB">6886</ref>
      <ref url="http://www.netvigilance.com/advisory0001" source="MISC">http://www.netvigilance.com/advisory0001</ref>
      <ref url="http://securitytracker.com/alerts/2004/Jan/1008844.html" source="SECTRACK">1008844</ref>
    </refs>
    <vuln_soft>
      <prod vendor="phpgedview" name="phpgedview">
        <vers prev="1" num="2.65"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0131" published="2004-03-03" name="CVE-2004-0131" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The rad_print_request function in logger.c for GNU Radius daemon (radiusd) before 1.2 allows remote atackers to cause a denial of service (crash) via a UDP packet with an Acct-Status-Type attribute without a value and no Acct-Session-Id attribute, which causes a null dereference.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <vuln_types>
      <exception/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/277396" source="CERT-VN" adv="1">VU#277396</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15046" source="XF" patch="1" adv="1">radius-radprintrequest-dos(15046)</ref>
      <ref url="http://www.securityfocus.com/bid/9578" source="BID" patch="1" adv="1">9578</ref>
      <ref url="http://ftp.gnu.org/gnu/radius/radius-1.2.tar.gz" source="CONFIRM">http://ftp.gnu.org/gnu/radius/radius-1.2.tar.gz</ref>
      <ref url="http://www.osvdb.org/3824" source="OSVDB">3824</ref>
      <ref url="http://www.idefense.com/application/poi/display?id=71&amp;type=vulnerabilities&amp;flashstatus=true" source="IDEFENSE">20040204 GNU Radius Remote Denial of Service Vulnerability</ref>
      <ref url="http://secunia.com/advisories/10799" source="SECUNIA">10799</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gnu" name="radius">
        <vers num="1.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0132" published="2004-03-03" name="CVE-2004-0132" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple PHP remote file inclusion vulnerabilities in ezContents 2.0.2 and earlier allow remote attackers to execute arbitrary PHP code from a remote web server, as demonstrated using (1) the GLOBALS[rootdp] parameter to db.php, or (2) the GLOBALS[language_home] parameter to archivednews.php, and a malicious version of lang_admin.php.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107651585921958&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20040210 PHP Code Injection Vulnerabilities in ezContents 2.0.2 and prior</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15135" source="XF" adv="1">ezcontents-multiple-file-include(15135)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="visualshapers" name="ezcontents">
        <vers num="1.40"/>
        <vers num="1.41"/>
        <vers num="1.42"/>
        <vers num="1.43"/>
        <vers num="1.44"/>
        <vers num="1.45"/>
        <vers num="1.45b"/>
        <vers num="2.0.1"/>
        <vers num="2.0.2"/>
        <vers num="2.0_rc1"/>
        <vers num="2.0_rc2"/>
        <vers num="2.0_rc3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2004-0133" published="2004-06-01" name="CVE-2004-0133" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">The XFS file system code in Linux 2.4.x has an information leak in which in-memory data is written to the device for the XFS file system, which allows local users to obtain sensitive information by reading the raw device.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <vuln_types>
      <config/>
      <other/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://www.linuxsecurity.com/advisories/engarde_advisory-4285.html" source="ENGARDE" patch="1" adv="1">ESA-20040428-004</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108213675028441&amp;w=2" source="TRUSTIX" patch="1" adv="1">2004-0020</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/20040405-01-U.asc" source="SGI" patch="1" adv="1">20040405-01-U</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200407-02.xml" source="GENTOO">GLSA-200407-02</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15901" source="XF">linux-xfs-info-disclosure(15901)</ref>
      <ref url="http://www.securityfocus.com/bid/10151" source="BID">10151</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2004:029" source="MANDRAKE">MDKSA-2004:029</ref>
      <ref url="http://secunia.com/advisories/11362" source="SECUNIA">11362</ref>
    </refs>
    <vuln_soft>
      <prod vendor="linux" name="linux_kernel">
        <vers num="2.4.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0134" published="2004-08-18" name="CVE-2004-0134" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">cpr (libcpr) in SGI IRIX before 6.5.25 allows local users to gain privileges by loading a user provided library while restarting the checkpointed process.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1" admin="1"/>
    </loss_types>
    <vuln_types>
      <input/>
      <exception/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/16259" source="XF" adv="1">irix-cpr-gain-privileges(16259)</ref>
      <ref url="http://www.securityfocus.com/bid/10418" source="BID" adv="1">10418</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/20040507-01-P.asc" source="SGI">20040507-01-P</ref>
    </refs>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0135" published="2004-08-06" name="CVE-2004-0135" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">The syssgi SGI_IOPROBE system call in IRIX 6.5.20 through 6.5.24 allows local users to gain privileges by reading and writing to kernel memory.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1" admin="1"/>
    </loss_types>
    <vuln_types>
      <access/>
      <design/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/16413" source="XF" adv="1">irix-sgiioprobe-gain-privileges(16413)</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/20040601-01-P.asc" source="SGI">20040601-01-P</ref>
      <ref url="http://www.osvdb.org/7122" source="OSVDB">7122</ref>
      <ref url="http://secunia.com/advisories/11872" source="SECUNIA">11872</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sgi" name="irix">
        <vers num="3.2"/>
        <vers num="3.3"/>
        <vers num="3.3.1"/>
        <vers num="3.3.2"/>
        <vers num="3.3.3"/>
        <vers num="4.0"/>
        <vers num="4.0.1"/>
        <vers num="4.0.1t"/>
        <vers num="4.0.2"/>
        <vers num="4.0.3"/>
        <vers num="4.0.4"/>
        <vers num="4.0.4b"/>
        <vers num="4.0.4t"/>
        <vers num="4.0.5"/>
        <vers num="4.0.5_iop"/>
        <vers num="4.0.5_ipr"/>
        <vers num="4.0.5a"/>
        <vers num="4.0.5b"/>
        <vers num="4.0.5e"/>
        <vers num="4.0.5f"/>
        <vers num="4.0.5g"/>
        <vers num="4.0.5h"/>
        <vers num="5.0"/>
        <vers num="5.0.1"/>
        <vers num="5.1"/>
        <vers num="5.1.1"/>
        <vers num="5.2"/>
        <vers num="5.3" edition=""/>
        <vers num="5.3" edition=":xfs"/>
        <vers num="6.0"/>
        <vers num="6.0.1" edition=""/>
        <vers num="6.0.1" edition=":xfs"/>
        <vers num="6.1"/>
        <vers num="6.2"/>
        <vers num="6.3"/>
        <vers num="6.4"/>
        <vers num="6.5"/>
        <vers num="6.5.1"/>
        <vers num="6.5.10"/>
        <vers num="6.5.10f"/>
        <vers num="6.5.10m"/>
        <vers num="6.5.11"/>
        <vers num="6.5.11f"/>
        <vers num="6.5.11m"/>
        <vers num="6.5.12"/>
        <vers num="6.5.12f"/>
        <vers num="6.5.12m"/>
        <vers num="6.5.13"/>
        <vers num="6.5.13f"/>
        <vers num="6.5.13m"/>
        <vers num="6.5.14"/>
        <vers num="6.5.14f"/>
        <vers num="6.5.14m"/>
        <vers num="6.5.15"/>
        <vers num="6.5.15f"/>
        <vers num="6.5.15m"/>
        <vers num="6.5.16"/>
        <vers num="6.5.16f"/>
        <vers num="6.5.16m"/>
        <vers num="6.5.17"/>
        <vers num="6.5.17f"/>
        <vers num="6.5.17m"/>
        <vers num="6.5.18"/>
        <vers num="6.5.18f"/>
        <vers num="6.5.18m"/>
        <vers num="6.5.19"/>
        <vers num="6.5.19f"/>
        <vers num="6.5.19m"/>
        <vers num="6.5.2"/>
        <vers num="6.5.20"/>
        <vers num="6.5.20f"/>
        <vers num="6.5.20m"/>
        <vers num="6.5.21"/>
        <vers num="6.5.21f"/>
        <vers num="6.5.21m"/>
        <vers num="6.5.22"/>
        <vers num="6.5.22m"/>
        <vers num="6.5.23"/>
        <vers num="6.5.24"/>
        <vers num="6.5.2f"/>
        <vers num="6.5.2m"/>
        <vers num="6.5.3"/>
        <vers num="6.5.3f"/>
        <vers num="6.5.3m"/>
        <vers num="6.5.4"/>
        <vers num="6.5.4f"/>
        <vers num="6.5.4m"/>
        <vers num="6.5.5"/>
        <vers num="6.5.5f"/>
        <vers num="6.5.5m"/>
        <vers num="6.5.6"/>
        <vers num="6.5.6f"/>
        <vers num="6.5.6m"/>
        <vers num="6.5.7"/>
        <vers num="6.5.7f"/>
        <vers num="6.5.7m"/>
        <vers num="6.5.8"/>
        <vers num="6.5.8f"/>
        <vers num="6.5.8m"/>
        <vers num="6.5.9"/>
        <vers num="6.5.9f"/>
        <vers num="6.5.9m"/>
        <vers num="6.5_20"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2004-0136" published="2004-08-06" name="CVE-2004-0136" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">The mapelf32exec function call in IRIX 6.5.20 through 6.5.24 allows local users to cause a denial of service (system crash) via a "corrupted binary."</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <vuln_types>
      <exception/>
      <other/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/16416" source="XF" adv="1">irix-mapelf32exec-dos(16416)</ref>
      <ref url="http://www.securityfocus.com/bid/10547" source="BID" adv="1">10547</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/20040601-01-P.asc" source="SGI">20040601-01-P</ref>
      <ref url="http://www.osvdb.org/7123" source="OSVDB">7123</ref>
      <ref url="http://secunia.com/advisories/11872" source="SECUNIA">11872</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sgi" name="irix">
        <vers num="6.5.20f"/>
        <vers num="6.5.20m"/>
        <vers num="6.5.21f"/>
        <vers num="6.5.21m"/>
        <vers num="6.5.22"/>
        <vers num="6.5.23"/>
        <vers num="6.5.24"/>
        <vers num="6.5.25"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2004-0137" published="2004-08-06" name="CVE-2004-0137" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">Unknown vulnerability in init for IRIX 6.5.20 through 6.5.24 allows local users to cause a denial of service (system panic) as a result of "page invalidation issues."</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <vuln_types>
      <exception/>
      <other/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/16417" source="XF" adv="1">irix-page-dos(16417)</ref>
      <ref url="http://www.securityfocus.com/bid/10549" source="BID" adv="1">10549</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/20040601-01-P.asc" source="SGI">20040601-01-P</ref>
      <ref url="http://www.osvdb.org/7124" source="OSVDB">7124</ref>
      <ref url="http://secunia.com/advisories/11872" source="SECUNIA">11872</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sgi" name="irix">
        <vers num="6.5.20f"/>
        <vers num="6.5.20m"/>
        <vers num="6.5.21f"/>
        <vers num="6.5.21m"/>
        <vers num="6.5.22"/>
        <vers num="6.5.23"/>
        <vers num="6.5.24"/>
        <vers num="6.5.25"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0138" published="2004-12-31" name="CVE-2004-0138" modified="2010-08-21" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="4.9" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="3.9" CVSS_base_score="4.9">
    <desc>
      <descript source="cve">The ELF loader in Linux kernel 2.4 before 2.4.25 allows local users to cause a denial of service (crash) via a crafted ELF file with an interpreter with an invalid arch (architecture), which triggers a BUG() when an invalid VMA is unmapped.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <vuln_types>
      <exception/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://www.debian.org/security/2006/dsa-1082" source="DEBIAN" patch="1" adv="1">DSA-1082</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1070" source="DEBIAN" patch="1" adv="1">DSA-1070</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1069" source="DEBIAN" patch="1" adv="1">DSA-1069</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1067" source="DEBIAN" patch="1" adv="1">DSA-1067</ref>
      <ref url="http://secunia.com/advisories/20202" source="SECUNIA" patch="1" adv="1">20202</ref>
      <ref url="http://secunia.com/advisories/20163" source="SECUNIA" patch="1" adv="1">20163</ref>
      <ref url="http://secunia.com/advisories/20162" source="SECUNIA" patch="1" adv="1">20162</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10123" source="OVAL">oval:org.mitre.oval:def:10123</ref>
      <ref url="http://linux.bkbits.net:8080/linux-2.4/cset@4021346f79nBb-4X_usRikR3Iyb4Vg" source="CONFIRM">http://linux.bkbits.net:8080/linux-2.4/cset@4021346f79nBb-4X_usRikR3Iyb4Vg</ref>
      <ref url="http://kernel.debian.net/debian/pool/main/kernel-source-2.4.17/kernel-source-2.4.17_2.4.17-1woody4_ia64.changes" source="CONFIRM">http://kernel.debian.net/debian/pool/main/kernel-source-2.4.17/kernel-source-2.4.17_2.4.17-1woody4_ia64.changes</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/43124" source="XF">linux-kernel-elfloader-dos(43124)</ref>
      <ref url="http://www.securityfocus.com/bid/18174" source="BID">18174</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-549.html" source="REDHAT">RHSA-2004:549</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-504.html" source="REDHAT">RHSA-2004:504</ref>
      <ref url="http://secunia.com/advisories/20338" source="SECUNIA">20338</ref>
      <ref url="http://kernel.org/pub/linux/kernel/v2.4/ChangeLog-2.4.25" source="CONFIRM">http://kernel.org/pub/linux/kernel/v2.4/ChangeLog-2.4.25</ref>
    </refs>
    <vuln_soft>
      <prod vendor="linux" name="linux_kernel">
        <vers num="2.4.0"/>
        <vers num="2.4.1"/>
        <vers num="2.4.10"/>
        <vers num="2.4.11"/>
        <vers num="2.4.12"/>
        <vers num="2.4.13"/>
        <vers num="2.4.14"/>
        <vers num="2.4.15"/>
        <vers num="2.4.16"/>
        <vers num="2.4.17"/>
        <vers num="2.4.18"/>
        <vers num="2.4.19"/>
        <vers num="2.4.2"/>
        <vers num="2.4.20"/>
        <vers num="2.4.21"/>
        <vers num="2.4.22"/>
        <vers num="2.4.23"/>
        <vers num="2.4.24"/>
        <vers num="2.4.3"/>
        <vers num="2.4.4"/>
        <vers num="2.4.5"/>
        <vers num="2.4.6"/>
        <vers num="2.4.7"/>
        <vers num="2.4.8"/>
        <vers num="2.4.9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0139" published="2005-01-10" name="CVE-2004-0139" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Unknown vulnerability in the bsd.a kernel networking for SGI IRIX 6.5.22 through 6.5.25, and possibly earlier versions, in which "t_unbind changes t_bind's behavior," has unknown impact and attack vectors.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <vuln_types>
      <other/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/11276" source="BID" patch="1" adv="1">11276</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/17547" source="XF" adv="1">irix-bsda-kernel(17547)</ref>
      <ref url="http://secunia.com/advisories/12682" source="SECUNIA">12682</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/20040905-01-P.asc" source="SGI">20040905-01-P</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sgi" name="irix">
        <vers num="6.5.22"/>
        <vers num="6.5.23"/>
        <vers num="6.5.24"/>
        <vers num="6.5.25"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0143" published="2004-03-03" name="CVE-2004-0143" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Multiple vulnerabilities in Nokia 6310(i) Mobile phones allow remote attackers to cause a denial of service (reset) via malformed Bluetooth OBject EXchange (OBEX) messages, probably triggering buffer overflows.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <vuln_types>
      <input buffer="1"/>
      <design/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/15107" source="XF" patch="1" adv="1">nokia-obex-dos(15107)</ref>
      <ref url="http://www.securityfocus.com/bid/9603" source="BID" patch="1" adv="1">9603</ref>
      <ref url="http://www.pentest.co.uk/documents/ptl-2004-01.html" source="MISC" patch="1" adv="1">http://www.pentest.co.uk/documents/ptl-2004-01.html</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107634788029065&amp;w=2" source="BUGTRAQ" adv="1">20040209 ptl-2004-01: Multiple vulnerabilities in Nokia phones</ref>
      <ref url="http://archives.neohapsis.com/archives/vulnwatch/2004-q1/0034.html" source="VULNWATCH">20040209 ptl-2004-01: Multiple vulnerabilities in Nokia phones</ref>
    </refs>
    <vuln_soft>
      <prod vendor="nokia" name="6310i">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0148" published="2004-04-15" name="CVE-2004-0148" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">wu-ftpd 2.6.2 and earlier, with the restricted-gid option enabled, allows local users to bypass access restrictions by changing the permissions to prevent access to their home directory, which causes wu-ftpd to use the root directory instead.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <vuln_types>
      <access/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/9832" source="BID" patch="1" adv="1">9832</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-096.html" source="REDHAT" patch="1" adv="1">RHSA-2004:096</ref>
      <ref url="http://www.debian.org/security/2004/dsa-457" source="DEBIAN" patch="1" adv="1">DSA-457</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15423" source="XF">wuftpd-restrictedgid-gain-access(15423)</ref>
      <ref url="http://www.frsirt.com/english/advisories/2006/1867" source="FRSIRT">ADV-2006-1867</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-102356-1" source="SUNALERT">102356</ref>
      <ref url="http://secunia.com/advisories/20168" source="SECUNIA">20168</ref>
      <ref url="http://secunia.com/advisories/11055" source="SECUNIA">11055</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108999466902690&amp;w=2" source="HP">SSRT4704</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:648" source="OVAL" sig="1">oval:org.mitre.oval:def:648</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1637" source="OVAL" sig="1">oval:org.mitre.oval:def:1637</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1636" source="OVAL" sig="1">oval:org.mitre.oval:def:1636</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1147" source="OVAL" sig="1">oval:org.mitre.oval:def:1147</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sgi" name="propack">
        <vers num="2.3"/>
        <vers num="2.4"/>
      </prod>
      <prod vendor="washington_university" name="wu-ftpd">
        <vers num="2.4.1"/>
        <vers num="2.4.2_beta18" edition=""/>
        <vers num="2.4.2_beta18" edition=":academ"/>
        <vers num="2.4.2_beta18_vr10"/>
        <vers num="2.4.2_beta18_vr11"/>
        <vers num="2.4.2_beta18_vr12"/>
        <vers num="2.4.2_beta18_vr13"/>
        <vers num="2.4.2_beta18_vr14"/>
        <vers num="2.4.2_beta18_vr15"/>
        <vers num="2.4.2_beta18_vr4"/>
        <vers num="2.4.2_beta18_vr5"/>
        <vers num="2.4.2_beta18_vr6"/>
        <vers num="2.4.2_beta18_vr7"/>
        <vers num="2.4.2_beta18_vr8"/>
        <vers num="2.4.2_beta18_vr9"/>
        <vers num="2.4.2_beta2" edition=""/>
        <vers num="2.4.2_beta2" edition=":academ"/>
        <vers num="2.4.2_vr16"/>
        <vers num="2.4.2_vr17"/>
        <vers num="2.5.0"/>
        <vers num="2.6.0"/>
        <vers num="2.6.1"/>
        <vers num="2.6.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0149" published="2004-05-04" name="CVE-2004-0149" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Multiple buffer overflows in xboing before 2.4 allow local users to gain privileges.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <vuln_types>
      <input buffer="1" bound="1"/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://www.debian.org/security/2004/dsa-451" source="DEBIAN" patch="1">DSA-451</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15347" source="XF" adv="1">xboing-bo(15347)</ref>
      <ref url="http://www.securityfocus.com/bid/9764" source="BID" adv="1">9764</ref>
    </refs>
    <vuln_soft>
      <prod vendor="xboing" name="xboing">
        <vers num="2.4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0150" published="2004-04-15" name="CVE-2004-0150" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in the getaddrinfo function in Python 2.2 before 2.2.2, when IPv6 support is disabled, allows remote attackers to execute arbitrary code via an IPv6 address that is obtained using DNS.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input bound="1"/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/9836" source="BID" patch="1" adv="1">9836</ref>
      <ref url="http://www.debian.org/security/2004/dsa-458" source="DEBIAN" patch="1" adv="1">DSA-458</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15409" source="XF">python-getaddrinfo-bo(15409)</ref>
      <ref url="http://www.osvdb.org/4172" source="OSVDB">4172</ref>
      <ref url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2004:019" source="MANDRAKE">MDKSA-2004:019</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200409-03.xml" source="GENTOO">GLSA-200409-03</ref>
    </refs>
    <vuln_soft>
      <prod vendor="python_software_foundation" name="python">
        <vers num="2.2"/>
        <vers num="2.2.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0151" published="2004-04-15" name="CVE-2004-0151" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Unknown vulnerability in xitalk 1.1.11 and earlier allows local users to execute arbitrary commands.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <vuln_types>
      <design/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/15456" source="XF" patch="1" adv="1">xitalk-gain-privileges(15456)</ref>
      <ref url="http://www.securityfocus.com/bid/9851" source="BID" patch="1" adv="1">9851</ref>
      <ref url="http://www.debian.org/security/2004/dsa-462" source="DEBIAN" patch="1" adv="1">DSA-462</ref>
      <ref url="http://shellcode.org/Advisories/XITALK.txt" source="MISC">http://shellcode.org/Advisories/XITALK.txt</ref>
      <ref url="http://secunia.com/advisories/11114/" source="SECUNIA">11114</ref>
    </refs>
    <vuln_soft>
      <prod vendor="xintercepttalk" name="xitalk">
        <vers num="1.1.11"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0152" published="2004-04-15" name="CVE-2004-0152" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple stack-based buffer overflows in (1) the encode_mime function, (2) the encode_uuencode function, (3) or the decode_uuencode function for emil 2.1.0 and earlier allow remote attackers to execute arbitrary code via e-mail messages containing attachments with filenames.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input buffer="1"/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.debian.org/security/2004/dsa-468" source="DEBIAN" patch="1" adv="1">DSA-468</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15601" source="XF" adv="1">emil-email-bo(15601)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108024939827236&amp;w=2" source="BUGTRAQ" adv="1">20040325 Re: [SECURITY] [DSA 468-1] New emil packages fix multiple vulnerabilities</ref>
    </refs>
    <vuln_soft>
      <prod vendor="emil" name="emil">
        <vers num="2.0.4"/>
        <vers num="2.0.5"/>
        <vers num="2.1.0_beta9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0153" published="2004-04-15" name="CVE-2004-0153" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple format string vulnerabilities in emil 2.1.0 and earlier may allow remote attackers to execute arbitrary code by triggering certain error messages.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.debian.org/security/2004/dsa-468" source="DEBIAN" patch="1" adv="1">DSA-468</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15602" source="XF" adv="1">emil-format-string(15602)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108024939827236&amp;w=2" source="BUGTRAQ" adv="1">20040325 Re: [SECURITY] [DSA 468-1] New emil packages fix multiple vulnerabilities</ref>
    </refs>
    <vuln_soft>
      <prod vendor="emil" name="emil">
        <vers num="2.0.4"/>
        <vers num="2.0.5"/>
        <vers num="2.1.0_beta9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0154" published="2004-06-14" name="CVE-2004-0154" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">rpc.mountd in nfs-utils after 1.0.3 and before 1.0.6 allows attackers to cause a denial of service (crash) via an NFS mount of a directory from a client whose reverse DNS lookup name is different from the forward lookup name.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <vuln_types>
      <exception/>
      <env/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/15418" source="XF" patch="1" adv="1">nfs-utils-dns-dos(15418)</ref>
      <ref url="http://www.trustix.org/errata/misc/2004/TSL-2004-0009-nfs-utils.asc.txt" source="TRUSTIX" patch="1" adv="1">2004-0009</ref>
      <ref url="http://www.securityfocus.com/bid/9813" source="BID" patch="1" adv="1">9813</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-072.html" source="REDHAT" patch="1" adv="1">RHSA-2004:072</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9673" source="OVAL">oval:org.mitre.oval:def:9673</ref>
      <ref url="http://bugzilla.redhat.com/bugzilla/long_list.cgi?buglist=114535" source="MISC" adv="1">http://bugzilla.redhat.com/bugzilla/long_list.cgi?buglist=114535</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:861" source="OVAL" sig="1">oval:org.mitre.oval:def:861</ref>
    </refs>
    <vuln_soft>
      <prod vendor="nfs" name="nfs-utils">
        <vers num="1.0"/>
        <vers num="1.0.1"/>
        <vers num="1.0.3"/>
        <vers num="1.0.4"/>
        <vers num="1.0.6"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0155" published="2004-06-01" name="CVE-2004-0155" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">The KAME IKE Daemon Racoon, when authenticating a peer during Phase 1, validates the X.509 certificate but does not verify the RSA signature authentication, which allows remote attackers to establish unauthorized IP connections or conduct man-in-the-middle attacks using a valid, trusted X.509 certificate.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <access/>
      <design/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/552398" source="CERT-VN">VU#552398</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-165.html" source="REDHAT" patch="1" adv="1">RHSA-2004:165</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108369640424244&amp;w=2" source="APPLE" patch="1">APPLE-SA-2004-05-03</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108136746911000&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20040407 CAN-2004-0155:  The KAME IKE Daemon Racoon does not verify RSA Signatures during Phase 1, allows man-in-the-middle attacks and unauthorized connections</ref>
      <ref url="http://www.securityfocus.com/bid/10072" source="BID">10072</ref>
      <ref url="http://www.mandrakesecure.net/en/advisories/advisory.php?name=MDKSA-2004:069" source="MANDRAKE">MDKSA-2004:069</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200406-17.xml" source="GENTOO">GLSA-200406-17</ref>
      <ref url="http://secunia.com/advisories/11328" source="SECUNIA">11328</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9291" source="OVAL">oval:org.mitre.oval:def:9291</ref>
      <ref url="ftp://ftp.sco.com/pub/updates/UnixWare/SCOSA-2005.10/SCOSA-2005.10.txt" source="SCO">SCOSA-2005.10</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2004:027" source="MANDRAKE">MDKSA-2004:027</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:945" source="OVAL" sig="1">oval:org.mitre.oval:def:945</ref>
    </refs>
    <vuln_soft>
      <prod vendor="kame" name="racoon">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0156" published="2004-06-01" name="CVE-2004-0156" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Format string vulnerabilities in the (1) die or (2) log_event functions for ssmtp before 2.50.6 allow remote mail relays to cause a denial of service and possibly execute arbitrary code.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <vuln_types>
      <design/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.debian.org/security/2004/dsa-485" source="DEBIAN" patch="1" adv="1">DSA-485</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200404-18.xml" source="GENTOO" patch="1" adv="1">GLSA-200404-18</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15872" source="XF">ssmtp-die-logevent-format-string(15872)</ref>
      <ref url="http://www.securityfocus.com/bid/10150" source="BID">10150</ref>
      <ref url="http://www.osvdb.org/5361" source="OSVDB">5361</ref>
      <ref url="http://www.osvdb.org/5360" source="OSVDB">5360</ref>
      <ref url="http://securitytracker.com/id?1009788" source="SECTRACK">1009788</ref>
      <ref url="http://secunia.com/advisories/11571" source="SECUNIA">11571</ref>
      <ref url="http://secunia.com/advisories/11485" source="SECUNIA">11485</ref>
      <ref url="http://secunia.com/advisories/11384" source="SECUNIA">11384</ref>
      <ref url="http://secunia.com/advisories/11378" source="SECUNIA">11378</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108403772130855&amp;w=2" source="BUGTRAQ">20040507 [OpenPKG-SA-2004.020] OpenPKG Security Advisory (ssmtp)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ssmtp" name="ssmtp">
        <vers prev="1" num="2.49"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0157" published="2004-06-01" name="CVE-2004-0157" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">x11.c in xonix 1.4 and earlier uses the current working directory to find and execute the rmail program, which allows local users to execute arbitrary code by modifying the path to point to a malicious rmail program.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <design/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://www.debian.org/security/2004/dsa-484" source="DEBIAN" patch="1" adv="1">DSA-484</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15873" source="XF">xonix-privilege-dropping(15873)</ref>
      <ref url="http://www.securityfocus.com/bid/10149" source="BID">10149</ref>
      <ref url="http://www.osvdb.org/5358" source="OSVDB">5358</ref>
      <ref url="http://shellcode.org/Advisories/XONIX.txt" source="MISC">http://shellcode.org/Advisories/XONIX.txt</ref>
      <ref url="http://securitytracker.com/id?1009789" source="SECTRACK">1009789</ref>
      <ref url="http://secunia.com/advisories/11382" source="SECUNIA">11382</ref>
    </refs>
    <vuln_soft>
      <prod vendor="xonix" name="xonix">
        <vers prev="1" num="1.4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0158" published="2004-03-29" name="CVE-2004-0158" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Buffer overflow in lbreakout2 allows local users to gain 'games' group privileges via a large HOME environment variable to (1) editor.c, (2) theme.c, (3) manager.c, (4) config.c, (5) game.c, (6) levels.c, or (7) main.c.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input bound="1"/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/15229" source="XF" patch="1" adv="1">breakout2-home-bo(15229)</ref>
      <ref url="http://www.securityfocus.com/bid/9712" source="BID" patch="1" adv="1">9712</ref>
      <ref url="http://www.debian.org/security/2004/dsa-445" source="DEBIAN" patch="1" adv="1">DSA-445</ref>
      <ref url="http://security.debian.org/pool/updates/main/l/lbreakout2/lbreakout2_2.2.2-1woody1.diff.gz" source="CONFIRM">http://security.debian.org/pool/updates/main/l/lbreakout2/lbreakout2_2.2.2-1woody1.diff.gz</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107755821705356&amp;w=2" source="BUGTRAQ">20040222 lbreakout2 &lt; 2.4beta-2 local exploit</ref>
    </refs>
    <vuln_soft>
      <prod vendor="lgames" name="lbreakout2">
        <vers num="2.0"/>
        <vers num="2.0.1"/>
        <vers num="2.1"/>
        <vers num="2.1.1"/>
        <vers num="2.1.2"/>
        <vers num="2.2"/>
        <vers num="2.2.1"/>
        <vers num="2.2.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0159" published="2004-03-15" name="CVE-2004-0159" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Format string vulnerability in hsftp 1.11 allows remote authenticated users to cause a denial of service and possibly execute arbitrary code via file names containing format string characters that are not properly handled when executing an "ls" command.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/9715" source="BID" patch="1" adv="1">9715</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107755803218677&amp;w=2" source="DEBIAN" patch="1" adv="1">DSA-447</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15276" source="XF" adv="1">hsftp-format-string(15276)</ref>
      <ref url="http://www.osvdb.org/4029" source="OSVDB">4029</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2004-February/017737.html" source="FULLDISC">20040223 Re: [SECURITY] [DSA 447-1] New hsftp packages fix format string vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="samhain_labs" name="hsftp">
        <vers num="1.10"/>
        <vers num="1.11"/>
        <vers num="1.4"/>
        <vers num="1.5"/>
        <vers num="1.6"/>
        <vers num="1.7"/>
        <vers num="1.9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0160" published="2004-03-29" name="CVE-2004-0160" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Synaesthesia 2.2 and earlier allows local users to execute arbitrary code via a symlink attack on the configuration file.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <vuln_types>
      <env/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/15279" source="XF" patch="1" adv="1">synaesthesia-configuration-symlink-attack(15279)</ref>
      <ref url="http://www.securityfocus.com/bid/9713" source="BID" patch="1" adv="1">9713</ref>
      <ref url="http://www.debian.org/security/2004/dsa-446" source="DEBIAN" patch="1" adv="1">DSA-446</ref>
    </refs>
    <vuln_soft>
      <prod vendor="synaesthesia" name="synaesthesia">
        <vers num="2.1.0"/>
        <vers num="2.1.1"/>
        <vers num="2.1.2"/>
        <vers num="2.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0161" published="2004-10-20" name="CVE-2004-0161" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple content security gateway and antivirus products allow remote attackers to bypass content restrictions via MIME messages that use RFC2231 encoding, which may be interpreted differently by mail clients.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <exception/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/9274" source="XF">mime-tools-parameter-encoding(9274)</ref>
      <ref url="http://www.uniras.gov.uk/vuls/2004/380375/mime.htm" source="MISC" adv="1">http://www.uniras.gov.uk/vuls/2004/380375/mime.htm</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109524928232568&amp;w=2" source="BUGTRAQ" adv="1">20040914 Corsaire Security Advisory - Multiple vendor MIME RFC2231 encoding issue</ref>
    </refs>
    <vuln_soft>
      <prod vendor="clearswift" name="mailsweeper">
        <vers num="4.3.10"/>
        <vers num="4.3.11"/>
        <vers num="4.3.13"/>
        <vers num="4.3.14"/>
        <vers num="4.3.15"/>
        <vers num="4.3.7"/>
        <vers num="4.3.8"/>
      </prod>
      <prod vendor="f-secure" name="internet_gatekeeper">
        <vers num="6.3"/>
        <vers num="6.31"/>
        <vers num="6.32"/>
        <vers num="6.4"/>
      </prod>
      <prod vendor="paul_l_daniels" name="ripmime">
        <vers num="1.2.0"/>
        <vers num="1.2.1"/>
        <vers num="1.2.2"/>
        <vers num="1.2.3"/>
        <vers num="1.2.4"/>
        <vers num="1.2.5"/>
        <vers num="1.2.6"/>
        <vers num="1.2.7"/>
        <vers num="1.3.2.0"/>
        <vers num="1.3.2.2"/>
        <vers num="1.3.2.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0162" published="2004-10-20" name="CVE-2004-0162" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple content security gateway and antivirus products allow remote attackers to bypass content restrictions via MIME encapsulation that uses RFC822 comment fields, which may be interpreted as other fields by mail clients.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <exception/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/17332" source="XF">mime-rfc822-filtering-bypass(17332)</ref>
      <ref url="http://www.uniras.gov.uk/vuls/2004/380375/mime.htm" source="MISC" adv="1">http://www.uniras.gov.uk/vuls/2004/380375/mime.htm</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109517563513776&amp;w=2" source="BUGTRAQ" adv="1">20040914 Corsaire Security Advisory - Multiple vendor MIME RFC822 comment issue</ref>
    </refs>
    <vuln_soft>
      <prod vendor="clearswift" name="mailsweeper">
        <vers num="4.3.10"/>
        <vers num="4.3.11"/>
        <vers num="4.3.13"/>
        <vers num="4.3.14"/>
        <vers num="4.3.15"/>
        <vers num="4.3.7"/>
        <vers num="4.3.8"/>
      </prod>
      <prod vendor="f-secure" name="internet_gatekeeper">
        <vers num="6.3"/>
        <vers num="6.31"/>
        <vers num="6.32"/>
        <vers num="6.4"/>
      </prod>
      <prod vendor="paul_l_daniels" name="ripmime">
        <vers num="1.2.0"/>
        <vers num="1.2.1"/>
        <vers num="1.2.2"/>
        <vers num="1.2.3"/>
        <vers num="1.2.4"/>
        <vers num="1.2.5"/>
        <vers num="1.2.6"/>
        <vers num="1.2.7"/>
        <vers num="1.3.2.0"/>
        <vers num="1.3.2.2"/>
        <vers num="1.3.2.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0163" published="2004-09-28" name="CVE-2004-0163" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Sygate Secure Enterprise (SSE) 3.5MR3 and earlier does not change the key used to encrypt data, which allows remote attackers to cause a denial of service (resource exhaustion) by capturing a session and repeatedly replaying the session.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <vuln_types>
      <design/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/16945" source="XF" patch="1" adv="1">sse-replay-dos(16945)</ref>
      <ref url="http://www.corsaire.com/advisories/c031120-002.txt" source="MISC" patch="1" adv="1">http://www.corsaire.com/advisories/c031120-002.txt</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109215685731675&amp;w=2" source="BUGTRAQ">20040810 Corsaire Security Advisory - Sygate Secure Enterprise replay issue</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sygate_technologies" name="secure_enterprise">
        <vers prev="1" num="3.5mr3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0164" published="2004-03-03" name="CVE-2004-0164" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">KAME IKE daemon (racoon) does not properly handle hash values, which allows remote attackers to delete certificates via (1) a certain delete message that is not properly handled in isakmp.c or isakmp_inf.c, or (2) a certain INITIAL-CONTACT message that is not properly handled in isakmp_inf.c.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <vuln_types>
      <access/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107411758202662&amp;w=2" source="BUGTRAQ" patch="1">20040114 Re: unauthorized deletion of IPsec (and ISAKMP) SAs in racoon</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/14118" source="XF">openbsd-isakmp-initialcontact-delete-sa(14118)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/14117" source="XF" adv="1">openbsd-isakmp-invalidspi-delete-sa(14117)</ref>
      <ref url="http://www.securityfocus.com/bid/9417" source="BID">9417</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9737" source="OVAL">oval:org.mitre.oval:def:9737</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2004/Feb/msg00000.html" source="APPLE">APPLE-SA-2004-02-23</ref>
      <ref url="ftp://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2004-001.txt.asc" source="NETBSD">NetBSD-SA2004-001</ref>
      <ref url="http://www.securityfocus.com/bid/9416" source="BID">9416</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107403331309838&amp;w=2" source="BUGTRAQ">20040113 unauthorized deletion of IPsec (and ISAKMP) SAs in racoon</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:947" source="OVAL" sig="1">oval:org.mitre.oval:def:947</ref>
    </refs>
    <vuln_soft>
      <prod vendor="kame" name="racoon">
        <vers num="all_versions"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0165" published="2004-03-15" name="CVE-2004-0165" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Format string vulnerability in Point-to-Point Protocol (PPP) daemon (pppd) 2.4.0 for Mac OS X 10.3.2 and earlier allows remote attackers to read arbitrary pppd process data, including PAP or CHAP authentication credentials, to gain privileges.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/841742" source="CERT-VN" adv="1">VU#841742</ref>
      <ref url="http://www.securityfocus.com/bid/9730" source="BID" patch="1" adv="1">9730</ref>
      <ref url="http://www.atstake.com/research/advisories/2004/a022304-1.txt" source="ATSTAKE" patch="1" adv="1">A022304-1</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15297" source="XF" adv="1">macos-pppd-format-string(15297)</ref>
      <ref url="http://www.osvdb.org/6822" source="OSVDB">6822</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2004/Feb/msg00000.html" source="APPLE">APPLE-SA-2004-02-23</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.1"/>
        <vers num="10.1.1"/>
        <vers num="10.1.2"/>
        <vers num="10.1.3"/>
        <vers num="10.1.4"/>
        <vers num="10.1.5"/>
        <vers num="10.2"/>
        <vers num="10.2.1"/>
        <vers num="10.2.2"/>
        <vers num="10.2.3"/>
        <vers num="10.2.4"/>
        <vers num="10.2.5"/>
        <vers num="10.2.6"/>
        <vers num="10.2.7"/>
        <vers num="10.2.8"/>
        <vers num="10.3"/>
        <vers num="10.3.1"/>
        <vers num="10.3.2"/>
      </prod>
      <prod vendor="apple" name="mac_os_x_server">
        <vers num="10.1"/>
        <vers num="10.1.1"/>
        <vers num="10.1.2"/>
        <vers num="10.1.3"/>
        <vers num="10.1.4"/>
        <vers num="10.1.5"/>
        <vers num="10.2"/>
        <vers num="10.2.1"/>
        <vers num="10.2.2"/>
        <vers num="10.2.3"/>
        <vers num="10.2.4"/>
        <vers num="10.2.5"/>
        <vers num="10.2.6"/>
        <vers num="10.2.7"/>
        <vers num="10.2.8"/>
        <vers num="10.3"/>
        <vers num="10.3.1"/>
        <vers num="10.3.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0166" published="2004-03-15" name="CVE-2004-0166" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Unknown vulnerability in Safari web browser for Mac OS X 10.2.8 related to "the display of URLs in the status bar."</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <vuln_types>
      <other/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/194238" source="CERT-VN" patch="1" adv="1">VU#194238</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/14993" source="XF" patch="1" adv="1">macosx-safari-unknown(14993)</ref>
      <ref url="http://secunia.com/advisories/10959" source="SECUNIA">10959</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2004/Feb/msg00000.html" source="APPLE">APPLE-SA-2004-02-23</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.2.8"/>
      </prod>
      <prod vendor="apple" name="mac_os_x_server">
        <vers num="10.2.8"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0167" published="2004-03-15" name="CVE-2004-0167" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">DiskArbitration in Mac OS X 10.2.8 and 10.3.2 does not properly initialize writeable removable media.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <other/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/578886" source="CERT-VN">VU#578886</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15300" source="XF" patch="1" adv="1">macos-diskarbitration-unknown(15300)</ref>
      <ref url="http://www.securityfocus.com/bid/9731" source="BID">9731</ref>
      <ref url="http://www.osvdb.org/6824" source="OSVDB">6824</ref>
      <ref url="http://secunia.com/advisories/10959" source="SECUNIA">10959</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2004/Feb/msg00000.html" source="APPLE">APPLE-SA-2004-02-23</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers prev="1" num="10.2.8"/>
        <vers prev="1" num="10.3.2"/>
      </prod>
      <prod vendor="apple" name="mac_os_x_server">
        <vers prev="1" num="10.2.8"/>
        <vers prev="1" num="10.3.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0168" published="2004-03-15" name="CVE-2004-0168" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Unknown vulnerability in CoreFoundation for Mac OS X 10.3.2, related to "notification logging."</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <vuln_types>
      <other/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/15299" source="XF" patch="1" adv="1">macos-corefoundation-unknown(15299)</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2004/Feb/msg00000.html" source="APPLE">APPLE-SA-2004-02-23</ref>
      <ref url="http://secunia.com/advisories/10959/" source="SECUNIA">10959</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers prev="1" num="10.2.8"/>
        <vers prev="1" num="10.3.2"/>
      </prod>
      <prod vendor="apple" name="mac_os_x_server">
        <vers prev="1" num="10.2.8"/>
        <vers prev="1" num="10.3.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0169" published="2004-03-15" name="CVE-2004-0169" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">QuickTime Streaming Server in MacOS X 10.2.8 and 10.3.2 allows remote attackers to cause a denial of service (crash) via DESCRIBE requests with long User-Agent fields, which causes an Assert error to be triggered in the BufferIsFull function.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <vuln_types>
      <exception/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/460350" source="CERT-VN" adv="1">VU#460350</ref>
      <ref url="http://www.securityfocus.com/bid/9735" source="BID" patch="1" adv="1">9735</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15291" source="XF" adv="1">darwin-describe-request-dos(15291)</ref>
      <ref url="http://www.osvdb.org/6837" source="OSVDB">6837</ref>
      <ref url="http://www.osvdb.org/6826" source="OSVDB">6826</ref>
      <ref url="http://www.idefense.com/application/poi/display?id=75&amp;type=vulnerabilities" source="IDEFENSE">20040223 Darwin Streaming Server Remote Denial of Service Vulnerability</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2004/Feb/msg00000.html" source="APPLE">APPLE-SA-2004-02-23</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="darwin_streaming_server">
        <vers num="4.1.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0171" published="2004-03-15" name="CVE-2004-0171" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">FreeBSD 5.1 and earlier, and Mac OS X before 10.3.4, allows remote attackers to cause a denial of service (resource exhaustion of memory buffers and system crash) via a large number of out-of-sequence TCP packets, which prevents the operating system from creating new connections.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <vuln_types>
      <exception/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/395670" source="CERT-VN">VU#395670</ref>
      <ref url="http://www.securityfocus.com/bid/9792" source="BID" patch="1" adv="1">9792</ref>
      <ref url="http://www.idefense.com/application/poi/display?id=78&amp;type=vulnerabilities" source="IDEFENSE" patch="1" adv="1">20040302 FreeBSD Memory Buffer Exhaustion Denial of Service Vulnerability</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15369" source="XF" adv="1">freebsd-mbuf-dos(15369)</ref>
      <ref url="http://www.osvdb.org/4124" source="OSVDB">4124</ref>
      <ref url="http://lists.seifried.org/pipermail/security/2004-May/003743.html" source="APPLE">APPLE-SA-2004-05-28</ref>
      <ref url="ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-04:04.tcp.asc" source="FREEBSD">FreeBSD-SA-04:04</ref>
    </refs>
    <vuln_soft>
      <prod vendor="freebsd" name="freebsd">
        <vers num="4.6.2"/>
        <vers num="4.7"/>
        <vers num="4.8"/>
        <vers num="4.9"/>
        <vers num="5.0"/>
        <vers num="5.1"/>
        <vers num="5.2"/>
      </prod>
      <prod vendor="openbsd" name="openbsd">
        <vers num="3.3"/>
        <vers num="3.4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0172" published="2004-03-15" name="CVE-2004-0172" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Heap-based buffer overflow in the search_for_command function of ltrace 0.3.10, if it is installed setuid, could allow local users to execute arbitrary code via a long filename.  NOTE: It is unclear whether there are any packages that install ltrace as a setuid program, so this candidate might be REJECTed.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <vuln_types>
      <input bound="1"/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/13389" source="XF" adv="1">ltrace-searchforcommand-bo(13389)</ref>
      <ref url="http://www.securityfocus.com/bid/8790" source="BID" adv="1">8790</ref>
      <ref url="http://securitytracker.com/id?1007896" source="SECTRACK">1007896</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2003-October/011610.html" source="FULLDISC">20031008 ltrace bug</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2003-October/011600.html" source="FULLDISC">20031008 ltrace bug</ref>
    </refs>
    <vuln_soft>
      <prod vendor="juan_cespedes" name="ltrace">
        <vers num="0.3.10"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0173" published="2004-04-15" name="CVE-2004-0173" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in Apache 1.3.29 and earlier, and Apache 2.0.48 and earlier, when running on Cygwin, allows remote attackers to read arbitrary files via a URL containing "..%5C" (dot dot encoded backslash) sequences.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/15293" source="XF" patch="1" adv="1">apache-cygwin-directory-traversal(15293)</ref>
      <ref url="http://www.securityfocus.com/bid/9733" source="BID" patch="1" adv="1">9733</ref>
      <ref url="http://www.apacheweek.com/issues/04-03-12" source="CONFIRM">http://www.apacheweek.com/issues/04-03-12</ref>
      <ref url="http://secunia.com/advisories/10962" source="SECUNIA">10962</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107765545431387&amp;w=2" source="BUGTRAQ">20040224 STG Security Advisory: [SSA-20040217-06] Apache for cygwin</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2004-February/017740.html" source="FULLDISC">20040224 STG Security Advisory: [SSA-20040217-06] Apache for cygwin directory traversal vulnerability</ref>
      <ref url="http://issues.apache.org/bugzilla/show_bug.cgi?id=26152" source="CONFIRM">http://issues.apache.org/bugzilla/show_bug.cgi?id=26152</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apache" name="http_server">
        <vers num="0.8.11"/>
        <vers num="0.8.14"/>
        <vers num="1.0"/>
        <vers num="1.0.2"/>
        <vers num="1.0.3"/>
        <vers num="1.0.5"/>
        <vers num="1.1"/>
        <vers num="1.1.1"/>
        <vers num="1.2"/>
        <vers num="1.2.5"/>
        <vers num="1.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0174" published="2004-05-04" name="CVE-2004-0174" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Apache 1.4.x before 1.3.30, and 2.0.x before 2.0.49, when using multiple listening sockets on certain platforms, allows remote attackers to cause a denial of service (blocked new connections) via a "short-lived connection on a rarely-accessed listening socket."</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <vuln_types>
      <design/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/132110" source="CERT-VN">VU#132110</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15540" source="XF" patch="1" adv="1">apache-socket-starvation-dos(15540)</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-405.html" source="REDHAT" patch="1" adv="1">RHSA-2004:405</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108066914830552&amp;w=2" source="TRUSTIX" patch="1" adv="1">2004-0017</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107973894328806&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20040319 [ANNOUNCE] Apache HTTP Server 2.0.49 Released (fwd)</ref>
      <ref url="http://www.trustix.org/errata/2004/0027" source="TRUSTIX">2004-0027</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200405-22.xml" source="GENTOO">GLSA-200405-22</ref>
      <ref url="http://secunia.com/advisories/11170" source="SECUNIA">11170</ref>
      <ref url="http://www.slackware.com/security/viewer.php?l=slackware-security&amp;y=2004&amp;m=slackware-security.529643" source="SLACKWARE">SSA:2004-133</ref>
      <ref url="http://www.securitytracker.com/alerts/2004/Mar/1009495.html" source="SECTRACK">1009495</ref>
      <ref url="http://www.securityfocus.com/bid/9921" source="BID">9921</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2004:046" source="MANDRAKE">MDKSA-2004:046</ref>
      <ref url="http://www.apache.org/dist/httpd/CHANGES_1.3" source="CONFIRM">http://www.apache.org/dist/httpd/CHANGES_1.3</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-57628-1" source="SUNALERT">57628</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-101555-1" source="SUNALERT">101555</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108731648532365&amp;w=2" source="HP">SSRT4717</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108437852004207&amp;w=2" source="BUGTRAQ">20040512 [OpenPKG-SA-2004.021] OpenPKG Security Advisory (apache)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108369640424244&amp;w=2" source="APPLE">APPLE-SA-2004-05-03</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1982" source="OVAL" sig="1">oval:org.mitre.oval:def:1982</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:100110" source="OVAL" sig="1">oval:org.mitre.oval:def:100110</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apache" name="http_server">
        <vers prev="1" num="2.0.49"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0175" published="2004-08-18" name="CVE-2004-0175" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Directory traversal vulnerability in scp for OpenSSH before 3.4p1 allows remote malicious servers to overwrite arbitrary files.  NOTE: this may be a rediscovery of CVE-2000-0992.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/9986" source="BID" patch="1" adv="1">9986</ref>
      <ref url="https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=120147" source="CONFIRM">https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=120147</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/16323" source="XF">openssh-scp-file-overwrite(16323)</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-567.html" source="REDHAT">RHSA-2005:567</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-562.html" source="REDHAT">RHSA-2005:562</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-495.html" source="REDHAT">RHSA-2005:495</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-481.html" source="REDHAT">RHSA-2005:481</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-165.html" source="REDHAT">RHSA-2005:165</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-106.html" source="REDHAT">RHSA-2005:106</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-074.html" source="REDHAT">RHSA-2005:074</ref>
      <ref url="http://www.osvdb.org/9550" source="OSVDB">9550</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2004_09_kernel.html" source="SUSE">SuSE-SA:2004:009</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2008:191" source="MANDRIVA">MDVSA-2008:191</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:100" source="MANDRIVA">MDKSA-2005:100</ref>
      <ref url="http://www.juniper.net/support/security/alerts/adv59739.txt" source="CONFIRM">http://www.juniper.net/support/security/alerts/adv59739.txt</ref>
      <ref url="http://www.ciac.org/ciac/bulletins/o-212.shtml" source="CIAC">O-212</ref>
      <ref url="http://secunia.com/advisories/19243" source="SECUNIA">19243</ref>
      <ref url="http://secunia.com/advisories/17135" source="SECUNIA">17135</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10184" source="OVAL">oval:org.mitre.oval:def:10184</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000831" source="CONECTIVA">CLSA-2004:831</ref>
      <ref url="ftp://ftp.sco.com/pub/updates/OpenServer/SCOSA-2006.11/SCOSA-2006.11.txt" source="SCO">SCOSA-2006.11</ref>
    </refs>
    <vuln_soft>
      <prod vendor="openbsd" name="openssh">
        <vers num="3.0"/>
        <vers num="3.0.1"/>
        <vers num="3.0.1p1"/>
        <vers num="3.0.2"/>
        <vers num="3.0.2p1"/>
        <vers num="3.0p1"/>
        <vers num="3.1"/>
        <vers num="3.1p1"/>
        <vers num="3.2"/>
        <vers num="3.2.2p1"/>
        <vers num="3.2.3p1"/>
        <vers num="3.3"/>
        <vers num="3.3p1"/>
        <vers num="3.4"/>
        <vers num="3.4p1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0176" published="2004-05-04" name="CVE-2004-0176" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Multiple buffer overflows in Ethereal 0.8.13 to 0.10.2 allow remote attackers to cause a denial of service and possibly execute arbitrary code via the (1) NetFlow, (2) IGAP, (3) EIGRP, (4) PGM, (5) IrDA, (6) BGP, (7) ISUP, or (8) TCAP dissectors.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <vuln_types>
      <design/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/931588" source="CERT-VN">VU#931588</ref>
      <ref url="http://www.kb.cert.org/vuls/id/864884" source="CERT-VN">VU#864884</ref>
      <ref url="http://www.kb.cert.org/vuls/id/740188" source="CERT-VN">VU#740188</ref>
      <ref url="http://www.kb.cert.org/vuls/id/659140" source="CERT-VN">VU#659140</ref>
      <ref url="http://www.kb.cert.org/vuls/id/644886" source="CERT-VN">VU#644886</ref>
      <ref url="http://www.kb.cert.org/vuls/id/591820" source="CERT-VN">VU#591820</ref>
      <ref url="http://www.kb.cert.org/vuls/id/433596" source="CERT-VN">VU#433596</ref>
      <ref url="http://www.kb.cert.org/vuls/id/125156" source="CERT-VN">VU#125156</ref>
      <ref url="http://www.kb.cert.org/vuls/id/119876" source="CERT-VN">VU#119876</ref>
      <ref url="http://www.debian.org/security/2004/dsa-511" source="DEBIAN" patch="1" adv="1">DSA-511</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108058005324316&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20040329 LNSA-#2004-0007: Multiple security problems in Ethereal</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15569" source="XF" adv="1">ethereal-multiple-dissectors-bo(15569)</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-137.html" source="REDHAT">RHSA-2004:137</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-136.html" source="REDHAT">RHSA-2004:136</ref>
      <ref url="http://www.ethereal.com/appnotes/enpa-sa-00013.html" source="CONFIRM">http://www.ethereal.com/appnotes/enpa-sa-00013.html</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200403-07.xml" source="GENTOO">GLSA-200403-07</ref>
      <ref url="http://security.e-matters.de/advisories/032004.html" source="MISC">http://security.e-matters.de/advisories/032004.html</ref>
      <ref url="http://secunia.com/advisories/11185" source="SECUNIA">11185</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10187" source="OVAL">oval:org.mitre.oval:def:10187</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108007072215742&amp;w=2" source="BUGTRAQ" adv="1">20040323 Advisory 03/2004: Multiple (13) Ethereal remote overflows</ref>
      <ref url="http://www.osvdb.org/6893" source="OSVDB">6893</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2004:024" source="MANDRAKE">MDKSA-2004:024</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108213710306260&amp;w=2" source="BUGTRAQ">20040416 [OpenPKG-SA-2004.015] OpenPKG Security Advisory (ethereal)</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000835" source="CONECTIVA">CLA-2004:835</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:887" source="OVAL" sig="1">oval:org.mitre.oval:def:887</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:878" source="OVAL" sig="1">oval:org.mitre.oval:def:878</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ethereal_group" name="ethereal">
        <vers num="0.10"/>
        <vers num="0.10.1"/>
        <vers num="0.10.2"/>
        <vers num="0.8.13"/>
        <vers num="0.8.14"/>
        <vers num="0.8.18"/>
        <vers num="0.8.19"/>
        <vers num="0.9"/>
        <vers num="0.9.1"/>
        <vers num="0.9.10"/>
        <vers num="0.9.11"/>
        <vers num="0.9.12"/>
        <vers num="0.9.13"/>
        <vers num="0.9.14"/>
        <vers num="0.9.15"/>
        <vers num="0.9.16"/>
        <vers num="0.9.2"/>
        <vers num="0.9.3"/>
        <vers num="0.9.4"/>
        <vers num="0.9.5"/>
        <vers num="0.9.6"/>
        <vers num="0.9.7"/>
        <vers num="0.9.8"/>
        <vers num="0.9.9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0177" published="2004-06-01" name="CVE-2004-0177" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The ext3 code in Linux 2.4.x before 2.4.26 does not properly initialize journal descriptor blocks, which causes an information leak in which in-memory data is written to the device for the ext3 file system, which allows privileged users to obtain portions of kernel memory by reading the raw device.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <vuln_types>
      <design/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.linuxsecurity.com/advisories/engarde_advisory-4285.html" source="ENGARDE" patch="1" adv="1">ESA-20040428-004</ref>
      <ref url="http://www.debian.org/security/2004/dsa-495" source="DEBIAN" patch="1" adv="1">DSA-495</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2004-166.html" source="REDHAT" patch="1" adv="1">RHSA-2004:166</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108213675028441&amp;w=2" source="TRUSTIX" patch="1" adv="1">2004-0020</ref>
      <ref url="https://bugzilla.fedora.us/show_bug.cgi?id=2336" source="FEDORA">FLSA:2336</ref>
      <ref url="http://www.debian.org/security/2004/dsa-491" source="DEBIAN">DSA-491</ref>
      <ref url="http://www.debian.org/security/2004/dsa-489" source="DEBIAN">DSA-489</ref>
      <ref url="http://www.debian.org/security/2004/dsa-482" source="DEBIAN">DSA-482</ref>
      <ref url="http://www.debian.org/security/2004/dsa-481" source="DEBIAN">DSA-481</ref>
      <ref url="http://www.debian.org/security/2004/dsa-480" source="DEBIAN">DSA-480</ref>
      <ref url="http://www.debian.org/security/2004/dsa-479" source="DEBIAN">DSA-479</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200407-02.xml" source="GENTOO">GLSA-200407-02</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10556" source="OVAL">oval:org.mitre.oval:def:10556</ref>
      <ref url="http://linux.bkbits.net:8080/linux-2.4/cset@4056b368s6vpJbGWxDD_LhQNYQrdzQ" source="MISC">http://linux.bkbits.net:8080/linux-2.4/cset@4056b368s6vpJbGWxDD_LhQNYQrdzQ</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15867" source="XF">linux-ext3-info-disclosure(15867)</ref>
      <ref url="http://www.securityfocus.com/bid/10152" source="BID">10152</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-293.html" source="REDHAT">RHSA-2005:293</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-505.html" source="REDHAT">RHSA-2004:505</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-504.html" source="REDHAT">RHSA-2004:504</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2004:029" source="MANDRAKE">MDKSA-2004:029</ref>
      <ref url="http://www.ciac.org/ciac/bulletins/o-127.shtml" source="CIAC">O-127</ref>
      <ref url="http://www.ciac.org/ciac/bulletins/o-126.shtml" source="CIAC">O-126</ref>
      <ref url="http://www.ciac.org/ciac/bulletins/o-121.shtml" source="CIAC">O-121</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000846" source="CONECTIVA">CLA-2004:846</ref>
    </refs>
    <vuln_soft>
      <prod vendor="linux" name="linux_kernel">
        <vers num="2.4.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2004-0178" published="2004-06-01" name="CVE-2004-0178" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">The OSS code for the Sound Blaster (sb16) driver in Linux 2.4.x before 2.4.26, when operating in 16 bit mode, does not properly handle certain sample sizes, which allows local users to cause a denial of service (crash) via a sample with an odd number of bytes.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <vuln_types>
      <design/>
      <config/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://www.debian.org/security/2004/dsa-495" source="DEBIAN" patch="1" adv="1">DSA-495</ref>
      <ref url="http://www.debian.org/security/2004/dsa-491" source="DEBIAN" patch="1" adv="1">DSA-491</ref>
      <ref url="http://www.debian.org/security/2004/dsa-489" source="DEBIAN" patch="1" adv="1">DSA-489</ref>
      <ref url="http://www.debian.org/security/2004/dsa-482" source="DEBIAN" patch="1" adv="1">DSA-482</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-437.html" source="REDHAT">RHSA-2004:437</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-413.html" source="REDHAT">RHSA-2004:413</ref>
      <ref url="http://www.debian.org/security/2004/dsa-481" source="DEBIAN">DSA-481</ref>
      <ref url="http://www.debian.org/security/2004/dsa-480" source="DEBIAN">DSA-480</ref>
      <ref url="http://www.debian.org/security/2004/dsa-479" source="DEBIAN">DSA-479</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200407-02.xml" source="GENTOO">GLSA-200407-02</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9427" source="OVAL">oval:org.mitre.oval:def:9427</ref>
      <ref url="http://linux.bkbits.net:8080/linux-2.4/cset@404ce5967rY2Ryu6Z_uNbYh643wuFA" source="MISC">http://linux.bkbits.net:8080/linux-2.4/cset@404ce5967rY2Ryu6Z_uNbYh643wuFA</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/20040804-01-U.asc" source="SGI">20040804-01-U</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15868" source="XF">linux-sound-blaster-dos(15868)</ref>
      <ref url="http://www.securityfocus.com/bid/9985" source="BID">9985</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2004:029" source="MANDRAKE">MDKSA-2004:029</ref>
      <ref url="http://www.ciac.org/ciac/bulletins/o-193.shtml" source="CIAC">O-193</ref>
      <ref url="http://www.ciac.org/ciac/bulletins/o-127.shtml" source="CIAC">O-127</ref>
      <ref url="http://www.ciac.org/ciac/bulletins/o-121.shtml" source="CIAC">O-121</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000846" source="CONECTIVA">CLA-2004:846</ref>
    </refs>
    <vuln_soft>
      <prod vendor="linux" name="linux_kernel">
        <vers num="2.4.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0179" published="2004-06-01" name="CVE-2004-0179" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_score="5.1" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="4.9" CVSS_base_score="5.1">
    <desc>
      <descript source="cve">Multiple format string vulnerabilities in (1) neon 0.24.4 and earlier, and other products that use neon including (2) Cadaver, (3) Subversion, and (4) OpenOffice, allow remote malicious WebDAV servers to execute arbitrary code.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input/>
      <exception/>
    </vuln_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="https://bugzilla.fedora.us/show_bug.cgi?id=1552" source="FEDORA" patch="1">FEDORA-2004-1552</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-160.html" source="REDHAT" patch="1">RHSA-2004:160</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-159.html" source="REDHAT" patch="1">RHSA-2004:159</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-158.html" source="REDHAT" patch="1">RHSA-2004:158</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-157.html" source="REDHAT" patch="1" adv="1">RHSA-2004:157</ref>
      <ref url="http://www.debian.org/security/2004/dsa-487" source="DEBIAN" patch="1" adv="1">DSA-487</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200405-04.xml" source="GENTOO" patch="1" adv="1">GLSA-200405-04</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200405-01.xml" source="GENTOO" patch="1" adv="1">GLSA-200405-01</ref>
      <ref url="http://secunia.com/advisories/11363" source="SECUNIA" patch="1" adv="1">11363</ref>
      <ref url="http://lists.suse.com/archive/suse-security-announce/2004-Apr/0003.html" source="SUSE" patch="1" adv="1">SuSE-SA:2004:008</ref>
      <ref url="http://lists.suse.com/archive/suse-security-announce/2004-Apr/0002.html" source="SUSE" patch="1" adv="1">SuSE-SA:2004:009</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/20040404-01-U.asc" source="SGI" patch="1" adv="1">20040404-01-U</ref>
      <ref url="http://www.securityfocus.com/bid/10136" source="BID">10136</ref>
      <ref url="http://www.osvdb.org/5365" source="OSVDB">5365</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2004:032" source="MANDRAKE" adv="1">MDKSA-2004:032</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10913" source="OVAL">oval:org.mitre.oval:def:10913</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108214147022626&amp;w=2" source="BUGTRAQ">20040416 void.at - neon format string bugs</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108213873203477&amp;w=2" source="BUGTRAQ">20040416 [OpenPKG-SA-2004.016] OpenPKG Security Advisory (neon)</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1065" source="OVAL" sig="1">oval:org.mitre.oval:def:1065</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cadaver" name="cadaver_webdav_client">
        <vers num="0.20.0"/>
        <vers num="0.20.1"/>
        <vers num="0.20.2"/>
        <vers num="0.20.3"/>
        <vers num="0.20.4"/>
        <vers num="0.20.5"/>
        <vers num="0.21.0"/>
        <vers num="0.22.0"/>
        <vers num="0.22.1"/>
      </prod>
      <prod vendor="neon" name="neon_client_library">
        <vers num="0.19.3"/>
        <vers num="0.23"/>
        <vers num="0.23.1"/>
        <vers num="0.23.2"/>
        <vers num="0.23.3"/>
        <vers num="0.23.4"/>
        <vers num="0.23.5"/>
        <vers num="0.23.6"/>
        <vers num="0.23.7"/>
        <vers num="0.23.8"/>
        <vers num="0.24"/>
        <vers num="0.24.1"/>
        <vers num="0.24.2"/>
        <vers num="0.24.3"/>
        <vers num="0.24.4"/>
      </prod>
      <prod vendor="openoffice" name="openoffice">
        <vers num="1.1.2"/>
      </prod>
      <prod vendor="subversion" name="subversion">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2004-0180" published="2004-06-01" name="CVE-2004-0180" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:P/A:N)" CVSS_score="2.6" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="4.9" CVSS_base_score="2.6">
    <desc>
      <descript source="cve">The client for CVS before 1.11 allows a remote malicious CVS server to create arbitrary files using certain RCS diff files that use absolute pathnames during checkouts or updates, a different vulnerability than CVE-2004-0405.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <vuln_types>
      <design/>
    </vuln_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-154.html" source="REDHAT" patch="1" adv="1">RHSA-2004:154</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-153.html" source="REDHAT" patch="1" adv="1">RHSA-2004:153</ref>
      <ref url="http://www.debian.org/security/2004/dsa-486" source="DEBIAN" patch="1" adv="1">DSA-486</ref>
      <ref url="ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-04:07.cvs.asc" source="FREEBSD" patch="1" adv="1">FreeBSD-SA-04:07</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9462" source="OVAL">oval:org.mitre.oval:def:9462</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/20040404-01-U.asc" source="SGI">20040404-01-U</ref>
      <ref url="ftp://ftp.openbsd.org/pub/OpenBSD/patches/3.5/common/002_cvs.patch" source="CONFIRM">ftp://ftp.openbsd.org/pub/OpenBSD/patches/3.5/common/002_cvs.patch</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15864" source="XF">cvs-rcs-create-files(15864)</ref>
      <ref url="http://www.slackware.com/security/viewer.php?l=slackware-security&amp;y=2004&amp;m=slackware-security.400181" source="SLACKWARE">SSA:2004-108-02</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2004:028" source="MANDRAKE">MDKSA-2004:028</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200404-13.xml" source="GENTOO">GLSA-200404-13</ref>
      <ref url="http://secunia.com/advisories/11548" source="SECUNIA">11548</ref>
      <ref url="http://secunia.com/advisories/11405" source="SECUNIA">11405</ref>
      <ref url="http://secunia.com/advisories/11400" source="SECUNIA">11400</ref>
      <ref url="http://secunia.com/advisories/11391" source="SECUNIA">11391</ref>
      <ref url="http://secunia.com/advisories/11380" source="SECUNIA">11380</ref>
      <ref url="http://secunia.com/advisories/11377" source="SECUNIA">11377</ref>
      <ref url="http://secunia.com/advisories/11375" source="SECUNIA">11375</ref>
      <ref url="http://secunia.com/advisories/11374" source="SECUNIA">11374</ref>
      <ref url="http://secunia.com/advisories/11371" source="SECUNIA">11371</ref>
      <ref url="http://secunia.com/advisories/11368" source="SECUNIA">11368</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108636445031613&amp;w=2" source="FEDORA">FEDORA-2004-1620</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1042" source="OVAL" sig="1">oval:org.mitre.oval:def:1042</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cvs" name="cvs">
        <vers prev="1" num="1.10"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2004-0181" published="2004-06-01" name="CVE-2004-0181" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">The JFS file system code in Linux 2.4.x has an information leak in which in-memory data is written to the device for the JFS file system, which allows local users to obtain sensitive information by reading the raw device.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <vuln_types>
      <design/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://www.linuxsecurity.com/advisories/engarde_advisory-4285.html" source="ENGARDE" patch="1" adv="1">ESA-20040428-004</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108213675028441&amp;w=2" source="TRUSTIX" patch="1" adv="1">2004-0020</ref>
      <ref url="http://www.vupen.com/english/advisories/2005/1878" source="VUPEN">ADV-2005-1878</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200407-02.xml" source="GENTOO">GLSA-200407-02</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10329" source="OVAL">oval:org.mitre.oval:def:10329</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15902" source="XF">linux-jfs-info-disclosure(15902)</ref>
      <ref url="http://www.turbolinux.com/security/2004/TLSA-2004-14.txt" source="TURBO">TLSA-2004-14</ref>
      <ref url="http://www.securityfocus.com/bid/10143" source="BID">10143</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-663.html" source="REDHAT">RHSA-2005:663</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-504.html" source="REDHAT">RHSA-2004:504</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2004:029" source="MANDRAKE">MDKSA-2004:029</ref>
      <ref url="http://secunia.com/advisories/17002" source="SECUNIA">17002</ref>
    </refs>
    <vuln_soft>
      <prod vendor="linux" name="linux_kernel">
        <vers num="2.4.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0182" published="2004-06-01" name="CVE-2004-0182" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Mailman before 2.0.13 allows remote attackers to cause a denial of service (crash) via an email message with an empty subject field.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <vuln_types>
      <exception/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-156.html" source="REDHAT" patch="1" adv="1">RHSA-2004:156</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/20040404-01-U.asc" source="SGI" patch="1" adv="1">20040404-01-U</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gnu" name="mailman">
        <vers prev="1" num="2.0.12"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0183" published="2004-05-04" name="CVE-2004-0183" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">TCPDUMP 3.8.1 and earlier allows remote attackers to cause a denial of service (crash) via ISAKMP packets containing a Delete payload with a large number of SPI's, which causes an out-of-bounds read, as demonstrated by the Striker ISAKMP Protocol Test Suite.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <vuln_types>
      <input bound="1"/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/240790" source="CERT-VN">VU#240790</ref>
      <ref url="http://www.debian.org/security/2004/dsa-478" source="DEBIAN" patch="1" adv="1">DSA-478</ref>
      <ref url="https://bugzilla.fedora.us/show_bug.cgi?id=1468" source="FEDORA">FEDORA-2004-1468</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15680" source="XF">tcpdump-isakmp-delete-bo(15680)</ref>
      <ref url="http://www.tcpdump.org/tcpdump-changes.txt" source="CONFIRM">http://www.tcpdump.org/tcpdump-changes.txt</ref>
      <ref url="http://www.securityfocus.com/bid/10003" source="BID">10003</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-219.html" source="REDHAT">RHSA-2004:219</ref>
      <ref url="http://www.rapid7.com/advisories/R7-0017.html" source="MISC">http://www.rapid7.com/advisories/R7-0017.html</ref>
      <ref url="http://securitytracker.com/id?1009593" source="SECTRACK">1009593</ref>
      <ref url="http://secunia.com/advisories/11258" source="SECUNIA">11258</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9971" source="OVAL">oval:org.mitre.oval:def:9971</ref>
      <ref url="http://www.trustix.org/errata/2004/0015" source="TRUSTIX">2004-0015</ref>
      <ref url="http://secunia.com/advisories/11320" source="SECUNIA">11320</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108067265931525&amp;w=2" source="BUGTRAQ">20040330 R7-0017: TCPDUMP ISAKMP payload handling denial-of-service vulnerabilities</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:972" source="OVAL" sig="1">oval:org.mitre.oval:def:972</ref>
    </refs>
    <vuln_soft>
      <prod vendor="lbl" name="tcpdump">
        <vers prev="1" num="3.8.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0184" published="2004-05-04" name="CVE-2004-0184" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Integer underflow in the isakmp_id_print for TCPDUMP 3.8.1 and earlier allows remote attackers to cause a denial of service (crash) via an ISAKMP packet with an Identification payload with a length that becomes less than 8 during byte order conversion, which causes an out-of-bounds read, as demonstrated by the Striker ISAKMP Protocol Test Suite.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <vuln_types>
      <input bound="1"/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/492558" source="CERT-VN">VU#492558</ref>
      <ref url="http://www.debian.org/security/2004/dsa-478" source="DEBIAN" patch="1" adv="1">DSA-478</ref>
      <ref url="https://bugzilla.fedora.us/show_bug.cgi?id=1468" source="FEDORA">FEDORA-2004-1468</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15679" source="XF">tcpdump-isakmp-integer-underflow(15679)</ref>
      <ref url="http://www.tcpdump.org/tcpdump-changes.txt" source="CONFIRM">http://www.tcpdump.org/tcpdump-changes.txt</ref>
      <ref url="http://www.securityfocus.com/bid/10004" source="BID">10004</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-219.html" source="REDHAT">RHSA-2004:219</ref>
      <ref url="http://www.rapid7.com/advisories/R7-0017.html" source="MISC" adv="1">http://www.rapid7.com/advisories/R7-0017.html</ref>
      <ref url="http://securitytracker.com/id?1009593" source="SECTRACK">1009593</ref>
      <ref url="http://secunia.com/advisories/11258" source="SECUNIA">11258</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9581" source="OVAL">oval:org.mitre.oval:def:9581</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108067265931525&amp;w=2" source="BUGTRAQ">20040330 R7-0017: TCPDUMP ISAKMP payload handling denial-of-service vulnerabilities</ref>
      <ref url="http://www.trustix.org/errata/2004/0015" source="TRUSTIX">2004-0015</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:976" source="OVAL" sig="1">oval:org.mitre.oval:def:976</ref>
    </refs>
    <vuln_soft>
      <prod vendor="lbl" name="tcpdump">
        <vers prev="1" num="3.8.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0185" published="2004-03-15" name="CVE-2004-0185" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Buffer overflow in the skey_challenge function in ftpd.c for wu-ftp daemon (wu-ftpd) 2.6.2 allows remote attackers to cause a denial of service and possibly execute arbitrary code via a s/key (SKEY) request with a long name.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <vuln_types>
      <input buffer="1"/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securiteam.com/unixfocus/6X00Q1P8KC.html" source="MISC" patch="1" adv="1">http://www.securiteam.com/unixfocus/6X00Q1P8KC.html</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-096.html" source="REDHAT" patch="1" adv="1">RHSA-2004:096</ref>
      <ref url="http://www.debian.org/security/2004/dsa-457" source="DEBIAN" patch="1" adv="1">DSA-457</ref>
      <ref url="ftp://ftp.wu-ftpd.org/pub/wu-ftpd/patches/apply_to_2.6.2/skeychallenge.patch" source="CONFIRM" patch="1">ftp://ftp.wu-ftpd.org/pub/wu-ftpd/patches/apply_to_2.6.2/skeychallenge.patch</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/13518" source="XF" adv="1">wuftpd-skey-bo(13518)</ref>
      <ref url="http://unixpunx.org/txt/exploits_archive/packetstorm/0310-advisories/wuftpd-skey.txt" source="MISC">http://unixpunx.org/txt/exploits_archive/packetstorm/0310-advisories/wuftpd-skey.txt</ref>
      <ref url="http://www.securityfocus.com/bid/8893" source="BID">8893</ref>
    </refs>
    <vuln_soft>
      <prod vendor="washington_university" name="wu-ftpd">
        <vers num="2.6.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0186" published="2004-03-15" name="CVE-2004-0186" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">smbmnt in Samba 2.x and 3.x on Linux 2.6, when installed setuid, allows local users to gain root privileges by mounting a Samba share that contains a setuid root program, whose setuid attributes are not cleared when the share is mounted.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <vuln_types>
      <access/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/15131" source="XF" patch="1" adv="1">samba-smbmnt-gain-privileges(15131)</ref>
      <ref url="http://www.securityfocus.com/bid/9619" source="BID" patch="1" adv="1">9619</ref>
      <ref url="http://www.debian.org/security/2004/dsa-463" source="DEBIAN" patch="1" adv="1">DSA-463</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107636290906296&amp;w=2" source="BUGTRAQ">20040209 Samba 3.x + kernel 2.6.x local root vulnerability</ref>
      <ref url="http://www.osvdb.org/3916" source="OSVDB">3916</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107657505718743&amp;w=2" source="BUGTRAQ">20040211 Re: Samba 3.x + kernel 2.6.x local root vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="samba" name="samba">
        <vers num="2.0"/>
        <vers num="3.0.0"/>
      </prod>
      <prod vendor="linux" name="linux_kernel">
        <vers num="2.6.0" edition="test1"/>
        <vers num="2.6.0" edition="test10"/>
        <vers num="2.6.0" edition="test11"/>
        <vers num="2.6.0" edition="test2"/>
        <vers num="2.6.0" edition="test3"/>
        <vers num="2.6.0" edition="test4"/>
        <vers num="2.6.0" edition="test5"/>
        <vers num="2.6.0" edition="test6"/>
        <vers num="2.6.0" edition="test7"/>
        <vers num="2.6.0" edition="test8"/>
        <vers num="2.6.0" edition="test9"/>
        <vers num="2.6.1" edition="rc1"/>
        <vers num="2.6.1" edition="rc2"/>
        <vers num="2.6_test9_cvs"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" seq="2004-0187" reject="1" published="2004-03-15" name="CVE-2004-0187" modified="2008-09-10">
    <desc>
      <descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: CVE-2004-0185.  Reason: This candidate is a reservation duplicate of CVE-2004-0185.  Notes: All CVE users should reference CVE-2004-0185 instead of this candidate.  All references and descriptions in this candidate have been removed to prevent accidental usage.</descript>
    </desc>
    <refs/>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0188" published="2004-03-15" name="CVE-2004-0188" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Heap-based buffer overflow in Calife 2.8.5 and earlier may allow local users to execute arbitrary code via a long password.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <vuln_types>
      <input bound="1"/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/9756" source="BID" patch="1" adv="1">9756</ref>
      <ref url="http://www.debian.org/security/2004/dsa-461" source="DEBIAN" patch="1" adv="1">DSA-461</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15335" source="XF" adv="1">calife-long-password-bo(15335)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107789737832092&amp;w=2" source="BUGTRAQ" adv="1">20040227 Calife heap corrupt / potential local root exploit</ref>
      <ref url="http://www.securityfocus.com/bid/9776" source="BID">9776</ref>
    </refs>
    <vuln_soft>
      <prod vendor="calife" name="calife">
        <vers num="2.8.4_c"/>
        <vers num="2.8.5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0189" published="2004-03-15" name="CVE-2004-0189" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">The "%xx" URL decoding function in Squid 2.5STABLE4 and earlier allows remote attackers to bypass url_regex ACLs via a URL with a NULL ("%00") characterm, which causes Squid to use only a portion of the requested URL when comparing it against the access control lists.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.squid-cache.org/Advisories/SQUID-2004_1.txt" source="CONFIRM" patch="1" adv="1">http://www.squid-cache.org/Advisories/SQUID-2004_1.txt</ref>
      <ref url="http://www.securityfocus.com/bid/9778" source="BID" patch="1" adv="1">9778</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15366" source="XF" adv="1">squid-urlregex-acl-bypass(15366)</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-134.html" source="REDHAT">RHSA-2004:134</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-133.html" source="REDHAT">RHSA-2004:133</ref>
      <ref url="http://www.osvdb.org/5916" source="OSVDB">5916</ref>
      <ref url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2004:025" source="MANDRAKE">MDKSA-2004:025</ref>
      <ref url="http://www.debian.org/security/2004/dsa-474" source="DEBIAN">DSA-474</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200403-11.xml" source="GENTOO">GLSA-200403-11</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108084935904110&amp;w=2" source="BUGTRAQ">20040401 [OpenPKG-SA-2004.008] OpenPKG Security  Advisory (squid)</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000838" source="CONECTIVA">CLA-2004:838</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/20040404-01-U.asc" source="SGI">20040404-01-U</ref>
      <ref url="ftp://ftp.sco.com/pub/updates/UnixWare/SCOSA-2005.16/SCOSA-2005.16.txt" source="SCO">SCOSA-2005.16</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:941" source="OVAL" sig="1">oval:org.mitre.oval:def:941</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:877" source="OVAL" sig="1">oval:org.mitre.oval:def:877</ref>
    </refs>
    <vuln_soft>
      <prod vendor="squid" name="squid">
        <vers num="2.0_patch2"/>
        <vers num="2.1_patch2"/>
        <vers num="2.3_stable5"/>
        <vers num="2.4"/>
        <vers num="2.4_stable7"/>
        <vers num="2.5_stable3"/>
        <vers num="2.5_stable4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0190" published="2004-03-15" name="CVE-2004-0190" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Symantec FireWall/VPN Appliance model 200 records a cleartext password for the password administration page, which may be cached on the administrator's local system or in a proxy, which allows attackers to steal the password and gain privileges.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <design/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/9784" source="BID" patch="1" adv="1">9784</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15212" source="XF" adv="1">symantec-firewallvpn-password-plaintext(15212)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107694794031839&amp;w=2" source="BUGTRAQ" adv="1">20040216 Symantec FireWall/VPN Appliance model 200 leak of security</ref>
      <ref url="http://www.osvdb.org/4117" source="OSVDB">4117</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2004-February/017414.html" source="FULLDISC">20040216 Symantec FireWall/VPN Appliance model 200 leak of security</ref>
    </refs>
    <vuln_soft>
      <prod vendor="symantec" name="firewall_vpn_appliance_100">
        <vers num=""/>
      </prod>
      <prod vendor="symantec" name="firewall_vpn_appliance_200">
        <vers num=""/>
      </prod>
      <prod vendor="symantec" name="firewall_vpn_appliance_200r">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0191" published="2004-03-15" name="CVE-2004-0191" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Mozilla before 1.4.2 executes Javascript events in the context of a new page while it is being loaded, allowing it to interact with the previous page (zombie document) and enable cross-domain and cross-site scripting (XSS) attacks, as demonstrated using onmousemove events.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <design/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/15322" source="XF" adv="1">mozilla-event-handler-xss(15322)</ref>
      <ref url="http://www.securityfocus.com/bid/9747" source="BID" adv="1">9747</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107774710729469&amp;w=2" source="BUGTRAQ" adv="1">20040225 Sandblad #13: Cross-domain exploit on zombie document with event handlers</ref>
      <ref url="http://bugzilla.mozilla.org/show_bug.cgi?id=227417" source="CONFIRM" adv="1">http://bugzilla.mozilla.org/show_bug.cgi?id=227417</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-112.html" source="REDHAT">RHSA-2004:112</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-110.html" source="REDHAT">RHSA-2004:110</ref>
      <ref url="http://www.osvdb.org/4062" source="OSVDB">4062</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108448379429944&amp;w=2" source="HP">SSRT4722</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:937" source="OVAL" sig="1">oval:org.mitre.oval:def:937</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:874" source="OVAL" sig="1">oval:org.mitre.oval:def:874</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="mozilla">
        <vers num="0.8"/>
        <vers num="0.9.2"/>
        <vers num="0.9.2.1"/>
        <vers num="0.9.3"/>
        <vers num="0.9.35"/>
        <vers num="0.9.4"/>
        <vers num="0.9.4.1"/>
        <vers num="0.9.48"/>
        <vers num="0.9.5"/>
        <vers num="0.9.6"/>
        <vers num="0.9.7"/>
        <vers num="0.9.8"/>
        <vers num="0.9.9"/>
        <vers num="1.0" edition="rc1"/>
        <vers num="1.0" edition="rc2"/>
        <vers num="1.0.1"/>
        <vers num="1.0.2"/>
        <vers num="1.1" edition="alpha"/>
        <vers num="1.1" edition="beta"/>
        <vers num="1.2" edition="alpha"/>
        <vers num="1.2" edition="beta"/>
        <vers num="1.2.1"/>
        <vers num="1.3"/>
        <vers num="1.3.1"/>
        <vers num="1.4" edition="alpha"/>
        <vers num="1.4" edition="beta"/>
        <vers num="1.4.1"/>
        <vers num="1.5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0192" published="2004-03-15" name="CVE-2004-0192" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in the Management Service for Symantec Gateway Security 2.0 allows remote attackers to steal cookies and hijack a management session via a /sgmi URL that contains malicious script, which is not quoted in the resulting error page.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/9755" source="BID" patch="1" adv="1">9755</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107790684732458&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20040227 Symantec Gateway Security Management Service Cross Site Scripting</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15330" source="XF" adv="1">symantecgateway-error-xss(15330)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="symantec" name="gateway_security_5400">
        <vers num="2.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0193" published="2004-03-15" name="CVE-2004-0193" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Heap-based buffer overflow in the ISS Protocol Analysis Module (PAM), as used in certain versions of RealSecure Network 7.0 and Server Sensor 7.0, Proventia A, G, and M Series, RealSecure Desktop 7.0 and 3.6, RealSecure Guard 3.6, RealSecure Sentry 3.6, BlackICE PC Protection 3.6, and BlackICE Server Protection 3.6, allows remote attackers to execute arbitrary code via an SMB packet containing an authentication request with a long username.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input buffer="1"/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/150326" source="CERT-VN" patch="1" adv="1">VU#150326</ref>
      <ref url="http://xforce.iss.net/xforce/alerts/id/165" source="ISS" patch="1" adv="1">20040226 Vulnerability in SMB Parsing in ISS Products</ref>
      <ref url="http://www.eeye.com/html/Research/Upcoming/20040213.html" source="MISC" adv="1">http://www.eeye.com/html/Research/Upcoming/20040213.html</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15207" source="XF">pam-smb-protocol-bo(15207)</ref>
      <ref url="http://www.securityfocus.com/bid/9752" source="BID">9752</ref>
      <ref url="http://www.osvdb.org/4072" source="OSVDB">4072</ref>
      <ref url="http://www.eeye.com/html/Research/Advisories/AD20040226.html" source="EEYE">AD20040226</ref>
      <ref url="http://secunia.com/advisories/10988" source="SECUNIA">10988</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107789851117176&amp;w=2" source="BUGTRAQ">20040227 EEYE: RealSecure/BlackICE Server Message Block (SMB) Processing Overflow</ref>
    </refs>
    <vuln_soft>
      <prod vendor="iss" name="blackice_agent_server">
        <vers num="3.6eca"/>
      </prod>
      <prod vendor="iss" name="blackice_pc_protection">
        <vers num="3.6cbd"/>
      </prod>
      <prod vendor="iss" name="blackice_server_protection">
        <vers num="3.6cbz"/>
      </prod>
      <prod vendor="iss" name="realsecure_desktop">
        <vers num="3.6eca"/>
        <vers num="3.6ecf"/>
        <vers num="7.0ebg"/>
        <vers num="7.0epk"/>
      </prod>
      <prod vendor="iss" name="realsecure_guard">
        <vers num="3.6ecb"/>
      </prod>
      <prod vendor="iss" name="realsecure_network">
        <vers num="7.0" edition="xpu_20.15"/>
      </prod>
      <prod vendor="iss" name="realsecure_sentry">
        <vers num="3.6ecf"/>
      </prod>
      <prod vendor="iss" name="realsecure_server_sensor">
        <vers num="7.0" edition="xpu20.16"/>
      </prod>
      <prod vendor="iss" name="proventia_a_series_xpu">
        <vers num="20.15"/>
      </prod>
      <prod vendor="iss" name="proventia_g_series_xpu">
        <vers num="22.3"/>
      </prod>
      <prod vendor="iss" name="proventia_m_series_xpu">
        <vers num="1.30"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0194" published="2004-03-29" name="CVE-2004-0194" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Stack-based buffer overflow in the OutputDebugString function for Adobe Acrobat Reader 5.1 allows remote attackers to execute arbitrary code via a PDF document with XML Forms Data Format (XFDF) data.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input buffer="1"/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/9802" source="BID" patch="1" adv="1">9802</ref>
      <ref url="http://www.nextgenss.com/advisories/adobexfdf.txt" source="MISC" patch="1" adv="1">http://www.nextgenss.com/advisories/adobexfdf.txt</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15384" source="XF" adv="1">acrobatreader-xfdf-bo(15384)</ref>
      <ref url="http://www.osvdb.org/4135" source="OSVDB">4135</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107842545022724&amp;w=2" source="BUGTRAQ">20040303 Abobe Reader 5.1 XFDF Buffer Overflow Vulnerability</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2004-March/018227.html" source="FULLDISC">20040303 Adobe Acrobat Reader XML Forms Data Format Buffer Overflow</ref>
    </refs>
    <vuln_soft>
      <prod vendor="adobe" name="acrobat_reader">
        <vers num="5.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0197" published="2004-06-01" name="CVE-2004-0197" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in Microsoft Jet Database Engine 4.0 allows remote attackers to execute arbitrary code via a specially-crafted database query.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input buffer="1"/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/740716" source="CERT-VN">VU#740716</ref>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA04-104A.html" source="CERT">TA04-104A</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15703" source="XF">msjet-query-execute-code(15703)</ref>
      <ref url="http://www.securityfocus.com/bid/10112" source="BID">10112</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms04-014.asp" source="MS">MS04-014</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:968" source="OVAL" sig="1">oval:org.mitre.oval:def:968</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="jet">
        <vers num="4.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0199" published="2004-06-14" name="CVE-2004-0199" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_score="5.1" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="4.9" CVSS_base_score="5.1">
    <desc>
      <descript source="cve">Help and Support Center in Microsoft Windows XP and Windows Server 2003 SP1 does not properly validate HCP URLs, which allows remote attackers to execute arbitrary code, as demonstrated using certain hcp:// URLs that access the DVD Upgrade capability (dvdupgrd.htm).</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <design/>
    </vuln_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/484814" source="CERT-VN" patch="1" adv="1">VU#484814</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/16095" source="XF" patch="1" adv="1">win-hcp-code-execution(16095)</ref>
      <ref url="http://www.securityfocus.com/bid/10321" source="BID" patch="1" adv="1">10321</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/MS04-015.mspx" source="MS" patch="1" adv="1">MS04-015</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108437759930820&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20040512 MS04-015 - Windows Help Center - Dvdupgrade</ref>
      <ref url="http://www.exploitlabs.com/files/advisories/EXPL-A-2004-001-helpctr.txt" source="MISC">http://www.exploitlabs.com/files/advisories/EXPL-A-2004-001-helpctr.txt</ref>
      <ref url="http://marc.theaimsgroup.com/?l=full-disclosure&amp;m=108430407801825&amp;w=2" source="FULLDISC">20040512 MS04-015 - Windows Help Center - Dvdupgrade</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1032" source="OVAL" sig="1">oval:org.mitre.oval:def:1032</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1008" source="OVAL" sig="1">oval:org.mitre.oval:def:1008</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_2003_server">
        <vers num="enterprise" edition=""/>
        <vers num="enterprise" edition=":64-bit"/>
        <vers num="enterprise_64-bit"/>
        <vers num="r2" edition=""/>
        <vers num="r2" edition=":64-bit"/>
        <vers num="r2" edition=":datacenter_64-bit"/>
        <vers num="standard" edition=""/>
        <vers num="standard" edition=":64-bit"/>
        <vers num="web"/>
      </prod>
      <prod vendor="microsoft" name="windows_xp">
        <vers num="" edition=":home"/>
        <vers num="" edition=":64-bit"/>
        <vers num="" edition="gold"/>
        <vers num="" edition="gold:professional"/>
        <vers num="" edition="sp1"/>
        <vers num="" edition="sp1:64-bit"/>
        <vers num="" edition="sp1:home"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0200" published="2004-09-28" name="CVE-2004-0200" modified="2008-09-10" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Buffer overflow in the JPEG (JPG) parsing engine in the Microsoft Graphic Device Interface Plus (GDI+) component, GDIPlus.dll, allows remote attackers to execute arbitrary code via a JPEG image with a small JPEG COM field length that is normalized to a large integer length before a memory copy operation.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <vuln_types>
      <input buffer="1"/>
    </vuln_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA04-260A.html" source="CERT">TA04-260A</ref>
      <ref url="http://www.kb.cert.org/vuls/id/297462" source="CERT-VN">VU#297462</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/16304" source="XF" patch="1" adv="1">win-jpeg-bo(16304)</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms04-028.asp" source="MS" patch="1" adv="1">MS04-028</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109524346729948&amp;w=2" source="BUGTRAQ">20040914 Microsoft GDIPlus.DLL JPEG Parsing Engine Buffer Overflow</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:4307" source="OVAL" sig="1">oval:org.mitre.oval:def:4307</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:4216" source="OVAL" sig="1">oval:org.mitre.oval:def:4216</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:4003" source="OVAL" sig="1">oval:org.mitre.oval:def:4003</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:3881" source="OVAL" sig="1">oval:org.mitre.oval:def:3881</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:3810" source="OVAL" sig="1">oval:org.mitre.oval:def:3810</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:3320" source="OVAL" sig="1">oval:org.mitre.oval:def:3320</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:3082" source="OVAL" sig="1">oval:org.mitre.oval:def:3082</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:3038" source="OVAL" sig="1">oval:org.mitre.oval:def:3038</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2706" source="OVAL" sig="1">oval:org.mitre.oval:def:2706</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1721" source="OVAL" sig="1">oval:org.mitre.oval:def:1721</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1105" source="OVAL" sig="1">oval:org.mitre.oval:def:1105</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name=".net_framework">
        <vers num="1.0" edition="sp2"/>
        <vers num="1.0" edition="sp2:sdk"/>
      </prod>
      <prod vendor="microsoft" name="digital_image_pro">
        <vers num="7.0"/>
        <vers num="9"/>
      </prod>
      <prod vendor="microsoft" name="digital_image_suite">
        <vers num="9"/>
      </prod>
      <prod vendor="microsoft" name="excel">
        <vers num="2002"/>
        <vers num="2003"/>
      </prod>
      <prod vendor="microsoft" name="frontpage">
        <vers num="2002"/>
        <vers num="2003"/>
      </prod>
      <prod vendor="microsoft" name="greetings">
        <vers num="2002"/>
      </prod>
      <prod vendor="microsoft" name="infopath">
        <vers num="2003"/>
      </prod>
      <prod vendor="microsoft" name="office">
        <vers num="2003" edition=""/>
        <vers num="2003" edition=":student_teacher"/>
        <vers num="xp" edition="sp3"/>
      </prod>
      <prod vendor="microsoft" name="onenote">
        <vers num="2003"/>
      </prod>
      <prod vendor="microsoft" name="outlook">
        <vers num="2002"/>
        <vers num="2003"/>
      </prod>
      <prod vendor="microsoft" name="picture_it">
        <vers num="2002"/>
        <vers num="7.0"/>
        <vers num="9"/>
      </prod>
      <prod vendor="microsoft" name="powerpoint">
        <vers num="2002"/>
        <vers num="2003"/>
      </prod>
      <prod vendor="microsoft" name="producer">
        <vers num="" edition="gold"/>
        <vers num="" edition="gold:office_powerpoints"/>
      </prod>
      <prod vendor="microsoft" name="project">
        <vers num="2002" edition="sp1"/>
        <vers num="2003"/>
      </prod>
      <prod vendor="microsoft" name="publisher">
        <vers num="2002"/>
        <vers num="2003"/>
      </prod>
      <prod vendor="microsoft" name="visio">
        <vers num="2002" edition="sp2"/>
        <vers num="2003"/>
      </prod>
      <prod vendor="microsoft" name="visual_basic">
        <vers num="2002" edition=""/>
        <vers num="2002" edition=":.net_standard"/>
        <vers num="2003" edition=""/>
        <vers num="2003" edition=":.net_standard"/>
      </prod>
      <prod vendor="microsoft" name="visual_c#">
        <vers num="2002" edition=""/>
        <vers num="2002" edition=":.net_standard"/>
        <vers num="2003" edition=""/>
        <vers num="2003" edition=":.net_standard"/>
      </prod>
      <prod vendor="microsoft" name="visual_c++">
        <vers num="2002" edition=""/>
        <vers num="2002" edition=":.net_standard"/>
        <vers num="2003" edition=""/>
        <vers num="2003" edition=":.net_standard"/>
      </prod>
      <prod vendor="microsoft" name="visual_j#_.net">
        <vers num="2003" edition=""/>
        <vers num="2003" edition=":.net_standard"/>
      </prod>
      <prod vendor="microsoft" name="visual_studio_.net">
        <vers num="2002" edition="gold"/>
        <vers num="2003" edition="gold"/>
      </prod>
      <prod vendor="microsoft" name="word">
        <vers num="2002"/>
        <vers num="2003"/>
      </prod>
      <prod vendor="microsoft" name="windows_2003_server">
        <vers num="r2"/>
      </prod>
      <prod vendor="microsoft" name="windows_xp">
        <vers num="" edition=":64-bit"/>
        <vers num="" edition="gold"/>
        <vers num="" edition="sp1"/>
        <vers num="" edition="sp1:tablet_pc"/>
        <vers num="" edition="sp1:64-bit"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0201" published="2004-08-06" name="CVE-2004-0201" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Heap-based buffer overflow in the HtmlHelp program (hh.exe) in HTML Help for Microsoft Windows 98, Me, NT 4.0, 2000, XP, and Server 2003 allows remote attackers to execute arbitrary commands via a .CHM file with a large length field, a different vulnerability than CVE-2003-1041.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1" admin="1"/>
    </loss_types>
    <vuln_types>
      <input buffer="1"/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA04-196A.html" source="CERT" patch="1" adv="1">TA04-196A</ref>
      <ref url="http://www.kb.cert.org/vuls/id/920060" source="CERT-VN" patch="1" adv="1">VU#920060</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/MS04-023.mspx" source="MS" patch="1" adv="1">MS04-023</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/16586" source="XF" adv="1">win-htmlhelp-execute-code(16586)</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2004-July/023919.html" source="FULLDISC">20040714 HtmlHelp - .CHM File Heap Overflow</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:3179" source="OVAL" sig="1">oval:org.mitre.oval:def:3179</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2155" source="OVAL" sig="1">oval:org.mitre.oval:def:2155</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1530" source="OVAL" sig="1">oval:org.mitre.oval:def:1530</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1503" source="OVAL" sig="1">oval:org.mitre.oval:def:1503</ref>
    </refs>
    <vuln_soft>
      <prod vendor="avaya" name="ip600_media_servers">
        <vers num=""/>
      </prod>
      <prod vendor="avaya" name="definity_one_media_server">
        <vers num=""/>
      </prod>
      <prod vendor="avaya" name="s8100">
        <vers num=""/>
      </prod>
      <prod vendor="avaya" name="modular_messaging_message_storage_server">
        <vers num="s3400"/>
      </prod>
      <prod vendor="microsoft" name="windows_2000">
        <vers num="" edition=":professional"/>
        <vers num="" edition=":server"/>
        <vers num="" edition=":advanced_server"/>
        <vers num="" edition=":datacenter_server"/>
        <vers num="" edition="sp1"/>
        <vers num="" edition="sp1:datacenter_server"/>
        <vers num="" edition="sp1:professional"/>
        <vers num="" edition="sp1:server"/>
        <vers num="" edition="sp1:advanced_server"/>
        <vers num="" edition="sp2"/>
        <vers num="" edition="sp2:advanced_server"/>
        <vers num="" edition="sp2:professional"/>
        <vers num="" edition="sp2:datacenter_server"/>
        <vers num="" edition="sp2:server"/>
        <vers num="" edition="sp3"/>
        <vers num="" edition="sp3:datacenter_server"/>
        <vers num="" edition="sp3:server"/>
        <vers num="" edition="sp3:professional"/>
        <vers num="" edition="sp3:advanced_server"/>
        <vers num="" edition="sp4"/>
        <vers num="" edition="sp4:datacenter_server"/>
        <vers num="" edition="sp4:server"/>
        <vers num="" edition="sp4:professional"/>
        <vers num="" edition="sp4:advanced_server"/>
      </prod>
      <prod vendor="microsoft" name="windows_2003_server">
        <vers num="enterprise" edition=""/>
        <vers num="enterprise" edition=":64-bit"/>
        <vers num="enterprise_64-bit"/>
        <vers num="r2" edition=""/>
        <vers num="r2" edition=":datacenter_64-bit"/>
        <vers num="r2" edition=":64-bit"/>
        <vers num="standard" edition=""/>
        <vers num="standard" edition=":64-bit"/>
        <vers num="web"/>
      </prod>
      <prod vendor="microsoft" name="windows_98">
        <vers num="" edition="gold"/>
      </prod>
      <prod vendor="microsoft" name="windows_98se">
        <vers num=""/>
      </prod>
      <prod vendor="microsoft" name="windows_me">
        <vers num=""/>
      </prod>
      <prod vendor="microsoft" name="windows_nt">
        <vers num="4.0" edition=""/>
        <vers num="4.0" edition=":server"/>
        <vers num="4.0" edition=":enterprise_server"/>
        <vers num="4.0" edition=":terminal_server"/>
        <vers num="4.0" edition=":workstation"/>
        <vers num="4.0" edition="sp1"/>
        <vers num="4.0" edition="sp1:server"/>
        <vers num="4.0" edition="sp1:workstation"/>
        <vers num="4.0" edition="sp1:terminal_server"/>
        <vers num="4.0" edition="sp1:enterprise_server"/>
        <vers num="4.0" edition="sp2"/>
        <vers num="4.0" edition="sp2:enterprise_server"/>
        <vers num="4.0" edition="sp2:server"/>
        <vers num="4.0" edition="sp2:workstation"/>
        <vers num="4.0" edition="sp2:terminal_server"/>
        <vers num="4.0" edition="sp3"/>
        <vers num="4.0" edition="sp3:workstation"/>
        <vers num="4.0" edition="sp3:server"/>
        <vers num="4.0" edition="sp3:terminal_server"/>
        <vers num="4.0" edition="sp3:enterprise_server"/>
        <vers num="4.0" edition="sp4"/>
        <vers num="4.0" edition="sp4:workstation"/>
        <vers num="4.0" edition="sp4:enterprise_server"/>
        <vers num="4.0" edition="sp4:terminal_server"/>
        <vers num="4.0" edition="sp4:server"/>
        <vers num="4.0" edition="sp5"/>
        <vers num="4.0" edition="sp5:workstation"/>
        <vers num="4.0" edition="sp5:enterprise_server"/>
        <vers num="4.0" edition="sp5:server"/>
        <vers num="4.0" edition="sp5:terminal_server"/>
        <vers num="4.0" edition="sp6"/>
        <vers num="4.0" edition="sp6:terminal_server"/>
        <vers num="4.0" edition="sp6:server"/>
        <vers num="4.0" edition="sp6:enterprise_server"/>
        <vers num="4.0" edition="sp6:workstation"/>
        <vers num="4.0" edition="sp6a"/>
        <vers num="4.0" edition="sp6a:server"/>
        <vers num="4.0" edition="sp6a:enterprise_server"/>
        <vers num="4.0" edition="sp6a:workstation"/>
      </prod>
      <prod vendor="microsoft" name="windows_xp">
        <vers num="" edition=":home"/>
        <vers num="" edition=":64-bit"/>
        <vers num="" edition="gold"/>
        <vers num="" edition="gold:professional"/>
        <vers num="" edition="sp1"/>
        <vers num="" edition="sp1:home"/>
        <vers num="" edition="sp1:64-bit"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0202" published="2004-08-06" name="CVE-2004-0202" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">IDirectPlay4 Application Programming Interface (API) of Microsoft DirectPlay 7.0a thru 9.0b, as used in Windows Server 2003 and earlier allows remote attackers to cause a denial of service (application crash) via a malformed packet.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <vuln_types>
      <exception/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/10487" source="BID" patch="1" adv="1">10487</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms04-016.asp" source="MS">MS04-016</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/16306" source="XF">ms-directx-directplay-dos(16306)</ref>
      <ref url="http://www.osvdb.org/6742" source="OSVDB">6742</ref>
      <ref url="http://secunia.com/advisories/11802" source="SECUNIA">11802</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2705" source="OVAL" sig="1">oval:org.mitre.oval:def:2705</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2516" source="OVAL" sig="1">oval:org.mitre.oval:def:2516</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2413" source="OVAL" sig="1">oval:org.mitre.oval:def:2413</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2190" source="OVAL" sig="1">oval:org.mitre.oval:def:2190</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1027" source="OVAL" sig="1">oval:org.mitre.oval:def:1027</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="directx">
        <vers num="7.0"/>
        <vers num="7.0a"/>
        <vers num="7.1"/>
        <vers num="8.0"/>
        <vers num="8.0a"/>
        <vers num="8.1"/>
        <vers num="8.1a"/>
        <vers num="8.1b"/>
        <vers num="8.2"/>
        <vers num="9.0a"/>
        <vers num="9.0b"/>
      </prod>
      <prod vendor="microsoft" name="windows_2000">
        <vers num="" edition="sp2"/>
        <vers num="" edition="sp2:professional"/>
        <vers num="" edition="sp2:datacenter_server"/>
        <vers num="" edition="sp2:server"/>
        <vers num="" edition="sp3"/>
        <vers num="" edition="sp3:datacenter_server"/>
        <vers num="" edition="sp3:server"/>
        <vers num="" edition="sp3:professional"/>
        <vers num="" edition="sp4"/>
        <vers num="" edition="sp4:server"/>
        <vers num="" edition="sp4:datacenter_server"/>
        <vers num="" edition="sp4:professional"/>
      </prod>
      <prod vendor="microsoft" name="windows_2003_server">
        <vers num="enterprise" edition=""/>
        <vers num="enterprise" edition=":64-bit"/>
        <vers num="enterprise_64-bit"/>
        <vers num="r2" edition=""/>
        <vers num="r2" edition=":64-bit"/>
        <vers num="r2" edition=":datacenter_64-bit"/>
        <vers num="standard" edition=""/>
        <vers num="standard" edition=":64-bit"/>
        <vers num="web"/>
      </prod>
      <prod vendor="microsoft" name="windows_98">
        <vers num="" edition="gold"/>
      </prod>
      <prod vendor="microsoft" name="windows_98se">
        <vers num=""/>
      </prod>
      <prod vendor="microsoft" name="windows_me">
        <vers num=""/>
      </prod>
      <prod vendor="microsoft" name="windows_xp">
        <vers num="" edition=":home"/>
        <vers num="" edition=":64-bit"/>
        <vers num="" edition="gold"/>
        <vers num="" edition="gold:professional"/>
        <vers num="" edition="sp1"/>
        <vers num="" edition="sp1:64-bit"/>
        <vers num="" edition="sp1:home"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0203" published="2004-11-23" name="CVE-2004-0203" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in Outlook Web Access for Exchange Server 5.5 Service Pack 4 allows remote attackers to insert arbitrary script and spoof content in HTML email or web caches via an HTML redirect query.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/948750" source="CERT-VN">VU#948750</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms04-026.mspx" source="MS" patch="1" adv="1">MS04-026</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/16583" source="XF">exchange-owa-execute-code(16583)</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2016" source="OVAL" sig="1">oval:org.mitre.oval:def:2016</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="exchange_server">
        <vers num="5.5" edition="sp1"/>
        <vers num="5.5" edition="sp2"/>
        <vers num="5.5" edition="sp3"/>
        <vers num="5.5" edition="sp4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0204" published="2004-08-06" name="CVE-2004-0204" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Directory traversal vulnerability in the web viewers for Business Objects Crystal Reports 9 and 10, and Crystal Enterprise 9 or 10, as used in Visual Studio .NET 2003 and Outlook 2003 with Business Contact Manager, Microsoft Business Solutions CRM 1.2, and other products, allows remote attackers to read and delete arbitrary files via ".." sequences in the dynamicimag argument to crystalimagehandler.aspx.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/10260" source="BID" patch="1" adv="1">10260</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/16044" source="XF" adv="1">crystalreports-file-deletion(16044)</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms04-017.asp" source="MS">MS04-017</ref>
      <ref url="http://support.businessobjects.com/fix/hot/critical/bulletins/security_bulletin_june04.asp" source="CONFIRM">http://support.businessobjects.com/fix/hot/critical/bulletins/security_bulletin_june04.asp</ref>
      <ref url="http://www.osvdb.org/6748" source="OSVDB">6748</ref>
      <ref url="http://secunia.com/advisories/11800" source="SECUNIA">11800</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108671836127360&amp;w=2" source="BUGTRAQ">20040608 Vulnerability: Arbitrary File Access &amp; DoS in Crystal Reports</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108360413811017&amp;w=2" source="BUGTRAQ">20040502 Crystal Reports Vulnerabilities</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1157" source="OVAL" sig="1">oval:org.mitre.oval:def:1157</ref>
    </refs>
    <vuln_soft>
      <prod vendor="bea" name="weblogic_server">
        <vers num="8.1" edition=""/>
        <vers num="8.1" edition=":win32"/>
        <vers num="8.1" edition=":express"/>
        <vers num="8.1" edition="sp1"/>
        <vers num="8.1" edition="sp1:express"/>
        <vers num="8.1" edition="sp1:win32"/>
        <vers num="8.1" edition="sp2"/>
        <vers num="8.1" edition="sp2:express"/>
        <vers num="8.1" edition="sp2:win32"/>
      </prod>
      <prod vendor="borland_software" name="j_builder">
        <vers num=""/>
      </prod>
      <prod vendor="businessobjects" name="crystal_enterprise">
        <vers num="10"/>
        <vers num="9"/>
      </prod>
      <prod vendor="businessobjects" name="crystal_enterprise_java_sdk">
        <vers num="8.5"/>
      </prod>
      <prod vendor="businessobjects" name="crystal_enterprise_ras">
        <vers num="8.5" edition=""/>
        <vers num="8.5" edition=":unix"/>
      </prod>
      <prod vendor="businessobjects" name="crystal_reports">
        <vers num="10"/>
        <vers num="9"/>
      </prod>
      <prod vendor="microsoft" name="business_solutions_crm">
        <vers num="1.2"/>
      </prod>
      <prod vendor="microsoft" name="outlook">
        <vers num="2003" edition=""/>
        <vers num="2003" edition=":business_contact_manager"/>
      </prod>
      <prod vendor="microsoft" name="visual_studio_.net">
        <vers num="2003" edition="gold"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0205" published="2004-08-06" name="CVE-2004-0205" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Buffer overflow in Microsoft Internet Information Server (IIS) 4.0 allows local users to execute arbitrary code via the redirect function.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1" admin="1"/>
    </loss_types>
    <vuln_types>
      <input buffer="1"/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA04-196A.html" source="CERT" patch="1" adv="1">TA04-196A</ref>
      <ref url="http://www.kb.cert.org/vuls/id/717748" source="CERT-VN" patch="1" adv="1">VU#717748</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/16578" source="XF" adv="1">iis-redirect-bo(16578)</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms04-021.asp" source="MS">MS04-021</ref>
      <ref url="http://www.ciac.org/ciac/bulletins/o-179.shtml" source="CIAC">O-179</ref>
      <ref url="http://www.securityfocus.com/bid/10706" source="BID">10706</ref>
      <ref url="http://www.osvdb.org/7799" source="OSVDB">7799</ref>
      <ref url="http://secunia.com/advisories/12061" source="SECUNIA">12061</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2204" source="OVAL" sig="1">oval:org.mitre.oval:def:2204</ref>
    </refs>
    <vuln_soft>
      <prod vendor="avaya" name="ip600_media_servers">
        <vers num=""/>
      </prod>
      <prod vendor="microsoft" name="internet_information_server">
        <vers num="4.0"/>
      </prod>
      <prod vendor="avaya" name="definity_one_media_server">
        <vers num=""/>
      </prod>
      <prod vendor="avaya" name="s8100">
        <vers num=""/>
      </prod>
      <prod vendor="avaya" name="modular_messaging_message_storage_server">
        <vers num="s3400"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0206" published="2004-11-03" name="CVE-2004-0206" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Network Dynamic Data Exchange (NetDDE) services for Microsoft Windows 98, Windows NT 4.0, Windows 2000, Windows XP, and Windows Server 2003 allows attackers to remotely execute arbitrary code or locally gain privileges via a malicious message or application that involves an "unchecked buffer," possibly a buffer overflow.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input buffer="1"/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/640488" source="CERT-VN" patch="1" adv="1">VU#640488</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/17657" source="XF" patch="1" adv="1">win-ms04031-patch(17657)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/16556" source="XF" patch="1" adv="1">win-netdde-bo(16556)</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms04-031.asp" source="MS" patch="1" adv="1">MS04-031</ref>
      <ref url="http://secunia.com/advisories/12803/" source="SECUNIA">12803</ref>
      <ref url="http://www.securityfocus.com/bid/11372" source="BID">11372</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109786703930674&amp;w=2" source="BUGTRAQ">20041013 Microsoft Windows NetDDE Service Buffer Overflow</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6788" source="OVAL" sig="1">oval:org.mitre.oval:def:6788</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5074" source="OVAL" sig="1">oval:org.mitre.oval:def:5074</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:4592" source="OVAL" sig="1">oval:org.mitre.oval:def:4592</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:3242" source="OVAL" sig="1">oval:org.mitre.oval:def:3242</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:3120" source="OVAL" sig="1">oval:org.mitre.oval:def:3120</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2394" source="OVAL" sig="1">oval:org.mitre.oval:def:2394</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1852" source="OVAL" sig="1">oval:org.mitre.oval:def:1852</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_2000">
        <vers num=""/>
      </prod>
      <prod vendor="microsoft" name="windows_2003_server">
        <vers num="r2"/>
      </prod>
      <prod vendor="microsoft" name="windows_98">
        <vers num="" edition="gold"/>
      </prod>
      <prod vendor="microsoft" name="windows_nt">
        <vers num="4.0"/>
      </prod>
      <prod vendor="microsoft" name="windows_xp">
        <vers num="" edition="gold"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2004-0207" published="2004-11-03" name="CVE-2004-0207" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">"Shatter" style vulnerability in the Window Management application programming interface (API) for Microsoft Windows 98, Windows NT 4.0, Windows 2000, Windows XP, and Windows Server 2003 allows local users to gain privileges by using certain API functions to change properties of privileged programs using the SetWindowLong and SetWIndowLongPtr API functions.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <vuln_types>
      <access/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/218526" source="CERT-VN" patch="1" adv="1">VU#218526</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/17658" source="XF" patch="1" adv="1">win-ms04032-patch(17658)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/16579" source="XF" patch="1" adv="1">win-mngmt-api-gain-privileges(16579)</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms04-032.asp" source="MS" patch="1" adv="1">MS04-032</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109777417922695&amp;w=2" source="BUGTRAQ">20041013 SetWindowLong Shatter Attacks</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_2000">
        <vers num=""/>
      </prod>
      <prod vendor="microsoft" name="windows_2003_server">
        <vers num="r2"/>
      </prod>
      <prod vendor="microsoft" name="windows_98">
        <vers num="" edition="gold"/>
      </prod>
      <prod vendor="microsoft" name="windows_nt">
        <vers num="4.0"/>
      </prod>
      <prod vendor="microsoft" name="windows_xp">
        <vers num="" edition="gold"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0208" published="2004-11-03" name="CVE-2004-0208" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">The Virtual DOS Machine (VDM) subsystem of Microsoft Windows NT 4.0, Windows 2000, Windows XP, and Windows Server 2003 allows local users to access kernel memory and gain privileges via a malicious program that modified some system structures in a way that is not properly validated by privileged operating system functions.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <vuln_types>
      <access/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/910998" source="CERT-VN" patch="1" adv="1">VU#910998</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/17658" source="XF" patch="1" adv="1">win-ms04032-patch(17658)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/16580" source="XF" patch="1" adv="1">win-vdm-gain-privilege(16580)</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms04-032.asp" source="MS" patch="1" adv="1">MS04-032</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109772135404427&amp;w=2" source="BUGTRAQ">20041013 EEYE: Windows VDM #UD Local Privilege Escalation</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:4762" source="OVAL" sig="1">oval:org.mitre.oval:def:4762</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:4316" source="OVAL" sig="1">oval:org.mitre.oval:def:4316</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:3953" source="OVAL" sig="1">oval:org.mitre.oval:def:3953</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:3161" source="OVAL" sig="1">oval:org.mitre.oval:def:3161</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1751" source="OVAL" sig="1">oval:org.mitre.oval:def:1751</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_2000">
        <vers num=""/>
      </prod>
      <prod vendor="microsoft" name="windows_2003_server">
        <vers num="r2"/>
      </prod>
      <prod vendor="microsoft" name="windows_nt">
        <vers num="4.0"/>
      </prod>
      <prod vendor="microsoft" name="windows_xp">
        <vers num="" edition="gold"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0209" published="2004-11-03" name="CVE-2004-0209" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Unknown vulnerability in the Graphics Rendering Engine processes of Microsoft Windows 2000, Windows XP, and Windows Server 2003 allows remote attackers to execute arbitrary code via (1) Windows Metafile (WMF) or (2) Enhanced Metafile (EMF) image formats that involve "an unchecked buffer."</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <vuln_types>
      <access/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/806278" source="CERT-VN">VU#806278</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/16581" source="XF" patch="1" adv="1">win-emf-bo(16581)</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms04-032.asp" source="MS" patch="1" adv="1">MS04-032</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109829067325779&amp;w=2" source="BUGTRAQ">20041019 [EXPL] (MS04-032) Microsoft Windows XP Metafile (.emf) Heap Overflow</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/17658" source="XF">win-ms04032-patch(17658)</ref>
      <ref url="http://www.securityfocus.com/bid/11375" source="BID">11375</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2428" source="OVAL" sig="1">oval:org.mitre.oval:def:2428</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2114" source="OVAL" sig="1">oval:org.mitre.oval:def:2114</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1872" source="OVAL" sig="1">oval:org.mitre.oval:def:1872</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_2000">
        <vers num=""/>
      </prod>
      <prod vendor="microsoft" name="windows_2003_server">
        <vers num="r2"/>
      </prod>
      <prod vendor="microsoft" name="windows_xp">
        <vers num="" edition="gold"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0210" published="2004-08-06" name="CVE-2004-0210" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">The POSIX component of Microsoft Windows NT and Windows 2000 allows local users to execute arbitrary code via certain parameters, possibly by modifying message length values and causing a buffer overflow.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1" admin="1"/>
    </loss_types>
    <vuln_types>
      <input buffer="1"/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA04-196A.html" source="CERT" patch="1" adv="1">TA04-196A</ref>
      <ref url="http://www.kb.cert.org/vuls/id/647436" source="CERT-VN" patch="1" adv="1">VU#647436</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/16590" source="XF" adv="1">win-posix-bo(16590)</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms04-020.asp" source="MS">MS04-020</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2847" source="OVAL" sig="1">oval:org.mitre.oval:def:2847</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2166" source="OVAL" sig="1">oval:org.mitre.oval:def:2166</ref>
    </refs>
    <vuln_soft>
      <prod vendor="avaya" name="modular_messaging_message_storage_server">
        <vers num="s3400"/>
      </prod>
      <prod vendor="microsoft" name="windows_2000">
        <vers num="" edition="sp2"/>
        <vers num="" edition="sp2:datacenter_server"/>
        <vers num="" edition="sp2:advanced_server"/>
        <vers num="" edition="sp2:professional"/>
        <vers num="" edition="sp2:server"/>
        <vers num="" edition="sp3"/>
        <vers num="" edition="sp3:professional"/>
        <vers num="" edition="sp3:datacenter_server"/>
        <vers num="" edition="sp3:advanced_server"/>
        <vers num="" edition="sp3:server"/>
        <vers num="" edition="sp4"/>
        <vers num="" edition="sp4:datacenter_server"/>
        <vers num="" edition="sp4:server"/>
        <vers num="" edition="sp4:professional"/>
        <vers num="" edition="sp4:advanced_server"/>
      </prod>
      <prod vendor="microsoft" name="windows_nt">
        <vers num="4.0" edition="sp6"/>
        <vers num="4.0" edition="sp6:terminal_server"/>
        <vers num="4.0" edition="sp6:alpha"/>
        <vers num="4.0" edition="sp6a"/>
        <vers num="4.0" edition="sp6a:enterprise_server"/>
        <vers num="4.0" edition="sp6a:workstation"/>
        <vers num="4.0" edition="sp6a:server"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2004-0211" published="2004-11-03" name="CVE-2004-0211" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">The kernel for Microsoft Windows Server 2003 does not reset certain values in CPU data structures, which allows local users to cause a denial of service (system crash) via a malicious program.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <vuln_types>
      <design/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/119262" source="CERT-VN" patch="1" adv="1">VU#119262</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/17658" source="XF" patch="1" adv="1">win-ms04032-patch(17658)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/16582" source="XF" patch="1" adv="1">win2k3-kernel-cpu-dos(16582)</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms04-032.asp" source="MS" patch="1" adv="1">MS04-032</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:4893" source="OVAL" sig="1">oval:org.mitre.oval:def:4893</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_2003_server">
        <vers num="r2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0212" published="2004-08-06" name="CVE-2004-0212" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Stack-based buffer overflow in the Task Scheduler for Windows 2000 and XP, and Internet Explorer 6 on Windows NT 4.0, allows local or remote attackers to execute arbitrary code via a .job file containing long parameters, as demonstrated using Internet Explorer and accessing a .job file on an anonymous share.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1" admin="1"/>
    </loss_types>
    <vuln_types>
      <input buffer="1"/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA04-196A.html" source="CERT" patch="1" adv="1">TA04-196A</ref>
      <ref url="http://www.kb.cert.org/vuls/id/228028" source="CERT-VN">VU#228028</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/16591" source="XF" adv="1">win-taskscheduler-bo(16591)</ref>
      <ref url="http://www.ngssoftware.com/advisories/mstaskjob.txt" source="MISC">http://www.ngssoftware.com/advisories/mstaskjob.txt</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms04-022.asp" source="MS">MS04-022</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108981403025596&amp;w=2" source="BUGTRAQ">20040714 Unchecked buffer in mstask.dll</ref>
      <ref url="http://secunia.com/advisories/12060" source="SECUNIA">12060</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108981273009250&amp;w=2" source="BUGTRAQ">20040714 Microsoft Windows Task Scheduler '.job' Stack Overflow</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:3428" source="OVAL" sig="1">oval:org.mitre.oval:def:3428</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1964" source="OVAL" sig="1">oval:org.mitre.oval:def:1964</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1781" source="OVAL" sig="1">oval:org.mitre.oval:def:1781</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1344" source="OVAL" sig="1">oval:org.mitre.oval:def:1344</ref>
    </refs>
    <vuln_soft>
      <prod vendor="avaya" name="ip600_media_servers">
        <vers num=""/>
      </prod>
      <prod vendor="microsoft" name="ie">
        <vers num="6.0" edition="sp1"/>
      </prod>
      <prod vendor="avaya" name="definity_one_media_server">
        <vers num=""/>
      </prod>
      <prod vendor="avaya" name="s8100">
        <vers num=""/>
      </prod>
      <prod vendor="avaya" name="modular_messaging_message_storage_server">
        <vers num="s3400"/>
      </prod>
      <prod vendor="microsoft" name="windows_2000">
        <vers num="" edition=":advanced_server"/>
        <vers num="" edition=":professional"/>
        <vers num="" edition=":datacenter_server"/>
        <vers num="" edition=":server"/>
        <vers num="" edition="sp1"/>
        <vers num="" edition="sp1:datacenter_server"/>
        <vers num="" edition="sp1:professional"/>
        <vers num="" edition="sp1:server"/>
        <vers num="" edition="sp1:advanced_server"/>
        <vers num="" edition="sp2"/>
        <vers num="" edition="sp2:advanced_server"/>
        <vers num="" edition="sp2:professional"/>
        <vers num="" edition="sp2:datacenter_server"/>
        <vers num="" edition="sp2:server"/>
        <vers num="" edition="sp3"/>
        <vers num="" edition="sp3:datacenter_server"/>
        <vers num="" edition="sp3:server"/>
        <vers num="" edition="sp3:professional"/>
        <vers num="" edition="sp3:advanced_server"/>
        <vers num="" edition="sp4"/>
        <vers num="" edition="sp4:server"/>
        <vers num="" edition="sp4:datacenter_server"/>
        <vers num="" edition="sp4:professional"/>
        <vers num="" edition="sp4:advanced_server"/>
      </prod>
      <prod vendor="microsoft" name="windows_nt">
        <vers num="4.0" edition="sp6a"/>
        <vers num="4.0" edition="sp6a:enterprise_server"/>
        <vers num="4.0" edition="sp6a:workstation"/>
        <vers num="4.0" edition="sp6a:server"/>
      </prod>
      <prod vendor="microsoft" name="windows_xp">
        <vers num="" edition=":home"/>
        <vers num="" edition=":64-bit"/>
        <vers num="" edition="gold"/>
        <vers num="" edition="gold:professional"/>
        <vers num="" edition="sp1"/>
        <vers num="" edition="sp1:64-bit"/>
        <vers num="" edition="sp1:home"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0213" published="2004-08-06" name="CVE-2004-0213" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Utility Manager in Windows 2000 launches winhlp32.exe while Utility Manager is running with raised privileges, which allows local users to gain system privileges via a "Shatter" style attack that sends a Windows message to cause Utility Manager to launch winhlp32 by directly accessing the context sensitive help and bypassing the GUI, then sending another message to winhlp32 in order to open a user-selected file, a different vulnerability than CVE-2003-0908.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <vuln_types>
      <access/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA04-196A.html" source="CERT" patch="1" adv="1">TA04-196A</ref>
      <ref url="http://www.kb.cert.org/vuls/id/868580" source="CERT-VN">VU#868580</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms04-019.asp" source="MS" patch="1" adv="1">MS04-019</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108975382413405&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20040713 Microsoft Window Utility Manager Local Elevation of Privileges</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/16592" source="XF" adv="1">win-utilitymanager-gain-privileges(16592)</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2495" source="OVAL" sig="1">oval:org.mitre.oval:def:2495</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_2000">
        <vers num="" edition=":datacenter_server"/>
        <vers num="" edition=":server"/>
        <vers num="" edition=":advanced_server"/>
        <vers num="" edition=":professional"/>
        <vers num="" edition="sp1"/>
        <vers num="" edition="sp1:professional"/>
        <vers num="" edition="sp1:datacenter_server"/>
        <vers num="" edition="sp1:server"/>
        <vers num="" edition="sp1:advanced_server"/>
        <vers num="" edition="sp2"/>
        <vers num="" edition="sp2:datacenter_server"/>
        <vers num="" edition="sp2:advanced_server"/>
        <vers num="" edition="sp2:professional"/>
        <vers num="" edition="sp2:server"/>
        <vers num="" edition="sp3"/>
        <vers num="" edition="sp3:professional"/>
        <vers num="" edition="sp3:datacenter_server"/>
        <vers num="" edition="sp3:advanced_server"/>
        <vers num="" edition="sp3:server"/>
        <vers num="" edition="sp4"/>
        <vers num="" edition="sp4:datacenter_server"/>
        <vers num="" edition="sp4:server"/>
        <vers num="" edition="sp4:professional"/>
        <vers num="" edition="sp4:advanced_server"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0214" published="2004-11-03" name="CVE-2004-0214" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Buffer overflow in Microsoft Internet Explorer and Explorer on Windows XP SP1, WIndows 2000, Windows 98, and Windows Me may allow remote malicious servers to cause a denial of service (application crash) and possibly execute arbitrary code via long share names, as demonstrated using Samba.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <vuln_types>
      <input buffer="1"/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/616200" source="CERT-VN">VU#616200</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/17662" source="XF" patch="1" adv="1">win-ms04037-patch(17662)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15956" source="XF" patch="1" adv="1">win-long-fileshare-bo(15956)</ref>
      <ref url="http://www.securityfocus.com/bid/10213" source="BID">10213</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms04-037.mspx" source="MS">MS04-037</ref>
      <ref url="http://support.microsoft.com/default.aspx?scid=kb;en-us;322857" source="MSKB">322857</ref>
      <ref url="http://securitytracker.com/id?1011647" source="SECTRACK">1011647</ref>
      <ref url="http://secunia.com/advisories/11482/" source="SECUNIA">11482</ref>
      <ref url="http://seclists.org/lists/fulldisclosure/2004/Apr/0933.html" source="FULLDISC" adv="1">20040425 Microsoft's Explorer and Internet Explorer long share name buffer overflow.</ref>
      <ref url="http://seclists.org/lists/bugtraq/2004/Apr/0322.html" source="BUGTRAQ" adv="1">20040425 Microsoft's Explorer and Internet Explorer long share name buffer overflow.</ref>
      <ref url="http://www.securiteam.com/windowsntfocus/5JP0M1PCKI.html" source="MISC">http://www.securiteam.com/windowsntfocus/5JP0M1PCKI.html</ref>
      <ref url="http://www.osvdb.org/5687" source="OSVDB">5687</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5307" source="OVAL" sig="1">oval:org.mitre.oval:def:5307</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:4345" source="OVAL" sig="1">oval:org.mitre.oval:def:4345</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2638" source="OVAL" sig="1">oval:org.mitre.oval:def:2638</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1749" source="OVAL" sig="1">oval:org.mitre.oval:def:1749</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1601" source="OVAL" sig="1">oval:org.mitre.oval:def:1601</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="ie">
        <vers num="6.0.2900"/>
      </prod>
      <prod vendor="microsoft" name="windows_2000">
        <vers num=""/>
      </prod>
      <prod vendor="microsoft" name="windows_98">
        <vers num="" edition="gold"/>
      </prod>
      <prod vendor="microsoft" name="windows_me">
        <vers num=""/>
      </prod>
      <prod vendor="microsoft" name="windows_xp">
        <vers num="" edition="sp1"/>
        <vers num="" edition="sp1:tablet_pc"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0215" published="2004-08-06" name="CVE-2004-0215" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Microsoft Outlook Express 5.5 and 6 allows attackers to cause a denial of service (application crash) via a malformed e-mail header.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <vuln_types>
      <input/>
      <exception/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA04-196A.html" source="CERT" patch="1" adv="1">TA04-196A</ref>
      <ref url="http://www.kb.cert.org/vuls/id/869640" source="CERT-VN" patch="1" adv="1">VU#869640</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/16585" source="XF" adv="1">outlook-malformed-email-header-dos(16585)</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms04-018.asp" source="MS">MS04-018</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:3376" source="OVAL" sig="1">oval:org.mitre.oval:def:3376</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2657" source="OVAL" sig="1">oval:org.mitre.oval:def:2657</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2137" source="OVAL" sig="1">oval:org.mitre.oval:def:2137</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1950" source="OVAL" sig="1">oval:org.mitre.oval:def:1950</ref>
    </refs>
    <vuln_soft>
      <prod vendor="avaya" name="ip600_media_servers">
        <vers num=""/>
      </prod>
      <prod vendor="microsoft" name="outlook_express">
        <vers num="6.0"/>
      </prod>
      <prod vendor="avaya" name="definity_one_media_server">
        <vers num=""/>
      </prod>
      <prod vendor="avaya" name="s8100">
        <vers num=""/>
      </prod>
      <prod vendor="avaya" name="modular_messaging_message_storage_server">
        <vers num="s3400"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0216" published="2004-11-03" name="CVE-2004-0216" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Integer overflow in the Install Engine (inseng.dll) for Internet Explorer 5.01, 5.5, and 6 allows remote attackers to execute arbitrary code via a malicious website or HTML email with a long .CAB file name, which triggers the integer overflow when calculating a buffer length and leads to a heap-based buffer overflow.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <vuln_types>
      <input buffer="1"/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA04-293A.html" source="CERT" patch="1" adv="1">TA04-293A</ref>
      <ref url="http://www.kb.cert.org/vuls/id/637760" source="CERT-VN" patch="1" adv="1">VU#637760</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/17620" source="XF" patch="1" adv="1">ie-installenginectl-setciffile-bo(17620)</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms04-038.asp" source="MS" patch="1" adv="1">MS04-038</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109760693512754&amp;w=2" source="BUGTRAQ" patch="1">20041012 Microsoft Internet Explorer Install Engine Control Buffer Overflow</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/17651" source="XF">ie-ms04038-patch(17651)</ref>
      <ref url="http://www.ngssoftware.com/advisories/msinsengfull.txt" source="MISC">http://www.ngssoftware.com/advisories/msinsengfull.txt</ref>
      <ref url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=110619893620517&amp;w=2" source="NTBUGTRAQ">20050119 Microsoft Internet Explorer Install Engine Control Buffer Overflow (#NISR19012005a)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110616383332055&amp;w=2" source="BUGTRAQ">20050119 Microsoft Internet Explorer Install Engine Control Buffer Overflow (#NISR19012005a)</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:7865" source="OVAL" sig="1">oval:org.mitre.oval:def:7865</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:7717" source="OVAL" sig="1">oval:org.mitre.oval:def:7717</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6600" source="OVAL" sig="1">oval:org.mitre.oval:def:6600</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6100" source="OVAL" sig="1">oval:org.mitre.oval:def:6100</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5329" source="OVAL" sig="1">oval:org.mitre.oval:def:5329</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5316" source="OVAL" sig="1">oval:org.mitre.oval:def:5316</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="ie">
        <vers num="5.01"/>
        <vers num="5.5"/>
        <vers num="6" edition="windows_server_2003_sp1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2004-0217" published="2004-04-15" name="CVE-2004-0217" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:H/Au:N/C:P/I:P/A:P)" CVSS_score="3.7" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="1.9" CVSS_base_score="3.7">
    <desc>
      <descript source="cve">The LiveUpdate capability (liveupdate.sh) in Symantec AntiVirus Scan Engine 4.0 and 4.3 for Red Hat Linux allows local users to create or append to arbitrary files via a symlink attack on /tmp/LiveUpdate.log.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <race/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/15215" source="XF" patch="1" adv="1">symantec-scanengine-race-condition(15215)</ref>
      <ref url="http://www.securityfocus.com/bid/9662" source="BID" patch="1" adv="1">9662</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107694800908164&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20040216 Possible race condition in Symantec AntiVirus Scan Engine for Red</ref>
    </refs>
    <vuln_soft>
      <prod vendor="symantec" name="antivirus_scan_engine">
        <vers num="4.0" edition=""/>
        <vers num="4.0" edition=":red_hat_linux"/>
        <vers num="4.3" edition=""/>
        <vers num="4.3" edition=":red_hat_linux"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0218" published="2004-05-04" name="CVE-2004-0218" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">isakmpd in OpenBSD 3.4 and earlier allows remote attackers to cause a denial of service (infinite loop) via an ISAKMP packet with a zero-length payload, as demonstrated by the Striker ISAKMP Protocol Test Suite.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/349113" source="CERT-VN">VU#349113</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15518" source="XF" patch="1" adv="1">openbsd-isakmp-zerolength-dos(15518)</ref>
      <ref url="http://www.openbsd.org/errata.html" source="OPENBSD" patch="1">20040317 015: RELIABILITY FIX: March 17, 2004</ref>
      <ref url="http://www.rapid7.com/advisories/R7-0018.html" source="MISC">http://www.rapid7.com/advisories/R7-0018.html</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108008530028019&amp;w=2" source="BUGTRAQ" adv="1">20040323 R7-0018: OpenBSD isakmpd payload handling denial-of-service vulnerabilities</ref>
      <ref url="http://www.securitytracker.com/alerts/2004/Mar/1009468.html" source="SECTRACK">1009468</ref>
      <ref url="http://www.securityfocus.com/bid/10028" source="BID">10028</ref>
      <ref url="http://secunia.com/advisories/11156" source="SECUNIA">11156</ref>
    </refs>
    <vuln_soft>
      <prod vendor="openbsd" name="openbsd">
        <vers prev="1" num="3.4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0219" published="2004-05-04" name="CVE-2004-0219" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">isakmpd in OpenBSD 3.4 and earlier allows remote attackers to cause a denial of service (crash) via an ISAKMP packet with a malformed IPSEC SA payload, as demonstrated by the Striker ISAKMP Protocol Test Suite.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/785945" source="CERT-VN">VU#785945</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15628" source="XF" patch="1" adv="1">openbsd-isakmp-ipsec-dos(15628)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108008530028019&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20040323 R7-0018: OpenBSD isakmpd payload handling denial-of-service vulnerabilities</ref>
      <ref url="http://www.rapid7.com/advisories/R7-0018.html" source="MISC">http://www.rapid7.com/advisories/R7-0018.html</ref>
      <ref url="http://www.openbsd.org/errata.html" source="OPENBSD">20040317 015: RELIABILITY FIX: March 17, 2004</ref>
      <ref url="http://www.securitytracker.com/alerts/2004/Mar/1009468.html" source="SECTRACK">1009468</ref>
      <ref url="http://www.securityfocus.com/bid/9907" source="BID">9907</ref>
    </refs>
    <vuln_soft>
      <prod vendor="openbsd" name="openbsd">
        <vers prev="1" num="3.4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0220" published="2004-05-04" name="CVE-2004-0220" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">isakmpd in OpenBSD 3.4 and earlier allows remote attackers to cause a denial of service via a an ISAKMP packet with a malformed Cert Request payload, which causes an integer underflow that is used in a malloc operation that is not properly handled, as demonstrated by the Striker ISAKMP Protocol Test Suite.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/223273" source="CERT-VN">VU#223273</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15629" source="XF" patch="1" adv="1">openbsd-isakmp-integer-underflow(15629)</ref>
      <ref url="http://www.openbsd.org/errata.html" source="OPENBSD" patch="1">20040317 015: RELIABILITY FIX: March 17, 2004</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108008530028019&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20040323 R7-0018: OpenBSD isakmpd payload handling denial-of-service vulnerabilities</ref>
      <ref url="http://www.securitytracker.com/alerts/2004/Mar/1009468.html" source="SECTRACK">1009468</ref>
      <ref url="http://www.securityfocus.com/bid/9907" source="BID">9907</ref>
      <ref url="http://www.rapid7.com/advisories/R7-0018.html" source="MISC">http://www.rapid7.com/advisories/R7-0018.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="openbsd" name="openbsd">
        <vers prev="1" num="3.4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0221" published="2004-05-04" name="CVE-2004-0221" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">isakmpd in OpenBSD 3.4 and earlier allows remote attackers to cause a denial of service (crash) via an ISAKMP packet with a delete payload containing a large number of SPIs, which triggers an out-of-bounds read error, as demonstrated by the Striker ISAKMP Protocol Test Suite.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/524497" source="CERT-VN">VU#524497</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15630" source="XF" patch="1" adv="1">openbsd-isakmp-delete-dos(15630)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108008530028019&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20040323 R7-0018: OpenBSD isakmpd payload handling denial-of-service vulnerabilities</ref>
      <ref url="http://www.rapid7.com/advisories/R7-0018.html" source="MISC">http://www.rapid7.com/advisories/R7-0018.html</ref>
      <ref url="http://www.openbsd.org/errata.html" source="OPENBSD" adv="1">20040317 015: RELIABILITY FIX: March 17, 2004</ref>
      <ref url="http://www.securitytracker.com/alerts/2004/Mar/1009468.html" source="SECTRACK">1009468</ref>
      <ref url="http://www.securityfocus.com/bid/9907" source="BID">9907</ref>
    </refs>
    <vuln_soft>
      <prod vendor="openbsd" name="openbsd">
        <vers prev="1" num="3.4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0222" published="2004-05-04" name="CVE-2004-0222" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Multiple memory leaks in isakmpd in OpenBSD 3.4 and earlier allow remote attackers to cause a denial of service (memory exhaustion) via certain ISAKMP packets, as demonstrated by the Striker ISAKMP Protocol Test Suite.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <vuln_types>
      <input bound="1"/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/996177" source="CERT-VN">VU#996177</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15519" source="XF" patch="1" adv="1">openbsd-isakmp-memory-leak(15519)</ref>
      <ref url="http://www.openbsd.org/errata.html" source="OPENBSD" patch="1">20040317 015: RELIABILITY FIX: March 17, 2004</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108008530028019&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20040323 R7-0018: OpenBSD isakmpd payload handling denial-of-service vulnerabilities</ref>
      <ref url="http://www.rapid7.com/advisories/R7-0018.html" source="MISC">http://www.rapid7.com/advisories/R7-0018.html</ref>
      <ref url="http://www.securitytracker.com/alerts/2004/Mar/1009468.html" source="SECTRACK">1009468</ref>
      <ref url="http://www.securityfocus.com/bid/10032" source="BID">10028</ref>
    </refs>
    <vuln_soft>
      <prod vendor="openbsd" name="openbsd">
        <vers prev="1" num="3.4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0224" published="2004-04-15" name="CVE-2004-0224" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple buffer overflows in (1) iso2022jp.c or (2) shiftjis.c for Courier-IMAP before 3.0.0, Courier before 0.45, and SqWebMail before 4.0.0 may allow remote attackers to execute arbitrary code "when Unicode character is out of BMP range."</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input bound="1"/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/9845" source="BID" patch="1" adv="1">9845</ref>
      <ref url="http://secunia.com/advisories/11087/" source="SECUNIA" patch="1" adv="1">11087</ref>
      <ref url="http://sourceforge.net/project/shownotes.php?release_id=5767" source="CONFIRM" adv="1">http://sourceforge.net/project/shownotes.php?release_id=5767</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15434" source="XF">courier-codeset-converter-bo(15434)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="double_precision_incorporated" name="courier_mta">
        <vers num="0.43"/>
        <vers num="0.43.1"/>
        <vers num="0.43.2"/>
        <vers num="0.44"/>
        <vers num="0.44.2"/>
      </prod>
      <prod vendor="double_precision_incorporated" name="sqwebmail">
        <vers num="3.5.2"/>
        <vers num="3.5.3"/>
        <vers num="3.6.1"/>
        <vers num="3.6.2"/>
        <vers num="3.6_.0"/>
      </prod>
      <prod vendor="inter7" name="courier-imap">
        <vers num="1.6"/>
        <vers num="1.7"/>
        <vers num="2.0.0"/>
        <vers num="2.1"/>
        <vers num="2.1.1"/>
        <vers num="2.1.2"/>
        <vers num="2.2.0"/>
        <vers num="2.2.1"/>
      </prod>
      <prod vendor="gentoo" name="linux">
        <vers num="1.4" edition="rc1"/>
        <vers num="1.4" edition="rc2"/>
        <vers num="1.4" edition="rc3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0226" published="2004-08-18" name="CVE-2004-0226" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Multiple buffer overflows in Midnight Commander (mc) before 4.6.0 may allow attackers to cause a denial of service or execute arbitrary code.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1" admin="1"/>
    </loss_types>
    <vuln_types>
      <input buffer="1"/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-172.html" source="REDHAT" patch="1" adv="1">RHSA-2004:172</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/16016" source="XF" adv="1">midnight-commander-local-privileges(16016)</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2004_12_mc.html" source="SUSE">SuSE-SA:2004:012</ref>
      <ref url="http://www.debian.org/security/2004/dsa-497" source="DEBIAN">DSA-497</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200405-21.xml" source="GENTOO">GLSA-200405-21</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2004:039" source="MANDRAKE">MDKSA-2004:039</ref>
    </refs>
    <vuln_soft>
      <prod vendor="midnight_commander" name="midnight_commander">
        <vers num="4.5.40"/>
        <vers num="4.5.41"/>
        <vers num="4.5.42"/>
        <vers num="4.5.43"/>
        <vers num="4.5.44"/>
        <vers num="4.5.45"/>
        <vers num="4.5.46"/>
        <vers num="4.5.47"/>
        <vers num="4.5.48"/>
        <vers num="4.5.49"/>
        <vers num="4.5.50"/>
        <vers num="4.5.51"/>
        <vers num="4.5.52"/>
        <vers num="4.5.55"/>
        <vers num="4.6"/>
      </prod>
      <prod vendor="sgi" name="propack">
        <vers num="2.3"/>
        <vers num="2.4"/>
      </prod>
      <prod vendor="gentoo" name="linux">
        <vers num="0.5"/>
        <vers num="0.7"/>
        <vers num="1.1a"/>
        <vers num="1.2"/>
        <vers num="1.4" edition="rc1"/>
        <vers num="1.4" edition="rc2"/>
        <vers num="1.4" edition="rc3"/>
      </prod>
      <prod vendor="slackware" name="slackware_linux">
        <vers num="9.0"/>
        <vers num="9.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0227" published="2004-06-14" name="CVE-2004-0227" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in the zms script in ZoneMinder before 1.19.2 may allow a remote attacker to execute arbitrary code via a long query string.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input buffer="1"/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/16136" source="XF" patch="1" adv="1">zoneminder-zms-bo(16136)</ref>
      <ref url="http://www.securityfocus.com/bid/10340" source="BID" patch="1" adv="1">10340</ref>
      <ref url="http://www.zoneminder.com/index.php?id=20&amp;type=0&amp;backPID=20&amp;tt_news=29" source="CONFIRM" adv="1">http://www.zoneminder.com/index.php?id=20&amp;type=0&amp;backPID=20&amp;tt_news=29</ref>
    </refs>
    <vuln_soft>
      <prod vendor="triornis" name="zoneminder">
        <vers num="1.17.0"/>
        <vers num="1.17.1"/>
        <vers num="1.17.2"/>
        <vers num="1.18.0"/>
        <vers num="1.18.1"/>
        <vers num="1.19.0"/>
        <vers num="1.19.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0228" published="2004-08-18" name="CVE-2004-0228" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Integer signedness error in the cpufreq proc handler (cpufreq_procctl) in Linux kernel 2.6 allows local users to gain privileges.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1" admin="1"/>
    </loss_types>
    <vuln_types>
      <design/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://www.novell.com/linux/security/advisories/2004_10_kernel.html" source="SUSE">SuSE-SA:2004:010</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200407-02.xml" source="GENTOO" adv="1">GLSA-200407-02</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15951" source="XF">linux-cpufreq-info-disclosure(15951)</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2004:050" source="MANDRAKE">MDKSA-2004:050</ref>
      <ref url="http://secunia.com/advisories/11683" source="SECUNIA">11683</ref>
      <ref url="http://secunia.com/advisories/11491" source="SECUNIA">11491</ref>
      <ref url="http://secunia.com/advisories/11486" source="SECUNIA">11486</ref>
      <ref url="http://secunia.com/advisories/11464" source="SECUNIA">11464</ref>
      <ref url="http://secunia.com/advisories/11429" source="SECUNIA">11429</ref>
      <ref url="http://fedoranews.org/updates/FEDORA-2004-111.shtml" source="FEDORA">FEDORA-2004-111</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000852" source="CONECTIVA">CLA-2004:852</ref>
    </refs>
    <vuln_soft>
      <prod vendor="linux" name="linux_kernel">
        <vers num="2.6.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0229" published="2004-08-18" name="CVE-2004-0229" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">The framebuffer driver in Linux kernel 2.6.x does not properly use the fb_copy_cmap function, with unknown impact.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <design/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/15974" source="XF" adv="1">linux-framebuffer(15974)</ref>
      <ref url="http://www.securityfocus.com/bid/10211" source="BID" adv="1">10211</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2004_10_kernel.html" source="SUSE">SuSE-SA:2004:010</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200407-02.xml" source="GENTOO" adv="1">GLSA-200407-02</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2004:037" source="MANDRAKE">MDKSA-2004:037</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000852" source="CONECTIVA">CLA-2004:852</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gentoo" name="linux">
        <vers num="1.4"/>
      </prod>
      <prod vendor="linux" name="linux_kernel">
        <vers num="2.4.20"/>
        <vers num="2.4.21" edition="pre1"/>
        <vers num="2.4.21" edition="pre4"/>
        <vers num="2.4.21" edition="pre7"/>
        <vers num="2.4.22"/>
        <vers num="2.4.23" edition="pre9"/>
        <vers num="2.4.23_ow2"/>
        <vers num="2.4.24"/>
        <vers num="2.4.24_ow1"/>
        <vers num="2.4.25"/>
        <vers num="2.4.26"/>
        <vers num="2.6.0" edition="test1"/>
        <vers num="2.6.0" edition="test10"/>
        <vers num="2.6.0" edition="test11"/>
        <vers num="2.6.0" edition="test2"/>
        <vers num="2.6.0" edition="test3"/>
        <vers num="2.6.0" edition="test4"/>
        <vers num="2.6.0" edition="test5"/>
        <vers num="2.6.0" edition="test6"/>
        <vers num="2.6.0" edition="test7"/>
        <vers num="2.6.0" edition="test8"/>
        <vers num="2.6.0" edition="test9"/>
        <vers num="2.6.1" edition="rc1"/>
        <vers num="2.6.1" edition="rc2"/>
        <vers num="2.6.2"/>
        <vers num="2.6.3"/>
        <vers num="2.6.4"/>
        <vers num="2.6.5"/>
        <vers num="2.6_test9_cvs"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0230" published="2004-08-18" name="CVE-2004-0230" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">TCP, when using a large Window Size, makes it easier for remote attackers to guess sequence numbers and cause a denial of service (connection loss) to persistent TCP connections by repeatedly injecting a TCP RST packet, especially in protocols that use long-lived connections, such as BGP.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <vuln_types>
      <design/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA04-111A.html" source="CERT" adv="1">TA04-111A</ref>
      <ref url="http://www.kb.cert.org/vuls/id/415294" source="CERT-VN">VU#415294</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15886" source="XF" adv="1">tcp-rst-dos(15886)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/3983" source="VUPEN">ADV-2006-3983</ref>
      <ref url="http://www.uniras.gov.uk/vuls/2004/236929/index.htm" source="MISC">http://www.uniras.gov.uk/vuls/2004/236929/index.htm</ref>
      <ref url="http://www.securityfocus.com/bid/10183" source="BID" adv="1">10183</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/449179/100/0/threaded" source="HP">SSRT061264</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms05-019.mspx" source="MS">MS05-019</ref>
      <ref url="http://www.juniper.net/support/alert.html" source="CONFIRM">http://www.juniper.net/support/alert.html</ref>
      <ref url="http://www.cisco.com/warp/public/707/cisco-sa-20040420-tcp-ios.shtml" source="CISCO">20040420 TCP Vulnerabilities in Multiple IOS-Based Cisco Products</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5711" source="OVAL">oval:org.mitre.oval:def:5711</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108302060014745&amp;w=2" source="BUGTRAQ">20040425 Perl code exploting TCP not checking RST ACK.</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/20040403-01-A.asc" source="SGI">20040403-01-A</ref>
      <ref url="ftp://ftp.sco.com/pub/updates/UnixWare/SCOSA-2005.14/SCOSA-2005.14.txt" source="SCO">SCOSA-2005.14</ref>
      <ref url="ftp://ftp.sco.com/pub/updates/OpenServer/SCOSA-2005.9/SCOSA-2005.9.txt" source="SCO">SCOSA-2005.9</ref>
      <ref url="ftp://ftp.sco.com/pub/updates/OpenServer/SCOSA-2005.3/SCOSA-2005.3.txt" source="SCO">SCOSA-2005.3</ref>
      <ref url="ftp://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2004-006.txt.asc" source="NETBSD">NetBSD-SA2004-006</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/449179/100/0/threaded" source="HP">SSRT061264</ref>
      <ref url="http://www.osvdb.org/4030" source="OSVDB">4030</ref>
      <ref url="http://www.microsoft.com/technet/security/Bulletin/MS06-064.mspx" source="MS">MS06-064</ref>
      <ref url="http://secunia.com/advisories/22341" source="SECUNIA">22341</ref>
      <ref url="http://secunia.com/advisories/11458" source="SECUNIA">11458</ref>
      <ref url="http://secunia.com/advisories/11440" source="SECUNIA">11440</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108506952116653&amp;w=2" source="HP">SSRT4696</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:4791" source="OVAL" sig="1">oval:org.mitre.oval:def:4791</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:3508" source="OVAL" sig="1">oval:org.mitre.oval:def:3508</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:270" source="OVAL" sig="1">oval:org.mitre.oval:def:270</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2689" source="OVAL" sig="1">oval:org.mitre.oval:def:2689</ref>
    </refs>
    <vuln_soft>
      <prod vendor="tcp" name="tcp">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2004-0231" published="2004-08-18" name="CVE-2004-0231" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">Multiple vulnerabilities in Midnight Commander (mc) before 4.6.0, with unknown impact, related to "Insecure temporary file and directory creations."</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <vuln_types>
      <design/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://www.debian.org/security/2004/dsa-497" source="DEBIAN" patch="1" adv="1">DSA-497</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/16020" source="XF" adv="1">midnight-commander-insecure-files(16020)</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-172.html" source="REDHAT">RHSA-2004:172</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2004_12_mc.html" source="SUSE">SuSE-SA:2004:012</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200405-21.xml" source="GENTOO" adv="1">GLSA-200405-21</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2004:039" source="MANDRAKE">MDKSA-2004:039</ref>
    </refs>
    <vuln_soft>
      <prod vendor="midnight_commander" name="midnight_commander">
        <vers num="4.5.40"/>
        <vers num="4.5.41"/>
        <vers num="4.5.42"/>
        <vers num="4.5.43"/>
        <vers num="4.5.44"/>
        <vers num="4.5.45"/>
        <vers num="4.5.46"/>
        <vers num="4.5.47"/>
        <vers num="4.5.48"/>
        <vers num="4.5.49"/>
        <vers num="4.5.50"/>
        <vers num="4.5.51"/>
        <vers num="4.5.52"/>
        <vers num="4.5.55"/>
        <vers num="4.6"/>
      </prod>
      <prod vendor="sgi" name="propack">
        <vers num="2.3"/>
        <vers num="2.4"/>
      </prod>
      <prod vendor="gentoo" name="linux">
        <vers num="0.5"/>
        <vers num="0.7"/>
        <vers num="1.1a"/>
        <vers num="1.2"/>
        <vers num="1.4" edition="rc1"/>
        <vers num="1.4" edition="rc2"/>
        <vers num="1.4" edition="rc3"/>
      </prod>
      <prod vendor="slackware" name="slackware_linux">
        <vers num="9.0"/>
        <vers num="9.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0232" published="2004-08-18" name="CVE-2004-0232" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Multiple format string vulnerabilities in Midnight Commander (mc) before 4.6.0 may allow attackers to cause a denial of service or execute arbitrary code.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/16021" source="XF" adv="1">midnight-commander-format-string(16021)</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-172.html" source="REDHAT">RHSA-2004:172</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2004_12_mc.html" source="SUSE">SuSE-SA:2004:012</ref>
      <ref url="http://www.debian.org/security/2004/dsa-497" source="DEBIAN">DSA-497</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200405-21.xml" source="GENTOO">GLSA-200405-21</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2004:039" source="MANDRAKE">MDKSA-2004:039</ref>
    </refs>
    <vuln_soft>
      <prod vendor="midnight_commander" name="midnight_commander">
        <vers num="4.5.40"/>
        <vers num="4.5.41"/>
        <vers num="4.5.42"/>
        <vers num="4.5.43"/>
        <vers num="4.5.44"/>
        <vers num="4.5.45"/>
        <vers num="4.5.46"/>
        <vers num="4.5.47"/>
        <vers num="4.5.48"/>
        <vers num="4.5.49"/>
        <vers num="4.5.50"/>
        <vers num="4.5.51"/>
        <vers num="4.5.52"/>
        <vers num="4.5.55"/>
        <vers num="4.6"/>
      </prod>
      <prod vendor="sgi" name="propack">
        <vers num="2.3"/>
        <vers num="2.4"/>
      </prod>
      <prod vendor="gentoo" name="linux">
        <vers num="0.5"/>
        <vers num="0.7"/>
        <vers num="1.1a"/>
        <vers num="1.2"/>
        <vers num="1.4" edition="rc1"/>
        <vers num="1.4" edition="rc2"/>
        <vers num="1.4" edition="rc3"/>
      </prod>
      <prod vendor="slackware" name="slackware_linux">
        <vers num="9.0"/>
        <vers num="9.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2004-0233" published="2004-08-18" name="CVE-2004-0233" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">Utempter allows device names that contain .. (dot dot) directory traversal sequences, which allows local users to overwrite arbitrary files via a symlink attack on device names in combination with an application that trusts the utmp or wtmp files.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/10178" source="BID" patch="1" adv="1">10178</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-174.html" source="REDHAT" patch="1" adv="1">RHSA-2004:174</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15904" source="XF" adv="1">utemper-symlink(15904)</ref>
      <ref url="http://www.slackware.com/security/viewer.php?l=slackware-security&amp;y=2004&amp;m=slackware-security.404389" source="SLACKWARE">SSA:2004-110</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-175.html" source="REDHAT">RHSA-2004:175</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-77-1000752.1-1" source="SUNALERT">1000752</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200405-05.xml" source="GENTOO">GLSA-200405-05</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10115" source="OVAL">oval:org.mitre.oval:def:10115</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2004:031" source="MANDRAKE">MDKSA-2004:031</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:979" source="OVAL" sig="1">oval:org.mitre.oval:def:979</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sgi" name="propack">
        <vers num="2.4"/>
        <vers num="3.0"/>
      </prod>
      <prod vendor="utempter" name="utempter">
        <vers num="0.5.2"/>
        <vers num="0.5.3"/>
      </prod>
      <prod vendor="slackware" name="slackware_linux">
        <vers num="9.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0234" published="2004-08-18" name="CVE-2004-0234" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Multiple stack-based buffer overflows in the get_header function in header.c for LHA 1.14, as used in products such as Barracuda Spam Firewall, allow remote attackers or local users to execute arbitrary code via long directory or file names in an LHA archive, which triggers the overflow when testing or extracting the archive.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1" admin="1"/>
    </loss_types>
    <vuln_types>
      <input buffer="1"/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/10243" source="BID" patch="1" adv="1">10243</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108422737918885&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20040510 [Ulf Harnhammar]: LHA Advisory + Patch</ref>
      <ref url="https://bugzilla.fedora.us/show_bug.cgi?id=1833" source="FEDORA">FLSA:1833</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/16012" source="XF" adv="1">lha-multiple-bo(16012)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1220" source="VUPEN" adv="1">ADV-2006-1220</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-179.html" source="REDHAT">RHSA-2004:179</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-178.html" source="REDHAT">RHSA-2004:178</ref>
      <ref url="http://www.redhat.com/archives/fedora-announce-list/2004-May/msg00005.html" source="FEDORA">FEDORA-2004-119</ref>
      <ref url="http://www.osvdb.org/5754" source="OSVDB">5754</ref>
      <ref url="http://www.osvdb.org/5753" source="OSVDB">5753</ref>
      <ref url="http://www.guay-leroux.com/projects/barracuda-advisory-LHA.txt" source="MISC">http://www.guay-leroux.com/projects/barracuda-advisory-LHA.txt</ref>
      <ref url="http://www.debian.org/security/2004/dsa-515" source="DEBIAN">DSA-515</ref>
      <ref url="http://securitytracker.com/id?1015866" source="SECTRACK">1015866</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200405-02.xml" source="GENTOO">GLSA-200405-02</ref>
      <ref url="http://secunia.com/advisories/19514" source="SECUNIA" adv="1">19514</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9881" source="OVAL">oval:org.mitre.oval:def:9881</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2004-May/020778.html" source="FULLDISC">20040502 Lha local stack overflow Proof Of Concept Code</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2004-May/020776.html" source="FULLDISC">20040501 LHa buffer overflows and directory traversal problems</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000840" source="CONECTIVA">CLA-2004:840</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2006-04/0059.html" source="BUGTRAQ">20060403 Barracuda LHA archiver security bug leads to remote compromise</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:977" source="OVAL" sig="1">oval:org.mitre.oval:def:977</ref>
    </refs>
    <vuln_soft>
      <prod vendor="clearswift" name="mailsweeper">
        <vers num="4.0"/>
        <vers num="4.1"/>
        <vers num="4.2"/>
        <vers num="4.3"/>
        <vers num="4.3.10"/>
        <vers num="4.3.11"/>
        <vers num="4.3.13"/>
        <vers num="4.3.3"/>
        <vers num="4.3.4"/>
        <vers num="4.3.5"/>
        <vers num="4.3.6"/>
        <vers num="4.3.6_sp1"/>
        <vers num="4.3.7"/>
        <vers num="4.3.8"/>
      </prod>
      <prod vendor="f-secure" name="f-secure_anti-virus">
        <vers num="2003"/>
        <vers num="2004"/>
        <vers num="4.51" edition=""/>
        <vers num="4.51" edition=":linux_workstations"/>
        <vers num="4.51" edition=":linux_servers"/>
        <vers num="4.51" edition=":linux_gateways"/>
        <vers num="4.52" edition=""/>
        <vers num="4.52" edition=":linux_servers"/>
        <vers num="4.52" edition=":linux_workstations"/>
        <vers num="4.52" edition=":linux_gateways"/>
        <vers num="4.60" edition=""/>
        <vers num="4.60" edition=":samba_servers"/>
        <vers num="5.41" edition=""/>
        <vers num="5.41" edition=":windows_servers"/>
        <vers num="5.41" edition=":mimesweeper"/>
        <vers num="5.41" edition=":workstations"/>
        <vers num="5.42" edition=""/>
        <vers num="5.42" edition=":windows_servers"/>
        <vers num="5.42" edition=":workstations"/>
        <vers num="5.42" edition=":mimesweeper"/>
        <vers num="5.5" edition=""/>
        <vers num="5.5" edition=":client_security"/>
        <vers num="5.52" edition=""/>
        <vers num="5.52" edition=":client_security"/>
        <vers num="6.21" edition=""/>
        <vers num="6.21" edition=":ms_exchange"/>
      </prod>
      <prod vendor="f-secure" name="f-secure_for_firewalls">
        <vers num="6.20"/>
      </prod>
      <prod vendor="f-secure" name="f-secure_internet_security">
        <vers num="2003"/>
        <vers num="2004"/>
      </prod>
      <prod vendor="f-secure" name="f-secure_personal_express">
        <vers num="4.5"/>
        <vers num="4.6"/>
        <vers num="4.7"/>
      </prod>
      <prod vendor="f-secure" name="internet_gatekeeper">
        <vers num="6.31"/>
        <vers num="6.32"/>
      </prod>
      <prod vendor="rarlab" name="winrar">
        <vers num="3.20"/>
      </prod>
      <prod vendor="redhat" name="lha">
        <vers num="1.14i-9" edition=""/>
        <vers num="1.14i-9" edition=":i386"/>
      </prod>
      <prod vendor="sgi" name="propack">
        <vers num="2.4"/>
        <vers num="3.0"/>
      </prod>
      <prod vendor="stalker" name="cgpmcafee">
        <vers num="3.2"/>
      </prod>
      <prod vendor="tsugio_okamoto" name="lha">
        <vers num="1.14"/>
        <vers num="1.15"/>
        <vers num="1.17"/>
      </prod>
      <prod vendor="winzip" name="winzip">
        <vers num="9.0"/>
      </prod>
      <prod vendor="redhat" name="fedora_core">
        <vers num="core_1.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0235" published="2004-08-18" name="CVE-2004-0235" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)" CVSS_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_base_score="6.4">
    <desc>
      <descript source="cve">Multiple directory traversal vulnerabilities in LHA 1.14 allow remote attackers or local users to create arbitrary files via an LHA archive containing filenames with (1) .. sequences or (2) absolute pathnames with double leading slashes ("//absolute/path").</descript>
    </desc>
    <loss_types>
      <conf/>
      <int/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/10243" source="BID" patch="1" adv="1">10243</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108422737918885&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20040510 [Ulf Harnhammar]: LHA Advisory + Patch</ref>
      <ref url="https://bugzilla.fedora.us/show_bug.cgi?id=1833" source="FEDORA">FLSA:1833</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/16013" source="XF" adv="1">lha-directory-traversal(16013)</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-179.html" source="REDHAT">RHSA-2004:179</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-178.html" source="REDHAT">RHSA-2004:178</ref>
      <ref url="http://www.redhat.com/archives/fedora-announce-list/2004-May/msg00005.html" source="FEDORA">FEDORA-2004-119</ref>
      <ref url="http://www.debian.org/security/2004/dsa-515" source="DEBIAN">DSA-515</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200405-02.xml" source="GENTOO">GLSA-200405-02</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10409" source="OVAL">oval:org.mitre.oval:def:10409</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2004-May/020776.html" source="FULLDISC">20040501 LHa buffer overflows and directory traversal problems</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000840" source="CONECTIVA">CLA-2004:840</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:978" source="OVAL" sig="1">oval:org.mitre.oval:def:978</ref>
    </refs>
    <vuln_soft>
      <prod vendor="clearswift" name="mailsweeper">
        <vers num="4.0"/>
        <vers num="4.1"/>
        <vers num="4.2"/>
        <vers num="4.3"/>
        <vers num="4.3.10"/>
        <vers num="4.3.11"/>
        <vers num="4.3.13"/>
        <vers num="4.3.3"/>
        <vers num="4.3.4"/>
        <vers num="4.3.5"/>
        <vers num="4.3.6"/>
        <vers num="4.3.6_sp1"/>
        <vers num="4.3.7"/>
        <vers num="4.3.8"/>
      </prod>
      <prod vendor="f-secure" name="f-secure_anti-virus">
        <vers num="2003"/>
        <vers num="2004"/>
        <vers num="4.51" edition=""/>
        <vers num="4.51" edition=":linux_workstations"/>
        <vers num="4.51" edition=":linux_servers"/>
        <vers num="4.51" edition=":linux_gateways"/>
        <vers num="4.52" edition=""/>
        <vers num="4.52" edition=":linux_servers"/>
        <vers num="4.52" edition=":linux_workstations"/>
        <vers num="4.52" edition=":linux_gateways"/>
        <vers num="4.60" edition=""/>
        <vers num="4.60" edition=":samba_servers"/>
        <vers num="5.41" edition=""/>
        <vers num="5.41" edition=":windows_servers"/>
        <vers num="5.41" edition=":mimesweeper"/>
        <vers num="5.41" edition=":workstations"/>
        <vers num="5.42" edition=""/>
        <vers num="5.42" edition=":windows_servers"/>
        <vers num="5.42" edition=":workstations"/>
        <vers num="5.42" edition=":mimesweeper"/>
        <vers num="5.5" edition=""/>
        <vers num="5.5" edition=":client_security"/>
        <vers num="5.52" edition=""/>
        <vers num="5.52" edition=":client_security"/>
        <vers num="6.21" edition=""/>
        <vers num="6.21" edition=":ms_exchange"/>
      </prod>
      <prod vendor="f-secure" name="f-secure_for_firewalls">
        <vers num="6.20"/>
      </prod>
      <prod vendor="f-secure" name="f-secure_internet_security">
        <vers num="2003"/>
        <vers num="2004"/>
      </prod>
      <prod vendor="f-secure" name="f-secure_personal_express">
        <vers num="4.5"/>
        <vers num="4.6"/>
        <vers num="4.7"/>
      </prod>
      <prod vendor="f-secure" name="internet_gatekeeper">
        <vers num="6.31"/>
        <vers num="6.32"/>
      </prod>
      <prod vendor="rarlab" name="winrar">
        <vers num="3.20"/>
      </prod>
      <prod vendor="redhat" name="lha">
        <vers num="1.14i-9" edition=""/>
        <vers num="1.14i-9" edition=":i386"/>
      </prod>
      <prod vendor="sgi" name="propack">
        <vers num="2.4"/>
        <vers num="3.0"/>
      </prod>
      <prod vendor="stalker" name="cgpmcafee">
        <vers num="3.2"/>
      </prod>
      <prod vendor="tsugio_okamoto" name="lha">
        <vers num="1.14"/>
        <vers num="1.15"/>
        <vers num="1.17"/>
      </prod>
      <prod vendor="winzip" name="winzip">
        <vers num="9.0"/>
      </prod>
      <prod vendor="redhat" name="fedora_core">
        <vers num="core_1.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0236" published="2004-11-23" name="CVE-2004-0236" modified="2009-01-29" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">SQL injection vulnerability in login.asp in thePHOTOtool allows remote attackers to gain unauthorized access via the password field.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1" admin="1"/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/15007" source="XF" adv="1">thephototool-login-sql-injection(15007)</ref>
      <ref url="http://www.securityfocus.com/bid/9884" source="BID" adv="1">9884</ref>
      <ref url="http://www.osvdb.org/6727" source="OSVDB">6727</ref>
      <ref url="http://securitytracker.com/alerts/2004/Feb/1008906.html" source="SECTRACK">1008906</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107576894019530&amp;w=2" source="BUGTRAQ" adv="1">20040131 Advisory !</ref>
    </refs>
    <vuln_soft>
      <prod vendor="steelid" name="thephototool">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0237" published="2004-11-23" name="CVE-2004-0237" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in index.php in Aprox PHP Portal allows remote attackers to read arbitrary files via a full pathname in the show parameter.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/15014" source="XF" adv="1">aproxphpportal-index-directory-traversal(15014)</ref>
      <ref url="http://www.securityfocus.com/bid/9540" source="BID" adv="1">9540</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107577555527321&amp;w=2" source="BUGTRAQ" adv="1">20040131 Directory Traversal in Aprox PHP Portal.</ref>
      <ref url="http://www.osvdb.org/10859" source="OSVDB">10859</ref>
      <ref url="http://securitytracker.com/id?1008915" source="SECTRACK">1008915</ref>
    </refs>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0238" published="2004-11-23" name="CVE-2004-0238" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Multiple buffer overflows in Overkill (0verkill) 0.15pre3 might allow local users to execute arbitrary code in the client via a long HOME environment variable in the (1) load_cfg and (2) save_cfg functions; possibly allow remote attackers to execute arbitrary code via long strings to (3) the send_message function; and, in the server, via (4) the parse_command_line function.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1" admin="1"/>
    </loss_types>
    <vuln_types>
      <input buffer="1"/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/15000" source="XF">overkill-server-parsecommandline-bo(15000)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/14999" source="XF" adv="1">overkill-client-multiple-bo(14999)</ref>
      <ref url="http://www.securityfocus.com/bid/9550" source="BID" adv="1">9550</ref>
      <ref url="http://www.securiteam.com/securitynews/5AP010KC0C.html" source="MISC">http://www.securiteam.com/securitynews/5AP010KC0C.html</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107577335424509&amp;w=2" source="BUGTRAQ" adv="1">20040202 0verkill - little simple vulnerability.</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2004-February/016579.html" source="FULLDISC">20040202 0verkill - little simple vulnerability.</ref>
    </refs>
    <vuln_soft>
      <prod vendor="0verkill" name="0verkill">
        <vers num="0.16"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0239" published="2004-11-23" name="CVE-2004-0239" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">SQL injection vulnerability in showphoto.php in PhotoPost PHP Pro 4.6 and earlier allows remote attackers to gain unauthorized access via the photo variable.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1" admin="1"/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/15008" source="XF" adv="1">photopostphp-sql-injection(15008)</ref>
      <ref url="http://www.securityfocus.com/bid/9557" source="BID" adv="1">9557</ref>
      <ref url="http://www.securiteam.com/securitynews/5KP010UC0W.html" source="MISC">http://www.securiteam.com/securitynews/5KP010UC0W.html</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107582512023998&amp;w=2" source="BUGTRAQ">20040202 ZH2004-03SA (security advisory): Photopost PHP Pro 4.6 Sql</ref>
    </refs>
    <vuln_soft>
      <prod vendor="photopost" name="photopost_php_pro">
        <vers num="3.1"/>
        <vers num="3.2"/>
        <vers num="3.3"/>
        <vers num="4.0"/>
        <vers num="4.1"/>
        <vers num="4.6"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0240" published="2004-11-23" name="CVE-2004-0240" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in X-Cart 3.4.3 allows remote attackers to view arbitrary files via a .. (dot dot) in the shop_closed_file argument to auth.php.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/15033" source="XF" adv="1">xcart-dotdot-directory-traversal(15033)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107582648326448&amp;w=2" source="BUGTRAQ" adv="1">20040203 X-Cart vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="qualiteam" name="x-cart">
        <vers num="3.2.0"/>
        <vers num="3.2.1"/>
        <vers num="3.3.0"/>
        <vers num="3.3.2"/>
        <vers num="3.4.0"/>
        <vers num="3.4.11"/>
        <vers num="3.4.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0241" published="2004-11-23" name="CVE-2004-0241" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">X-Cart 3.4.3 allows remote attackers to execute arbitrary commands via the perl_binary argument in (1) upgrade.php or (2) general.php.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1" admin="1"/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/9560" source="BID" patch="1" adv="1">9560</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15034" source="XF" adv="1">xcart-perlbinary-execute-commands(15034)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107582648326448&amp;w=2" source="BUGTRAQ" adv="1">20040203 X-Cart vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="qualiteam" name="x-cart">
        <vers num="3.2.0"/>
        <vers num="3.2.1"/>
        <vers num="3.3.0"/>
        <vers num="3.3.2"/>
        <vers num="3.4.0"/>
        <vers num="3.4.11"/>
        <vers num="3.4.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0242" published="2004-11-23" name="CVE-2004-0242" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">X-Cart 3.4.3 allows remote attackers to gain sensitive information via a mode parameter with (1) phpinfo command or (2) perlinfo command.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/9563" source="BID" patch="1" adv="1">9563</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15036" source="XF" adv="1">xcart-generalphp-obtain-information(15036)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107582648326448&amp;w=2" source="BUGTRAQ" adv="1">20040203 X-Cart vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="qualiteam" name="x-cart">
        <vers num="3.2.0"/>
        <vers num="3.2.1"/>
        <vers num="3.3.0"/>
        <vers num="3.3.2"/>
        <vers num="3.4.0"/>
        <vers num="3.4.11"/>
        <vers num="3.4.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0243" published="2004-11-23" name="CVE-2004-0243" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">AIX 4.3.3 through AIX 5.1, when direct remote login is disabled, displays a different message if the password is correct, which allows remote attackers to guess the password via brute force methods.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <vuln_types>
      <design/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/15172" source="XF">aix-password-enumeration(15172)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107583269206044&amp;w=2" source="BUGTRAQ" adv="1">20040203 Re: sqwebmail web login</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2004-02/0313.html" source="BUGTRAQ">20040206 AIX password enumeration possible</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="aix">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0244" published="2004-11-23" name="CVE-2004-0244" modified="2009-03-04" CVSS_version="2.0" CVSS_vector="(AV:L/AC:M/Au:N/C:N/I:N/A:C)" CVSS_score="4.7" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="3.4" CVSS_base_score="4.7">
    <desc>
      <descript source="cve">Cisco 6000, 6500, and 7600 series systems with Multilayer Switch Feature Card 2 (MSFC2) and a FlexWAN or OSM module allow local users to cause a denial of service (hang or reset) by sending a layer 2 frame packet that encapsulates a layer 3 packet, but has inconsistent length values with that packet.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <vuln_types>
      <exception/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/810062" source="CERT-VN">VU#810062</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15013" source="XF" adv="1">cisco-malformed-frame-dos(15013)</ref>
      <ref url="http://www.securityfocus.com/bid/9562" source="BID" adv="1">9562</ref>
      <ref url="http://www.cisco.com/warp/public/707/cisco-sa-20040203-cat6k.shtml" source="CISCO" adv="1">20040203 Cisco 6000/6500/7600 Crafted Layer 2 Frame Vulnerability</ref>
      <ref url="http://secunia.com/advisories/10780" source="SECUNIA">10780</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5828" source="OVAL">oval:org.mitre.oval:def:5828</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="ios">
        <vers num="12.1e"/>
        <vers num="12.2sy"/>
        <vers num="12.2za"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0245" published="2004-11-23" name="CVE-2004-0245" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Web Crossing 4.x and 5.x allows remote attackers to cause a denial of service (crash) by sending a HTTP POST request with a large or negative Content-Length, which causes an integer divide-by-zero.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <vuln_types>
      <exception/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107586518120516&amp;w=2" source="BUGTRAQ" adv="1">20040203 Web Crossing 4.x/5.x Denial of Service Vulnerability</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15022" source="XF">webcrossing-contentlength-post-dos(15022)</ref>
      <ref url="http://www.securityfocus.com/bid/9576" source="BID">9576</ref>
    </refs>
    <vuln_soft>
      <prod vendor="web_crossing_inc" name="web_crossing">
        <vers num="4.0"/>
        <vers num="5.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0246" published="2004-11-23" name="CVE-2004-0246" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Multiple PHP remote file inclusion vulnerabilities in (1) fonctions.lib.php, (2) derniers_commentaires.php, and (3) admin.php in Les Commentaires 2.0 allow remote attackers to execute arbitrary PHP code via the rep parameter.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1" admin="1"/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107584083719763&amp;w=2" source="BUGTRAQ" patch="1">20040203 Les Commentaires (PHP) Include file</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15010" source="XF" adv="1">lescommentaires-multiple-file-include(15010)</ref>
      <ref url="http://www.securityfocus.com/bid/9536" source="BID" adv="1">9536</ref>
      <ref url="http://secunia.com/advisories/10768/" source="SECUNIA">10768</ref>
    </refs>
    <vuln_soft>
      <prod vendor="laurent_adda" name="les_commentaires">
        <vers num="2.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0247" published="2004-11-23" name="CVE-2004-0247" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The client and server of Chaser 1.50 and earlier allow remote attackers to cause a denial of service (crash via exception) via a UDP packet with a length field that is greater than the actual data length, which causes Chaser to read unexpected memory.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <vuln_types>
      <input bound="1"/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/15031" source="XF" adv="1">chaser-memory-dos(15031)</ref>
      <ref url="http://www.securityfocus.com/bid/9567" source="BID" adv="1">9567</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107584109420084&amp;w=2" source="BUGTRAQ" adv="1">20040203 Remote crash of Chaser game &lt;= 1.50</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cauldron" name="chaser_client">
        <vers num="1.5"/>
      </prod>
      <prod vendor="cauldron" name="chaser_server">
        <vers num="1.4.9"/>
        <vers num="1.5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0248" published="2004-11-23" name="CVE-2004-0248" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Cross-site scripting vulnerability (XSS) in PHPX 3.2.3 allows remote attackers to execute arbitrary script as other users by injecting arbitrary HTML or script into (1) keywords argument of main.inc.php, (2) body argument of help.inc.php, or (3) the subject field in Personal Messages and Forum.</descript>
    </desc>
    <sols>
      <sol source="nvd">This vulnerability is addressed in the following product release:
PHPX, PHPX, 3.2.4</sol>
    </sols>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/15051" source="XF" patch="1">phpx-main-help-xss(15051)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15050" source="XF" patch="1">phpx-subject-html-injection(15050)</ref>
      <ref url="http://www.securityfocus.com/bid/9569" source="BID" patch="1">9569</ref>
      <ref url="http://secunia.com/advisories/10797/" source="SECUNIA" patch="1" adv="1">10797</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107586932324901&amp;w=2" source="BUGTRAQ" patch="1">20040203 Multiple Vulnerabilities in PHPX</ref>
    </refs>
    <vuln_soft>
      <prod vendor="phpx" name="phpx">
        <vers num="3.2.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0249" published="2004-11-23" name="CVE-2004-0249" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">PHPX 2.0 through 3.2.4 allows remote attackers to gain access to other accounts by modifying the cookie's PXL variable to reference another userID.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1" admin="1"/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/9569" source="BID" patch="1" adv="1">9569</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15052" source="XF" adv="1">phpx-cookie-account-hijacking(15052)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107586932324901&amp;w=2" source="BUGTRAQ" adv="1">20040203 Multiple Vulnerabilities in PHPX</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15512" source="XF">phpx-session-hijack(15512)</ref>
      <ref url="http://secunia.com/advisories/10797/" source="SECUNIA">10797</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2004-03/0154.html" source="BUGTRAQ">20040316 PHPX 2.x - 3.2.4</ref>
    </refs>
    <vuln_soft>
      <prod vendor="phpx" name="phpx">
        <vers num="3.2.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0250" published="2004-11-23" name="CVE-2004-0250" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">SQL injection vulnerability in PhotoPost PHP Pro 4.6 and earlier allows remote attackers to gain privileges via (1) the product parameter in showproduct.php or (2) the cat parameter in showcat.php.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1" admin="1"/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107593114909696&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20040204 ZH2004-04SA (security advisory): Multiple Sql Injection</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15008" source="XF" adv="1">photopostphp-sql-injection(15008)</ref>
      <ref url="http://www.zone-h.org/en/advisories/read/id=3864/" source="MISC">http://www.zone-h.org/en/advisories/read/id=3864/</ref>
      <ref url="http://www.securityfocus.com/bid/9557" source="BID" adv="1">9557</ref>
    </refs>
    <vuln_soft>
      <prod vendor="photopost" name="photopost_php_pro">
        <vers num="3.1"/>
        <vers num="3.2"/>
        <vers num="3.3"/>
        <vers num="4.0"/>
        <vers num="4.1"/>
        <vers num="4.6"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0251" published="2004-11-23" name="CVE-2004-0251" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in rxgoogle.cgi allows remote attackers to execute arbitrary script as other users via the query parameter.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107594183924958&amp;w=2" source="BUGTRAQ" patch="1">20040204 rxgoogle.cgi XSS Vulnerability.</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15043" source="XF">rxgoogle-query-xss(15043)</ref>
      <ref url="http://www.securityfocus.com/bid/9575" source="BID">9575</ref>
    </refs>
    <vuln_soft>
      <prod vendor="rxgoogle.cgi" name="rxgoogle.cgi">
        <vers num="1.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0252" published="2004-11-23" name="CVE-2004-0252" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">TYPSoft FTP Server 1.10 allows remote attackers to cause a denial of service (CPU consumption) via an empty USER name.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <vuln_types>
      <input/>
      <exception/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/15048" source="XF" adv="1">typsoft-empty-username-dos(15048)</ref>
      <ref url="http://www.securityfocus.com/bid/9573" source="BID" adv="1">9573</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107591511716707&amp;w=2" source="BUGTRAQ" adv="1">20040204 TYPSoft FTP Server 1.10 may be crashed</ref>
      <ref url="http://www.securitytracker.com/alerts/2004/Feb/1008943.html" source="SECTRACK">1008943</ref>
    </refs>
    <vuln_soft>
      <prod vendor="typsoft" name="typsoft_ftp_server">
        <vers num="1.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0253" published="2004-11-23" name="CVE-2004-0253" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">IBM Cloudscape 5.1 running jdk 1.4.2_03 allows remote attackers to execute arbitrary programs or cause a denial of service via certain SQL code, possibly due to a SQL injection vulnerability.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1" admin="1"/>
    </loss_types>
    <vuln_types>
      <input/>
      <config/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/15067" source="XF" adv="1">cloudscape-sql-injection(15067)</ref>
      <ref url="http://www.securityfocus.com/bid/9583" source="BID" adv="1">9583</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107604065819233&amp;w=2" source="BUGTRAQ" adv="1">20040205 IBM cloudscape SQL Database (DB2J) vulnerable to remote command</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="cloudscape">
        <vers num="5.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0254" published="2004-11-23" name="CVE-2004-0254" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in Discuz! Board 2.x and 3.x allows remote attackers to execute arbitrary script as other users via an img tag.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/15066" source="XF">discuzboard-image-tag-xss(15066)</ref>
      <ref url="http://www.securityfocus.com/bid/9584" source="BID">9584</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107606726417150&amp;w=2" source="BUGTRAQ">20040205 Possible Cross Site Scripting in Discuz! Board</ref>
    </refs>
    <vuln_soft>
      <prod vendor="crosscom_olicom" name="discuz">
        <vers num="2.0"/>
        <vers num="3.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0255" published="2004-11-23" name="CVE-2004-0255" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Xlight 1.52, with log to screen enabled, allows remote attackers to cause a denial of service by requesting a long directory consisting of . (dot) and / (slash) characters, which causes the server to crash when the administrator views the log file, possibly triggering a buffer overflow.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <vuln_types>
      <input buffer="1"/>
      <config/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/15064" source="XF" adv="1">xlight-long-string-dos(15064)</ref>
      <ref url="http://www.securityfocus.com/bid/9585" source="BID" adv="1">9585</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107605633904122&amp;w=2" source="BUGTRAQ" adv="1">20040205 Remote crash Xlight ftp server 1.52</ref>
    </refs>
    <vuln_soft>
      <prod vendor="xlight_ftp_server" name="xlight_ftp_server">
        <vers num="1.25"/>
        <vers num="1.41"/>
        <vers num="1.45"/>
        <vers num="1.52"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2004-0256" published="2004-11-23" name="CVE-2004-0256" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">GNU libtool before 1.5.2, during compile time, allows local users to overwrite arbitrary files via a symlink attack on libtool directories in /tmp.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <vuln_types>
      <design/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/9530" source="BID" patch="1" adv="1">9530</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15017" source="XF" adv="1">libtool-insecure-temp-directory(15017)</ref>
      <ref url="http://www.securityfocus.com/archive/1/352333" source="BUGTRAQ">20040130 Symlink Vulnerability in GNU libtool &lt;1.5.2</ref>
      <ref url="http://www.osvdb.org/3795" source="OSVDB">3795</ref>
      <ref url="http://www.geocrawler.com/mail/msg.php3?msg_id=3438808&amp;list=405" source="MISC">http://www.geocrawler.com/mail/msg.php3?msg_id=3438808&amp;list=405</ref>
      <ref url="http://secunia.com/advisories/10777" source="SECUNIA">10777</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000811" source="CONECTIVA">CLA-2004:811</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gnu" name="libtool">
        <vers num="1.0"/>
        <vers num="1.1"/>
        <vers num="1.2"/>
        <vers num="1.3"/>
        <vers num="1.3.2"/>
        <vers num="1.3.3"/>
        <vers num="1.3.4"/>
        <vers num="1.3.5"/>
        <vers num="1.4"/>
        <vers num="1.4.1"/>
        <vers num="1.4.2"/>
        <vers num="1.4.3"/>
        <vers num="1.5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0257" published="2004-11-23" name="CVE-2004-0257" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">OpenBSD 3.4 and NetBSD 1.6 and 1.6.1 allow remote attackers to cause a denial of service (crash) by sending an IPv6 packet with a small MTU to a listening port and then issuing a TCP connect to that port.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <vuln_types>
      <exception/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/9577" source="BID" patch="1" adv="1">9577</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15044" source="XF" adv="1">openbsd-ipv6-dos(15044)</ref>
      <ref url="http://www.openbsd.org/cgi-bin/cvsweb/src/sys/netinet6/ip6_output.c" source="CONFIRM">http://www.openbsd.org/cgi-bin/cvsweb/src/sys/netinet6/ip6_output.c</ref>
      <ref url="http://www.guninski.com/obsdmtu.html" source="MISC">http://www.guninski.com/obsdmtu.html</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107604603226564&amp;w=2" source="BUGTRAQ" adv="1">20040205 OpenBSD IPv6 remote kernel crash</ref>
      <ref url="http://www.osvdb.org/3825" source="OSVDB">3825</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2004-February/016704.html" source="FULLDISC">20040204 Remote openbsd crash with ip6, yet still openbsd much better than windows</ref>
      <ref url="ftp://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2004-002.txt.asc" source="NETBSD">NetBSD-SA2004-002</ref>
    </refs>
    <vuln_soft>
      <prod vendor="netbsd" name="netbsd">
        <vers num="1.6"/>
        <vers num="1.6.1"/>
      </prod>
      <prod vendor="openbsd" name="openbsd">
        <vers num="3.0"/>
        <vers num="3.1"/>
        <vers num="3.2"/>
        <vers num="3.3"/>
        <vers num="3.4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0258" published="2004-11-23" name="CVE-2004-0258" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:H/Au:N/C:C/I:C/A:C)" CVSS_score="7.6" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="4.9" CVSS_base_score="7.6">
    <desc>
      <descript source="cve">Multiple buffer overflows in RealOne Player, RealOne Player 2.0, RealOne Enterprise Desktop, and RealPlayer Enterprise allow remote attackers to execute arbitrary code via malformed (1) .RP, (2) .RT, (3) .RAM, (4) .RPM or (5) .SMIL files.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1" admin="1"/>
    </loss_types>
    <vuln_types>
      <input buffer="1"/>
    </vuln_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/473814" source="CERT-VN" adv="1">VU#473814</ref>
      <ref url="http://www.securityfocus.com/bid/9579" source="BID" patch="1" adv="1">9579</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107608748813559&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20040204 Multiple File Format Vulnerabilities (Overruns) in REALOne &amp; RealPlayer</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15040" source="XF" adv="1">realoneplayer-multiple-file-bo(15040)</ref>
      <ref url="http://www.service.real.com/help/faq/security/040123_player/EN/" source="CONFIRM">http://www.service.real.com/help/faq/security/040123_player/EN/</ref>
      <ref url="http://www.nextgenss.com/advisories/realone.txt" source="MISC">http://www.nextgenss.com/advisories/realone.txt</ref>
      <ref url="http://www.ciac.org/ciac/bulletins/o-075.shtml" source="CIAC">O-075</ref>
      <ref url="http://archives.neohapsis.com/archives/vulnwatch/2004-q1/0027.html" source="VULNWATCH">20040204 [VulnWatch] Multiple File Format Vulnerabilities (Overruns) in REALOne &amp; RealPlayer</ref>
    </refs>
    <vuln_soft>
      <prod vendor="realnetworks" name="realone_desktop_manager">
        <vers num=""/>
      </prod>
      <prod vendor="realnetworks" name="realone_enterprise_desktop">
        <vers num="6.0.11.774"/>
      </prod>
      <prod vendor="realnetworks" name="realone_player">
        <vers num="1.0"/>
        <vers num="2.0" edition=""/>
        <vers num="2.0" edition=":win"/>
        <vers num="6.0.11.818"/>
        <vers num="6.0.11.830"/>
        <vers num="6.0.11.841"/>
        <vers num="6.0.11.853"/>
        <vers num="6.0.11.868"/>
      </prod>
      <prod vendor="realnetworks" name="realplayer">
        <vers num="10.0_beta"/>
        <vers num="8.0" edition=""/>
        <vers num="8.0" edition=":win32"/>
        <vers num="8.0" edition=":mac_os"/>
        <vers num="8.0" edition=":unix"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0259" published="2004-11-23" name="CVE-2004-0259" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">The check_referer() function in Formmail.php 5.0 and earlier allows remote attackers to bypass access restrictions via an empty or spoofed HTTP Referer, as demonstrated using an application on the same web server that contains a cross-site scripting (XSS) issue.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1" admin="1"/>
    </loss_types>
    <vuln_types>
      <access/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/15079" source="XF" adv="1">jack-formmail-file-upload(15079)</ref>
      <ref url="http://www.securityfocus.com/bid/9591" source="BID" adv="1">9591</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107619109629629&amp;w=2" source="BUGTRAQ" adv="1">20040206 formmail (PHP) Upload file using CSS</ref>
    </refs>
    <vuln_soft>
      <prod vendor="joe_lumbroso_acks" name="formmail.php">
        <vers num="2.0"/>
        <vers num="5.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0260" published="2004-11-23" name="CVE-2004-0260" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The AddToMailingList function in CactuSoft CactuShop 5.0 Lite contains a backdoor that allows remote attackers to delete arbitrary files via an email address that starts with |||.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <vuln_types>
      <design/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/15063" source="XF" adv="1">cactushoplite-backdoor(15063)</ref>
      <ref url="http://www.securityfocus.com/bid/9589" source="BID" adv="1">9589</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107619501815888&amp;w=2" source="BUGTRAQ" adv="1">20040206 CactuSoft CactuShop 5.0 Lite shopping cart software backdoor</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2004-February/016819.html" source="FULLDISC">20040206 CactuSoft CactuShop 5.0 Lite shopping cart software backdoor</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cactusoft" name="cactushop_lite">
        <vers num="5.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0261" published="2004-11-23" name="CVE-2004-0261" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">oj.cgi in OpenJournal 2.0 through 2.0.5 allows remote attackers to bypass authentication and access the control panel via a 0 in the uid parameter.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1" admin="1"/>
    </loss_types>
    <vuln_types>
      <access/>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/9598" source="BID" patch="1" adv="1">9598</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15069" source="XF" adv="1">openjournal-uid-admin-access(15069)</ref>
      <ref url="http://www.grohol.com/downloads/oj/latest/changelog.txt" source="CONFIRM">http://www.grohol.com/downloads/oj/latest/changelog.txt</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107619136600713&amp;w=2" source="BUGTRAQ" adv="1">20040206 Open Journal Blog Authenticaion Bypassing Vulnerability</ref>
      <ref url="http://www.osvdb.org/3872" source="OSVDB">3872</ref>
    </refs>
    <vuln_soft>
      <prod vendor="openjournal" name="openjournal">
        <vers num="2.0"/>
        <vers num="2.0_1"/>
        <vers num="2.0_2"/>
        <vers num="2.0_3"/>
        <vers num="2.0_4"/>
        <vers num="2.0_5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0262" published="2004-11-23" name="CVE-2004-0262" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Stack-based buffer overflow in The Palace 3.5 and earlier client allows remote attackers to execute arbitrary code via a link to a palace:// url followed by a long server address string.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1" admin="1"/>
    </loss_types>
    <vuln_types>
      <input buffer="1"/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/15074" source="XF" adv="1">palace-server-address-bo(15074)</ref>
      <ref url="http://www.securityfocus.com/bid/9602" source="BID" adv="1">9602</ref>
      <ref url="http://www.elitehaven.net/thepalace.txt" source="MISC">http://www.elitehaven.net/thepalace.txt</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107634556632195&amp;w=2" source="BUGTRAQ" adv="1">20040207 The Palace 3.x (Client) Stack Overflow Vulnerability</ref>
      <ref url="http://archives.neohapsis.com/archives/vulnwatch/2004-q1/0033.html" source="VULNWATCH">20040207 The Palace 3.x (Client) Stack Overflow Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="the_palace" name="the_palace_client">
        <vers num="3.5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0263" published="2004-11-23" name="CVE-2004-0263" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">PHP 4.3.4 and earlier in Apache 1.x and 2.x (mod_php) can leak global variables between virtual hosts that are handled by the same Apache child process but have different settings, which could allow remote attackers to obtain sensitive information.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <vuln_types>
      <access/>
      <config/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/15072" source="XF" patch="1" adv="1">php-virtualhost-info-disclosure(15072)</ref>
      <ref url="http://www.securityfocus.com/bid/9599" source="BID" adv="1">9599</ref>
      <ref url="http://www.osvdb.org/3878" source="OSVDB">3878</ref>
      <ref url="http://http://security.gentoo.org/glsa/glsa-200402-01.xml" source="GENTOO">GLSA-200402-01</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apache" name="http_server">
        <vers num="1.0"/>
        <vers num="1.0.2"/>
        <vers num="1.0.3"/>
        <vers num="1.0.5"/>
        <vers num="1.1"/>
        <vers num="1.1.1"/>
        <vers num="1.2"/>
        <vers num="1.2.5"/>
        <vers num="1.3"/>
        <vers num="1.3.1"/>
        <vers num="1.3.11"/>
        <vers num="1.3.12"/>
        <vers num="1.3.14"/>
        <vers num="1.3.17"/>
        <vers num="1.3.18"/>
        <vers num="1.3.19"/>
        <vers num="1.3.20"/>
        <vers num="1.3.22"/>
        <vers num="1.3.23"/>
        <vers num="1.3.24"/>
        <vers num="1.3.25"/>
        <vers num="1.3.26"/>
        <vers num="1.3.27"/>
        <vers num="1.3.28"/>
        <vers num="1.3.29"/>
        <vers num="1.3.3"/>
        <vers num="1.3.4"/>
        <vers num="1.3.6"/>
        <vers num="1.3.7" edition=""/>
        <vers num="1.3.7" edition=":dev"/>
        <vers num="1.3.9"/>
        <vers num="2.0"/>
        <vers num="2.0.28" edition="beta"/>
        <vers num="2.0.32"/>
        <vers num="2.0.35"/>
        <vers num="2.0.36"/>
        <vers num="2.0.37"/>
        <vers num="2.0.38"/>
        <vers num="2.0.39"/>
        <vers num="2.0.40"/>
        <vers num="2.0.41"/>
        <vers num="2.0.42"/>
        <vers num="2.0.43"/>
        <vers num="2.0.44"/>
        <vers num="2.0.45"/>
        <vers num="2.0.46"/>
        <vers num="2.0.47"/>
        <vers num="2.0.48"/>
        <vers num="2.0.9"/>
      </prod>
      <prod vendor="ibm" name="http_server">
        <vers num="1.3.19"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0264" published="2004-11-23" name="CVE-2004-0264" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">palmhttpd for PalmOS allows remote attackers to cause a denial of service (crash) by establishing two simultaneous HTTP connections, which exceeds the PalmOS accept queue.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <vuln_types>
      <input bound="1"/>
      <exception/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/9608" source="BID" patch="1" adv="1">9608</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107634638201570&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20040208 PalmOS httpd accept() queue overflow DoS vulnerability.</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15090" source="XF" adv="1">palmhttpd-accept-bo(15090)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="jim_rees" name="jim_rees_httpd">
        <vers num="palmos"/>
      </prod>
      <prod vendor="shaun2k2" name="palmhttpd">
        <vers num="3.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0265" published="2004-11-23" name="CVE-2004-0265" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in modules.php for Php-Nuke 6.x-7.1.0 allows remote attackers to execute arbitrary script as other users via URL-encoded (1) title or (2) fname parameters in the News or Reviews modules.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/15076" source="XF">phpnuke-mulitple-xss(15076)</ref>
      <ref url="http://www.securityfocus.com/bid/9613" source="BID">9613</ref>
      <ref url="http://www.securityfocus.com/bid/9605" source="BID">9605</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107634727520936&amp;w=2" source="BUGTRAQ">20040208 [waraxe-2004-SA#002] - Cross-Site Scripting (XSS) in Php-Nuke 7.1.0</ref>
    </refs>
    <vuln_soft>
      <prod vendor="francisco_burzi" name="php-nuke">
        <vers num="6.0"/>
        <vers num="6.5"/>
        <vers num="6.5_beta1"/>
        <vers num="6.5_final"/>
        <vers num="6.5_rc1"/>
        <vers num="6.5_rc2"/>
        <vers num="6.5_rc3"/>
        <vers num="6.6"/>
        <vers num="6.7"/>
        <vers num="6.9"/>
        <vers num="7.0"/>
        <vers num="7.0_final"/>
        <vers num="7.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0266" published="2004-11-23" name="CVE-2004-0266" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">SQL injection vulnerability in the "public message" capability (public_message) for Php-Nuke 6.x to 7.1.0 allows remote attackers obtain the administrator password via the c_mid parameter.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/15080" source="XF" adv="1">phpnuke-publicmessage-sql-injection(15080)</ref>
      <ref url="http://www.securityfocus.com/bid/9615" source="BID" adv="1">9615</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107635110327066&amp;w=2" source="BUGTRAQ" adv="1">20040208 [waraxe-2004-SA#003] - SQL injection in Php-Nuke 7.1.0</ref>
    </refs>
    <vuln_soft>
      <prod vendor="francisco_burzi" name="php-nuke">
        <vers num="6.0"/>
        <vers num="6.5"/>
        <vers num="6.5_beta1"/>
        <vers num="6.5_final"/>
        <vers num="6.5_rc1"/>
        <vers num="6.5_rc2"/>
        <vers num="6.5_rc3"/>
        <vers num="6.6"/>
        <vers num="6.7"/>
        <vers num="6.9"/>
        <vers num="7.0"/>
        <vers num="7.0_final"/>
        <vers num="7.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2004-0267" published="2004-11-23" name="CVE-2004-0267" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">The (1) inoregupdate, (2) uniftest, or (3) unimove scripts in eTrust InoculateIT for Linux 6.0 allow local users to overwrite arbitrary files via a symlink attack on files in /tmp.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <vuln_types>
      <design/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/15102" source="XF" adv="1">etrust-inoculateit-symlink(15102)</ref>
      <ref url="http://www.securityfocus.com/bid/9616" source="BID" adv="1">9616</ref>
      <ref url="http://www.osvdb.org/4856" source="OSVDB">4856</ref>
      <ref url="http://www.osvdb.org/4855" source="OSVDB">4855</ref>
      <ref url="http://www.osvdb.org/4735" source="OSVDB">4735</ref>
      <ref url="http://www.excluded.org/advisories/advisory10.txt" source="MISC">http://www.excluded.org/advisories/advisory10.txt</ref>
      <ref url="http://secunia.com/advisories/10833" source="SECUNIA">10833</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107635584431518&amp;w=2" source="BUGTRAQ" adv="1">20040209 [local problems] eTrust Virus Protection 6.0 InoculateIT for linux</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ca" name="inoculateit">
        <vers num="6.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0268" published="2004-11-23" name="CVE-2004-0268" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Multiple buffer overflows in EvolutionX 3921 and 3935 allow remote attackers to cause a denial of service (hang) via (1) a long cd command to the FTP server, or (2) a long dir command to the telnet server.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <vuln_types>
      <input buffer="1"/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/15104" source="XF" adv="1">evolutionx-command-line-dos(15104)</ref>
      <ref url="http://www.securityfocus.com/bid/9631" source="BID" adv="1">9631</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2004-February/016988.html" source="FULLDISC">20040210 XBOX EvolutionX ftp 'cd' command and telnet 'dir' buffer overflow</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107643394724891&amp;w=2" source="BUGTRAQ">20040210 XBOX EvolutionX ftp 'cd' command and telnet 'dir' buffer overflow</ref>
    </refs>
    <vuln_soft>
      <prod vendor="evolutionx" name="evolutionx">
        <vers num="build_3921"/>
        <vers num="build_3935"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0269" published="2004-11-23" name="CVE-2004-0269" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)" CVSS_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_base_score="6.4">
    <desc>
      <descript source="cve">SQL injection vulnerability in PHP-Nuke 6.9 and earlier, and possibly 7.x, allows remote attackers to inject arbitrary SQL code and gain sensitive information via (1) the category variable in the Search module or (2) the admin variable in the Web_Links module.</descript>
    </desc>
    <loss_types>
      <conf/>
      <int/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/9630" source="BID" patch="1" adv="1">9630</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107643348117646&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20040210 [SCAN Associates Sdn Bhd Security Advisory] PHPNuke 6.9 > and below SQL Injection in multiple module</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15115" source="XF" adv="1">phpnuke-modules-sql-injection(15115)</ref>
      <ref url="http://www.scan-associates.net/papers/phpnuke69.txt" source="MISC">http://www.scan-associates.net/papers/phpnuke69.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="francisco_burzi" name="php-nuke">
        <vers num="1.0"/>
        <vers num="2.5"/>
        <vers num="3.0"/>
        <vers num="4.0"/>
        <vers num="4.3"/>
        <vers num="4.4"/>
        <vers num="4.4.1a"/>
        <vers num="5.0"/>
        <vers num="5.0.1"/>
        <vers num="5.1"/>
        <vers num="5.2"/>
        <vers num="5.2a"/>
        <vers num="5.3.1"/>
        <vers num="5.4"/>
        <vers num="5.5"/>
        <vers num="5.6"/>
        <vers num="6.0"/>
        <vers num="6.5"/>
        <vers num="6.5_beta1"/>
        <vers num="6.5_final"/>
        <vers num="6.5_rc1"/>
        <vers num="6.5_rc2"/>
        <vers num="6.5_rc3"/>
        <vers num="6.6"/>
        <vers num="6.7"/>
        <vers num="6.9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0270" published="2004-11-23" name="CVE-2004-0270" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">libclamav in Clam AntiVirus 0.65 allows remote attackers to cause a denial of service (crash) via a uuencoded e-mail message with an invalid line length (e.g., a lowercase character), which causes an assert error in clamd that terminates the calling program.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <vuln_types>
      <input/>
      <exception/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/9610" source="BID" patch="1" adv="1">9610</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107634700823822&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20040209 clamav 0.65 remote DOS exploit</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15077" source="XF" adv="1">clam-antivirus-uuencoded-dos(15077)</ref>
      <ref url="http://www.freebsd.org/cgi/query-pr.cgi?pr=62586" source="CONFIRM">http://www.freebsd.org/cgi/query-pr.cgi?pr=62586</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200402-07.xml" source="GENTOO" adv="1">GLSA-200402-07</ref>
      <ref url="http://www.osvdb.org/3894" source="OSVDB">3894</ref>
    </refs>
    <vuln_soft>
      <prod vendor="clam_anti-virus" name="clamav">
        <vers num="0.65"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0271" published="2004-11-23" name="CVE-2004-0271" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Multiple cross-site scripting vulnerabilities (XSS) in MaxWebPortal allow remote attackers to execute arbitrary web script as other users via (1) the sub_name parameter of dl_showall.asp, (2) the SendTo parameter in Personal Messages, (3) the HTTP_REFERER for down.asp, or (4) the image name of an Avatar in the register form.</descript>
    </desc>
    <sols>
      <sol source="nvd">This vulnerability is addressed in the following product release:
MaxWebPortal, MaxWebPortal, 1.32</sol>
    </sols>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/15122" source="XF" patch="1">maxwebportal-register-xss(15122)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15120" source="XF" patch="1">maxwebportal-multiple-xss(15120)</ref>
      <ref url="http://www.securityfocus.com/bid/9625" source="BID" patch="1">9625</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107643014606515&amp;w=2" source="BUGTRAQ" patch="1">20040210 XSS, Sql Injection and Avatar ScriptCode Injection in MaxWebPortal</ref>
    </refs>
    <vuln_soft>
      <prod vendor="maxwebportal" name="maxwebportal">
        <vers num="1.30"/>
        <vers num="1.31"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0272" published="2004-11-23" name="CVE-2004-0272" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in MaxWebPortal allows remote attackers to inject arbitrary SQL code and gain sensitive information via the SendTo parameter in Personal Messages.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/15121" source="XF" adv="1">maxwebportal-personalmesssages-sql-injection(15121)</ref>
      <ref url="http://www.securityfocus.com/bid/9625" source="BID" adv="1">9625</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107643014606515&amp;w=2" source="BUGTRAQ" adv="1">20040210 XSS, Sql Injection and Avatar ScriptCode Injection in MaxWebPortal</ref>
    </refs>
    <vuln_soft>
      <prod vendor="maxwebportal" name="maxwebportal">
        <vers num="1.30"/>
        <vers num="1.31"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0273" published="2004-11-23" name="CVE-2004-0273" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Directory traversal vulnerability in RealOne Player, RealOne Player 2.0, and RealOne Enterprise Desktop allows remote attackers to upload arbitrary files via an RMP file that contains .. (dot dot) sequences in a .rjs skin file.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/514734" source="CERT-VN">VU#514734</ref>
      <ref url="http://www.securityfocus.com/bid/9580" source="BID" patch="1" adv="1">9580</ref>
      <ref url="http://service.real.com/help/faq/security/040123_player/EN/" source="CONFIRM" patch="1" adv="1">http://service.real.com/help/faq/security/040123_player/EN/</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107642978524321&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20040210 Directory traversal in RealPlayer allows code execution</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15123" source="XF">realoneplayer-rmp-directory-traversal(15123)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="realnetworks" name="realone_desktop_manager">
        <vers num=""/>
      </prod>
      <prod vendor="realnetworks" name="realone_enterprise_desktop">
        <vers num="6.0.11.774"/>
      </prod>
      <prod vendor="realnetworks" name="realone_player">
        <vers num="1.0"/>
        <vers num="2.0" edition=""/>
        <vers num="2.0" edition=":win"/>
        <vers num="6.0.11.818"/>
        <vers num="6.0.11.830"/>
        <vers num="6.0.11.841"/>
        <vers num="6.0.11.853"/>
        <vers num="6.0.11.868"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0274" published="2004-11-23" name="CVE-2004-0274" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Share.mod in Eggheads Eggdrop IRC bot 1.6.10 through 1.6.15 can mistakenly assign STAT_OFFERED status to a bot that is not a sharebot, which allows remote attackers to use STAT_OFFERED to promote a bot to a sharebot and conduct unauthorized activities.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <design/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107643315623958&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20040210 Re: Eggrop bug</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107634593827102&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20040208 Eggrop bug</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15084" source="XF" adv="1">eggdrop-sharemod-gain-access(15084)</ref>
      <ref url="http://www.securityfocus.com/bid/9606" source="BID" adv="1">9606</ref>
      <ref url="http://mogan.nonsoloirc.com/egg_advisory.txt" source="MISC">http://mogan.nonsoloirc.com/egg_advisory.txt</ref>
      <ref url="http://www.osvdb.org/3928" source="OSVDB">3928</ref>
      <ref url="http://www.eggheads.org/news/2004/04/10/26" source="CONFIRM">http://www.eggheads.org/news/2004/04/10/26</ref>
    </refs>
    <vuln_soft>
      <prod vendor="eggheads" name="eggdrop_irc_bot">
        <vers num="1.6.10"/>
        <vers num="1.6.11"/>
        <vers num="1.6.12"/>
        <vers num="1.6.13"/>
        <vers num="1.6.14"/>
        <vers num="1.6.15"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0275" published="2004-11-23" name="CVE-2004-0275" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">SQL injection vulnerability in calendar_download.php in BosDates 3.2 and earlier allows remote attackers to obtain sensitive information and gain access via the calendar parameter.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/15133" source="XF" adv="1">bosdates-calendar-sql-injection(15133)</ref>
      <ref url="http://www.zone-h.org/en/advisories/read/id=3925/" source="MISC">http://www.zone-h.org/en/advisories/read/id=3925/</ref>
      <ref url="http://www.securityfocus.com/bid/9639" source="BID" adv="1">9639</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107651618613575&amp;w=2" source="BUGTRAQ" adv="1">20040211 ZH2004-05SA (security advisory): Sql Injection Vulnerability in BosDates</ref>
    </refs>
    <vuln_soft>
      <prod vendor="bosdev" name="bosdates">
        <vers num="3.0"/>
        <vers num="3.1"/>
        <vers num="3.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0276" published="2004-11-23" name="CVE-2004-0276" modified="2012-10-24" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The get_real_string function in Monkey HTTP Daemon (monkeyd) 0.8.1 and earlier allows remote attackers to cause a denial of service (crash) via an HTTP request with a sequence of "%" characters and a missing Host field.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/9642" source="BID" patch="1" adv="1">9642</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15187" source="XF" adv="1">monkey-getrealstring-dos(15187)</ref>
      <ref url="http://www.osvdb.org/3921" source="OSVDB">3921</ref>
      <ref url="http://monkeyd.sourceforge.net/" source="CONFIRM">http://monkeyd.sourceforge.net/</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107652610506968&amp;w=2" source="BUGTRAQ" adv="1">20040211 Denial of Service in Monkey httpd &lt;= 0.8.1</ref>
      <ref url="http://aluigi.altervista.org/poc/monkeydos.zip" source="MISC">http://aluigi.altervista.org/poc/monkeydos.zip</ref>
    </refs>
    <vuln_soft>
      <prod vendor="monkey-project" name="monkey_http_daemon">
        <vers num="0.1.1"/>
        <vers num="0.5.2"/>
        <vers num="0.6.0"/>
        <vers num="0.6.1"/>
        <vers num="0.6.2"/>
        <vers num="0.6.3"/>
        <vers num="0.7.0"/>
        <vers num="0.7.1"/>
        <vers num="0.7.2"/>
        <vers num="0.8.0"/>
        <vers prev="1" num="0.8.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0277" published="2004-11-23" name="CVE-2004-0277" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Format string vulnerability in Dream FTP 1.02 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via format string specifiers in the username.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1" admin="1"/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/15070" source="XF" adv="1">dreamftp-username-format-string(15070)</ref>
      <ref url="http://www.securityfocus.com/bid/9600" source="BID" adv="1">9600</ref>
      <ref url="http://www.security-protocols.com/modules.php?name=News&amp;file=article&amp;sid=1722" source="MISC">http://www.security-protocols.com/modules.php?name=News&amp;file=article&amp;sid=1722</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107656166402882&amp;w=2" source="BUGTRAQ">20040211 Re: [Full-Disclosure] DreamFTP Server 1.02 Buffer Overflow</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2004-February/016871.html" source="FULLDISC">20040207 DreamFTP Server 1.02 Buffer Overflow</ref>
    </refs>
    <vuln_soft>
      <prod vendor="bolintech" name="dream_ftp_server">
        <vers num="1.02"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0278" published="2004-11-23" name="CVE-2004-0278" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Ratbag game engine, as used in products such as Dirt Track Racing, Leadfoot, and World of Outlaws Spring Cars, allows remote attackers to cause a denial of service (CPU consumption) via a TCP packet that specifies the length of data to read and then sends a second TCP packet that contains less data than specified, which causes Ratbag to repeatedly check the socket for more data.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <vuln_types>
      <exception/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/15188" source="XF" adv="1">ratbag-data-length-dos(15188)</ref>
      <ref url="http://www.securityfocus.com/bid/9644" source="BID" adv="1">9644</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107655269820530&amp;w=2" source="BUGTRAQ" adv="1">20040211 Denial of Service in Ratbag's game engine</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ratbag" name="dirt_track_racing">
        <vers num="1.0.3"/>
        <vers num="2.0"/>
      </prod>
      <prod vendor="ratbag" name="dirt_track_racing_australia">
        <vers num=""/>
      </prod>
      <prod vendor="ratbag" name="dirt_track_racing_sprint_cars">
        <vers num=""/>
      </prod>
      <prod vendor="ratbag" name="leadfoot">
        <vers num=""/>
      </prod>
      <prod vendor="ratbag" name="world_of_outlaws_sprint_cars">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0279" published="2004-11-23" name="CVE-2004-0279" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">AIM Sniff (aimSniff.pl) 0.9b allows local users to overwrite arbitrary files via a symlink attack on /tmp/AS.log.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1" admin="1"/>
    </loss_types>
    <vuln_types>
      <access/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/9653" source="BID" patch="1" adv="1">9653</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107662243303439&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20040212 aimSniff.pl file "deletion" (local)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15199" source="XF" adv="1">aim-sniff-symlink(15199)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="aim_sniff" name="aim_sniff">
        <vers num="0.6"/>
        <vers num="0.7"/>
        <vers num="0.8"/>
        <vers num="0.9"/>
        <vers num="0.9b"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0280" published="2004-11-23" name="CVE-2004-0280" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Caucho Technology Resin 2.1.12 allows remote attackers to view JSP source via an HTTP request to a .jsp file that ends in a "%20" (encoded space character), e.g. index.jsp%20.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/15085" source="XF" adv="1">resin-source-disclosure(15085)</ref>
      <ref url="http://www.securityfocus.com/bid/9614" source="BID" adv="1">9614</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107635084830547&amp;w=2" source="BUGTRAQ">20040205 Apache Http Server Reveals Script Source Code to Remote Users And Any Users Can Access Resin Forbidden Directory ("/WEB-INF/")</ref>
    </refs>
    <vuln_soft>
      <prod vendor="caucho_technology" name="resin">
        <vers num="2.1.12"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0281" published="2004-11-23" name="CVE-2004-0281" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Caucho Technology Resin 2.1.12 allows remote attackers to gain sensitive information and view the contents of the /WEB-INF/ directory via an HTTP request for "WEB-INF..", which is equivalent to "WEB-INF" in Windows.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/15087" source="XF" adv="1">resin-dotdot-directory-traversal(15087)</ref>
      <ref url="http://www.securityfocus.com/bid/9617" source="BID" adv="1">9617</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107635084830547&amp;w=2" source="BUGTRAQ">20040205 Apache Http Server Reveals Script Source Code to Remote Users And Any Users Can Access Resin Forbidden Directory ("/WEB-INF/")</ref>
    </refs>
    <vuln_soft>
      <prod vendor="caucho_technology" name="resin">
        <vers num="2.1.12"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0282" published="2004-11-23" name="CVE-2004-0282" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Crob FTP daemon 3.5.2 allows remote attackers to cause a denial of service (crash) by repeatedly connecting to and disconnecting from the server.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <vuln_types>
      <exception/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/15201" source="XF" adv="1">crob-multiple-connections-dos(15201)</ref>
      <ref url="http://www.securityfocus.com/bid/9651" source="BID" adv="1">9651</ref>
      <ref url="http://www.osvdb.org/6621" source="OSVDB">6621</ref>
      <ref url="http://secunia.com/advisories/10882" source="SECUNIA">10882</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107665920909374&amp;w=2" source="BUGTRAQ" adv="1">20040212 crob ftpd Denial of Service</ref>
    </refs>
    <vuln_soft>
      <prod vendor="crob" name="crob_ftp_server">
        <vers num="3.5.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2004-0283" published="2004-11-23" name="CVE-2004-0283" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">Mailmgr 1.2.3 allows local users to overwrite arbitrary files via a symlink attack on (1) /tmp/mailmgr.unsort, (2) /tmp/mailmgr.tmp, or (3) /tmp/mailmgr.sort.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <vuln_types>
      <config/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/15203" source="XF" adv="1">mailmgr-insecure-temp-directory (15203)</ref>
      <ref url="http://www.securityfocus.com/bid/9654" source="BID" adv="1">9654</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107665013714517&amp;w=2" source="BUGTRAQ" adv="1">20040212 Symlink vulnerabilities in mailmgr</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mailmgr" name="mailmgr">
        <vers num="1.2.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0284" published="2004-11-23" name="CVE-2004-0284" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Microsoft Internet Explorer 6.0, Outlook 2002, and Outlook 2003 allow remote attackers to cause a denial of service (CPU consumption), if "Do not save encrypted pages to disk" is disabled, via a web site or HTML e-mail that contains two null characters (%00) after the host name.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <vuln_types>
      <design/>
      <exception/>
      <config/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/9629" source="BID" patch="1" adv="1">9629</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107643134712133&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20040210 ASPR #2004-01-20-1: Internet Explorer/Outlook double null character DoS</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15127" source="XF" adv="1">ie-host-null-dos(15127)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="ie">
        <vers num="6.0" edition="sp1"/>
      </prod>
      <prod vendor="microsoft" name="outlook">
        <vers num="2002" edition="sp1"/>
        <vers num="2002" edition="sp2"/>
        <vers num="2003"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0285" published="2004-11-23" name="CVE-2004-0285" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">PHP remote file inclusion vulnerabilities in include/footer.inc.php in (1) AllMyVisitors, (2) AllMyLinks, and (3) AllMyGuests allow remote attackers to execute arbitrary PHP code via a URL in the _AMVconfig[cfg_serverpath] parameter.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/9664" source="BID" patch="1" adv="1">9664</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15228" source="XF">allmyvisitors-file-include(15228)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15227" source="XF" adv="1">allmyguests-php-file-include(15227)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15226" source="XF" adv="1">allmylinks-file-include(15226)</ref>
      <ref url="http://www.osvdb.org/6721" source="OSVDB">6721</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107696291728750&amp;w=2" source="BUGTRAQ" adv="1">20040214 AllMyLinks PHP Code Injection vulnerability</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107696235424865&amp;w=2" source="BUGTRAQ">20040214 AllMyVisitors PHP Code Injection vulnerability</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107696209514155&amp;w=2" source="BUGTRAQ">20040214 AllMyGuests PHP Code Injection vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="voice_of_web" name="allmyguests">
        <vers num="0.1.2"/>
        <vers num="0.3"/>
        <vers num="0.4"/>
        <vers num="0.4.1"/>
      </prod>
      <prod vendor="voice_of_web" name="allmylinks">
        <vers num="0.3"/>
        <vers num="0.4"/>
        <vers num="0.4.1"/>
        <vers num="0.4.3"/>
        <vers num="0.4.4"/>
        <vers num="0.4.9"/>
        <vers num="0.5"/>
      </prod>
      <prod vendor="voice_of_web" name="allmyvisitors">
        <vers num="0.3"/>
        <vers num="0.4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0286" published="2004-11-23" name="CVE-2004-0286" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Buffer overflow in RobotFTP 1.0 and 2.0 beta 1 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long username.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1" admin="1"/>
    </loss_types>
    <vuln_types>
      <input buffer="1"/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/15225" source="XF" adv="1">robot-username-bo(15225)</ref>
      <ref url="http://www.securityfocus.com/bid/9672" source="BID" adv="1">9672</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107696194306878&amp;w=2" source="BUGTRAQ" adv="1">20040215 buffer overflow in Robot FTP Server</ref>
    </refs>
    <vuln_soft>
      <prod vendor="robotftp" name="robotftp_server">
        <vers num="1.0"/>
        <vers num="2.0_beta_1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0287" published="2004-11-23" name="CVE-2004-0287" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Xlight FTP server 1.52 allows remote authenticated users to cause a denial of service (crash) via a RETR command with a long argument containing a large number of / (slash) characters, possibly triggering a buffer overflow.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <vuln_types>
      <input buffer="1"/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/15220" source="XF" adv="1">xlight-retr-dos(15220)</ref>
      <ref url="http://www.securityfocus.com/bid/9668" source="BID">9668</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107695172917263&amp;w=2" source="BUGTRAQ" adv="1">20040215 Xlight ftp server 1.52 RETR bug</ref>
    </refs>
    <vuln_soft>
      <prod vendor="xlight_ftp_server" name="xlight_ftp_server">
        <vers num="1.52"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0288" published="2004-11-23" name="CVE-2004-0288" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Buffer overflow in the UdmDocToTextBuf function in mnoGoSearch 3.2.13 through 3.2.15 could allow remote attackers to execute arbitrary code by indexing a large document.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1" admin="1"/>
    </loss_types>
    <vuln_types>
      <input buffer="1"/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/9667" source="BID" patch="1" adv="1">9667</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107695139930726&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20040215 Buffer overflow in mnoGoSearch</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15209" source="XF" adv="1">mnogosearch-udmdoctotextbuf-bo(15209)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mnogosearch" name="mnogosearch">
        <vers num="3.1.19"/>
        <vers num="3.1.20"/>
        <vers num="3.2.10"/>
        <vers num="3.2.13"/>
        <vers num="3.2.14"/>
        <vers num="3.2.15"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2004-0289" published="2004-11-23" name="CVE-2004-0289" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">Buffer overflow in sdbscan in SignatureDB 0.1.1 allows local users to cause a denial of service (segmentation fault) via a database file that contains a large key parameter.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <vuln_types>
      <input buffer="1"/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/15217" source="XF" adv="1">signaturedb-sdbscan-bo(15217)</ref>
      <ref url="http://www.securityfocus.com/bid/9661" source="BID" adv="1">9661</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107695113832648&amp;w=2" source="BUGTRAQ" adv="1">20040215 problems with database files in 'SignatureDB'</ref>
    </refs>
    <vuln_soft>
      <prod vendor="paul_l_daniels" name="signaturedb">
        <vers num="0.1.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0290" published="2004-11-23" name="CVE-2004-0290" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Buffer overflow in Purge Jihad 2.0.1 and earlier allows remote game servers to execute arbitrary code via an information packet that contains large (1) battle type and (2) map name fields.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1" admin="1"/>
    </loss_types>
    <vuln_types>
      <input buffer="1"/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/15216" source="XF" adv="1">purge-battletype-map-bo(15216)</ref>
      <ref url="http://www.securityfocus.com/bid/9671" source="BID" adv="1">9671</ref>
      <ref url="http://purge.worthplaying.com/phpbb/viewtopic.php?t=1167" source="CONFIRM">http://purge.worthplaying.com/phpbb/viewtopic.php?t=1167</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107695064204362&amp;w=2" source="BUGTRAQ" adv="1">20040216 Broadcast client buffer-overflow in Purge Jihad &lt;= 2.0.1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="freeform_interactive" name="purge">
        <vers num="1.4.7"/>
      </prod>
      <prod vendor="freeform_interactive" name="purge_jihad">
        <vers num="2.0.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0291" published="2004-11-23" name="CVE-2004-0291" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">SQL injection vulnerability in post.php for YaBB SE 1.5.4 and 1.5.5 allows remote attackers to obtain hashed passwords via the quote parameter.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/9674" source="BID" patch="1" adv="1">9674</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15224" source="XF" adv="1">yabb-post-sql-injection(15224)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107696318522985&amp;w=2" source="BUGTRAQ">20040216 Another YabbSE SQL Injection</ref>
    </refs>
    <vuln_soft>
      <prod vendor="yabb" name="yabb">
        <vers num="1.5.4" edition=""/>
        <vers num="1.5.4" edition=":second_edition"/>
        <vers num="1.5.5" edition=""/>
        <vers num="1.5.5" edition=":second_edition"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0292" published="2004-11-23" name="CVE-2004-0292" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Buffer overflow in KarjaSoft Sami HTTP Server 1.0.4 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long HTTP GET request.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1" admin="1"/>
    </loss_types>
    <vuln_types>
      <input buffer="1"/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/15237" source="XF" adv="1">sami-http-get-bo(15237)</ref>
      <ref url="http://www.securityfocus.com/bid/9679" source="BID" adv="1">9679</ref>
      <ref url="http://www.security-protocols.com/modules.php?name=News&amp;file=article&amp;sid=1746" source="MISC">http://www.security-protocols.com/modules.php?name=News&amp;file=article&amp;sid=1746</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107703630913205&amp;w=2" source="BUGTRAQ" adv="1">20040217 KarjaSoft Sami HTTP Server 1.0.4 Buffer Overflow</ref>
    </refs>
    <vuln_soft>
      <prod vendor="karjasoft" name="sami_http_server">
        <vers num="1.0.4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0293" published="2004-11-23" name="CVE-2004-0293" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in ShopCartCGI 2.3 allows remote attackers to retrieve arbitrary files via a .. (dot dot) in a HTTP request to (1) gotopage.cgi or (2) genindexpage.cgi.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/14982" source="XF" adv="1">shopcartcgi-dotdot-directory-traversal(14982)</ref>
      <ref url="http://www.zone-h.org/en/advisories/read/id=3962/" source="MISC">http://www.zone-h.org/en/advisories/read/id=3962/</ref>
      <ref url="http://www.securityfocus.com/bid/9670" source="BID" adv="1">9670</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107703602707450&amp;w=2" source="BUGTRAQ" adv="1">20040217 ZH2004-06SA (security advisory): ShopCartCGI v2.3 Remote</ref>
    </refs>
    <vuln_soft>
      <prod vendor="shopcartcgi" name="shopcartcgi">
        <vers num="2.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0294" published="2004-11-23" name="CVE-2004-0294" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">YaBB 1 SP 1.3.1 displays different error messages when a user exists or not, which makes it easier for remote attackers to identify valid users and conduct a brute force password guessing attack.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <vuln_types>
      <design/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/15236" source="XF" adv="1">yabb-invalidmessage-obtain-information(15236)</ref>
      <ref url="http://www.securityfocus.com/bid/9677" source="BID" adv="1">9677</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107703591314745&amp;w=2" source="BUGTRAQ">20040217 YABB information leakage on failed login</ref>
    </refs>
    <vuln_soft>
      <prod vendor="yabb" name="yabb">
        <vers num="1_gold_-_sp_1.3.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0295" published="2004-11-23" name="CVE-2004-0295" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">TsFtpSrv.exe in Broker FTP 6.1.0.0 allows remote attackers to cause a denial of service (CPU consumption) via an open idle connection.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <vuln_types>
      <design/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/15242" source="XF" adv="1">broker-ftp-tsftpsrv-dos(15242)</ref>
      <ref url="http://www.securityfocus.com/bid/9680" source="BID" adv="1">9680</ref>
      <ref url="http://www.securiteam.com/windowsntfocus/5IP0B0AC1I.html" source="MISC">http://www.securiteam.com/windowsntfocus/5IP0B0AC1I.html</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107705346817241&amp;w=2" source="BUGTRAQ" adv="1">20040217 Broker FTP DoS (Message Server)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="transsoft" name="broker_ftp_server">
        <vers num="6.1_.0.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0296" published="2004-11-23" name="CVE-2004-0296" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">TsFtpSrv.exe in Broker FTP 6.1.0.0 allows remote attackers to cause a TsFtpSrv.exe to exit with an exception by opening and immediately closing a connection.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <vuln_types>
      <design/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/15241" source="XF" adv="1">broker-ftp-dos(15241)</ref>
      <ref url="http://www.securityfocus.com/bid/9680" source="BID" adv="1">9680</ref>
      <ref url="http://www.securiteam.com/windowsntfocus/5IP0B0AC1I.html" source="MISC">http://www.securiteam.com/windowsntfocus/5IP0B0AC1I.html</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107705346817241&amp;w=2" source="BUGTRAQ" adv="1">20040217 Broker FTP DoS (Message Server)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="transsoft" name="broker_ftp_server">
        <vers num="6.1_.0.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0297" published="2004-11-23" name="CVE-2004-0297" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Buffer overflow in the Lightweight Directory Access Protocol (LDAP) daemon (iLDAP.exe 3.9.15.10) in Ipswitch IMail Server 8.03 allows remote attackers to cause a denial of service (crash) and execute arbitrary code via an LDAP message with a large tag length.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1" admin="1"/>
    </loss_types>
    <vuln_types>
      <input buffer="1"/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/972334" source="CERT-VN" adv="1">VU#972334</ref>
      <ref url="http://www.securityfocus.com/bid/9682" source="BID" patch="1" adv="1">9682</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15243" source="XF" adv="1">imail-ldap-tag-bo(15243)</ref>
      <ref url="http://www.ipswitch.com/support/imail/releases/imail_professional/im805HF2.html" source="CONFIRM">http://www.ipswitch.com/support/imail/releases/imail_professional/im805HF2.html</ref>
      <ref url="http://www.osvdb.org/3984" source="OSVDB">3984</ref>
      <ref url="http://www.idefense.com/application/poi/display?id=74" source="IDEFENSE">20040217 Ipswitch IMail LDAP Daemon Remote Buffer Overflow</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ipswitch" name="imail">
        <vers num="8.0.3"/>
        <vers num="8.0.5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0298" published="2004-11-23" name="CVE-2004-0298" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">CesarFTP 0.99e allows remote attackers to cause a denial of service (CPU consumption) via a long RETR parameter.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <vuln_types>
      <input buffer="1"/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/15252" source="XF" adv="1">cesarftp-userpass-dos(15252)</ref>
      <ref url="http://www.securityfocus.com/bid/9666" source="BID" adv="1">9666</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107712057628250&amp;w=2" source="BUGTRAQ" adv="1">20040217 CesarFTP 0.99 : 100% employment of computer resources</ref>
    </refs>
    <vuln_soft>
      <prod vendor="aclogic" name="cesarftp">
        <vers num="0.99e"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2004-0299" published="2004-11-23" name="CVE-2004-0299" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">Buffer overflow in smallftpd 0.99 allows local users to cause a denial of service (crash) via an FTP request with a large number of "/" (slash) characters.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <vuln_types>
      <input buffer="1"/>
      <exception/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/15262" source="XF" adv="1">smallftpd-forwardslash-dos(15262)</ref>
      <ref url="http://www.securityfocus.com/bid/9684" source="BID" adv="1">9684</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107714207708375&amp;w=2" source="BUGTRAQ" adv="1">20040217 Smallftpd 1.0.3 DoS</ref>
    </refs>
    <vuln_soft>
      <prod vendor="smallftpd" name="smallftpd">
        <vers num="1.0.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0300" published="2004-11-23" name="CVE-2004-0300" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">SQL injection vulnerability in Online Store Kit 3.0 allows remote attackers to inject arbitrary SQL and gain unauthorized access via (1) the cat parameter in shop.php, (2) the id parameter in more.php, (3) the cat_manufacturer parameter in shop_by_brand.php, or (4) the id parameter in listing.php.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1" admin="1"/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/15232" source="XF" adv="1">onlinestorekit-more-sql-injection(15232)</ref>
      <ref url="http://www.zone-h.org/en/advisories/read/id=3972/" source="MISC">http://www.zone-h.org/en/advisories/read/id=3972/</ref>
      <ref url="http://www.systemsecure.org/advisories/ssadvisory16022004.php" source="MISC">http://www.systemsecure.org/advisories/ssadvisory16022004.php</ref>
      <ref url="http://www.securityfocus.com/bid/9687" source="BID" adv="1">9687</ref>
      <ref url="http://www.securityfocus.com/bid/9676" source="BID" adv="1">9676</ref>
      <ref url="http://secunia.com/advisories/10902/" source="SECUNIA">10902</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107712117913185&amp;w=2" source="BUGTRAQ" adv="1">20040218 ZH2004-07SA (security advisory): Multiple Sql injection</ref>
      <ref url="http://www.osvdb.org/3973" source="OSVDB">3973</ref>
      <ref url="http://securitytracker.com/alerts/2004/Feb/1009092.html" source="SECTRACK">1009092</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ecommerce_corporation_online" name="store_kit">
        <vers num="3.0_lite"/>
        <vers num="3.0_pro"/>
        <vers num="3.0_standard"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0301" published="2004-11-23" name="CVE-2004-0301" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in more.php for Online Store Kit 3.0 allows remote attackers to inject arbitrary HTML via the id parameter.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/15235" source="XF">onlinestorekit-more-xss(15235)</ref>
      <ref url="http://www.systemsecure.org/advisories/ssadvisory16022004.php" source="MISC">http://www.systemsecure.org/advisories/ssadvisory16022004.php</ref>
      <ref url="http://www.securityfocus.com/bid/9676" source="BID">9676</ref>
      <ref url="http://securitytracker.com/alerts/2004/Feb/1009079.html" source="SECTRACK">1009079</ref>
      <ref url="http://secunia.com/advisories/10902/" source="SECUNIA" adv="1">10902</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ecommerce_corporation_online" name="store_kit">
        <vers num="3.0_lite"/>
        <vers num="3.0_pro"/>
        <vers num="3.0_standard"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0302" published="2004-11-23" name="CVE-2004-0302" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in OWLS 1.0 allows remote attackers to read arbitrary files via a .. (dot dot) in the (1) file parameter in index.php, (2) editfile in glossary.php, or (3) editfile in newmultiplechoice.php.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/15249" source="XF" adv="1">owls-file-retrieval(15249)</ref>
      <ref url="http://www.zone-h.org/en/advisories/read/id=3973/" source="MISC">http://www.zone-h.org/en/advisories/read/id=3973/</ref>
      <ref url="http://www.securityfocus.com/bid/9689" source="BID" adv="1">9689</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107712123305706&amp;w=2" source="BUGTRAQ" adv="1">20040218 ZH2004-08SA (security advisory): OWLS 1.0 Remote arbitrary files</ref>
    </refs>
    <vuln_soft>
      <prod vendor="fools_workshop" name="owls_workshop">
        <vers num="1.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0303" published="2004-11-23" name="CVE-2004-0303" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">OWLS 1.0 allows remote attackers to retrieve arbitrary files via absolute pathnames in (1) the file parameter in /glossaries/index.php, (2) the filename parameter in /readings/index.php, or (3) the filename parameter in /multiplechoice/resultsignore.php, as demonstrated using /etc/passwd.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/15249" source="XF" adv="1">owls-file-retrieval(15249)</ref>
      <ref url="http://www.zone-h.org/en/advisories/read/id=3973/" source="MISC">http://www.zone-h.org/en/advisories/read/id=3973/</ref>
      <ref url="http://www.securityfocus.com/bid/9689" source="BID" adv="1">9689</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107712123305706&amp;w=2" source="BUGTRAQ" adv="1">20040218 ZH2004-08SA (security advisory): OWLS 1.0 Remote arbitrary files</ref>
    </refs>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0304" published="2004-11-23" name="CVE-2004-0304" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">SQL injection vulnerability in browse_items.asp in WebCortex WebStores 2000 6.0 allows remote attackers to gain unauthorized access and execute arbitrary commands via the Search_Text parameter.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1" admin="1"/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/15253" source="XF" adv="1">webstores-browseitems-sql-injection(15253)</ref>
      <ref url="http://www.securityfocus.com/bid/7766" source="BID" adv="1">7766</ref>
      <ref url="http://www.s-quadra.com/advisories/Adv-20040218.txt" source="MISC">http://www.s-quadra.com/advisories/Adv-20040218.txt</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107712159425226&amp;w=2" source="BUGTRAQ" adv="1">20040218 WebCortex Webstores2000 version 6.0 multiple security vulnerabilities</ref>
    </refs>
    <vuln_soft>
      <prod vendor="webcortex" name="webstores_2000">
        <vers num="6.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0305" published="2004-11-23" name="CVE-2004-0305" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in error.asp in WebCortex WebStores 2000 6.0 allows remote attackers to execute arbitrary script as other users and steal session IDs via the Message_id parameter.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/15254" source="XF">webstores-error-xss(15254)</ref>
      <ref url="http://www.securityfocus.com/bid/9693" source="BID">9693</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107712159425226&amp;w=2" source="BUGTRAQ">20040218 WebCortex Webstores2000 version 6.0 multiple security vulnerabilities</ref>
    </refs>
    <vuln_soft>
      <prod vendor="webcortex" name="webstores_2000">
        <vers num="6.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0306" published="2004-11-23" name="CVE-2004-0306" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Cisco ONS 15327 before 4.1(3), ONS 15454 before 4.6(1), ONS 15454 SD before 4.1(3), and Cisco ONS 15600 before 1.3(0) enable TFTP service on UDP port 69 by default, which allows remote attackers to GET or PUT ONS system files on the current active TCC in the /flash0 or /flash1 directories.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <vuln_types>
      <design/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/9699" source="BID" patch="1" adv="1">9699</ref>
      <ref url="http://www.cisco.com/warp/public/707/cisco-sa-20040219-ONS.shtml" source="CISCO" patch="1" adv="1">20040219 Cisco ONS 15327, ONS 15454, ONS 15454 SDH, and ONS 15600 Vulnerabilities</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15264" source="XF" adv="1">cisco-ons-file-upload(15264)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="ons_15327">
        <vers num="4.0"/>
        <vers num="4.0(1)"/>
        <vers num="4.0(2)"/>
        <vers num="4.1(0)"/>
        <vers num="4.1(1)"/>
        <vers num="4.1(2)"/>
      </prod>
      <prod vendor="cisco" name="ons_15454_optical_transport_platform">
        <vers num="4.0"/>
        <vers num="4.0(1)"/>
        <vers num="4.1"/>
        <vers num="4.1(0)"/>
        <vers num="4.1(1)"/>
        <vers num="4.1(2)"/>
        <vers num="4.1(3)"/>
      </prod>
      <prod vendor="cisco" name="ons_15454sdh">
        <vers num="4.0"/>
        <vers num="4.1(0)"/>
        <vers num="4.1(1)"/>
        <vers num="4.1(2)"/>
        <vers num="4.5"/>
      </prod>
      <prod vendor="cisco" name="ons_15600">
        <vers num="1.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0307" published="2004-11-23" name="CVE-2004-0307" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Cisco ONS 15327 before 4.1(3), ONS 15454 before 4.6(1), and ONS 15454 SD before 4.1(3) allows remote attackers to cause a denial of service (reset) by not sending the ACK portion of the TCP three-way handshake and sending an invalid response instead.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <vuln_types>
      <exception/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/9699" source="BID" patch="1" adv="1">9699</ref>
      <ref url="http://www.cisco.com/warp/public/707/cisco-sa-20040219-ONS.shtml" source="CISCO" patch="1" adv="1">20040219 Cisco ONS 15327, ONS 15454, ONS 15454 SDH, and ONS 15600 Vulnerabilities</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15265" source="XF" adv="1">cisco-ons-ack-dos(15265)</ref>
      <ref url="http://www.osvdb.org/4009" source="OSVDB">4009</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="ons_15327">
        <vers num="4.0"/>
        <vers num="4.0(1)"/>
        <vers num="4.0(2)"/>
        <vers num="4.1(0)"/>
        <vers num="4.1(1)"/>
        <vers num="4.1(2)"/>
      </prod>
      <prod vendor="cisco" name="ons_15454_optical_transport_platform">
        <vers num="4.0"/>
        <vers num="4.0(1)"/>
        <vers num="4.1"/>
        <vers num="4.1(0)"/>
        <vers num="4.1(1)"/>
        <vers num="4.1(2)"/>
        <vers num="4.1(3)"/>
      </prod>
      <prod vendor="cisco" name="ons_15454sdh">
        <vers num="4.0"/>
        <vers num="4.1(0)"/>
        <vers num="4.1(1)"/>
        <vers num="4.1(2)"/>
        <vers num="4.5"/>
      </prod>
      <prod vendor="cisco" name="ons_15600">
        <vers num="1.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0308" published="2004-11-24" name="CVE-2004-0308" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Unknown vulnerability in Cisco ONS 15327 before 4.1(3), ONS 15454 before 4.6(1), ONS 15454 SD before 4.1(3), and Cisco ONS15600 before 1.3(0) allows a superuser whose account is locked out, disabled, or suspended to gain unauthorized access via a Telnet connection to the VxWorks shell.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <vuln_types>
      <other/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/9699" source="BID" patch="1" adv="1">9699</ref>
      <ref url="http://www.cisco.com/warp/public/707/cisco-sa-20040219-ONS.shtml" source="CISCO" patch="1" adv="1">20040219 Cisco ONS 15327, ONS 15454, ONS 15454 SDH, and ONS 15600 Vulnerabilities</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15266" source="XF" adv="1">cisco-ons-gain-access(15266)</ref>
      <ref url="http://www.osvdb.org/4010" source="OSVDB">4010</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="ons_15327">
        <vers num="4.0"/>
        <vers num="4.0(1)"/>
        <vers num="4.0(2)"/>
        <vers num="4.1(0)"/>
        <vers num="4.1(1)"/>
        <vers num="4.1(2)"/>
      </prod>
      <prod vendor="cisco" name="ons_15454_optical_transport_platform">
        <vers num="4.0"/>
        <vers num="4.0(1)"/>
        <vers num="4.1"/>
        <vers num="4.1(0)"/>
        <vers num="4.1(1)"/>
        <vers num="4.1(2)"/>
        <vers num="4.1(3)"/>
      </prod>
      <prod vendor="cisco" name="ons_15454sdh">
        <vers num="4.0"/>
        <vers num="4.1(0)"/>
        <vers num="4.1(1)"/>
        <vers num="4.1(2)"/>
        <vers num="4.5"/>
      </prod>
      <prod vendor="cisco" name="ons_15600">
        <vers num="1.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0309" published="2004-11-23" name="CVE-2004-0309" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Stack-based buffer overflow in the SMTP service support in vsmon.exe in Zone Labs ZoneAlarm before 4.5.538.001, ZoneLabs Integrity client 4.0 before 4.0.146.046, and 4.5 before 4.5.085, allows remote attackers to execute arbitrary code via a long RCPT TO argument.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1" admin="1"/>
    </loss_types>
    <vuln_types>
      <input buffer="1"/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/619982" source="CERT-VN" adv="1">VU#619982</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107722656827427&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20040219 EEYE: ZoneLabs SMTP Processing Buffer Overflow</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/14991" source="XF" adv="1">zonelabs-multiple-products-bo(14991)</ref>
      <ref url="http://www.securityfocus.com/bid/9696" source="BID" adv="1">9696</ref>
      <ref url="http://download.zonelabs.com/bin/free/securityAlert/8.html" source="CONFIRM">http://download.zonelabs.com/bin/free/securityAlert/8.html</ref>
      <ref url="http://www.osvdb.org/3991" source="OSVDB">3991</ref>
      <ref url="http://www.ciac.org/ciac/bulletins/o-084.shtml" source="CIAC">O-084</ref>
    </refs>
    <vuln_soft>
      <prod vendor="zonelabs" name="integrity">
        <vers num="4.0"/>
      </prod>
      <prod vendor="zonelabs" name="zonealarm">
        <vers num="4.0" edition=""/>
        <vers num="4.0" edition=":pro"/>
        <vers num="4.0" edition=":plus"/>
        <vers num="4.5" edition=""/>
        <vers num="4.5" edition=":pro"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0310" published="2004-11-23" name="CVE-2004-0310" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in LiveJournal 1.0 and 1.1 allows remote attackers to execute Javascript as other users via the stylesheet, which does not strip the semicolon or parentheses, as demonstrated using a background:url.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/15268" source="XF">livejournal-url-xss(15268)</ref>
      <ref url="http://www.securityfocus.com/bid/9700" source="BID">9700</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107722627800820&amp;w=2" source="BUGTRAQ">20040219 LiveJournal XSS</ref>
    </refs>
    <vuln_soft>
      <prod vendor="livejournal" name="livejournal">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0311" published="2004-11-23" name="CVE-2004-0311" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">American Power Conversion (APC) Web/SNMP Management SmartSlot Card 3.0 through 3.0.3 and 3.21 are shipped with a default password of TENmanUFactOryPOWER, which allows remote attackers to gain unauthorized access.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1" admin="1"/>
    </loss_types>
    <vuln_types>
      <design/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/9681" source="BID" patch="1" adv="1">9681</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15238" source="XF" adv="1">apc-smartslot-default-password(15238)</ref>
      <ref url="http://nam-en.apc.com/cgi-bin/nam_en.cfg/php/enduser/std_adp.php?p_faqid=3131&amp;p_created=1077139129" source="CONFIRM">http://nam-en.apc.com/cgi-bin/nam_en.cfg/php/enduser/std_adp.php?p_faqid=3131&amp;p_created=1077139129</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107721020803565&amp;w=2" source="BUGTRAQ">20040219 Re: Fw: APC 9606 SmartSlot Web/SNMP management card "backdoor"</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107703696631367&amp;w=2" source="BUGTRAQ">20040216 APC 9606 SmartSlot Web/SNMP management card "backdoor"</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apc" name="ap9606">
        <vers num="3.0"/>
        <vers num="3.0.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0312" published="2004-11-23" name="CVE-2004-0312" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)" CVSS_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_base_score="6.4">
    <desc>
      <descript source="cve">Linksys WAP55AG 1.07 allows remote attackers with access to an SNMP read only community string to gain access to read/write communtiy strings via a query for OID 1.3.6.1.4.1.3955.2.1.13.1.2.</descript>
    </desc>
    <loss_types>
      <conf/>
      <int/>
    </loss_types>
    <vuln_types>
      <config/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/15257" source="XF" adv="1">linksys-snmp-strings-disclosure(15257)</ref>
      <ref url="http://www.securityfocus.com/bid/9688" source="BID" adv="1">9688</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107730681012131&amp;w=2" source="BUGTRAQ" adv="1">20040219 Re: SNMP community string disclosure in Linksys WAP55AG</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107712101324233&amp;w=2" source="BUGTRAQ">20040217 SNMP community string disclosure in Linksys WAP55AG</ref>
    </refs>
    <vuln_soft>
      <prod vendor="linksys" name="wap55ag">
        <vers num="1.0.7"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0313" published="2004-11-23" name="CVE-2004-0313" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Buffer overflow in PSOProxy 0.91 allows remote attackers to cause a denial of service and possibly execute arbitrary code via a long HTTP request, as demonstrated using a long (1) GET argument or (2) method name.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1" admin="1"/>
    </loss_types>
    <vuln_types>
      <input buffer="1"/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/15275" source="XF" adv="1">psoproxy-long-get-bo(15275)</ref>
      <ref url="http://www.securityfocus.com/bid/9706" source="BID" adv="1">9706</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107730731900261&amp;w=2" source="BUGTRAQ" adv="1">20040220 Remote Buffer Overflow in PSOProxy 0.91</ref>
    </refs>
    <vuln_soft>
      <prod vendor="psoproxy" name="psoproxy_server">
        <vers num="0.91"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0314" published="2004-11-23" name="CVE-2004-0314" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in done.jsp in WebzEdit 1.9 and earlier allows remote attackers to execute arbitrary script as other users via the message parameter.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/15289" source="XF" adv="1">webzedit-done-xss(15289)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107757029514146&amp;w=2" source="BUGTRAQ">20040221 Cross Site Scripting in WebzEdit</ref>
    </refs>
    <vuln_soft>
      <prod vendor="freewebs" name="webzedit">
        <vers prev="1" num="1.9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0315" published="2004-11-23" name="CVE-2004-0315" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Buffer overflow in Avirt Voice 4.0 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long GET request on port 1080.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1" admin="1"/>
    </loss_types>
    <vuln_types>
      <input buffer="1"/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/15288" source="XF">avirt-voice-get-bo(15288)</ref>
      <ref url="http://www.securityfocus.com/bid/9721" source="BID" adv="1">9721</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107756584609841&amp;w=2" source="BUGTRAQ" adv="1">20040223 Remote Buffer Overflow in Avirt Voice 4.0</ref>
    </refs>
    <vuln_soft>
      <prod vendor="avirt" name="voice">
        <vers num="4.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0316" published="2004-11-23" name="CVE-2004-0316" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Buffer overflow in Avirt Soho 4.3 allows remote attackers to cause a denial of service (crash) via (1) a large GET request to port 1080 or (2) a large GET request of % characters to port 8080.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <vuln_types>
      <input buffer="1"/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/15286" source="XF" adv="1">avirt-soho-multiple-bo(15286)</ref>
      <ref url="http://www.securityfocus.com/bid/9723" source="BID" adv="1">9723</ref>
      <ref url="http://www.securityfocus.com/bid/9722" source="BID" adv="1">9722</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107756666701194&amp;w=2" source="BUGTRAQ" adv="1">20030223 Multiple Remote Buffer Overflow in Avirt Soho 4.3</ref>
    </refs>
    <vuln_soft>
      <prod vendor="avirt" name="avirt_soho">
        <vers num="4.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0317" published="2004-11-23" name="CVE-2004-0317" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Buffer overflow in eauth in Load Sharing Facility 4.x, 5.x, and 6.x allows local users or remote attackers within the LSF cluster to cause a denial of service (segmentation fault) and possibly execute arbitrary code via a long LSF_From_PC parameter.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1" admin="1"/>
    </loss_types>
    <vuln_types>
      <input buffer="1"/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/9719" source="BID" patch="1" adv="1">9719</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107756611501236&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20040223 Lam3rZ Security Advisory #1/2004: LSF eauth vulnerability leads to remote code execution</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15282" source="XF" adv="1">lsf-eauth-execute-code(15282)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="platform" name="lsf">
        <vers num="4.0"/>
        <vers num="4.2"/>
        <vers num="5.0"/>
        <vers num="5.1"/>
        <vers num="6.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0318" published="2004-11-23" name="CVE-2004-0318" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Load Sharing Facility (LSF) 4.x, 5.x, and 6.x uses the LSF_EAUTH_UID environment variable, if it exists, instead of the real UID of the user, which could allow remote attackers within the local cluster to gain privileges.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1" admin="1"/>
    </loss_types>
    <vuln_types>
      <design/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/9724" source="BID" patch="1" adv="1">9724</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107756600403557&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20040223 Lam3rZ Security Advisory #2/2004: LSF eauth vulnerability leads to a possibility of controlling cluster jobs on behalf of other users</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15278" source="XF" adv="1">lsf-eauth-process-hijack(15278)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="platform" name="lsf">
        <vers num="4.0"/>
        <vers num="4.2"/>
        <vers num="5.0"/>
        <vers num="5.1"/>
        <vers num="6.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0319" published="2004-11-23" name="CVE-2004-0319" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in the font tag in ezBoard 7.3u allows remote attackers to execute arbitrary script as other users, as demonstrated using the background:url in a (1) font color or (2) font face argument.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/15287" source="XF">ezboard-font-xss(15287)</ref>
      <ref url="http://www.securityfocus.com/bid/9725" source="BID">9725</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107756639427140&amp;w=2" source="BUGTRAQ">20040223 ezBoard Cross Site Scripting Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ezboard" name="ezboard">
        <vers num="7.3u"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2004-0320" published="2004-11-23" name="CVE-2004-0320" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">Unknown vulnerability in nCipher Hardware Security Modules (HSM) 1.67.x through 1.99.x allows local users to access secrets stored in the module's run-time memory via certain sequences of commands.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <vuln_types>
      <design/>
      <exception/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107755899018249&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20040223 nCipher Advisory #9: Host-side attackers can access secret data</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15281" source="XF" adv="1">ncipher-hsm-obtain-info(15281)</ref>
      <ref url="http://www.securityfocus.com/bid/9717" source="BID" adv="1">9717</ref>
      <ref url="http://www.osvdb.org/4055" source="OSVDB">4055</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ncipher" name="nshield">
        <vers num="1.71.11"/>
        <vers num="1.71.15"/>
        <vers num="1.71.90"/>
        <vers num="1.75.15"/>
        <vers num="1.77.9"/>
        <vers num="1.77.93"/>
        <vers num="1.77.97"/>
        <vers num="1.79.12"/>
        <vers num="1.79.80"/>
        <vers num="1.79.81"/>
        <vers num="2.0"/>
        <vers num="2.0.4"/>
        <vers num="2.12"/>
        <vers num="2.12.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0321" published="2004-11-23" name="CVE-2004-0321" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Team Factor 1.25 and earlier allows remote attackers to cause a denial of service (crash) via a packet that uses a negative number to specify the size of the data block that follows, which causes Team Factor to read unallocated memory.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <vuln_types>
      <input bound="1"/>
      <exception/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107756001412888&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20040223 Remote server crash in Team Factor &lt;= 1.25</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15274" source="XF" adv="1">teamfactor-packet-dos(15274)</ref>
      <ref url="http://www.zone-h.org/advisories/read/id=4006" source="MISC">http://www.zone-h.org/advisories/read/id=4006</ref>
      <ref url="http://www.securityfocus.com/bid/9708" source="BID" adv="1">9708</ref>
    </refs>
    <vuln_soft>
      <prod vendor="singularity_software" name="team_factor">
        <vers num="1.25"/>
        <vers num="1.25m"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0322" published="2004-02-23" name="CVE-2004-0322" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in XMB 1.8 Final SP2 allow remote attackers to execute arbitrary script as other users via the (1) member parameter in member.php, (2) uid parameter in u2uadmin.php, (3) user parameter in editprofile.php, (4) an onmouseover event in an align tag when bbcode is allowed, or (5) img tag where bbcode is allowed.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/15292" source="XF" patch="1" adv="1">xmb-multiple-scripts-xss(15292)</ref>
      <ref url="http://www.securityfocus.com/bid/9726" source="BID" patch="1" adv="1">9726</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107756526625179&amp;w=2" source="BUGTRAQ" adv="1">20040223 [waraxe-2004-SA#004] - Multiple vulnerabilities in XMB 1.8 Partagium Final SP2</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15294" source="XF">xmb-bbcode-execute-code(15294)</ref>
      <ref url="http://www.xmbforum.com/community/boards/viewthread.php?tid=746859" source="CONFIRM">http://www.xmbforum.com/community/boards/viewthread.php?tid=746859</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2004-02/0645.html" source="BUGTRAQ">20040225 Re: [waraxe-2004-SA#004] - Multiple vulnerabilities in XMB 1.8 Partagium Final SP2</ref>
    </refs>
    <vuln_soft>
      <prod vendor="xmb_forum" name="xmb">
        <vers num="1.8"/>
        <vers num="1.8_sp1"/>
        <vers num="1.8_sp2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0323" published="2004-12-31" name="CVE-2004-0323" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple SQL injection vulnerabilities in XMB 1.8 Final SP2 allow remote attackers to inject arbitrary SQL and gain privileges via the (1) ppp parameter in viewthread.php, (2) desc parameter in misc.php, (3) tpp parameter in forumdisplay.php, (4) ascdesc parameter in forumdisplay.php, or (5) the addon parameter in stats.php.  NOTE: it has also been shown that item (3) is also in XMB 1.9 beta.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/15295" source="XF" patch="1">xmb-multiple-sql-injection(15295)</ref>
      <ref url="http://www.securityfocus.com/bid/9726" source="BID" patch="1">9726</ref>
      <ref url="http://www.xmbforum.com/community/boards/viewthread.php?tid=746859" source="CONFIRM">http://www.xmbforum.com/community/boards/viewthread.php?tid=746859</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107756526625179&amp;w=2" source="BUGTRAQ" adv="1">20040223 [waraxe-2004-SA#004] - Multiple vulnerabilities in XMB 1.8 Partagium Final SP2</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2004-03/0265.html" source="BUGTRAQ">20040326 [waraxe-2004-SA#012 - Multiple vulnerabilities in XMB Forum 1.8 SP3 and 1.9 beta]</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2004-02/0645.html" source="BUGTRAQ">20040225 Re: [waraxe-2004-SA#004] - Multiple vulnerabilities in XMB 1.8 Partagium Final SP2</ref>
    </refs>
    <vuln_soft>
      <prod vendor="xmb_forum" name="xmb">
        <vers num="1.8"/>
        <vers num="1.8_sp1"/>
        <vers num="1.8_sp2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0324" published="2004-02-23" name="CVE-2004-0324" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Confirm 0.62 and earlier could allow remote attackers to execute arbitrary code via an e-mail header that contains shell metacharacters such as ", `, |, ;, or $.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/15290" source="XF" patch="1" adv="1">confirm-header-gain-access(15290)</ref>
      <ref url="http://www.securityfocus.com/bid/9728" source="BID" patch="1" adv="1">9728</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107757320401858&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20040223 Lam3rZ Security Advisory #3/2004: A bug in Confirm leads to remote command execution</ref>
    </refs>
    <vuln_soft>
      <prod vendor="confirm" name="confirm">
        <vers num="0.50"/>
        <vers num="0.51"/>
        <vers num="0.52"/>
        <vers num="0.53"/>
        <vers num="0.54"/>
        <vers num="0.55"/>
        <vers num="0.60"/>
        <vers num="0.61"/>
        <vers num="0.62"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2004-0325" published="2004-12-31" name="CVE-2004-0325" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">TYPSoft FTP Server 1.10 allows remote authenticated users to cause a denial of service (CPU consumption) via "//../" arguments to (1) mkd, (2) xmkd, (3) dele, (4) size, (5) retr, (6) stor, (7) appe, (8) rnfr, (9) rnto, (10) rmd, or (11) xrmd, as demonstrated using "//../qwerty".</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <vuln_types>
      <exception/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/15306" source="XF">typsoft-ftp-command-dos(15306)</ref>
      <ref url="http://www.securityfocus.com/bid/9702" source="BID">9702</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107764173821905&amp;w=2" source="BUGTRAQ" adv="1">20040223 TYPSoft FTP Server 1.10 multiple vulnerabilities</ref>
    </refs>
    <vuln_soft>
      <prod vendor="typsoft" name="typsoft_ftp_server">
        <vers num="1.10"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0326" published="2004-11-23" name="CVE-2004-0326" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Buffer overflow in the web proxy for GateKeeper Pro 4.7 allows remote attackers to execute arbitrary code via a long GET request.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1" admin="1"/>
    </loss_types>
    <vuln_types>
      <input buffer="1"/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/15277" source="XF" adv="1">gatekeeper-long-get-bo(15277)</ref>
      <ref url="http://www.securityfocus.com/bid/9716" source="BID" adv="1">9716</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107755692400728&amp;w=2" source="BUGTRAQ" adv="1">20040222 GateKeeper Pro 4.7 buffer overflow</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2004-February/017703.html" source="FULLDISC">20040222 GateKeeper Pro 4.7 buffer overflow</ref>
    </refs>
    <vuln_soft>
      <prod vendor="proxy-pro" name="professional_gatekeeper">
        <vers num="4.7"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0327" published="2004-11-23" name="CVE-2004-0327" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in functions.php in PhpNewsManager 1.46 allows remote attackers to retrieve arbitrary files via ..  (dot dot) sequences in the clang parameter.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <vuln_types>
      <access/>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/15283" source="XF" adv="1">phpnewsmanager-dotdot-directory-traversal(15283)</ref>
      <ref url="http://www.zone-h.org/advisories/read/id=4024" source="MISC">http://www.zone-h.org/advisories/read/id=4024</ref>
      <ref url="http://www.securityfocus.com/bid/9720" source="BID" adv="1">9720</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107772470111000&amp;w=2" source="BUGTRAQ" adv="1">20040223 ZH2004-09SA (security advisory): PhpNewsManager Remote arbitrary</ref>
    </refs>
    <vuln_soft>
      <prod vendor="skintech" name="phpnewsmanager">
        <vers num="1.36"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0328" published="2004-11-23" name="CVE-2004-0328" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Gigabyte Gn-B46B 2.4Ghz wireless broadband router firmware 1.003.00 allows local users on the same local network as the router to bypass authentication by using a copy of the router's html menu on a separate system.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1" admin="1"/>
    </loss_types>
    <vuln_types>
      <access/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/15313" source="XF" adv="1">gigabyte-gnb46b-bypass-authentication(15313)</ref>
      <ref url="http://www.securityfocus.com/bid/9740" source="BID" adv="1">9740</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107766719227942&amp;w=2" source="BUGTRAQ" adv="1">20040224 Gigabyte Broadband Router  - Multiple Vulnerabilities</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gigabyte" name="gn-b46b">
        <vers num="1.003.00"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0329" published="2004-11-23" name="CVE-2004-0329" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">FreeChat 1.1.1a allows remote attackers to cause a denial of service (crash) via certain unexpected strings, as demonstrated using "aaaaa".</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <vuln_types>
      <exception/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/15321" source="XF" adv="1">freechat-string-dos(15321)</ref>
      <ref url="http://www.securityfocus.com/bid/9744" source="BID" adv="1">9744</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107781043621074&amp;w=2" source="BUGTRAQ" adv="1">20040226 Denial Of Service in FreeChat 1.1.1a</ref>
    </refs>
    <vuln_soft>
      <prod vendor="freechat" name="freechat">
        <vers num="0.1.1a"/>
        <vers num="1.1.1a"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0330" published="2004-11-23" name="CVE-2004-0330" modified="2010-04-28" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Buffer overflow in Serv-U ftp before 5.0.0.4 allows remote authenticated users to execute arbitrary code via a long time zone argument to the MDTM command.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1" admin="1"/>
    </loss_types>
    <vuln_types>
      <input buffer="1"/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/15323" source="XF" adv="1">servu-mdtm-bo(15323)</ref>
      <ref url="http://www.securityfocus.com/bid/9751" source="BID" adv="1">9751</ref>
      <ref url="http://www.cnhonker.com/advisory/serv-u.mdtm.txt" source="MISC">http://www.cnhonker.com/advisory/serv-u.mdtm.txt</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107781164214399&amp;w=2" source="BUGTRAQ" adv="1">20040226 [vulnwatch] Serv-U MDTM Command Buffer Overflow Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="serv-u" name="serv-u">
        <vers num="3.0.0.16"/>
        <vers num="3.0.0.17"/>
        <vers num="3.1.0.0"/>
        <vers num="3.1.0.1"/>
        <vers num="3.1.0.3"/>
        <vers num="4.0.0.4"/>
        <vers num="4.1.0.0"/>
        <vers num="4.1.0.3"/>
        <vers prev="1" num="5.0.0.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0331" published="2004-11-23" name="CVE-2004-0331" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Heap-based buffer overflow in Dell OpenManage Web Server 3.4.0 allows remote attackers to cause a denial of service (crash) via a HTTP POST with a long application variable.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <vuln_types>
      <input buffer="1"/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/9750" source="BID" patch="1" adv="1">9750</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15325" source="XF" adv="1">dell-openmanage-ocsgetoeminpathfile-bo(15325)</ref>
      <ref url="http://sh0dan.org/files/domadv.txt" source="MISC">http://sh0dan.org/files/domadv.txt</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107781539829143&amp;w=2" source="BUGTRAQ" adv="1">20040226  Dell OpenManage Web Server Heap Overflow (Pre-Auth)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="dell" name="openmanage">
        <vers num="3.2"/>
        <vers num="3.4"/>
        <vers num="3.7"/>
        <vers num="3.7.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0332" published="2004-11-23" name="CVE-2004-0332" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Extremail 1.5.9 does not check passwords correctly when they are all digits or begin with a digit, which allows remote attackers to gain privileges.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1" admin="1"/>
    </loss_types>
    <vuln_types>
      <exception/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/15329" source="XF" adv="1">extremail-password-gain-access(15329)</ref>
      <ref url="http://www.securityfocus.com/bid/9754" source="BID" adv="1">9754</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107783767517850&amp;w=2" source="BUGTRAQ" adv="1">20040226 Extremail Security Problem</ref>
    </refs>
    <vuln_soft>
      <prod vendor="extremail" name="extremail">
        <vers num="1.0"/>
        <vers num="1.0.1"/>
        <vers num="1.0.2"/>
        <vers num="1.0.3"/>
        <vers num="1.1"/>
        <vers num="1.1.1"/>
        <vers num="1.1.10"/>
        <vers num="1.1.2"/>
        <vers num="1.1.3"/>
        <vers num="1.1.4"/>
        <vers num="1.1.5"/>
        <vers num="1.1.6"/>
        <vers num="1.1.7"/>
        <vers num="1.1.8"/>
        <vers num="1.1.9"/>
        <vers num="1.5"/>
        <vers num="1.5.5"/>
        <vers num="1.5.8"/>
        <vers num="1.5.9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0333" published="2004-11-23" name="CVE-2004-0333" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Buffer overflow in the UUDeview package, as used in WinZip 6.2 through WinZip 8.1 SR-1, and possibly other packages, allows remote attackers to execute arbitrary code via a MIME archive with certain long MIME parameters.</descript>
    </desc>
    <sols>
      <sol source="nvd">This was fixed in WinZip 8.1 SR-2 in March of 2004. You can find more information on the subject on the following pages of the winzip site:
http://www.winzip.com/wz81sr2.htm
http://www.winzip.com/fmwz90.htm</sol>
    </sols>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1" admin="1"/>
    </loss_types>
    <vuln_types>
      <input buffer="1"/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/116182" source="CERT-VN" adv="1">VU#116182</ref>
      <ref url="http://www.securityfocus.com/bid/9758" source="BID" patch="1" adv="1">9758</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15490" source="XF">uudeview-multiple-bo(15490)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15336" source="XF" adv="1">winzip-mime-bo(15336)</ref>
      <ref url="http://www.winzip.com/fmwz90.htm" source="CONFIRM">http://www.winzip.com/fmwz90.htm</ref>
      <ref url="http://www.osvdb.org/4119" source="OSVDB">4119</ref>
      <ref url="http://www.openpkg.org/security/OpenPKG-SA-2004.006-uudeview.html" source="CONFIRM">http://www.openpkg.org/security/OpenPKG-SA-2004.006-uudeview.html</ref>
      <ref url="http://www.idefense.com/application/poi/display?id=76&amp;type=vulnerabiliti&amp;flashstatus=true" source="IDEFENSE">20040227 WinZip MIME Parsing Buffer Overflow Vulnerability</ref>
      <ref url="http://www.ciac.org/ciac/bulletins/o-092.shtml" source="CIAC">O-092</ref>
      <ref url="http://secunia.com/advisories/11019" source="SECUNIA">11019</ref>
      <ref url="http://secunia.com/advisories/10995" source="SECUNIA">10995</ref>
    </refs>
    <vuln_soft>
      <prod vendor="openpkg" name="openpkg">
        <vers num=""/>
      </prod>
      <prod vendor="uudeview" name="uudeview">
        <vers num="0.5.18"/>
        <vers num="0.5.19"/>
      </prod>
      <prod vendor="winzip" name="winzip">
        <vers num="7.0"/>
        <vers num="8.0"/>
        <vers num="8.1" edition="sr1"/>
      </prod>
      <prod vendor="gentoo" name="linux">
        <vers num="1.4" edition="rc1"/>
        <vers num="1.4" edition="rc2"/>
        <vers num="1.4" edition="rc3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0334" published="2004-11-23" name="CVE-2004-0334" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">InnoMedia VideoPhone allows remote attackers to bypass Basic Authorization via an HTTP request to (1) videophone_admindetail.asp, (2) videophone_syscfg.asp, (3) videophone_upgrade.asp, or (4) videophone_sysctrl.asp that contains a trailing / (slash).  NOTE: the original report mentioned AXIS 2100 Network Camera, but this was likely a cut-and-paste error.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <vuln_types>
      <access/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/15636" source="XF">InnoMedia-videophone-bypass-authentication(15636)</ref>
      <ref url="http://www.osvdb.org/4809" source="OSVDB">4809</ref>
      <ref url="http://securitytracker.com/alerts/2004/Mar/1009522.html" source="SECTRACK">1009522</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107799556111784&amp;w=2" source="BUGTRAQ">20040227 InnoMedia VideoPhone Authorization Bypass</ref>
    </refs>
    <vuln_soft>
      <prod vendor="innomedia" name="innomedia_videophone">
        <vers num="au75200xvi04010x"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0335" published="2004-11-23" name="CVE-2004-0335" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">LAN SUITE Web Mail 602Pro, when configured to use the "Directory browsing" feature, allows remote attackers to obtain a directory listing via an HTTP request to (1) index.html, (2) cgi-bin/, or (3) users/.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <vuln_types>
      <config/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/15349" source="XF" adv="1">602pro-directory-listing(15349)</ref>
      <ref url="http://www.securityfocus.com/bid/9780" source="BID">9780</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2004-03/0096.html" source="BUGTRAQ">20040310 Re: LAN SUITE Web Mail 602Pro Multiple Vulnerabilities</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107799540630302&amp;w=2" source="BUGTRAQ">20040228 LAN SUITE Web Mail 602Pro Multiple Vulnerabilities</ref>
    </refs>
    <vuln_soft>
      <prod vendor="software602" name="602pro_lan_suite">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0336" published="2004-11-23" name="CVE-2004-0336" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">LAN SUITE Web Mail 602Pro allows remote attackers to gain sensitive information via the mail login form, which contains the path to the mail directory.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <vuln_types>
      <design/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/15350" source="XF" adv="1">602pro-path-disclosure(15350)</ref>
      <ref url="http://www.securityfocus.com/bid/9781" source="BID" adv="1">9781</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107799540630302&amp;w=2" source="BUGTRAQ" adv="1">20040228 LAN SUITE Web Mail 602Pro Multiple Vulnerabilities</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2004-03/0096.html" source="BUGTRAQ">20040310 Re: LAN SUITE Web Mail 602Pro Multiple Vulnerabilities</ref>
    </refs>
    <vuln_soft>
      <prod vendor="software602" name="602pro_lan_suite">
        <vers num="2002"/>
        <vers num="2003"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0337" published="2004-11-23" name="CVE-2004-0337" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in LAN SUITE Web Mail 602Pro allows remote attackers to execute arbitrary script or HTML as other users via a URL to index.html, followed by a / (slash) and the desired script.  NOTE: the vendor states that this bug could not be reproduced, so this issue may be REJECTed in the future.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/15351" source="XF">602pro-index-xss(15351)</ref>
      <ref url="http://www.securityfocus.com/bid/9777" source="BID">9777</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107799540630302&amp;w=2" source="BUGTRAQ">20040228 LAN SUITE Web Mail 602Pro Multiple Vulnerabilities</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2004-03/0096.html" source="BUGTRAQ">20040310 Re: LAN SUITE Web Mail 602Pro Multiple Vulnerabilities</ref>
    </refs>
    <vuln_soft>
      <prod vendor="software602" name="602pro_lan_suite">
        <vers num="2002"/>
        <vers num="2003"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0338" published="2004-11-23" name="CVE-2004-0338" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">SQL injection vulnerability in search.php for Invision Board Forum allows remote attackers to execute arbitrary SQL queries via the st parameter.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1" admin="1"/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107799527428834&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20040228 Invision Power Board SQL injection!</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15343" source="XF" adv="1">invision-search-sql-injection(15343)</ref>
      <ref url="http://www.securityfocus.com/bid/9766" source="BID">9766</ref>
    </refs>
    <vuln_soft>
      <prod vendor="invision_power_services" name="invision_board">
        <vers num="1.0"/>
        <vers num="1.0.1"/>
        <vers num="1.1.1"/>
        <vers num="1.1.2"/>
        <vers num="1.2"/>
        <vers num="1.3"/>
        <vers num="2.0_alpha_3"/>
        <vers num="2.0_pdr3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0339" published="2004-11-23" name="CVE-2004-0339" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in ViewTopic.php in phpBB, possibly 2.0.6c and earlier, allows remote attackers to execute arbitrary script or HTML as other users via the postorder parameter.</descript>
    </desc>
    <sols>
      <sol source="nvd">This vulnerability is addressed in the following product release:
phpBB Group, phpBB, 2.0.7</sol>
    </sols>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/9765" source="BID" patch="1">9765</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15348" source="XF">phpbb-viewtopicphp-xss(15348)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107799508130700&amp;w=2" source="BUGTRAQ">20040228 New phpBB ViewTopic.php Cross Site Scripting Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="phpbb_group" name="phpbb">
        <vers num="2.0"/>
        <vers num="2.0.1"/>
        <vers num="2.0.2"/>
        <vers num="2.0.3"/>
        <vers num="2.0.4"/>
        <vers num="2.0.5"/>
        <vers num="2.0.6"/>
        <vers num="2.0.6c"/>
        <vers num="2.0_rc4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0340" published="2004-11-23" name="CVE-2004-0340" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Stack-based buffer overflow in WFTPD Pro Server 3.21 Release 1, Pro Server 3.20 Release 2, Server 3.21 Release 1, and Server 3.10 allows local users to execute arbitrary code via long (1) LIST, (2) NLST, or (3) STAT commands.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1" admin="1"/>
    </loss_types>
    <vuln_types>
      <input buffer="1"/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/9767" source="BID" patch="1" adv="1">9767</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15340" source="XF" adv="1">wftpd-ftp-commands-bo(15340)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107801208004699&amp;w=2" source="BUGTRAQ" adv="1">20040228 Critical WFTPD buffer overflow vulnerability</ref>
      <ref url="http://secunia.com/advisories/11001" source="SECUNIA">11001</ref>
    </refs>
    <vuln_soft>
      <prod vendor="texas_imperial_software" name="wftpd">
        <vers num="3.0" edition=""/>
        <vers num="3.0" edition=":pro"/>
        <vers num="3.0_0r3"/>
        <vers num="3.0_0r4" edition=""/>
        <vers num="3.0_0r4" edition=":pro"/>
        <vers num="3.0_0r5" edition=""/>
        <vers num="3.0_0r5" edition=":pro"/>
        <vers num="3.10_r1"/>
        <vers num="3.20"/>
        <vers num="3.21"/>
        <vers num="pro_3.10_r1"/>
        <vers num="pro_3.20"/>
        <vers num="pro_3.21"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2004-0341" published="2004-11-23" name="CVE-2004-0341" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">WFTPD Pro Server 3.21 Release 1 allocates memory for a command until a 0Ah byte (newline) is sent, which allows local users to cause a denial of service (CPU consumption) by continuing to send a long command that does not contain a newline.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <vuln_types>
      <design/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/9767" source="BID" patch="1" adv="1">9767</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15341" source="XF" adv="1">wftpd-string-0Ahbyte-dos(15341)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107801142924976&amp;w=2" source="BUGTRAQ" adv="1">20040228 Multiple WFTPD Denial of Service vulnerabilities</ref>
      <ref url="http://www.osvdb.org/4115" source="OSVDB">4115</ref>
      <ref url="http://secunia.com/advisories/11001" source="SECUNIA">11001</ref>
    </refs>
    <vuln_soft>
      <prod vendor="texas_imperial_software" name="wftpd">
        <vers num="3.0" edition=""/>
        <vers num="3.0" edition=":pro"/>
        <vers num="3.0_0r3"/>
        <vers num="3.0_0r4" edition=""/>
        <vers num="3.0_0r4" edition=":pro"/>
        <vers num="3.0_0r5" edition=""/>
        <vers num="3.0_0r5" edition=":pro"/>
        <vers num="3.10_r1"/>
        <vers num="3.20"/>
        <vers num="3.21"/>
        <vers num="pro_3.10_r1"/>
        <vers num="pro_3.20"/>
        <vers num="pro_3.21"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2004-0342" published="2004-11-23" name="CVE-2004-0342" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">WFTPD Pro Server 3.21 Release 1, with the XeroxDocutech option enabled, allows local users to cause a denial of service (crash) via a (1) MKD or (2) XMKD command that causes an absolute path of 260 characters to be used, which overwrites a cookie with a null character, possibly due to an off-by-one error.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <vuln_types>
      <input bound="1"/>
      <exception/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/9767" source="BID" patch="1" adv="1">9767</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15342" source="XF" adv="1">wftpd-ftp-command-dos(15342)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107801142924976&amp;w=2" source="BUGTRAQ" adv="1">20040228 Multiple WFTPD Denial of Service vulnerabilities</ref>
      <ref url="http://www.osvdb.org/4116" source="OSVDB">4116</ref>
      <ref url="http://secunia.com/advisories/11001" source="SECUNIA">11001</ref>
    </refs>
    <vuln_soft>
      <prod vendor="texas_imperial_software" name="wftpd">
        <vers num="3.0" edition=""/>
        <vers num="3.0" edition=":pro"/>
        <vers num="3.0_0r3"/>
        <vers num="3.0_0r4" edition=""/>
        <vers num="3.0_0r4" edition=":pro"/>
        <vers num="3.0_0r5" edition=""/>
        <vers num="3.0_0r5" edition=":pro"/>
        <vers num="3.10_r1"/>
        <vers num="3.20"/>
        <vers num="3.21"/>
        <vers num="pro_3.10_r1"/>
        <vers num="pro_3.20"/>
        <vers num="pro_3.21"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0343" published="2004-11-23" name="CVE-2004-0343" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Multiple SQL injection vulnerabilities in YaBB SE 1.5.4 through 1.5.5b allow remote attackers to execute arbitrary SQL via (1) the msg parameter in ModifyMessage.php or (2) the postid parameter in ModifyMessage.php.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1" admin="1"/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/9774" source="BID" patch="1" adv="1">9774</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15354" source="XF" adv="1">yabb-multiple-sql-injection(15354)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107816202813083&amp;w=2" source="BUGTRAQ">20040301 YabbSE  (3 on 1)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="yabb" name="yabb">
        <vers num="1.5.4" edition=""/>
        <vers num="1.5.4" edition=":second_edition"/>
        <vers num="1.5.5" edition=""/>
        <vers num="1.5.5" edition=":second_edition"/>
        <vers num="1.5.5b" edition=""/>
        <vers num="1.5.5b" edition=":second_edition"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0344" published="2004-11-23" name="CVE-2004-0344" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:P)" CVSS_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_base_score="6.4">
    <desc>
      <descript source="cve">Directory traversal vulnerability in ModifyMessage.php in YaBB SE 1.5.4 through 1.5.5b allows remote attackers to delete arbitrary files via a .. (dot dot) in the attachOld parameter.</descript>
    </desc>
    <loss_types>
      <avail/>
      <int/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/9774" source="BID" patch="1" adv="1">9774</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107816202813083&amp;w=2" source="BUGTRAQ">20040301 YabbSE  (3 on 1)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="yabb" name="yabb">
        <vers num="1.5.5" edition=""/>
        <vers num="1.5.5" edition=":second_edition"/>
        <vers num="1.5.5b" edition=""/>
        <vers num="1.5.5b" edition=":second_edition"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0345" published="2004-11-23" name="CVE-2004-0345" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Buffer overflow in Red Faction client 1.20 and earlier allows remote servers to execute arbitrary code via a long server name.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1" admin="1"/>
    </loss_types>
    <vuln_types>
      <input buffer="1"/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/15353" source="XF" adv="1">redfaction-bo(15353)</ref>
      <ref url="http://www.securityfocus.com/bid/9775" source="BID" adv="1">9775</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107816217901923&amp;w=2" source="BUGTRAQ" adv="1">20040301 Clients broadcast buffer overflow in Red Faction &lt;= 1.20</ref>
    </refs>
    <vuln_soft>
      <prod vendor="volition" name="red_faction">
        <vers num="1.0"/>
        <vers num="1.1"/>
        <vers num="1.20"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0346" published="2004-11-23" name="CVE-2004-0346" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Off-by-one buffer overflow in _xlate_ascii_write() in ProFTPD 1.2.7 through 1.2.9rc2p allows local users to gain privileges via a 1024 byte RETR command.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1" admin="1"/>
    </loss_types>
    <vuln_types>
      <input buffer="1"/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/15387" source="XF" adv="1">proftpd-offbyone-bo(15387)</ref>
      <ref url="http://www.securityfocus.com/bid/9782" source="BID" adv="1">9782</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107824679817240&amp;w=2" source="BUGTRAQ">20040302 The Cult of a Cardinal Number</ref>
    </refs>
    <vuln_soft>
      <prod vendor="proftpd_project" name="proftpd">
        <vers num="1.2.7"/>
        <vers num="1.2.8"/>
        <vers num="1.2.9_rc1"/>
        <vers num="1.2.9_rc2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0347" published="2004-11-23" name="CVE-2004-0347" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:S/C:P/I:P/A:P)" CVSS_score="6.0" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="6.8" CVSS_base_score="6.0">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in delhomepage.cgi in NetScreen-SA 5000 Series running firmware 3.3 Patch 1 (build 4797) allows remote authenticated users to execute arbitrary script as other users via the row parameter.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/114070" source="CERT-VN">VU#114070</ref>
      <ref url="http://www.securityfocus.com/bid/9791" source="BID" patch="1">9791</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107850564102190&amp;w=2" source="BUGTRAQ" patch="1">20040304 NetScreen Advisory 58412: XSS Bug in NetScreen-SA SSL VPN</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107826362024112&amp;w=2" source="BUGTRAQ" patch="1">20040302 03-02-04 XSS Bug in NetScreen-SA 5000 Series of SSL VPN appliance</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15368" source="XF">netscreen-delhomepagecgi-xss(15368)</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2004-March/018120.html" source="FULLDISC">20040302 03-02-04 XSS Bug in NetScreen-SA 5000 Series of SSL VPN appliance</ref>
    </refs>
    <vuln_soft>
      <prod vendor="netscreen" name="netscreen-sa_5000_series">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0348" published="2004-11-23" name="CVE-2004-0348" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">SQL injection vulnerability in viewCart.asp in SpiderSales shopping cart software allows remote attackers to execute arbitrary SQL via the userId parameter.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1" admin="1"/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/15371" source="XF" adv="1">spidersales-userid-sql-injection(15371)</ref>
      <ref url="http://www.securityfocus.com/bid/9799" source="BID" adv="1">9799</ref>
      <ref url="http://www.s-quadra.com/advisories/Adv-20040303.txt" source="MISC">http://www.s-quadra.com/advisories/Adv-20040303.txt</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107833097705486&amp;w=2" source="BUGTRAQ" adv="1">20040303 Spider Sales shopping cart software multiple security vulnerabilities</ref>
    </refs>
    <vuln_soft>
      <prod vendor="spidersales" name="spidersales">
        <vers num="2.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0349" published="2004-11-23" name="CVE-2004-0349" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in GWeb HTTP Server 0.6 allows remote attackers to view arbitrary files via a .. (dot dot) in the URL.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107833161617397&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20040303 directory traversal in GWeb 0.6</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15381" source="XF" adv="1">gweb-dotdot-directory-traversal(15381)</ref>
      <ref url="http://www.securityfocus.com/bid/9742" source="BID" adv="1">9742</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gweb" name="gweb_http_server">
        <vers num="0.5"/>
        <vers num="0.6"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2004-0350" published="2004-11-23" name="CVE-2004-0350" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">SpiderSales shopping cart does not enforce a minimum length for the private key, which can make it easier for local users to obtain the private key by factoring.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <vuln_types>
      <design/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/15370" source="XF" adv="1">spidersales-weak-encryption(15370)</ref>
      <ref url="http://www.securityfocus.com/bid/9799" source="BID" adv="1">9799</ref>
      <ref url="http://www.s-quadra.com/advisories/Adv-20040303.txt" source="MISC">http://www.s-quadra.com/advisories/Adv-20040303.txt</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107833097705486&amp;w=2" source="BUGTRAQ" adv="1">20040303 Spider Sales shopping cart software multiple security vulnerabilities</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2004-March/018177.html" source="FULLDISC">20040303 Spider Sales shopping cart software multiple security vulnerabilities</ref>
    </refs>
    <vuln_soft>
      <prod vendor="spidersales" name="spidersales">
        <vers num="2.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2004-0351" published="2004-11-23" name="CVE-2004-0351" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">Spider Sales shopping cart stores the private key in the same database and table as the public key, which allows local users with access to the database to decrypt data.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <vuln_types>
      <design/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/15370" source="XF" adv="1">spidersales-weak-encryption(15370)</ref>
      <ref url="http://www.securityfocus.com/bid/9799" source="BID" adv="1">9799</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107833097705486&amp;w=2" source="BUGTRAQ" adv="1">20040303 Spider Sales shopping cart software multiple security vulnerabilities</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2004-March/018177.html" source="FULLDISC">20040303 Spider Sales shopping cart software multiple security vulnerabilities</ref>
    </refs>
    <vuln_soft>
      <prod vendor="spidersales" name="spidersales">
        <vers num="2.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0352" published="2004-11-23" name="CVE-2004-0352" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Cisco 11000 Series Content Services Switches (CSS) running WebNS 5.0(x) before 05.0(04.07)S, and 6.10(x) before 06.10(02.05)S allow remote attackers to cause a denial of service (device reset) via a malformed packet to UDP port 5002.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <vuln_types>
      <input/>
      <design/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/363374" source="CERT-VN" adv="1">VU#363374</ref>
      <ref url="http://www.securityfocus.com/bid/9806" source="BID" patch="1" adv="1">9806</ref>
      <ref url="http://www.cisco.com/warp/public/707/cisco-sa-20040304-css.shtml" source="CISCO" patch="1" adv="1">20040304 Cisco CSS 11000 Series Content Services Switches Malformed UDP Packet Vulnerability</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15388" source="XF" adv="1">cisco-css-udp-dos(15388)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="content_services_switch_11000">
        <vers num=""/>
      </prod>
      <prod vendor="cisco" name="content_services_switch_11050">
        <vers num=""/>
      </prod>
      <prod vendor="cisco" name="content_services_switch_11150">
        <vers num=""/>
      </prod>
      <prod vendor="cisco" name="content_services_switch_11800">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0353" published="2004-11-23" name="CVE-2004-0353" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Multiple buffer overflows in auth_ident() function in auth.c for GNU Anubis 3.6.0 through 3.6.2, 3.9.92 and 3.9.93 allow remote attackers to gain privileges via a long string.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1" admin="1"/>
    </loss_types>
    <vuln_types>
      <input buffer="1"/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/9772" source="BID" patch="1" adv="1">9772</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15345" source="XF" adv="1">anubis-ident-bo(15345)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107894315012081&amp;w=2" source="BUGTRAQ">20040310 GNU Anubis 3.6.2 remote root exploit</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107843915424588&amp;w=2" source="BUGTRAQ" adv="1">20040304 GNU Anubis buffer overflows and format string bugs</ref>
      <ref url="http://mail.gnu.org/archive/html/bug-anubis/2004-02/msg00000.html" source="MLIST">[bug-anubis] 20040228 Important security update</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gnu" name="anubis">
        <vers num="3.6.0"/>
        <vers num="3.6.1"/>
        <vers num="3.6.2"/>
        <vers num="3.9.92"/>
        <vers num="3.9.93"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0354" published="2004-11-23" name="CVE-2004-0354" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Multiple format string vulnerabilities in GNU Anubis 3.6.0 through 3.6.2, 3.9.92 and 3.9.93 allow remote attackers to execute arbitrary code via format string specifiers in strings passed to (1) the info function in log.c, (2) the anubis_error function in errs.c, or (3) the ssl_error function in ssl.c.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1" admin="1"/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/9772" source="BID" patch="1" adv="1">9772</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15346" source="XF" adv="1">anubis-format-string(15346)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107843915424588&amp;w=2" source="BUGTRAQ" adv="1">20040304 GNU Anubis buffer overflows and format string bugs</ref>
      <ref url="http://mail.gnu.org/archive/html/bug-anubis/2004-02/msg00000.html" source="MLIST">[bug-anubis] 20040228 Important security update</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gnu" name="anubis">
        <vers num="3.6.0"/>
        <vers num="3.6.1"/>
        <vers num="3.6.2"/>
        <vers num="3.9.92"/>
        <vers num="3.9.93"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0355" published="2004-11-23" name="CVE-2004-0355" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Invision Power Board 1.3 Final allows remote attackers to gain sensitive information by selecting a file for "Personal Photo" that is not an image file, which displays the installation path in an error message.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <vuln_types>
      <design/>
      <exception/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/15400" source="XF" adv="1">invision-invalid-path-disclosure(15400)</ref>
      <ref url="http://www.securityfocus.com/bid/9810" source="BID" adv="1">9810</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107850510428567&amp;w=2" source="BUGTRAQ" adv="1">20040305 Invision Power Board 1.3 Final Path Disclosure Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="invision_power_services" name="invision_board">
        <vers num="1.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0356" published="2004-11-23" name="CVE-2004-0356" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Stack-based buffer overflow in Supervisor Report Center in SL Mail Pro 2.0.9 and earlier allows remote attackers to execute arbitrary code via an HTTP request with a long HTTP sub-version.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1" admin="1"/>
    </loss_types>
    <vuln_types>
      <input buffer="1"/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/15398" source="XF" adv="1">slmail-src-stack-bo(15398)</ref>
      <ref url="http://www.securityfocus.com/bid/9809" source="BID" adv="1">9809</ref>
      <ref url="http://www.nextgenss.com/advisories/slmailsrc.txt" source="MISC">http://www.nextgenss.com/advisories/slmailsrc.txt</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107850488326232&amp;w=2" source="BUGTRAQ" adv="1">20040305 SLMail Pro Supervisor Report Center Buffer Overflow (#NISR05022004a)</ref>
      <ref url="http://216.26.170.92/Download/webfiles/Patches/SLMPPatch-2.0.14.pdf" source="CONFIRM">http://216.26.170.92/Download/webfiles/Patches/SLMPPatch-2.0.14.pdf</ref>
    </refs>
    <vuln_soft>
      <prod vendor="seattle_lab_software" name="slmail_pro">
        <vers num="2.0"/>
        <vers num="2.0.1"/>
        <vers num="2.0.2"/>
        <vers num="2.0.3"/>
        <vers num="2.0.4"/>
        <vers num="2.0.5"/>
        <vers num="2.0.6"/>
        <vers num="2.0.7"/>
        <vers num="2.0.8"/>
        <vers num="2.0.9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0357" published="2004-11-23" name="CVE-2004-0357" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Stack-based buffer overflows in SL Mail Pro 2.0.9 allow remote attackers to execute arbitrary code via (1) user.dll, (2) loadpageadmin.dll or (3) loadpageuser.dll.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1" admin="1"/>
    </loss_types>
    <vuln_types>
      <input buffer="1"/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/9808" source="BID" patch="1" adv="1">9808</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15399" source="XF" adv="1">slmail-slwebmail-bo(15399)</ref>
      <ref url="http://www.nextgenss.com/advisories/slmailwm.txt" source="MISC">http://www.nextgenss.com/advisories/slmailwm.txt</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107850432827699&amp;w=2" source="BUGTRAQ" adv="1">20040305 SLWebMail Multiple Buffer Overflow Vulnerabilities (#NISR05022004b)</ref>
      <ref url="http://216.26.170.92/Download/webfiles/Patches/SLMPPatch-2.0.14.pdf" source="CONFIRM">http://216.26.170.92/Download/webfiles/Patches/SLMPPatch-2.0.14.pdf</ref>
    </refs>
    <vuln_soft>
      <prod vendor="seattle_lab_software" name="slmail_pro">
        <vers num="2.0.9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0358" published="2004-11-23" name="CVE-2004-0358" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in VirtuaNews Admin Panel Pro 1.0.3 allows remote attackers to execute arbitrary script as other users via (1) the mainnews parameter in admin.php, (2) the expand parameter in admin.php, (3) the id parameter in admin.php, (4) the catid parameter in admin.php, or (5) an unnamed parameter during the newslogo_upload action in admin.php.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/15402" source="XF">virtuanews-multiple-xss(15402)</ref>
      <ref url="http://www.securityfocus.com/bid/9819" source="BID">9819</ref>
      <ref url="http://www.securityfocus.com/bid/9812" source="BID">9812</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107851556116088&amp;w=2" source="BUGTRAQ" adv="1">20040305 VirtuaNews Admin Panel 1.0.3 Pro Cross Site Scripting Vulnerabillity</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2004-03/0069.html" source="BUGTRAQ">20040307 RE: VirtuaNews Admin Panel 1.0.3 Pro Cross Site Scripting Vulnerabillity</ref>
    </refs>
    <vuln_soft>
      <prod vendor="virtuasystems" name="virtuanews_pro">
        <vers num="1.0"/>
        <vers num="1.0.1"/>
        <vers num="1.0.2"/>
        <vers num="1.0.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0359" published="2004-11-23" name="CVE-2004-0359" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in index.php for Invision Power Board 1.3 final allows remote attackers to execute arbitrary script as other users via the (1) c, (2) f, (3) showtopic, (4) showuser, or (5) username parameters.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/15403" source="XF">invision-xss(15403)</ref>
      <ref url="http://www.securityfocus.com/bid/9768" source="BID">9768</ref>
      <ref url="http://www.osvdb.org/4154" source="OSVDB">4154</ref>
      <ref url="http://secunia.com/advisories/11053" source="SECUNIA" adv="1">11053</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107851589701916&amp;w=2" source="BUGTRAQ" adv="1">20040305 Invision Power Board v1.3 Final Cross Site Scripting Vulnerabillity</ref>
    </refs>
    <vuln_soft>
      <prod vendor="invision_power_services" name="invision_board">
        <vers num="1.3.1_final"/>
        <vers num="1.3_final"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0360" published="2004-11-23" name="CVE-2004-0360" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Unknown vulnerability in passwd(1) in Solaris 8.0 and 9.0 allows local users to gain privileges via unknown attack vectors.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1" admin="1"/>
    </loss_types>
    <vuln_types>
      <other/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/694782" source="CERT-VN" adv="1">VU#694782</ref>
      <ref url="http://www.securityfocus.com/bid/9757" source="BID" patch="1" adv="1">9757</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15327" source="XF" adv="1">solaris-passwd-gain-privileges(15327)</ref>
      <ref url="http://www.ciac.org/ciac/bulletins/o-088.shtml" source="CIAC">O-088</ref>
      <ref url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doc=fsalert/57454" source="SUNALERT">57454</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107852274423414&amp;w=2" source="BUGTRAQ" adv="1">200470305 O-088: Sun passwd(1) Command Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="solaris">
        <vers num="8.0" edition=""/>
        <vers num="8.0" edition=":x86"/>
        <vers num="9.0" edition=""/>
        <vers num="9.0" edition=":sparc"/>
        <vers num="9.0" edition=":x86"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0361" published="2004-11-23" name="CVE-2004-0361" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The Javascript engine in Safari 1.2 and earlier allows remote attackers to cause a denial of service (segmentation fault) by creating a new Array object with a large size value, then writing into that array.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <vuln_types>
      <exception/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/15413" source="XF" adv="1">safari-array-dos(15413)</ref>
      <ref url="http://www.securityfocus.com/bid/9815" source="BID" adv="1">9815</ref>
      <ref url="http://www.insecure.ws/article.php?story=2004021918172533" source="MISC">http://www.insecure.ws/article.php?story=2004021918172533</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107861828510106&amp;w=2" source="BUGTRAQ" adv="1">20040306 Safari javascript array overflow</ref>
    </refs>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0362" published="2004-04-15" name="CVE-2004-0362" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple stack-based buffer overflows in the ICQ parsing routines of the ISS Protocol Analysis Module (PAM) component, as used in various RealSecure, Proventia, and BlackICE products, allow remote attackers to execute arbitrary code via a SRV_MULTI response containing a SRV_USER_ONLINE response packet and a SRV_META_USER response packet with long (1) nickname, (2) firstname, (3) lastname, or (4) email address fields, as exploited by the Witty worm.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input buffer="1"/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/947254" source="CERT-VN" patch="1" adv="1">VU#947254</ref>
      <ref url="http://xforce.iss.net/xforce/alerts/id/166" source="ISS" patch="1" adv="1">20040318 Vulnerability in ICQ Parsing in ISS Products</ref>
      <ref url="http://www.securityfocus.com/bid/9913" source="BID" patch="1" adv="1">9913</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107965651712378&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20040318 EEYE: Internet Security Systems PAM ICQ Server Response Processing Vulnerability</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15543" source="XF">witty-worm-propagation(15543)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15442" source="XF">pam-icq-parsing-bo(15442)</ref>
      <ref url="http://www.osvdb.org/4355" source="OSVDB">4355</ref>
      <ref url="http://www.eeye.com/html/Research/Advisories/AD20040318.html" source="EEYE">AD20040318</ref>
      <ref url="http://www.ciac.org/ciac/bulletins/o-104.shtml" source="CIAC">O-104</ref>
      <ref url="http://secunia.com/advisories/11073" source="SECUNIA">11073</ref>
    </refs>
    <vuln_soft>
      <prod vendor="iss" name="blackice_agent_server">
        <vers num="3.6ebz"/>
        <vers num="3.6eca"/>
        <vers num="3.6ecb"/>
        <vers num="3.6ecc"/>
        <vers num="3.6ecd"/>
        <vers num="3.6ece"/>
        <vers num="3.6ecf"/>
      </prod>
      <prod vendor="iss" name="blackice_pc_protection">
        <vers num="3.6cbz"/>
        <vers num="3.6cca"/>
        <vers num="3.6ccb"/>
        <vers num="3.6ccc"/>
        <vers num="3.6ccd"/>
        <vers num="3.6cce"/>
        <vers num="3.6ccf"/>
      </prod>
      <prod vendor="iss" name="blackice_server_protection">
        <vers num="3.6cbz"/>
        <vers num="3.6cca"/>
        <vers num="3.6ccb"/>
        <vers num="3.6ccc"/>
        <vers num="3.6ccd"/>
        <vers num="3.6cce"/>
        <vers num="3.6ccf"/>
      </prod>
      <prod vendor="iss" name="realsecure_desktop">
        <vers num="3.6ebz"/>
        <vers num="3.6eca"/>
        <vers num="3.6ecb"/>
        <vers num="3.6ecd"/>
        <vers num="3.6ece"/>
        <vers num="3.6ecf"/>
        <vers num="7.0eba"/>
        <vers num="7.0ebf"/>
        <vers num="7.0ebg"/>
        <vers num="7.0ebh"/>
        <vers num="7.0ebj"/>
        <vers num="7.0ebk"/>
        <vers num="7.0ebl"/>
      </prod>
      <prod vendor="iss" name="realsecure_guard">
        <vers num="3.6ebz"/>
        <vers num="3.6eca"/>
        <vers num="3.6ecb"/>
        <vers num="3.6ecc"/>
        <vers num="3.6ecd"/>
        <vers num="3.6ece"/>
        <vers num="3.6ecf"/>
      </prod>
      <prod vendor="iss" name="realsecure_network_sensor">
        <vers num="7.0" edition="xpu_20.11"/>
        <vers num="7.0" edition="xpu_22.10"/>
        <vers num="7.0" edition="xpu_22.4"/>
        <vers num="7.0" edition="xpu_22.9"/>
      </prod>
      <prod vendor="iss" name="realsecure_sentry">
        <vers num="3.6ebz"/>
        <vers num="3.6eca"/>
        <vers num="3.6ecb"/>
        <vers num="3.6ecc"/>
        <vers num="3.6ecd"/>
        <vers num="3.6ece"/>
        <vers num="3.6ecf"/>
      </prod>
      <prod vendor="iss" name="realsecure_server_sensor">
        <vers num="6.0" edition=""/>
        <vers num="6.0" edition=":windows"/>
        <vers num="6.0.1" edition=""/>
        <vers num="6.0.1" edition=":windows"/>
        <vers num="6.0.1_win_sr1.1"/>
        <vers num="6.5" edition=""/>
        <vers num="6.5" edition=":windows"/>
        <vers num="6.5" edition="sr3.2"/>
        <vers num="6.5" edition="sr3.2:windows"/>
        <vers num="6.5" edition="sr3.3"/>
        <vers num="6.5" edition="sr3.3:windows"/>
        <vers num="6.5_win_sr3.1"/>
        <vers num="6.5_win_sr3.10"/>
        <vers num="6.5_win_sr3.4"/>
        <vers num="6.5_win_sr3.5"/>
        <vers num="6.5_win_sr3.6"/>
        <vers num="6.5_win_sr3.7"/>
        <vers num="6.5_win_sr3.8"/>
        <vers num="6.5_win_sr3.9"/>
        <vers num="7.0" edition="xpu22.1"/>
        <vers num="7.0" edition="xpu22.10"/>
        <vers num="7.0" edition="xpu22.11"/>
        <vers num="7.0" edition="xpu22.2"/>
        <vers num="7.0" edition="xpu22.3"/>
        <vers num="7.0" edition="xpu22.4"/>
        <vers num="7.0" edition="xpu22.5"/>
        <vers num="7.0" edition="xpu22.6"/>
        <vers num="7.0" edition="xpu22.7"/>
        <vers num="7.0" edition="xpu22.8"/>
        <vers num="7.0" edition="xpu22.9"/>
      </prod>
      <prod vendor="iss" name="proventia_a_series_xpu">
        <vers num="20.11"/>
        <vers num="22.1"/>
        <vers num="22.10"/>
        <vers num="22.2"/>
        <vers num="22.3"/>
        <vers num="22.4"/>
        <vers num="22.5"/>
        <vers num="22.6"/>
        <vers num="22.7"/>
        <vers num="22.8"/>
        <vers num="22.9"/>
      </prod>
      <prod vendor="iss" name="proventia_g_series_xpu">
        <vers num="22.1"/>
        <vers num="22.10"/>
        <vers num="22.11"/>
        <vers num="22.2"/>
        <vers num="22.3"/>
        <vers num="22.4"/>
        <vers num="22.5"/>
        <vers num="22.6"/>
        <vers num="22.7"/>
        <vers num="22.8"/>
        <vers num="22.9"/>
      </prod>
      <prod vendor="iss" name="proventia_m_series_xpu">
        <vers num="1.1"/>
        <vers num="1.2"/>
        <vers num="1.3"/>
        <vers num="1.4"/>
        <vers num="1.5"/>
        <vers num="1.6"/>
        <vers num="1.7"/>
        <vers num="1.8"/>
        <vers num="1.9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0363" published="2004-04-15" name="CVE-2004-0363" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Stack-based buffer overflow in the SymSpamHelper ActiveX component (symspam.dll) in Norton AntiSpam 2004, as used in Norton Internet Security 2004, allows remote attackers to execute arbitrary code via a long parameter to the LaunchCustomRuleWizard method.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <vuln_types>
      <input buffer="1"/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/344718" source="CERT-VN">VU#344718</ref>
      <ref url="http://www.nextgenss.com/advisories/antispam.txt" source="MISC" patch="1" adv="1">http://www.nextgenss.com/advisories/antispam.txt</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15536" source="XF" adv="1">nas-launchcustomrulewizard-bo(15536)</ref>
      <ref url="http://www.securityfocus.com/bid/9916" source="BID" adv="1">9916</ref>
      <ref url="http://www.sarc.com/avcenter/security/Content/2004.03.19.html" source="CONFIRM">http://www.sarc.com/avcenter/security/Content/2004.03.19.html</ref>
      <ref url="http://secunia.com/advisories/11169" source="SECUNIA">11169</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107970870606638&amp;w=2" source="BUGTRAQ" adv="1">20040319 Norton AntiSpam Remote Buffer Overrun (#NISR19042004a)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107980262324362&amp;w=2" source="BUGTRAQ">20040319 Ref: NGSSoftware Advisories NISR19042004a and NISR19042004b</ref>
    </refs>
    <vuln_soft>
      <prod vendor="symantec" name="norton_antispam">
        <vers num="2004"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0364" published="2004-04-15" name="CVE-2004-0364" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">The WrapNISUM ActiveX component (WrapUM.dll) in Norton Internet Security 2004 is marked safe for scripting, which allows remote attackers to execute arbitrary programs via the LaunchURL method.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <design/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/549054" source="CERT-VN">VU#549054</ref>
      <ref url="http://www.nextgenss.com/advisories/nisrce.txt" source="MISC" patch="1" adv="1">http://www.nextgenss.com/advisories/nisrce.txt</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15538" source="XF" adv="1">norton-is-launchurl-command-execution(15538)</ref>
      <ref url="http://www.securityfocus.com/bid/9915" source="BID" adv="1">9915</ref>
      <ref url="http://www.sarc.com/avcenter/security/Content/2004.03.19.html" source="CONFIRM">http://www.sarc.com/avcenter/security/Content/2004.03.19.html</ref>
      <ref url="http://secunia.com/advisories/11168" source="SECUNIA">11168</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107970885922442&amp;w=2" source="BUGTRAQ" adv="1">20040319 Norton Internet Security Remote Command Execution (#NISR19042004b)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107980262324362&amp;w=2" source="BUGTRAQ">20040319 Ref: NGSSoftware Advisories NISR19042004a and NISR19042004b</ref>
    </refs>
    <vuln_soft>
      <prod vendor="symantec" name="norton_internet_security">
        <vers num="2004" edition=""/>
        <vers num="2004" edition=":professional"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0365" published="2004-05-04" name="CVE-2004-0365" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The dissect_attribute_value_pairs function in packet-radius.c for Ethereal 0.8.13 to 0.10.2 allows remote attackers to cause a denial of service (crash) via a malformed RADIUS packet that triggers a null dereference.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <vuln_types>
      <exception/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/124454" source="CERT-VN">VU#124454</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108058005324316&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20040329 LNSA-#2004-0007: Multiple security problems in Ethereal</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15571" source="XF" adv="1">ethereal-radius-dos(15571)</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-137.html" source="REDHAT">RHSA-2004:137</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-136.html" source="REDHAT">RHSA-2004:136</ref>
      <ref url="http://www.ethereal.com/appnotes/enpa-sa-00013.html" source="CONFIRM">http://www.ethereal.com/appnotes/enpa-sa-00013.html</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200403-07.xml" source="GENTOO" adv="1">GLSA-200403-07</ref>
      <ref url="http://secunia.com/advisories/11185" source="SECUNIA">11185</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9196" source="OVAL">oval:org.mitre.oval:def:9196</ref>
      <ref url="http://marc.theaimsgroup.com/?l=ethereal-dev&amp;m=107962966700423&amp;w=2" source="MLIST" adv="1">[ethereal-dev] 20040318 ethereal radius dissector vulnerability</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2004:024" source="MANDRAKE">MDKSA-2004:024</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108213710306260&amp;w=2" source="BUGTRAQ">20040416 [OpenPKG-SA-2004.015] OpenPKG Security Advisory (ethereal)</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000835" source="CONECTIVA">CLA-2004:835</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:891" source="OVAL" sig="1">oval:org.mitre.oval:def:891</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:879" source="OVAL" sig="1">oval:org.mitre.oval:def:879</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ethereal_group" name="ethereal">
        <vers num="0.10"/>
        <vers num="0.10.1"/>
        <vers num="0.10.2"/>
        <vers num="0.8.13"/>
        <vers num="0.8.14"/>
        <vers num="0.8.18"/>
        <vers num="0.8.19"/>
        <vers num="0.9"/>
        <vers num="0.9.1"/>
        <vers num="0.9.10"/>
        <vers num="0.9.11"/>
        <vers num="0.9.12"/>
        <vers num="0.9.13"/>
        <vers num="0.9.14"/>
        <vers num="0.9.15"/>
        <vers num="0.9.16"/>
        <vers num="0.9.2"/>
        <vers num="0.9.3"/>
        <vers num="0.9.4"/>
        <vers num="0.9.5"/>
        <vers num="0.9.6"/>
        <vers num="0.9.7"/>
        <vers num="0.9.8"/>
        <vers num="0.9.9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0366" published="2004-05-04" name="CVE-2004-0366" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in the libpam-pgsql library before 0.5.2 allows attackers to execute arbitrary SQL statements.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/15651" source="XF" patch="1" adv="1">pam-pgsql-sql-injection(15651)</ref>
      <ref url="http://www.debian.org/security/2004/dsa-469" source="DEBIAN" patch="1" adv="1">DSA-469</ref>
      <ref url="http://www.securityfocus.com/bid/10266" source="BID">10266</ref>
      <ref url="http://secunia.com/advisories/11237" source="SECUNIA">11237</ref>
    </refs>
    <vuln_soft>
      <prod vendor="leon_j_breedt" name="pam-pgsql">
        <vers prev="1" num="0.5.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0367" published="2004-05-04" name="CVE-2004-0367" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Ethereal 0.10.1 to 0.10.2 allows remote attackers to cause a denial of service (crash) via a zero-length Presentation protocol selector.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/792286" source="CERT-VN">VU#792286</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-137.html" source="REDHAT" patch="1" adv="1">RHSA-2004:137</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15570" source="XF" adv="1">ethereal-zero-presentation-dos(15570)</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-136.html" source="REDHAT">RHSA-2004:136</ref>
      <ref url="http://www.ethereal.com/lists/ethereal-dev/200404/msg00296.html" source="MLIST">[Ethereal-dev] 20040416 Possibly incorrect CVE entry CAN-2004-0367</ref>
      <ref url="http://www.ethereal.com/appnotes/enpa-sa-00013.html" source="CONFIRM">http://www.ethereal.com/appnotes/enpa-sa-00013.html</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200403-07.xml" source="GENTOO">GLSA-200403-07</ref>
      <ref url="http://secunia.com/advisories/11185" source="SECUNIA">11185</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11071" source="OVAL">oval:org.mitre.oval:def:11071</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108058005324316&amp;w=2" source="BUGTRAQ" adv="1">20040329 LNSA-#2004-0007: Multiple security problems in Ethereal</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000835" source="CONECTIVA" adv="1">CLA-2004:835</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2004:024" source="MANDRAKE">MDKSA-2004:024</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:905" source="OVAL" sig="1">oval:org.mitre.oval:def:905</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:880" source="OVAL" sig="1">oval:org.mitre.oval:def:880</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ethereal_group" name="ethereal">
        <vers num="0.10"/>
        <vers num="0.10.1"/>
        <vers num="0.10.2"/>
        <vers num="0.8.13"/>
        <vers num="0.8.14"/>
        <vers num="0.8.18"/>
        <vers num="0.8.19"/>
        <vers num="0.9"/>
        <vers num="0.9.1"/>
        <vers num="0.9.10"/>
        <vers num="0.9.11"/>
        <vers num="0.9.12"/>
        <vers num="0.9.13"/>
        <vers num="0.9.14"/>
        <vers num="0.9.15"/>
        <vers num="0.9.16"/>
        <vers num="0.9.2"/>
        <vers num="0.9.3"/>
        <vers num="0.9.4"/>
        <vers num="0.9.5"/>
        <vers num="0.9.6"/>
        <vers num="0.9.7"/>
        <vers num="0.9.8"/>
        <vers num="0.9.9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0368" published="2004-05-04" name="CVE-2004-0368" modified="2008-09-10" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Double free vulnerability in dtlogin in CDE on Solaris, HP-UX, and other operating systems allows remote attackers to execute arbitrary code via a crafted XDMCP packet.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <vuln_types>
      <input/>
      <exception/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/179804" source="CERT-VN" adv="1">VU#179804</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15581" source="XF" adv="1">cde-dtlogin-double-free(15581)</ref>
      <ref url="http://www.securityfocus.com/bid/9958" source="BID">9958</ref>
      <ref url="http://www.immunitysec.com/downloads/dtlogin.sxw.pdf" source="MISC">http://www.immunitysec.com/downloads/dtlogin.sxw.pdf</ref>
      <ref url="http://www.ciac.org/ciac/bulletins/o-129.shtml" source="CIAC">O-129</ref>
      <ref url="http://www.auscert.org.au/render.html?it=4103&amp;cid=3734" source="HP">HPSBUX01038</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-57539-1&amp;searchclause=security" source="SUNALERT">57539</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-101478-1" source="SUNALERT">101478</ref>
      <ref url="http://secunia.com/advisories/11614/" source="SECUNIA" adv="1">11614</ref>
      <ref url="http://secunia.com/advisories/11495/" source="SECUNIA" adv="1">11495</ref>
      <ref url="http://secunia.com/advisories/11214/" source="SECUNIA" adv="1">11214</ref>
      <ref url="http://secunia.com/advisories/11210/" source="SECUNIA" adv="1">11210</ref>
      <ref url="http://lists.immunitysec.com/pipermail/dailydave/2004-March/000402.html" source="MLIST" adv="1">[Dailydave] 20040323 dtlogin advisory</ref>
      <ref url="http://archives.neohapsis.com/archives/vulnwatch/2004-q1/0064.html" source="VULNWATCH" adv="1">20040323 how much fun can you have with UDP?</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/20040801-01-P" source="SGI">20040801-01-P</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1436" source="OVAL" sig="1">oval:org.mitre.oval:def:1436</ref>
    </refs>
    <vuln_soft>
      <prod vendor="open_group" name="cde_common_desktop_environment">
        <vers num="1.0.1"/>
        <vers num="1.0.2"/>
        <vers num="1.1"/>
        <vers num="1.2"/>
        <vers num="2.0"/>
        <vers num="2.1"/>
        <vers num="2.1.20"/>
      </prod>
      <prod vendor="xi_graphics" name="dextop">
        <vers num="2.1"/>
        <vers num="3.0"/>
      </prod>
      <prod vendor="ibm" name="aix">
        <vers num="4.3.3"/>
        <vers num="5.1"/>
        <vers num="5.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0369" published="2004-12-31" name="CVE-2004-0369" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in Entrust LibKmp ISAKMP library, as used by Symantec Enterprise Firewall 7.0 through 8.0, Gateway Security 5300 1.0, Gateway Security 5400 2.0, and VelociRaptor 1.5, allows remote attackers to execute arbitrary code via a crafted ISAKMP payload.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <vuln_types>
      <input buffer="1"/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/15669" source="XF" patch="1">isakmp-spi-size-bo(15669)</ref>
      <ref url="http://xforce.iss.net/xforce/alerts/id/181" source="ISS" patch="1" adv="1">20040826 Entrust LibKmp Library Buffer Overflow</ref>
      <ref url="http://www.securityfocus.com/bid/11039" source="BID">11039</ref>
      <ref url="http://www.ciac.org/ciac/bulletins/o-206.shtml" source="CIAC" adv="1">O-206</ref>
      <ref url="http://www.auscert.org.au/render.html?it=4339" source="AUSCERT" adv="1">ESB-2004.0538</ref>
      <ref url="http://securityresponse.symantec.com/avcenter/security/Content/2004.08.26.html" source="CONFIRM" adv="1">http://securityresponse.symantec.com/avcenter/security/Content/2004.08.26.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="entrust" name="entrust_libkmp_isakmp_library">
        <vers num=""/>
      </prod>
      <prod vendor="symantec" name="enterprise_firewall">
        <vers num="7.0" edition=""/>
        <vers num="7.0" edition=":solaris"/>
        <vers num="7.0.4" edition=""/>
        <vers num="7.0.4" edition=":solaris"/>
        <vers num="7.0.4" edition=":windows_2000_nt"/>
        <vers num="8.0" edition=""/>
        <vers num="8.0" edition=":solaris"/>
        <vers num="8.0" edition=":windows_2000_nt"/>
      </prod>
      <prod vendor="symantec" name="velociraptor">
        <vers num="1.5"/>
      </prod>
      <prod vendor="symantec" name="gateway_security_5300">
        <vers num="1.0"/>
      </prod>
      <prod vendor="symantec" name="gateway_security_5400">
        <vers num="2.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2004-0370" published="2004-05-04" name="CVE-2004-0370" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">The setsockopt call in the KAME Project IPv6 implementation, as used in FreeBSD 5.2, does not properly handle certain IPv6 socket options, which could allow attackers to read kernel memory and cause a system panic.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <vuln_types>
      <exception/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/15662" source="XF" patch="1" adv="1">freebsd-ipv6-dos(15662)</ref>
      <ref url="http://www.securityfocus.com/bid/9992" source="BID">9992</ref>
      <ref url="http://secunia.com/advisories/11233" source="SECUNIA">11233</ref>
      <ref url="ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-04:06.ipv6.asc" source="FREEBSD">FreeBSD-SA-04:06</ref>
    </refs>
    <vuln_soft>
      <prod vendor="freebsd" name="freebsd">
        <vers num="5.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0371" published="2004-05-04" name="CVE-2004-0371" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Heimdal 0.6.x before 0.6.1 and 0.5.x before 0.5.3 does not properly perform certain consistency checks for cross-realm requests, which allows remote attackers with control of a realm to impersonate others in the cross-realm trust path.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/15701" source="XF" patch="1" adv="1">heimdal-cross-realm-spoofing(15701)</ref>
      <ref url="http://www.debian.org/security/2004/dsa-476" source="DEBIAN" patch="1" adv="1">DSA-476</ref>
      <ref url="http://www.pdc.kth.se/heimdal/advisory/2004-04-01/" source="CONFIRM">http://www.pdc.kth.se/heimdal/advisory/2004-04-01/</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200404-09.xml" source="GENTOO" adv="1">GLSA-200404-09</ref>
      <ref url="ftp://ftp.openbsd.org/pub/OpenBSD/patches/3.5/common/009_kerberos.patch" source="OPENBSD">20040530 009: SECURITY FIX: May 30, 2004</ref>
      <ref url="ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-04:08.heimdal.asc" source="FREEBSD">FreeBSD-SA-04:08</ref>
    </refs>
    <vuln_soft>
      <prod vendor="kth" name="heimdal">
        <vers num="0.4a"/>
        <vers num="0.4b"/>
        <vers num="0.4c"/>
        <vers num="0.4d"/>
        <vers num="0.4e"/>
        <vers num="0.5"/>
        <vers num="0.5.1"/>
        <vers num="0.5.2"/>
        <vers num="0.6.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2004-0372" published="2004-04-15" name="CVE-2004-0372" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">xine allows local users to overwrite arbitrary files via a symlink attack on a bug report email that is generated by the (1) xine-bugreport or (2) xine-check scripts.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <vuln_types>
      <design/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/15564" source="XF" patch="1" adv="1">xine-xinebugreport-xinecheck-symlink(15564)</ref>
      <ref url="http://www.debian.org/security/2004/dsa-477" source="DEBIAN" patch="1" adv="1">DSA-477</ref>
      <ref url="http://www.securityfocus.com/bid/9939" source="BID" adv="1">9939</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200404-20.xml" source="GENTOO">GLSA-200404-20</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107997911025558&amp;w=2" source="BUGTRAQ" adv="1">20040320 xine-check/xine-bugreport symlink vulnerability.</ref>
    </refs>
    <vuln_soft>
      <prod vendor="xine" name="xine">
        <vers num="0.9.13"/>
        <vers num="1_beta1"/>
        <vers num="1_beta10"/>
        <vers num="1_beta11"/>
        <vers num="1_beta12"/>
        <vers num="1_beta2"/>
        <vers num="1_beta3"/>
        <vers num="1_beta4"/>
        <vers num="1_beta5"/>
        <vers num="1_beta6"/>
        <vers num="1_beta7"/>
        <vers num="1_beta8"/>
        <vers num="1_beta9"/>
        <vers num="1_rc0a"/>
        <vers num="1_rc1"/>
        <vers num="1_rc2"/>
        <vers num="1_rc3"/>
        <vers num="1_rc3a"/>
        <vers num="1_rc3b"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0374" published="2004-05-04" name="CVE-2004-0374" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)" CVSS_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_base_score="6.4">
    <desc>
      <descript source="cve">Interchange before 5.0.1 allows remote attackers to "expose the content of arbitrary variables" and read or modify sensitive SQL information via an HTTP request ending with the "__SQLUSER__" string.</descript>
    </desc>
    <loss_types>
      <conf/>
      <int/>
    </loss_types>
    <vuln_types>
      <other/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/15670" source="XF" patch="1" adv="1">interchange-url-obtain-information(15670)</ref>
      <ref url="http://www.debian.org/security/2004/dsa-471" source="DEBIAN" patch="1" adv="1">DSA-471</ref>
      <ref url="http://www.securityfocus.com/bid/10005" source="BID">10005</ref>
      <ref url="http://secunia.com/advisories/11234" source="SECUNIA">11234</ref>
      <ref url="http://ftp.icdevgroup.org/interchange/5.0/WHATSNEW" source="CONFIRM">http://ftp.icdevgroup.org/interchange/5.0/WHATSNEW</ref>
      <ref url="http://www.icdevgroup.org/pipermail/interchange-announce/2004/000043.html" source="MLIST">[interchange-announce] 20040329 Security Problem in Interchange</ref>
    </refs>
    <vuln_soft>
      <prod vendor="interchange_development_group" name="interchange">
        <vers num="4.8.1"/>
        <vers num="4.8.2"/>
        <vers num="4.8.3"/>
        <vers num="4.8.4"/>
        <vers num="4.8.5"/>
        <vers num="4.8.6"/>
        <vers num="4.8.7"/>
        <vers num="4.8.8"/>
        <vers num="4.8.9"/>
        <vers num="5.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0375" published="2004-08-18" name="CVE-2004-0375" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">SYMNDIS.SYS in Symantec Norton Internet Security 2003 and 2004, Norton Personal Firewall 2003 and 2004, Client Firewall 5.01 and 5.1.1, and Client Security 1.0 and 1.1 allow remote attackers to cause a denial of service (infinite loop) via a TCP packet with (1) SACK option or (2) Alternate Checksum Data option followed by a length of zero.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <vuln_types>
      <exception/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/15936" source="XF" adv="1">symantec-firewall-tcp-dos(15936)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15433" source="XF">norton-firewalls-dos(15433)</ref>
      <ref url="http://www.symantec.com/avcenter/security/Content/2004.04.20.html" source="CONFIRM">http://www.symantec.com/avcenter/security/Content/2004.04.20.html</ref>
      <ref url="http://www.securityfocus.com/bid/9912" source="BID" adv="1">9912</ref>
      <ref url="http://www.eeye.com/html/Research/Upcoming/20040309.html" source="MISC">http://www.eeye.com/html/Research/Upcoming/20040309.html</ref>
      <ref url="http://securitytracker.com/id?1009380" source="SECTRACK">1009380</ref>
      <ref url="http://securitytracker.com/id?1009379" source="SECTRACK">1009379</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108275582432246&amp;w=2" source="BUGTRAQ">20040423 EEYE: Symantec Multiple Firewall TCP Options Denial of Service</ref>
    </refs>
    <vuln_soft>
      <prod vendor="symantec" name="client_firewall">
        <vers num="5.01"/>
        <vers num="5.1.1"/>
      </prod>
      <prod vendor="symantec" name="client_security">
        <vers num="1.0"/>
        <vers num="1.1"/>
      </prod>
      <prod vendor="symantec" name="norton_internet_security">
        <vers num="2003" edition=""/>
        <vers num="2003" edition=":pro"/>
        <vers num="2004" edition=""/>
        <vers num="2004" edition=":pro"/>
      </prod>
      <prod vendor="symantec" name="norton_personal_firewall">
        <vers num="2003"/>
        <vers num="2004"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0376" published="2004-05-04" name="CVE-2004-0376" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">oftpd 0.3.6 and earlier allows remote attackers to cause a denial of service (crash) via a PORT command with a large value.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <vuln_types>
      <exception/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/9980" source="BID" patch="1" adv="1">9980</ref>
      <ref url="http://www.debian.org/security/2004/dsa-473" source="DEBIAN" patch="1" adv="1">DSA-473</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15622" source="XF" adv="1">oftpd-port-dos(15622)</ref>
      <ref url="http://www.time-travellers.org/oftpd/oftpd-dos.html" source="CONFIRM">http://www.time-travellers.org/oftpd/oftpd-dos.html</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200403-08.xml" source="GENTOO">GLSA-200403-08</ref>
      <ref url="http://secunia.com/advisories/11220" source="SECUNIA">11220</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oftpd" name="oftpd">
        <vers prev="1" num="0.3.6"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0377" published="2004-05-04" name="CVE-2004-0377" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Buffer overflow in the win32_stat function for (1) ActiveState's ActivePerl and (2) Larry Wall's Perl before 5.8.3 allows local or remote attackers to execute arbitrary commands via filenames that end in a backslash character.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <vuln_types>
      <input bound="1"/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/722414" source="CERT-VN" patch="1" adv="1">VU#722414</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15732" source="XF" patch="1" adv="1">perl-win32stat-bo(15732)</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2004-April/019794.html" source="FULLDISC" patch="1" adv="1">20040405 iDEFENSE Security Advisory 04.05.04: Perl win32_stat Function</ref>
      <ref url="http://public.activestate.com/cgi-bin/perlbrowse?patch=22552" source="CONFIRM">http://public.activestate.com/cgi-bin/perlbrowse?patch=22552</ref>
      <ref url="http://www.idefense.com/application/poi/display?id=93&amp;type=vulnerabilities" source="MISC">http://www.idefense.com/application/poi/display?id=93&amp;type=vulnerabilities</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108118694327979&amp;w=2" source="BUGTRAQ">20040405 [Full-Disclosure] iDEFENSE Security Advisory 04.05.04: Perl win32_stat Function</ref>
    </refs>
    <vuln_soft>
      <prod vendor="activestate" name="activeperl">
        <vers num=""/>
      </prod>
      <prod vendor="larry_wall" name="perl">
        <vers prev="1" num="5.8.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0379" published="2004-05-04" name="CVE-2004-0379" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in Microsoft SharePoint Portal Server 2001 allow remote attackers to process arbitrary web content and steal cookies via certain server scripts.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108118352303273&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20040405 Multiple XSS vulnerabilities in Microsoft SharePoint Portal Server 2001</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15729" source="XF" adv="1">sharepoint-portal-xss(15729)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="sharepoint_portal_server">
        <vers num="2001" edition="sp1"/>
        <vers num="2001" edition="sp2"/>
        <vers num="2001" edition="sp2a"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0380" published="2004-05-04" name="CVE-2004-0380" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">The MHTML protocol handler in Microsoft Outlook Express 5.5 SP2 through Outlook Express 6 SP1 allows remote attackers to bypass domain restrictions and execute arbitrary code, as demonstrated on Internet Explorer using script in a compiled help (CHM) file that references the InfoTech Storage (ITS) protocol handlers such as (1) ms-its, (2) ms-itss, (3) its, or (4) mk:@MSITStore, aka the "MHTML URL Processing Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <vuln_types>
      <design/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/323070" source="CERT-VN">VU#323070</ref>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA04-104A.html" source="CERT">TA04-104A</ref>
      <ref url="http://www.securityfocus.com/archive/1/358913" source="BUGTRAQ" patch="1" adv="1">20040328 IE ms-its: and mk:@MSITStore: vulnerability</ref>
      <ref url="http://www.securityfocus.com/archive/1/354447" source="BUGTRAQ" patch="1" adv="1">20040219 Microsoft Internet Explorer Unspecified CHM File Processing Arbitrary Code Execution Vulnerability (bid 9658)</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/MS04-013.mspx" source="MS" patch="1" adv="1">MS04-013</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15705" source="XF" adv="1">outlook-mhtml-execute-code(15705)</ref>
      <ref url="http://www.securityfocus.com/bid/9658" source="BID">9658</ref>
      <ref url="http://www.k-otik.net/bugtraq/02.18.InternetExplorer.php" source="MISC">http://www.k-otik.net/bugtraq/02.18.InternetExplorer.php</ref>
      <ref url="http://www.securityfocus.com/bid/9105" source="BID">9105</ref>
      <ref url="http://secunia.com/advisories/10523" source="SECUNIA">10523</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:990" source="OVAL" sig="1">oval:org.mitre.oval:def:990</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:882" source="OVAL" sig="1">oval:org.mitre.oval:def:882</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1028" source="OVAL" sig="1">oval:org.mitre.oval:def:1028</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1010" source="OVAL" sig="1">oval:org.mitre.oval:def:1010</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="outlook_express">
        <vers num="5.5"/>
        <vers num="6.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2004-0381" published="2004-05-04" name="CVE-2004-0381" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">mysqlbug in MySQL allows local users to overwrite arbitrary files via a symlink attack on the failed-mysql-bugreport temporary file.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <vuln_types>
      <design/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/9976" source="BID" patch="1" adv="1">9976</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108206802810402&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20040414 [OpenPKG-SA-2004.014] OpenPKG Security Advisory (mysql)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15617" source="XF" adv="1">mysql-mysqlbug-symlink(15617)</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-597.html" source="REDHAT">RHSA-2004:597</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-569.html" source="REDHAT">RHSA-2004:569</ref>
      <ref url="http://www.debian.org/security/2004/dsa-483" source="DEBIAN">DSA-483</ref>
      <ref url="http://www.ciac.org/ciac/bulletins/p-018.shtml" source="CIAC">P-018</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200405-20.xml" source="GENTOO">GLSA-200405-20</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11557" source="OVAL">oval:org.mitre.oval:def:11557</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108023246916294&amp;w=2" source="BUGTRAQ">20040324 mysqlbug tmpfile/symlink vulnerability.</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2004:034" source="MANDRAKE">MDKSA-2004:034</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mysql" name="mysql">
        <vers num="3.20.32a"/>
        <vers num="3.22.26"/>
        <vers num="3.22.27"/>
        <vers num="3.22.28"/>
        <vers num="3.22.29"/>
        <vers num="3.22.30"/>
        <vers num="3.22.32"/>
        <vers num="3.23.10"/>
        <vers num="3.23.2"/>
        <vers num="3.23.22"/>
        <vers num="3.23.23"/>
        <vers num="3.23.24"/>
        <vers num="3.23.25"/>
        <vers num="3.23.26"/>
        <vers num="3.23.27"/>
        <vers num="3.23.28" edition="gamma"/>
        <vers num="3.23.29"/>
        <vers num="3.23.3"/>
        <vers num="3.23.30"/>
        <vers num="3.23.31"/>
        <vers num="3.23.32"/>
        <vers num="3.23.33"/>
        <vers num="3.23.34"/>
        <vers num="3.23.36"/>
        <vers num="3.23.37"/>
        <vers num="3.23.38"/>
        <vers num="3.23.39"/>
        <vers num="3.23.40"/>
        <vers num="3.23.41"/>
        <vers num="3.23.42"/>
        <vers num="3.23.43"/>
        <vers num="3.23.44"/>
        <vers num="3.23.45"/>
        <vers num="3.23.46"/>
        <vers num="3.23.47"/>
        <vers num="3.23.48"/>
        <vers num="3.23.49"/>
        <vers num="3.23.5"/>
        <vers num="3.23.50"/>
        <vers num="3.23.51"/>
        <vers num="3.23.52"/>
        <vers num="3.23.53"/>
        <vers num="3.23.53a"/>
        <vers num="3.23.54"/>
        <vers num="3.23.54a"/>
        <vers num="3.23.55"/>
        <vers num="3.23.56"/>
        <vers num="3.23.58"/>
        <vers num="3.23.8"/>
        <vers num="3.23.9"/>
        <vers num="4.0.0"/>
        <vers num="4.0.1"/>
        <vers num="4.0.10"/>
        <vers num="4.0.11" edition="gamma"/>
        <vers num="4.0.12"/>
        <vers num="4.0.13"/>
        <vers num="4.0.14"/>
        <vers num="4.0.15"/>
        <vers num="4.0.18"/>
        <vers num="4.0.2"/>
        <vers num="4.0.3"/>
        <vers num="4.0.4"/>
        <vers num="4.0.5"/>
        <vers num="4.0.5a"/>
        <vers num="4.0.6"/>
        <vers num="4.0.7" edition="gamma"/>
        <vers num="4.0.8" edition="gamma"/>
        <vers num="4.0.9" edition="gamma"/>
        <vers num="4.1.0" edition="alpha"/>
        <vers num="4.1.0.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0382" published="2004-05-04" name="CVE-2004-0382" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Unknown vulnerability in the CUPS printing system in Mac OS X 10.3.3 and Mac OS X 10.2.8 with unknown impact, possibly related to a configuration file setting.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <vuln_types>
      <config/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/15769" source="XF" patch="1" adv="1">macos-cups-configuration-unknown(15769)</ref>
      <ref url="http://lists.apple.com/mhonarc/security-announce/msg00047.html" source="CONFIRM">http://lists.apple.com/mhonarc/security-announce/msg00047.html</ref>
      <ref url="http://docs.info.apple.com/article.html?artnum=61798" source="CONFIRM">http://docs.info.apple.com/article.html?artnum=61798</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.2.8"/>
        <vers num="10.3.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0383" published="2004-05-04" name="CVE-2004-0383" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Unknown vulnerability in Mail for Mac OS X 10.3.3 and 10.2.8, with unknown impact, related to "the handling of HTML-formatted email."</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <vuln_types>
      <design/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/15768" source="XF" patch="1" adv="1">macos-mail-unknown(15768)</ref>
      <ref url="http://lists.apple.com/mhonarc/security-announce/msg00047.html" source="CONFIRM">http://lists.apple.com/mhonarc/security-announce/msg00047.html</ref>
      <ref url="http://docs.info.apple.com/article.html?artnum=61798" source="CONFIRM">http://docs.info.apple.com/article.html?artnum=61798</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.2.8"/>
        <vers num="10.3.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0385" published="2004-06-01" name="CVE-2004-0385" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Heap-based buffer overflow in Oracle 9i Application Server Web Cache 9.0.4.0.0, 9.0.3.1.0, 9.0.2.3.0, and 9.0.0.4.0 allows remote attackers to execute arbitrary code via a long HTTP request method header to the Web Cache listener.  NOTE: due to the vagueness of the Oracle advisory, it is not clear whether there are additional issues besides this overflow, although the advisory alludes to multiple "vulnerabilities."</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1" other="1" admin="1"/>
    </loss_types>
    <vuln_types>
      <input bound="1"/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/413006" source="CERT-VN" patch="1" adv="1">VU#413006</ref>
      <ref url="http://otn.oracle.com/deploy/security/pdf/2004alert66.pdf" source="CONFIRM" patch="1" adv="1">http://otn.oracle.com/deploy/security/pdf/2004alert66.pdf</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15463" source="XF">oracle-web-cache-vulnerabilities(15463)</ref>
      <ref url="http://www.securityfocus.com/bid/9868" source="BID">9868</ref>
      <ref url="http://www.inaccessnetworks.com/ian/services/secadv01.txt" source="MISC" adv="1">http://www.inaccessnetworks.com/ian/services/secadv01.txt</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107945649127635&amp;w=2" source="BUGTRAQ">20040316 new security alert #66 issued in Oracle web cache</ref>
      <ref url="http://archives.neohapsis.com/archives/vulnwatch/2004-q1/0078.html" source="VULNWATCH">20040408 Heap Overflow in Oracle 9iAS / 10g Application Server Web Cache</ref>
      <ref url="http://www.osvdb.org/4249" source="OSVDB">4249</ref>
      <ref url="http://secunia.com/advisories/11118" source="SECUNIA">11118</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108144419001770&amp;w=2" source="BUGTRAQ">20040408 Heap Overflow in Oracle 9iAS / 10g Application Server Web Cache</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="application_server_web_cache">
        <vers num="9.0.0.4.0"/>
        <vers num="9.0.2.3.0"/>
        <vers num="9.0.3.1.0"/>
        <vers num="9.0.4.0.0"/>
      </prod>
      <prod vendor="oracle" name="e-business_suite">
        <vers num="11i"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0386" published="2004-05-04" name="CVE-2004-0386" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Buffer overflow in the HTTP parser for MPlayer 1.0pre3 and earlier, 0.90, and 0.91 allows remote attackers to execute arbitrary code via a long Location header.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <vuln_types>
      <input buffer="1"/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/723910" source="CERT-VN" patch="1" adv="1">VU#723910</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15675" source="XF" patch="1">mplayer-header-bo(15675)</ref>
      <ref url="http://www.securityfocus.com/bid/10008" source="BID" patch="1">10008</ref>
      <ref url="http://www.securityfocus.com/archive/1/359025" source="BUGTRAQ" patch="1" adv="1">20040330 Heap overflow in MPlayer</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200403-13.xml" source="GENTOO" patch="1" adv="1">GLSA-200403-13</ref>
      <ref url="http://secunia.com/advisories/11259" source="SECUNIA" patch="1" adv="1">11259</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108067020624076&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20040330 MPlayer Security Advisory #002 - HTTP parsing vulnerability</ref>
      <ref url="http://www.mplayerhq.hu/homepage/design6/news.html" source="CONFIRM">http://www.mplayerhq.hu/homepage/design6/news.html</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2004:026" source="MANDRAKE">MDKSA-2004:026</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mplayer" name="mplayer">
        <vers num="0.90"/>
        <vers num="0.90_pre"/>
        <vers num="0.90_rc"/>
        <vers num="0.91"/>
        <vers num="1.0_pre1"/>
        <vers num="1.0_pre2"/>
        <vers num="1.0_pre3"/>
      </prod>
      <prod vendor="gentoo" name="linux">
        <vers num="0.5"/>
        <vers num="0.7"/>
        <vers num="1.1a"/>
        <vers num="1.2"/>
        <vers num="1.4" edition="rc1"/>
        <vers num="1.4" edition="rc2"/>
        <vers num="1.4" edition="rc3"/>
      </prod>
      <prod vendor="mandrakesoft" name="mandrake_linux">
        <vers num="10.0"/>
        <vers num="9.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0387" published="2004-06-01" name="CVE-2004-0387" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_score="5.1" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="4.9" CVSS_base_score="5.1">
    <desc>
      <descript source="cve">Stack-based buffer overflow in the RT3 plugin, as used in RealPlayer 8, RealOne Player, RealOne Player 10 beta, and RealOne Player Enterprise, allows remote attackers to execute arbitrary code via a malformed .R3T file.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <vuln_types>
      <input buffer="1"/>
    </vuln_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/15774" source="XF" patch="1" adv="1">realplayer-r3t-bo(15774)</ref>
      <ref url="http://www.service.real.com/help/faq/security/040406_r3t/en/" source="CONFIRM" patch="1" adv="1">http://www.service.real.com/help/faq/security/040406_r3t/en/</ref>
      <ref url="http://www.ngssoftware.com/advisories/realr3t.txt" source="MISC" patch="1" adv="1">http://www.ngssoftware.com/advisories/realr3t.txt</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108135350810135&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20040307 REAL One Player R3T File Format Stack Overflow</ref>
      <ref url="http://www.securityfocus.com/bid/10070" source="BID">10070</ref>
      <ref url="http://www.osvdb.org/displayvuln.php?osvdb_id=4977" source="OSVDB">4977</ref>
      <ref url="http://secunia.com/advisories/11314" source="SECUNIA">11314</ref>
      <ref url="http://archives.neohapsis.com/archives/vulnwatch/2004-q1/0077.html" source="VULNWATCH">20040307 REAL One Player R3T File Format Stack Overflow</ref>
    </refs>
    <vuln_soft>
      <prod vendor="realnetworks" name="realone_player">
        <vers num="" edition=":enterprise"/>
        <vers num="10_beta"/>
      </prod>
      <prod vendor="realnetworks" name="realplayer">
        <vers num="8.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2004-0388" published="2004-06-01" name="CVE-2004-0388" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">The mysqld_multi script in MySQL allows local users to overwrite arbitrary files via a symlink attack.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <vuln_types>
      <env/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://www.debian.org/security/2004/dsa-483" source="DEBIAN" patch="1" adv="1">DSA-483</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15883" source="XF">mysql-mysqldmulti-symlink(15883)</ref>
      <ref url="http://www.securityfocus.com/bid/10142" source="BID">10142</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-597.html" source="REDHAT">RHSA-2004:597</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-569.html" source="REDHAT">RHSA-2004:569</ref>
      <ref url="http://www.osvdb.org/6421" source="OSVDB">6421</ref>
      <ref url="http://www.ciac.org/ciac/bulletins/p-018.shtml" source="CIAC">P-018</ref>
      <ref url="http://securitytracker.com/id?1009784" source="SECTRACK">1009784</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200405-20.xml" source="GENTOO" adv="1">GLSA-200405-20</ref>
      <ref url="http://secunia.com/advisories/11223/" source="SECUNIA">11223</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10559" source="OVAL">oval:org.mitre.oval:def:10559</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108206802810402&amp;w=2" source="BUGTRAQ">20040414 [OpenPKG-SA-2004.014] OpenPKG Security Advisory (mysql)</ref>
      <ref url="http://dev.mysql.com/doc/mysql/en/news-4-1-2.html" source="CONFIRM">http://dev.mysql.com/doc/mysql/en/news-4-1-2.html</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2004:034" source="MANDRAKE">MDKSA-2004:034</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mysql" name="mysql">
        <vers num="5.0.33"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0389" published="2004-06-01" name="CVE-2004-0389" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">RealNetworks Helix Universal Server 9.0.1 and 9.0.2 allows remote attackers to cause a denial of service (crash) via malformed requests that trigger a null dereference, as demonstrated using (1) GET_PARAMETER or (2) DESCRIBE requests.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <vuln_types>
      <input/>
      <exception/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.idefense.com/application/poi/display?id=102&amp;type=vulnerabilities" source="IDEFENSE" patch="1" adv="1">20040415 RealNetworks Helix Universal Server Denial of Service Vulnerability</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15880" source="XF">helix-get-dos(15880)</ref>
      <ref url="http://www.securityfocus.com/bid/10157" source="BID">10157</ref>
      <ref url="http://secunia.com/advisories/11395" source="SECUNIA" adv="1">11395</ref>
    </refs>
    <vuln_soft>
      <prod vendor="realnetworks" name="helix_universal_server">
        <vers num="9.0.1"/>
        <vers num="9.0.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0390" published="2004-12-31" name="CVE-2004-0390" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SCO OpenServer 5.0.5 through 5.0.7 only supports Xauthority style access control when users log in using scologin, which allows remote attackers to gain unauthorized access to an X session via other X login methods.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <access/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/16113" source="XF">openserver-x-session-insecure(16113)</ref>
      <ref url="http://www.securityfocus.com/advisories/6684" source="SCO">SCOSA-2004.5</ref>
      <ref url="http://archives.neohapsis.com/archives/fulldisclosure/2004-05/0424.html" source="FULLDISC">20040510 OpenServer 5.0.5 OpenServer 5.0.6 OpenServer 5.0.7 : X sessions which are not started by scologin cannot use the X authorization protocol</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sco" name="openserver">
        <vers num="5.0.5"/>
        <vers num="5.0.6"/>
        <vers num="5.0.7"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0391" published="2004-06-01" name="CVE-2004-0391" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Cisco Wireless LAN Solution Engine (WLSE) 2.0 through 2.5 and Hosting Solution Engine (HSE) 1.7 through 1.7.3 have a hardcoded username and password, which allows remote attackers to add new users, modify existing users, and change configuration.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1" other="1" admin="1"/>
    </loss_types>
    <vuln_types>
      <design/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/659228" source="CERT-VN" patch="1" adv="1">VU#659228</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15773" source="XF" patch="1" adv="1">cisco-default-password(15773)</ref>
      <ref url="http://www.cisco.com/warp/public/707/cisco-sa-20040407-username.shtml" source="CISCO" patch="1" adv="1">20040407 A Default Username and Password in WLSE and HSE Devices</ref>
      <ref url="http://www.ciac.org/ciac/bulletins/o-111.shtml" source="CIAC" patch="1" adv="1">O-111</ref>
      <ref url="http://www.securityfocus.com/bid/10076" source="BID">10076</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="wireless_lan_solution_engine">
        <vers num="2.0"/>
        <vers num="2.1"/>
        <vers num="2.2"/>
        <vers num="2.3"/>
        <vers num="2.4"/>
        <vers num="2.5"/>
      </prod>
      <prod vendor="cisco" name="hosting_solution_engine">
        <vers num="1.7"/>
        <vers num="1.7.0"/>
        <vers num="1.7.1"/>
        <vers num="1.7.2"/>
        <vers num="1.7.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0392" published="2004-06-14" name="CVE-2004-0392" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">racoon before 20040407b allows remote attackers to cause a denial of service (infinite loop and dropped connections) via an IKE message with a malformed Generic Payload Header containing invalid (1) "Security Association Next Payload" and (2) "RESERVED" fields.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <vuln_types>
      <exception/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/15893" source="XF" patch="1" adv="1">racoon-isakmp-dos(15893)</ref>
      <ref url="http://www.vuxml.org/freebsd/40fcf20f-8891-11d8-90d1-0020ed76ef5a.html" source="CONFIRM" adv="1">http://www.vuxml.org/freebsd/40fcf20f-8891-11d8-90d1-0020ed76ef5a.html</ref>
      <ref url="ftp://ftp.sco.com/pub/updates/UnixWare/SCOSA-2005.10/SCOSA-2005.10.txt" source="SCO">SCOSA-2005.10</ref>
      <ref url="http://orange.kame.net/dev/query-pr.cgi?pr=555" source="CONFIRM">http://orange.kame.net/dev/query-pr.cgi?pr=555</ref>
    </refs>
    <vuln_soft>
      <prod vendor="kame" name="racoon">
        <vers prev="1" num="2004-04-07a"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0393" published="2004-12-06" name="CVE-2004-0393" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Format string vulnerability in the msg function for rlpr daemon (rlprd) 2.0.4 allows remote attackers to execute arbitrary code via format string specifiers in a buffer that can not be resolved, which is provided to the syslog function.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1" other="1" admin="1"/>
    </loss_types>
    <vuln_types>
      <input buffer="1"/>
      <design/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/16453" source="XF" patch="1" adv="1">rlpr-msg-format-string(16453)</ref>
      <ref url="http://www.securityfocus.com/bid/10578" source="BID" patch="1" adv="1">10578</ref>
      <ref url="http://www.debian.org/security/2004/dsa-524" source="DEBIAN" patch="1" adv="1">DSA-524</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108810992313652&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20040624 Rlpr Advisory</ref>
    </refs>
    <vuln_soft>
      <prod vendor="rlpr" name="rlpr">
        <vers num="2.0"/>
        <vers num="2.0.1"/>
        <vers num="2.0.2"/>
        <vers num="2.0.3"/>
        <vers num="2.0.4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2004-0394" published="2004-08-18" name="CVE-2004-0394" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">A "potential" buffer overflow exists in the panic() function in Linux 2.4.x, although it may not be exploitable due to the functionality of panic.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <vuln_types>
      <input buffer="1"/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/15953" source="XF" adv="1">linux-panic-bo(15953)</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2004_10_kernel.html" source="SUSE">SuSE-SA:2004:010</ref>
      <ref url="http://www.linuxsecurity.com/advisories/engarde_advisory-4285.html" source="ENGARDE">ESA-20040428-004</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200407-02.xml" source="GENTOO" adv="1">GLSA-200407-02</ref>
      <ref url="http://lwn.net/Articles/81773/" source="MLIST">[fedora-announce] 20040422 Fedora alert FEDORA-2004-111 (kernel)</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000846" source="CONECTIVA" adv="1">CLA-2004:846</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/20040505-01-U.asc" source="SGI">20040505-01-U</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/20040504-01-U.asc" source="SGI">20040504-01-U</ref>
      <ref url="http://www.securityfocus.com/bid/10233" source="BID">10233</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2004:037" source="MANDRAKE">MDKSA-2004:037</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1082" source="DEBIAN">DSA-1082</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1070" source="DEBIAN">DSA-1070</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1069" source="DEBIAN">DSA-1069</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1067" source="DEBIAN">DSA-1067</ref>
      <ref url="http://secunia.com/advisories/20338" source="SECUNIA">20338</ref>
      <ref url="http://secunia.com/advisories/20202" source="SECUNIA">20202</ref>
      <ref url="http://secunia.com/advisories/20163" source="SECUNIA">20163</ref>
      <ref url="http://secunia.com/advisories/20162" source="SECUNIA">20162</ref>
    </refs>
    <vuln_soft>
      <prod vendor="linux" name="linux_kernel">
        <vers num="2.6.20.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0395" published="2004-12-06" name="CVE-2004-0395" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">The xatitv program in the gatos package does not properly drop root privileges when the configuration file does not exist, which allows local users to execute arbitrary commands via shell metacharacters in a system call.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1" other="1" admin="1"/>
    </loss_types>
    <vuln_types>
      <design/>
      <env/>
      <config/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/16273" source="XF" patch="1" adv="1">gatos-xatitv-gain-privileges(16273)</ref>
      <ref url="http://www.securityfocus.com/bid/10437" source="BID" patch="1" adv="1">10437</ref>
      <ref url="http://www.debian.org/security/2004/dsa-509" source="DEBIAN" patch="1" adv="1">DSA-509</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gatos" name="gatos">
        <vers num=".5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0396" published="2004-06-14" name="CVE-2004-0396" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Heap-based buffer overflow in CVS 1.11.x up to 1.11.15, and 1.12.x up to 1.12.7, when using the pserver mechanism allows remote attackers to execute arbitrary code via Entry lines.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input buffer="1"/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/192038" source="CERT-VN" patch="1" adv="1">VU#192038</ref>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA04-147A.html" source="CERT">TA04-147A</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-190.html" source="REDHAT" patch="1" adv="1">RHSA-2004:190</ref>
      <ref url="http://www.debian.org/security/2004/dsa-505" source="DEBIAN" patch="1" adv="1">DSA-505</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108498454829020&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20040519 Advisory 07/2004: CVS remote vulnerability</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200405-12.xml" source="GENTOO">GLSA-200405-12</ref>
      <ref url="http://security.e-matters.de/advisories/072004.html" source="MISC">http://security.e-matters.de/advisories/072004.html</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9058" source="OVAL">oval:org.mitre.oval:def:9058</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2004-May/021742.html" source="SUSE">SuSE-SA:2004:013</ref>
      <ref url="ftp://ftp.NetBSD.org/pub/NetBSD/security/advisories/NetBSD-SA2004-008.txt.asc" source="NETBSD">NetBSD-SA2004-008</ref>
      <ref url="ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-04:10.cvs.asc" source="FREEBSD">FreeBSD-SA-04:10</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/16193" source="XF">cvs-entry-line-bo(16193)</ref>
      <ref url="http://www.slackware.com/security/viewer.php?l=slackware-security&amp;y=2004&amp;m=slackware-security.395865" source="SLACKWARE">SSA:2004-140-01</ref>
      <ref url="http://www.securityfocus.com/bid/10384" source="BID">10384</ref>
      <ref url="http://www.osvdb.org/6305" source="OSVDB">6305</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2004:048" source="MANDRAKE">MDKSA-2004:048</ref>
      <ref url="http://www.ciac.org/ciac/bulletins/o-147.shtml" source="CIAC">O-147</ref>
      <ref url="http://secunia.com/advisories/11674" source="SECUNIA">11674</ref>
      <ref url="http://secunia.com/advisories/11652" source="SECUNIA">11652</ref>
      <ref url="http://secunia.com/advisories/11651" source="SECUNIA">11651</ref>
      <ref url="http://secunia.com/advisories/11647" source="SECUNIA">11647</ref>
      <ref url="http://secunia.com/advisories/11641" source="SECUNIA">11641</ref>
      <ref url="http://marc.theaimsgroup.com/?l=openbsd-security-announce&amp;m=108508894405639&amp;w=2" source="OPENBSD">20040520 cvs server buffer overflow vulnerability</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108636445031613&amp;w=2" source="FEDORA">FEDORA-2004-1620</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108500040719512&amp;w=2" source="BUGTRAQ">20040519 [OpenPKG-SA-2004.022] OpenPKG Security Advisory (cvs)</ref>
      <ref url="http://cert.uni-stuttgart.de/archive/bugtraq/2004/05/msg00219.html" source="BUGTRAQ">20040519 Advisory 07/2004: CVS remote vulnerability</ref>
      <ref url="http://archives.neohapsis.com/archives/fulldisclosure/2004-05/0980.html" source="FULLDISC">20040519 Advisory 07/2004: CVS remote vulnerability</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:970" source="OVAL" sig="1">oval:org.mitre.oval:def:970</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cvs" name="cvs">
        <vers num="1.11"/>
        <vers num="1.12"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0397" published="2004-07-07" name="CVE-2004-0397" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Stack-based buffer overflow during the apr_time_t data conversion in Subversion 1.0.2 and earlier allows remote attackers to execute arbitrary code via a (1) DAV2 REPORT query or (2) get-dated-rev svn-protocol command.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input buffer="1"/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/16191" source="XF" patch="1" adv="1">subversion-date-parsing-command-execution(16191)</ref>
      <ref url="http://www.securityfocus.com/bid/10386" source="BID" patch="1" adv="1">10386</ref>
      <ref url="http://www.securityfocus.com/archive/1/363814" source="BUGTRAQ" patch="1" adv="1">20040519 [OpenPKG-SA-2004.023] OpenPKG Security Advisory (subversion)</ref>
      <ref url="https://bugzilla.fedora.us/show_bug.cgi?id=1748" source="FEDORA">FLSA:1748</ref>
      <ref url="http://www.linuxsecurity.com/advisories/fedora_advisory-4373.html" source="FEDORA" adv="1">FEDORA-2004-128</ref>
      <ref url="http://security.e-matters.de/advisories/082004.html" source="MISC">http://security.e-matters.de/advisories/082004.html</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108498676517697&amp;w=2" source="BUGTRAQ" adv="1">20040519 Advisory 08/2004: Subversion remote vulnerability</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2004-May/021737.html" source="FULLDISC">20040519 Advisory 08/2004: Subversion remote vulnerability</ref>
      <ref url="http://www.osvdb.org/6301" source="OSVDB">6301</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200405-14.xml" source="GENTOO">GLSA-200405-14</ref>
      <ref url="http://subversion.tigris.org/svn-sscanf-advisory.txt" source="CONFIRM">http://subversion.tigris.org/svn-sscanf-advisory.txt</ref>
      <ref url="http://secunia.com/advisories/11675" source="SECUNIA">11675</ref>
      <ref url="http://secunia.com/advisories/11642" source="SECUNIA">11642</ref>
    </refs>
    <vuln_soft>
      <prod vendor="subversion" name="subversion">
        <vers num="1.0"/>
        <vers num="1.0.1"/>
        <vers num="1.0.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0398" published="2004-07-07" name="CVE-2004-0398" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Heap-based buffer overflow in the ne_rfc1036_parse date parsing function for the neon library (libneon) 0.24.5 and earlier, as used by cadaver before 0.22, allows remote WebDAV servers to execute arbitrary code on the client.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <vuln_types>
      <input buffer="1"/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="https://bugzilla.fedora.us/show_bug.cgi?id=1552" source="FEDORA" patch="1">FEDORA-2004-1552</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/16192" source="XF" patch="1">neon-library-nerfc1036parse-bo(16192)</ref>
      <ref url="http://www.securityfocus.com/bid/10385" source="BID" patch="1">10385</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-191.html" source="REDHAT" patch="1" adv="1">RHSA-2004:191</ref>
      <ref url="http://www.debian.org/security/2004/dsa-507" source="DEBIAN" patch="1" adv="1">DSA-507</ref>
      <ref url="http://www.debian.org/security/2004/dsa-506" source="DEBIAN" patch="1" adv="1">DSA-506</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200405-15.xml" source="GENTOO" patch="1" adv="1">GLSA-200405-15</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200405-13.xml" source="GENTOO" patch="1" adv="1">GLSA-200405-13</ref>
      <ref url="http://secunia.com/advisories/11673" source="SECUNIA" patch="1" adv="1">11673</ref>
      <ref url="http://secunia.com/advisories/11650" source="SECUNIA" patch="1" adv="1">11650</ref>
      <ref url="http://secunia.com/advisories/11638" source="SECUNIA" patch="1" adv="1">11638</ref>
      <ref url="http://www.osvdb.org/6302" source="OSVDB">6302</ref>
      <ref url="http://www.ciac.org/ciac/bulletins/o-148.shtml" source="CIAC" adv="1">O-148</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000841" source="CONECTIVA" adv="1">CLA-2004:841</ref>
      <ref url="http://archives.neohapsis.com/archives/fulldisclosure/2004-05/0982.html" source="FULLDISC" adv="1">20040519 Advisory 06/2004: libneon date parsing vulnerability</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2004:049" source="MANDRAKE">MDKSA-2004:049</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108500057108022&amp;w=2" source="BUGTRAQ">20040519 [OpenPKG-SA-2004.024] OpenPKG Security Advisory (neon)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108498433632333&amp;w=2" source="BUGTRAQ">20040519 Advisory 06/2004: libneon date parsing vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cadaver" name="cadaver_webdav_client">
        <vers num="0.20.0"/>
        <vers num="0.20.1"/>
        <vers num="0.20.2"/>
        <vers num="0.20.3"/>
        <vers num="0.20.4"/>
        <vers num="0.20.5"/>
        <vers num="0.21.0"/>
        <vers num="0.22.0"/>
        <vers num="0.22.1"/>
      </prod>
      <prod vendor="neon" name="neon_client_library">
        <vers num="0.19.3"/>
        <vers num="0.23"/>
        <vers num="0.23.1"/>
        <vers num="0.23.2"/>
        <vers num="0.23.3"/>
        <vers num="0.23.4"/>
        <vers num="0.23.5"/>
        <vers num="0.23.6"/>
        <vers num="0.23.7"/>
        <vers num="0.23.8"/>
        <vers num="0.24"/>
        <vers num="0.24.1"/>
        <vers num="0.24.2"/>
        <vers num="0.24.3"/>
        <vers num="0.24.4"/>
      </prod>
      <prod vendor="openoffice" name="openoffice">
        <vers num="1.1.2"/>
      </prod>
      <prod vendor="subversion" name="subversion">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0399" published="2004-07-07" name="CVE-2004-0399" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Stack-based buffer overflow in Exim 3.35, and other versions before 4, when the sender_verify option is true, allows remote attackers to cause a denial of service and possibly execute arbitrary code during sender verification.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input buffer="1"/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/16079" source="XF" patch="1" adv="1">exim-requireverify-bo(16079)</ref>
      <ref url="http://www.guninski.com/exim1.html" source="MISC" patch="1" adv="1">http://www.guninski.com/exim1.html</ref>
      <ref url="http://www.debian.org/security/2004/dsa-502" source="DEBIAN" patch="1" adv="1">DSA-502</ref>
      <ref url="http://www.debian.org/security/2004/dsa-501" source="DEBIAN" patch="1" adv="1">DSA-501</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2004-May/021015.html" source="FULLDISC">20040506 Buffer overflows in exim, yet still exim much better than windows</ref>
      <ref url="http://secunia.com/advisories/11558" source="SECUNIA">11558</ref>
    </refs>
    <vuln_soft>
      <prod vendor="university_of_cambridge" name="exim">
        <vers num="3.35"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0400" published="2004-07-07" name="CVE-2004-0400" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Stack-based buffer overflow in Exim 4 before 4.33, when the headers_check_syntax option is enabled, allows remote attackers to cause a denial of service and possibly execute arbitrary code during the header check.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input buffer="1"/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/16077" source="XF" patch="1" adv="1">exim-headerschecksyntax-bo(16077)</ref>
      <ref url="http://www.guninski.com/exim1.html" source="MISC" patch="1" adv="1">http://www.guninski.com/exim1.html</ref>
      <ref url="http://www.debian.org/security/2004/dsa-502" source="DEBIAN" patch="1" adv="1">DSA-502</ref>
      <ref url="http://www.debian.org/security/2004/dsa-501" source="DEBIAN" patch="1" adv="1">DSA-501</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2004-May/021015.html" source="FULLDISC">20040506 Buffer overflows in exim, yet still exim much better than windows</ref>
    </refs>
    <vuln_soft>
      <prod vendor="university_of_cambridge" name="exim">
        <vers prev="1" num="4.32"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0401" published="2004-07-07" name="CVE-2004-0401" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Unknown vulnerability in libtasn1 0.1.x before 0.1.2, and 0.2.x before 0.2.7, related to the DER parsing functions.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/16157" source="XF" patch="1">libtasn1-der-parsing(16157)</ref>
      <ref url="http://www.backports.org/changelog.html" source="MISC" adv="1">http://www.backports.org/changelog.html</ref>
      <ref url="http://www.securityfocus.com/bid/10360" source="BID">10360</ref>
      <ref url="http://www.osvdb.org/15126" source="OSVDB">15126</ref>
      <ref url="http://securitytracker.com/id?1010159" source="SECTRACK">1010159</ref>
      <ref url="http://packages.debian.org/changelogs/pool/main/libt/libtasn1-2/libtasn1-2_0.2.13-1/changelog" source="CONFIRM">http://packages.debian.org/changelogs/pool/main/libt/libtasn1-2/libtasn1-2_0.2.13-1/changelog</ref>
    </refs>
    <vuln_soft>
      <prod vendor="free_software_foundation_inc." name="libtasn1">
        <vers num="0.1"/>
        <vers num="0.1.0"/>
        <vers num="0.1.1"/>
        <vers num="0.2.0"/>
        <vers num="0.2.1"/>
        <vers num="0.2.2"/>
        <vers num="0.2.3"/>
        <vers num="0.2.4"/>
        <vers num="0.2.5"/>
        <vers num="0.2.6"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0402" published="2004-07-07" name="CVE-2004-0402" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Buffer overflow in xpcd-svga in xpcd before 2.08, and possibly other versions, may allow local users to execute arbitrary code.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input buffer="1"/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/10403" source="BID" patch="1" adv="1">10403</ref>
      <ref url="http://www.debian.org/security/2004/dsa-508" source="DEBIAN" patch="1" adv="1">DSA-508</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/16236" source="XF" adv="1">xpcd-svga-pcdopen-bo(16236)</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2004:053" source="MANDRAKE">MDKSA-2004:053</ref>
    </refs>
    <vuln_soft>
      <prod vendor="xpcd" name="xpcd">
        <vers num="2.08"/>
      </prod>
      <prod vendor="mandrakesoft" name="mandrake_linux">
        <vers num="10.0" edition=""/>
        <vers num="10.0" edition=":amd64"/>
        <vers num="9.2" edition=""/>
        <vers num="9.2" edition=":amd64"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0403" published="2004-06-01" name="CVE-2004-0403" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Racoon before 20040408a allows remote attackers to cause a denial of service (memory consumption) via an ISAKMP packet with a large length field.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <vuln_types>
      <input bound="1"/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-165.html" source="REDHAT" patch="1" adv="1">RHSA-2004:165</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108369640424244&amp;w=2" source="APPLE" patch="1" adv="1">APPLE-SA-2004-05-03</ref>
      <ref url="http://www.vuxml.org/freebsd/ccd698df-8e20-11d8-90d1-0020ed76ef5a.html" source="CONFIRM" adv="1">http://www.vuxml.org/freebsd/ccd698df-8e20-11d8-90d1-0020ed76ef5a.html</ref>
      <ref url="http://www.mandrakesecure.net/en/advisories/advisory.php?name=MDKSA-2004:069" source="MANDRAKE">MDKSA-2004:069</ref>
      <ref url="http://www.kame.net/dev/cvsweb2.cgi/kame/kame/kame/racoon/isakmp.c.diff?r1=1.180&amp;r2=1.181" source="CONFIRM">http://www.kame.net/dev/cvsweb2.cgi/kame/kame/kame/racoon/isakmp.c.diff?r1=1.180&amp;r2=1.181</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200404-17.xml" source="GENTOO">GLSA-200404-17</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11220" source="OVAL">oval:org.mitre.oval:def:11220</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/20040506-01-U.asc" source="SGI">20040506-01-U</ref>
      <ref url="ftp://ftp.sco.com/pub/updates/UnixWare/SCOSA-2005.10/SCOSA-2005.10.txt" source="SCO">SCOSA-2005.10</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15893" source="XF">racoon-isakmp-dos(15893)</ref>
      <ref url="http://www.securityfocus.com/bid/10172" source="BID">10172</ref>
      <ref url="http://www.osvdb.org/5491" source="OSVDB">5491</ref>
      <ref url="http://sourceforge.net/project/shownotes.php?release_id=232288" source="CONFIRM">http://sourceforge.net/project/shownotes.php?release_id=232288</ref>
      <ref url="http://securitytracker.com/id?1009937" source="SECTRACK">1009937</ref>
      <ref url="http://secunia.com/advisories/11877" source="SECUNIA">11877</ref>
      <ref url="http://secunia.com/advisories/11410" source="SECUNIA">11410</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:984" source="OVAL" sig="1">oval:org.mitre.oval:def:984</ref>
    </refs>
    <vuln_soft>
      <prod vendor="kame" name="racoon">
        <vers prev="1" num="2004-04-08a"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2004-0404" published="2004-07-07" name="CVE-2004-0404" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:H/Au:N/C:N/I:P/A:N)" CVSS_score="1.2" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="1.9" CVSS_base_score="1.2">
    <desc>
      <descript source="cve">logcheck before 1.1.1 allows local users to overwrite arbitrary files via a symlink attack on a temporary directory in /var/tmp.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <vuln_types>
      <race/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/15888" source="XF" patch="1">logcheck-directory-symlink(15888)</ref>
      <ref url="http://www.securityfocus.com/bid/10162" source="BID" patch="1">10162</ref>
      <ref url="http://www.debian.org/security/2004/dsa-488" source="DEBIAN" patch="1" adv="1">DSA-488</ref>
      <ref url="http://secunia.com/advisories/11399" source="SECUNIA" adv="1">11399</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2004:155" source="MANDRAKE">MDKSA-2004:155</ref>
    </refs>
    <vuln_soft>
      <prod vendor="psionic" name="logcheck">
        <vers prev="1" num="1.1.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0405" published="2004-06-01" name="CVE-2004-0405" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">CVS before 1.11 allows CVS clients to read arbitrary files via .. (dot dot) sequences in filenames via CVS client requests, a different vulnerability than CVE-2004-0180.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <vuln_types>
      <input/>
      <design/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.debian.org/security/2004/dsa-486" source="DEBIAN" patch="1" adv="1">DSA-486</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108636445031613&amp;w=2" source="FEDORA" patch="1" adv="1">FEDORA-2004-1620</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/20040404-01-U.asc" source="SGI" patch="1" adv="1">20040404-01-U</ref>
      <ref url="ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-04:07.cvs.asc" source="FREEBSD" patch="1" adv="1">FreeBSD-SA-04:07</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10818" source="OVAL">oval:org.mitre.oval:def:10818</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15891" source="XF">cvs-dotdot-directory-traversal(15891)</ref>
      <ref url="http://www.slackware.com/security/viewer.php?l=slackware-security&amp;y=2004&amp;m=slackware-security.400181" source="SLACKWARE">SSA:2004-108-02</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200404-13.xml" source="GENTOO">GLSA-200404-13</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1060" source="OVAL" sig="1">oval:org.mitre.oval:def:1060</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cvs" name="cvs">
        <vers prev="1" num="1.10"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2004-0407" published="2004-06-01" name="CVE-2004-0407" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:N/A:P)" CVSS_score="2.6" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="4.9" CVSS_base_score="2.6">
    <desc>
      <descript source="cve">The HTML form upload capability in ColdFusion MX 6.1 does not reclaim disk space if an upload is interrupted, which allows remote attackers to cause a denial of service (disk consumption) by repeatedly uploading files and interrupting the uploads before they finish.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <vuln_types>
      <exception/>
      <env/>
      <race/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.macromedia.com/devnet/security/security_zone/mpsb04-06.html" source="CONFIRM" patch="1" adv="1">http://www.macromedia.com/devnet/security/security_zone/mpsb04-06.html</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108213782629001&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20040416 [securityzone@macromedia.com: New Macromedia Security Zone Bulletin Posted]</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15882" source="XF">coldfusion-upload-file-dos(15882)</ref>
      <ref url="http://www.securityfocus.com/bid/10158" source="BID">10158</ref>
      <ref url="http://www.osvdb.org/5402" source="OSVDB">5402</ref>
      <ref url="http://securitytracker.com/id?1009825" source="SECTRACK">1009825</ref>
      <ref url="http://secunia.com/advisories/11392" source="SECUNIA">11392</ref>
    </refs>
    <vuln_soft>
      <prod vendor="macromedia" name="coldfusion">
        <vers num="6.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0408" published="2004-09-28" name="CVE-2004-0408" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in the child_service function in the ident2 ident daemon allows remote attackers to execute arbitrary code.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input buffer="1"/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/15938" source="XF" patch="1" adv="1">ident2-childservice-bo(15938)</ref>
      <ref url="http://www.securityfocus.com/bid/10192" source="BID" patch="1" adv="1">10192</ref>
      <ref url="http://www.debian.org/security/2004/dsa-494" source="DEBIAN" patch="1" adv="1">DSA-494</ref>
    </refs>
    <vuln_soft>
      <prod vendor="michael_bacarella" name="ident2">
        <vers num=".999c"/>
        <vers num="1.3"/>
        <vers num="1.3_1"/>
        <vers num="1.4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0409" published="2004-06-01" name="CVE-2004-0409" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Stack-based buffer overflow in the Socks-5 proxy code for XChat 1.8.0 to 2.0.8, with socks5 traversal enabled, allows remote attackers to execute arbitrary code.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1" other="1"/>
    </loss_types>
    <vuln_types>
      <input bound="1"/>
      <config/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.xchat.org/" source="CONFIRM" patch="1" adv="1">http://www.xchat.org/</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-177.html" source="REDHAT" patch="1" adv="1">RHSA-2004:177</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108258002427226&amp;w=2" source="DEBIAN" patch="1" adv="1">DSA-493</ref>
      <ref url="http://mail.nl.linux.org/xchat-announce/2004-04/msg00000.html" source="MLIST" patch="1" adv="1">[xchat-announce] 20040405 xchat 2.0.x Socks5 Vulnerability</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-585.html" source="REDHAT">RHSA-2004:585</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200404-15.xml" source="GENTOO">GLSA-200404-15</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11312" source="OVAL">oval:org.mitre.oval:def:11312</ref>
      <ref url="http://www.fedoralegacy.org/updates/FC2/2005-11-14-FLSA_2005_123013" source="FEDORA">FLSA:123013</ref>
    </refs>
    <vuln_soft>
      <prod vendor="xchat" name="xchat">
        <vers num="1.8.0"/>
        <vers num="1.8.1"/>
        <vers num="1.8.2"/>
        <vers num="1.8.3"/>
        <vers num="1.8.4"/>
        <vers num="1.8.5"/>
        <vers num="1.8.6"/>
        <vers num="1.8.7"/>
        <vers num="1.8.8"/>
        <vers num="1.8.9"/>
        <vers num="1.9.0"/>
        <vers num="1.9.1"/>
        <vers num="1.9.2"/>
        <vers num="1.9.3"/>
        <vers num="1.9.4"/>
        <vers num="1.9.5"/>
        <vers num="1.9.6"/>
        <vers num="1.9.7"/>
        <vers num="1.9.8"/>
        <vers num="1.9.9"/>
        <vers num="2.0.0"/>
        <vers num="2.0.1"/>
        <vers num="2.0.2"/>
        <vers num="2.0.3"/>
        <vers num="2.0.4"/>
        <vers num="2.0.5"/>
        <vers num="2.0.6"/>
        <vers num="2.0.7"/>
        <vers num="2.0.8"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" seq="2004-0410" reject="1" published="2004-12-31" name="CVE-2004-0410" modified="2008-09-10">
    <desc>
      <descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: none.  Reason: This candidate was withdrawn by its CNA.  Further investigation showed that it was not a security issue.  Notes: none.</descript>
    </desc>
    <refs/>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0411" published="2004-07-07" name="CVE-2004-0411" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">The URI handlers in Konqueror for KDE 3.2.2 and earlier do not properly filter "-" characters that begin a hostname in a (1) telnet, (2) rlogin, (3) ssh, or (4) mailto URI, which allows remote attackers to manipulate the options that are passed to the associated programs, possibly to read arbitrary files or execute arbitrary code.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <exception/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.kde.org/info/security/advisory-20040517-1.txt" source="CONFIRM" patch="1" adv="1">http://www.kde.org/info/security/advisory-20040517-1.txt</ref>
      <ref url="http://www.securityfocus.com/archive/1/363225" source="BUGTRAQ" adv="1">20040513 Opera Telnet URI Handler Vulnerability also applies to other browsers</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-222.html" source="REDHAT">RHSA-2004:222</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2004_14_kdelibs.html" source="SUSE">SuSE-SA:2003:014</ref>
      <ref url="http://www.debian.org/security/2004/dsa-518" source="DEBIAN">DSA-518</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200405-11.xml" source="GENTOO">GLSA-200405-11</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/16163" source="XF">kde-url-handler-gain-access(16163)</ref>
      <ref url="http://www.slackware.org/security/viewer.php?l=slackware-security&amp;y=2004&amp;m=slackware-security.362635" source="SLACKWARE">SSA:2004-238</ref>
      <ref url="http://www.securityfocus.com/bid/10358" source="BID">10358</ref>
      <ref url="http://www.securityfocus.com/advisories/6743" source="FEDORA">FEDORA-2004-122</ref>
      <ref url="http://www.securityfocus.com/advisories/6717" source="FEDORA">FEDORA-2004-121</ref>
      <ref url="http://www.osvdb.org/6107" source="OSVDB">6107</ref>
      <ref url="http://www.ciac.org/ciac/bulletins/o-146.shtml" source="CIAC">O-146</ref>
      <ref url="http://secunia.com/advisories/11602" source="SECUNIA">11602</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108481412427344&amp;w=2" source="BUGTRAQ">20040517 KDE Security Advisory: URI Handler Vulnerabilities</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000843" source="CONECTIVA">CLA-2004:843</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:954" source="OVAL" sig="1">oval:org.mitre.oval:def:954</ref>
    </refs>
    <vuln_soft>
      <prod vendor="kde" name="konqueror">
        <vers prev="1" num="3.2.2"/>
      </prod>
      <prod vendor="opera_software" name="opera_web_browser">
        <vers num="9.10"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0412" published="2004-08-18" name="CVE-2004-0412" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Mailman before 2.1.5 allows remote attackers to obtain user passwords via a crafted email request to the Mailman server.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/10412" source="BID" patch="1" adv="1">10412</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109034869927955&amp;w=2" source="FEDORA" patch="1" adv="1">FEDORA-2004-1734</ref>
      <ref url="https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=123559" source="CONFIRM">https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=123559</ref>
      <ref url="http://www.mandrakesecure.net/en/advisories/advisory.php?name=MDKSA-2004:051" source="MANDRAKE">MDKSA-2004:051</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200406-04.xml" source="GENTOO" adv="1">GLSA-200406-04</ref>
      <ref url="http://mail.python.org/pipermail/mailman-announce/2004-May/000072.html" source="MLIST">[Mailman-Announce] 20040515 RELEASED Mailman 2.1.5</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000842" source="CONECTIVA" adv="1">CLA-2004:842</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/16256" source="XF">mailman-obtain-password(16256)</ref>
      <ref url="http://secunia.com/advisories/11701" source="SECUNIA">11701</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gnu" name="mailman">
        <vers num="2.1"/>
        <vers num="2.1.1"/>
        <vers num="2.1.2"/>
        <vers num="2.1.3"/>
        <vers num="2.1.4"/>
        <vers num="2.1b1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0413" published="2004-08-06" name="CVE-2004-0413" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">libsvn_ra_svn in Subversion 1.0.4 trusts the length field of (1) svn://, (2) svn+ssh://, and (3) other svn protocol URL strings, which allows remote attackers to cause a denial of service (memory consumption) and possibly execute arbitrary code via an integer overflow that leads to a heap-based buffer overflow.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1" admin="1"/>
    </loss_types>
    <vuln_types>
      <input buffer="1" bound="1"/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/16396" source="XF" patch="1" adv="1">subversion-svn-bo(16396)</ref>
      <ref url="http://www.securityfocus.com/bid/10519" source="BID" patch="1" adv="1">10519</ref>
      <ref url="https://bugzilla.fedora.us/show_bug.cgi?id=1748" source="FEDORA">FLSA:1748</ref>
      <ref url="http://www.securityfocus.com/advisories/6847" source="FEDORA">FEDORA-2004-165</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2004_18_subversion.html" source="SUSE">SuSE-SA:2004:018</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200406-07.xml" source="GENTOO" adv="1">GLSA-200406-07</ref>
      <ref url="http://subversion.tigris.org/security/CAN-2004-0413-advisory.txt" source="CONFIRM">http://subversion.tigris.org/security/CAN-2004-0413-advisory.txt</ref>
      <ref url="http://www.securityfocus.com/archive/1/365836" source="BUGTRAQ">20041012 [FMADV] Subversion &lt;= 1.04 Heap Overflow</ref>
    </refs>
    <vuln_soft>
      <prod vendor="openpkg" name="openpkg">
        <vers num="2.0"/>
      </prod>
      <prod vendor="subversion" name="subversion">
        <vers num="1.0"/>
        <vers num="1.0.1"/>
        <vers num="1.0.2"/>
        <vers num="1.0.3"/>
        <vers num="1.0.4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0414" published="2004-08-06" name="CVE-2004-0414" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">CVS 1.12.x through 1.12.8, and 1.11.x through 1.11.16, does not properly handle malformed "Entry" lines, which prevents a NULL terminator from being used and may lead to a denial of service (crash), modification of critical program data, or arbitrary code execution.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1" admin="1"/>
    </loss_types>
    <vuln_types>
      <input buffer="1"/>
      <exception/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.debian.org/security/2004/dsa-517" source="DEBIAN" patch="1" adv="1">DSA-517</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108716553923643&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20040611 [OpenPKG-SA-2004.027] OpenPKG Security Advisory (cvs)</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-233.html" source="REDHAT">RHSA-2004:233</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200406-06.xml" source="GENTOO" adv="1">GLSA-200406-06</ref>
      <ref url="http://security.e-matters.de/advisories/092004.html" source="MISC">http://security.e-matters.de/advisories/092004.html</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10575" source="OVAL">oval:org.mitre.oval:def:10575</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2004-June/022441.html" source="FULLDISC">20040609 Advisory 09/2004: More CVS remote vulnerabilities</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/20040605-01-U.asc" source="SGI">20040605-01-U</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/20040604-01-U.asc" source="SGI">20040604-01-U</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2004:058" source="MANDRAKE">MDKSA-2004:058</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:993" source="OVAL" sig="1">oval:org.mitre.oval:def:993</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cvs" name="cvs">
        <vers num="1.10.7"/>
        <vers num="1.10.8"/>
        <vers num="1.11"/>
        <vers num="1.11.1"/>
        <vers num="1.11.10"/>
        <vers num="1.11.11"/>
        <vers num="1.11.14"/>
        <vers num="1.11.15"/>
        <vers num="1.11.16"/>
        <vers num="1.11.1_p1"/>
        <vers num="1.11.2"/>
        <vers num="1.11.3"/>
        <vers num="1.11.4"/>
        <vers num="1.11.5"/>
        <vers num="1.11.6"/>
        <vers num="1.12.1"/>
        <vers num="1.12.2"/>
        <vers num="1.12.5"/>
        <vers num="1.12.7"/>
        <vers num="1.12.8"/>
      </prod>
      <prod vendor="openpkg" name="openpkg">
        <vers num="1.3"/>
        <vers num="2.0"/>
      </prod>
      <prod vendor="sgi" name="propack">
        <vers num="2.4"/>
        <vers num="3.0"/>
      </prod>
      <prod vendor="gentoo" name="linux">
        <vers num="1.4"/>
      </prod>
      <prod vendor="openbsd" name="openbsd">
        <vers num="3.4"/>
        <vers num="3.5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2004-0415" published="2004-11-23" name="CVE-2004-0415" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">Linux kernel does not properly convert 64-bit file offset pointers to 32 bits, which allows local users to access portions of kernel memory.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <vuln_types>
      <design/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-418.html" source="REDHAT" patch="1" adv="1">RHSA-2004:418</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/16877" source="XF" adv="1">linux-pointer-info-disclosure(16877)</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-413.html" source="REDHAT">RHSA-2004:413</ref>
      <ref url="http://www.mandrakesecure.net/en/advisories/advisory.php?name=MDKSA-2004:087" source="MANDRAKE">MDKSA-2004:087</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200408-24.xml" source="GENTOO">GLSA-200408-24</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9965" source="OVAL">oval:org.mitre.oval:def:9965</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/20040804-01-U.asc" source="SGI">20040804-01-U</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000879" source="CONECTIVA">CLA-2004:879</ref>
    </refs>
    <vuln_soft>
      <prod vendor="linux" name="linux_kernel">
        <vers num="2.4.0" edition="test1"/>
        <vers num="2.4.0" edition="test10"/>
        <vers num="2.4.0" edition="test11"/>
        <vers num="2.4.0" edition="test12"/>
        <vers num="2.4.0" edition="test2"/>
        <vers num="2.4.0" edition="test3"/>
        <vers num="2.4.0" edition="test4"/>
        <vers num="2.4.0" edition="test5"/>
        <vers num="2.4.0" edition="test6"/>
        <vers num="2.4.0" edition="test7"/>
        <vers num="2.4.0" edition="test8"/>
        <vers num="2.4.0" edition="test9"/>
        <vers num="2.4.1"/>
        <vers num="2.4.10"/>
        <vers num="2.4.11"/>
        <vers num="2.4.12"/>
        <vers num="2.4.13"/>
        <vers num="2.4.14"/>
        <vers num="2.4.15"/>
        <vers num="2.4.16"/>
        <vers num="2.4.17"/>
        <vers num="2.4.18" edition=""/>
        <vers num="2.4.18" edition=":x86"/>
        <vers num="2.4.18" edition="pre1"/>
        <vers num="2.4.18" edition="pre2"/>
        <vers num="2.4.18" edition="pre3"/>
        <vers num="2.4.18" edition="pre4"/>
        <vers num="2.4.18" edition="pre5"/>
        <vers num="2.4.18" edition="pre6"/>
        <vers num="2.4.18" edition="pre7"/>
        <vers num="2.4.18" edition="pre8"/>
        <vers num="2.4.19" edition="pre1"/>
        <vers num="2.4.19" edition="pre2"/>
        <vers num="2.4.19" edition="pre3"/>
        <vers num="2.4.19" edition="pre4"/>
        <vers num="2.4.19" edition="pre5"/>
        <vers num="2.4.19" edition="pre6"/>
        <vers num="2.4.2"/>
        <vers num="2.4.20"/>
        <vers num="2.4.21" edition="pre1"/>
        <vers num="2.4.21" edition="pre4"/>
        <vers num="2.4.21" edition="pre7"/>
        <vers num="2.4.22"/>
        <vers num="2.4.23" edition="pre9"/>
        <vers num="2.4.23_ow2"/>
        <vers num="2.4.24"/>
        <vers num="2.4.24_ow1"/>
        <vers num="2.4.25"/>
        <vers num="2.4.26"/>
        <vers num="2.4.3"/>
        <vers num="2.4.4"/>
        <vers num="2.4.5"/>
        <vers num="2.4.6"/>
        <vers num="2.4.7"/>
        <vers num="2.4.8"/>
        <vers num="2.4.9"/>
        <vers num="2.6.0" edition="test1"/>
        <vers num="2.6.0" edition="test10"/>
        <vers num="2.6.0" edition="test11"/>
        <vers num="2.6.0" edition="test2"/>
        <vers num="2.6.0" edition="test3"/>
        <vers num="2.6.0" edition="test4"/>
        <vers num="2.6.0" edition="test5"/>
        <vers num="2.6.0" edition="test6"/>
        <vers num="2.6.0" edition="test7"/>
        <vers num="2.6.0" edition="test8"/>
        <vers num="2.6.0" edition="test9"/>
        <vers num="2.6.1" edition="rc1"/>
        <vers num="2.6.1" edition="rc2"/>
        <vers num="2.6.2"/>
        <vers num="2.6.3"/>
        <vers num="2.6.4"/>
        <vers num="2.6.5"/>
        <vers num="2.6.6" edition="rc1"/>
        <vers num="2.6.7" edition="rc1"/>
        <vers num="2.6_test9_cvs"/>
      </prod>
      <prod vendor="redhat" name="fedora_core">
        <vers num="core_1.0"/>
      </prod>
      <prod vendor="trustix" name="secure_linux">
        <vers num="2.0"/>
        <vers num="2.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0416" published="2004-08-06" name="CVE-2004-0416" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Double free vulnerability for the error_prog_name string in CVS 1.12.x through 1.12.8, and 1.11.x through 1.11.16, may allow remote attackers to execute arbitrary code.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1" admin="1"/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.debian.org/security/2004/dsa-519" source="DEBIAN" patch="1" adv="1">DSA-519</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108716553923643&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20040611 [OpenPKG-SA-2004.027] OpenPKG Security Advisory (cvs)</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-233.html" source="REDHAT">RHSA-2004:233</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2004:058" source="MANDRAKE">MDKSA-2004:058</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200406-06.xml" source="GENTOO">GLSA-200406-06</ref>
      <ref url="http://security.e-matters.de/advisories/092004.html" source="MISC">http://security.e-matters.de/advisories/092004.html</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10070" source="OVAL">oval:org.mitre.oval:def:10070</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2004-June/022441.html" source="FULLDISC">20040609 Advisory 09/2004: More CVS remote vulnerabilities</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/20040605-01-U.asc" source="SGI">20040605-01-U</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/20040604-01-U.asc" source="SGI">20040604-01-U</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:994" source="OVAL" sig="1">oval:org.mitre.oval:def:994</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cvs" name="cvs">
        <vers num="1.10.7"/>
        <vers num="1.10.8"/>
        <vers num="1.11"/>
        <vers num="1.11.1"/>
        <vers num="1.11.10"/>
        <vers num="1.11.11"/>
        <vers num="1.11.14"/>
        <vers num="1.11.15"/>
        <vers num="1.11.16"/>
        <vers num="1.11.1_p1"/>
        <vers num="1.11.2"/>
        <vers num="1.11.3"/>
        <vers num="1.11.4"/>
        <vers num="1.11.5"/>
        <vers num="1.11.6"/>
        <vers num="1.12.1"/>
        <vers num="1.12.2"/>
        <vers num="1.12.5"/>
        <vers num="1.12.7"/>
        <vers num="1.12.8"/>
      </prod>
      <prod vendor="openpkg" name="openpkg">
        <vers num="1.3"/>
        <vers num="2.0"/>
      </prod>
      <prod vendor="sgi" name="propack">
        <vers num="2.4"/>
        <vers num="3.0"/>
      </prod>
      <prod vendor="gentoo" name="linux">
        <vers num="1.4"/>
      </prod>
      <prod vendor="openbsd" name="openbsd">
        <vers num="3.4"/>
        <vers num="3.5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0417" published="2004-08-06" name="CVE-2004-0417" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Integer overflow in the "Max-dotdot" CVS protocol command (serve_max_dotdot) for CVS 1.12.x through 1.12.8, and 1.11.x through 1.11.16, may allow remote attackers to cause a server crash, which could cause temporary data to remain undeleted and consume disk space.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <vuln_types>
      <input bound="1"/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.debian.org/security/2004/dsa-519" source="DEBIAN" patch="1" adv="1">DSA-519</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108716553923643&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20040611 [OpenPKG-SA-2004.027] OpenPKG Security Advisory (cvs)</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-233.html" source="REDHAT">RHSA-2004:233</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200406-06.xml" source="GENTOO" adv="1">GLSA-200406-06</ref>
      <ref url="http://security.e-matters.de/advisories/092004.html" source="MISC">http://security.e-matters.de/advisories/092004.html</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11145" source="OVAL">oval:org.mitre.oval:def:11145</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2004-June/022441.html" source="FULLDISC">20040609 Advisory 09/2004: More CVS remote vulnerabilities</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/20040605-01-U.asc" source="SGI">20040605-01-U</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2004:058" source="MANDRAKE">MDKSA-2004:058</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1001" source="OVAL" sig="1">oval:org.mitre.oval:def:1001</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cvs" name="cvs">
        <vers num="1.10.7"/>
        <vers num="1.10.8"/>
        <vers num="1.11"/>
        <vers num="1.11.1"/>
        <vers num="1.11.10"/>
        <vers num="1.11.11"/>
        <vers num="1.11.14"/>
        <vers num="1.11.15"/>
        <vers num="1.11.16"/>
        <vers num="1.11.1_p1"/>
        <vers num="1.11.2"/>
        <vers num="1.11.3"/>
        <vers num="1.11.4"/>
        <vers num="1.11.5"/>
        <vers num="1.11.6"/>
        <vers num="1.12.1"/>
        <vers num="1.12.2"/>
        <vers num="1.12.5"/>
        <vers num="1.12.7"/>
        <vers num="1.12.8"/>
      </prod>
      <prod vendor="openpkg" name="openpkg">
        <vers num="1.3"/>
        <vers num="2.0"/>
      </prod>
      <prod vendor="sgi" name="propack">
        <vers num="2.4"/>
        <vers num="3.0"/>
      </prod>
      <prod vendor="gentoo" name="linux">
        <vers num="1.4"/>
      </prod>
      <prod vendor="openbsd" name="openbsd">
        <vers num="3.4"/>
        <vers num="3.5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0418" published="2004-08-06" name="CVE-2004-0418" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">serve_notify in CVS 1.12.x through 1.12.8, and 1.11.x through 1.11.16, does not properly handle empty data lines, which may allow remote attackers to perform an "out-of-bounds" write for a single byte to execute arbitrary code or modify critical program data.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1" admin="1"/>
    </loss_types>
    <vuln_types>
      <exception/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.debian.org/security/2004/dsa-519" source="DEBIAN" patch="1" adv="1">DSA-519</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108716553923643&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20040611 [OpenPKG-SA-2004.027] OpenPKG Security Advisory (cvs)</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-233.html" source="REDHAT">RHSA-2004:233</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200406-06.xml" source="GENTOO" adv="1">GLSA-200406-06</ref>
      <ref url="http://security.e-matters.de/advisories/092004.html" source="MISC">http://security.e-matters.de/advisories/092004.html</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11242" source="OVAL">oval:org.mitre.oval:def:11242</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2004-June/022441.html" source="FULLDISC">20040609 Advisory 09/2004: More CVS remote vulnerabilities</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/20040605-01-U.asc" source="SGI">20040605-01-U</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/20040604-01-U.asc" source="SGI">20040604-01-U</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2004:058" source="MANDRAKE">MDKSA-2004:058</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1003" source="OVAL" sig="1">oval:org.mitre.oval:def:1003</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cvs" name="cvs">
        <vers num="1.10.7"/>
        <vers num="1.10.8"/>
        <vers num="1.11"/>
        <vers num="1.11.1"/>
        <vers num="1.11.10"/>
        <vers num="1.11.11"/>
        <vers num="1.11.14"/>
        <vers num="1.11.15"/>
        <vers num="1.11.16"/>
        <vers num="1.11.1_p1"/>
        <vers num="1.11.2"/>
        <vers num="1.11.3"/>
        <vers num="1.11.4"/>
        <vers num="1.11.5"/>
        <vers num="1.11.6"/>
        <vers num="1.12.1"/>
        <vers num="1.12.2"/>
        <vers num="1.12.5"/>
        <vers num="1.12.7"/>
        <vers num="1.12.8"/>
      </prod>
      <prod vendor="openpkg" name="openpkg">
        <vers num="1.3"/>
        <vers num="2.0"/>
      </prod>
      <prod vendor="sgi" name="propack">
        <vers num="2.4"/>
        <vers num="3.0"/>
      </prod>
      <prod vendor="gentoo" name="linux">
        <vers num="1.4"/>
      </prod>
      <prod vendor="openbsd" name="openbsd">
        <vers num="3.4"/>
        <vers num="3.5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0419" published="2004-08-18" name="CVE-2004-0419" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">XDM in XFree86 opens a chooserFd TCP socket even when DisplayManager.requestPort is 0, which could allow remote attackers to connect to the port, in violation of the intended restrictions.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <design/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/10423" source="BID" patch="1" adv="1">10423</ref>
      <ref url="http://www.mandrakesecure.net/en/advisories/advisory.php?name=MDKSA-2004:073" source="MANDRAKE" patch="1" adv="1">MDKSA-2004:073</ref>
      <ref url="https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=124900" source="CONFIRM">https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=124900</ref>
      <ref url="http://www.openbsd.org/errata.html#xdm" source="OPENBSD">20040526 008: SECURITY FIX: May 26, 2004</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200407-05.xml" source="GENTOO" adv="1">GLSA-200407-05</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10161" source="OVAL">oval:org.mitre.oval:def:10161</ref>
      <ref url="http://bugs.xfree86.org/show_bug.cgi?id=1376" source="CONFIRM">http://bugs.xfree86.org/show_bug.cgi?id=1376</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/16264" source="XF">xdm-socket-gain-access(16264)</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-478.html" source="REDHAT">RHSA-2004:478</ref>
      <ref url="http://www.ciac.org/ciac/bulletins/p-001.shtml" source="CIAC">P-001</ref>
      <ref url="http://securitytracker.com/id?1010306" source="SECTRACK">1010306</ref>
      <ref url="http://secunia.com/advisories/12019" source="SECUNIA">12019</ref>
    </refs>
    <vuln_soft>
      <prod vendor="x.org" name="x11r6">
        <vers num="6.7.0"/>
      </prod>
      <prod vendor="xfree86_project" name="xdm">
        <vers num="cvs"/>
      </prod>
      <prod vendor="gentoo" name="linux">
        <vers num="1.4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0420" published="2004-07-07" name="CVE-2004-0420" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">The Windows Shell application in Windows 98, Windows ME, Windows NT 4.0, Windows 2000, Windows XP, and Windows Server 2003 allows remote attackers to execute arbitrary code by spoofing the type of a file via a CLSID specifier in the filename, as demonstrated using Internet Explorer 6.0.2800.1106 on Windows XP.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1" admin="1"/>
    </loss_types>
    <vuln_types>
      <design/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA04-196A.html" source="CERT" adv="1">TA04-196A</ref>
      <ref url="http://www.kb.cert.org/vuls/id/106324" source="CERT-VN">VU#106324</ref>
      <ref url="http://www.securityfocus.com/bid/9510" source="BID" adv="1">9510</ref>
      <ref url="http://www.securityfocus.com/archive/1/351379" source="BUGTRAQ" adv="1">20040127 GOOROO CROSSING: File Spoofing Internet Explorer 6</ref>
      <ref url="http://www.security-express.com/archives/bugtraq/2004-01/0300.html" source="BUGTRAQ">20040127 RE: GOOROO CROSSING: File Spoofing Internet Explorer 6</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms04-024.asp" source="MS">MS04-024</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/14964" source="XF">ie-clsid-file-extension-spoofing(14964)</ref>
      <ref url="http://secunia.com/advisories/10736/" source="SECUNIA">10736</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:3604" source="OVAL" sig="1">oval:org.mitre.oval:def:3604</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:3533" source="OVAL" sig="1">oval:org.mitre.oval:def:3533</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:3386" source="OVAL" sig="1">oval:org.mitre.oval:def:3386</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2894" source="OVAL" sig="1">oval:org.mitre.oval:def:2894</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2381" source="OVAL" sig="1">oval:org.mitre.oval:def:2381</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2245" source="OVAL" sig="1">oval:org.mitre.oval:def:2245</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="ie">
        <vers num="6.0" edition="sp1"/>
        <vers num="6.0.2800.1106"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0421" published="2004-08-18" name="CVE-2004-0421" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The Portable Network Graphics library (libpng) 1.0.15 and earlier allows attackers to cause a denial of service (crash) via a malformed PNG image file that triggers an error that causes an out-of-bounds read when creating the error message.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <vuln_types>
      <input buffer="1"/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/10244" source="BID" patch="1" adv="1">10244</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-180.html" source="REDHAT" patch="1" adv="1">RHSA-2004:180</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/16022" source="XF" adv="1">libpng-png-dos(16022)</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-181.html" source="REDHAT">RHSA-2004:181</ref>
      <ref url="http://www.debian.org/security/2004/dsa-498" source="DEBIAN">DSA-498</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11710" source="OVAL">oval:org.mitre.oval:def:11710</ref>
      <ref url="http://marc.theaimsgroup.com/?l=fedora-announce-list&amp;m=108451353608968&amp;w=2" source="FEDORA">FEDORA-2004-106</ref>
      <ref url="http://marc.theaimsgroup.com/?l=fedora-announce-list&amp;m=108451350029261&amp;w=2" source="FEDORA">FEDORA-2004-105</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108335030208523&amp;w=2" source="TRUSTIX">2004-0025</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108334922320309&amp;w=2" source="BUGTRAQ">20040429 [OpenPKG-SA-2004.017] OpenPKG Security Advisory (png)</ref>
      <ref url="http://lists.apple.com/mhonarc/security-announce/msg00056.html" source="APPLE">APPLE-SA-2004-09-09</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:213" source="MANDRIVA">MDKSA-2006:213</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:212" source="MANDRIVA">MDKSA-2006:212</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2004:040" source="MANDRAKE">MDKSA-2004:040</ref>
      <ref url="http://secunia.com/advisories/22958" source="SECUNIA">22958</ref>
      <ref url="http://secunia.com/advisories/22957" source="SECUNIA">22957</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:971" source="OVAL" sig="1">oval:org.mitre.oval:def:971</ref>
    </refs>
    <vuln_soft>
      <prod vendor="greg_roelofs" name="libpng">
        <vers num="1.0"/>
        <vers num="1.0.10"/>
        <vers num="1.0.11"/>
        <vers num="1.0.12"/>
        <vers num="1.0.13"/>
        <vers num="1.0.14"/>
        <vers num="1.0.5"/>
        <vers num="1.0.6"/>
        <vers num="1.0.7"/>
        <vers num="1.0.8"/>
        <vers num="1.0.9"/>
      </prod>
      <prod vendor="greg_roelofs" name="libpng3">
        <vers num="1.2.0"/>
        <vers num="1.2.1"/>
        <vers num="1.2.2"/>
        <vers num="1.2.3"/>
        <vers num="1.2.4"/>
        <vers num="1.2.5"/>
      </prod>
      <prod vendor="openpkg" name="openpkg">
        <vers num="1.3"/>
        <vers num="2.0"/>
      </prod>
      <prod vendor="redhat" name="libpng">
        <vers num="1.2.2-16" edition=""/>
        <vers num="1.2.2-16" edition=":i386_dev"/>
        <vers num="1.2.2-16" edition=":i386"/>
        <vers num="1.2.2-20" edition=""/>
        <vers num="1.2.2-20" edition=":i386"/>
        <vers num="1.2.2-20" edition=":i386_dev"/>
        <vers num="10.1.0.13.11" edition=""/>
        <vers num="10.1.0.13.11" edition=":i386"/>
        <vers num="10.1.0.13.11" edition=":i386_dev"/>
        <vers num="10.1.0.13.8" edition=""/>
        <vers num="10.1.0.13.8" edition=":i386"/>
        <vers num="10.1.0.13.8" edition=":i386_dev"/>
      </prod>
      <prod vendor="redhat" name="enterprise_linux">
        <vers num="2.1" edition=""/>
        <vers num="2.1" edition=":advanced_server"/>
        <vers num="2.1" edition=":enterprise_server"/>
        <vers num="2.1" edition=":workstation"/>
        <vers num="3.0" edition=""/>
        <vers num="3.0" edition=":advanced_server"/>
        <vers num="3.0" edition=":workstation_server"/>
        <vers num="3.0" edition=":enterprise_server"/>
      </prod>
      <prod vendor="redhat" name="enterprise_linux_desktop">
        <vers num="3.0"/>
      </prod>
      <prod vendor="redhat" name="linux_advanced_workstation">
        <vers num="2.1" edition=""/>
        <vers num="2.1" edition=":itanium_processor"/>
        <vers num="2.1" edition=":ia64"/>
      </prod>
      <prod vendor="trustix" name="secure_linux">
        <vers num="2.0"/>
        <vers num="2.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2004-0422" published="2004-07-07" name="CVE-2004-0422" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">flim before 1.14.3 creates temporary files insecurely, which allows local users to overwrite arbitrary files of the Emacs user via a symlink attack.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <vuln_types>
      <design/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/16027" source="XF" patch="1" adv="1">flim-insecure-temporary-file(16027)</ref>
      <ref url="http://www.debian.org/security/2004/dsa-500" source="DEBIAN" patch="1" adv="1">DSA-500</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-344.html" source="REDHAT">RHSA-2004:344</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gnu" name="flim">
        <vers prev="1" num="1.14.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2004-0423" published="2004-07-07" name="CVE-2004-0423" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">The log_event function in ssmtp 2.50.6 and earlier allows local users to overwrite arbitrary files via a symlink attack on the ssmtp.log temporary log file.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <vuln_types>
      <design/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108239608131119&amp;w=2" source="BUGTRAQ">20040418 ssmtp insecure file creation</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ssmtp" name="ssmtp">
        <vers prev="1" num="2.50.6"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0424" published="2004-07-07" name="CVE-2004-0424" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Integer overflow in the ip_setsockopt function in Linux kernel 2.4.22 through 2.4.25 and 2.6.1 through 2.6.3 allows local users to cause a denial of service (crash) or execute arbitrary code via the MCAST_MSFILTER socket option.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1" other="1" admin="1"/>
    </loss_types>
    <vuln_types>
      <input bound="1"/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/15907" source="XF" patch="1" adv="1">linux-ipsetsockopt-integer-bo(15907)</ref>
      <ref url="http://www.securityfocus.com/bid/10179" source="BID" patch="1" adv="1">10179</ref>
      <ref url="http://www.linuxsecurity.com/advisories/engarde_advisory-4285.html" source="ENGARDE" patch="1" adv="1">ESA-20040428-004</ref>
      <ref url="http://www.isec.pl/vulnerabilities/isec-0015-msfilter.txt" source="MISC" patch="1" adv="1">http://www.isec.pl/vulnerabilities/isec-0015-msfilter.txt</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108253171301153&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20040420 Linux kernel setsockopt MCAST_MSFILTER integer overflow</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2004_10_kernel.html" source="SUSE">SuSE-SA:2004:010</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11214" source="OVAL">oval:org.mitre.oval:def:11214</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/20040504-01-U.asc" source="SGI">20040504-01-U</ref>
      <ref url="http://www.slackware.com/security/viewer.php?l=slackware-security&amp;y=2004&amp;m=slackware-security.659586" source="SLACKWARE">SSA:2004-119</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-183.html" source="REDHAT">RHSA-2004:183</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2004:037" source="MANDRAKE">MDKSA-2004:037</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000852" source="CONECTIVA">CLA-2004:852</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:939" source="OVAL" sig="1">oval:org.mitre.oval:def:939</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sgi" name="propack">
        <vers num="3.0"/>
      </prod>
      <prod vendor="linux" name="linux_kernel">
        <vers num="2.4.22"/>
        <vers num="2.4.23" edition="pre9"/>
        <vers num="2.4.23_ow2"/>
        <vers num="2.4.24"/>
        <vers num="2.4.24_ow1"/>
        <vers num="2.4.25"/>
        <vers num="2.6.1" edition="rc1"/>
        <vers num="2.6.1" edition="rc2"/>
        <vers num="2.6.2"/>
        <vers num="2.6.3"/>
      </prod>
      <prod vendor="slackware" name="slackware_linux">
        <vers num="9.1"/>
        <vers num="current"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0425" published="2004-08-18" name="CVE-2004-0425" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Heap-based buffer overflow in SiteMinder Affiliate Agent 4.x allows remote attackers to execute arbitrary code via a large SMPROFILE cookie.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1" admin="1"/>
    </loss_types>
    <vuln_types>
      <input buffer="1"/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/15950" source="XF" adv="1">siteminder-affiliate-smprofile-bo(15950)</ref>
      <ref url="http://www.securityfocus.com/bid/10198" source="BID" adv="1">10198</ref>
      <ref url="http://www.atstake.com/research/advisories/2004/a042204-1.txt" source="ATSTAKE" adv="1">A042204-1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="netegrity" name="sideminder_affiliate_agent">
        <vers num="4.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0426" published="2004-07-07" name="CVE-2004-0426" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">rsync before 2.6.1 does not properly sanitize paths when running a read/write daemon without using chroot, which allows remote attackers to write files outside of the module's path.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <vuln_types>
      <design/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-192.html" source="REDHAT" patch="1" adv="1">RHSA-2004:192</ref>
      <ref url="http://www.debian.org/security/2004/dsa-499" source="DEBIAN" patch="1" adv="1">DSA-499</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108515912212018&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20040521 [OpenPKG-SA-2004.025] OpenPKG Security Advisory (rsync)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/16014" source="XF">rsync-write-files(16014)</ref>
      <ref url="http://www.trustix.net/errata/misc/2004/TSL-2004-0024-rsync.asc.txt" source="TRUSTIX">TSL-2004-0024</ref>
      <ref url="http://www.slackware.org/security/viewer.php?l=slackware-security&amp;y=2004&amp;m=slackware-security.403462" source="SLACKWARE">SSA:2004-124-01</ref>
      <ref url="http://www.securityfocus.com/bid/10247" source="BID">10247</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200407-10.xml" source="GENTOO">GLSA-200407-10</ref>
      <ref url="http://www.ciac.org/ciac/bulletins/o-212.shtml" source="CIAC">O-212</ref>
      <ref url="http://www.ciac.org/ciac/bulletins/o-134.shtml" source="CIAC">O-134</ref>
      <ref url="http://secunia.com/advisories/12054" source="SECUNIA">12054</ref>
      <ref url="http://secunia.com/advisories/11993" source="SECUNIA">11993</ref>
      <ref url="http://secunia.com/advisories/11688" source="SECUNIA">11688</ref>
      <ref url="http://secunia.com/advisories/11669" source="SECUNIA">11669</ref>
      <ref url="http://secunia.com/advisories/11583" source="SECUNIA">11583</ref>
      <ref url="http://secunia.com/advisories/11537" source="SECUNIA">11537</ref>
      <ref url="http://secunia.com/advisories/11523" source="SECUNIA">11523</ref>
      <ref url="http://secunia.com/advisories/11515" source="SECUNIA">11515</ref>
      <ref url="http://secunia.com/advisories/11514" source="SECUNIA">11514</ref>
      <ref url="http://rsync.samba.org/" source="CONFIRM" adv="1">http://rsync.samba.org/</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9495" source="OVAL">oval:org.mitre.oval:def:9495</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2004:042" source="MANDRAKE">MDKSA-2004:042</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:967" source="OVAL" sig="1">oval:org.mitre.oval:def:967</ref>
    </refs>
    <vuln_soft>
      <prod vendor="andrew_tridgell" name="rsync">
        <vers prev="1" num="2.6"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2004-0427" published="2004-07-07" name="CVE-2004-0427" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">The do_fork function in Linux 2.4.x before 2.4.26, and 2.6.x before 2.6.6, does not properly decrement the mm_count counter when an error occurs after the mm_struct for a child process has been activated, which triggers a memory leak that allows local users to cause a denial of service (memory exhaustion) via the clone (CLONE_VM) system call.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <vuln_types>
      <design/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=linux-kernel&amp;m=108139073506983&amp;w=2" source="MLIST" patch="1" adv="1">[linux-kernel] 20040408 [PATCH]: 2.4/2.6 do_fork() error path memory leak</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/20040505-01-U.asc" source="SGI" patch="1" adv="1">20040505-01-U</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/20040504-01-U.asc" source="SGI" patch="1" adv="1">20040504-01-U</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-255.html" source="REDHAT">RHSA-2004:255</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2004_10_kernel.html" source="SUSE">SuSE-SA:2004:010</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200407-02.xml" source="GENTOO">GLSA-200407-02</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10297" source="OVAL">oval:org.mitre.oval:def:10297</ref>
      <ref url="http://linux.bkbits.net:8080/linux-2.6/cset@407b1217x4jtqEkpFW2g_-RcF0726A" source="MISC">http://linux.bkbits.net:8080/linux-2.6/cset@407b1217x4jtqEkpFW2g_-RcF0726A</ref>
      <ref url="http://linux.bkbits.net:8080/linux-2.4/cset@407bf20eDeeejm8t36_tpvSE-8EFHA" source="MISC">http://linux.bkbits.net:8080/linux-2.4/cset@407bf20eDeeejm8t36_tpvSE-8EFHA</ref>
      <ref url="http://fedoranews.org/updates/FEDORA-2004-111.shtml" source="FEDORA">FEDORA-2004-111</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000846" source="CONECTIVA">CLA-2004:846</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/16002" source="XF">linux-dofork-memory-leak(16002)</ref>
      <ref url="http://www.turbolinux.com/security/2004/TLSA-2004-14.txt" source="TURBO">TLSA-2004-14</ref>
      <ref url="http://www.securityfocus.com/bid/10221" source="BID">10221</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-327.html" source="REDHAT">RHSA-2004:327</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-260.html" source="REDHAT">RHSA-2004:260</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2004:037" source="MANDRAKE">MDKSA-2004:037</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1082" source="DEBIAN">DSA-1082</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1070" source="DEBIAN">DSA-1070</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1069" source="DEBIAN">DSA-1069</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1067" source="DEBIAN">DSA-1067</ref>
      <ref url="http://www.ciac.org/ciac/bulletins/o-164.shtml" source="CIAC">O-164</ref>
      <ref url="http://secunia.com/advisories/20338" source="SECUNIA">20338</ref>
      <ref url="http://secunia.com/advisories/20202" source="SECUNIA">20202</ref>
      <ref url="http://secunia.com/advisories/20163" source="SECUNIA">20163</ref>
      <ref url="http://secunia.com/advisories/20162" source="SECUNIA">20162</ref>
      <ref url="http://secunia.com/advisories/11892" source="SECUNIA">11892</ref>
      <ref url="http://secunia.com/advisories/11891" source="SECUNIA">11891</ref>
      <ref url="http://secunia.com/advisories/11861" source="SECUNIA">11861</ref>
      <ref url="http://secunia.com/advisories/11541" source="SECUNIA">11541</ref>
      <ref url="http://secunia.com/advisories/11486" source="SECUNIA">11486</ref>
      <ref url="http://secunia.com/advisories/11464" source="SECUNIA">11464</ref>
      <ref url="http://secunia.com/advisories/11429" source="SECUNIA">11429</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2819" source="OVAL" sig="1">oval:org.mitre.oval:def:2819</ref>
    </refs>
    <vuln_soft>
      <prod vendor="linux" name="linux_kernel">
        <vers num="2.4.0"/>
        <vers num="2.6.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0428" published="2004-05-03" name="CVE-2004-0428" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Unknown vulnerability in CoreFoundation in Mac OS X 10.3.3 and Mac OS X 10.3.3 Server, related to "the handling of an environment variable," has unknown attack vectors and unknown impact.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/16051" source="XF" patch="1" adv="1">macos-corefoundation-environment(16051)</ref>
      <ref url="http://www.securityfocus.com/bid/10270" source="BID" patch="1" adv="1">10270</ref>
      <ref url="http://www.auscert.org.au/render.html?it=4070" source="AUSCERT" patch="1" adv="1">ESB-2004.0314</ref>
      <ref url="http://securitytracker.com/id?1010045" source="SECTRACK" patch="1" adv="1">1010045</ref>
      <ref url="http://secunia.com/advisories/11539" source="SECUNIA" patch="1" adv="1">11539</ref>
      <ref url="http://lists.virus.org/macsec-0405/msg00000.html" source="APPLE" patch="1" adv="1">APPLE-SA-2004-05-03</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.2"/>
        <vers num="10.2.1"/>
        <vers num="10.2.2"/>
        <vers num="10.2.3"/>
        <vers num="10.2.4"/>
        <vers num="10.2.5"/>
        <vers num="10.2.6"/>
        <vers num="10.2.7"/>
        <vers num="10.2.8"/>
        <vers num="10.3"/>
        <vers num="10.3.1"/>
        <vers num="10.3.2"/>
        <vers num="10.3.3"/>
      </prod>
      <prod vendor="apple" name="mac_os_x_server">
        <vers num="10.2"/>
        <vers num="10.2.1"/>
        <vers num="10.2.2"/>
        <vers num="10.2.3"/>
        <vers num="10.2.4"/>
        <vers num="10.2.5"/>
        <vers num="10.2.6"/>
        <vers num="10.2.7"/>
        <vers num="10.2.8"/>
        <vers num="10.3"/>
        <vers num="10.3.1"/>
        <vers num="10.3.2"/>
        <vers num="10.3.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0429" published="2004-12-31" name="CVE-2004-0429" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Unknown vulnerability related to "the handling of large requests" in RAdmin for Apple Mac OS X 10.3.3 and Mac OS X 10.2.8 may allow attackers to have unknown impact via unknown attack vectors.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.auscert.org.au/render.html?it=4070" source="AUSCERT" patch="1">ESB-2004.0314</ref>
      <ref url="http://securitytracker.com/id?1010045" source="SECTRACK" patch="1">1010045</ref>
      <ref url="http://secunia.com/advisories/11539/" source="SECUNIA" patch="1" adv="1">11539</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108369640424244&amp;w=2" source="BUGTRAQ" patch="1">20040503 [product-security@apple.com: APPLE-SA-2004-05-03 Security Update 2004-05-03]</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2004/May/msg00000.html" source="APPLE" patch="1">APPLE-SA-2004-05-03</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/16053" source="XF">macos-radmin-large-request(16053)</ref>
      <ref url="http://www.ciac.org/ciac/bulletins/o-138.shtml" source="CIAC">O-138</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.2.8"/>
        <vers num="10.3.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0430" published="2004-07-07" name="CVE-2004-0430" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_score="5.1" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="4.9" CVSS_base_score="5.1">
    <desc>
      <descript source="cve">Stack-based buffer overflow in AppleFileServer for Mac OS X 10.3.3 and earlier allows remote attackers to execute arbitrary code via a LoginExt packet for a Cleartext Password User Authentication Method (UAM) request with a PathName argument that includes an AFPName type string that is longer than the associated length field.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input bound="1"/>
    </vuln_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/648406" source="CERT-VN">VU#648406</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/16049" source="XF" patch="1" adv="1">applefileserver-afp-pathname-bo(16049)</ref>
      <ref url="http://www.atstake.com/research/advisories/2004/a050304-1.txt" source="ATSTAKE" patch="1" adv="1">A050304-1</ref>
      <ref url="http://www.securiteam.com/securitynews/5QP0115CUO.html" source="MISC">http://www.securiteam.com/securitynews/5QP0115CUO.html</ref>
      <ref url="http://securitytracker.com/id?1010039" source="SECTRACK">1010039</ref>
      <ref url="http://secunia.com/advisories/11539" source="SECUNIA">11539</ref>
      <ref url="http://lists.apple.com/mhonarc/security-announce/msg00049.html" source="APPLE">APPLE-SA-2004-05-03</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers prev="1" num="10.3.3"/>
      </prod>
      <prod vendor="apple" name="mac_os_x_server">
        <vers prev="1" num="10.3.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0431" published="2004-07-07" name="CVE-2004-0431" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_score="5.1" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="4.9" CVSS_base_score="5.1">
    <desc>
      <descript source="cve">Integer overflow in Apple QuickTime (QuickTime.qts) before 6.5.1 allows attackers to execute arbitrary code via a large "number of entries" field in the sample-to-chunk table data for a .mov movie file, which leads to a heap-based buffer overflow.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input bound="1"/>
    </vuln_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/782958" source="CERT-VN">VU#782958</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/16026" source="XF" patch="1" adv="1">quicktime-heap-bo(16026)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=108356485013237&amp;w=2" source="NTBUGTRAQ" patch="1" adv="1">20040502 EEYE: Apple QuickTime (QuickTime.qts) Heap Overflow</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108360110618389&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20040502 EEYE: Apple QuickTime (QuickTime.qts) Heap Overflow</ref>
      <ref url="http://lists.apple.com/mhonarc/security-announce/msg00048.html" source="APPLE">APPLE-SA-2004-04-30</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="quicktime">
        <vers prev="1" num="6.5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0432" published="2004-08-18" name="CVE-2004-0432" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">ProFTPD 1.2.9 treats the Allow and Deny directives for CIDR based ACL entries as if they were AllowAll, which could allow FTP clients to bypass intended access restrictions.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <access/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/10252" source="BID" patch="1" adv="1">10252</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/16038" source="XF" adv="1">proftpd-cidr-acl-bypass(16038)</ref>
      <ref url="http://secunia.com/advisories/11527" source="SECUNIA">11527</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108335030208523&amp;w=2" source="TRUSTIX">2004-0025</ref>
      <ref url="http://bugs.proftpd.org/show_bug.cgi?id=2267" source="CONFIRM">http://bugs.proftpd.org/show_bug.cgi?id=2267</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2004:041" source="MANDRAKE">MDKSA-2004:041</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108335051011341&amp;w=2" source="BUGTRAQ">20040430 [OpenPKG-SA-2004.018] OpenPKG Security Advisory (proftpd)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="proftpd_project" name="proftpd">
        <vers num="1.2.9"/>
      </prod>
      <prod vendor="gentoo" name="linux">
        <vers num="0.5"/>
        <vers num="0.7"/>
        <vers num="1.1a"/>
        <vers num="1.2"/>
        <vers num="1.4" edition="rc1"/>
        <vers num="1.4" edition="rc2"/>
        <vers num="1.4" edition="rc3"/>
      </prod>
      <prod vendor="trustix" name="secure_linux">
        <vers num="2.0"/>
        <vers num="2.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0433" published="2004-08-18" name="CVE-2004-0433" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Multiple buffer overflows in the Real-Time Streaming Protocol (RTSP) client for (1) MPlayer before 1.0pre4 and (2) xine lib (xine-lib) before 1-rc4, when playing Real RTSP (realrtsp) streams, allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via (a) long URLs, (b) long Real server responses, or (c) long Real Data Transport (RDT) packets.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1" admin="1"/>
    </loss_types>
    <vuln_types>
      <input buffer="1"/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/16019" source="XF" adv="1">mplayer-rtsp-rdt-bo(16019)</ref>
      <ref url="http://www.xinehq.de/index.php/security/XSA-2004-3" source="CONFIRM">http://www.xinehq.de/index.php/security/XSA-2004-3</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200405-24.xml" source="GENTOO" adv="1">GLSA-200405-24</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mplayer" name="mplayer">
        <vers num="1.0_pre3try2"/>
      </prod>
      <prod vendor="xine" name="xine-lib">
        <vers num="1_beta1"/>
        <vers num="1_beta10"/>
        <vers num="1_beta11"/>
        <vers num="1_beta2"/>
        <vers num="1_beta3"/>
        <vers num="1_beta4"/>
        <vers num="1_beta5"/>
        <vers num="1_beta6"/>
        <vers num="1_beta7"/>
        <vers num="1_beta8"/>
        <vers num="1_beta9"/>
        <vers num="1_rc2"/>
        <vers num="1_rc3a"/>
        <vers num="1_rc3b"/>
        <vers num="1_rc3c"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0434" published="2004-07-07" name="CVE-2004-0434" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">k5admind (kadmind) for Heimdal allows remote attackers to execute arbitrary code via a Kerberos 4 compatibility administration request whose framing length is less than 2, which leads to a heap-based buffer overflow.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1" other="1" admin="1"/>
    </loss_types>
    <vuln_types>
      <input buffer="1"/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/16071" source="XF" patch="1" adv="1">heimdal-kadmind-bo(16071)</ref>
      <ref url="http://www.debian.org/security/2004/dsa-504" source="DEBIAN" patch="1" adv="1">DSA-504</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200405-23.xml" source="GENTOO">GLSA-200405-23</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108386148126457&amp;w=2" source="BUGTRAQ" adv="1">20040505 Advisory: Heimdal kadmind version4 remote heap overflow</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2004-May/020998.html" source="FULLDISC">20040506 Advisory: Heimdal kadmind version4 remote heap overflow</ref>
      <ref url="ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-04:09.kadmind.asc" source="FREEBSD">FreeBSD-SA-04:09</ref>
    </refs>
    <vuln_soft>
      <prod vendor="kth" name="heimdal">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2004-0435" published="2004-08-18" name="CVE-2004-0435" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:P)" CVSS_score="3.6" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="3.9" CVSS_base_score="3.6">
    <desc>
      <descript source="cve">Certain "programming errors" in the msync system call for FreeBSD 5.2.1 and earlier, and 4.10 and earlier, do not properly handle the MS_INVALIDATE operation, which leads to cache consistency problems that allow a local user to prevent certain changes to files from being committed to disk.</descript>
    </desc>
    <loss_types>
      <avail/>
      <int/>
    </loss_types>
    <vuln_types>
      <design/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-04:11.msync.asc" source="FREEBSD">FreeBSD-SA-04:11</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/16254" source="XF">freebsd-msync-gain-privileges(16254)</ref>
      <ref url="http://www.securityfocus.com/bid/10416" source="BID">10416</ref>
      <ref url="http://secunia.com/advisories/11714" source="SECUNIA">11714</ref>
    </refs>
    <vuln_soft>
      <prod vendor="freebsd" name="freebsd">
        <vers num="4.0" edition="releng"/>
        <vers num="4.10" edition="release"/>
        <vers num="4.10" edition="releng"/>
        <vers num="4.8" edition="pre-release"/>
        <vers num="4.8" edition="release_p6"/>
        <vers num="4.8" edition="releng"/>
        <vers num="4.9" edition="pre-release"/>
        <vers num="4.9" edition="releng"/>
        <vers num="5.2"/>
        <vers num="5.2.1" edition="release"/>
        <vers num="5.2.1" edition="releng"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0437" published="2004-07-07" name="CVE-2004-0437" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Titan FTP Server version 3.01 build 163, and possibly other versions before build 169, allows remote authenticated users to cause a denial of service (crash) by disconnecting from the system during a "LIST -L" command, which causes Titan to access an invalid socket.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <vuln_types>
      <exception/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/16057" source="XF" patch="1" adv="1">titan-list-command-dos(16057)</ref>
      <ref url="http://www.securiteam.com/windowsntfocus/5RP0215CUU.html" source="MISC" patch="1" adv="1">http://www.securiteam.com/windowsntfocus/5RP0215CUU.html</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108378048513596&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20040505 Titan FTP Server Aborted LIST DoS</ref>
      <ref url="http://archives.neohapsis.com/archives/vulnwatch/2004-q2/0025.html" source="VULNWATCH" patch="1" adv="1">20040505 Titan FTP Server Aborted LIST DoS</ref>
    </refs>
    <vuln_soft>
      <prod vendor="south_river_technologies" name="titan_ftp_server">
        <vers num="3.01_build_163"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0444" published="2004-07-07" name="CVE-2004-0444" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Multiple vulnerabilities in SYMDNS.SYS for Symantec Norton Internet Security and Professional 2002 through 2004, Norton Personal Firewall 2002 through 2004, Norton AntiSpam 2004, Client Firewall 5.01 and 5.1.1, and Client Security 1.0 through 2.0 allow remote attackers to cause a denial of service or execute arbitrary code via (1) a manipulated length byte in the first-level decoding routine for NetBIOS Name Service (NBNS) that modifies an index variable and leads to a stack-based buffer overflow, (2) a heap-based corruption problem in an NBNS response that is missing certain RR fields, and (3) a stack-based buffer overflow in the DNS component via a Resource Record (RR) with a long canonical name (CNAME) field composed of many smaller components.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1" other="1" admin="1"/>
    </loss_types>
    <vuln_types>
      <input buffer="1" bound="1"/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/634414" source="CERT-VN" patch="1" adv="1">VU#634414</ref>
      <ref url="http://www.kb.cert.org/vuls/id/294998" source="CERT-VN" patch="1" adv="1">VU#294998</ref>
      <ref url="http://www.kb.cert.org/vuls/id/637318" source="CERT-VN">VU#637318</ref>
      <ref url="http://www.securityfocus.com/bid/10335" source="BID">10335</ref>
      <ref url="http://www.securityfocus.com/bid/10334" source="BID">10334</ref>
      <ref url="http://www.securityfocus.com/bid/10333" source="BID">10333</ref>
      <ref url="http://securityresponse.symantec.com/avcenter/security/Content/2004.05.12.html" source="CONFIRM">http://securityresponse.symantec.com/avcenter/security/Content/2004.05.12.html</ref>
      <ref url="http://secunia.com/advisories/11066" source="SECUNIA">11066</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2004-May/021362.html" source="FULLDISC">20040512 EEYE: Symantec Multiple Firewall NBNS Response Remote Heap Corruption</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2004-May/021361.html" source="FULLDISC">20040512 EEYE: Symantec Multiple Firewall Remote DNS KERNEL Overflow</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2004-May/021360.html" source="FULLDISC">20040512 EEYE: Symantec Multiple Firewall NBNS Response Processing Stack Overflow</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/16137" source="XF">symantec-dns-response-bo(16137)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/16135" source="XF">symantec-firewalls-nbns-bo(16135)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/16134" source="XF">symantec-nbns-response-bo(16134)</ref>
      <ref url="http://www.osvdb.org/6102" source="OSVDB">6102</ref>
      <ref url="http://www.osvdb.org/6101" source="OSVDB">6101</ref>
      <ref url="http://www.osvdb.org/6099" source="OSVDB">6099</ref>
      <ref url="http://www.ciac.org/ciac/bulletins/o-141.shtml" source="CIAC">O-141</ref>
      <ref url="http://securitytracker.com/id?1010146" source="SECTRACK">1010146</ref>
      <ref url="http://securitytracker.com/id?1010145" source="SECTRACK">1010145</ref>
      <ref url="http://securitytracker.com/id?1010144" source="SECTRACK">1010144</ref>
    </refs>
    <vuln_soft>
      <prod vendor="symantec" name="client_firewall">
        <vers num="5.01"/>
        <vers num="5.1.1"/>
      </prod>
      <prod vendor="symantec" name="client_security">
        <vers num="1.0"/>
        <vers num="1.1"/>
        <vers num="1.2"/>
        <vers num="1.3"/>
        <vers num="1.4"/>
        <vers num="1.5"/>
        <vers num="1.6"/>
        <vers num="1.7"/>
        <vers num="1.8"/>
        <vers num="1.9"/>
        <vers num="2.0"/>
      </prod>
      <prod vendor="symantec" name="norton_antispam">
        <vers num="2004"/>
      </prod>
      <prod vendor="symantec" name="norton_internet_security">
        <vers num="2002" edition=""/>
        <vers num="2002" edition=":pro"/>
        <vers num="2003" edition=""/>
        <vers num="2003" edition=":pro"/>
        <vers num="2004" edition=""/>
        <vers num="2004" edition=":pro"/>
      </prod>
      <prod vendor="symantec" name="norton_personal_firewall">
        <vers num="2002"/>
        <vers num="2003"/>
        <vers num="2004"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2004-0445" published="2004-07-07" name="CVE-2004-0445" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:N/A:P)" CVSS_score="2.6" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="4.9" CVSS_base_score="2.6">
    <desc>
      <descript source="cve">The SYMDNS.SYS driver in Symantec Norton Internet Security and Professional 2002 through 2004, Norton Personal Firewall 2002 through 2004, Norton AntiSpam 2004, Client Firewall 5.01 and 5.1.1, and Client Security 1.0 through 2.0 allows remote attackers to cause a denial of service (CPU consumption from infinite loop) via a DNS response with a compressed name pointer that points to itself.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <vuln_types>
      <exception/>
    </vuln_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/682110" source="CERT-VN" patch="1" adv="1">VU#682110</ref>
      <ref url="http://securityresponse.symantec.com/avcenter/security/Content/2004.05.12.html" source="CONFIRM" patch="1" adv="1">http://securityresponse.symantec.com/avcenter/security/Content/2004.05.12.html</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/16132" source="XF">symantec-firewall-dns-dos(16132)</ref>
      <ref url="http://www.securityfocus.com/bid/10336" source="BID">10336</ref>
      <ref url="http://secunia.com/advisories/11066" source="SECUNIA">11066</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2004-May/021359.html" source="FULLDISC">20040512 EEYE: Symantec Multiple Firewall DNS Response Denial-of-Service</ref>
      <ref url="http://www.osvdb.org/6100" source="OSVDB">6100</ref>
      <ref url="http://www.ciac.org/ciac/bulletins/o-141.shtml" source="CIAC">O-141</ref>
      <ref url="http://securitytracker.com/id?1010146" source="SECTRACK">1010146</ref>
      <ref url="http://securitytracker.com/id?1010145" source="SECTRACK">1010145</ref>
      <ref url="http://securitytracker.com/id?1010144" source="SECTRACK">1010144</ref>
    </refs>
    <vuln_soft>
      <prod vendor="symantec" name="client_firewall">
        <vers num="5.01"/>
        <vers num="5.1.1"/>
      </prod>
      <prod vendor="symantec" name="client_security">
        <vers num="1.0"/>
        <vers num="1.1"/>
        <vers num="1.2"/>
        <vers num="1.3"/>
        <vers num="1.4"/>
        <vers num="1.5"/>
        <vers num="1.6"/>
        <vers num="1.7"/>
        <vers num="1.8"/>
        <vers num="1.9"/>
        <vers num="2.0"/>
      </prod>
      <prod vendor="symantec" name="norton_antispam">
        <vers num="2004"/>
      </prod>
      <prod vendor="symantec" name="norton_internet_security">
        <vers num="2002" edition=""/>
        <vers num="2002" edition=":pro"/>
        <vers num="2003" edition=""/>
        <vers num="2003" edition=":pro"/>
        <vers num="2004" edition=""/>
        <vers num="2004" edition=":pro"/>
      </prod>
      <prod vendor="symantec" name="norton_personal_firewall">
        <vers num="2002"/>
        <vers num="2003"/>
        <vers num="2004"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0447" published="2004-08-06" name="CVE-2004-0447" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Unknown vulnerability in Linux before 2.4.26 for IA64 allows local users to cause a denial of service, with unknown impact.  NOTE: due to a typo, this issue was accidentally assigned CVE-2004-0477.  This is the proper candidate to use for the Linux local DoS.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <vuln_types>
      <exception/>
      <other/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/10783" source="BID" patch="1" adv="1">10783</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/16661" source="XF">linux-ia64-dos(16661)</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-413.html" source="REDHAT">RHSA-2004:413</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1082" source="DEBIAN">DSA-1082</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1070" source="DEBIAN">DSA-1070</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1069" source="DEBIAN">DSA-1069</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1067" source="DEBIAN">DSA-1067</ref>
      <ref url="http://www.ciac.org/ciac/bulletins/o-193.shtml" source="CIAC">O-193</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200407-16.xml" source="GENTOO">GLSA-200407-16</ref>
      <ref url="http://secunia.com/advisories/20338" source="SECUNIA">20338</ref>
      <ref url="http://secunia.com/advisories/20202" source="SECUNIA">20202</ref>
      <ref url="http://secunia.com/advisories/20163" source="SECUNIA">20163</ref>
      <ref url="http://secunia.com/advisories/20162" source="SECUNIA">20162</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10918" source="OVAL">oval:org.mitre.oval:def:10918</ref>
      <ref url="http://archives.neohapsis.com/archives/linux/owl/2004-q2/0038.html" source="MLIST" adv="1">[owl-users] 20040619 Linux 2.4.26-ow2</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/20040804-01-U.asc" source="SGI">20040804-01-U</ref>
    </refs>
    <vuln_soft>
      <prod vendor="linux" name="linux_kernel">
        <vers prev="1" num="2.4.25" edition=""/>
        <vers prev="1" num="2.4.25" edition=":ia64"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0448" published="2004-12-06" name="CVE-2004-0448" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Format string vulnerability in the log function for jftpgw 0.13.4 and earlier allows remote authenticated users to execute arbitrary code via format string specifiers in certain syslog messages.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <vuln_types>
      <input/>
      <design/>
      <exception/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/16271" source="XF" patch="1" adv="1">jftpgw-log-format-string(16271)</ref>
      <ref url="http://www.securityfocus.com/bid/10438" source="BID" patch="1" adv="1">10438</ref>
      <ref url="http://www.debian.org/security/2004/dsa-510" source="DEBIAN" patch="1" adv="1">DSA-510</ref>
    </refs>
    <vuln_soft>
      <prod vendor="jftpgw" name="jftpgw">
        <vers num="0.13"/>
        <vers num="0.13.1"/>
        <vers num="0.13.2"/>
        <vers num="0.13.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0450" published="2004-08-06" name="CVE-2004-0450" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Format string vulnerability in the printlog function in log2mail before 0.2.5.2 allows local users or remote attackers to execute arbitrary code via format string specifiers in a logfile monitored by log2mail.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1" admin="1"/>
    </loss_types>
    <vuln_types>
      <design/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/10460" source="BID" patch="1" adv="1">10460</ref>
      <ref url="http://www.debian.org/security/2004/dsa-513" source="DEBIAN" patch="1" adv="1">DSA-513</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/16311" source="XF">log2mail-syslog-format-string(16311)</ref>
      <ref url="http://secunia.com/advisories/11769" source="SECUNIA">11769</ref>
      <ref url="http://secunia.com/advisories/11768" source="SECUNIA">11768</ref>
      <ref url="http://osvdb.org/6711" source="OSVDB">6711</ref>
      <ref url="http://felinemenace.org/~jaguar/advisories/log2mail.txt" source="MISC">http://felinemenace.org/~jaguar/advisories/log2mail.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="log2mail" name="log2mail">
        <vers num="0.2.2.2"/>
        <vers num="0.2.5.0"/>
        <vers num="0.2.5.1"/>
        <vers num="0.2.5.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0451" published="2004-12-06" name="CVE-2004-0451" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Multiple format string vulnerabilities in the (1) logquit, (2) logerr, or (3) loginfo functions in Software Upgrade Protocol (SUP) allows remote attackers to execute arbitrary code via format string specifiers in messages that are logged by syslog.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <vuln_types>
      <input/>
      <exception/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/16459" source="XF" patch="1" adv="1">sup-format-string(16459)</ref>
      <ref url="http://www.securityfocus.com/bid/10571" source="BID" patch="1" adv="1">10571</ref>
      <ref url="http://www.debian.org/security/2004/dsa-521" source="DEBIAN" patch="1" adv="1">DSA-521</ref>
      <ref url="http://securitytracker.com/id?1010539" source="SECTRACK">1010539</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sup" name="sup">
        <vers num="1.8"/>
      </prod>
      <prod vendor="debian" name="debian_linux">
        <vers num="3.0" edition=""/>
        <vers num="3.0" edition=":hppa"/>
        <vers num="3.0" edition=":mips"/>
        <vers num="3.0" edition=":ia-32"/>
        <vers num="3.0" edition=":m68k"/>
        <vers num="3.0" edition=":s-390"/>
        <vers num="3.0" edition=":alpha"/>
        <vers num="3.0" edition=":arm"/>
        <vers num="3.0" edition=":ia-64"/>
        <vers num="3.0" edition=":mipsel"/>
        <vers num="3.0" edition=":sparc"/>
        <vers num="3.0" edition=":ppc"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2004-0452" published="2004-12-21" name="CVE-2004-0452" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:H/Au:N/C:N/I:P/A:P)" CVSS_score="2.6" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="1.9" CVSS_base_score="2.6">
    <desc>
      <descript source="cve">Race condition in the rmtree function in the File::Path module in Perl 5.6.1 and 5.8.4 sets read/write permissions for the world, which allows local users to delete arbitrary files and directories, and possibly read files and directories, via a symlink attack.</descript>
    </desc>
    <loss_types>
      <avail/>
      <int/>
    </loss_types>
    <vuln_types>
      <race/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-103.html" source="REDHAT" patch="1" adv="1">RHSA-2005:103</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200501-38.xml" source="GENTOO" patch="1" adv="1">GLSA-200501-38</ref>
      <ref url="http://www.debian.org/security/2004/dsa-620" source="DEBIAN" patch="1" adv="1">DSA-620</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110547693019788&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20050111 [OpenPKG-SA-2005.001] OpenPKG Security Advisory (perl)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/18650" source="XF">perl-filepathrmtree-insecure-permissions(18650)</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9938" source="OVAL">oval:org.mitre.oval:def:9938</ref>
      <ref url="http://marc.free.net.ph/message/20041221.102713.5d5e603a.html" source="UBUNTU" adv="1">USN-44-1</ref>
      <ref url="http://www.securityfocus.com/bid/12072" source="BID">12072</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-105.html" source="REDHAT">RHSA-2005:105</ref>
      <ref url="http://secunia.com/advisories/18517" source="SECUNIA">18517</ref>
      <ref url="http://secunia.com/advisories/12991" source="SECUNIA">12991</ref>
      <ref url="http://fedoranews.org/updates/FEDORA--.shtml" source="FEDORA">FLSA-2006:152845</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/20060101-01-U" source="SGI">20060101-01-U</ref>
    </refs>
    <vuln_soft>
      <prod vendor="larry_wall" name="perl">
        <vers num="5.6.1"/>
        <vers num="5.8.4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0453" published="2004-08-06" name="CVE-2004-0453" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Format string vulnerability in the monitor "memory dump" command in VICE 1.6 to 1.14 allows local users to cause a denial of service (emulator crash) and possibly execute arbitrary code via format string specifiers in an output string.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1" admin="1"/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/10543" source="BID" patch="1" adv="1">10543</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/16404" source="XF" adv="1">vice-memory-dump-format-string(16404)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108723630730487&amp;w=2" source="BUGTRAQ" adv="1">20040614 VICE emulator format string vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="vice" name="vice">
        <vers num="1.13"/>
        <vers num="1.14"/>
        <vers num="1.6"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0454" published="2004-12-06" name="CVE-2004-0454" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Buffer overflow in the msg function for rlpr daemon (rlprd) 2.04 allows local users to execute arbitrary code.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <vuln_types>
      <input buffer="1"/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/16454" source="XF" patch="1" adv="1">rlpr-msg-bo(16454)</ref>
      <ref url="http://www.securityfocus.com/bid/10578" source="BID" patch="1" adv="1">10578</ref>
      <ref url="http://www.debian.org/security/2004/dsa-524" source="DEBIAN" patch="1" adv="1">DSA-524</ref>
    </refs>
    <vuln_soft>
      <prod vendor="rlpr" name="rlpr">
        <vers num="2.0"/>
        <vers num="2.0.1"/>
        <vers num="2.0.2"/>
        <vers num="2.0.3"/>
        <vers num="2.0.4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0455" published="2004-12-06" name="CVE-2004-0455" modified="2005-10-20" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Buffer overflow in cgi.c in www-sql before 0.5.7 allows local users to execute arbitrary code via a web page that is processed by www-sql.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/16455" source="XF">wwwsql-cgi-command-execution(16455)</ref>
      <ref url="http://www.securityfocus.com/bid/10577" source="BID">10577</ref>
      <ref url="http://www.debian.org/security/2004/dsa-523" source="DEBIAN">DSA-523</ref>
    </refs>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0456" published="2004-12-06" name="CVE-2004-0456" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:H/Au:N/C:C/I:C/A:C)" CVSS_score="7.6" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="4.9" CVSS_base_score="7.6">
    <desc>
      <descript source="cve">Stack-based buffer overflow in pavuk 0.9pl28, 0.9pl27, and possibly other versions allows remote web sites to execute arbitrary code via a long HTTP Location header.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <vuln_types>
      <input buffer="1"/>
    </vuln_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/16551" source="XF" patch="1" adv="1">pavuk-location-bo(16551)</ref>
      <ref url="http://www.securityfocus.com/bid/10633" source="BID" patch="1" adv="1">10633</ref>
      <ref url="http://www.debian.org/security/2004/dsa-527" source="DEBIAN" patch="1" adv="1">DSA-527</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200406-22.xml" source="GENTOO" patch="1" adv="1">GLSA-200406-22</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2004-July/023322.html" source="FULLDISC">20040702 pavuk buffer overflow</ref>
    </refs>
    <vuln_soft>
      <prod vendor="pavuk" name="pavuk">
        <vers num="0.928r1"/>
        <vers num="0.9pl28i"/>
      </prod>
      <prod vendor="debian" name="debian_linux">
        <vers num="3.0" edition=""/>
        <vers num="3.0" edition=":hppa"/>
        <vers num="3.0" edition=":mips"/>
        <vers num="3.0" edition=":ia-32"/>
        <vers num="3.0" edition=":m68k"/>
        <vers num="3.0" edition=":s-390"/>
        <vers num="3.0" edition=":alpha"/>
        <vers num="3.0" edition=":arm"/>
        <vers num="3.0" edition=":ia-64"/>
        <vers num="3.0" edition=":mipsel"/>
        <vers num="3.0" edition=":sparc"/>
        <vers num="3.0" edition=":ppc"/>
      </prod>
      <prod vendor="gentoo" name="linux">
        <vers num="1.1a"/>
        <vers num="1.2"/>
        <vers num="1.4" edition="rc1"/>
        <vers num="1.4" edition="rc2"/>
        <vers num="1.4" edition="rc3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0457" published="2004-09-28" name="CVE-2004-0457" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">The mysqlhotcopy script in mysql 4.0.20 and earlier, when using the scp method from the mysql-server package, allows local users to overwrite arbitrary files via a symlink attack on temporary files.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <vuln_types>
      <design/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/17030" source="XF" patch="1" adv="1">mysql-mysqlhotcopy-insecure-file(17030)</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-597.html" source="REDHAT" patch="1" adv="1">RHSA-2004:597</ref>
      <ref url="http://www.debian.org/security/2004/dsa-540" source="DEBIAN" patch="1" adv="1">DSA-540</ref>
      <ref url="http://www.ciac.org/ciac/bulletins/p-018.shtml" source="CIAC">P-018</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10693" source="OVAL">oval:org.mitre.oval:def:10693</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mysql" name="mysql">
        <vers prev="1" num="4.0.20"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0458" published="2004-09-28" name="CVE-2004-0458" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">mah-jong before 1.6.2 allows remote attackers to cause a denial of service (server crash) via a missing argument, which triggers a null pointer dereference.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <vuln_types>
      <input/>
      <design/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/16143" source="XF" patch="1" adv="1">mah-jong-null-dos(16143)</ref>
      <ref url="http://www.securityfocus.com/bid/10343" source="BID" patch="1" adv="1">10343</ref>
      <ref url="http://www.debian.org/security/2004/dsa-503" source="DEBIAN" patch="1" adv="1">DSA-503</ref>
    </refs>
    <vuln_soft>
      <prod vendor="nicolas_boullis" name="mah-jong">
        <vers num="1.4"/>
        <vers num="1.6"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0459" published="2004-07-07" name="CVE-2004-0459" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The Clear Channel Assessment (CCA) algorithm in the IEEE 802.11 wireless protocol, when using DSSS transmission encoding, allows remote attackers to cause a denial of service via a certain RF signal that causes a channel to appear busy (aka "jabber"), which prevents devices from transmitting data.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <vuln_types>
      <exception/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/106678" source="CERT-VN" adv="1">VU#106678</ref>
      <ref url="http://www.auscert.org.au/render.html?it=4091" source="AUSCERT" adv="1">AA-2004.02</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/16138" source="XF">ieee80211-cca-dos(16138)</ref>
      <ref url="http://www.securityfocus.com/bid/10342" source="BID">10342</ref>
      <ref url="http://www.osvdb.org/16034" source="OSVDB">16034</ref>
      <ref url="http://support.avaya.com/elmodocs2/security/ASA-2004-009.pdf" source="MISC">http://support.avaya.com/elmodocs2/security/ASA-2004-009.pdf</ref>
      <ref url="http://securitytracker.com/id?1010152" source="SECTRACK">1010152</ref>
      <ref url="http://archives.neohapsis.com/archives/fulldisclosure/2004-05/0631.html" source="FULLDISC">20040513 802.11b (others) single packet DoS</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ieee" name="802.11_wireless_protocol">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0460" published="2004-08-06" name="CVE-2004-0460" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Buffer overflow in the logging capability for the DHCP daemon (DHCPD) for ISC DHCP 3.0.1rc12 and 3.0.1rc13 allows remote attackers to cause a denial of service (server crash) and possibly execute arbitrary code via multiple hostname options in (1) DISCOVER, (2) OFFER, (3) REQUEST, (4) ACK, or (5) NAK messages, which can generate a long string when writing to a log file.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1" admin="1"/>
    </loss_types>
    <vuln_types>
      <input buffer="1"/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA04-174A.html" source="CERT" adv="1">TA04-174A</ref>
      <ref url="http://www.kb.cert.org/vuls/id/317350" source="CERT-VN">VU#317350</ref>
      <ref url="http://www.securityfocus.com/bid/10590" source="BID" patch="1" adv="1">10590</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/16475" source="XF" adv="1">dhcp-ascii-log-bo(16475)</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2004_19_dhcp_server.html" source="SUSE">SuSE-SA:2004:019</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108843959502356&amp;w=2" source="BUGTRAQ" adv="1">20040628 ISC DHCP overflows</ref>
      <ref url="http://www.xerox.com/downloads/usa/en/c/cert_XRX06_004_v11.pdf" source="CONFIRM">http://www.xerox.com/downloads/usa/en/c/cert_XRX06_004_v11.pdf</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2004:061" source="MANDRAKE">MDKSA-2004:061</ref>
      <ref url="http://secunia.com/advisories/23265" source="SECUNIA">23265</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108938625206063&amp;w=2" source="BUGTRAQ">20040708 [OpenPKG-SA-2004.031] OpenPKG Security Advisory (dhcpd)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108795911203342&amp;w=2" source="BUGTRAQ">20040622 DHCP Vuln // no code 0day //</ref>
    </refs>
    <vuln_soft>
      <prod vendor="isc" name="dhcpd">
        <vers num="3.0.1" edition="rc12"/>
        <vers num="3.0.1" edition="rc13"/>
      </prod>
      <prod vendor="suse" name="suse_email_server">
        <vers num="iii"/>
      </prod>
      <prod vendor="suse" name="suse_linux_admin-cd_for_firewall">
        <vers num=""/>
      </prod>
      <prod vendor="suse" name="suse_linux_connectivity_server">
        <vers num=""/>
      </prod>
      <prod vendor="suse" name="suse_linux_database_server">
        <vers num=""/>
      </prod>
      <prod vendor="suse" name="suse_linux_firewall_cd">
        <vers num=""/>
      </prod>
      <prod vendor="suse" name="suse_linux_office_server">
        <vers num=""/>
      </prod>
      <prod vendor="infoblox" name="dns_one_appliance">
        <vers num="2.3.1_r5"/>
        <vers num="2.4.0.8"/>
        <vers num="2.4.0.8a"/>
      </prod>
      <prod vendor="mandrakesoft" name="mandrake_linux">
        <vers num="10.0" edition=""/>
        <vers num="10.0" edition=":amd64"/>
        <vers num="9.0"/>
        <vers num="9.1" edition=""/>
        <vers num="9.1" edition=":ppc"/>
        <vers num="9.2" edition=""/>
        <vers num="9.2" edition=":amd64"/>
      </prod>
      <prod vendor="redhat" name="fedora_core">
        <vers num="core_2.0"/>
      </prod>
      <prod vendor="suse" name="suse_linux">
        <vers num="7" edition=""/>
        <vers num="7" edition=":enterprise_server"/>
        <vers num="8" edition=""/>
        <vers num="8" edition=":enterprise_server"/>
        <vers num="8.0" edition=""/>
        <vers num="8.0" edition=":i386"/>
        <vers num="8.1"/>
        <vers num="8.2"/>
        <vers num="9.0" edition=""/>
        <vers num="9.0" edition=":x86_64"/>
        <vers num="9.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0461" published="2004-08-06" name="CVE-2004-0461" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">The DHCP daemon (DHCPD) for ISC DHCP 3.0.1rc12 and 3.0.1rc13, when compiled in environments that do not provide the vsnprintf function, uses C include files that define vsnprintf to use the less safe vsprintf function, which can lead to buffer overflow vulnerabilities that enable a denial of service (server crash) and possibly execute arbitrary code.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1" admin="1"/>
    </loss_types>
    <vuln_types>
      <input buffer="1"/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA04-174A.html" source="CERT" adv="1">TA04-174A</ref>
      <ref url="http://www.kb.cert.org/vuls/id/654390" source="CERT-VN">VU#654390</ref>
      <ref url="http://www.securityfocus.com/bid/10591" source="BID" patch="1" adv="1">10591</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/16476" source="XF" adv="1">dhcp-c-include-bo(16476)</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2004_19_dhcp_server.html" source="SUSE">SuSE-SA:2004:019</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108843959502356&amp;w=2" source="BUGTRAQ" adv="1">20040628 ISC DHCP overflows</ref>
      <ref url="http://www.xerox.com/downloads/usa/en/c/cert_XRX06_004_v11.pdf" source="CONFIRM">http://www.xerox.com/downloads/usa/en/c/cert_XRX06_004_v11.pdf</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2004:061" source="MANDRAKE">MDKSA-2004:061</ref>
      <ref url="http://secunia.com/advisories/23265" source="SECUNIA">23265</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108938625206063&amp;w=2" source="BUGTRAQ">20040708 [OpenPKG-SA-2004.031] OpenPKG Security Advisory (dhcpd)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108795911203342&amp;w=2" source="BUGTRAQ">20040622 DHCP Vuln // no code 0day //</ref>
    </refs>
    <vuln_soft>
      <prod vendor="isc" name="dhcpd">
        <vers num="3.0.1" edition="rc12"/>
        <vers num="3.0.1" edition="rc13"/>
      </prod>
      <prod vendor="suse" name="suse_email_server">
        <vers num="iii"/>
      </prod>
      <prod vendor="suse" name="suse_linux_admin-cd_for_firewall">
        <vers num=""/>
      </prod>
      <prod vendor="suse" name="suse_linux_connectivity_server">
        <vers num=""/>
      </prod>
      <prod vendor="suse" name="suse_linux_database_server">
        <vers num=""/>
      </prod>
      <prod vendor="suse" name="suse_linux_firewall_cd">
        <vers num=""/>
      </prod>
      <prod vendor="suse" name="suse_linux_office_server">
        <vers num=""/>
      </prod>
      <prod vendor="infoblox" name="dns_one_appliance">
        <vers num="2.3.1_r5"/>
        <vers num="2.4.0.8"/>
        <vers num="2.4.0.8a"/>
      </prod>
      <prod vendor="mandrakesoft" name="mandrake_linux">
        <vers num="10.0" edition=""/>
        <vers num="10.0" edition=":amd64"/>
        <vers num="9.0"/>
        <vers num="9.1" edition=""/>
        <vers num="9.1" edition=":ppc"/>
        <vers num="9.2" edition=""/>
        <vers num="9.2" edition=":amd64"/>
      </prod>
      <prod vendor="redhat" name="fedora_core">
        <vers num="core_2.0"/>
      </prod>
      <prod vendor="suse" name="suse_linux">
        <vers num="7" edition=""/>
        <vers num="7" edition=":enterprise_server"/>
        <vers num="8" edition=""/>
        <vers num="8" edition=":enterprise_server"/>
        <vers num="8.0" edition=""/>
        <vers num="8.0" edition=":i386"/>
        <vers num="8.1"/>
        <vers num="8.2"/>
        <vers num="9.0" edition=""/>
        <vers num="9.0" edition=":x86_64"/>
        <vers num="9.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2004-0462" published="2004-12-31" name="CVE-2004-0462" modified="2005-10-20" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">The built-in web servers for multiple networking devices do not set the Secure attribute for sensitive cookies in HTTPS sessions, which could cause the user agent to send those cookies in plaintext over an HTTP session with the same server.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <vuln_types>
      <design/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/546483" source="CERT-VN" adv="1">VU#546483</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/17702" source="XF">network-device-secure-plaintext(17702)</ref>
    </refs>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0465" published="2004-12-31" name="CVE-2004-0465" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in jretest.html in WebConnect 6.5 and 6.4.4, and possibly earlier versions, allows remote attackers to read keys within arbitrary INI formatted files via "..//" sequences in the WCP_USER parameter.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/JSHA-69HVPK" source="CONFIRM" adv="1">http://www.kb.cert.org/vuls/id/JSHA-69HVPK</ref>
      <ref url="http://www.kb.cert.org/vuls/id/628411" source="CERT-VN" adv="1">VU#628411</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/19394" source="XF" patch="1">webconnect-wcpuser-directory-traversal(19394)</ref>
      <ref url="http://www.cirt.dk/advisories/cirt-29-advisory.pdf" source="MISC" patch="1" adv="1">http://www.cirt.dk/advisories/cirt-29-advisory.pdf</ref>
      <ref url="http://secunia.com/advisories/14006/" source="SECUNIA" patch="1">14006</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110910838600145&amp;w=2" source="BUGTRAQ" adv="1">20050220 The WebConnect 6.4.4 and 6.5 contains several vulnerabilities</ref>
    </refs>
    <vuln_soft>
      <prod vendor="openconnect" name="webconnect">
        <vers num="6.4.4"/>
        <vers num="6.5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0466" published="2004-02-21" name="CVE-2004-0466" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">WebConnect 6.5, 6.4.4, and possibly earlier versions allows remote attackers to cause a denial of service (hang) via a URL containing an MS-DOS device name such as (1) AUX, (2) CON, (3) PRN, (4) COM1, or (5) LPT1.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/JSHA-69FVMM" source="CONFIRM" patch="1" adv="1">http://www.kb.cert.org/vuls/id/JSHA-69FVMM</ref>
      <ref url="http://www.kb.cert.org/vuls/id/552561" source="CERT-VN" patch="1" adv="1">VU#552561</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/19393" source="XF" patch="1" adv="1">webconnect-device-name-dos(19393)</ref>
      <ref url="http://secunia.com/advisories/14006/" source="SECUNIA" patch="1" adv="1">14006</ref>
      <ref url="http://www.cirt.dk/advisories/cirt-29-advisory.pdf" source="MISC" adv="1">http://www.cirt.dk/advisories/cirt-29-advisory.pdf</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110910838600145&amp;w=2" source="BUGTRAQ" adv="1">20050220 The WebConnect 6.4.4 and 6.5 contains several vulnerabilities</ref>
    </refs>
    <vuln_soft>
      <prod vendor="openconnect" name="webconnect">
        <vers num="6.4.4"/>
        <vers num="6.5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0467" published="2004-12-31" name="CVE-2004-0467" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Juniper JUNOS 5.x through JUNOS 7.x allows remote attackers to cause a denial of service (routing disabled) via a large number of MPLS packets, which are not filtered or verified before being sent to the Routing Engine, which reduces the speed at which other packets are processed.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/JSHA-68ZJCQ" source="CONFIRM" patch="1" adv="1">http://www.kb.cert.org/vuls/id/JSHA-68ZJCQ</ref>
      <ref url="http://www.kb.cert.org/vuls/id/409555" source="CERT-VN" patch="1" adv="1">VU#409555</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/19094" source="XF" patch="1">junos-dos(19094)</ref>
      <ref url="http://www.securityfocus.com/bid/12379" source="BID" patch="1">12379</ref>
      <ref url="http://www.niscc.gov.uk/niscc/docs/al-20050126-00067.html?lang=en" source="MISC" patch="1" adv="1">http://www.niscc.gov.uk/niscc/docs/al-20050126-00067.html?lang=en</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-081.html" source="REDHAT">RHSA-2005:081</ref>
      <ref url="http://securitytracker.com/id?1013039" source="SECTRACK">1013039</ref>
      <ref url="http://secunia.com/advisories/14049" source="SECUNIA">14049</ref>
    </refs>
    <vuln_soft>
      <prod vendor="juniper" name="junos">
        <vers num="5.0"/>
        <vers num="5.1"/>
        <vers num="5.2"/>
        <vers num="5.3"/>
        <vers num="5.4"/>
        <vers num="5.5"/>
        <vers num="5.6"/>
        <vers num="5.7"/>
        <vers num="6.1"/>
        <vers num="6.2"/>
        <vers num="6.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0468" published="2004-12-06" name="CVE-2004-0468" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Memory leak in Juniper JUNOS Packet Forwarding Engine (PFE) allows remote attackers to cause a denial of service (memory exhaustion and device reboot) via certain IPv6 packets.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <vuln_types>
      <design/>
      <exception/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/658859" source="CERT-VN" patch="1" adv="1">VU#658859</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/16548" source="XF" patch="1" adv="1">juniper-ipv6-dos(16548)</ref>
      <ref url="http://www.kb.cert.org/vuls/id/JSHA-6253CC" source="CONFIRM" patch="1" adv="1">http://www.kb.cert.org/vuls/id/JSHA-6253CC</ref>
      <ref url="http://www.jpcert.or.jp/at/2004/at040009.txt" source="MISC" patch="1" adv="1">http://www.jpcert.or.jp/at/2004/at040009.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="juniper" name="junos">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0469" published="2004-07-07" name="CVE-2004-0469" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Buffer overflow in the ISAKMP functionality for Check Point VPN-1 and FireWall-1 NG products, before VPN-1/FireWall-1 R55 HFA-03, R54 HFA-410 and NG FP3 HFA-325, or VPN-1 SecuRemote/SecureClient R56, may allow remote attackers to execute arbitrary code during VPN tunnel negotiation.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1" other="1" admin="1"/>
    </loss_types>
    <vuln_types>
      <input buffer="1"/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/16060" source="XF" patch="1" adv="1">vpn1-isakmp-bo(16060)</ref>
      <ref url="http://www.securityfocus.com/bid/10273" source="BID" patch="1" adv="1">10273</ref>
      <ref url="http://www.checkpoint.com/techsupport/alerts/ike_vpn.html" source="CHECKPOINT" patch="1" adv="1">20040504 ISAKMP Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="checkpoint" name="firewall-1">
        <vers num="" edition=":vsx-ng-ai"/>
        <vers num="2.0" edition=""/>
        <vers num="2.0" edition=":gx"/>
        <vers num="2.0.1" edition=""/>
        <vers num="2.0.1" edition=":vsx"/>
      </prod>
      <prod vendor="checkpoint" name="next_generation">
        <vers num="" edition=":fp3"/>
      </prod>
      <prod vendor="checkpoint" name="ng-ai">
        <vers num="r54"/>
        <vers num="r55"/>
      </prod>
      <prod vendor="checkpoint" name="vpn-1">
        <vers num="vsx_2.0.1"/>
        <vers num="vsx_ng_with_application_intelligence"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0470" published="2004-07-07" name="CVE-2004-0470" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">BEA WebLogic Server and WebLogic Express 7.0 through SP5 and 8.1 through SP2, when editing weblogic.xml using WebLogic Builder or the SecurityRoleAssignmentMBean.toXML method, inadvertently removes security-role-assignment tags when weblogic.xml does not have a principal-name tag, which can remove intended access restrictions for the associated web application.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <design/>
      <exception/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/950070" source="CERT-VN" adv="1">VU#950070</ref>
      <ref url="http://dev2dev.bea.com/resourcelibrary/advisoriesnotifications/BEA04_59.00.jsp" source="CONFIRM" patch="1" adv="1">http://dev2dev.bea.com/resourcelibrary/advisoriesnotifications/BEA04_59.00.jsp</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/16123" source="XF">weblogic-application-unauth-access(16123)</ref>
      <ref url="http://www.securityfocus.com/bid/10328" source="BID">10328</ref>
      <ref url="http://www.osvdb.org/6076" source="OSVDB">6076</ref>
      <ref url="http://securitytracker.com/id?1010128" source="SECTRACK">1010128</ref>
      <ref url="http://secunia.com/advisories/11593" source="SECUNIA">11593</ref>
    </refs>
    <vuln_soft>
      <prod vendor="bea" name="weblogic_server">
        <vers num="7.0" edition=""/>
        <vers num="7.0" edition=":express"/>
        <vers num="8.1" edition=""/>
        <vers num="8.1" edition=":express"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2004-0471" published="2004-07-07" name="CVE-2004-0471" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">BEA WebLogic Server and WebLogic Express 7.0 through SP5 and 8.1 through SP2 does not enforce site restrictions for starting and stopping servers for users in the Admin and Operator security roles, which allows unauthorized users to cause a denial of service (service shutdown).</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <vuln_types>
      <design/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://dev2dev.bea.com/resourcelibrary/advisoriesnotifications/BEA04_60.00.jsp" source="CONFIRM" patch="1" adv="1">http://dev2dev.bea.com/resourcelibrary/advisoriesnotifications/BEA04_60.00.jsp</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/16121" source="XF">weblogic-server-policy-bypass(16121)</ref>
      <ref url="http://www.securityfocus.com/bid/10327" source="BID">10327</ref>
      <ref url="http://www.osvdb.org/6077" source="OSVDB">6077</ref>
      <ref url="http://securitytracker.com/id?1010129" source="SECTRACK">1010129</ref>
      <ref url="http://secunia.com/advisories/11594" source="SECUNIA">11594</ref>
    </refs>
    <vuln_soft>
      <prod vendor="bea" name="weblogic_server">
        <vers num="7.0" edition=""/>
        <vers num="7.0" edition=":express"/>
        <vers num="8.1" edition=""/>
        <vers num="8.1" edition=":express"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" seq="2004-0472" reject="1" published="2004-07-07" name="CVE-2004-0472" modified="2008-09-10">
    <desc>
      <descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: none.  Reason: This candidate is a reservation duplicate of CVE-2004-0434.  Notes: All CVE users should reference CVE-2004-0434 instead of this candidate.  All references and descriptions in this candidate have been removed to prevent accidental usage.</descript>
    </desc>
    <refs/>
  </entry>
  <entry type="CVE" severity="Low" seq="2004-0473" published="2004-07-07" name="CVE-2004-0473" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:P/A:N)" CVSS_score="2.6" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="4.9" CVSS_base_score="2.6">
    <desc>
      <descript source="cve">Argument injection vulnerability in Opera before 7.50 does not properly filter "-" characters that begin a hostname in a telnet URI, which allows remote attackers to insert options to the resulting command line and overwrite arbitrary files via (1) the "-f" option on Windows XP or (2) the "-n" option on Linux.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <vuln_types>
      <input/>
      <exception/>
    </vuln_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.opera.com/linux/changelogs/750/index.dml" source="CONFIRM">http://www.opera.com/linux/changelogs/750/index.dml</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200405-19.xml" source="GENTOO">GLSA-200405-19</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/16139" source="XF">opera-telnet-file-overwrite(16139)</ref>
      <ref url="http://www.securityfocus.com/bid/10341" source="BID">10341</ref>
      <ref url="http://www.idefense.com/application/poi/display?id=104&amp;type=vulnerabilities" source="IDEFENSE">20040512 Opera Telnet URI Handler File Creation/Truncation Vulnerability</ref>
      <ref url="http://securitytracker.com/id?1010142" source="SECTRACK">1010142</ref>
    </refs>
    <vuln_soft>
      <prod vendor="opera_software" name="opera_web_browser">
        <vers num="9.10"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0474" published="2004-07-07" name="CVE-2004-0474" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_score="5.1" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="4.9" CVSS_base_score="5.1">
    <desc>
      <descript source="cve">Help Center (HelpCtr.exe) may allow remote attackers to read or execute arbitrary files via an "http://" or "file://" argument to the topic parameter in an hcp:// URL.  NOTE: since the initial report of this problem, several researchers have been unable to reproduce this issue.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <exception/>
    </vuln_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/15101" source="XF" adv="1">winxp-helpctr-hcp-xss(15101)</ref>
      <ref url="http://www.securityfocus.com/bid/9621" source="BID" adv="1">9621</ref>
      <ref url="http://www.securityfocus.com/archive/1/353248" source="BUGTRAQ">20040207 HelpCtr - allow open any page or run</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=107652584102003&amp;w=2" source="BUGTRAQ" adv="1">20040211 Re: HelpCtr - allow open any page or run</ref>
      <ref url="http://archives.neohapsis.com/archives/fulldisclosure/2004-02/0688.html" source="FULLDISC">20040213 Re: HelpCtr - allow open any page or run</ref>
      <ref url="http://archives.neohapsis.com/archives/fulldisclosure/2004-02/0450.html" source="FULLDISC">20040210 Re: HelpCtr - allow open any page or run</ref>
      <ref url="http://archives.neohapsis.com/archives/fulldisclosure/2004-02/0440.html" source="FULLDISC" adv="1">20040210 Re: HelpCtr - allow open any page or run</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_xp">
        <vers num="" edition=":home"/>
        <vers num="" edition="gold"/>
        <vers num="" edition="gold:professional"/>
        <vers num="" edition="sp1"/>
        <vers num="" edition="sp1:home"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0475" published="2004-07-07" name="CVE-2004-0475" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_score="5.1" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="4.9" CVSS_base_score="5.1">
    <desc>
      <descript source="cve">The showHelp function in Internet Explorer 6 on Windows XP Pro allows remote attackers to execute arbitrary local .CHM files via a double backward slash ("\\") before the target CHM file, as demonstrated using an "ms-its" URL to ntshared.chm.  NOTE: this bug may overlap CVE-2003-1041.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <exception/>
    </vuln_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/16147" source="XF" adv="1">ie-showhelp-chm-execution(16147)</ref>
      <ref url="http://www.securityfocus.com/bid/10348" source="BID" adv="1">10348</ref>
      <ref url="http://www.securityfocus.com/archive/1/363202" source="BUGTRAQ" adv="1">20040513 Showhelp() local CHM file execution</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="ie">
        <vers num="6.0" edition="sp1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0476" published="2004-08-18" name="CVE-2004-0476" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Buffer overflow in 3Com OfficeConnect Remote 812 ADSL Router 1.1.9.4 allows remote attackers to cause a denial of service (reboot or packet loss) via a long string containing Telnet escape characters to the Telnet port.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <vuln_types>
      <input buffer="1"/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/10419" source="BID" adv="1">10419</ref>
      <ref url="http://www.idefense.com/application/poi/display?id=105&amp;type=vulnerabilities" source="IDEFENSE" adv="1">20040526 OfficeConnect Remote 812 ADSL Router Telnet Protocol DoS Vulnerability</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/16257" source="XF">3com-officeconnect-telnet-bo(16257)</ref>
      <ref url="http://secunia.com/advisories/11716" source="SECUNIA">11716</ref>
    </refs>
    <vuln_soft>
      <prod vendor="3com" name="3cp4144">
        <vers num="1.1.9.4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0477" published="2004-12-06" name="CVE-2004-0477" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Unknown vulnerability in 3Com OfficeConnect Remote 812 ADSL Router allows remote attackers to bypass authentication via repeated attempts using any username and password.  NOTE: this identifier was inadvertently re-used for another issue due to a typo; that issue was assigned CVE-2004-0447.  This candidate is ONLY for the ADSL router bypass.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1" other="1" admin="1"/>
    </loss_types>
    <vuln_types>
      <access/>
      <design/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/10426" source="BID" patch="1" adv="1">10426</ref>
      <ref url="http://www.idefense.com/application/poi/display?id=106&amp;type=vulnerabilities&amp;flashstatus=false" source="IDEFENSE" patch="1" adv="1">20040527 iDEFENSE Security Advisory 05.27.04: 3Com OfficeConnect Remote 812 ADSL Router Authentication Bypass Vulnerability</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/16267" source="XF" adv="1">3com-officeconnect-gain-access(16267)</ref>
      <ref url="http://secunia.com/advisories/11716" source="SECUNIA">11716</ref>
    </refs>
    <vuln_soft>
      <prod vendor="3com" name="3cp4144">
        <vers num="1.1.9.4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2004-0478" published="2004-07-07" name="CVE-2004-0478" modified="2008-09-10" CVSS_version="2.0" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:N/A:P)" CVSS_score="2.6" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="4.9" CVSS_base_score="2.6">
    <desc>
      <descript source="cve">Unknown versions of Mozilla allow remote attackers to cause a denial of service (high CPU/RAM consumption) using Javascript with an infinite loop that continues to add input to a form, possibly as the result of inserting control characters, as demonstrated using an embedded ctrl-U.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <vuln_types>
      <design/>
      <exception/>
    </vuln_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/16225" source="XF">mozilla-javascript-dos(16225)</ref>
      <ref url="http://lists.immunitysec.com/pipermail/dailydave/2004-May/000587.html" source="MLIST" adv="1">[Dailydave] 20040514 Mozilla bug might even get fixed!</ref>
      <ref url="http://bugzilla.mozilla.org/show_bug.cgi?id=243540" source="CONFIRM" adv="1">http://bugzilla.mozilla.org/show_bug.cgi?id=243540</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="mozilla">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0479" published="2004-07-07" name="CVE-2004-0479" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Internet Explorer 6 allows remote attackers to cause a denial of service (crash) via Javascript that creates a new popup window and disables the imagetoolbar functionality with a META tag, which triggers a null dereference.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <vuln_types>
      <design/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=vuln-dev&amp;m=108476938219070&amp;w=2" source="VULN-DEV" adv="1">20040516 Re: IE Crash - Anyone Seen This Before?</ref>
      <ref url="http://marc.theaimsgroup.com/?l=vuln-dev&amp;m=108457938412310&amp;w=2" source="VULN-DEV" adv="1">20040514 IE Crash - Anyone Seen This Before?</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2004-May/021500.html" source="FULLDISC">20040514 IE Crash - Anyone Seen This Before?</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="ie">
        <vers num="6" edition="windows_server_2003_sp1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0480" published="2004-12-06" name="CVE-2004-0480" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Argument injection vulnerability in IBM Lotus Notes 6.0.3 and 6.5 allows remote attackers to execute arbitrary code via a notes: URI that uses a UNC network share pathname to provide an alternate notes.ini configuration file to notes.exe.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1" other="1" admin="1"/>
    </loss_types>
    <vuln_types>
      <input/>
      <config/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/16496" source="XF" patch="1" adv="1">lotus-notes-xss(16496)</ref>
      <ref url="http://www.securityfocus.com/bid/10600" source="BID" patch="1" adv="1">10600</ref>
      <ref url="http://www.idefense.com/application/poi/display?id=111&amp;type=vulnerabilities" source="MISC" patch="1" adv="1">http://www.idefense.com/application/poi/display?id=111&amp;type=vulnerabilities</ref>
      <ref url="http://www-1.ibm.com/support/docview.wss?rs=475/context=SSKTWP&amp;uid=swg21169510" source="CONFIRM" patch="1" adv="1">http://www-1.ibm.com/support/docview.wss?rs=475/context=SSKTWP&amp;uid=swg21169510</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108843896506099&amp;w=2" source="BUGTRAQ" adv="1">20040627 Lotus Notes URL argument injection vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="lotus_notes">
        <vers num="6.0"/>
        <vers num="6.0.1"/>
        <vers num="6.0.2"/>
        <vers num="6.0.3"/>
        <vers num="6.5"/>
        <vers num="6.5.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2004-0481" published="2005-02-23" name="CVE-2004-0481" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">The logging feature in kcms_configure in the KCMS package on Solaris 8 and 9, and possibly other versions, allows local users to corrupt arbitrary files via a symlink attack on the KCS_ClogFile file.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <vuln_types>
      <design/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://www.idefense.com/application/poi/display?id=206&amp;type=vulnerabilities" source="IDEFENSE" patch="1" adv="1">20050223 Sun Solaris kcms_configure Arbitrary File Corruption Vulnerability</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-57706-1" source="SUNALERT" patch="1" adv="1">57706</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="solaris">
        <vers num="8.0" edition=""/>
        <vers num="8.0" edition=":x86"/>
        <vers num="8.1"/>
        <vers num="8.2"/>
        <vers num="9.0" edition=""/>
        <vers num="9.0" edition=":sparc"/>
        <vers num="9.0" edition=":x86"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0482" published="2004-07-07" name="CVE-2004-0482" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Multiple integer overflows in (1) procfs_cmdline.c, (2) procfs_fpregs.c, (3) procfs_linux.c, (4) procfs_regs.c, (5) procfs_status.c, and (6) procfs_subr.c in procfs for OpenBSD 3.5 and earlier allow local users to read sensitive kernel memory and possibly perform other unauthorized activities.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input bound="1"/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=openbsd-security-announce&amp;m=108445767103004&amp;w=2" source="MLIST" patch="1" adv="1">[openbsd-security-announce] 20040513 procfs vulnerability</ref>
      <ref url="ftp://ftp.openbsd.org/pub/OpenBSD/patches/3.5/common/006_procfs.patch" source="CONFIRM" patch="1">ftp://ftp.openbsd.org/pub/OpenBSD/patches/3.5/common/006_procfs.patch</ref>
      <ref url="ftp://ftp.openbsd.org/pub/OpenBSD/patches/3.4/common/020_procfs.patch" source="CONFIRM" patch="1">ftp://ftp.openbsd.org/pub/OpenBSD/patches/3.4/common/020_procfs.patch</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/16226" source="XF">openbsd-procfs-gain-privileges(16226)</ref>
      <ref url="http://www.osvdb.org/6114" source="OSVDB">6114</ref>
      <ref url="http://www.openbsd.org/errata35.html" source="OPENBSD">20040513 [3.5] 006: SECURITY FIX: May 13, 2004</ref>
      <ref url="http://www.openbsd.org/errata34.html" source="OPENBSD">20040513 [3.4] 020: SECURITY FIX: May 13, 2004</ref>
      <ref url="http://www.deprotect.com/advisories/DEPROTECT-20041305.txt" source="MISC">http://www.deprotect.com/advisories/DEPROTECT-20041305.txt</ref>
      <ref url="http://secunia.com/advisories/11605" source="SECUNIA">11605</ref>
      <ref url="http://marc.theaimsgroup.com/?l=full-disclosure&amp;m=108481812926420&amp;w=2" source="FULLDISC">20040517 OpenBSD procfs</ref>
    </refs>
    <vuln_soft>
      <prod vendor="openbsd" name="openbsd">
        <vers num="3.4"/>
        <vers num="3.5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0483" published="2004-07-07" name="CVE-2004-0483" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Unknown vulnerability in rpc.mountd for SGI IRIX 6.5.24 allows remote attackers to cause a denial of service (infinite loop) via certain RPC requests.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/10372" source="BID" patch="1">10372</ref>
      <ref url="http://secunia.com/advisories/11628" source="SECUNIA" patch="1" adv="1">11628</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/16175" source="XF">rpcmountd-rpc-dos(16175)</ref>
      <ref url="http://www.osvdb.org/6201" source="OSVDB">6201</ref>
      <ref url="http://securitytracker.com/id?1010185" source="SECTRACK">1010185</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/20040503-01-P" source="SGI">20040503-01-P</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sgi" name="irix">
        <vers num="6.5.24"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2004-0484" published="2004-07-07" name="CVE-2004-0484" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:N/A:P)" CVSS_score="2.6" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="4.9" CVSS_base_score="2.6">
    <desc>
      <descript source="cve">mshtml.dll in Microsoft Internet Explorer 6.0.2800 allows remote attackers to cause a denial of service (crash) via a table containing a form that crosses multiple td elements, and whose "float: left" class is defined in a link to a CSS stylesheet after the end of the table, which may trigger a null dereference.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <vuln_types>
      <design/>
    </vuln_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/16189" source="XF">ie-css-dos(16189)</ref>
      <ref url="http://www.securityfocus.com/bid/10382" source="BID">10382</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108490218632590&amp;w=2" source="BUGTRAQ" adv="1">20040518 Unknown IE bug with css-styles</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="ie">
        <vers num="6.0.2900"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0485" published="2004-07-07" name="CVE-2004-0485" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The default protocol helper for the disk: URI on Mac OS X 10.3.3 and 10.2.8 allows remote attackers to write arbitrary files by causing a disk image file (.dmg) to be mounted as a disk volume.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <vuln_types>
      <design/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/210606" source="CERT-VN" patch="1" adv="1">VU#210606</ref>
      <ref url="http://secunia.com/advisories/11622/" source="SECUNIA" patch="1" adv="1">11622</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/16166" source="XF" adv="1">macos-runscript-code-execution(16166)</ref>
      <ref url="http://lists.apple.com/mhonarc/security-announce/msg00053.html" source="APPLE">APPLE-SA-2004-05-21</ref>
      <ref url="http://fundisom.com/owned/warning" source="MISC" adv="1">http://fundisom.com/owned/warning</ref>
      <ref url="http://lists.seifried.org/pipermail/security/2004-May/003743.html" source="APPLE">APPLE-SA-2004-05-28</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.2.8"/>
        <vers num="10.3.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0486" published="2004-07-07" name="CVE-2004-0486" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:H/Au:N/C:C/I:C/A:C)" CVSS_score="7.6" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="4.9" CVSS_base_score="7.6">
    <desc>
      <descript source="cve">HelpViewer in Mac OS X 10.3.3 and 10.2.8 processes scripts that it did not initiate, which can allow attackers to execute arbitrary code, an issue that was originally reported as a directory traversal vulnerability in the Safari web browser using the runscript parameter in a help: URI handler.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1" other="1" admin="1"/>
    </loss_types>
    <vuln_types>
      <design/>
    </vuln_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/578798" source="CERT-VN" patch="1" adv="1">VU#578798</ref>
      <ref url="http://www.securityfocus.com/bid/10356" source="BID" patch="1" adv="1">10356</ref>
      <ref url="http://secunia.com/advisories/11622/" source="SECUNIA" patch="1" adv="1">11622</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/16166" source="XF" adv="1">macos-runscript-code-execution(16166)</ref>
      <ref url="http://www.fundisom.com/owned/warning" source="MISC" adv="1">http://www.fundisom.com/owned/warning</ref>
      <ref url="http://lists.apple.com/mhonarc/security-announce/msg00053.html" source="APPLE">APPLE-SA-2004-05-21</ref>
      <ref url="http://www.osvdb.org/6184" source="OSVDB">6184</ref>
      <ref url="http://securitytracker.com/id?1010167" source="SECTRACK">1010167</ref>
      <ref url="http://archives.neohapsis.com/archives/fulldisclosure/2004-05/0837.html" source="FULLDISC">20040516 Vuln. MacOSX/Safari: Remote help-call, execute scripts</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.3"/>
        <vers num="10.3.1"/>
        <vers num="10.3.2"/>
        <vers num="10.3.3"/>
      </prod>
      <prod vendor="apple" name="mac_os_x_server">
        <vers num="10.3"/>
        <vers num="10.3.1"/>
        <vers num="10.3.2"/>
        <vers num="10.3.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0487" published="2004-08-18" name="CVE-2004-0487" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">A certain ActiveX control in Symantec Norton AntiVirus 2004 allows remote attackers to cause a denial of service (resource consumption) and possibly execute arbitrary programs.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1" admin="1"/>
    </loss_types>
    <vuln_types>
      <design/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/312510" source="CERT-VN" adv="1">VU#312510</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/16220" source="XF" adv="1">nav-activex-code-execution(16220)</ref>
      <ref url="http://www.symantec.com/avcenter/security/Content/2004.05.20.html" source="CONFIRM">http://www.symantec.com/avcenter/security/Content/2004.05.20.html</ref>
      <ref url="http://www.securityfocus.com/bid/10392" source="BID" adv="1">10392</ref>
      <ref url="http://www.lac.co.jp/security/csl/intelligence/SNSadvisory_e/72_e.html" source="MISC">http://www.lac.co.jp/security/csl/intelligence/SNSadvisory_e/72_e.html</ref>
      <ref url="http://www.ciac.org/ciac/bulletins/o-149.shtml" source="CIAC">O-149</ref>
      <ref url="http://secunia.com/advisories/11676" source="SECUNIA">11676</ref>
      <ref url="http://www.osvdb.org/6303" source="OSVDB">6303</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108515369718455&amp;w=2" source="BUGTRAQ">20040521 [SNS Advisory No.72] Symantec Norton AntiVirus 2004 ActiveX Control Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="symantec" name="norton_antivirus">
        <vers num="2.1" edition=""/>
        <vers num="2.1" edition=":ms_exchange"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0488" published="2004-07-07" name="CVE-2004-0488" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Stack-based buffer overflow in the ssl_util_uuencode_binary function in ssl_util.c for Apache mod_ssl, when mod_ssl is configured to trust the issuing CA, may allow remote attackers to execute arbitrary code via a client certificate with a long subject DN.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input buffer="1"/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/10355" source="BID" patch="1" adv="1">10355</ref>
      <ref url="https://bugzilla.fedora.us/show_bug.cgi?id=1888" source="FEDORA">FLSA:1888</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/16214" source="XF" adv="1">apache-modssl-uuencode-bo(16214)</ref>
      <ref url="http://www.trustix.net/errata/2004/0031/" source="TRUSTIX">2004-0031</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-405.html" source="REDHAT">RHSA-2004:405</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-342.html" source="REDHAT">RHSA-2004:342</ref>
      <ref url="http://www.debian.org/security/2004/dsa-532" source="DEBIAN">DSA-532</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200406-05.xml" source="GENTOO">GLSA-200406-05</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2004-245.html" source="REDHAT">RHSA-2004:245</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11458" source="OVAL">oval:org.mitre.oval:def:11458</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109215056218824&amp;w=2" source="HP">SSRT4788</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109181600614477&amp;w=2" source="HP">SSRT4777</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108619129727620&amp;w=2" source="BUGTRAQ">20040601 TSSA-2004-008 - apache</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2004-May/021610.html" source="FULLDISC">20040517 mod_ssl ssl_util_uuencode_binary potential problem</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/20040605-01-U.asc" source="SGI">20040605-01-U</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-816.html" source="REDHAT">RHSA-2005:816</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2004:055" source="MANDRAKE">MDKSA-2004:055</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2004:054" source="MANDRAKE">MDKSA-2004:054</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108567431823750&amp;w=2" source="BUGTRAQ">20040527 [OpenPKG-SA-2004.026] OpenPKG Security Advisory (apache)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apache" name="http_server">
        <vers num="1.3"/>
        <vers num="1.3.1"/>
        <vers num="1.3.11"/>
        <vers num="1.3.12"/>
        <vers num="1.3.14"/>
        <vers num="1.3.17"/>
        <vers num="1.3.18"/>
        <vers num="1.3.19"/>
        <vers num="1.3.20"/>
        <vers num="1.3.22"/>
        <vers num="1.3.23"/>
        <vers num="1.3.24"/>
        <vers num="1.3.25"/>
        <vers num="1.3.26"/>
        <vers num="1.3.27"/>
        <vers num="1.3.28"/>
        <vers num="1.3.29"/>
        <vers num="1.3.3"/>
        <vers num="1.3.31"/>
        <vers num="1.3.4"/>
        <vers num="1.3.6"/>
        <vers num="1.3.7" edition=""/>
        <vers num="1.3.7" edition=":dev"/>
        <vers num="1.3.9"/>
        <vers num="2.0"/>
        <vers num="2.0.28" edition="beta"/>
        <vers num="2.0.32"/>
        <vers num="2.0.35"/>
        <vers num="2.0.36"/>
        <vers num="2.0.37"/>
        <vers num="2.0.38"/>
        <vers num="2.0.39"/>
        <vers num="2.0.40"/>
        <vers num="2.0.41"/>
        <vers num="2.0.42"/>
        <vers num="2.0.43"/>
        <vers num="2.0.44"/>
        <vers num="2.0.45"/>
        <vers num="2.0.46"/>
        <vers num="2.0.47"/>
        <vers num="2.0.48"/>
        <vers num="2.0.49"/>
        <vers num="2.0.9"/>
      </prod>
      <prod vendor="mandrakesoft" name="mandrake_multi_network_firewall">
        <vers num="8.2"/>
      </prod>
      <prod vendor="mod_ssl" name="mod_ssl">
        <vers num="2.8.10"/>
        <vers num="2.8.12"/>
        <vers num="2.8.15"/>
        <vers num="2.8.16"/>
        <vers num="2.8.7"/>
      </prod>
      <prod vendor="sgi" name="propack">
        <vers num="2.4"/>
      </prod>
      <prod vendor="tinysofa" name="tinysofa_enterprise_server">
        <vers num="1.0"/>
        <vers num="1.0_u1"/>
      </prod>
      <prod vendor="gentoo" name="linux">
        <vers num="1.4"/>
      </prod>
      <prod vendor="mandrakesoft" name="mandrake_linux">
        <vers num="10.0" edition=""/>
        <vers num="10.0" edition=":amd64"/>
        <vers num="9.1" edition=""/>
        <vers num="9.1" edition=":ppc"/>
        <vers num="9.2" edition=""/>
        <vers num="9.2" edition=":amd64"/>
      </prod>
      <prod vendor="mandrakesoft" name="mandrake_linux_corporate_server">
        <vers num="2.1" edition=""/>
        <vers num="2.1" edition=":x86_64"/>
      </prod>
      <prod vendor="openbsd" name="openbsd">
        <vers num="3.4"/>
        <vers num="3.5"/>
        <vers num="current"/>
      </prod>
      <prod vendor="trustix" name="secure_linux">
        <vers num="1.5"/>
        <vers num="2.0"/>
        <vers num="2.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0489" published="2004-07-07" name="CVE-2004-0489" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:H/Au:N/C:C/I:C/A:C)" CVSS_score="7.6" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="4.9" CVSS_base_score="7.6">
    <desc>
      <descript source="cve">Argument injection vulnerability in the SSH URI handler for Safari on Mac OS 10.3.3 and earlier allows remote attackers to (1) execute arbitrary code via the ProxyCommand option or (2) conduct port forwarding via the -R option.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1" other="1" admin="1"/>
    </loss_types>
    <vuln_types>
      <design/>
    </vuln_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/16242" source="XF" adv="1">macos-ssh-code-execution(16242)</ref>
      <ref url="http://www.insecure.ws/article.php?story=200405222251133" source="MISC" adv="1">http://www.insecure.ws/article.php?story=200405222251133</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2004-May/021871.html" source="FULLDISC">20040524 SSH URI handler remote arbitrary code execution</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.3.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0490" published="2004-08-18" name="CVE-2004-0490" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">cPanel, when compiling Apache 1.3.29 and PHP with the mod_phpsuexec option, does not set the --enable-discard-path option, which causes php to use the SCRIPT_FILENAME variable to find and execute a script instead of the PATH_TRANSLATED variable, which allows local users to execute arbitrary PHP code as other users via a URL that references the attacker's script after the user's script, which executes the attacker's script with the user's privileges, a different vulnerability than CVE-2004-0529.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1" admin="1"/>
    </loss_types>
    <vuln_types>
      <design/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/16239" source="XF" adv="1">cpanel-modphpsuexec-execute-commands(16239)</ref>
      <ref url="http://www.securityfocus.com/bid/10407" source="BID" adv="1">10407</ref>
      <ref url="http://www.securityfocus.com/archive/1/364112" source="BUGTRAQ">20040524 cPanel mod_phpsuexec Vulnerability</ref>
      <ref url="http://www.securiteam.com/tools/5TP0N15CUA.html" source="MISC" adv="1">http://www.securiteam.com/tools/5TP0N15CUA.html</ref>
      <ref url="http://www.a-squad.com/audit/explain10.html" source="MISC">http://www.a-squad.com/audit/explain10.html</ref>
      <ref url="http://bugzilla.cpanel.net/show_bug.cgi?id=664" source="CONFIRM">http://bugzilla.cpanel.net/show_bug.cgi?id=664</ref>
      <ref url="http://bugzilla.cpanel.net/show_bug.cgi?id=283" source="MISC">http://bugzilla.cpanel.net/show_bug.cgi?id=283</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cpanel" name="cpanel">
        <vers num="5.0"/>
        <vers num="5.3"/>
        <vers num="6.0"/>
        <vers num="6.2"/>
        <vers num="6.4"/>
        <vers num="6.4.1"/>
        <vers num="6.4.2"/>
        <vers num="6.4.2_stable_48"/>
        <vers num="7.0"/>
        <vers num="8.0"/>
        <vers num="9.0"/>
        <vers num="9.1"/>
        <vers num="9.1.0_r85"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2004-0491" published="2004-12-31" name="CVE-2004-0491" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">The linux-2.4.21-mlock.patch in Red Hat Enterprise Linux 3 does not properly maintain the mlock page count when one process unlocks pages that belong to another process, which allows local users to mlock more memory than specified by the rlimit.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <vuln_types>
      <design/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=linux-kernel&amp;m=108087017610947&amp;w=2" source="MLIST" patch="1">[linux-kernel] 20040402 Re: disable-cap-mlock</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10672" source="OVAL">oval:org.mitre.oval:def:10672</ref>
      <ref url="http://www.securityfocus.com/bid/13769" source="BID">13769</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-472.html" source="REDHAT">RHSA-2005:472</ref>
      <ref url="http://secunia.com/advisories/19607" source="SECUNIA">19607</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/20060402-01-U" source="SGI">20060402-01-U</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1117" source="OVAL" sig="1">oval:org.mitre.oval:def:1117</ref>
    </refs>
    <vuln_soft>
      <prod vendor="redhat" name="enterprise_linux">
        <vers num="3.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0492" published="2004-08-06" name="CVE-2004-0492" modified="2011-09-06" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Heap-based buffer overflow in proxy_util.c for mod_proxy in Apache 1.3.25 to 1.3.31 allows remote attackers to cause a denial of service (process crash) and possibly execute arbitrary code via a negative Content-Length HTTP header field, which causes a large amount of data to be copied.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1" admin="1"/>
    </loss_types>
    <vuln_types>
      <input buffer="1"/>
      <exception/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/541310" source="CERT-VN">VU#541310</ref>
      <ref url="http://www.debian.org/security/2004/dsa-525" source="DEBIAN" patch="1" adv="1">DSA-525</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2004-245.html" source="REDHAT" patch="1" adv="1">RHSA-2004:245</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108711172710140&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20040611 [OpenPKG-SA-2004.029] OpenPKG Security Advisory (apache)</ref>
      <ref url="https://bugzilla.fedora.us/show_bug.cgi?id=1737" source="FEDORA">FLSA:1737</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/16387" source="XF" adv="1">apache-modproxy-contentlength-bo(16387)</ref>
      <ref url="http://www.guninski.com/modproxy1.html" source="MISC">http://www.guninski.com/modproxy1.html</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-57628-1" source="SUNALERT">57628</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-101841-1" source="SUNALERT">101841</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-101555-1" source="SUNALERT">101555</ref>
      <ref url="http://secunia.com/advisories/11841" source="SECUNIA">11841</ref>
      <ref url="http://seclists.org/lists/fulldisclosure/2004/Jun/0296.html" source="FULLDISC">20040610 Buffer overflow in apache mod_proxy,yet still apache much better than windows</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=130497311408250&amp;w=2" source="HP">SSRT090208</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=130497311408250&amp;w=2" source="HP">HPSBOV02683</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/20040605-01-U.asc" source="SGI">20040605-01-U</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2004:065" source="MANDRAKE">MDKSA-2004:065</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:4863" source="OVAL" sig="1">oval:org.mitre.oval:def:4863</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:100112" source="OVAL" sig="1">oval:org.mitre.oval:def:100112</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apache" name="http_server">
        <vers num="1.3.26"/>
        <vers num="1.3.27"/>
        <vers num="1.3.28"/>
        <vers num="1.3.29"/>
        <vers num="1.3.31"/>
      </prod>
      <prod vendor="hp" name="virtualvault">
        <vers num="11.0.4"/>
      </prod>
      <prod vendor="hp" name="webproxy">
        <vers num="2.0"/>
        <vers num="2.1"/>
      </prod>
      <prod vendor="ibm" name="http_server">
        <vers num="1.3.26"/>
        <vers num="1.3.26.1"/>
        <vers num="1.3.26.2"/>
        <vers num="1.3.28"/>
      </prod>
      <prod vendor="sgi" name="propack">
        <vers num="2.4"/>
      </prod>
      <prod vendor="hp" name="vvos">
        <vers num="11.04"/>
      </prod>
      <prod vendor="openbsd" name="openbsd">
        <vers num="3.4"/>
        <vers num="3.5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0493" published="2004-08-06" name="CVE-2004-0493" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:P)" CVSS_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_base_score="6.4">
    <desc>
      <descript source="cve">The ap_get_mime_headers_core function in Apache httpd 2.0.49 allows remote attackers to cause a denial of service (memory exhaustion), and possibly an integer signedness error leading to a heap-based buffer overflow on 64 bit systems, via long header lines with large numbers of space or tab characters.</descript>
    </desc>
    <loss_types>
      <avail/>
      <int/>
    </loss_types>
    <vuln_types>
      <input buffer="1"/>
      <exception/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/10619" source="BID" patch="1" adv="1">10619</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/16524" source="XF" adv="1">apache-apgetmimeheaderscore-dos(16524)</ref>
      <ref url="http://www.trustix.org/errata/2004/0039/" source="TRUSTIX">2004-0039</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-342.html" source="REDHAT">RHSA-2004:342</ref>
      <ref url="http://www.guninski.com/httpd1.html" source="MISC">http://www.guninski.com/httpd1.html</ref>
      <ref url="http://www.apacheweek.com/features/security-20" source="CONFIRM">http://www.apacheweek.com/features/security-20</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200407-03.xml" source="GENTOO">GLSA-200407-03</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10605" source="OVAL">oval:org.mitre.oval:def:10605</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109181600614477&amp;w=2" source="HP">SSRT4777</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2004-June/023133.html" source="FULLDISC">20040628 DoS in apache httpd 2.0.49, yet still apache much better than windows</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2004:064" source="MANDRAKE">MDKSA-2004:064</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108853066800184&amp;w=2" source="BUGTRAQ">20040629 TSSA-2004-012 - apache</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apache" name="http_server">
        <vers num="2.0.47"/>
        <vers num="2.0.48"/>
        <vers num="2.0.49"/>
      </prod>
      <prod vendor="ibm" name="http_server">
        <vers num="2.0.42"/>
        <vers num="2.0.42.1"/>
        <vers num="2.0.42.2"/>
        <vers num="2.0.47"/>
        <vers num="2.0.47.1"/>
      </prod>
      <prod vendor="avaya" name="converged_communications_server">
        <vers num="2.0"/>
      </prod>
      <prod vendor="avaya" name="s8300">
        <vers num="r2.0.0"/>
      </prod>
      <prod vendor="avaya" name="s8500">
        <vers num="r2.0.0"/>
      </prod>
      <prod vendor="avaya" name="s8700">
        <vers num="r2.0.0"/>
      </prod>
      <prod vendor="gentoo" name="linux">
        <vers num="1.4"/>
      </prod>
      <prod vendor="trustix" name="secure_linux">
        <vers num="1.5"/>
        <vers num="2.0"/>
        <vers num="2.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0494" published="2004-11-23" name="CVE-2004-0494" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple extfs backend scripts for GNOME virtual file system (VFS) before 1.0.1 may allow remote attackers to perform certain unauthorized actions via a gnome-vfs URI.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <design/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-373.html" source="REDHAT" patch="1" adv="1">RHSA-2004:373</ref>
      <ref url="https://bugzilla.fedora.us/show_bug.cgi?id=1944" source="FEDORA">FLSA:1944</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/16897" source="XF" adv="1">gnome-vfs-extfs-gain-access(16897)</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9854" source="OVAL">oval:org.mitre.oval:def:9854</ref>
      <ref url="http://rpmfind.net/linux/RPM/suse/9.3/i386/suse/i586/gnome-vfs-1.0.5-816.2.i586.html" source="CONFIRM">http://rpmfind.net/linux/RPM/suse/9.3/i386/suse/i586/gnome-vfs-1.0.5-816.2.i586.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="avaya" name="cvlan">
        <vers num=""/>
      </prod>
      <prod vendor="redhat" name="enterprise_linux">
        <vers num="2.1" edition=""/>
        <vers num="2.1" edition=":advanced_server_ia64"/>
        <vers num="2.1" edition=":workstation_ia64"/>
        <vers num="2.1" edition=":workstation"/>
        <vers num="2.1" edition=":advanced_server"/>
        <vers num="2.1" edition=":enterprise_server_ia64"/>
        <vers num="2.1" edition=":enterprise_server"/>
        <vers num="3.0" edition=""/>
        <vers num="3.0" edition=":advanced_server"/>
        <vers num="3.0" edition=":workstation_server"/>
        <vers num="3.0" edition=":enterprise_server"/>
      </prod>
      <prod vendor="redhat" name="enterprise_linux_desktop">
        <vers num="3.0"/>
      </prod>
      <prod vendor="redhat" name="linux_advanced_workstation">
        <vers num="2.1" edition=""/>
        <vers num="2.1" edition=":ia64"/>
        <vers num="2.1" edition=":itanium_processor"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0495" published="2004-08-06" name="CVE-2004-0495" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Multiple unknown vulnerabilities in Linux kernel 2.4 and 2.6 allow local users to gain privileges or access kernel memory, as found by the Sparse source code checking tool.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1" admin="1"/>
    </loss_types>
    <vuln_types>
      <other/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/10566" source="BID" patch="1" adv="1">10566</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-255.html" source="REDHAT" patch="1" adv="1">RHSA-2004:255</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/16449" source="XF" adv="1">linux-drivers-gain-privileges(16449)</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-260.html" source="REDHAT">RHSA-2004:260</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2004_20_kernel.html" source="SUSE">SUSE-SA:2004:020</ref>
      <ref url="http://www.mandrakesecure.net/en/advisories/advisory.php?name=MDKSA-2004:066" source="MANDRAKE">MDKSA-2004:066</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200407-02.xml" source="GENTOO" adv="1">GLSA-200407-02</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10155" source="OVAL">oval:org.mitre.oval:def:10155</ref>
      <ref url="http://lwn.net/Articles/91155/" source="FEDORA">FEDORA-2004-186</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000846" source="CONECTIVA">CLA-2004:846</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000845" source="CONECTIVA">CLA-2004:845</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2961" source="OVAL" sig="1">oval:org.mitre.oval:def:2961</ref>
    </refs>
    <vuln_soft>
      <prod vendor="avaya" name="intuity_audix">
        <vers num="" edition=":lx"/>
      </prod>
      <prod vendor="suse" name="suse_email_server">
        <vers num="3.1"/>
        <vers num="iii"/>
      </prod>
      <prod vendor="suse" name="suse_linux_admin-cd_for_firewall">
        <vers num=""/>
      </prod>
      <prod vendor="suse" name="suse_linux_connectivity_server">
        <vers num=""/>
      </prod>
      <prod vendor="suse" name="suse_linux_database_server">
        <vers num=""/>
      </prod>
      <prod vendor="suse" name="suse_linux_firewall_cd">
        <vers num=""/>
      </prod>
      <prod vendor="suse" name="suse_linux_office_server">
        <vers num=""/>
      </prod>
      <prod vendor="suse" name="suse_office_server">
        <vers num=""/>
      </prod>
      <prod vendor="avaya" name="converged_communications_server">
        <vers num="2.0"/>
      </prod>
      <prod vendor="avaya" name="s8300">
        <vers num="r2.0.0"/>
        <vers num="r2.0.1"/>
      </prod>
      <prod vendor="avaya" name="s8500">
        <vers num="r2.0.0"/>
        <vers num="r2.0.1"/>
      </prod>
      <prod vendor="avaya" name="s8700">
        <vers num="r2.0.0"/>
        <vers num="r2.0.1"/>
      </prod>
      <prod vendor="avaya" name="modular_messaging_message_storage_server">
        <vers num="s3400"/>
      </prod>
      <prod vendor="conectiva" name="linux">
        <vers num="8.0"/>
        <vers num="9.0"/>
      </prod>
      <prod vendor="gentoo" name="linux">
        <vers num="1.4"/>
      </prod>
      <prod vendor="linux" name="linux_kernel">
        <vers num="2.4.18"/>
        <vers num="2.4.19"/>
        <vers num="2.4.21"/>
        <vers num="2.4.22"/>
        <vers num="2.4.23"/>
        <vers num="2.4.24"/>
        <vers num="2.4.25"/>
        <vers num="2.4.26"/>
        <vers num="2.6.0"/>
        <vers num="2.6.1" edition="rc1"/>
        <vers num="2.6.1" edition="rc2"/>
        <vers num="2.6.2"/>
        <vers num="2.6.3"/>
        <vers num="2.6.4"/>
        <vers num="2.6.5"/>
        <vers num="2.6.6" edition="rc1"/>
        <vers num="2.6.7" edition="rc1"/>
      </prod>
      <prod vendor="redhat" name="enterprise_linux">
        <vers num="2.1" edition=""/>
        <vers num="2.1" edition=":advanced_server"/>
        <vers num="2.1" edition=":enterprise_server"/>
        <vers num="2.1" edition=":workstation"/>
        <vers num="3.0" edition=""/>
        <vers num="3.0" edition=":enterprise_server"/>
        <vers num="3.0" edition=":workstation"/>
        <vers num="3.0" edition=":advanced_servers"/>
      </prod>
      <prod vendor="suse" name="suse_linux">
        <vers num="7" edition=""/>
        <vers num="7" edition=":enterprise_server"/>
        <vers num="8" edition=""/>
        <vers num="8" edition=":enterprise_server"/>
        <vers num="8.0" edition=""/>
        <vers num="8.0" edition=":i386"/>
        <vers num="8.1"/>
        <vers num="8.2"/>
        <vers num="9.0" edition=""/>
        <vers num="9.0" edition=":x86_64"/>
        <vers num="9.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0496" published="2004-12-06" name="CVE-2004-0496" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Multiple unknown vulnerabilities in Linux kernel 2.6 allow local users to gain privileges or access kernel memory, a different set of vulnerabilities than those identified in CVE-2004-0495, as found by the Sparse source code checking tool.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/16625" source="XF" patch="1" adv="1">linux-gain-privileges(16625)</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2004_20_kernel.html" source="SUSE">SUSE-SA:2004:020</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mandrakesoft" name="mandrake_multi_network_firewall">
        <vers num="8.2"/>
      </prod>
      <prod vendor="suse" name="suse_email_server">
        <vers num="3"/>
        <vers num="3.1"/>
      </prod>
      <prod vendor="suse" name="suse_linux_connectivity_server">
        <vers num=""/>
      </prod>
      <prod vendor="suse" name="suse_linux_database_server">
        <vers num=""/>
      </prod>
      <prod vendor="suse" name="suse_linux_firewall">
        <vers num=""/>
      </prod>
      <prod vendor="suse" name="suse_linux_office_server">
        <vers num=""/>
      </prod>
      <prod vendor="gentoo" name="linux">
        <vers num=""/>
      </prod>
      <prod vendor="linux" name="linux_kernel">
        <vers num="2.6.0"/>
      </prod>
      <prod vendor="mandrakesoft" name="mandrake_linux">
        <vers num="10.0"/>
        <vers num="9.1"/>
        <vers num="9.2"/>
      </prod>
      <prod vendor="mandrakesoft" name="mandrake_linux_corporate_server">
        <vers num="2.1"/>
      </prod>
      <prod vendor="sun" name="solaris">
        <vers num="8.0"/>
        <vers num="8.1"/>
        <vers num="8.2"/>
        <vers num="9.0" edition=""/>
        <vers num="9.0" edition=":sparc"/>
        <vers num="9.1"/>
      </prod>
      <prod vendor="suse" name="suse_linux">
        <vers num="7" edition=""/>
        <vers num="7" edition=":enterprise_server"/>
        <vers num="8" edition=""/>
        <vers num="8" edition=":enterprise_server"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2004-0497" published="2004-12-06" name="CVE-2004-0497" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">Unknown vulnerability in Linux kernel 2.x may allow local users to modify the group ID of files, such as NFS exported files in kernel 2.4.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <vuln_types>
      <design/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/16599" source="XF" patch="1" adv="1">linux-fchown-groupid-modify(16599)</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-354.html" source="REDHAT" patch="1" adv="1">RHSA-2004:354</ref>
      <ref url="http://www.mandrakesecure.net/en/advisories/advisory.php?name=MDKSA-2004:066" source="MANDRAKE" patch="1" adv="1">MDKSA-2004:066</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000852" source="CONECTIVA" patch="1" adv="1">CLA-2004:852</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-360.html" source="REDHAT">RHSA-2004:360</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2004_20_kernel.html" source="SUSE">SUSE-SA:2004:020</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9867" source="OVAL">oval:org.mitre.oval:def:9867</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mandrakesoft" name="mandrake_multi_network_firewall">
        <vers num="8.2"/>
      </prod>
      <prod vendor="conectiva" name="linux">
        <vers num="10"/>
      </prod>
      <prod vendor="gentoo" name="linux">
        <vers num=""/>
      </prod>
      <prod vendor="linux" name="linux_kernel">
        <vers num="2.0"/>
      </prod>
      <prod vendor="mandrakesoft" name="mandrake_linux">
        <vers num="10.0"/>
        <vers num="9.1"/>
        <vers num="9.2"/>
      </prod>
      <prod vendor="mandrakesoft" name="mandrake_linux_corporate_server">
        <vers num="2.1"/>
      </prod>
      <prod vendor="redhat" name="enterprise_linux">
        <vers num="2.1" edition=""/>
        <vers num="2.1" edition=":workstation"/>
        <vers num="2.1" edition=":advanced_server"/>
        <vers num="2.1" edition=":enterprise_server"/>
        <vers num="3.0" edition=""/>
        <vers num="3.0" edition=":advanced_server"/>
        <vers num="3.0" edition=":workstation_server"/>
        <vers num="3.0" edition=":enterprise_server"/>
      </prod>
      <prod vendor="suse" name="suse_linux">
        <vers num="8.0"/>
        <vers num="8.1"/>
        <vers num="8.2"/>
        <vers num="9.0"/>
        <vers num="9.1"/>
      </prod>
      <prod vendor="trustix" name="secure_linux">
        <vers num="2"/>
        <vers num="2.0"/>
        <vers num="2.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0498" published="2004-12-31" name="CVE-2004-0498" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The H.323 protocol agent in StoneSoft firewall engine 2.2.8 and earlier allows remote attackers to cause a denial of service (crash) via crafted H.323 packets.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <vuln_types>
      <exception/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.uniras.gov.uk/niscc/docs/re-20041026-00956.pdf?lang=en" source="MISC" adv="1">http://www.uniras.gov.uk/niscc/docs/re-20041026-00956.pdf?lang=en</ref>
      <ref url="http://www.stonesoft.com/support/Security_Advisories/6735.html" source="MISC" adv="1">http://www.stonesoft.com/support/Security_Advisories/6735.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="stonesoft" name="firewall_engine">
        <vers prev="1" num="2.2.8"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" seq="2004-0499" reject="1" published="2004-12-31" name="CVE-2004-0499" modified="2008-09-10">
    <desc>
      <descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: none.  Reason: This candidate was withdrawn by its CNA.  Notes: none.</descript>
    </desc>
    <refs/>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0500" published="2004-09-28" name="CVE-2004-0500" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in the MSN protocol plugins (1) object.c and (2) slp.c for Gaim before 0.82 allows remote attackers to cause a denial of service and possibly execute arbitrary code via MSNSLP protocol messages that are not properly handled in a strncpy call.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input buffer="1"/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/16920" source="XF" patch="1" adv="1">gaim-msn-bo(16920)</ref>
      <ref url="http://www.securityfocus.com/bid/10865" source="BID" patch="1" adv="1">10865</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200408-12.xml" source="GENTOO" patch="1" adv="1">GLSA-200408-12</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-400.html" source="REDHAT">RHSA-2004:400</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2004_25_gaim.html" source="SUSE">SUSE-SA:2004:025</ref>
      <ref url="http://www.mandrakesecure.net/en/advisories/advisory.php?name=MDKSA-2004:081" source="MANDRAKE">MDKSA-2004:081</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200408-27.xml" source="GENTOO">GLSA-200408-27</ref>
      <ref url="http://www.fedoranews.org/updates/FEDORA-2004-279.shtml" source="FEDORA">FEDORA-2004-279</ref>
      <ref url="http://www.fedoranews.org/updates/FEDORA-2004-278.shtml" source="FEDORA">FEDORA-2004-278</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9429" source="OVAL">oval:org.mitre.oval:def:9429</ref>
      <ref url="http://gaim.sourceforge.net/security/?id=0" source="CONFIRM">http://gaim.sourceforge.net/security/?id=0</ref>
    </refs>
    <vuln_soft>
      <prod vendor="rob_flynn" name="gaim">
        <vers num="0.10"/>
        <vers num="0.10.3"/>
        <vers num="0.50"/>
        <vers num="0.51"/>
        <vers num="0.52"/>
        <vers num="0.53"/>
        <vers num="0.54"/>
        <vers num="0.55"/>
        <vers num="0.56"/>
        <vers num="0.57"/>
        <vers num="0.58"/>
        <vers num="0.59"/>
        <vers num="0.59.1"/>
        <vers num="0.60"/>
        <vers num="0.61"/>
        <vers num="0.62"/>
        <vers num="0.63"/>
        <vers num="0.64"/>
        <vers num="0.65"/>
        <vers num="0.66"/>
        <vers num="0.67"/>
        <vers num="0.68"/>
        <vers num="0.69"/>
        <vers num="0.70"/>
        <vers num="0.71"/>
        <vers num="0.72"/>
        <vers num="0.73"/>
        <vers num="0.74"/>
        <vers num="0.75"/>
      </prod>
      <prod vendor="gentoo" name="linux">
        <vers num="1.4"/>
      </prod>
      <prod vendor="mandrakesoft" name="mandrake_linux">
        <vers num="10.0" edition=""/>
        <vers num="10.0" edition=":amd64"/>
        <vers num="9.2" edition=""/>
        <vers num="9.2" edition=":amd64"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0501" published="2004-08-18" name="CVE-2004-0501" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Outlook 2003 allows remote attackers to bypass intended access restrictions and cause Outlook to request a URL from a remote site via an HTML e-mail message containing a Vector Markup Language (VML) entity whose src parameter points to the remote site, which could allow remote attackers to know when a message has been read, verify valid e-mail addresses, and possibly leak other information.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <vuln_types>
      <design/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/16116" source="XF" adv="1">outlook-vml-obtain-information(16116)</ref>
      <ref url="http://www.securityfocus.com/bid/10323" source="BID" adv="1">10323</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108430168919965&amp;w=2" source="BUGTRAQ" adv="1">20040511 PING: Outlook 2003 Spam</ref>
      <ref url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=108644231209698&amp;w=2" source="NTBUGTRAQ">20040604 RE: PING: Outlook 2003 Spam</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108637351805607&amp;w=2" source="BUGTRAQ">20040604 RE: PING: Outlook 2003 Spam</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="outlook">
        <vers num="2003"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0502" published="2004-08-18" name="CVE-2004-0502" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Outlook 2003, when replying to an e-mail message, stores certain files in a predictable location for the "src" of an img tag of the original message, which allows remote attackers to bypass zone restrictions and exploit other issues that rely on predictable locations, as demonstrated using a shell: URI.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <vuln_types>
      <design/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/16104" source="XF">outlook-file-location-predictable(16104)</ref>
      <ref url="http://www.securityfocus.com/bid/10307" source="BID" adv="1">10307</ref>
      <ref url="http://secunia.com/advisories/11572" source="SECUNIA">11572</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108637351805607&amp;w=2" source="BUGTRAQ" adv="1">20040604 RE: PING: Outlook 2003 Spam</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108420583612655&amp;w=2" source="BUGTRAQ" adv="1">20040509 OUTLOOK 2003: OuchLook</ref>
      <ref url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=108644231209698&amp;w=2" source="NTBUGTRAQ">20040604 RE: PING: Outlook 2003 Spam</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="outlook">
        <vers num="2003"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0503" published="2004-08-18" name="CVE-2004-0503" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Microsoft Outlook 2003 allows remote attackers to bypass the default zone restrictions and execute script within media files via a Rich Text Format (RTF) message containing an OLE object for the Windows Media Player, which bypasses Media Player's setting to disallow scripting and may lead to unprompted installation of an executable when exploited in conjunction with predictable-file-location exposures such as CVE-2004-0502.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <vuln_types>
      <design/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/10369" source="BID" patch="1" adv="1">10369</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/16173" source="XF" adv="1">outlook-ole-restriction-bypass(16173)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108483193328605&amp;w=2" source="BUGTRAQ" adv="1">20040517 ROCKET SCIENCE: Outllook 2003</ref>
      <ref url="http://www.osvdb.org/6217" source="OSVDB">6217</ref>
      <ref url="http://secunia.com/advisories/11629" source="SECUNIA">11629</ref>
      <ref url="http://archives.neohapsis.com/archives/fulldisclosure/2004-05/0885.html" source="FULLDISC">20040517 ROCKET SCIENCE: Outllook 2003</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="outlook">
        <vers num="2003"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0504" published="2004-08-18" name="CVE-2004-0504" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Ethereal 0.10.3 allows remote attackers to cause a denial of service (crash) via certain SIP messages between Hotsip servers and clients.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <vuln_types>
      <input buffer="1"/>
      <design/>
      <other/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/10347" source="BID" patch="1" adv="1">10347</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-234.html" source="REDHAT" patch="1" adv="1">RHSA-2004:234</ref>
      <ref url="http://www.ethereal.com/lists/ethereal-users/200405/msg00018.html" source="MLIST">[Ethereal-users] 20040503 Re: HotSIP sip-messages crasching ethereal</ref>
      <ref url="http://www.ethereal.com/appnotes/enpa-sa-00014.html" source="CONFIRM">http://www.ethereal.com/appnotes/enpa-sa-00014.html</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200406-01.xml" source="GENTOO" adv="1">GLSA-200406-01</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9769" source="OVAL">oval:org.mitre.oval:def:9769</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000916" source="CONECTIVA">CLA-2005:916</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/20040605-01-U.asc" source="SGI">20040605-01-U</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/20040604-01-U.asc" source="SGI">20040604-01-U</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/16148" source="XF">ethereal-sip-packet-dos(16148)</ref>
      <ref url="http://www.osvdb.org/6131" source="OSVDB">6131</ref>
      <ref url="http://www.ciac.org/ciac/bulletins/o-150.shtml" source="CIAC">O-150</ref>
      <ref url="http://securitytracker.com/id?1010158" source="SECTRACK">1010158</ref>
      <ref url="http://secunia.com/advisories/11836" source="SECUNIA">11836</ref>
      <ref url="http://secunia.com/advisories/11776" source="SECUNIA">11776</ref>
      <ref url="http://secunia.com/advisories/11608" source="SECUNIA">11608</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:982" source="OVAL" sig="1">oval:org.mitre.oval:def:982</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ethereal_group" name="ethereal">
        <vers num="0.10.1"/>
        <vers num="0.10.2"/>
        <vers num="0.10.3"/>
      </prod>
      <prod vendor="sgi" name="propack">
        <vers num="2.4"/>
        <vers num="3.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0505" published="2004-08-18" name="CVE-2004-0505" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The AIM dissector in Ethereal 0.10.3 allows remote attackers to cause a denial of service (assert error) via unknown attack vectors.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <vuln_types>
      <input buffer="1"/>
      <design/>
      <other/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/10347" source="BID" patch="1" adv="1">10347</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-234.html" source="REDHAT" patch="1" adv="1">RHSA-2004:234</ref>
      <ref url="http://www.ethereal.com/appnotes/enpa-sa-00014.html" source="CONFIRM">http://www.ethereal.com/appnotes/enpa-sa-00014.html</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200406-01.xml" source="GENTOO" adv="1">GLSA-200406-01</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9433" source="OVAL">oval:org.mitre.oval:def:9433</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000916" source="CONECTIVA">CLA-2005:916</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/20040605-01-U.asc" source="SGI">20040605-01-U</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/20040604-01-U.asc" source="SGI">20040604-01-U</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/16150" source="XF">ethereal-aim-dissector-dos(16150)</ref>
      <ref url="http://www.osvdb.org/6132" source="OSVDB">6132</ref>
      <ref url="http://www.ciac.org/ciac/bulletins/o-150.shtml" source="CIAC">O-150</ref>
      <ref url="http://securitytracker.com/id?1010158" source="SECTRACK">1010158</ref>
      <ref url="http://secunia.com/advisories/11836" source="SECUNIA">11836</ref>
      <ref url="http://secunia.com/advisories/11776" source="SECUNIA">11776</ref>
      <ref url="http://secunia.com/advisories/11608" source="SECUNIA">11608</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:986" source="OVAL" sig="1">oval:org.mitre.oval:def:986</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ethereal_group" name="ethereal">
        <vers num="0.10.1"/>
        <vers num="0.10.2"/>
        <vers num="0.10.3"/>
      </prod>
      <prod vendor="sgi" name="propack">
        <vers num="2.4"/>
        <vers num="3.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0506" published="2004-08-18" name="CVE-2004-0506" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The SPNEGO dissector in Ethereal 0.9.8 to 0.10.3 allows remote attackers to cause a denial of service (crash) via unknown attack vectors that cause a null pointer dereference.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <vuln_types>
      <input buffer="1"/>
      <design/>
      <other/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/10347" source="BID" patch="1" adv="1">10347</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-234.html" source="REDHAT" patch="1" adv="1">RHSA-2004:234</ref>
      <ref url="http://www.ethereal.com/appnotes/enpa-sa-00014.html" source="CONFIRM">http://www.ethereal.com/appnotes/enpa-sa-00014.html</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200406-01.xml" source="GENTOO" adv="1">GLSA-200406-01</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9695" source="OVAL">oval:org.mitre.oval:def:9695</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000916" source="CONECTIVA">CLA-2005:916</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/20040605-01-U.asc" source="SGI">20040605-01-U</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/20040604-01-U.asc" source="SGI">20040604-01-U</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/16151" source="XF">ethereal-spnego-dos(16151)</ref>
      <ref url="http://www.ciac.org/ciac/bulletins/o-150.shtml" source="CIAC">O-150</ref>
      <ref url="http://securitytracker.com/id?1010158" source="SECTRACK">1010158</ref>
      <ref url="http://secunia.com/advisories/11836" source="SECUNIA">11836</ref>
      <ref url="http://secunia.com/advisories/11776" source="SECUNIA">11776</ref>
      <ref url="http://secunia.com/advisories/11608" source="SECUNIA">11608</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:987" source="OVAL" sig="1">oval:org.mitre.oval:def:987</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ethereal_group" name="ethereal">
        <vers num="0.10.1"/>
        <vers num="0.10.2"/>
        <vers num="0.10.3"/>
      </prod>
      <prod vendor="sgi" name="propack">
        <vers num="2.4"/>
        <vers num="3.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0507" published="2004-08-18" name="CVE-2004-0507" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Buffer overflow in the MMSE dissector for Ethereal 0.10.1 to 0.10.3 allows remote attackers to cause a denial of service and possibly execute arbitrary code.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1" admin="1"/>
    </loss_types>
    <vuln_types>
      <input buffer="1"/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.ethereal.com/appnotes/enpa-sa-00014.html" source="CONFIRM" adv="1">http://www.ethereal.com/appnotes/enpa-sa-00014.html</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200406-01.xml" source="GENTOO" adv="1">GLSA-200406-01</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2004-234.html" source="REDHAT">RHSA-2004:234</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11026" source="OVAL">oval:org.mitre.oval:def:11026</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000916" source="CONECTIVA">CLA-2005:916</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/20040605-01-U.asc" source="SGI">20040605-01-U</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/20040604-01-U.asc" source="SGI">20040604-01-U</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/16152" source="XF">ethereal-mmse-bo(16152)</ref>
      <ref url="http://www.securityfocus.com/bid/10347" source="BID">10347</ref>
      <ref url="http://www.osvdb.org/6134" source="OSVDB">6134</ref>
      <ref url="http://www.ciac.org/ciac/bulletins/o-150.shtml" source="CIAC">O-150</ref>
      <ref url="http://securitytracker.com/id?1010158" source="SECTRACK">1010158</ref>
      <ref url="http://secunia.com/advisories/11836" source="SECUNIA">11836</ref>
      <ref url="http://secunia.com/advisories/11776" source="SECUNIA">11776</ref>
      <ref url="http://secunia.com/advisories/11608" source="SECUNIA">11608</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:988" source="OVAL" sig="1">oval:org.mitre.oval:def:988</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ethereal_group" name="ethereal">
        <vers num="0.10.1"/>
        <vers num="0.10.2"/>
        <vers num="0.10.3"/>
      </prod>
      <prod vendor="sgi" name="propack">
        <vers num="2.4"/>
        <vers num="3.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0510" published="2004-12-23" name="CVE-2004-0510" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Multiple buffer overflows in MMDF on OpenServer 5.0.6 and 5.0.7, and possibly other operating systems, may allow attackers to execute arbitrary code, as demonstrated via the execmail program.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <vuln_types>
      <input bound="1"/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/16738" source="XF" patch="1" adv="1">openserver-mmdf-bo(16738)</ref>
      <ref url="http://www.securityfocus.com/bid/10758" source="BID" patch="1" adv="1">10758</ref>
      <ref url="http://www.deprotect.com/advisories/DEPROTECT-20040206.txt" source="MISC">http://www.deprotect.com/advisories/DEPROTECT-20040206.txt</ref>
      <ref url="ftp://ftp.sco.com/pub/updates/OpenServer/SCOSA-2004.7/SCOSA-2004.7.txt" source="SCO">SCOSA-2004.7</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109889281711636&amp;w=2" source="BUGTRAQ">20041027 MMDF deliver local root exploit for SCO OpenServer 5.0.7 x86</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sco" name="openserver">
        <vers num="5.0.6"/>
        <vers num="5.0.6a"/>
        <vers num="5.0.7"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2004-0511" published="2004-12-23" name="CVE-2004-0511" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">Multiple unknown vulnerabilities in MMDF on OpenServer 5.0.6 and 5.0.7, and possibly other operating systems, may allow attackers to cause a denial of service by triggering a null dereference.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <vuln_types>
      <input bound="1"/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/16739" source="XF" patch="1" adv="1">openserver-mmdf-name-dos(16739)</ref>
      <ref url="http://www.securityfocus.com/bid/10758" source="BID" patch="1" adv="1">10758</ref>
      <ref url="ftp://ftp.sco.com/pub/updates/OpenServer/SCOSA-2004.7/SCOSA-2004.7.txt" source="SCO" patch="1" adv="1">SCOSA-2004.7</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sco" name="openserver">
        <vers num="5.0.6"/>
        <vers num="5.0.6a"/>
        <vers num="5.0.7"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2004-0512" published="2004-12-23" name="CVE-2004-0512" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">Multiple unknown vulnerabilities in MMDF on OpenServer 5.0.6 and 5.0.7, and possibly other operating systems, may allow attackers to cause a denial of service by triggering a core dump.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <vuln_types>
      <input bound="1"/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/16740" source="XF" patch="1" adv="1">openserver-mmdf-dos(16740)</ref>
      <ref url="http://www.securityfocus.com/bid/10758" source="BID" patch="1" adv="1">10758</ref>
      <ref url="ftp://ftp.sco.com/pub/updates/OpenServer/SCOSA-2004.7/SCOSA-2004.7.txt" source="SCO" patch="1" adv="1">SCOSA-2004.7</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sco" name="openserver">
        <vers num="5.0.6"/>
        <vers num="5.0.6a"/>
        <vers num="5.0.7"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0513" published="2004-08-18" name="CVE-2004-0513" modified="2008-09-10" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in Mac OS X before 10.3.4 has unknown impact and attack vectors related to "logging when tracing system calls."</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <vuln_types>
      <other/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/16291" source="XF">macosx-nfs-logging(16291)</ref>
      <ref url="http://www.securitytracker.com/alerts/2004/May/1010329.html" source="SECTRACK">1010329</ref>
      <ref url="http://www.securityfocus.com/bid/10432" source="BID">10432</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2004/May/msg00005.html" source="APPLE">APPLE-SA-2004-05-28</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers prev="1" num="10.3.4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0514" published="2004-08-18" name="CVE-2004-0514" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Unknown vulnerability in LoginWindow for Mac OS X 10.3.4, related to "handling of directory services lookups."</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1" admin="1"/>
    </loss_types>
    <vuln_types>
      <design/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/174790" source="CERT-VN" adv="1">VU#174790</ref>
      <ref url="http://www.securityfocus.com/bid/10432" source="BID" patch="1" adv="1">10432</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/16289" source="XF">macosx-loginwindow-gain-privileges(16289)</ref>
      <ref url="http://securitytracker.com/id?1010330" source="SECTRACK">1010330</ref>
      <ref url="http://lists.seifried.org/pipermail/security/2004-May/003743.html" source="APPLE">APPLE-SA-2004-05-28</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.3"/>
        <vers num="10.3.1"/>
        <vers num="10.3.2"/>
        <vers num="10.3.3"/>
      </prod>
      <prod vendor="apple" name="mac_os_x_server">
        <vers num="10.3"/>
        <vers num="10.3.1"/>
        <vers num="10.3.2"/>
        <vers num="10.3.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0515" published="2004-08-18" name="CVE-2004-0515" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Unknown vulnerability in LoginWindow for Mac OS X 10.3.4, related to "handling of console log files."</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <other/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/10432" source="BID" patch="1" adv="1">10432</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/16289" source="XF">macosx-loginwindow-gain-privileges(16289)</ref>
      <ref url="http://securitytracker.com/id?1010330" source="SECTRACK">1010330</ref>
      <ref url="http://lists.seifried.org/pipermail/security/2004-May/003743.html" source="APPLE">APPLE-SA-2004-05-28</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.3"/>
        <vers num="10.3.1"/>
        <vers num="10.3.2"/>
        <vers num="10.3.3"/>
      </prod>
      <prod vendor="apple" name="mac_os_x_server">
        <vers num="10.3"/>
        <vers num="10.3.1"/>
        <vers num="10.3.2"/>
        <vers num="10.3.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0516" published="2004-08-18" name="CVE-2004-0516" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Unknown vulnerability in Mac OS X 10.3.4, related to "package installation scripts," a different vulnerability than CVE-2004-0517.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <other/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/10432" source="BID" patch="1" adv="1">10432</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/16290" source="XF">macosx-package-installation(16290)</ref>
      <ref url="http://securitytracker.com/id?1010331" source="SECTRACK">1010331</ref>
      <ref url="http://lists.seifried.org/pipermail/security/2004-May/003743.html" source="APPLE">APPLE-SA-2004-05-28</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.3"/>
        <vers num="10.3.1"/>
        <vers num="10.3.2"/>
        <vers num="10.3.3"/>
      </prod>
      <prod vendor="apple" name="mac_os_x_server">
        <vers num="10.3"/>
        <vers num="10.3.1"/>
        <vers num="10.3.2"/>
        <vers num="10.3.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0517" published="2004-08-18" name="CVE-2004-0517" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Unknown vulnerability in Mac OS X 10.3.4, related to "handling of process IDs during package installation," a different vulnerability than CVE-2004-0516.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <other/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/10432" source="BID" patch="1" adv="1">10432</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/16290" source="XF">macosx-package-installation(16290)</ref>
      <ref url="http://securitytracker.com/id?1010331" source="SECTRACK">1010331</ref>
      <ref url="http://lists.seifried.org/pipermail/security/2004-May/003743.html" source="APPLE">APPLE-SA-2004-05-28</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.3"/>
        <vers num="10.3.1"/>
        <vers num="10.3.2"/>
        <vers num="10.3.3"/>
      </prod>
      <prod vendor="apple" name="mac_os_x_server">
        <vers num="10.3"/>
        <vers num="10.3.1"/>
        <vers num="10.3.2"/>
        <vers num="10.3.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0518" published="2004-08-18" name="CVE-2004-0518" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Unknown vulnerability in AppleFileServer for Mac OS X 10.3.4, related to "the use of SSH and reporting errors," has unknown impact and attack vectors.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <other/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/16288" source="XF">applefileserver-reporting-error(16288)</ref>
      <ref url="http://securitytracker.com/id?1010333" source="SECTRACK">1010333</ref>
      <ref url="http://lists.seifried.org/pipermail/security/2004-May/003743.html" source="APPLE">APPLE-SA-2004-05-28</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.3"/>
        <vers num="10.3.1"/>
        <vers num="10.3.2"/>
        <vers num="10.3.3"/>
      </prod>
      <prod vendor="apple" name="mac_os_x_server">
        <vers num="10.3"/>
        <vers num="10.3.1"/>
        <vers num="10.3.2"/>
        <vers num="10.3.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0519" published="2004-08-18" name="CVE-2004-0519" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in SquirrelMail 1.4.2 allow remote attackers to execute arbitrary script as other users and possibly steal authentication information via multiple attack vectors, including the mailbox parameter in compose.php.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="https://bugzilla.fedora.us/show_bug.cgi?id=1733" source="FEDORA" patch="1">FEDORA-2004-1733</ref>
      <ref url="http://www.securityfocus.com/bid/10246" source="BID" patch="1">10246</ref>
      <ref url="http://www.securityfocus.com/advisories/6827" source="FEDORA" patch="1" adv="1">FEDORA-2004-160</ref>
      <ref url="http://www.debian.org/security/2004/dsa-535" source="DEBIAN" patch="1" adv="1">DSA-535</ref>
      <ref url="http://secunia.com/advisories/12289" source="SECUNIA" patch="1">12289</ref>
      <ref url="http://secunia.com/advisories/11870" source="SECUNIA" patch="1" adv="1">11870</ref>
      <ref url="http://secunia.com/advisories/11686" source="SECUNIA" patch="1" adv="1">11686</ref>
      <ref url="http://secunia.com/advisories/11531" source="SECUNIA" patch="1" adv="1">11531</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2004-240.html" source="REDHAT" patch="1" adv="1">RHSA-2004:240</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/20040604-01-U.asc" source="SGI" patch="1">20040604-01-U</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/16025" source="XF">squirrel-composephp-xss(16025)</ref>
      <ref url="http://www.securityfocus.com/archive/1/361857" source="BUGTRAQ">20040430 Re: SquirrelMail Cross Scripting Attacks....</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2005_19_sr.html" source="SUSE" adv="1">SUSE-SR:2005:019</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200405-16.xml" source="GENTOO" adv="1">GLSA-200405-16</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10274" source="OVAL">oval:org.mitre.oval:def:10274</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108334862800260" source="BUGTRAQ">20040429 SquirrelMail Cross Scripting Attacks....</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000858" source="CONECTIVA">CLA-2004:858</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1006" source="OVAL" sig="1">oval:org.mitre.oval:def:1006</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sgi" name="propack">
        <vers num="3.0"/>
      </prod>
      <prod vendor="squirrelmail" name="squirrelmail">
        <vers num="1.0.4"/>
        <vers num="1.0.5"/>
        <vers num="1.2.0"/>
        <vers num="1.2.1"/>
        <vers num="1.2.10"/>
        <vers num="1.2.11"/>
        <vers num="1.2.2"/>
        <vers num="1.2.3"/>
        <vers num="1.2.4"/>
        <vers num="1.2.5"/>
        <vers num="1.2.6"/>
        <vers num="1.2.7"/>
        <vers num="1.2.8"/>
        <vers num="1.2.9"/>
        <vers num="1.4"/>
        <vers num="1.4.1"/>
        <vers num="1.4.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0520" published="2004-08-18" name="CVE-2004-0520" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in mime.php for SquirrelMail before 1.4.3 allows remote attackers to insert arbitrary HTML and script via the content-type mail header, as demonstrated using read_body.php.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="https://bugzilla.fedora.us/show_bug.cgi?id=1733" source="FEDORA" patch="1">FEDORA-2004-1733</ref>
      <ref url="http://www.securityfocus.com/bid/10439" source="BID" patch="1">10439</ref>
      <ref url="http://www.securityfocus.com/advisories/6827" source="FEDORA" patch="1" adv="1">FEDORA-2004-160</ref>
      <ref url="http://www.debian.org/security/2004/dsa-535" source="DEBIAN" patch="1" adv="1">DSA-535</ref>
      <ref url="http://secunia.com/advisories/12289" source="SECUNIA" patch="1" adv="1">12289</ref>
      <ref url="http://secunia.com/advisories/11870" source="SECUNIA" patch="1" adv="1">11870</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2004-240.html" source="REDHAT" patch="1" adv="1">RHSA-2004:240</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/20040604-01-U.asc" source="SGI" patch="1">20040604-01-U</ref>
      <ref url="http://www.rs-labs.com/adv/RS-Labs-Advisory-2004-1.txt" source="MISC" adv="1">http://www.rs-labs.com/adv/RS-Labs-Advisory-2004-1.txt</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200406-08.xml" source="GENTOO" adv="1">GLSA-200406-08</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10766" source="OVAL">oval:org.mitre.oval:def:10766</ref>
      <ref url="http://marc.theaimsgroup.com/?l=squirrelmail-cvs&amp;m=108532891231712" source="MLIST">[squirrelmail-cvs] 20040523 [SM-CVS] CVS: squirrelmail/functions mime.php,1.265.2.27,1.265.2.28</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108611554415078&amp;w=2" source="BUGTRAQ" adv="1">20040530 RS-2004-1: SquirrelMail "Content-Type" XSS vulnerability</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000858" source="CONECTIVA">CLA-2004:858</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1012" source="OVAL" sig="1">oval:org.mitre.oval:def:1012</ref>
    </refs>
    <vuln_soft>
      <prod vendor="open_webmail" name="open_webmail">
        <vers num="2.30"/>
        <vers num="2.31"/>
        <vers num="2.32"/>
      </prod>
      <prod vendor="sgi" name="propack">
        <vers num="3.0"/>
      </prod>
      <prod vendor="squirrelmail" name="squirrelmail">
        <vers num="1.2.0"/>
        <vers num="1.2.1"/>
        <vers num="1.2.10"/>
        <vers num="1.2.11"/>
        <vers num="1.2.2"/>
        <vers num="1.2.3"/>
        <vers num="1.2.4"/>
        <vers num="1.2.5"/>
        <vers num="1.2.6"/>
        <vers num="1.2.7"/>
        <vers num="1.2.8"/>
        <vers num="1.2.9"/>
        <vers num="1.4"/>
        <vers num="1.4.1"/>
        <vers num="1.4.2"/>
        <vers num="1.4.3_rc1"/>
        <vers num="1.5_dev"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0521" published="2004-08-18" name="CVE-2004-0521" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">SQL injection vulnerability in SquirrelMail before 1.4.3 RC1 allows remote attackers to execute unauthorized SQL statements, with unknown impact, probably via abook_database.php.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1" admin="1"/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/10397" source="BID" patch="1" adv="1">10397</ref>
      <ref url="https://bugzilla.fedora.us/show_bug.cgi?id=1733" source="FEDORA">FEDORA-2004-1733</ref>
      <ref url="http://www.debian.org/security/2004/dsa-535" source="DEBIAN">DSA-535</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200405-16.xml" source="GENTOO" adv="1">GLSA-200405-16</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2004-240.html" source="REDHAT">RHSA-2004:240</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11446" source="OVAL">oval:org.mitre.oval:def:11446</ref>
      <ref url="http://marc.theaimsgroup.com/?l=squirrelmail-cvs&amp;m=108309375029888" source="MLIST" adv="1">[squirrelmail-cvs] 20040427 [SM-CVS] CVS: squirrelmail/functions abook_database.php,1.15.2.1,1.15.2.2</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/20040604-01-U.asc" source="SGI">20040604-01-U</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/16235" source="XF">squirrelmail-sql-injection(16235)</ref>
      <ref url="http://www.securityfocus.com/advisories/7148" source="APPLE">APPLE-SA-2004-09-07</ref>
      <ref url="http://www.securityfocus.com/advisories/6827" source="FEDORA">FEDORA-2004-160</ref>
      <ref url="http://www.osvdb.org/6841" source="OSVDB">6841</ref>
      <ref url="http://www.ciac.org/ciac/bulletins/o-212.shtml" source="CIAC">O-212</ref>
      <ref url="http://secunia.com/advisories/12289" source="SECUNIA">12289</ref>
      <ref url="http://secunia.com/advisories/11870" source="SECUNIA">11870</ref>
      <ref url="http://secunia.com/advisories/11686" source="SECUNIA">11686</ref>
      <ref url="http://secunia.com/advisories/11685" source="SECUNIA">11685</ref>
      <ref url="http://marc.theaimsgroup.com/?l=squirrelmail-cvs&amp;m=108532891231712" source="MLIST">[squirrelmail-devel] 20040511 [SM-DEVEL] SquirrelMail 1.4.3-RC1 Release</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000858" source="CONECTIVA">CLA-2004:858</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1033" source="OVAL" sig="1">oval:org.mitre.oval:def:1033</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sgi" name="propack">
        <vers num="3.0"/>
      </prod>
      <prod vendor="squirrelmail" name="squirrelmail">
        <vers num="1.0.4"/>
        <vers num="1.0.5"/>
        <vers num="1.2.0"/>
        <vers num="1.2.1"/>
        <vers num="1.2.10"/>
        <vers num="1.2.11"/>
        <vers num="1.2.2"/>
        <vers num="1.2.3"/>
        <vers num="1.2.4"/>
        <vers num="1.2.5"/>
        <vers num="1.2.6"/>
        <vers num="1.2.7"/>
        <vers num="1.2.8"/>
        <vers num="1.2.9"/>
        <vers num="1.4"/>
        <vers num="1.4.1"/>
        <vers num="1.4.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0522" published="2004-08-06" name="CVE-2004-0522" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Gallery 1.4.3 and earlier allows remote attackers to bypass authentication and obtain Gallery administrator privileges.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <vuln_types>
      <access/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/10451" source="BID" patch="1" adv="1">10451</ref>
      <ref url="http://www.debian.org/security/2004/dsa-512" source="DEBIAN" patch="1" adv="1">DSA-512</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/16301" source="XF" adv="1">gallery-user-bypass-authentication(16301)</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200406-10.xml" source="GENTOO">GLSA-200406-10</ref>
      <ref url="http://secunia.com/advisories/11752" source="SECUNIA">11752</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gallery_project" name="gallery">
        <vers num="1.4"/>
        <vers num="1.4.1"/>
        <vers num="1.4.2"/>
        <vers num="1.4.3_pl1"/>
        <vers num="1.4_pl1"/>
        <vers num="1.4_pl2"/>
      </prod>
      <prod vendor="debian" name="debian_linux">
        <vers num="3.0" edition=""/>
        <vers num="3.0" edition=":hppa"/>
        <vers num="3.0" edition=":mips"/>
        <vers num="3.0" edition=":ia-32"/>
        <vers num="3.0" edition=":m68k"/>
        <vers num="3.0" edition=":s-390"/>
        <vers num="3.0" edition=":alpha"/>
        <vers num="3.0" edition=":arm"/>
        <vers num="3.0" edition=":ia-64"/>
        <vers num="3.0" edition=":mipsel"/>
        <vers num="3.0" edition=":sparc"/>
        <vers num="3.0" edition=":ppc"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0523" published="2004-08-18" name="CVE-2004-0523" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Multiple buffer overflows in krb5_aname_to_localname for MIT Kerberos 5 (krb5) 1.3.3 and earlier allow remote attackers to execute arbitrary code as root.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <vuln_types>
      <input buffer="1"/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/686862" source="CERT-VN" adv="1">VU#686862</ref>
      <ref url="http://www.debian.org/security/2004/dsa-520" source="DEBIAN" patch="1" adv="1">DSA-520</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/16268" source="XF">Kerberos-krb5anametolocalname-bo(16268)</ref>
      <ref url="http://www.securityfocus.com/bid/10448" source="BID">10448</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2004-236.html" source="REDHAT">RHSA-2004:236</ref>
      <ref url="http://www.mandrakesecure.net/en/advisories/advisory.php?name=MDKSA-2004:056" source="MANDRAKE">MDKSA-2004:056</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200406-21.xml" source="GENTOO">GLSA-200406-21</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-101512-1" source="SUNALERT">101512</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10295" source="OVAL">oval:org.mitre.oval:def:10295</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108619250923790&amp;w=2" source="TRUSTIX">2004-0032</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108619161815320&amp;w=2" source="BUGTRAQ">20040602 TSSA-2004-009 - kerberos5</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108612325909496&amp;w=2" source="BUGTRAQ">20040601 MITKRB5-SA-2004-001: buffer overflows in krb5_aname_to_localname</ref>
      <ref url="http://lwn.net/Articles/88206/" source="FEDORA">FEDORA-2004-149</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000860" source="CONECTIVA">CLA-2004:860</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/20040605-01-U.asc" source="SGI">20040605-01-U</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/20040604-01-U.asc" source="SGI">20040604-01-U</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:991" source="OVAL" sig="1">oval:org.mitre.oval:def:991</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:724" source="OVAL" sig="1">oval:org.mitre.oval:def:724</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2002" source="OVAL" sig="1">oval:org.mitre.oval:def:2002</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mit" name="kerberos">
        <vers num="1.0"/>
        <vers num="1.0.8"/>
        <vers num="1.2.2.beta1"/>
        <vers num="5-1.1"/>
        <vers num="5-1.2"/>
        <vers num="5-1.2.1"/>
        <vers num="5-1.2.2"/>
        <vers num="5-1.2.3"/>
        <vers num="5-1.2.4"/>
        <vers num="5-1.2.5"/>
        <vers num="5-1.2.6"/>
        <vers num="5-1.2.7"/>
        <vers num="5-1.3" edition="alpha1"/>
        <vers num="5_1.0"/>
        <vers num="5_1.0.6"/>
        <vers num="5_1.1"/>
        <vers num="5_1.1.1"/>
        <vers num="5_1.2" edition="beta1"/>
        <vers num="5_1.2" edition="beta2"/>
        <vers num="5_1.3.3"/>
      </prod>
      <prod vendor="sgi" name="propack">
        <vers num="2.4"/>
        <vers num="3.0"/>
      </prod>
      <prod vendor="sun" name="seam">
        <vers num="1.0"/>
        <vers num="1.0.1"/>
        <vers num="1.0.2"/>
      </prod>
      <prod vendor="tinysofa" name="tinysofa_enterprise_server">
        <vers num="1.0"/>
        <vers num="1.0_u1"/>
      </prod>
      <prod vendor="sun" name="solaris">
        <vers num="8.0" edition=""/>
        <vers num="8.0" edition=":x86"/>
        <vers num="9.0" edition=""/>
        <vers num="9.0" edition=":sparc"/>
        <vers num="9.0" edition=":x86"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2004-0524" published="2004-08-06" name="CVE-2004-0524" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Buffer overflow in the chpasswd command in the Change_passwd plugin before 4.0, as used in SquirrelMail, allows local users to gain root privileges via a long user name.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <vuln_types>
      <input buffer="1"/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/10166" source="BID" patch="1" adv="1">10166</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108311782032370&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20040427 Re:  Squirrelmail Chpasswod bof</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/15889" source="XF" adv="1">squirrelmail-chpasswd-binary-bo(15889)</ref>
      <ref url="http://www.squirrelmail.org/plugin_view.php?id=117" source="CONFIRM">http://www.squirrelmail.org/plugin_view.php?id=117</ref>
      <ref url="http://secunia.com/advisories/11415" source="SECUNIA">11415</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108222863917958&amp;w=2" source="BUGTRAQ">20040417 Squirrelmail Chpasswod bof</ref>
    </refs>
  </entry>
  <entry type="CVE" severity="Medium" seq="2004-0525" published="2004-08-06" name="CVE-2004-0525" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">HP Integrated Lights-Out (iLO) 1.10 and other versions before 1.55 allows remote attackers to cause a denial of service 